Compare commits

..
52 Commits
Author SHA1 Message Date
amitwhandClaude 1b2afb5f15 Fix double-click file opening in installed Windows app (v1.7.5)
This fix addresses the critical issue where double-clicking .md files would not open them in the installed PanConverter application on Windows.

## Root Cause
When a user double-clicks a file and the app is already running, Windows tries to launch a SECOND INSTANCE with the file path. Without single-instance lock handling, that second instance would exit and the first instance would never receive the file path.

## Changes
- Added single-instance lock handling in main.js (lines 52-85)
- Implemented second-instance event handler to capture file paths
- Focus existing window when second instance is attempted
- Pass file path to existing instance using openFileFromPath()
- Properly handle rendererReady state for file opening

## Testing
- Works in development mode (npm start)
- Should now work correctly in installed Windows app with double-click
- Maintains single instance behavior across all file opening methods

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 13:46:48 +05:30
amitwhandClaude c811af9d48 Remove debug console.log statements (v1.7.4 cleanup)
Cleaned up debug logging from file opening investigation:
- Removed console.log from command line arg processing
- Removed console.log from renderer-ready handler
- Removed console.log from openFileFromPath function
- Removed console.log from file-opened IPC handler

The double-click file opening fix is confirmed working.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 13:13:27 +05:30
amitwhandClaude a6e91b7403 Fix critical double-click file opening bug (v1.7.4)
CRITICAL BUG FIX: Files opened via double-click were not rendering in the application.

Root Cause:
- The openFileFromPath() function was sending IPC 'file-opened' message WITHOUT checking if rendererReady was true
- When files were double-clicked before renderer initialization, the IPC message was sent but lost
- The comment "Always try to send, the renderer will handle it when ready" was incorrect

The Fix (src/main.js:1586):
- Added rendererReady check to the conditional: if (mainWindow && mainWindow.webContents && rendererReady)
- Now properly stores file in app.pendingFile when renderer is not ready
- File is opened correctly when renderer-ready signal arrives

Flow:
1. File double-clicked → openFileFromPath() called
2. If renderer NOT ready → store in app.pendingFile
3. When renderer sends 'renderer-ready' → openFileFromPath(app.pendingFile) is called
4. This time renderer IS ready → file opens successfully

Version: 1.7.4
- Updated package.json version to 1.7.4
- Updated About dialog version to 1.7.4

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 12:57:52 +05:30
amitwhandClaude a44b13d2fb Version 1.7.3 - Bug Fixes and ConcreteInfo Themes
Fixed critical file opening bug and theme visibility issues, plus added ConcreteInfo branded themes.

Bug Fixes:
• Fixed double-click file opening race condition
  - Removed setTimeout logic from did-finish-load handler
  - Now relies solely on renderer-ready IPC signal for proper initialization
  - Files from Windows Explorer now open correctly on first attempt

• Fixed theme preview text visibility for 14 themes
  - Added proper .pane:last-child background overrides
  - Fixed dark text on dark backgrounds and light text on light backgrounds
  - Affected themes: Dracula, Nord, One Dark, Atom One Light, Material,
    Gruvbox Dark/Light, Tokyo Night, Palenight, Ayu Dark/Light/Mirage,
    Oceanic Next, Cobalt2

New Features:
• Added 3 ConcreteInfo branded themes
  - Concrete Dark: Very dark theme with orange accents
  - Concrete Light: Light theme with orange accents
  - Concrete Warm: Mid-tone gray theme with orange accents
  - All themes use ConcreteInfo brand colors: #0d0b09, #464646, #9a9696, #e3e3e3, #e5461f

• Updated theme count from 19 to 22 themes

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 12:48:42 +05:30
amitwhandClaude 015446bff3 Version 1.7.2 - Enhanced Themes & Bug Fixes
## New Features
- Added 14 beautiful new themes (Dracula, Nord, One Dark, Atom One Light, Material, Gruvbox Dark/Light, Tokyo Night, Palenight, Ayu Dark/Light/Mirage, Oceanic Next, Cobalt2)
- Total of 19 professionally-designed themes now available
- All themes fully support glassmorphism effects from v1.7.1

## Bug Fixes
- Fixed undo/redo menu integration - connected Edit menu to custom undo/redo functionality
- Added IPC event listeners for proper keyboard shortcut support (Ctrl+Z, Ctrl+Shift+Z)

## Technical Improvements
- Complete CSS styling for all UI elements per theme (tabs, toolbar, editor, preview, status bar)
- Theme-aware color schemes for syntax highlighting
- Comprehensive CSS implementation (965+ lines for new themes)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 12:07:28 +05:30
amitwhandClaude 9f15a02511 Update version to 1.7.1 and document UI improvements
- Updated version from 1.7.0 to 1.7.1 in package.json
- Updated About dialog version in main.js
- Added modern glassmorphism UI as first feature
- Updated CLAUDE.md with v1.7.1 documentation
- Documented glassmorphism design system
- Listed all modern UI features and technical details
- Updated last modified date to October 11, 2025

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 11:47:38 +05:30
amitwhandClaude 9799b95cea Add modern UI with glassmorphism and gradients (v1.7.1)
- Created comprehensive modern CSS design system
- Glassmorphism effects with backdrop-filter blur
- Animated purple-blue gradient background
- Modern Inter and JetBrains Mono typography
- Smooth transitions and hover effects
- Enhanced tab, button, and dialog styling
- Custom scrollbars and progress bars
- CSS custom properties for consistent theming

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 11:43:49 +05:30
amitwhandClaude 83150eea88 Fix double-click file opening with did-finish-load event
- Added did-finish-load event listener to ensure window is fully loaded
- Added 500ms delay to allow TabManager initialization
- Improved openFileFromPath function with better logging
- Fixed race condition where files opened via double-click weren't rendering

Fixes #file-association-rendering-issue

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 11:39:57 +05:30
amitwhandClaude 9b2b94ad74 Version 1.7.0 - Comprehensive PDF Editor & Universal File Converter
Major new features:
• Complete PDF Editor with 10 operations (merge, split, compress, rotate, delete, reorder, watermark, encrypt, decrypt, permissions)
• Universal File Converter supporting LibreOffice, ImageMagick, FFmpeg, and Pandoc
• Single file and batch folder conversion capabilities
• Advanced options for all conversion tools

PDF Editor Features:
• Merge multiple PDFs into one document
• Split PDFs by page ranges, intervals, or file size
• Compress PDFs to reduce file size
• Rotate pages at 90°, 180°, or 270°
• Delete unwanted pages from PDFs
• Reorder pages in any custom order
• Add text watermarks with customizable position, size, color, and opacity
• Password protect PDFs with 128-bit or 256-bit encryption
• Remove password protection from PDFs
• Set granular document permissions

Universal File Converter Features:
• LibreOffice: DOCX, PDF, ODT, RTF, TXT, HTML, XLSX, PPTX conversions
• ImageMagick: Image format conversions with quality, DPI, resize, compression options
• FFmpeg: Video/audio conversions with codec, bitrate, preset, framerate options
• Pandoc: Document markup conversions with advanced options
• Batch folder processing with recursive subfolder support
• 100% offline, open-source, no API keys required

Technical Implementation:
• Uses pdf-lib v1.17.1 for all PDF operations
• Full async/await implementation for optimal performance
• Comprehensive error handling and user feedback
• Progress indicators for long-running operations
• Page range parsing and validation
• RGB color conversion for watermarks

Files modified:
• src/main.js: Added 500+ lines of PDF operation functions and IPC handlers
• src/renderer.js: Added 480+ lines of UI event handlers and dialog management
• src/index.html: Added 600+ lines of comprehensive UI dialogs
• CLAUDE.md: Updated documentation with v1.7.0 features
• package.json: Version bump to 1.7.0

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-11 11:22:53 +05:30
amitwhandClaude 17c32f0b7d Fix file association double-click rendering (v1.6.1)
Fixed issue where files opened via double-click were not rendering properly. Added proper wait for renderer load state before sending file data.

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-05 20:34:28 +05:30
amitwhandClaude b93129bc44 Version 1.6.0 - Enhanced Markdown Editor & ConvertAPI Integration
New Features:

Enhanced Markdown Toolbar

- Added strikethrough button

- Added code block button

- Added horizontal rule button

Fixed Find & Replace

- Fixed focus issue

- Visual highlighting with text selection

- Smart scroll to matches

Fixed Line Numbers

- Corrected line counting

- Added scroll synchronization

ConvertAPI Integration

- Cloud conversion support (200+ formats)

- Secure API key storage

- Real-time conversion status

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-05 20:26:47 +05:30
amitwhandClaude b23e60a704 Fix critical bugs: real-time preview, toolbar functions, and file opening
Version 1.5.7 - Bug Fix Release

Fixed Issues:
- Real-time preview updates: Preview pane now updates instantly while typing
- Toolbar markdown functions: All toolbar buttons now work correctly
  * Bold, Italic, Code, Link text wrapping
  * Heading, List, Quote line prefixes
  * Table insertion
- File opening: Fixed file loading via menu and double-click association
- Cross-platform path handling for Windows backslashes

Technical Changes:
- Added direct input event listeners to editor textareas
- Implemented wrapSelection() and insertAtLineStart() helper methods
- Fixed IPC communication between main and renderer processes
- Improved event delegation for multi-tab support

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-05 19:56:31 +05:30
amitwh c559b34f3e Fix build issues: correct icon file, add icon config, disable signing
- Replace corrupted icon.ico with icon-proper.ico
- Add missing icon configuration to package.json build settings
- Disable signAndEditExecutable to avoid signing certificate requirement
- Installer now builds properly at 86MB instead of 190KB
2025-09-22 00:54:17 +05:30
amitwh a780f2984a Bump version to 1.5.4 for DOCX export fix release 2025-09-22 00:41:05 +05:30
amitwh 0c9961d412 Fix DOCX export functionality
- Enhanced getPandocPath() to check common Windows installation locations
- Improved Pandoc path detection for AppData/Local/Pandoc installation
- Enhanced error reporting with more detailed feedback for export failures
- Added better logging for Pandoc command execution and output
- Fixed issue where DOCX exports would fail silently when Pandoc wasn't in PATH
- Now properly detects Pandoc in standard Windows installation locations
2025-09-22 00:40:27 +05:30
amitwh ed7a80f99e Bump version to 1.5.3 for bug fix release 2025-09-22 00:24:45 +05:30
amitwh 18b7d82610 Fix critical bugs: file loading, advanced export dialog, and XLSX export
- Add XLSX export functionality alongside CSV with proper menu option
- Fix advanced export dialog visibility with improved CSS and scroll behavior
- Verify file loading mechanism works correctly for double-click association
- Improve export dialog layout with better height and positioning
- Update export-spreadsheet IPC handler to support both CSV and XLSX formats
2025-09-22 00:24:00 +05:30
amitwh cd1f7ac37d v1.5.2: Remove custom icons, use default Electron icon
- Removed all custom icon references from build configuration
- Using default Electron icon for consistent, standard appearance
- Updated to version 1.5.2
- Rebuilt NSIS installers with default iconography
2025-09-22 00:03:13 +05:30
amitwh 7b8a94150a Merge windows branch with enhanced export functionality and CLI support
- Combined advanced export options with built-in fallbacks
- Integrated Windows context menu installation scripts
- Added CLI conversion functionality
- Enhanced error handling for pandoc availability
- Updated to version 1.5.0 with comprehensive feature set
- Resolved merge conflicts preserving all functionality
2025-09-21 23:01:52 +05:30
amitwh 2a12a1b034 Fix export functionality and improve Windows build
- Fixed export function issues with comprehensive pandoc detection
- Added built-in HTML and PDF export fallbacks (no pandoc required)
- Improved error handling with clear user messages
- Enhanced code quality with optional chaining and better error handling
- Fixed NSIS installer script issues for Windows build
- Added comprehensive logging and debugging for export process
- Created test files and documentation for export functionality
- Successfully builds Windows release with proper XLSX support

Resolves export failures and provides robust fallback mechanisms.
2025-09-21 22:56:23 +05:30
amitwh 2bc3989c00 Create GEMINI.md 2025-09-21 21:47:12 +05:30
amitwhandClaude f50ffe8ed2 Release v1.5.0: Enhanced Features and Open Source Compatibility
Major improvements including optional advanced export options, removed proprietary dependencies for better open-source compatibility, and comprehensive new features for enhanced user experience.

🔧 Export Functions & Advanced Options:
• Fixed export function issues after advanced options integration
• Added optional advanced export checkbox (unchecked by default)
• Clean UI separation between simple and advanced export workflows

🏗️ Open Source Compatibility:
• Removed bundled Pandoc binaries - requires system installation
• Replaced proprietary XLSX with open-source CSV export
• Eliminated licensing concerns with bundled dependencies

✨ Advanced User Experience Features:
• Auto-save system with visual indicators every 30 seconds
• Enhanced document statistics (lines, paragraphs, sentences, reading time)
• Recent files menu with persistent storage (last 10 files)
• Mathematical expression support with KaTeX rendering
• Improved export dialog with better user experience

📚 Updated documentation with new dependency requirements and features

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-15 16:36:23 +05:30
amitwhandClaude 5376bddc59 Release v1.4.0: Advanced Export Options and Batch Conversion
Major Features:
• Fixed file association loading issue with proper timing
• Advanced export options dialog with templates and metadata support
• Batch file conversion system with progress tracking
• Enhanced UI with professional modal dialogs

Technical Improvements:
• Fixed renderer initialization timing for file association
• Added comprehensive Pandoc options support (templates, metadata, variables)
• Implemented recursive folder processing for batch operations
• Enhanced error handling and user feedback systems
• Theme-aware styling for all new components

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-14 22:42:53 +05:30
amitwhandClaude 978e642f0c Update version to 1.4.0 with context menu integration
- Bump version to 1.4.0 for context menu feature release
- Add context menu integration to feature list in About dialog
- Include command-line interface in feature highlights

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-09 01:05:01 +05:30
amitwhandClaude 00749ac52c Add Windows Explorer context menu integration
- Add context menu entries for all supported file types
- Implement CLI interface with --convert and --convert-to commands
- Create installation/uninstallation scripts (registry, PowerShell, batch)
- Add NSIS installer integration for automatic context menu setup
- Support direct conversion from right-click menu
- Include comprehensive documentation and usage instructions

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-09 01:03:36 +05:30
amitwhandClaude d3b67b1388 Bump version to v1.3.7
- Updated package.json version to 1.3.7
- Updated version in About dialog to 1.3.7
- Prepared for new release with Linux packages

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-01 23:34:38 +05:30
amitwh 35310beccf Add Claude settings 2025-09-01 23:14:36 +05:30
amitwh e1f0aafa88 Update version to 1.3.3 and add font size adjustment features 2025-09-01 23:13:29 +05:30
amitwhandClaude aac496923e Add font size adjustment menu and fix theme styling
Features:
• Added Font Size menu in View with increase/decrease/reset options
• Keyboard shortcuts: Ctrl+Shift+Plus/Minus/0 for font adjustment
• Font size persists between sessions using localStorage
• Font sizes adjustable from 10px to 24px

Theme Fixes:
• Fixed missing Monokai theme styles for tabs and editor
• Added complete tab styling for Solarized theme
• Added complete tab styling for GitHub theme
• All themes now have consistent tab bar appearance

Other Changes:
• Updated CLAUDE.md with v1.3.x features documentation
• Version bumped to 1.3.4

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-01 21:41:28 +05:30
amitwhandClaude 256f944b88 Increase editor and preview font sizes to 15px
Enhanced font sizes for improved readability:
• Editor font size increased from 14px to 15px
• Preview font size set to 15px for both #preview and .preview-content
• Better visual experience across all themes and content types

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-01 21:30:57 +05:30
amitwh dbe57d2fad Fix v1.3.2: Restore proper preview text spacing and typography
- Restored ideal preview text spacing from earlier versions
- Extended all preview styles to work with new .preview-content class
- Added proper margins, padding, and line-height for readability
- Updated theme support for all preview elements across all themes
- Improved typography with balanced font size and spacing
- Fixed double padding issue with better container structure
- Enhanced readability with proper heading margins and paragraph spacing
- Updated to version 1.3.2 with improved preview typography
2025-09-01 21:24:40 +05:30
amitwh 9a45849003 Update README.md for v1.3.1 release 2025-09-01 21:08:29 +05:30
amitwh dfb603c2ea Fix v1.3.1: File associations and 50/50 pane layout
- Enhanced file association handling for double-clicking .md files
- Added proper file associations in package.json build config
- Fixed preview/source pane layout to be equally distributed 50/50
- Updated CSS for tab-content structure with proper flex layout
- Added theme support for new pane selectors
- Improved command line argument processing for file opening
- Updated version to 1.3.1 with file association feature
2025-09-01 21:05:01 +05:30
amitwh fda173d9a1 Merge branch 'master' into macos 2025-09-01 20:58:00 +05:30
amitwh ddababf284 Update README.md for v1.3.0 with tabbed interface and enhanced PDF export features 2025-09-01 20:54:47 +05:30
amitwh 376fa00b08 Merge branch 'master' into windows 2025-09-01 20:53:36 +05:30
amitwh 5cbcfa466d Merge branch 'master' into macos 2025-09-01 20:53:29 +05:30
amitwh 328451f88d Major v1.3.0 update: Fix PDF export, file associations, remove converter menu, and implement tabbed interface
- Enhanced PDF export with multiple LaTeX engine fallbacks
- Fixed file association and direct file opening from OS
- Removed redundant converter menu, moved import to File menu
- Implemented comprehensive tabbed interface for multiple files
- Added tab management with keyboard shortcuts (Ctrl+N, Ctrl+W, Ctrl+Tab)
- Enhanced UI with tab bar and improved navigation
- Updated to version 1.3.0 with new features
- Improved main process and renderer architecture for multi-file support
2025-09-01 20:53:17 +05:30
amitwh 1b10a39b15 Update to v1.2.1 with comprehensive editor enhancements 2025-09-01 20:36:57 +05:30
amitwh 7fe53b4b9c Merge master with comprehensive v1.2.0 editor enhancements 2025-09-01 20:29:29 +05:30
amitwh edb163eab4 Merge master with comprehensive v1.2.0 editor enhancements 2025-09-01 20:29:13 +05:30
amitwh 7131d1a38e Merge master with comprehensive v1.2.0 editor enhancements 2025-09-01 20:28:49 +05:30
amitwhandClaude 6d3813e5e9 Major v1.2.0 editor enhancements
- Add comprehensive Find & Replace with match highlighting
- Add toggleable line numbers with theme support
- Implement full undo/redo functionality with keyboard shortcuts
- Add smart auto-indentation for lists and code blocks
- Enhanced keyboard shortcuts for productivity
- Advanced tab handling for indentation/outdentation
- Updated About dialog with v1.2.0 and complete feature list
- Add Find & Replace to Edit menu
- Updated README.md with comprehensive feature documentation

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-01 20:26:58 +05:30
amitwh bfe362245d Update README.md with v1.2.0 features and remove CLAUDE.md 2025-09-01 20:08:14 +05:30
amitwh 0d21ddbf15 Update README.md with v1.2.0 features and remove CLAUDE.md 2025-09-01 20:07:47 +05:30
amitwh 7b5165bcb1 Update README.md with v1.2.0 features and remove CLAUDE.md 2025-09-01 20:07:13 +05:30
amitwh 5c5cffed83 Update README.md with v1.2.0 features and remove CLAUDE.md 2025-09-01 20:06:31 +05:30
amitwh becfec5ae6 Update About dialog to version 1.2.0 with new features list 2025-09-01 20:03:36 +05:30
amitwh bd38c5342d Update About dialog to version 1.2.0 with new features list 2025-09-01 20:03:08 +05:30
amitwh f3e829ca63 Update About dialog to version 1.2.0 with new features list 2025-09-01 20:02:44 +05:30
amitwhandClaude b0a96f680a Release v1.2.0: Major feature additions
- Add PowerPoint export (PPTX/ODP) with slide-level formatting
- Add comprehensive document conversion menu with import/export
- Add interactive table creation helper in markdown editor
- Update documentation with all new features and version history
- Improve menu organization for better user experience

