Two step-by-step TDD plans derived from the 2026-09-14 design specs:
* theme-registry: 9 tasks, 70+ steps. Creates src/main/ThemeRegistry.js
(pure module), bootstrap with 37 themes, buildThemeMenu for main.js,
migrates 25 existing per-theme CSS blocks into src/styles/themes/<id>.css,
rewrites the renderer apply-theme function to toggle <link disabled>,
adds 12 new theme CSS files using shared token vocabulary.
* flowchart-editor: 8 tasks, 41 TDD steps. Pure renderer-side feature
(no main-process modules). Pure data store with IO injection, 5 SVG
shape functions, Mermaid translator, hand-rolled SVG canvas with
pointer events, sidebar panel wiring with debounced preview (250ms)
+ debounced persistence (500ms) + panel-scoped keyboard shortcuts.
Three minimal userData-path-validated IPC channels added for
persistence (renderer can't reach <userData> under the current
nodeIntegration:true security model without them).
Amit Haridas
Three new specs for the v4.8.0+ feature wave:
* Theme registry: replace hardcoded 25-theme menu in main.js with a pure
ThemeRegistry module + per-theme CSS file convention. Add 12 new themes
(Catppuccin x4, One Light, Tokyo Night Storm, Synthwave '84, Outrun,
Winter is Coming Light+Dark, Solarized Dark HC, Spring Light).
* ASCII art upgrade: consolidate dual implementations (standalone window
vs dead in-app modal) into a single path; add 12 hand-coded fonts +
figlet npm library for 400+ fonts; add copy/save/insert output
destinations; comprehensive tests for the previously-zero-coverage
textToASCII/createASCIIBox/getASCIITemplate machinery.
* Flow chart editor: sidebar panel with hand-rolled SVG canvas, node-graph
data model, drag/drop editing, live Mermaid source preview, undo/redo,
session persistence. Emits Mermaid which the existing preview pane
already renders natively.
Amit Haridas
@ cantoo/pdf-lib 2.9.1 was already the dep in use; the encryption plumbing
and probe were already in place from the prior hardening pass. This commit:
- adds a test confirming executeOperation('permissions', ...) routes through
pdfSetPermissions and produces an encrypted PDF unlocked by the owner
password (mirrors the existing 'encrypt' route coverage)
- updates docs/superpowers/plans/2026-08-23-security-assessment-summary.md
to mark deferred risk D1 as resolved (the honest-failure message remains
as a fail-closed net for any future library regression)
35 PDF ops tests pass; lint/format clean.
Amit Haridas
Final-review nit: the hardcoded-list rationale covers the dialog path
only; the drop stands on the trusted-argv precedent for --convert-to.
Amit Haridas
Task-20-review finding: File.path removed in Electron 32, app on ^41.1.1,
~15 renderer file-picker sites read it and get undefined at runtime.
Amit Haridas
Inlines @font-face as base64 data URI so the iframe srcdoc can render
JetBrains Mono / Fira Code without depending on the parent window's
loaded @font-face sets. Reads family + ligature state from the
renderer-wide cache populated by applyMonospaceClasses().
Amit Haridas
Bundles JetBrains Mono + Fira Code TTFs in assets/fonts/. Embeds them into
DOCX (jszip), passes path via xelatex fontspec for PDF, base64-injects
@font-face for HTML/EPUB. Replaces Consolas (Windows-only) and Google Fonts
CDN load in the ASCII generator window.
Adds user-pickable monospace family + ligature toggle (default JBM, no
ligatures) for ASCII column alignment.
Closes: N/A
Refs: docs/superpowers/specs/2026-06-30-monospace-font-embedding-design.md
Amit Haridas
9 tasks across 8 chunks, strict TDD:
- EventBus with crash-safe handlers
- PluginAPI base class
- PluginLoader with manifest validation
- PluginContext with scoped API
- PluginRegistry with lifecycle management
- SettingsStore for plugin-scoped settings
- Export hooks integration
- Sample plugin + renderer wiring
Amit Haridas
- GGUF GPU: child process isolation with crash detection/restart
- Event bus: versioned payload schemas for all events
- Plugin sandbox: 5s handler timeout, IPC delegation for heavy ops
- AI streaming: full lifecycle with requestId, cancel, heartbeat, orphan cleanup
- Comment anchors: context-based positioning (not byte offsets) with re-anchor on file change
- Cross-plugin: capability discovery, 30s timeout, graceful degradation
- Bundle size: GPU variants as lazy downloads, not bundled by default
- Command uniqueness: registry rejects duplicates at load time
Amit Haridas