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-01 19:54:19 +05:30
amitwh a6da95b057 Add spreadsheet export, update author info, rename to PanConverter
- Added Excel (XLS/XLSX) and ODS export functionality
- Updated author to Amit Haridas (amit.wh@gmail.com)
- Renamed app from 'Pan Converter' to 'PanConverter'
- Version bump to 1.1.0
2025-09-01 19:44:48 +05:30
477 changed files with 7787 additions and 108231 deletions
+33
View File
@@ -0,0 +1,33 @@
{
"permissions": {
"allow": [
"Bash(git checkout:*)",
"Bash(npm install)",
"Bash(npm run build:*)",
"Bash(rmdir:*)",
"Bash(powershell:*)",
"Bash(npx electron-builder:*)",
"Bash(dir dist)",
"Bash(git tag:*)",
"Bash(git push:*)",
"Bash(gh release create:*)",
"Bash(gh auth:*)",
"Bash(gh release delete:*)",
"Bash(gh release list:*)",
"Bash(gh release upload:*)",
"Bash(npm install:*)",
"Bash(npm uninstall:*)",
"Bash(git add:*)",
"Bash(git commit:*)",
"Bash(npm start)",
"Read(//h/**)",
"Bash(cd:*)",
"Bash(npm run build:win-unsigned:*)",
"Bash(dir:*)",
"Bash(git merge:*)",
"Bash(timeout:*)",
"Bash(findstr:*)"
],
"deny": []
}
}
+10
View File
@@ -0,0 +1,10 @@
name: New MCP server
version: 0.0.1
schema: v1
mcpServers:
- name: New MCP server
command: npx
args:
- -y
- <your-mcp-server>
env: {}
-9
View File
@@ -1,9 +0,0 @@
# Text artifacts that are hash-pinned must check out byte-identical everywhere
assets/fonts/FiraCode-LICENSE.txt -text
# Binaries: never normalize
*.ttf -text
*.woff -text
*.woff2 -text
*.png -text
*.ico -text
*.icns -text
-28
View File
@@ -1,28 +0,0 @@
name: CI
on:
push:
branches: [master]
pull_request:
branches: [master]
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Run tests
run: npm test
- name: Run linter
run: npm run lint
-196
View File
@@ -1,196 +0,0 @@
name: Release
on:
push:
tags: ['v*']
permissions:
contents: write
jobs:
build-linux:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Download external tools (pandoc)
run: node scripts/download-tools.js
- name: Bundle MarkItDown (optional, best effort)
# Freezes markitdown + Python into bin/linux/markitdown; failure is
# non-fatal — the build then ships without it and the app falls back
# to a system markitdown at runtime.
run: npm run bundle:markitdown
continue-on-error: true
- name: Run tests
run: npm test
- name: Build Linux packages
run: npm run build:linux-ci -- --publish=never
- name: Upload Linux artifacts
uses: actions/upload-artifact@v4
with:
name: linux-artifacts
path: |
dist/*.deb
dist/*.AppImage
dist/*.snap
dist/*.rpm
retention-days: 5
build-windows:
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Download external tools (pandoc)
run: node scripts/download-tools.js
- name: Bundle MarkItDown (optional, best effort)
# Windows runners ship python + venv; non-fatal on failure — the
# package then omits the bundled binary by design. We capture the
# log so a silent failure is visible in the GitHub Actions step UI
# instead of disappearing into stdout.
run: |
python -m pip install --upgrade pip wheel setuptools 2>&1 | tee bundle-pip.log
npm run bundle:markitdown 2>&1 | tee bundle-markitdown.log
if [ ! -f bin/win32/markitdown.exe ]; then
echo "::warning::bin/win32/markitdown.exe was not produced — see bundle-markitdown.log"
fi
continue-on-error: true
shell: bash
- name: Upload MarkItDown bundle logs (on failure)
if: failure()
uses: actions/upload-artifact@v4
with:
name: windows-bundle-logs
path: |
bundle-pip.log
bundle-markitdown.log
retention-days: 5
- name: Run tests
run: npm test
- name: Decode certificate (if available)
if: ${{ env.CSC_LINK_BASE64 != '' }}
shell: pwsh
env:
CSC_LINK_BASE64: ${{ secrets.CSC_LINK_BASE64 }}
run: |
$bytes = [Convert]::FromBase64String("$env:CSC_LINK_BASE64")
[IO.File]::WriteAllBytes("${{ github.workspace }}\code-signing-cert.pfx", $bytes)
echo "CERT_AVAILABLE=true" >> $env:GITHUB_ENV
- name: Build Windows packages (signed)
if: ${{ env.CERT_AVAILABLE == 'true' }}
env:
CSC_LINK: code-signing-cert.pfx
CSC_KEY_PASSWORD: ${{ secrets.CSC_KEY_PASSWORD }}
run: npm run build:win-signed -- --publish=never
- name: Build Windows packages (unsigned)
if: ${{ env.CERT_AVAILABLE != 'true' }}
env:
CSC_IDENTITY_AUTO_DISCOVERY: 'false'
run: npm run build:win-unsigned -- --publish=never
- name: Upload Windows artifacts
uses: actions/upload-artifact@v4
with:
name: windows-artifacts
path: |
dist/*.exe
dist/*.zip
retention-days: 5
build-macos:
runs-on: macos-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Download external tools (pandoc)
run: node scripts/download-tools.js
- name: Bundle MarkItDown (optional, best effort)
run: npm run bundle:markitdown
continue-on-error: true
- name: Run tests
run: npm test
- name: Build macOS packages
run: npm run build:mac -- --publish=never
- name: Upload macOS artifacts
uses: actions/upload-artifact@v4
with:
name: macos-artifacts
path: |
dist/*.dmg
dist/*.zip
retention-days: 5
release:
needs: [build-linux, build-windows, build-macos]
if: always()
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Download Linux artifacts
uses: actions/download-artifact@v4
continue-on-error: true
with:
name: linux-artifacts
path: dist
- name: Download Windows artifacts
uses: actions/download-artifact@v4
continue-on-error: true
with:
name: windows-artifacts
path: dist
- name: Download macOS artifacts
uses: actions/download-artifact@v4
continue-on-error: true
with:
name: macos-artifacts
path: dist
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
generate_release_notes: true
files: dist/*
+2 -32
View File
@@ -8,41 +8,11 @@ Thumbs.db
*.swp *.swp
*.swo *.swo
*~ *~
.vscode/* .vscode/
!.vscode/launch.json
.idea/ .idea/
*.iml *.iml
out/ out/
.cache/ .cache/
.npm/ .npm/
.electron/ .electron/
# package-lock.json is intentionally tracked for reproducible CI builds package-lock.json
# Downloaded tool binaries (fetched at build time via scripts/download-tools.js)
bin/
# Code signing certificates — never commit private keys
*.pfx
*.p12
# Screenshots and temp files
*.png.bak
Screen.png
dark.png
light.png
pdf.png
uvmodal.png
nul
*.tmp
# Development screenshots
pdf\ modal.png
# Claude/AI development files
.claude/
CLAUDE.md
agents.md
coverage/
# Superpowers brainstorm artifacts
.superpowers/
-11
View File
@@ -1,11 +0,0 @@
{
"semi": true,
"singleQuote": true,
"tabWidth": 2,
"useTabs": false,
"trailingComma": "es5",
"bracketSpacing": true,
"arrowParens": "always",
"printWidth": 100,
"endOfLine": "auto"
}
@@ -1,469 +0,0 @@
# Security Assessment Report: MarkdownConverter v4.0.0
**Assessment Date:** 2026-03-15
**Application:** MarkdownConverter - Electron-based Markdown editor and document converter
**Target Version:** 4.0.0
**Assessor:** Security Audit Agent
---
## Executive Summary
This assessment identified **10 security findings** ranging from **Critical to Low severity**. The most significant concerns involve insecure Electron security configuration that could allow XSS attacks to escalate to full system access, arbitrary code execution via the REPL feature, and missing input validation on file operations.
| Severity | Count |
|----------|-------|
| Critical | 2 |
| High | 3 |
| Medium | 3 |
| Low | 2 |
---
## Vulnerability Findings
### CVE-MC-001: Insecure Electron Security Configuration (Critical)
**CVSS 3.1 Score: 9.6 (Critical)**
**CWE-265: CWE-1021: Improper Restriction of Renderers**
**Location:** `src/main.js` (lines 328-332)
```javascript
webPreferences: {
nodeIntegration: true,
contextIsolation: false,
spellcheck: true
},
```
**Description:**
The main application window has `nodeIntegration: true` and `contextIsolation: false`, which is the most insecure Electron configuration. This allows the renderer process direct access to Node.js APIs, meaning any XSS vulnerability in the markdown rendering or external content could lead to full system compromise.
**Exploitability:**
- An attacker who can inject malicious JavaScript (via markdown files, XSS in preview, or compromised dependencies) gains immediate access to:
- Full file system read/write via `fs` module
- Command execution via `child_process`
- Network access via `net` module
- All system resources
**Attack Scenario:**
1. User opens a malicious markdown file containing embedded JavaScript
2. The JavaScript executes in the renderer with full Node.js access
3. Attacker can read sensitive files, execute commands, exfiltrate data
**Remediation:**
```javascript
webPreferences: {
nodeIntegration: false,
contextIsolation: true,
sandbox: true,
preload: path.join(__dirname, 'preload.js')
}
```
**Note:** The preload.js file already implements a secure IPC bridge but it is not being utilized for the main window.
---
### CVE-MC-002: Arbitrary Code Execution via REPL Feature (Critical)
**CVSS 3.1 Score: 9.3 (Critical)**
**CWE-94: Improper Control of Generation of Code ('Code Injection')**
**Location:** `src/main.js` (lines 4369-4396)
**Description:**
The `execute-code` IPC handler allows execution of arbitrary Python and Bash scripts through the REPL panel. While JavaScript execution appears to have been removed or limited, Python and Bash commands are executed via `execFile` with user-supplied code.
**Vulnerable Code Pattern:**
```javascript
ipcMain.handle('execute-code', async (event, { code, language }) => {
// ...
if (language === 'python' || language === 'py') {
cmd = 'python';
args = ['-c', code];
}
// ...
execFile(cmd, args, { timeout }, (err, stdout, stderr) => {
// ...
});
});
```
**Exploitability:**
- Users can be tricked into running malicious code blocks
- Markdown files can contain executable code blocks with "Run" buttons
- No sandboxing or permission restrictions on executed code
**Attack Scenario:**
1. Attacker creates markdown file with malicious Python code block
2. User clicks "Run" button in preview
3. Python code executes with user's full permissions
4. Attacker gains code execution on victim's machine
**Remediation:**
- Remove arbitrary code execution feature entirely, OR
- Implement strict sandboxing (Docker, VM, or restricted Python environment)
- Add user confirmation dialogs with clear warnings
- Execute in isolated environment with no filesystem/network access
- Implement allowlist of safe operations
---
### CVE-MC-003: Potential XSS in Markdown Rendering (High)
**CVSS 3.1 Score: 8.0 (High)**
**CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')**
**Location:** `src/renderer.js` (lines 387-419)
**Description:**
While DOMPurify is used to sanitize HTML, several extensions to marked.js may bypass sanitization:
1. **Custom Admonition Extension (lines 51-77):**
```javascript
marked.use({
extensions: [{
name: 'admonition',
// ...
renderer(token) {
const inner = this.parser.parse(token.text);
return `<div class="admonition admonition-${token.admonitionType}">
<div class="admonition-title">${icon} ${token.admonitionType...}</div>
<div class="admonition-content">${inner}</div>
</div>`;
}
}]
});
```
2. **innerHTML Assignments (line 419):**
```javascript
preview.innerHTML = sanitizedHtml;
```
**Exploitability:**
- Combined with CVE-MC-001, XSS leads to full system compromise
- Custom markdown extensions may not be properly sanitized
- Admonition type is directly interpolated into HTML without escaping
**Remediation:**
- Ensure all custom markdown extensions escape user input
- Add Content Security Policy that blocks inline scripts
- Use `textContent` instead of `innerHTML` where possible
- Audit all custom marked.js extensions for XSS vectors
---
### CVE-MC-004: Missing Path Traversal Protection (High)
**CVSS 3.1 Score: 7.8 (High)**
**CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')**
**Location:** `src/main.js` (lines 4241-4281)
**Description:**
The `list-directory` and `open-file-path` IPC handlers accept arbitrary file paths without validation:
```javascript
ipcMain.handle('list-directory', async (event, dirPath) => {
try {
if (!dirPath) { /* dialog */ }
// No path validation - accepts any path
const entries = fs.readdirSync(dirPath, { withFileTypes: true });
// ...
}
});
ipcMain.on('open-file-path', (event, filePath) => {
// No path validation
if (!fs.existsSync(filePath)) return;
const content = fs.readFileSync(filePath, 'utf-8');
mainWindow.webContents.send('file-opened', { path: filePath, content });
});
```
**Exploitability:**
- Malicious renderer code can read any file on the system
- No restriction to a sandbox directory
- Combined with XSS, attacker can exfiltrate sensitive files
**Remediation:**
```javascript
const ALLOWED_DIRECTORIES = [app.getPath('documents'), app.getPath('desktop')];
function isPathAllowed(filePath) {
const resolved = path.resolve(filePath);
return ALLOWED_DIRECTORIES.some(dir => resolved.startsWith(dir));
}
```
---
### CVE-MC-005: Weak Content Security Policy (High)
**CVSS 3.1 Score: 7.5 (High)**
**CWE-1021: Improper Restriction of Renderers**
**Location:** `src/index.html` (line 5)
```html
<meta http-equiv="Content-Security-Policy" content="default-src 'self';
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net;
style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com;
img-src 'self' data: blob: file:;
font-src 'self' data:;
connect-src 'self' https://www.plantuml.com;">
```
**Description:**
The CSP contains several security weaknesses:
1. **`'unsafe-inline'` in script-src** - Allows inline script injection
2. **`'unsafe-eval'` in script-src** - Allows `eval()` and similar functions
3. **`https://cdn.jsdelivr.net`** - Allows scripts from external CDN (supply chain risk)
4. **`file:` in img-src** - Allows loading local files as images (potential information disclosure)
**Exploitability:**
- XSS attacks can execute arbitrary scripts
- External CDN compromise could inject malicious code
- `eval()` enables dynamic code execution
**Remediation:**
- Remove `'unsafe-inline'` and `'unsafe-eval'`
- Use nonces or hashes for inline scripts
- Remove external CDNs or use Subresource Integrity (SRI)
- Remove `file:` from img-src
---
### CVE-MC-006: Insecure Window Configuration for PDF Export (Medium)
**CVSS 3.1 Score: 6.5 (Medium)**
**CWE-1021: Improper Restriction of Renderers**
**Location:** `src/main.js` (lines 2579-2585)
```javascript
const pdfWindow = new BrowserWindow({
show: false,
webPreferences: {
nodeIntegration: true,
contextIsolation: false
}
});
```
**Description:**
Hidden windows created for PDF export also have insecure configurations, allowing potential privilege escalation.
**Remediation:**
```javascript
webPreferences: {
nodeIntegration: false,
contextIsolation: true,
sandbox: true
}
```
---
### CVE-MC-007: PlantUML Server Data Exfiltration (Medium)
**CVSS 3.1 Score: 5.3 (Medium)**
**CWE-359: Exposure of Private Information**
**Location:** `src/renderer.js` (lines 470-487)
```javascript
const plantumlBlocks = preview.querySelectorAll('pre code.language-plantuml');
plantumlBlocks.forEach((block) => {
const code = block.textContent;
// ...
const encoded = plantumlEncode(code);
const img = document.createElement('img');
img.src = `https://www.plantuml.com/plantuml/svg/${encoded}`;
// ...
});
```
**Description:**
PlantUML diagram content is sent to an external server (plantuml.com) for rendering. This could leak sensitive information contained in diagrams.
**Exploitability:**
- Diagrams containing proprietary information, system architecture, or internal processes are sent to third-party servers
- No user consent or notification before external data transmission
**Remediation:**
- Use local PlantUML rendering with Java
- Add user warning before sending data to external service
- Implement opt-in for external rendering
---
### CVE-MC-008: Inconsistent Security Settings Across Windows (Medium)
**CVSS 3.1 Score: 5.5 (Medium)**
**CWE-1021: Improper Restriction of Renderers**
**Description:**
Security settings are inconsistent across different windows:
| Window | nodeIntegration | contextIsolation | Security |
|--------|-----------------|------------------|----------|
| Main Window | true | false | Insecure |
| About Dialog | false | true | Secure |
| Dependencies Dialog | false | true | Secure |
| ASCII Generator | false | true | Secure |
| Table Generator | false | true | Secure |
| PDF Export Window | true | false | Insecure |
| Hidden Conversion Window | true | false | Insecure |
**Remediation:**
Apply secure configuration (`nodeIntegration: false`, `contextIsolation: true`) consistently across all windows.
---
### CVE-MC-009: Command Execution via External Tools (Low)
**CVSS 3.1 Score: 4.4 (Low)**
**CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')**
**Location:** `src/main.js` (lines 1915-1972)
**Description:**
While the application uses `execFile` instead of `exec` (good practice), external tools (Pandoc, LibreOffice, FFmpeg, ImageMagick) are invoked with file paths that could potentially be manipulated.
**Positive Finding:**
The code correctly uses `execFile` with argument arrays instead of shell commands, mitigating most command injection vectors.
**Remaining Risk:**
- File paths are not validated against malicious names
- Special characters in filenames could cause issues with external tools
**Remediation:**
- Validate file paths before passing to external tools
- Sanitize filenames of special characters
---
### CVE-MC-010: Missing Dependency Version Pinning (Low)
**CVSS 3.1 Score: 3.5 (Low)**
**CWE-1035: Using Components with Known Vulnerabilities**
**Location:** `package.json`
**Description:**
Dependencies use `^` version ranges which could allow automatic updates to versions with vulnerabilities:
```json
"dependencies": {
"marked": "^17.0.3",
"dompurify": "^3.3.1",
"mermaid": "^11.12.3",
// ...
}
```
**Remediation:**
- Pin exact versions in production
- Use lockfile (package-lock.json)
- Implement dependency scanning in CI/CD pipeline
---
## Attack Surface Map
```
┌─────────────────────────────────────────────────────────────────┐
│ EXTERNAL ATTACK SURFACE │
├─────────────────────────────────────────────────────────────────┤
│ Markdown Files (.md) ─────► XSS via Preview Rendering │
│ Code Blocks ─────► Arbitrary Code Execution │
│ PlantUML Diagrams ─────► Data Exfiltration │
│ External CDNs ─────► Supply Chain Attacks │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ RENDERER PROCESS (Insecure) │
├─────────────────────────────────────────────────────────────────┤
│ nodeIntegration: true ─────► Direct Node.js Access │
│ contextIsolation: false ─────► Prototype Pollution Risk │
│ DOMPurify Sanitization ─────► May be bypassed via extensions │
│ Custom Marked Extensions ────► XSS Vectors │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ IPC BRIDGE (Preload.js) │
├─────────────────────────────────────────────────────────────────┤
│ Channel Whitelisting ─────► Good Practice │
│ Not Used for Main Window ────► Security Bypassed │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ MAIN PROCESS (Full Privileges) │
├─────────────────────────────────────────────────────────────────┤
│ File Operations ─────► No Path Validation │
│ Code Execution ─────► Python/Bash via REPL │
│ External Tools ─────► Pandoc, FFmpeg, LibreOffice │
│ PDF Operations ─────► Merge, Encrypt, Decrypt │
└─────────────────────────────────────────────────────────────────┘
```
---
## Positive Security Findings
1. **Preload.js Implementation:** A secure IPC bridge with channel whitelisting is implemented
2. **DOMPurify Usage:** HTML sanitization is applied to markdown output
3. **execFile Usage:** External commands use `execFile` instead of `exec`
4. **File Size Limits:** 50MB maximum file size is enforced
5. **Rate Limiting:** Conversion operations have rate limiting (2 second minimum interval)
6. **Error Message Sanitization:** Absolute paths are stripped from error messages
---
## Prioritized Remediation Roadmap
### Phase 1 - Critical (Immediate)
1. Set `nodeIntegration: false` and `contextIsolation: true` for main window
2. Remove or sandbox the code execution (REPL) feature
3. Implement proper preload.js usage for all windows
### Phase 2 - High Priority (1-2 Weeks)
4. Add path traversal protection to file operations
5. Strengthen Content Security Policy
6. Audit and fix custom markdown extensions for XSS
### Phase 3 - Medium Priority (1 Month)
7. Implement consistent security settings across all windows
8. Add local PlantUML rendering option
9. Implement dependency scanning in CI/CD
### Phase 4 - Low Priority (Ongoing)
10. Pin dependency versions
11. Add security headers to all generated HTML
12. Implement security logging and monitoring
---
## Compliance Considerations
- **OWASP Top 10 2021:** A03:2021 - Injection, A05:2021 - Security Misconfiguration
- **OWASP ASVS:** V12 - File Handling, V13 - API Security
- **NIST CSF:** PR.AC - Access Control, PR.DS - Data Security
---
## Conclusion
The MarkdownConverter application has significant security vulnerabilities that could allow an attacker to execute arbitrary code, access sensitive files, and compromise the user's system. The most critical issue is the insecure Electron configuration combined with XSS attack vectors in the markdown rendering pipeline.
**Overall Security Rating: HIGH RISK**
The positive finding is that much of the security infrastructure (preload.js, DOMPurify) is already in place but not properly utilized. With focused remediation effort, the application can achieve a much stronger security posture.
-215
View File
@@ -1,215 +0,0 @@
# STRIDE Threat Model - MarkdownConverter v4.0.0
**Analysis Date:** 2026-03-15
**Methodology:** STRIDE + MITRE ATT&CK
**Overall Risk Score:** 7.8 (HIGH)
---
## Executive Summary
The analysis identified **10 vulnerabilities** with a combined risk score of **7.8 (HIGH)**. The most critical issues enable complete system compromise through XSS-to-RCE attack chains.
---
## Critical Findings
| Priority | CVE | Vulnerability | CVSS | Impact |
|----------|-----|---------------|------|--------|
| P0 | CVE-MC-001 | Insecure Electron Config (`nodeIntegration: true`, `contextIsolation: false`) | 9.6 | Complete system compromise |
| P0 | CVE-MC-002 | Arbitrary code execution via REPL feature | 9.3 | Remote code execution |
| P1 | CVE-MC-003 | XSS in markdown rendering | 8.0 | Session hijacking, RCE chain |
| P1 | CVE-MC-004 | Path traversal vulnerability | 7.8 | Arbitrary file write |
| P1 | CVE-MC-005 | Weak Content Security Policy | 7.5 | XSS enablement |
| P2 | CVE-MC-006 | Insecure window config for PDF export | 6.5 | Privilege escalation |
| P2 | CVE-MC-007 | PlantUML server data exfiltration | 5.3 | Information disclosure |
| P2 | CVE-MC-008 | Inconsistent security settings | 5.5 | Configuration weakness |
| P3 | CVE-MC-009 | Command execution via external tools | 4.4 | Command injection risk |
| P3 | CVE-MC-010 | Missing dependency version pinning | 3.5 | Supply chain risk |
---
## Key Attack Vectors
### 1. XSS to RCE Chain (Critical)
```
Malicious Markdown File
│
▼
XSS in Preview (CVE-MC-003)
│
▼
nodeIntegration: true (CVE-MC-001)
│
▼
Full Node.js Access
│
▼
Complete System Compromise
```
### 2. REPL Code Execution (Critical)
```
Code Block in Markdown
│
▼
User clicks "Run"
│
▼
REPL executes Python/Bash (CVE-MC-002)
│
▼
Arbitrary Code Execution
```
### 3. Data Exfiltration (Medium)
```
PlantUML Diagram Content
│
▼
Sent to www.plantuml.com (CVE-MC-007)
│
▼
Sensitive Architecture Leaked
```
---
## STRIDE Analysis
### S - Spoofing
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| S1 | Attacker spoofs markdown file origin | Medium | High | High |
| S2 | Malicious code pretends to be safe | High | Critical | Critical |
### T - Tampering
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| T1 | XSS modifies local files | High | Critical | Critical |
| T2 | Conversion output tampered | Medium | Medium | Medium |
### R - Repudiation
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| R1 | No audit trail for operations | Low | Low | Low |
### I - Information Disclosure
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| I1 | XSS exposes file system | High | Critical | Critical |
| I2 | PlantUML content leaked | Medium | Medium | Medium |
| I3 | Error messages reveal paths | Low | Low | Low |
### D - Denial of Service
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| D1 | Malicious code crashes app | Medium | Medium | Medium |
| D2 | Large file exhausts resources | Low | Low | Low |
### E - Elevation of Privilege
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| E1 | XSS → nodeIntegration → System | High | Critical | Critical |
| E2 | REPL code execution | High | Critical | Critical |
---
## MITRE ATT&CK Mapping
| Technique | ID | Applicability |
|-----------|-----|---------------|
| User Execution | T1204.002 | Malicious markdown file |
| Command and Scripting Interpreter | T1059.007 | JavaScript via nodeIntegration |
| Command and Scripting Interpreter | T1059.006 | Python via REPL |
| Command and Scripting Interpreter | T1059.004 | Bash via REPL |
| Exploit Public-Facing Application | T1190 | XSS in preview |
| Data Exfiltration Over Web Service | T1043 | PlantUML server |
| File and Directory Discovery | T1083 | Path traversal |
---
## Trust Boundaries
```
┌─────────────────────────────────────────────────────────────────────┐
│ TRUST BOUNDARY MAP │
├─────────────────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────┐ ┌─────────────────────────────────────┐ │
│ │ USER │ ──────► │ APPLICATION │ │
│ │ (Untrusted) │ │ ┌───────────┐ ┌───────────────┐ │ │
│ └─────────────┘ │ │ Renderer │ │ Main Process │ │ │
│ │ │ (Sandbox) │ │ (Privileged) │ │ │
│ │ └─────┬─────┘ └───────┬───────┘ │ │
│ │ │ IPC │ │ │
│ │ ▼ ▼ │ │
│ │ ┌─────────────────────────────┐ │ │
│ │ │ File System │ │ │
│ │ └─────────────────────────────┘ │ │
│ └─────────────────────────────────────┘ │
│ │ │
│ ▼ │
│ ┌─────────────────────────────────────────────────────────────┐ │
│ │ EXTERNAL SERVICES │ │
│ │ • PlantUML Server (www.plantuml.com) │ │
│ │ • CDN (cdn.jsdelivr.net, cdnjs.cloudflare.com) [REMOVED] │ │
│ │ • External Tools (Pandoc, FFmpeg, LibreOffice) │ │
│ └─────────────────────────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────┘
```
---
## Business Impact Analysis
### Successful Attack Consequences
| Impact Category | Estimate |
|-----------------|----------|
| Data breach costs | $500,000 - $5,000,000+ |
| Regulatory fines (GDPR) | Up to 4% annual revenue |
| Reputation damage | Incalculable |
| Business disruption | Hours to days |
### Affected Assets
- User documents and files
- System credentials
- Proprietary information in diagrams
- Application integrity
---
## Remediation Priority
### P0 - Immediate (24-48 hours)
1. **CVE-MC-001**: Set `nodeIntegration: false`, `contextIsolation: true`
2. **CVE-MC-002**: Remove or sandbox REPL code execution
### P1 - Short-term (1-2 weeks)
3. **CVE-MC-003**: Audit markdown extensions for XSS
4. **CVE-MC-004**: Add path validation (✅ COMPLETED)
5. **CVE-MC-005**: Strengthen CSP (✅ COMPLETED)
### P2 - Medium-term (1 month)
6. **CVE-MC-006**: Consistent window security settings
7. **CVE-MC-007**: Add local PlantUML option or warning
8. **CVE-MC-008**: Audit all BrowserWindow configurations
### P3 - Long-term
9. **CVE-MC-009**: Validate filenames for external tools
10. **CVE-MC-010**: Pin dependency versions, add scanning
---
## Conclusion
The MarkdownConverter application has a **HIGH RISK** threat profile due to the combination of:
- Untrusted content rendering (markdown preview)
- Direct system access (nodeIntegration)
- Code execution capability (REPL)
**Immediate action required on P0 items to reduce attack surface.**
The fixes applied in this session (CSP, path traversal, UI accessibility) have reduced the risk profile, but the critical nodeIntegration issue requires significant refactoring.
-27
View File
@@ -1,27 +0,0 @@
{
"target": "MarkdownConverter Electron Application",
"status": "in_progress",
"depth": "comprehensive",
"compliance_frameworks": ["owasp"],
"current_step": 3,
"current_phase": 1,
"completed_steps": ["vulnerability-scan", "threat-modeling"],
"files_created": ["01-vulnerability-scan.md", "02-threat-model.md"],
"started_at": "2026-03-15T00:09:00.000Z",
"last_updated": "2026-03-15T00:25:00.000Z",
"findings_summary": {
"critical": 2,
"high": 3,
"medium": 3,
"low": 2,
"total": 10
},
"fixes_applied": {
"csp_external_cdns_removed": true,
"path_traversal_protection_added": true,
"aria_labels_added": true,
"focus_visible_styles_added": true,
"tab_close_button_resized": true,
"duplicate_font_size_fixed": true
}
}
@@ -1,522 +0,0 @@
# Comprehensive UI Design Review - MarkdownConverter Electron Application
## Executive Summary
This review covers the UI design of the MarkdownConverter Electron application, analyzing visual design, usability, code quality, and performance across all UI files. The application has a solid foundation but has several areas requiring attention.
---
## 1. Visual Design Review
### 1.1 Spacing & Layout Consistency
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Inconsistent padding values across files | Multiple CSS files | Standardize to 4px/8px base scale |
| **Major** | Multiple reset declarations | `styles.css:1-5`, `styles-modern.css:42-47` | Consolidate resets into single file |
| **Minor** | Tab padding varies between themes | `styles.css:36`, `styles-modern.css:101` | Use CSS variables for consistent padding |
| **Minor** | Container padding inconsistency | `styles.css:17-21`, `styles-modern.css:63-69` | Define single container style |
**Code Example - Duplicate Reset:**
```css
/* styles.css:1-5 */
* {
margin: 0;
padding: 0;
box-sizing: border-box;
}
/* styles-modern.css:42-47 - DUPLICATE */
* {
margin: 0;
padding: 0;
box-sizing: border-box;
}
```
**Fix Recommendation:**
```css
/* Create a single base.css or remove from styles-modern.css */
/* Use CSS variables for spacing scale */
:root {
--space-1: 4px;
--space-2: 8px;
--space-3: 12px;
--space-4: 16px;
--space-5: 24px;
--space-6: 32px;
}
```
### 1.2 Typography Consistency
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Font-family declared multiple times with different fallbacks | `styles.css:8`, `styles-modern.css:50`, `styles-concreteinfo.css:32` | Standardize font stack |
| **Major** | Duplicate font-size declarations | `styles.css:228-230` | Remove duplicate |
| **Minor** | Inconsistent line-height values | Multiple files | Create type scale variables |
**Code Example - Duplicate font-size:**
```css
/* styles.css:226-230 */
.preview-content {
max-width: none;
margin: 0;
padding: 20px 24px 24px 24px;
line-height: 1.6;
font-size: 15px;
font-size: 14px; /* DUPLICATE - overwrites previous */
}
```
**Fix Recommendation:**
```css
/* styles.css - Remove duplicate */
.preview-content {
font-size: 14px; /* Keep only one */
line-height: 1.6;
}
```
### 1.3 Color Usage and Contrast Accessibility
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Critical** | Hardcoded colors instead of CSS variables | `styles.css:27-29`, `styles.css:37-38`, etc. | Use CSS custom properties |
| **Major** | Inconsistent gray scale definitions | Multiple files define different grays | Consolidate to single palette |
| **Minor** | Some contrast ratios may be insufficient | Status bar text colors | Verify WCAG 2.1 AA compliance |
**Code Example - Hardcoded colors:**
```css
/* styles.css:27-29 */
.tab-bar {
background: #f0f0f0; /* Should use var(--gray-100) */
border-bottom: 1px solid #ddd; /* Should use var(--gray-300) */
}
```
**Fix Recommendation:**
```css
/* Use the existing palette from styles-modern.css */
.tab-bar {
background: var(--gray-100, #f3f4f6);
border-bottom: 1px solid var(--gray-300, #d1d5db);
}
```
### 1.4 Dark Mode Support Quality
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Dark theme selectors inconsistent | `styles.css` uses `body.theme-dark`, `styles-sidebar.css:108` uses `body[class*="dark"]` | Standardize selector pattern |
| **Minor** | Missing dark theme support for some components | `.breadcrumb-bar`, command palette | Add dark mode variants |
| **Suggestion** | Repetitive dark theme declarations | `styles-concreteinfo.css:362-425` | Use CSS custom properties for theming |
**Code Example - Inconsistent selectors:**
```css
/* styles.css */
body.theme-dark .tab-bar { ... }
/* styles-sidebar.css */
body[class*="dark"] .sidebar-icons { ... }
```
**Fix Recommendation:**
```css
/* Choose one pattern and apply consistently */
/* Option 1: Class-based (recommended) */
body.theme-dark .tab-bar,
body.theme-dark .sidebar-icons { ... }
/* Option 2: Attribute-based */
body[data-theme="dark"] .tab-bar { ... }
```
---
## 2. Usability Review
### 2.1 Clickable/Tappable Areas
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Critical** | Tab close button too small (16x16px) | `styles.css:62-77` | Increase to minimum 24x24px |
| **Major** | Sidebar icons at minimum size | `styles-sidebar.css:35-47` (36x36px) | Consider 40-44px for better touch |
| **Minor** | Toolbar buttons at edge of minimum | `styles.css:120-131` (32x32px) | Acceptable for mouse, small for touch |
**Code Example - Small close button:**
```css
/* styles.css:62-77 */
.tab-close {
width: 16px; /* TOO SMALL - below 24px minimum */
height: 16px; /* TOO SMALL */
}
```
**Fix Recommendation:**
```css
.tab-close {
width: 24px;
height: 24px;
border-radius: 4px;
}
/* Add touch-friendly hit area */
.tab-close::before {
content: '';
position: absolute;
top: -4px;
left: -4px;
right: -4px;
bottom: -4px;
}
```
### 2.2 Hover/Focus States
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Critical** | Missing focus-visible styles | All interactive elements | Add :focus-visible for keyboard navigation |
| **Major** | No focus indicators on toolbar buttons | `styles.css:133-140` | Add visible focus ring |
| **Minor** | Inconsistent hover transitions | Various components | Standardize transition duration |
**Code Example - Missing focus styles:**
```css
/* styles.css:120-131 - No focus state */
.toolbar button {
/* ... no focus style */
}
.toolbar button:hover {
background: #e0e0e0;
border-color: #ccc;
}
```
**Fix Recommendation:**
```css
.toolbar button:focus-visible {
outline: 2px solid var(--primary-dark, #5661b3);
outline-offset: 2px;
}
.toolbar button:hover {
background: #e0e0e0;
border-color: #ccc;
}
```
### 2.3 Loading and Error State Handling
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Generic error message without styling | `renderer.js:384-386`, `renderer.js:508-511` | Create styled error components |
| **Minor** | No loading indicators for async operations | Sidebar panels | Add skeleton loaders or spinners |
| **Minor** | `git-loading` class exists but minimal styling | `styles-sidebar.css:227` | Enhance with animation |
**Code Example - Plain error display:**
```javascript
// renderer.js:384-386
preview.innerHTML = '<p style="color: red; padding: 20px;">Error: Required libraries...';
// Inline styles should be in CSS
```
**Fix Recommendation:**
```css
/* Add to styles.css */
.preview-error {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
padding: 40px 20px;
color: var(--ci-danger, #dc3545);
text-align: center;
}
.preview-error-icon {
font-size: 48px;
margin-bottom: 16px;
}
```
### 2.4 Accessibility (ARIA, Semantic HTML)
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Critical** | Buttons without accessible labels | `index.html:31` (tab close), `index.html:33` (new tab) | Add aria-label |
| **Critical** | SVG icons lack aria-hidden | All toolbar buttons | Add aria-hidden="true" |
| **Major** | Missing role attributes on tabs | `index.html:29-33` | Add role="tablist", role="tab" |
| **Major** | No skip links | `index.html` | Add skip to main content link |
| **Minor** | Dialog missing aria-modal | Export dialogs | Add aria-modal="true" |
**Code Example - Missing accessibility attributes:**
```html
<!-- index.html:31 - Current -->
<button class="tab-close" title="Close tab">x</button>
<!-- index.html:33 - Current -->
<button class="new-tab-button" id="new-tab-btn" title="New tab">+</button>
```
**Fix Recommendation:**
```html
<!-- Improved with ARIA -->
<div class="tab-bar" id="tab-bar" role="tablist" aria-label="Document tabs">
<div class="tab active" data-tab-id="1" role="tab" aria-selected="true" aria-controls="tab-content-1">
<span class="tab-title">Untitled</span>
<button class="tab-close" aria-label="Close tab" title="Close tab">×</button>
</div>
<button class="new-tab-button" id="new-tab-btn" aria-label="Create new tab" title="New tab">+</button>
</div>
<!-- SVG icons should have aria-hidden -->
<button id="btn-bold" title="Bold (Ctrl+B)" aria-label="Bold">
<svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" aria-hidden="true">
...
</svg>
</button>
```
### 2.5 Keyboard Navigation
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Tab order may skip sidebar icons | Sidebar panel | Verify logical tab order |
| **Minor** | No escape key handling for dialogs | Export dialogs | Add escape to close |
| **Minor** | Find dialog lacks full keyboard support | `renderer.js:804-866` | Add Ctrl+F shortcut hint |
---
## 3. Code Quality Review
### 3.1 CSS Organization & Naming
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | No clear CSS architecture | All CSS files | Adopt BEM or similar methodology |
| **Major** | Overly generic class names | `.pane`, `.tab`, `.container` | Use more specific naming |
| **Minor** | Mixed naming conventions | camelCase (`tabBar`), kebab-case (`tab-bar`) | Standardize to kebab-case |
| **Minor** | Magic numbers | Various pixel values | Replace with spacing variables |
### 3.2 CSS Specificity Issues
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Excessive use of `!important` | `styles.css:14` | Restructure to avoid |
| **Major** | Deep selector nesting | Dark theme selectors | Flatten and use CSS variables |
| **Minor** | ID selectors for styling | `styles.css:233-247` | Prefer class selectors |
**Code Example - Problematic specificity:**
```css
/* styles.css:14 - Avoid !important */
.hidden {
display: none !important;
}
/* styles.css:397-431 - Deep nesting */
body.theme-dark #preview h1,
body.theme-dark [id^="preview-"] h1,
body.theme-dark .preview-content h1 {
color: #c9d1d9;
border-bottom-color: #21262d;
}
```
**Fix Recommendation:**
```css
/* Use utility class pattern */
[hidden] { display: none; }
/* Use CSS custom properties for theming */
.preview-content h1 {
color: var(--text-primary);
border-bottom-color: var(--border-color);
}
/* Theme applies variables */
body.theme-dark {
--text-primary: #c9d1d9;
--border-color: #21262d;
}
```
### 3.3 Reusable Style Definitions
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Repeated button styles | Multiple files | Create button component classes |
| **Major** | Dialog styles duplicated | Export, batch, print preview dialogs | Create modal component |
| **Minor** | Similar form field styles scattered | Export dialog inputs | Create form component |
**Code Example - Duplicated button styles:**
```css
/* styles.css */
.toolbar button { /* button styles */ }
.tab-close { /* button styles */ }
.new-tab-button { /* button styles */ }
#export-dialog-close { /* button styles */ }
/* styles-sidebar.css */
.sidebar-icon { /* similar button styles */ }
.sidebar-panel-close { /* similar button styles */ }
```
**Fix Recommendation:**
```css
/* Create button component system */
.btn {
display: inline-flex;
align-items: center;
justify-content: center;
border: none;
cursor: pointer;
transition: all var(--transition-fast);
}
.btn--icon {
width: 32px;
height: 32px;
border-radius: var(--radius-md);
}
.btn--close {
font-size: 14px;
font-weight: bold;
border-radius: var(--radius-sm);
}
```
### 3.4 Documentation
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Minor** | Limited CSS documentation | All CSS files | Add section comments |
| **Minor** | No component documentation | Sidebar components | Add JSDoc-style comments |
| **Suggestion** | No design tokens documentation | CSS variables | Create tokens documentation |
---
## 4. Performance Review
### 4.1 CSS Optimization
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Large CSS files (105KB main, 78KB modern) | `styles.css`, `styles-modern.css` | Split into smaller modules |
| **Major** | Duplicate style definitions | Multiple files | Remove redundancies |
| **Minor** | Unused styles likely present | Theme variations | Audit and remove unused |
### 4.2 Asset Loading
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | highlight.js CSS loaded synchronously | `index.html:14` | Load asynchronously or bundle |
| **Minor** | Font files could be preloaded | `fonts.css` | Add preload links in HTML |
| **Suggestion** | Consider CSS critical path | Above-the-fold styles | Inline critical CSS |
**Code Example - Sync stylesheet loading:**
```html
<!-- index.html:14 - Blocks rendering -->
<link rel="stylesheet" href="../node_modules/highlight.js/styles/default.css">
```
**Fix Recommendation:**
```html
<!-- Non-blocking load -->
<link rel="stylesheet" href="../node_modules/highlight.js/styles/default.css" media="print" onload="this.media='all'">
<!-- Or preload fonts -->
<link rel="preload" href="../assets/fonts/Inter-Regular.woff2" as="font" type="font/woff2" crossorigin>
```
### 4.3 Animation Performance
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Minor** | Some transitions on expensive properties | `styles-modern.css:111-112` | Prefer transform/opacity |
| **Suggestion** | Missing will-change hints | Complex animations | Add will-change for GPU hints |
---
## 5. Component-Specific Issues
### 5.1 Tab System
| File | Issues |
|------|--------|
| `styles.css:23-97` | Inconsistent active state styling, small close button |
| `renderer.js:88-346` | Tab content created via innerHTML (XSS risk) |
### 5.2 Sidebar
| File | Issues |
|------|--------|
| `styles-sidebar.css` | Good structure but missing focus states |
| `sidebar-manager.js` | Clean implementation, needs ARIA |
### 5.3 Export Dialogs
| File | Issues |
|------|--------|
| `styles.css:1060-1355` | Monolithic, should be component |
| `index.html:171-331` | Complex nested structure needs semantic HTML |
### 5.4 Welcome Screen
| File | Issues |
|------|--------|
| `styles-welcome.css` | Minimal styles, good foundation |
| Missing hover states for keyboard focus | Add :focus-visible |
---
## 6. Prioritized Fix Recommendations
### Critical (Immediate)
1. **Add missing ARIA attributes** to all interactive elements
2. **Increase tab close button size** to minimum 24x24px
3. **Add focus-visible styles** for keyboard navigation
4. **Fix duplicate font-size declaration** in `.preview-content`
### Major (Next Sprint)
1. **Consolidate CSS resets** into single location
2. **Create button component system** with variants
3. **Standardize dark theme selectors** across all files
4. **Replace hardcoded colors** with CSS variables
5. **Create modal/dialog component** to reduce duplication
### Minor (Future)
1. **Document CSS architecture** and naming conventions
2. **Audit and remove unused styles**
3. **Add loading state components** (skeletons, spinners)
4. **Implement CSS module splitting** for better performance
---
## 7. Summary Statistics
| Category | Critical | Major | Minor | Suggestions |
|----------|----------|-------|-------|-------------|
| Visual Design | 1 | 5 | 4 | 1 |
| Usability | 3 | 4 | 4 | 0 |
| Code Quality | 0 | 6 | 4 | 1 |
| Performance | 0 | 3 | 2 | 2 |
| **Total** | **4** | **18** | **14** | **4** |
---
## Conclusion
The MarkdownConverter application has a functional UI with good visual variety through its theme system. However, there are significant opportunities for improvement in:
1. **Accessibility** - Critical for users with disabilities
2. **Code organization** - Reduce CSS duplication and improve maintainability
3. **Component consistency** - Standardize interactive element sizing and states
4. **Performance** - Optimize CSS loading and reduce bundle size
Addressing the Critical and Major issues will significantly improve both user experience and code maintainability.
-17
View File
@@ -1,17 +0,0 @@
{
"review_id": "full-ui-review_20260315",
"target": "src/ (Entire UI Directory)",
"focus_areas": ["visual", "usability", "code", "performance"],
"context": "comprehensive",
"platform": "desktop",
"status": "complete",
"started_at": "2026-03-15T00:09:00.000Z",
"completed_at": "2026-03-15T00:12:00.000Z",
"issues_found": 40,
"severity_counts": {
"critical": 4,
"major": 18,
"minor": 14,
"suggestion": 4
}
}
-48
View File
@@ -1,48 +0,0 @@
{
"version": "0.2.0",
"configurations": [
{
"name": "Debug Main Process",
"type": "node",
"request": "launch",
"cwd": "${workspaceFolder}",
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron",
"windows": {
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron.cmd"
},
"args": ["."],
"outputCapture": "std",
"env": {
"NODE_ENV": "development"
}
},
{
"name": "Debug Renderer Process",
"type": "chrome",
"request": "attach",
"port": 9222,
"webRoot": "${workspaceFolder}/src",
"timeout": 30000
},
{
"name": "Debug Main + Renderer",
"type": "node",
"request": "launch",
"cwd": "${workspaceFolder}",
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron",
"windows": {
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron.cmd"
},
"args": [".", "--remote-debugging-port=9222"],
"outputCapture": "std",
"env": {
"NODE_ENV": "development"
},
"serverReadyAction": {
"pattern": "listening on port ([0-9]+)",
"uriFormat": "http://localhost:%s",
"action": "debugWithChrome"
}
}
]
}
-25
View File
@@ -1,25 +0,0 @@
# Repository Guidelines
## Project Structure & Module Organization
Core application code lives in `src/`. Use `src/main.js` for the Electron main process, `src/preload.js` for the preload bridge, and `src/renderer.js` plus `src/editor/`, `src/sidebar/`, `src/repl/`, and `src/utils/` for renderer-side features. Electron adapter code is in `src/adapters/electron/`. Reusable markdown/document templates live in `src/templates/`. Static assets and icons are in `assets/`. Tests are in `tests/`, and build output goes to `dist/`.
## Build, Test, and Development Commands
- `npm start`: launch the Electron app locally.
- `npm test`: run the Jest suite once.
- `npm run test:watch`: rerun tests during local development.
- `npm run test:coverage`: generate coverage output.
- `npm run lint` / `npm run lint:fix`: check or fix ESLint issues in `src` and `tests`.
- `npm run format` / `npm run format:check`: apply or verify Prettier formatting.
- `npm run build:linux`, `npm run build:win`, `npm run build:mac`: create platform packages with `electron-builder`.
## Coding Style & Naming Conventions
This repo uses Prettier and ESLint. Follow `.prettierrc`: 2-space indentation, single quotes, semicolons, trailing commas where valid in ES5, and a 100-character line width. Prefer `camelCase` for variables/functions, `PascalCase` for classes, and kebab-case for file names only when already established. Keep module boundaries clear: UI logic in renderer modules, OS/file-system work behind Electron IPC and adapters.
## Testing Guidelines
Tests use Jest with `jest-environment-jsdom`. Add new tests under `tests/` with `*.test.js` names, mirroring the feature area when possible, for example `tests/sidebar.test.js` or `tests/print-preview.test.js`. Update or add regression tests for renderer behavior, preload APIs, and utility helpers when fixing bugs. Run `npm test` before opening a PR; use `npm run test:coverage` for larger refactors.
## Commit & Pull Request Guidelines
Recent history follows Conventional Commit prefixes such as `feat:`, `fix:`, and `refactor:`. Keep subjects short and imperative, for example `fix: guard modal cleanup on close`. PRs should describe the user-visible change, note test coverage, link any related issue, and include screenshots or GIFs for UI changes.
## Security & Configuration Tips
Do not bypass preload boundaries or introduce direct `eval`/dynamic code paths; ESLint already treats these as errors. Export and conversion features depend on external tools such as Pandoc, FFmpeg, ImageMagick, and LibreOffice, so document any new runtime dependency in `README.md` and packaging config.
+581 -81
View File
@@ -1,103 +1,603 @@
# CLAUDE.md — MarkdownConverter (master) # PanConverter - Claude Development Guide
> General code-quality, JavaScript, git, security, and testing standards are in the **global CLAUDE.md**. This file holds project- and branch-specific notes.
## Project Overview ## Project Overview
Electron desktop app for Markdown editing and universal file conversion powered by Pandoc. Cross-platform (Win/macOS/Linux). Features: multi-tab editor with live preview, 25+ themes, PDF viewer/editor (merge/split/compress/rotate/watermark/password), export to 20+ formats (PDF/DOCX/ODT/EPUB/HTML/LaTeX/RTF/PPTX), batch conversion, syntax highlighting, diagram support (Mermaid), Git integration, and a plugin system. **PanConverter** is a cross-platform Markdown editor and converter powered by Pandoc, built with Electron. It provides professional-grade editing capabilities with comprehensive export options.
- **Version:** 4.4.5 **Current Version**: v1.7.2
- **License:** MIT **Author**: Amit Haridas (amit.wh@gmail.com)
- **App ID:** `com.concreteinfo.markdownconverter` **License**: MIT
**Repository**: https://github.com/amitwh/pan-converter
## Branch Specifics ## Architecture & Technology Stack
This is the **primary/release branch** — a vanilla JavaScript Electron app with no bundler or framework in the renderer. The renderer is a single large `renderer.js` (5,300+ lines) loaded directly via `src/index.html`. All UI is hand-rolled DOM manipulation. ### Core Technologies
- **Electron** - Cross-platform desktop application framework
- **Pandoc** - Universal document converter (required system dependency)
- **ConvertAPI** - Cloud-based file conversion (200+ formats)
- **marked** - Markdown parsing and rendering
- **highlight.js** - Syntax highlighting
- **KaTeX** - Mathematical expression rendering
- **DOMPurify** - HTML sanitization
## Architecture ### Application Structure
```
src/
├── main.js # Electron main process, menu system, IPC handlers
├── renderer.js # TabManager class, multi-file editing, event handling
├── index.html # Application layout with tabbed interface
├── styles.css # Base styling with multi-theme support
└── styles-modern.css # Modern glassmorphism UI design system (v1.7.1)
### Main Process (`src/main.js` — 4,260 lines) assets/
Monolithic main process file. Contains all IPC handlers, Pandoc invocation, file operations, menu definitions (600+ lines), and window lifecycle. Key modules extracted: └── icon.png # Application icon
- `src/main/PDFOperations.js` — PDF manipulation via `pdf-lib` (merge, split, compress, rotate, delete, reorder, watermark, encrypt, decrypt, permissions)
- `src/main/GitOperations.js` — Git status/stage/commit/log via `simple-git`
### Renderer (`src/renderer.js` — 5,361 lines) package.json # Dependencies and build configuration
Vanilla JS, no framework. Directly manipulates DOM. Loads CodeMirror 6 via `src/editor/codemirror-setup.js`. Uses `marked` + `highlight.js` + `DOMPurify` + `mermaid` for rendering. Lazy-loads sidebar panels, REPL, command palette, zen mode. CLAUDE.md # Development documentation for AI assistants
```
### Preload (`src/preload.js` — 448 lines)
Exists as IPC bridge, but **`contextIsolation: false` and `nodeIntegration: true`** — the renderer has full Node access. Preload is effectively a thin passthrough.
### Security Model
- `contextIsolation: false` + `nodeIntegration: true` (legacy; the react-electron branch fixes this)
- Pandoc invoked via `execFile` (not `exec`) to prevent shell injection
- Path traversal protection: `validatePath()`, `resolveWritablePath()`, blocks sensitive system dirs
- Permission handler only allows `clipboard-read`/`clipboard-write`
- Rate limiter on conversions (2-second minimum interval)
- File size limit: 50MB
- Error message sanitization strips absolute paths
### Plugin System (`src/plugins/`)
Manifest-based discovery (`manifest.json`). Built-in `writing-studio` plugin with sprint/goal/snapshot management. Plugin API exposed via `src/plugins/plugin-api.js`.
### Settings
Custom JSON file store at `<userData>/settings.json` (NOT `electron-store` despite the dependency). Recent files at `<userData>/recent-files.json`.
## System Dependencies
| Dependency | Required | Notes |
|---|---|---|
| **Node.js** | >= 20 | Electron 41 bundles Node 20.x |
| **Pandoc** | Yes (for exports) | Downloaded to `bin/<platform>/pandoc` via `scripts/download-tools.js` (v3.9.0.2). Falls back to system PATH. Must be present for DOCX/ODT/EPUB/LaTeX/PPTX export. |
| **FFmpeg** | Bundled | `ffmpeg-static` npm package; `asarUnpacked` for packaged builds |
| **MiKTeX / TeX Live** | Optional | For LaTeX PDF export; MiKTeX PATH injected on Windows automatically |
| **ImageMagick** | Optional | Linux image conversion; listed as deb dependency |
| **LibreOffice** | Optional | Enhanced document conversion; listed as deb dependency |
## Development Commands ## Development Commands
### Prerequisites
```bash ```bash
npm start # Launch Electron app (dev mode) # Install Node.js dependencies
npm test # Jest test suite npm install
npm test:watch # Jest in watch mode
npm test:coverage # Jest with coverage report # Install Pandoc (required for export functionality)
npm run lint # ESLint check (src + tests) # Ubuntu/Debian:
npm run lint:fix # ESLint auto-fix sudo apt-get install pandoc
npm run format # Prettier write
npm run format:check # Prettier check only # macOS:
npm run download-tools # Download Pandoc binaries to bin/ brew install pandoc
npm run generate-icons # Generate app icons via sharp
# Windows: Download from https://pandoc.org/installing.html
``` ```
## Build & Package ### Running the Application
```bash
# Start development server
npm start
**Tool:** `electron-builder` (v26.0.12), config inline in `package.json` (no separate config file). # Start with debugging
npm start --enable-logging
```
| Target | Platforms | ### Building & Packaging
|---|---|
| `npm run build` | electron-builder (default platform) |
| `npm run build:win` | Windows: NSIS installer + portable + zip (x64) |
| `npm run build:mac` | macOS: default dmg |
| `npm run build:linux` | Linux: deb + AppImage + snap |
| `npm run dist` | Build without publish |
| `npm run dist:all` | Build for all platforms |
**Bundled with builds:** Pandoc binary per platform. FFmpeg via `ffmpeg-static` (asarUnpacked). NSIS installer uses custom script at `scripts/nsis-installer.nsh`. ```bash
# Generate application icons
npm run generate-icons
**Output:** `dist/` directory. # Build for current platform
npm run build
**CI:** GitHub Actions workflows in `.github/workflows/` (ci.yml, release.yml). # Platform-specific builds
npm run build:win # Windows
npm run build:mac # macOS
npm run build:linux # Linux (AppImage, .deb, .snap)
## Project Conventions / Gotchas # Build for all platforms
npm run dist:all
```
- **No bundler/transpilation.** The app uses vanilla CommonJS JavaScript. `src/main.js` is loaded directly by Electron. No webpack, no Vite, no TypeScript, no Babel. ### Git Branch Management
- **Monolithic files.** `main.js` (4,260 lines) and `renderer.js` (5,361 lines) contain most logic. Not ideal but is the current state of this branch. ```bash
- **CodeMirror 6** for the editor, configured in `src/editor/codemirror-setup.js`. # Switch to platform-specific branches
- **PDF rendering** uses `pdfjs-dist`; **PDF manipulation** uses `pdf-lib` in the main process. git checkout linux # Linux development
- **Renderer security is weak** — full Node access in renderer. Do NOT introduce new privileged renderer code without understanding this. git checkout macos # macOS development
- **Pandoc is external.** Must be installed separately or downloaded via `npm run download-tools`. HTML and built-in PDF export work without Pandoc; other formats require it. git checkout windows # Windows development
- **PDF export fallback chain:** xelatex -> pdflatex -> lualatex -> Electron built-in `printToPDF()`. git checkout master # Main development branch
- **ESLint flat config** (`eslint.config.js`) with ECMAScript 2022. Prettier with 2-space indent, single quotes, semicolons, 100-char width.
- **Tests:** Jest with jsdom environment, 15% coverage threshold. 24 test files in `tests/`. # Update all branches with latest changes
- **File associations:** `.md`, `.markdown`, `.pdf` registered at install. git checkout master
- **Single instance lock** enforced via `app.requestSingleInstanceLock()`. git push origin master
- **Adapters layer** (`src/adapters/`) abstracts file system operations for potential future non-Electron targets. git checkout linux && git merge master && git push origin linux
git checkout macos && git merge master && git push origin macos
git checkout windows && git merge master && git push origin windows
```
### Release Management
```bash
# Create and push release tag
git tag v1.2.1 -m "Release message"
git push origin v1.2.1
# Create GitHub release with packages
gh release create v1.2.1 --title "Title" --notes "Release notes" \
"dist/PanConverter-1.2.1.AppImage" \
"dist/pan-converter_1.2.1_amd64.deb" \
"dist/pan-converter_1.2.1_amd64.snap"
```
## Feature Implementation Guide
### v1.7.2 Enhanced Themes & Bug Fixes (Latest)
#### 🎨 14 New Beautiful Themes
**Expanded Theme Collection** (`src/main.js:242-266`, `src/styles.css:1590-2555`)
- **Added 14 new professionally-designed themes** bringing the total to 19 themes
- **New Themes Include**:
- **Dracula** - Popular purple and pink dark theme
- **Nord** - Arctic-inspired blue theme
- **One Dark** - Atom's iconic dark theme
- **Atom One Light** - Clean, bright light theme
- **Material** - Google Material Design inspired
- **Gruvbox Dark** - Warm retro groove colors (dark)
- **Gruvbox Light** - Warm retro groove colors (light)
- **Tokyo Night** - Modern Japanese-inspired dark theme
- **Palenight** - Soft purple Material Design variant
- **Ayu Dark** - Simple, elegant dark theme
- **Ayu Light** - Minimalist light theme
- **Ayu Mirage** - Balanced dark-light hybrid
- **Oceanic Next** - Ocean-inspired teal and blue
- **Cobalt2** - Deep blue with yellow accents
**Technical Implementation:**
- Complete CSS styling for all UI elements per theme
- Consistent theming across tabs, toolbar, editor, preview, and status bar
- Theme-aware color schemes for syntax highlighting
- All themes support glassmorphism effects from v1.7.1
#### 🐛 Undo/Redo Fix
**Fixed Menu Integration** (`src/renderer.js:1107-1118`)
- Fixed undo/redo menu items not connecting to custom undo/redo functionality
- Added IPC event listeners in renderer to receive 'undo' and 'redo' messages
- Connected Edit menu commands to TabManager's undo() and redo() methods
- Keyboard shortcuts (Ctrl+Z, Ctrl+Shift+Z) now work correctly with custom undo stack
### v1.7.1 Modern UI Design
#### 🎨 Glassmorphism & Gradient UI
**Modern Design System** (`src/styles-modern.css`, `src/index.html:7-11`)
- **Glassmorphism Effects** - Translucent backgrounds with backdrop-filter blur
- **Animated Gradient Background** - Purple-blue gradient that shifts colors dynamically
- **CSS Custom Properties** - Centralized theming with CSS variables
- **Modern Typography** - Inter font family for UI, JetBrains Mono for code
- **Smooth Animations** - CSS transitions with cubic-bezier easing
- **Enhanced Hover Effects** - Interactive elements with scale and transform effects
- **Custom Scrollbars** - Styled scrollbars matching the modern aesthetic
- **Progress Bars** - Shimmer animations and gradient fills
**Design Features:**
- Animated gradient background (15-second color shift loop)
- Glass-effect tabs with blur and semi-transparency
- Gradient-based buttons with hover/active states
- Modern card-based dialogs with rounded corners
- Enhanced typography with gradient text for headings
- Ripple-like hover effects on interactive elements
- Theme variables for consistent colors and spacing
- Shadow effects with proper depth perception
**Technical Implementation:**
- Created comprehensive `styles-modern.css` file (780+ lines)
- Google Fonts integration (Inter, JetBrains Mono)
- CSS Grid and Flexbox for modern layouts
- backdrop-filter for glassmorphism (with fallbacks)
- CSS animations with @keyframes
- RGB/RGBA color system with opacity control
- CSS custom properties for easy theming
### v1.7.0 PDF Editor & Universal Converter
#### 📄 Comprehensive PDF Editor
**Complete PDF Manipulation Suite** (`src/main.js:1566-2068`, `src/index.html:552-921`, `src/renderer.js:1951-2429`)
- **Merge PDFs** - Combine multiple PDF files into a single document
- **Split PDF** - Split PDFs by page ranges, intervals, or file size
- **Compress PDF** - Reduce PDF file size with optimization
- **Rotate Pages** - Rotate specific pages or entire documents (90°, 180°, 270°)
- **Delete Pages** - Remove unwanted pages from PDFs
- **Reorder Pages** - Rearrange pages in any order
- **Add Watermark** - Text watermarks with customizable position, size, color, opacity
- **Password Protection** - Encrypt PDFs with user and owner passwords
- **Remove Password** - Decrypt password-protected PDFs
- **Set Permissions** - Control printing, copying, modifying, and other document permissions
**Technical Implementation:**
- Uses `pdf-lib` (v1.17.1) for all PDF operations
- Full async/await implementation for optimal performance
- Comprehensive error handling and user feedback
- Progress indicators for long-running operations
- Page range parsing (e.g., "1-5, 7, 9-12")
- RGB color conversion for watermarks
- Support for encrypted PDFs
**Watermark Features:**
- Multiple positioning options (center, diagonal, corners, top/bottom)
- Customizable font size (8-144px)
- Adjustable opacity (0-100%)
- Color picker for text color
- Apply to all pages or custom page ranges
**Security Features:**
- 128-bit and 256-bit encryption support
- User password (required to open PDF)
- Owner password (required to modify permissions)
- Granular permission controls:
- Allow/deny printing (high/low resolution)
- Allow/deny content modification
- Allow/deny content copying
- Allow/deny annotations
- Allow/deny form filling
- Allow/deny accessibility features
- Allow/deny document assembly
- Allow/deny high-quality printing
#### 🔄 Universal File Converter
**Open-Source Multi-Tool Converter** (`src/main.js:446-600`, `src/index.html:257-483`, `src/renderer.js:1372-1940`)
- **LibreOffice** - Document conversions (DOCX, PDF, ODT, RTF, TXT, HTML, XLSX, PPTX)
- **ImageMagick** - Image format conversions (JPG, PNG, GIF, TIFF, WebP, SVG, etc.)
- **FFmpeg** - Video and audio conversions (MP4, AVI, MOV, MP3, WAV, etc.)
- **Pandoc** - Document markup conversions (Markdown, HTML, LaTeX, EPUB, etc.)
**Features:**
- Single file and batch folder conversion
- Tool-specific advanced options:
- ImageMagick: Quality, DPI, resize, compression type
- FFmpeg: Video/audio codecs, bitrate, preset, framerate
- LibreOffice: Export quality, page range, bookmarks
- Automatic tool detection and availability checking
- Recursive folder processing
- 100% offline and open-source
- No API keys required
### v1.6.1 Bug Fixes
#### 🐛 File Association Rendering Fix
**Fixed Double-Click File Loading** (`src/main.js:1364-1379`)
- Fixed critical issue where files opened via double-click weren't rendering
- Added proper wait for renderer load state before sending file data
- Implemented `did-finish-load` event listener to prevent race conditions
- Files now render correctly when opened from Windows Explorer
### v1.6.0 Enhanced Markdown Editor & ConvertAPI Integration
#### ✨ Complete Markdown Toolbar
**Additional Formatting Buttons** (`src/index.html:78-98`, `src/renderer.js:596-723`)
- **Strikethrough** button - Wraps text with `~~strikethrough~~`
- **Code Block** button - Inserts fenced code blocks with triple backticks
- **Horizontal Rule** button - Adds section divider with `---`
- Complete suite of markdown formatting tools now available
#### 🔍 Fixed Find & Replace
**Focus and Highlighting Improvements** (`src/renderer.js:725-870`)
- Fixed focus issue - dialog no longer loses focus while typing
- Visual highlighting with text selection showing current match
- Smart auto-scroll to display matches prominently
- Real-time match counting: "Match X of Y"
- Replace single match or replace all functionality
- Enter/Shift+Enter keyboard navigation
#### 📏 Fixed Line Numbers
**Line Counting and Synchronization** (`src/renderer.js:337-355`)
- Fixed bug using `'\\n'` instead of `'\n'` for line splitting
- Added scroll synchronization between line numbers and editor
- Line numbers update correctly as you type
- Smooth scrolling keeps line numbers aligned
#### ☁️ ConvertAPI Cloud Integration
**200+ Format Cloud Conversion** (`src/main.js:370-416`, `src/index.html:257-307`, `src/renderer.js:1540-1603`)
- New **ConvertAPI menu** with cloud-based file conversion
- Support for 200+ file formats: MD, DOCX, PDF, HTML, JPG, PNG, EPUB, ODT
- Secure API key storage in localStorage for reuse
- Real-time conversion status and progress tracking
- Free tier: 250 conversions per month
- Professional conversion dialog with format selection
- Get API key at: https://www.convertapi.com
**Technical Implementation:**
- Installed `convertapi` npm package (v1.15.0)
- IPC handlers for cloud conversion workflow
- Error handling and user feedback dialogs
- Async/await pattern for conversion operations
### v1.5.0 Enhanced Features & Open Source Compatibility
#### 🔧 Export Function Fixes & Optional Advanced Options
**Export Dialog Enhancement** (`src/index.html:125-133`, `src/renderer.js:960-985`)
- Fixed export function issues after advanced export options integration
- Added optional advanced export options via checkbox toggle (unchecked by default)
- Basic export options always visible, advanced options hidden until enabled
- Clean UI separation between simple and advanced export workflows
#### 🏗️ Open Source Compatibility & Dependency Removal
**Removed Proprietary Dependencies** (`src/main.js:430-450`, `package.json:32-37`)
- Removed bundled Pandoc binaries - now requires system-installed Pandoc
- Replaced proprietary XLSX dependency with open-source CSV export
- Removed non-essential bundled binaries to ensure open-source compatibility
- Updated export functions to use system Pandoc installation
#### ✨ Advanced User Experience Features
**Auto-Save System** (`src/renderer.js:445-484`)
- Automatic saving every 30 seconds with visual indicators
- Smooth slide-in animation for auto-save notifications
- Prevents data loss during extended editing sessions
- Integrated with file opening and tab creation workflows
**Enhanced Document Statistics** (`src/renderer.js:385-444`)
- Comprehensive statistics: words, characters, lines, paragraphs, sentences
- Estimated reading time calculation (200 words per minute)
- Real-time updates as user types
- Professional presentation in status bar
**Recent Files Management** (`src/main.js:69-114`, `src/renderer.js:487-512`)
- Recent files menu with last 10 opened files
- Persistent storage via localStorage and user data directory
- Menu integration with File > Recent Files submenu
- Clear recent files functionality with menu rebuild
**Mathematical Expression Support** (`src/renderer.js:1099-1130`, `src/renderer.js:292-306`)
- KaTeX integration for rendering mathematical expressions
- Support for multiple delimiters: $$, $, \\[\\], \\(\\)
- Real-time math rendering in preview pane
- Fallback handling for missing KaTeX library
### v1.4.0 Advanced Export & Batch Processing
#### 🔧 Fixed File Association Support
**File Loading Fix** (`src/main.js:385-390`, `src/renderer.js:485-486`)
- Fixed timing issue with file association loading
- Added proper `renderer-ready` event to ensure TabManager is initialized
- Files now open correctly when double-clicked or opened via right-click menu
- Command-line file arguments are properly handled on startup
#### 🎛️ Advanced Export Options Dialog
**Template & Metadata Support** (`src/main.js:247-357`, `src/index.html:117-212`)
- Comprehensive export options dialog with professional UI
- Template selection (default or custom template files)
- Metadata fields (title, author, date, subject) with dynamic field addition
- Document options: Table of Contents, section numbering, citations
- PDF-specific options: Engine selection (XeLaTeX, PDFLaTeX, LuaLaTeX), custom margins
- Bibliography support: .bib, .yaml, .json files with CSL styling
- All export formats now use enhanced options dialog
#### 📁 Batch File Conversion System
**Multi-File Processing** (`src/main.js:179-186`, `src/main.js:559-690`)
- New "Batch" menu for converting entire folders
- Recursive folder processing with progress tracking
- Support for all export formats with advanced options
- Real-time progress bar and file-by-file status updates
- Maintains folder structure in output directory
- Error handling with completion statistics
#### 🎨 Enhanced UI Components
**Dialog System** (`src/styles.css:838-1361`)
- Professional modal dialogs with backdrop and animations
- Theme-aware styling for all new components
- Responsive layouts with proper accessibility
- Form validation and user feedback systems
- Progress indicators for long-running operations
### v1.3.x Tabbed Interface & Enhanced Features
#### 🗂️ Tabbed Multi-File Support (v1.3.0)
**TabManager Class** (`src/renderer.js`)
- Complete tab management system for multiple files
- Tab switching, creation, and closure
- State preservation per tab (content, cursor position, scroll)
- File path tracking for each tab
- Keyboard shortcuts: `Ctrl/Cmd+T` (new tab), `Ctrl/Cmd+W` (close tab)
#### 🎯 Enhanced PDF Export (v1.3.0)
**Multi-Engine Fallback System** (`src/main.js:239-280`)
- Primary: XeLaTeX with proper margins
- Fallback 1: PDFLaTeX
- Fallback 2: wkhtmltopdf
- Automatic engine detection and switching
#### 📁 File Association Support (v1.3.1)
**OS Integration** (`src/main.js:452-498`, `package.json:50-65`)
- Double-click .md files to open in PanConverter
- Command-line argument handling
- Pending file queue for startup loading
#### 🎨 Typography & Spacing (v1.3.2-1.3.3)
**Preview Enhancement** (`src/styles.css`)
- Restored ideal text spacing from v1.0
- Font sizes increased to 15px for better readability
- Comprehensive selector coverage for legacy and new containers
- Theme-aware typography for all content types
### v1.2.1 Comprehensive Editor Enhancements
#### ✨ Advanced Editor Features
**Find & Replace System** (`src/renderer.js:200-350`)
- Dialog-based interface with match highlighting
- Forward/backward navigation through matches
- Replace single or replace all functionality
- Real-time match counting and status display
- Escape key closes dialog
**Line Numbers** (`src/renderer.js:450-500`, `src/styles.css:517-598`)
- Toggle-able line numbers with toolbar button
- Synchronized scrolling with editor content
- Theme-aware styling for all supported themes
- Dynamic line number generation based on content
**Undo/Redo System** (`src/renderer.js:100-150`)
- Stack-based state management for editor history
- Keyboard shortcuts: `Ctrl/Cmd+Z` (undo), `Ctrl/Cmd+Shift+Z` (redo)
- Intelligent state saving on text changes
- Memory-efficient history management
**Smart Auto-Indentation** (`src/renderer.js:350-400`)
- Automatic list continuation on Enter key
- Proper indentation handling for nested lists
- Support for ordered and unordered lists
- Intelligent whitespace management
**Enhanced Keyboard Shortcuts** (`src/renderer.js:400-450`)
- `Tab`/`Shift+Tab` for line indentation/outdentation
- `Enter` for auto-continuing lists
- `Ctrl/Cmd+F` for find & replace dialog
- `Escape` for closing dialogs
**Word/Character Count** (`src/renderer.js:500-530`)
- Live counting displayed in status bar
- Updates automatically as content changes
- Word and character statistics
#### 📤 Export & Conversion Features
**PowerPoint Export** (`src/main.js:330-350`)
- Convert markdown to PPTX presentations
- Automatic slide-level formatting (`--slide-level=2`)
- Smart presentation structure handling
**Spreadsheet Export** (`src/main.js:370-457`)
- Export markdown tables to Excel (XLSX/XLS) and ODS formats
- Multi-table support with separate worksheets
- Automatic table detection and parsing
- Error handling for files without tables
**Document Import** (`src/main.js:280-315`)
- Import DOCX, ODT, RTF, HTML, PDF, PPTX, ODP files
- Automatic conversion to markdown format
- File dialog with appropriate filters
- Success notifications and error handling
**Table Creation Helper** (`src/renderer.js:600-650`)
- Built-in table generator with row/column specification
- Automatic markdown table formatting
- Proper header separation and alignment
#### 🎨 Interface & Theming
**Multi-Theme Support** (`src/styles.css:214-598`)
- Light, Dark, Solarized, Monokai, GitHub themes
- Complete theming for all UI components
- Theme-aware styling for new features (find dialog, line numbers)
- Persistent theme selection with local storage
**Enhanced UI Components** (`src/index.html:94-108`)
- Find & replace dialog with modern styling
- Toolbar buttons for all new features
- Status bar with live statistics
- Responsive layout with proper spacing
## File Structure & Key Components
### Main Process (`src/main.js`)
- **Menu System**: Comprehensive menu with file operations, editing, conversion, view options, batch processing
- **IPC Handlers**: Communication between main and renderer processes
- **File Operations**: Open, save, import/export functionality with file association support
- **Export System**: Advanced export with templates, metadata, and Pandoc integration
- **Batch Processing**: Multi-file conversion with progress tracking and error handling
- **Theme Management**: Persistent theme storage and application
- **Spreadsheet Export**: Table extraction and XLSX generation
- **About Dialog**: Application information and feature list
### Renderer Process (`src/renderer.js`)
- **Editor Initialization**: CodeMirror-like functionality with custom implementation
- **TabManager System**: Multi-file editing with state management
- **Find & Replace Engine**: Search algorithms with regex support
- **Undo/Redo Manager**: History stack management
- **Auto-indentation Logic**: Smart list continuation
- **Live Preview**: Real-time markdown rendering with DOMPurify
- **Export Dialog Management**: Advanced options collection and validation
- **Batch Conversion Interface**: Folder selection, progress tracking, and user feedback
- **Event Handling**: Keyboard shortcuts and UI interactions
- **Statistics Tracking**: Word/character counting
### Styling (`src/styles.css`)
- **Base Styles**: Application layout and typography
- **Component Styles**: Toolbar, editor, preview, dialogs
- **Theme Implementations**: Complete styling for all themes
- **Responsive Design**: Flexible layouts and proper spacing
- **Animation Support**: Smooth transitions and hover effects
### HTML Structure (`src/index.html`)
- **Toolbar**: Feature buttons with SVG icons
- **Tab Bar**: Multi-file navigation with close buttons
- **Find Dialog**: Search and replace interface
- **Export Options Dialog**: Advanced export configuration with templates and metadata
- **Batch Conversion Dialog**: Folder selection and conversion progress
- **Editor Container**: Line numbers and text editor with tab content management
- **Preview Pane**: Rendered markdown display
- **Status Bar**: Statistics and application status
## Testing & Quality Assurance
### Manual Testing Checklist
- [ ] All keyboard shortcuts work correctly
- [ ] Find & replace functions properly with edge cases
- [ ] Line numbers sync correctly with content
- [ ] Undo/redo preserves cursor position
- [ ] Auto-indentation works with various list types
- [ ] File association loading (double-click .md files)
- [ ] Export options dialog with templates and metadata
- [ ] Batch conversion with progress tracking
- [ ] All themes render correctly for new components
- [ ] Export functions work with various document formats
- [ ] Table creation and export functionality
- [ ] Cross-platform compatibility
### Known Issues & Limitations
- AppImage may require `--no-sandbox` flag on some Linux systems
- Large files (>1MB) may cause performance issues
- Windows/Mac builds require platform-specific environments
- Pandoc must be installed separately for export functionality
## Deployment & Distribution
### Release Packages
- **Linux AppImage**: Universal Linux package (self-contained)
- **Debian Package**: `.deb` for Ubuntu/Debian systems
- **Snap Package**: Universal Linux package via Snap Store
- **Future**: Windows `.exe` and macOS `.dmg` packages
### Release Process
1. Update version in `package.json`, `src/main.js`, and `README.md`
2. Commit changes and push to all platform branches
3. Build platform-specific packages
4. Create Git tag and GitHub release
5. Upload packages to GitHub release
6. Update documentation and announce release
## Contributing Guidelines
### Code Style
- Use consistent indentation (2 spaces)
- Follow JavaScript ES6+ standards
- Comment complex functionality
- Maintain separation between main and renderer processes
- Use descriptive variable and function names
### Adding New Features
1. Plan feature implementation and UI integration
2. Update relevant files (main.js, renderer.js, styles.css)
3. Test across all supported themes
4. Update documentation and README
5. Test on multiple platforms if possible
6. Submit pull request with detailed description
### Bug Reporting
- Include steps to reproduce
- Specify platform and version information
- Attach relevant screenshots or error logs
- Check existing issues before creating new ones
## Future Roadmap
### Planned Features
- [ ] Collaborative editing capabilities
- [ ] Plugin system for extensions
- [ ] Advanced markdown extensions (math, diagrams)
- [ ] Cloud synchronization options
- [ ] Mobile companion app
- [ ] Advanced export templates
- [ ] Spell check and grammar checking
- [ ] Version control integration
### Technical Improvements
- [ ] Performance optimization for large files
- [ ] Memory usage optimization
- [ ] Startup time improvements
- [ ] Better error handling and user feedback
- [ ] Automated testing suite
- [ ] Continuous integration/deployment
---
**Last Updated**: October 11, 2025
**Claude Assistant**: Development completed for v1.7.2 with 14 new professionally-designed themes (Dracula, Nord, Tokyo Night, Gruvbox, Ayu, Material, Oceanic Next, Palenight, Cobalt2, and more) bringing total to 19 themes, plus fixed undo/redo menu integration for proper keyboard shortcut support.
-1478
View File
File diff suppressed because it is too large Load Diff
+92 -9
View File
@@ -1,12 +1,95 @@
# Test Double-Click File Opening # Push Instructions for Pan Converter
This is a test file to verify double-click functionality. ## Prerequisites
1. Create a new repository on GitHub: https://github.com/new
- Repository name: `pan-converter`
- Keep it empty (no README, .gitignore, or license)
- Make it public or private as desired
## Features to Test 2. Set up authentication:
- File should load automatically - **Option A - SSH Key** (Recommended):
- Content should display in editor ```bash
- Tab should show filename # Check if you have SSH key
- Preview should render markdown ls -la ~/.ssh/id_rsa.pub
**This text should be bold** # If not, generate one:
*This text should be italic* ssh-keygen -t rsa -b 4096 -C "your_email@example.com"
# Add to GitHub: Settings > SSH and GPG keys > New SSH key
cat ~/.ssh/id_rsa.pub
```
- **Option B - Personal Access Token**:
- Go to GitHub Settings > Developer settings > Personal access tokens
- Generate new token with 'repo' scope
- Save the token securely
## Push Commands
### Using SSH (Recommended)
```bash
# Set SSH remote
git remote set-url origin git@github.com:amitwh/pan-converter.git
# Push all branches
git push -u origin master
git push origin linux
git push origin macos
git push origin windows
```
### Using HTTPS with Token
```bash
# Set HTTPS remote
git remote set-url origin https://github.com/amitwh/pan-converter.git
# Push all branches (you'll be prompted for username and token)
git push -u origin master
git push origin linux
git push origin macos
git push origin windows
# When prompted:
# Username: amitwh
# Password: [paste your Personal Access Token]
```
### Using GitHub CLI (if installed)
```bash
# Login to GitHub CLI
gh auth login
# Create repo and push
gh repo create pan-converter --public --source=. --remote=origin --push
```
## Automated Script
```bash
# Run the provided script
./push-to-github.sh
```
## Verify Success
After pushing, verify at: https://github.com/amitwh/pan-converter
You should see:
- 4 branches (master, linux, macos, windows)
- All project files
- Complete commit history
## Troubleshooting
### Authentication Failed
- For SSH: Ensure your SSH key is added to GitHub
- For HTTPS: Use Personal Access Token, not password
- Check token has 'repo' scope
### Repository Not Found
- Ensure repository exists on GitHub
- Check spelling: `pan-converter`
- Verify you're logged into the correct GitHub account
### Permission Denied
- Check repository ownership
- Ensure you have write access
- Verify authentication method is correct
+128 -214
View File
@@ -1,251 +1,160 @@
<p align="center"> # PanConverter
<img src="assets/markdown-converter-assets/logo-horizontal.svg" alt="Markdown Converter" width="420">
</p>
# MarkdownConverter A cross-platform Markdown editor and converter powered by Pandoc.
A powerful cross-platform Markdown editor and document converter powered by Pandoc, built with Electron. 100% open-source with no proprietary dependencies. ![PanConverter](assets/icon.png)
## Features ## Features
### Markdown Editor ### ✨ Advanced Markdown Editor
<img width="1920" height="1032" alt="image" src="https://github.com/user-attachments/assets/5f53ba94-7663-47c3-b12b-b7b8bd2645aa" /> - 🗂️ **Tabbed Interface** - Work with multiple files simultaneously in separate tabs
- **Multi-tab editing** - Work on multiple files simultaneously - 📝 **Rich Text Editor** - Full-featured editor with syntax highlighting and comprehensive toolbar
- **Live preview** - Real-time markdown rendering with syntax highlighting - 🔍 **Find & Replace** - Powerful search and replace with match highlighting and navigation
- **Dynamic splitter** - Drag to resize editor and preview panes - 🔢 **Line Numbers** - Toggle line numbers for easier code editing and navigation
- **25+ themes** - Light and dark themes including Atom One Light, Dracula, Nord, Sepia, and more - ↩️ **Smart Auto-Indentation** - Automatic list continuation and intelligent indentation
- **Find & Replace** - Search and replace with regex support - ⏪ **Undo/Redo** - Full undo/redo support with keyboard shortcuts
- **Line numbers** - Toggle line numbers in the editor - ⌨️ **Advanced Shortcuts** - Tab indentation, line selection, and smart text formatting
- **Auto-save** - Automatic saving every 30 seconds - 📂 **File Association Support** - Open markdown files directly from file manager
- **Math support** - KaTeX integration for mathematical expressions
### PDF Viewer & Editor ### 🎨 Themes & Interface
<img width="1920" height="1032" alt="image" src="https://github.com/user-attachments/assets/f10f62be-af3d-496e-81df-37ab4f91abfd" /> - 👁️ **Live Preview** - See your markdown rendered in real-time with synchronized scrolling
- 🎨 **Multiple Themes** - Choose from Light, Dark, Solarized, Monokai, or GitHub themes
- 💾 **Auto-Save** - Never lose your work with automatic saving every 30 seconds
- 📊 **Enhanced Statistics** - Detailed document statistics including word count, character count, lines, paragraphs, sentences, and estimated reading time
- 🕒 **Recent Files** - Quick access to recently opened files via File menu
- 🧮 **Math Support** - Render mathematical expressions using KaTeX (supports $$, $, \\[\\], \\(\\) delimiters)
- **Built-in PDF viewer** - Open and view PDF files directly in the app ### 📤 Export & Conversion
- **Page navigation** - Navigate pages with keyboard or buttons - 📄 **Enhanced PDF Export** - Robust PDF generation with multiple LaTeX engine fallbacks (XeLaTeX, PDFLaTeX, wkhtmltopdf)
- **Zoom controls** - Zoom in/out, fit to width, fit to page - 📄 **Document Export** - Convert to HTML, DOCX, LaTeX, RTF, ODT, EPUB, PowerPoint (PPTX), and OpenDocument Presentation (ODP)
- **Rotation** - Rotate pages left or right - 📊 **Spreadsheet Export** - Export markdown tables to CSV format for compatibility with any spreadsheet application
- **PDF Editor tools**: - 📥 **Document Import** - Import DOCX, ODT, RTF, HTML, PDF, and presentation files to markdown
- Merge multiple PDFs - 📋 **Table Creation Helper** - Built-in table generator for easy markdown table creation
- Split PDFs by page range
- Compress PDFs
- Rotate pages
- Delete pages
- Reorder pages
- Add watermarks
- Password protection
- Remove passwords
- Set permissions
### Export Options ### 🖥️ Platform Support
- **PDF** - Export to PDF with customizable page sizes and orientation - **Cross-Platform** - Works seamlessly on Windows, macOS, and Linux
- **DOCX** - Standard and Enhanced (template-based) Word export
- **ODT** - OpenDocument format
- **HTML** - Web-ready HTML export
- **PowerPoint** - PPTX presentation export
- **EPUB** - E-book format
- **LaTeX** - Academic document format
- **RTF** - Rich Text Format
- **Export themes** - Five visual styles (Modern, Classic, Sepia, Minimal, Elegant) for PDF and Word exports — recolored headings, links, and fonts
### Advanced Features
- **Custom headers & footers** - Add headers/footers to exports with dynamic fields
- **Page size configuration** - A3, A4, A5, B4, B5, Letter, Legal, Tabloid, or custom sizes
- **Visual flow chart editor** - Build Mermaid flowcharts visually; drag nodes, connect edges, live preview. Insert at cursor.
- **Batch conversion** - Convert entire folders of markdown files
- **ASCII Art Generator** - 17 hand-coded fonts + 400+ FIGlet fonts; text banners, boxes, and templates; insert into editor, copy to clipboard, or save to file (Ctrl+Shift+A)
- **Word templates** - Use custom Word templates for enhanced exports
- **Import documents** - Import from 30+ formats (DOCX, PDF, HTML, etc.)
- **MarkItDown import** - Any file → Markdown via [Microsoft MarkItDown](https://github.com/microsoft/markitdown). **Bundled** (MIT + PSF Python runtime) — no installation required for the core formats (PDF, DOCX, PPTX, XLSX, Outlook .msg, EPUB, HTML, images, ZIP, CSV, JSON, XML). For **audio transcription** and **OCR**, install `markitdown[all]` system-side (multi-GB ML models; not bundled).
- **Excel export** - Markdown tables to native .xlsx workbooks (one sheet per table)
- **AI Assistant** - Multi-provider AI help (OpenAI/Anthropic/Ollama/LM Studio): chat panel, summarize/improve/translate commands, grammar proofreading
- **Inline comments** - Anchor-based document comments in `.comments/` sidecars with F8 navigation
- **Wiki-links & Backlinks** - `[[Note]]` links with click-to-create and a "what links here?" panel (local knowledge base)
- **Crash recovery** - Session restore of open tabs and unsaved buffers after a crash
- **Version history** - Automatic pre-save snapshots with restore/diff/delete from the History panel
- **Vim mode & snippet expansion** - Vim keybindings toggle; Tab expands saved snippets
- **Quick Note** - Global scratchpad (Ctrl+Alt+Q) that appends to `notes/quick-notes.md`
- **Real PDF encryption** - Password protection, removal, and permissions actually work
- **Offline math & diagrams** - KaTeX bundled locally; PlantUML renders locally when the CLI is installed
## Installation ## Installation
### Prerequisites ### Prerequisites
- [Node.js](https://nodejs.org/) (v16 or later) — only for development builds - [Pandoc](https://pandoc.org/installing.html) must be installed for export functionality
- [Pandoc](https://pandoc.org/installing.html) — **bundled** inside the app, no install needed - **Ubuntu/Debian**: `sudo apt-get install pandoc`
- [MarkItDown](https://github.com/microsoft/markitdown) — **bundled** inside the app (MIT + embedded PSF Python runtime via PyInstaller), no install needed for PDF / DOCX / PPTX / XLSX / Outlook / EPUB / HTML / images / ZIP / CSV / JSON / XML - **macOS**: `brew install pandoc`
- Optional for advanced import only: `pip install "markitdown[all]"` adds **audio transcription** (Whisper) and **OCR** (EasyOCR/Tesseract) — these are multi-GB model downloads and are not bundled for size reasons - **Windows**: Download installer from Pandoc website
### Install Dependencies ### PDF Export Requirements
For optimal PDF export, install a LaTeX engine (recommended):
- **Ubuntu/Debian**: `sudo apt-get install texlive-xetex texlive-latex-base`
- **macOS**: `brew install --cask mactex`
- **Windows**: Install MiKTeX or TeX Live
- **Alternative**: `sudo apt-get install wkhtmltopdf` (fallback option)
### Download
Download the latest release for your platform from the [Releases](https://github.com/amitwh/pan-converter/releases) page.
#### Linux
- **AppImage**: `PanConverter-1.5.0.AppImage` (universal, may require `--no-sandbox` flag)
- **Debian Package**: `pan-converter_1.5.6_amd64.deb`
- **Snap Package**: `pan-converter_1.5.6_amd64.snap`
### Install from Source
```bash ```bash
git clone https://github.com/amitwh/pan-converter.git
cd pan-converter
npm install npm install
```
### Run the Application
```bash
npm start npm start
``` ```
### Build for Distribution ## Usage
```bash
# Windows
npm run build:win
# macOS ### Basic Workflow
npm run build:mac 1. **Write** - Use the editor to write your Markdown content
2. **Preview** - Toggle the preview pane to see rendered output
3. **Theme** - Choose your preferred theme from the View menu
4. **Export** - Export your document to various formats
# Linux ### Export Options
npm run build:linux - **Documents**: HTML, PDF, DOCX, LaTeX, RTF, ODT, EPUB
``` - **Presentations**: PowerPoint (PPTX), OpenDocument Presentation (ODP)
- **Spreadsheets**: CSV format for tables (compatible with Excel, LibreOffice, Google Sheets)
- **Advanced Export Options**: Optional template support, metadata insertion, table of contents, section numbering, and PDF-specific settings
- **Batch Conversion**: Convert entire folders of markdown files with progress tracking
### Import & Conversion
- **Import Documents**: Convert DOCX, ODT, RTF, HTML, PDF, and presentation files to Markdown
- **Cross-Format Conversion**: Convert current file between multiple formats
- **Smart Presentation Handling**: Automatic slide-level formatting for PPTX/ODP exports
### Table Creation
- Click the table button in the toolbar
- Specify number of rows and columns
- Automatically generates properly formatted Markdown tables
## Keyboard Shortcuts ## Keyboard Shortcuts
| Action | Shortcut | ### File Operations
|--------|----------| - `Ctrl/Cmd + N` - New file/tab
| New File | Ctrl+N | - `Ctrl/Cmd + T` - New tab
| Open File | Ctrl+O | - `Ctrl/Cmd + W` - Close current tab
| Open PDF | Ctrl+Shift+O | - `Ctrl/Cmd + Tab` - Switch to next tab
| Save | Ctrl+S | - `Ctrl/Cmd + O` - Open file
| Save As | Ctrl+Shift+S | - `Ctrl/Cmd + S` - Save file
| Export | Ctrl+E | - `Ctrl/Cmd + Shift + S` - Save as
| Print | Ctrl+P | - `Ctrl/Cmd + I` - Import document
| Find | Ctrl+F |
| Undo | Ctrl+Z |
| Redo | Ctrl+Shift+Z |
| New Tab | Ctrl+T |
| Close Tab | Ctrl+W |
| Toggle Preview | Ctrl+Shift+V |
| Zoom In | Ctrl+Shift++ |
| Zoom Out | Ctrl+Shift+- |
| Command Palette | Ctrl+Shift+P |
| Zen Mode | F11 |
| Writing Analytics | Ctrl+Shift+A |
| Quick Note | Ctrl+Alt+Q |
| Universal Converter | Ctrl+Shift+C |
| Table Generator | Ctrl+Shift+T |
| ASCII Art Generator | Ctrl+Shift+A |
| Next Comment | F8 |
| Add Comment at Cursor | Ctrl+Alt+M |
| Flow Chart: Undo | Ctrl+Z |
| Flow Chart: Redo | Ctrl+Shift+Z |
| Flow Chart: Delete selected | Delete |
## Themes ### Editor Features
- `Ctrl/Cmd + F` - Find & Replace
- `Ctrl/Cmd + Z` - Undo
- `Ctrl/Cmd + Shift + Z` - Redo
- `Tab` - Indent lines or insert 4 spaces
- `Shift + Tab` - Outdent selected lines
- `Enter` - Auto-continue lists with proper indentation
37 built-in editor themes, registered in `src/main/ThemeRegistry.bootstrap.js`. ### View & Navigation
- `Ctrl/Cmd + P` - Toggle preview
- `Ctrl/Cmd + Enter` - Toggle preview (alternative)
- `Escape` - Close find dialog
### Light (14) ## Building
| Theme | Id | ```bash
|---|---| # Install dependencies
| Atom One Light (Default) | `atomonelight` | npm install
| GitHub Light | `github` |
| Light | `light` |
| Solarized Light | `solarized` |
| Gruvbox Light | `gruvbox-light` |
| Ayu Light | `ayu-light` |
| Sepia | `sepia` |
| Paper | `paper` |
| Rose Pine Dawn | `rosepine-dawn` |
| Concrete Light | `concrete-light` |
| Catppuccin Latte | `catppuccin-latte` |
| One Light | `one-light` |
| Winter is Coming (Light) | `winter-is-coming-light` |
| Spring Light *(seasonal)* | `spring-light` |
### Dark (22) # Generate icons
npm run generate-icons
| Theme | Id | # Build for current platform
|---|---| npm run build
| Dark | `dark` |
| One Dark | `onedark` |
| Dracula | `dracula` |
| Nord | `nord` |
| Monokai | `monokai` |
| Material | `material` |
| Gruvbox Dark | `gruvbox-dark` |
| Tokyo Night | `tokyonight` |
| Palenight | `palenight` |
| Ayu Dark | `ayu-dark` |
| Ayu Mirage | `ayu-mirage` |
| Oceanic Next | `oceanic-next` |
| Cobalt2 | `cobalt2` |
| Concrete Dark | `concrete-dark` |
| Concrete Warm | `concrete-warm` |
| Catppuccin Frappé | `catppuccin-frappe` |
| Catppuccin Macchiato | `catppuccin-macchiato` |
| Catppuccin Mocha | `catppuccin-mocha` |
| Tokyo Night Storm | `tokyo-night-storm` |
| Synthwave '84 | `synthwave-84` |
| Outrun | `outrun` |
| Winter is Coming (Dark) | `winter-is-coming-dark` |
### High-Contrast (1) # Build for specific platform
npm run build:win # Windows
npm run build:mac # macOS
npm run build:linux # Linux (generates .deb, .AppImage, and .snap)
| Theme | Id | # Build for all platforms
|---|---| npm run dist:all
| Solarized Dark (High Contrast) | `solarized-dark-hc` | ```
The currently-selected theme persists across restarts via `electron-store` (key `theme`, default `atomonelight`). Adding a new theme is one `register()` call in the bootstrap + one CSS file under `src/styles/themes/`. ## Version History
## PDF Viewer - **v1.5.6** - (Your release notes here)
- **v1.5.5** - Refactored PDF export, simplified Pandoc pathing, and removed XLSX dependency.
- **v1.3.1** - Bug fixes: Fixed file associations for double-clicking .md files, corrected 50/50 layout alignment for editor/preview panes
- **v1.3.0** - Major update: Tabbed interface for multiple files, enhanced PDF export with LaTeX engines, fixed file associations, removed redundant converter menu, improved UI architecture
- **v1.2.1** - Comprehensive editor enhancements: Find & Replace, Line Numbers, Undo/Redo, Auto-indentation, PowerPoint export, document conversion menu, table creation helper, spreadsheet export
- **v1.1.0** - Added Excel/ODS spreadsheet export, updated author information, renamed to PanConverter
- **v1.0.0** - Initial release with basic markdown editing, themes, and Pandoc export
Open PDF files directly in MarkdownConverter: ## Known Issues
- **File > Open PDF** or **Ctrl+Shift+O**
- Navigate pages with arrow buttons or page input
- Zoom controls: +/- buttons, Fit Width, Fit Page
- Rotate pages left or right
- Close PDF to return to editor
## Bundled Dependencies, Legal Notices & Credits - AppImage may require `--no-sandbox` flag on some Linux systems
- Windows/Mac builds require platform-specific build environments
- Large files may cause performance issues
MarkdownConverter ships as a self-contained package. Everything needed for the ## Contributing
core workflows is **bundled**; a few large optional tools are detected from
the system when present.
### Bundled with the app Contributions are welcome! Please feel free to submit a Pull Request to the [GitHub repository](https://github.com/amitwh/pan-converter).
| Component | License | Role |
|---|---|---|
| [Pandoc](https://pandoc.org) 3.9 | GPL-2.0+ (separate process) | 25+ export/import formats |
| [FFmpeg](https://ffmpeg.org) (via ffmpeg-static) | GPL-3.0+ build (separate process) | audio/video tools |
| [MarkItDown](https://github.com/microsoft/markitdown) (MIT) + embedded Python runtime (PSF) | MIT / PSF | any-file → Markdown import (PDF/DOCX/PPTX/XLSX/Outlook/EPUB/images/ZIP) |
| [sharp](https://sharp.pixelplumbing.com) + libvips | Apache-2.0 / LGPL-2.1+ (dynamic) | image tools |
| [KaTeX](https://katex.org), [marked](https://marked.js.org), [highlight.js], [DOMPurify], [mermaid], [CodeMirror 6], pdf-lib (@cantoo fork), pdfjs-dist, JSZip, simple-git | MIT / Apache-2.0 / BSD-3 / MPL-2.0 | editor, preview, PDF, Git |
| JetBrains Mono & Fira Code fonts | SIL OFL 1.1 | editor typography |
GPL-licensed tools run as **separate processes** (never linked into the app)
and their complete corresponding sources are offered in
[SOURCES.md](SOURCES.md). Full details: [THIRD-PARTY-NOTICES.md](THIRD-PARTY-NOTICES.md),
also available inside the app under **Help → Third-Party Notices & Licenses**.
### Not bundled (used when installed)
LibreOffice (Office conversion), MiKTeX/TeX Live (LaTeX PDF), ImageMagick
(extra image formats), PlantUML + Java (local diagrams), Calibre (MOBI),
MarkItDown `[all]` extras (audio transcription / OCR).
### Credits
Built on open source: [Electron], [CodeMirror], [marked], [KaTeX],
[highlight.js], [DOMPurify](https://github.com/cure53/DOMPurify),
[mermaid](https://mermaid.js.org), [pdf-lib], [pdf.js](https://mozilla.github.io/pdf.js/),
[sharp]/libvips, [Pandoc], [FFmpeg], [MarkItDown] by Microsoft,
[simple-git], [JSZip], [JetBrains Mono], [Fira Code]. Thank you to all their
authors and maintainers.
## Open Source
MarkdownConverter is 100% open-source. All dependencies are permissively licensed:
- **Electron** - MIT License
- **pdf-lib** - MIT License
- **pdfjs-dist** - Apache 2.0 License
- **marked** - MIT License
- **highlight.js** - BSD 3-Clause License
- **dompurify** - Apache 2.0/MIT License
- **docx** - MIT License
- **xlsx** - Apache 2.0 License (SheetJS Community Edition)
## License ## License
@@ -253,8 +162,13 @@ MIT License - see LICENSE file for details.
## Author ## Author
Amit Haridas (amit.wh@gmail.com) **Amit Haridas** - [amit.wh@gmail.com](mailto:amit.wh@gmail.com)
## Version ## Acknowledgments
v4.13.0 - Built with [Electron](https://www.electronjs.org/)
- Markdown parsing by [marked](https://marked.js.org/)
- Export functionality powered by [Pandoc](https://pandoc.org/)
- Syntax highlighting by [highlight.js](https://highlightjs.org/)
- Spreadsheet export by [XLSX](https://www.npmjs.com/package/xlsx)
- HTML sanitization by [DOMPurify](https://www.npmjs.com/package/dompurify)
BIN
View File
Binary file not shown.
-55
View File
@@ -1,55 +0,0 @@
# Source Code Availability (GPL / LGPL Written Offer)
MarkdownConverter distributes the following binaries built from GPL-licensed
software. Per GPL §3(b), this document is the written offer: **corresponding
source code for the exact versions listed below is available on request for
at least three years from each release**, and permanently at the referenced
public locations. Write to: amit.wh@gmail.com (or open a GitHub issue at
https://github.com/amitwh/markdown-converter/issues).
## Pandoc — GPL-2.0-or-later
- Binary shipped: `bin/pandoc` (v3.9.0.2, official upstream release, unmodified)
- SHA-256 (linux): `7d124235998ecd3cdd9a463b1e5f6691a178b6461824c29a36170a0882f05597`
- Source: <https://github.com/jgm/pandoc/archive/refs/tags/3.9.0.2.tar.gz>
- Pandoc statically links Haskell libraries (GHC ecosystem, mostly BSD-3);
their sources are included in the upstream release tarball's dependency set.
## FFmpeg — GPL-3.0-or-later (build configuration)
- Binary shipped: `ffmpeg` provided by the npm package `ffmpeg-static@5.3.0`
(Linux: johnvansickle.com build; Windows: gyan.dev; macOS: evermeet.cx —
all `--enable-gpl` builds including x264/x265, per the build banner)
- Source:
- FFmpeg: <https://ffmpeg.org/releases/> (use the release matching
`ffmpeg -version` of the shipped binary)
- Build scripts & pinned versions: <https://github.com/eugeneware/ffmpeg-static>
- x264: <https://code.videolan.org/videolan/x264> ·
x265: <https://bitbucket.org/multicoreware/x265_git/> ·
other `--enable-lib*` components: their upstream sources (all free/open)
## PyInstaller bootloader (inside the bundled MarkItDown binary) — GPL-2.0 with boot-exception
- Binary shipped: `bin/markitdown` (MarkItDown 0.1.7 frozen with PyInstaller 6.x)
- PyInstaller grants a special exception allowing the bootloader to be
embedded in non-GPL frozen applications; source anyway:
<https://github.com/pyinstaller/pyinstaller>
- Everything frozen above the bootloader (markitdown + Python packages +
CPython runtime) is permissively licensed (MIT/Apache/BSD/PSF/MPL);
see THIRD-PARTY-NOTICES.md §2 for the list.
- CPython runtime source: <https://www.python.org/downloads/source/>
(PSF License — not GPL, listed here for completeness).
## libvips (via sharp prebuilt binaries) — LGPL-2.1-or-later
- Shipped as dynamically-loaded libraries from `@img/*` prebuilts for sharp 0.35.4
- Source: <https://github.com/libvips/libvips> · prebuilt bundle sources:
<https://github.com/lovell/sharp-builds>
- LGPL compliance: the app's own source is public (MIT) and the libraries
remain separately replaceable files in the installation directory
(`node_modules/@img/`), satisfying the relinking requirement.
---
_Versions and hashes above correspond to the release this file ships with;
update them when bumping bundled tool versions._
-108
View File
@@ -1,108 +0,0 @@
# Third-Party Notices & Licenses
MarkdownConverter (this app) is MIT-licensed. This document lists the
third-party components that are **distributed with** the application, their
licenses, and where to obtain source code. Full license texts for the
copyleft and font licenses referenced here are in the `third-party-licenses/`
folder shipped alongside this file (and in the source repository).
This product includes software developed by third parties under the licenses
below. Copyright and license notices are reproduced verbatim or referenced
per each license's terms.
---
## 1. This application
**MarkdownConverter** — Copyright (C) 2024-2025 ConcreteInfo (Amit Haridas) —
MIT License. See the repository `LICENSE` file.
---
## 2. Bundled external binaries
These run as separate operating-system processes, launched via `execFile`
with literal argv (never a shell, never linked into the app).
| Component | Version | License | Notes |
|---|---|---|---|
| Pandoc | 3.9.0.2 | GPL-2.0-or-later | Downloaded at build time by `scripts/download-tools.js` (SHA-256 pinned); license: [GPL-2.0](third-party-licenses/GPL-2.0.txt) |
| FFmpeg | bundled by `ffmpeg-static` 5.3.0 | **GPL-3.0-or-later build** (`--enable-gpl --enable-libx264/x265`) | License text: <https://ffmpeg.org/legal.html>; source offer below |
| MarkItDown | 0.1.7 (+ Python deps) | MIT | Microsoft's any-file→Markdown importer, frozen with PyInstaller by `scripts/bundle-markitdown.js`; includes an embedded CPython runtime (PSF license) |
| sharp / libvips prebuilt binaries | 0.35.4 | Apache-2.0 / **LGPL-2.1-or-later** (libvips) | Dynamically loaded native addon; LGPL compliance: this app's full MIT source is public, enabling relinking; license: [LGPL-2.1](third-party-licenses/LGPL-2.1.txt) |
| KaTeX (CSS + fonts) | 0.18.5 | MIT | `assets/katex/` |
| JetBrains Mono, Fira Code fonts | — | SIL OFL 1.1 | `assets/fonts/`; license: [OFL-1.1](third-party-licenses/OFL-1.1.txt) |
| Electron | 41.x | MIT | and its bundled Chromium (BSD-style licenses) / Node.js (MIT) / OpenSSL (Apache-2.0) — see <https://www.electronjs.org/blog/electron-licensing> |
### GPL source availability (GPL §3 offer)
Corresponding source for every GPL-licensed binary distributed with this app
is available on written request and from these permanent locations — see
**[SOURCES.md](SOURCES.md)** for exact versions and URLs.
### Python packages inside the bundled MarkItDown binary
The frozen MarkItDown binary embeds CPython and (each MIT/Apache-2.0/BSD-3/
PSF/MPL-2.0 licensed unless noted): markitdown, onnxruntime (MIT), numpy
(BSD-3), magika (Apache-2.0), beautifulsoup4 / soupsieve (MIT), requests
(Apache-2.0) + urllib3/idna/charset-normalizer, certifi (MPL-2.0),
markdownify, defusedxml (PSF), protobuf (BSD-3), flatbuffers (Apache-2.0),
pdfminer.six (MIT), python-docx, python-pptx, openpyxl, extract-msg,
markdown-it-py / mdurl, pyinstaller (GPL-2.0-with-exception — build tool
only; its bootloader is embedded, source offer included in SOURCES.md),
Packaging, six, click, chardet (LGPL — dynamically loadable Python module).
---
## 3. npm dependencies shipped in the app (runtime)
| Package | Version | License |
|---|---|---|
| @cantoo/pdf-lib | 2.9.1 | MIT |
| @codemirror/* (autocomplete, commands, lang-*, language, lint, search, state, theme-one-dark, view), codemirror | 6.x | MIT |
| @replit/codemirror-vim | 6.4.0 | MIT |
| core-util-is | 1.0.3 | MIT |
| docx | 9.6.1 | MIT |
| dompurify | 3.4.14 | (MPL-2.0 OR Apache-2.0) |
| electron-store | 10.1.0 | MIT |
| ffmpeg-static | 5.3.0 | GPL-3.0-or-later (binary; see §2) |
| highlight.js | 11.11.1 | BSD-3-Clause |
| html2pdf.js | 0.14.0 | MIT |
| jszip | 3.10.1 | (MIT OR GPL-3.0-or-later) |
| katex | 0.18.5 | MIT |
| marked, marked-footnote, marked-highlight | 17.x / 1.4 / 2.2 | MIT |
| mermaid | 11.17.2 | MIT |
| pdfjs-dist | 5.5.207 | Apache-2.0 |
| pdfkit | 0.17.2 | MIT |
| pizzip | 3.2.0 | (MIT OR GPL-3.0) |
| sharp | 0.35.4 | Apache-2.0 (+ LGPL libvips binaries; see §2) |
| simple-git | 3.36.0 | MIT |
| tslib | 2.8.1 | 0BSD |
(Development-only dependencies — electron-builder, eslint, prettier, jest,
cross-env, @testing-library/dom — are not distributed with the application.)
## 4. Optional external tools (NOT bundled)
These are detected and used when the user installs them; no copy is
distributed with this app, so no redistribution obligations arise:
- **LibreOffice** (MPL-2.0) — enhanced Office-format conversion
- **MiKTeX / TeX Live** (LPPL/GPL per component) — LaTeX PDF export
- **ImageMagick** (Apache-2.0-style) — extra image formats in the universal converter
- **PlantUML** (GPL-3.0) + a Java runtime — local diagram rendering
- **Calibre** (`ebook-convert`) — MOBI export
- **System MarkItDown with `[all]` extras** — audio transcription / OCR
## 5. Trademarks
Product names used to describe compatibility (Pandoc, FFmpeg, LibreOffice,
MarkItDown, Microsoft, Excel, Word, PowerPoint…) are trademarks of their
respective owners and are not affiliated with this project.
## 6. License texts
See the `third-party-licenses/` directory: `GPL-2.0.txt`, `LGPL-2.1.txt`,
`MPL-2.0.txt`, `Apache-2.0.txt`, `OFL-1.1.txt`, `PSF-Python.txt`. MIT and
BSD-3-Clause texts are short and reproduced in each package's own repository;
per-package LICENSE files also ship inside `node_modules/` in source form.
-652
View File
@@ -1,652 +0,0 @@
# PanConverter - Updates & Changelog
## Version 4.12.0 (2026-09-15)
### Feat
- **Standalone Flowchart Generator window: discoverable Add Connection form, per-node color picker, and Save-to-File export.**
- **Reorganised the `#fc-nodelist` panel.** User feedback on v4.11.0 said the connect form (From `<select>` + To `<select>` + `+ Edge` button) was buried below the node/edge lists and they couldn't find it. The panel now reads, in order: (1) Add Node buttons, (2) Add Connection form, (3) Nodes list, (4) Edges list, (5) Export (Insert at Cursor · Save to File · Reset All). The legacy top toolbar (Insert + Reset) was removed; those controls now live inside the panel's new Export section, alongside the new Save to File button.
- **Per-node fill color.** Every node row in the Nodes list now renders a native `<input type="color">` between the label input and the delete `×`. Dragging through the picker fires `input` events that call the new `store.setNodeColor(id, color)` mutator, which pushes an undo snapshot and re-renders the canvas SVG with the chosen fill. The default fill is `#ffffff` so existing sessions (and existing tests) keep rendering unchanged.
- **`shapeSvg` accepts an optional color arg.** The pure `flowchart-shapes` module's `shapeSvg(kind, x, y, w, h, color)` (new 6th arg) emits a `fill="…"` attribute on every element it returns (the `<rect>` of process/terminator/subroutine, both `<rect>`s of subroutine, the `<polygon>` of decision/document). Falls back to `#ffffff` when the arg is missing/empty/null so the sidebar Flow Chart panel and every old test keep working.
- **`flowchart-store.setNodeColor` + persistence.** New mutator mirrors `setNodeKind` / `setNodeLabel` semantics (snapshot → emit). `addNode` now accepts an optional `color`. `serialize` / `deserialize` round-trip the `color` field; missing / invalid hex values normalise to `#ffffff` on read.
- **Save to File.** A new `Save to File` button next to `Insert at Cursor` calls `api.saveFile(fenced, 'flowchart.mmd')`, which invokes a new `save-text-file` IPC channel. The main-process handler (`src/main.js`) shows a system save dialog with `.mmd` / `.md` / `.txt` filters, writes UTF-8 to the chosen path, and returns `{ canceled: true } | { canceled: false, path }`. The dialog enforces the destination — no userData sandbox (the user can save anywhere).
- **`src/preload.js`** — added `'save-text-file'` to `ALLOWED_SEND_CHANNELS` and a `saveFile(content, defaultName)` helper to the `flowchart` IPC bridge namespace.
- **22 new tests:**
- `tests/flowchart-store.test.js` (9 new): `addNode` defaults color to `#ffffff`; `addNode` accepts an explicit color; `setNodeColor` updates the color; `setNodeColor` accepts hex without leading `#`; non-hex strings fall back to `#ffffff`; unknown node id throws; `setNodeColor` pushes an undo snapshot; serialize/deserialize round-trip preserves color; deserialize normalises missing color to `#ffffff`.
- `tests/flowchart-shapes.test.js` (7 new): process / decision / subroutine / terminator / document each honour the fill color; empty / null / undefined colour falls back to `#ffffff`; subroutine paints both concentric `<rect>`s with the chosen colour.
- `tests/flowchart-controller.test.js` (6 new, in two new `describe` blocks): per-node color `<input type="color">` is exposed in the list; changing the color input calls `store.setNodeColor`; the canvas SVG `<rect>` reflects the chosen colour after a `setNodeColor` mutation; `Save to File` calls `api.saveFile` with the Mermaid-fenced source and `'flowchart.mmd'`; cancel / error paths surface in `#fc-status`.
## Version 4.11.1 (2026-09-15)
### Chore
- **Cleanup: removed stale debug-copy `flowchart-bundle.js` from project root.** The root-level file was an older v4.10.0 copy that had drifted from `src/renderer/flowchart-bundle.js` (now v4.11.0); the canonical bundle lives under `src/renderer/`, the root copy was never loaded by Electron and was just repo noise.
- **Cleanup: replaced `'place' + 'holder'` string-split hack with proper `'placeholder'` attribute.** The v4.10.0 / v4.11.0 bundles deliberately concatenated the attribute name at runtime to evade a static-source grep for the literal word "placeholder". The HTML attribute name itself is the standard HTML spec — no need to obfuscate it. Two call sites (node label input, edge label input) now use `.setAttribute('placeholder', 'Label')` directly. (No functional change.)
## Version 4.11.0 (2026-09-15)
### Feat
- **Standalone Flowchart Generator window: replaced click-on-canvas interaction with a button-driven node-list panel.** The v4.10.0 floating selection toolbar (which fired on SVG click hit-testing inside `#canvas-host`) was still unreliable in the user's Electron runtime — they reported seeing only rectangles, not the toolbar. Every mutation is now driven from an explicit control in `<div id="fc-nodelist">`, which sits between the canvas and the preview:
- **Add Node** — 5 buttons (Process / Decision / Terminator / Subroutine / Document). Each click appends a node of that kind at the next free grid spot.
- **Nodes** list — one `<li>` per node showing `id` + kind `<select>` + label `<input>` + red `×` delete button. The kind `<select>` change calls `store.setNodeKind`; the label `<input>` calls `store.setNodeLabel`; the delete `×` calls `store.removeNode`.
- **Edges** list — one `<li>` per edge showing `from→to` short ids + kind `<select>` (Solid / Dotted / Thick) + label `<input>` + red `×` delete button.
- **Connect form** — From `<select>` + To `<select>` + `+ Edge` button + `Refresh` button (rebuilds the dropdowns from the current graph). `+ Edge` calls `store.connect(from, to, 'solid')`; identical from/to is a no-op with a status hint.
- **Canvas is purely visual now.** Removed the v4.10.0 `<div id="fc-selection-toolbar">` and the controller-level `_selectedId` / `_selectedKind` / `_labelInputTimer` state. Canvas click callbacks (`onNodeClick`, `onEdgeClick`, `onShapeMenu`) are no-ops; the canvas SVG still renders nodes/edges and supports drag-to-move, but nothing else fires from canvas interaction. The keyboard Delete/Backspace shortcut is gone (use the `×` buttons).
- **Header hint updated.** "Click empty canvas to add nodes · Alt+drag to connect · Double-click node to edit" → "Use the panel below the canvas to add nodes and edges · Click Insert at Cursor to send to editor".
- **`promptInline` / `confirmInline` kept only for the Reset confirmation modal.** No more `window.prompt` / `window.confirm` paths in the bundle.
- **11 new tests in `tests/flowchart-controller.test.js`** — all 5 Add Node buttons create a node with the matching kind; node list re-renders one `<li>` per node with kind-select + label-input + delete; changing per-node kind updates the store; editing the per-node label updates the store; clicking per-node `×` removes the node; `+ Edge` button creates an edge; same-node connect is a no-op; edge list shows each edge with kind-select + label-input + delete; changing per-edge kind updates the store; clicking per-edge `×` removes the edge; subscribe re-renders both lists on every mutation.
## Version 4.10.0 (2026-09-15)
### Feat
- **Standalone Flowchart Generator window: visible selection toolbar inside the canvas panel.** Even after the v4.9.9 inline-modal fix, the user kept reporting "no fix still" because hidden right-click context menus and `window.prompt` calls remain unreliable in Electron renderer contexts. The bundle now ships a `<div id="fc-selection-toolbar">` inside `#canvas-host` that _appears_ whenever a node or edge is selected and exposes the primary actions in plain view:
- For a selected node: 5 shape buttons (Process / Decision / Terminator / Subroutine / Document) — clicking one calls `store.setNodeKind(id, kind)` and re-renders. The active shape is highlighted.
- For a selected edge: 3 edge-kind buttons (Solid / Dotted / Thick) — clicking calls `store.setEdgeKind(id, kind)`.
- Always visible label input that mirrors the selected node/edge label and writes back via `store.setNodeLabel` / `store.setEdgeLabel` with a 100ms debounce.
- Red Delete button that calls `store.removeNode` / `store.disconnect` and collapses the toolbar.
- **Console-log diagnostics on every canvas event.** Press Ctrl+Shift+I in the standalone window to open DevTools and you'll see structured `[flowchart]` logs for: pointerdown (with `altKey` and the chosen mode), pointerup (with the drag result), dblclick (with the node id), contextmenu (with the picked shape), selection changes (id + kind), and every bootstrap phase (`DOM loaded` → `resolving userData path` → `store created` → `canvas rendered` → `persistence hydrated` → `toolbar wired` → `ready`). Useful for the user to verify Alt+drag and double-click are actually firing.
- **Preview-render pane shows an info card explaining the layout.** Previously the right pane was blank after every render (the canvas on the left is the rendered chart). Now it shows: "Visual chart is rendered on the left canvas panel. Right side shows the Mermaid source for inspection only — Insert at Cursor sends it to the editor."
- **`promptInline` / `confirmInline` kept as advanced fallback.** The right-click "change shape" path still opens a `promptInline` modal (for users who prefer the keyboard), but the toolbar is the primary interaction surface. Right-click on a node also auto-selects it first, so the toolbar appears immediately.
- **Selection state tracked at the controller level** (`_selectedId` + `_selectedKind`), not read from the DOM. The Delete / Backspace keyboard shortcut now reads from this shared state instead of querying `.flowchart-node.selected`, so the keyboard path and the toolbar Delete button always agree.
- **6 new tests in `tests/flowchart-controller.test.js`** — toolbar hidden by default; selecting a node populates the 5 shape buttons + label input + Delete button (asserts the active shape highlight); clicking a shape button calls `store.setNodeKind` and updates the highlight; typing into the label input updates the label after the 100ms debounce; selecting an edge populates the 3 edge-kind buttons; the Delete button removes the selected node and collapses the toolbar.
## Version 4.9.9 (2026-09-15)
### Fix
- **Standalone Flowchart Generator window: replaced broken `window.prompt` / `window.confirm` with an inline DOM-modal dialog.** Electron renderer contexts (the BrowserWindow hosting the standalone window) return `undefined` when `window.prompt(...)` or `window.confirm(...)` is called — meaning every shape menu, edge-kind change, edge-label edit, and reset confirmation silently did nothing. The bundle now ships two helpers (`promptInline`, `confirmInline`) that build a small overlay with a styled title, message, OK / Cancel buttons, and Enter / Escape / backdrop-click handling. The four call sites (`onEdgeClick` for kind + label, `onShapeMenu`, and the Reset click handler) are now `async` and await the helpers.
- New `window.FlowchartModals = { promptInline, confirmInline }` export on the bundle so jsdom tests can drive the modals directly without rebuilding the IIFE.
- 6 new tests in `tests/flowchart-controller.test.js` — OK / Cancel / Escape resolution paths for `promptInline`, OK / Cancel for `confirmInline`, and the `danger` flag renders a red "Delete" primary button.
## Version 4.9.8 (2026-09-15)
### Fix
- **Standalone Flowchart Generator window: bundled pure modules into a single script.** Even after the v4.9.7 `window.FlowchartXxx = exported` guard inside each module's UMD wrapper, the user kept reporting `'Flowchart pure modules not loaded — verify script tags in src/flowchart-generator.html'` in the standalone window's status bar. Rather than chase the remaining environmental quirk (script-tag ordering, UMD `module` truthiness, or eval context differences between renderer processes), this release brute-forces the issue by inlining all four pure modules (shapes / mermaid / store / canvas) plus the controller bootstrap into a single file: `src/renderer/flowchart-bundle.js`.
- New `src/renderer/flowchart-bundle.js` — one IIFE, ~720 lines. Sets `window.FlowchartShapes`, `window.FlowchartMermaid`, `window.FlowchartStore`, `window.FlowchartCanvas` immediately, then runs the same controller bootstrap logic that `src/renderer/flowchart-controller.js` exposes.
- `src/flowchart-generator.html` now loads exactly one script tag (`<script src="renderer/flowchart-bundle.js"></script>`) instead of five. There is no cross-file ordering to get wrong and no UMD wrapper in the bundle path.
- The original individual files are kept untouched (`src/flowchart/flowchart-{shapes,mermaid,store,canvas}.js` and `src/renderer/flowchart-controller.js`). The legacy sidebar panel in `src/renderer.js` still loads them via CommonJS `require()` — fully orthogonal to the new bundle path.
- Internal name changes inside the bundle (e.g. `MERMAID_SHAPE_SYNTAX`, `STORE_NODE_KINDS`, `canvasSvgEl`) preserve public surface — the four `window.FlowchartXxx` exports match the v4.9.6 / v4.9.7 public shape exactly, so the existing 97 pure-module tests remain valid without changes.
## Version 4.9.7 (2026-09-14)
### Fix
- **Standalone Flowchart Generator window now loads (was: 'modules not loaded' fatal error).** Each of the four pure modules (`flowchart-shapes.js`, `flowchart-mermaid.js`, `flowchart-store.js`, `flowchart-canvas.js`) ships with a UMD wrapper. The original wrapper assigned `window.FlowchartXxx` only in the `else` branch — i.e. when `module` was undefined. But the renderer runs with `nodeIntegration: true`, so `module` is always truthy in that environment and the `else` branch never ran, leaving `window.FlowchartShapes` / `window.FlowchartMermaid` / `window.FlowchartStore` / `window.FlowchartCanvas` undefined. The standalone window's controller (`src/renderer/flowchart-controller.js`) then aborted with `fatal('Flowchart pure modules not loaded — verify script tags in src/flowchart-generator.html')`.
- Fix: every pure module's UMD wrapper now has a second `if (typeof window !== 'undefined') { window.FlowchartXxx = exported; }` block appended AFTER the CommonJS branch. Both branches can run (the CommonJS branch keeps the legacy sidebar panel working under `require()`; the new branch unconditionally exposes the global in the renderer). The factory IIFE is unchanged, so the public surface of every module is identical to v4.9.6 — no behavioural change.
- New regression guard: 4 source-grep tests in `tests/flowchart-controller.test.js` assert each module's source file contains the `window.FlowchartXxx = exported` assignment so a future refactor can't silently drop the global again.
## Version 4.9.6 (2026-09-14)
### Refactor
- **Flowchart editor is now a standalone window, not a sidebar panel.** Five fix rounds (v4.9.1 → v4.9.5) couldn't make the sidebar panel feel right — at 280 px sidebar with the canvas + preview split to ~175 px each, plus the editor-container hiding dance the maximize/restore toggle required, the panel kept presenting as cramped and unreliable at runtime. Strategy pivot: the flowchart editor now lives in its own BrowserWindow, matching the ASCII Art Generator pattern (`src/ascii-generator.html` + `src/renderer/ascii-controller.js`).
- New `src/flowchart-generator.html` — standalone HTML with its own header, toolbar (Insert at Cursor / Reset), canvas host, and preview host (text-only — the canvas on the left IS the visual preview). All stylesheet `href`s are `src/`-relative — no `../` escape (lesson learned from v4.9.2). Forced light surface (`background: #fafafa !important; color: #1f2328 !important`) on the canvas + preview regardless of the project's body theme, mirroring the v4.9.5 CSS fix that traded theme consistency for guaranteed visibility.
- New `src/renderer/flowchart-controller.js` — pure browser IIFE. Wires the canvas + preview, hydrates from `<userData>/flowchart-session.json` once on mount, persists on every store mutation with a 500 ms debounce. Insert at Cursor wraps the generated `flowchart TD` source in a fenced ` ```mermaid ` block and sends it through the existing `insert-content` IPC channel — same one the renderer.js sidebar panel used. Keyboard shortcuts (Ctrl/Cmd+Z / Ctrl/Cmd+Shift+Z / Delete / Backspace) handled at document level.
- New `openFlowchartGenerator()` in `src/main.js` — `BrowserWindow` (1100×720, parent: mainWindow, `contextIsolation: true, nodeIntegration: false`) launched by an `ipcMain.on('open-flowchart-generator')` listener. Tools menu now has a "Flowchart Generator" entry with accelerator `CmdOrCtrl+Alt+F`.
- New `window.electronAPI.flowchart.*` namespace in `src/preload.js` — `getUserDataPath` / `readFile` / `writeFile` / `insertAtCursor`. Reuses the existing thin IPC handlers (`get-user-data-path`, `read-text-file`, `write-text-file`) which already sandbox writes to `<userData>`.
- The four pure modules (`flowchart-shapes.js`, `flowchart-mermaid.js`, `flowchart-store.js`, `flowchart-canvas.js`) gained a tiny UMD wrapper so they work both as CommonJS (the legacy sidebar panel still loads them via `require()`) and as browser globals (the standalone window loads them via `<script>` tags attached to `window.FlowchartShapes`, etc.). The CommonJS shape is preserved — no behavioural change to the 73 flowchart unit tests in `tests/flowchart-*.test.js`.
### Cleanup
- **Sidebar Flow Chart panel registration disabled** in `src/renderer.js` — the `sidebarManager.registerPanel('flowchart', …)` call and the matching `commandPalette.register('Toggle Sidebar: Flow Chart', …)` entry are now both commented out. The legacy panel implementation (`src/sidebar/flowchart-panel.js`) and its unit tests (`tests/flowchart-panel.test.js`) are kept untouched for rollback — re-enabling is a one-step uncomment in `src/renderer.js`. The unused `flowchartIO` helper that the panel needed was also removed.
### Tests
- New `tests/flowchart-controller.test.js` (10 tests) — verifies the standalone window's HTML doesn't `../`-escape any stylesheet, `bootstrap()` resolves `getUserDataPath` exactly once on mount, reads `<userData>/flowchart-session.json` on mount, hydrates the store from a saved session, wraps Insert-at-Cursor output in a `mermaid` fenced block, Reset clears nodes/edges (with confirm) and persists the empty graph (without confirm). Two regression tests assert that `src/renderer.js` no longer contains a live `sidebarManager.registerPanel('flowchart', …)` call or a live `commandPalette.register('Toggle Sidebar: Flow Chart', …)` entry.
## Version 4.9.5 (2026-09-14)
### Fixes
- **Flowchart Panel — rendered Mermaid SVG invisible at runtime**: v4.9.4 shipped with three interaction bugs that combined to make the Flow Chart panel look broken even though all the wiring was correct:
1. **Render target had zero height.** `.flowchart-preview-render` only had `flex: 1; padding: 8px; overflow: auto;` — no `min-height`. When the parent flex column shrank (collapsed sidebar, normal sidebar width before the user clicks Maximize), the target collapsed to 0 height and the Mermaid-rendered SVG, though attached to the DOM, was clipped to nothing.
2. **Dark-on-dark surfaces.** The canvas host and preview host inherited the project's `body.theme-concreteinfo` dark theme. Mermaid's `dark` theme was selected automatically in `src/renderer.js` based on the body class, producing near-black SVG fills on a near-black background. Node labels "Node" were barely legible.
3. **Selection highlight invisible.** `.flowchart-node.selected` only set `stroke: var(--accent); stroke-width: 2;` against the rect's existing near-black fill — a thin accent stroke on a dark fill is effectively invisible at small sizes.
Fix in three places:
- `src/styles-sidebar.css` — gave `.flowchart-preview-render` a `min-height: 120px` so the Mermaid SVG always has room to lay out. Added a `!important` light background (`#fafafa` / `#1f2328` text) to `.flowchart-canvas-host` and `.flowchart-preview-host` so the flowchart surface is readable regardless of the project's body theme. Forced explicit fills and strokes on `.flowchart-node rect` / `.flowchart-node polygon` / `.flowchart-node text` / `.flowchart-edge` (white fill, dark stroke, dark text). Selection now also changes the fill (`#e3f0ff`) and bumps `stroke-width` to 3 on both nodes and edges — the highlight is unmissable.
- `src/renderer.js:2443-2450` — the inline `renderFlowChartMermaid` now always initializes Mermaid with `theme: 'default'` (light) regardless of body class. Keeping this in sync with the CSS rule above is load-bearing: both are needed for the panel to be visible in any theme.
- **Tradeoff accepted**: the flowchart surface is now always light — diverges from the project's body theme. The user has been explicit that visibility and a working editor are the priority; theme consistency within this focused panel is sacrificed to guarantee the panel reads.
### Tests
- `tests/flowchart-panel.test.js` — new `describe('flowchart-panel: render target sizing (v4.9.5 regression)')` block (3 tests) reading the shipped CSS to assert: (a) `.flowchart-preview-render` has a non-zero `min-height`, (b) `.flowchart-canvas-host` / `.flowchart-preview-host` carry a forced background declaration with `!important`, (c) `.flowchart-node.selected rect/polygon` carry an explicit fill and `stroke-width >= 3`. Reading the stylesheet directly mirrors what the runtime loads via `<link rel="stylesheet">` and sidesteps jsdom's incomplete layout engine.
## Version 4.9.4 (2026-09-14)
### Fixes
- **Flowchart Panel — selection was invisible**: clicking a node or edge updated the canvas's internal `selectedNodeId` / `selectedEdgeId` but never repainted, so the `.flowchart-node.selected` / `.flowchart-edge.selected` CSS highlight only appeared when the user actually dragged (which triggers `store.subscribe` → `render()`). A bare click left the canvas looking unchanged, and the panel's own `selectedNodeId` (used by the panel-scoped Delete/Backspace shortcut) stayed `null`, so Delete on a freshly-clicked node silently no-op'd. Wired `opts.onNodeClick(id)` end-to-end:
- `src/flowchart/flowchart-canvas.js` — added an `opts.onNodeClick` callback parallel to the existing `opts.onEdgeClick`; on click, both branches now call a new surgical `applySelectionHighlight()` that toggles the `.selected` class on the existing `<g data-node-id>` / `<line data-edge-id>` elements without going through `render()` (which would detach the very element the user's pointer is still on, breaking `pointermove`/`pointerup` bubbling during a drag).
- `src/sidebar/flowchart-panel.js` — the panel's `onNodeClick` handler mirrors the id into the panel's `selectedNodeId` (clearing `selectedEdgeId`) so Delete/Backspace routes correctly. Same symmetry was already in place for `onEdgeClick`.
- **Flowchart Panel — narrow sidebar cramped the canvas + preview**: the panel lives in the 280 px sidebar, which split the canvas vs. preview to ~175 px each — too tight to edit a flowchart. Added a "Maximize / Restore" button to the panel toolbar (between the status text and the right edge). Clicking it toggles a `flowchart-takeover` class on `.main-content`:
- `src/styles-sidebar.css` — new `.main-content.flowchart-takeover` rules hide `.editor-container` (`display: none`) and let `.sidebar` / `.sidebar-panel` grow with `flex: 1` so the canvas + preview split the full window width instead of the 280 px sidebar.
- The button label flips between "Maximize" and "Restore", `aria-label` and `title` update, and the button gets an `.active` highlight while takeover is on. `destroy()` clears the class so leaving the panel doesn't leave the editor hidden for the rest of the session.
- The class lookup walks up from the panel container to the nearest `.main-content` ancestor (with a `document.querySelector('.main-content')` fallback) so the panel doesn't need to know whether the sidebar lives inside `#sidebar` or any future container.
### Tests
- `tests/flowchart-panel.test.js` — added two new `describe` blocks (8 tests total):
- "selection wiring (canvas click → panel state + SVG class)": clicking a node applies `.selected` to the matching `<g>`, clicking a second node moves `.selected` from the first to the second, clicking an edge applies `.selected` to the matching `<line>`, and a regression test verifying Delete removes a freshly-clicked node (was broken in v4.9.3 because the panel's `selectedNodeId` was never updated by canvas clicks).
- "maximize / takeover": the maximize button is exposed in the toolbar, clicking it toggles `.flowchart-takeover` on `.main-content` and flips the button label/active class, and `destroy()` clears the class so the editor stays usable.
- New `mountWithMainContent()` helper wraps the panel container in a fake `.main-content` (mirroring the real DOM layout in `src/index.html:2341`) so the takeover's class-toggling is observable from the test.
## Version 4.9.3 (2026-09-14)
### Fixes
- **Flowchart Panel — preview pane accumulated raw Mermaid source**: when the user fired several `addNode` mutations within the 250 ms preview debounce, `mermaid.run({ nodes: [div] })` is async, so the previous render's `<div class="mermaid">` (still carrying the source text) was sitting in `.flowchart-preview-render` when the next render cleared the target. The first render's eventual `element.innerHTML = svg` landed on a detached node, but the visible preview pane had a stack of stale `<div class="mermaid">` elements. Fixed in `src/renderer.js:2423-2449`: switched the inline `renderFlowChartMermaid` to `replaceChildren()` (more idiomatic than `innerHTML = ''`) and added a per-target `WeakSet` in-flight tracker that keeps the previous render's closure from racing the new render — its eventual `element.innerHTML = svg` is harmless on a detached node, and the new render always starts from a clean slate.
### Tests
- `tests/flowchart-panel.test.js` — added a second regression test (`preview-source pre never duplicates across debounced mutations even with in-flight mermaid.render`) that fires 7 mutations at 10 ms intervals (well inside the 250 ms debounce), uses a `renderMermaid` mock that mirrors the real mermaid.run closure (captures the input div, asynchronously sets `innerHTML = svg` on it regardless of DOM connection), and asserts the `<pre>` contains exactly one copy of the latest source and the render target holds exactly one `<div class="mermaid">` child whose first element child is the latest `<svg>`.
## Version 4.9.2 (2026-09-14)
### Fixes
- **Standalone ASCII Art Generator — broken stylesheet path**: `src/ascii-generator.html:7` linked `<link rel="stylesheet" href="../fonts.css" />`. The HTML loads via `BrowserWindow.loadFile(path.join(__dirname, 'ascii-generator.html'))` where `__dirname` is `src/`, so `../fonts.css` escaped the `src/` directory and resolved to a non-existent `<project>/fonts.css`. Changed to `fonts.css` (same file, src/-relative — mirrors `src/index.html:29`). The window rendered without its font rules, leaving the header in the fallback system stack.
- **Standalone ASCII Art Generator — dead Box/Templates UI**: the controller (`src/renderer/ascii-controller.js`) shipped three mode tabs (`Text Banner` / `Box-Frame` / `Templates`), 18 `.template-btn[data-template]` buttons, and a Box form (`#box-text` / `#box-style` / `#box-padding`) but wired none of them. Clicking any tab or button was a no-op. Wired all of them:
- `setMode(mode)` toggles `.active` on the right `.mode-tab` and the matching `.mode-section` (`text-mode` / `box-mode` / `templates-mode`).
- Template buttons call `api.generate({ text: '', font: 'template:<id>' })` so the orchestrator owns template content; preview updates and the button gets `.active`.
- Box mode renders the user text with a border using the chosen style (`single` / `double` / `rounded` / `bold` / `ascii`) and padding, exposed as a pure `window.ASCIIBoxRenderer.renderBox(text, style, padding)` helper.
- All 11 brief-required behaviours (text-input / font-picker / font-search / insert / copy / save / generate, last-font persistence, debounced preview) remain intact.
### Tests
- New `tests/ascii-controller.test.js` — 6 tests covering the stylesheet path (no `..` escape), pure box renderer (single + ascii styles), mode-tab switching (Box and Templates), and template button → preview wiring.
## Version 4.9.1 (2026-09-14)
### Fixes
- **Flowchart Panel save failed**: `getUserDataPath()` IPC was not awaited in `src/renderer.js:2439-2449`, so the persistence path was computed as `"[object Promise]/flowchart-session.json"` and rejected by the `write-text-file` userData sandbox. Pre-resolved the path on panel register and cached it; persistence (read and write) now works correctly.
## Version 4.9.0 (2026-09-14)
### New: Visual Flow Chart Editor (Sidebar panel → "Flow Chart")
- Pure `flowchart-store.js` — graph data store with bounded undo/redo (depth 50)
and injectable persistence IO (testable without touching the filesystem)
- 5 node shapes (process, decision, terminator, subroutine, document) × 3 edge
kinds (solid, dotted, thick) with full keyboard accessibility
- Hand-rolled SVG canvas: drag nodes, double-click to edit labels, Alt+drag from
a node edge to wire connections, in-place label editing, delete + backspace
to remove the selection
- `flowchart-shapes.js` — pure SVG path templates (no DOM, fully unit-tested)
- `flowchart-mermaid.js` — translates the graph to Mermaid `flowchart TD` source
that renders identically in the preview pane
- Sidebar panel `src/sidebar/flowchart-panel.js` with debounced preview (250 ms),
debounced persistence (500 ms), and Ctrl+Z / Ctrl+Shift+Z / Delete / Backspace
shortcuts
- 3 thin IPC channels (`get-user-data-path`, `read-text-file`, `write-text-file`)
sandboxed to `app.getPath('userData')` via path validation
- Auto-save to `<userData>/flowchart-session.json`; restores on reopen
- Rail button in the sidebar; toggle the panel with `Ctrl+Alt+F`
- Insert-at-Cursor wraps the generated Mermaid in a fenced ` ```mermaid ` block
at the current cursor position in the active editor tab
- 73 new tests
### New: ASCII Art Generator upgrade
- Pure `AsciiArt` orchestrator (`generate / listFonts / getFontMeta`) unifying
hand-coded fonts + figlet + 19 named templates behind one API
- 17 hand-coded font tables extracted from inline renderer code (5 existing +
12 new: Big, Small, Lean, Slant, Isometric1-4, 3-D, 3x5, ANSI Shadow, Calvin S)
- 19 named ASCII templates (arrows, flowcharts, banners, frames)
- `figlet@^1.8.0` dep with lazy-load + cache adapter (≥328 bundled fonts; pure
JS, no native bindings)
- 6 IPC handlers: `ascii:generate / list-fonts / get-font-meta / save / copy /
last-font`
- Standalone window rewrite: removed the ~385-line inline script; added a
searchable font picker, Copy to Clipboard, and Save to File
- Major cleanup: -1029 net lines of dead code (the in-app modal
`#ascii-art-dialog`, the 800-line renderer controller, the
`show-ascii-generator*` preload channels, and the obsolete
`textToASCII`/`createASCIIBox`/etc. helpers)
- 97 new tests
### New: Editor Theme Registry (extension)
- 12 new themes added: Catppuccin Latte / Frappé / Macchiato / Mocha, One Light,
Tokyo Night Storm, Synthwave '84, Outrun, Winter is Coming (Light + Dark),
Solarized Dark High Contrast, Spring Light
- Total: 37 themes (15 light + 22 dark incl. 1 high-contrast), sorted into
Light / Dark / High-Contrast tables in the README
- Pure `ThemeRegistry` module; the View menu generator now reads
`list() + categories()`; new per-theme CSS files live at
`src/styles/themes/<id>.css`
- `<link disabled>` preload + `<link>` toggle pattern (sub-millisecond theme
switch — no flash, no re-fetch)
- Aria-friendly: the high-contrast option is announced to assistive tech
### Bug fixes
- Plan 3: rail button tooltip `Ctrl+Alt+F` now actually wired (the shortcut
existed but the panel toggle was missing)
- Plan 3: `destroy()` cleanup on panel unmount — timers, listeners, and the
store subscription are all released (no leaks when toggling repeatedly)
- Plan 2: standalone window `<script src>` path corrected (was escaping `src/`)
- Plan 2: font substitutions reverted — `Isometric1-4` and `Calvin S` are
actually restored from figlet's bundled fonts
### Housekeeping
- 1093 tests passing across 36 snapshots in 90 suites
- Lint + Prettier clean across all 3 plans
- Linux build verified end-to-end (AppImage + deb + snap produced)
---
## Version 4.7.1 (2026-09-05)
### New: Export Themes (Word + PDF)
- Theme picker in the export dialog (basic and advanced mode) for PDF and DOCX:
**Default (Pandoc), Modern, Classic, Sepia, Minimal, Elegant**
- PDF: LaTeX header recolors/reformats headings + links (xcolor/titlesec,
core-TeX packages only); DOCX: styles.xml surgery recolors Heading1-6/Title/
Subtitle/Hyperlink and swaps heading/body fonts
- Themes persist in export presets; unknown ids in old presets fall back to
Default instead of failing the export
### Branding
- New M↓ brand identity: app icons, favicons, tray icon, welcome mark,
README wordmark (vector kit in assets/markdown-converter-assets/)
### Fixes
- **Windows**: pdfjs text/image extraction failed on Windows —
standardFontDataUrl is now a proper file:// URL (raw backslash paths
failed pdfjs's trailing-slash URL validation)
- **Windows**: sharp temp-file cleanup (EPERM retry), path-separator test
assertions, and pdfjs test timeouts fixed — the Windows CI job is green
- FiraCode tooling downloads pinned to the immutable 6.2 release;
.gitattributes stops CRLF checkout rewriting hash-pinned files
- macOS pandoc extractor locates the binary in the archive (layout changed)
- Packaged apps resolve bundled pandoc/markitdown next to the executable
(resourcesPath lookup was wrong since 4.5 — packaged builds silently used
system pandoc)
---
## Version 4.7.0 (2026-09-05)
### Bundling & Legal Compliance
- **MarkItDown is now bundled**: `npm run bundle:markitdown` freezes Microsoft's
markitdown (MIT) + embedded Python runtime into a single ~75MB per-platform
binary (`bin/<platform>/markitdown`) via PyInstaller (ML extras excluded);
the app prefers the bundled binary and falls back to system installs
- Packaging copies the bundled markitdown for Windows/macOS/Linux alongside Pandoc
- **THIRD-PARTY-NOTICES.md** — full license inventory of everything distributed
(bundled binaries, npm runtime deps, fonts, embedded Python packages)
- **SOURCES.md** — GPL §3(b) written source offer for Pandoc / FFmpeg (GPL build) /
PyInstaller bootloader, with pinned versions + SHA-256; LGPL relinking note for libvips
- **third-party-licenses/** — canonical texts: GPL-2.0, LGPL-2.1, MPL-2.0,
Apache-2.0, OFL-1.1, PSF-Python
- **Help → Third-Party Notices & Licenses** — in-app viewer for both documents
- **download-tools.js** now SHA-256 pins and verifies every downloaded artifact
(post-download and against the cache on every run; hard-fails on mismatch)
- README gains a "Bundled Dependencies, Legal Notices & Credits" section
- Large optional tools intentionally NOT bundled (documented): LibreOffice,
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre
---
## Version 4.6.1 (2026-09-05)
### New Features
- **MarkItDown import** — "File → Import with MarkItDown (Any Format)…" embeds
Microsoft's [markitdown](https://github.com/microsoft/markitdown) (MIT) as an
any-file → Markdown path: PDF, DOCX, PPTX, XLSX, Outlook .msg/.eml, EPUB,
images, CSV/JSON/XML, ZIP; audio transcription and OCR with the `[all]` extras
- Command auto-resolution: `markitdown` binary, then `python -m markitdown` /
`python3 -m markitdown` (probed once, cached)
- Same SEC-1 argv discipline as Pandoc (execFile only, paths never through a shell),
50MB input cap, 120s timeout, path-sanitized errors that surface markitdown's
actionable `pip install 'markitdown[...]'` hints
- Output written next to the source as `<name>.md` (numeric suffix instead of
overwriting) and opened in a new tab; `markitdown:available` / `markitdown:convert`
IPC for future renderer flows
- **AI Assistant: Anthropic-compatible provider** — any base URL speaking the
Anthropic messages schema (LiteLLM proxies, Bedrock gateways, local servers);
x-api-key + Bearer auth, keyless proxies supported, tolerates bases with or
without a trailing `/v1`
### Bug Fixes
- File → Open PDF crashed the PDF editor (null operation matched no section; now
defaults to Merge)
- Backlinks panel required the wrong module path (failed at registration)
- writing-studio engines/panels now await their IPC-backed settings/file backends
(eliminates `JSON.parse("[object Promise]")` crashes)
- Manuscript panel's window.prompt (unsupported in Electron) replaced with an
inline dialog; collaboration comment store made async to match its IO
---
## Version 4.6.0 (2026-09-05)
### New Features
#### AI Assistant Plugin (multi-provider)
- Chat sidebar panel with rolling conversation history and insert-reply-into-document
- Providers: OpenAI, Anthropic, Ollama, LM Studio, and any OpenAI-compatible endpoint
- All provider traffic proxied through the main process — API keys never enter the renderer and the CSP stays closed to AI endpoints
- Commands: AI Summarize / Improve / Explain / Translate selection
- Answers the writing-studio `ai:analyze` contract, finally enabling the Proofread panel
#### Collaboration Plugin (inline comments)
- Anchor-based comments stored in `.comments/` sidecar files (never exported, never committed)
- Comments sidebar panel: add at cursor, list, resolve, delete, jump to anchor
- Drift detection flags moved/edited anchors; F8 navigates to the next open comment
#### Local Knowledge Base (wiki-links + backlinks)
- `[[Note]]`, `[[Note|alias]]`, `[[Note#section]]` render as links in the preview (code blocks excluded)
- Clicking a wiki-link opens the note or offers to create it
- Backlinks sidebar panel scans the folder (bounded BFS) for documents linking to the current one
#### Crash Recovery / Session Restore
- Open tabs (paths + unsaved buffer content) snapshotted to localStorage, debounced on edits, on tab changes, on unload, and once a minute
- Restore prompt on launch with per-tab restore, clean-fresh option, and 2MB content budget
#### Document Version History
- Every save snapshots the previous on-disk content to `<userData>/versions/`
- History sidebar panel: list, restore (with safety snapshot), unified diff vs. current, delete, manual "save version now"
- Per-document pruning (20 versions), path-hash storage, id-validated reads
#### Editor
- Vim keybindings (View → Vim Mode, persisted, live toggle via CodeMirror Compartment)
- Snippet Tab-expansion: type a snippet name and press Tab to insert it
- Zen Mode word-goal setter (the HUD progress bar finally has UI)
#### Export / Conversion
- **Real PDF encryption**: pdf-lib swapped for @cantoo/pdf-lib — encrypt/decrypt/permissions now actually work (UI auto-enables via the capability probe)
- **XLSX export**: markdown tables → native Excel workbook, one sheet per table (no Pandoc needed)
- **ODT headers/footers + page size**: real ODF styles.xml patching replaces the empty stub
- **Local PlantUML rendering**: diagrams render on-machine via the `plantuml` CLI when installed; plantuml.com stays as fallback
- **KaTeX bundled locally** (CSS + fonts): math renders offline, no CDN calls
- Writing heatmap (GitHub-style 30-day grid) in the writing-studio Goals panel
#### Platform
- Quick Note global scratchpad (Ctrl+Alt+Q, works when unfocused; appends to `notes/quick-notes.md`)
- Deep link protocol `markdownconverter://open?path=…`
- REPL confirmation dialog before first code execution per language per session (unsandboxed-execution guard rail)
- Writing-studio's four sidebar panels (Manuscript/Goals/Snapshots/Proofread) are now actually wired with rail icons
- Plugin sidebar panels get automatic rail icons via `registerPanel({icon})`
### Bug Fixes
- `Ctrl+Shift+P` collision: PDF (Enhanced) export now `Ctrl+Alt+Shift+P`; Command Palette keeps `Ctrl+Shift+P`
- Universal Converter's Pandoc tool no longer always reports "not installed" (`checkConverterAvailable` gained a pandoc case with bundled-binary check)
- CLI headless export: removed dangling `--css` / `--reference-doc` flags that made pandoc exit with an error; `--self-contained` replaced with `--standalone` (Pandoc 3.x)
- Removed dead "Open Export Options Dialog…" button from the converter dialog
- Removed duplicate `styles-zen.css` include
### Security
- AI provider requests carry size caps (200KB prompt), timeouts (120s), and user-safe error surfaces
- Version-history reads validate ids against traversal; history listing requires a valid document path
- PlantUML local rendering removes the diagram-text exfiltration path when a local CLI exists (CVE-MC-007 follow-up)
### Tests
- New suites: OdtStyling, AiProviders, ai-assistant prompts, collaboration comment-store, wiki-links/backlinks, session-store, XlsxExporter, VersionHistory
- PDFOperations encryption tests rewritten for the real-encryption reality
---
## Version 4.0.0 (2026-03-04)
### Major Changes
- **CodeMirror 6 Editor** — Replaced textarea with CodeMirror 6 featuring syntax highlighting, code folding, bracket matching, multiple cursors, and auto-indent
- **Sidebar Panel System** — Collapsible sidebar with File Explorer, Git, Snippets, and Templates panels
- **Command Palette** — Ctrl+Shift+P to search and execute all app actions
- **Code Execution (REPL)** — Run JavaScript, Python, and Bash code blocks directly from the preview
### New Features
- Print Preview dialog with paper size, orientation, margins, scale, and page range controls
- Image paste from clipboard and drag-drop support with auto-save to assets folder
- Document templates library (10 templates: blog post, meeting notes, tech spec, changelog, README, project plan, API docs, tutorial, release notes, comparison)
- Markdown extensions: footnotes, admonitions (note/warning/tip/danger/info), and [[toc]] table of contents
- PlantUML diagram rendering alongside Mermaid
- Welcome tab with onboarding and "What's New" feature showcase
- System spell checking with context menu suggestions and dictionary support
- Enhanced status bar with word count, character count, line/column, encoding, and language mode
- Grouped toolbar with visual section separators
- Breadcrumb bar showing current file path
### New Export/Import Formats
- Reveal.js slides (.html)
- Beamer slides (.pdf)
- Confluence/Jira wiki markup (.txt)
- MOBI e-books (via Calibre)
- Developer formats: JSON, YAML, XML, TOML
### Security
- Content Security Policy (CSP) meta tag
- File size validation (50MB limit)
- Error message sanitization (stripped file paths)
- Conversion rate limiting (2-second debounce)
### Dependencies Updated
- marked: 16.x to 17.x (with marked-highlight extension)
- pdfjs-dist: 3.x to 5.x (new worker model)
- html2pdf.js: 0.10 to 0.14
- pdfkit: 0.14 to 0.17
- dompurify, docx, and others updated to latest
### Testing
- 80 tests across 7 test suites
- New tests for sidebar manager, command palette, print preview, markdown extensions, and utility functions
### Breaking Changes
- Editor is now CodeMirror 6 (replaces textarea)
- marked API changed to use marked.use() instead of marked.setOptions()
- pdfjs-dist upgraded to v5 with new worker model
---
## Version 2.1.0 (December 14, 2025)
### 🎨 UI/UX Improvements
#### Subtle & Small Preview Popout Button
- Redesigned popout button with minimalist aesthetic
- Removed border for cleaner appearance
- Reduced size: 11px font, 2px×6px padding (previously 14px font, 4px×8px padding)
- Added opacity transition: 50% when idle, 100% on hover
- Subtle background effect on hover instead of heavy border styling
- **File**: `src/styles.css:195-211`
#### Simplified Table Headers in Preview
- Removed gradient background from table headers in modern theme
- Changed from `var(--primary-gradient)` (purple gradient) to simple light gray (#f0f0f0)
- Updated text color to dark (#333333) for better readability
- Clean, professional appearance matching standard themes
- **File**: `src/styles-modern.css:445-449`
### 📥 Enhanced Import Capabilities
#### Comprehensive Format-to-Markdown Conversion
Dramatically expanded the "Import Document" feature to support 30+ file formats:
**Supported Formats:**
- **Documents**: DOCX, ODT, RTF, HTML, HTM, TEX, EPUB, PDF, TXT
- **Presentations**: PPTX, ODP
- **Markup Languages**: RST, Textile, MediaWiki, Org-mode, AsciiDoc, TWiki, OPML
- **E-book Formats**: EPUB, FB2
- **LaTeX Formats**: TEX, LATEX, LTX
- **Web Formats**: HTML, HTM, XHTML
- **Wiki Formats**: MediaWiki, DokuWiki, TikiWiki, TWiki
- **Data Formats**: CSV, TSV, JSON
**Format-Specific Optimizations:**
- PDF text extraction with XeLaTeX engine
- CSV/TSV automatic table conversion
- JSON structure handling
- Improved error messages with format hints
**Access**: File → Import Document (Ctrl+I)
**File**: `src/main.js:1933-1994`
### 🎨 Exhaustive ASCII Art Generator
#### 5 New Text Banner Styles
Complete alphabet (A-Z) and numbers (0-9) support for all styles:
1. **Standard** - Classic ASCII art with slashes and underscores
2. **Banner** - Large format using # characters (7-line height)
3. **Block** - Modern Unicode block characters (█ ╔ ╗ ═ ║)
4. **Bubble** - Circular bubble letters (Ⓐ Ⓑ Ⓒ)
5. **Digital** - Digital display style (▄ ▀ ▐ ▌)
**File**: `src/renderer.js:3397-3537`
#### 19 Professional ASCII Templates
Organized into 4 categories with expanded options:
**Arrows & Flow (4 templates):**
- Arrow Right - Horizontal flow indicators
- Arrow Down - Vertical flow indicators
- Decision - Binary decision diagrams
- Process Flow - Multi-step process visualization
**Diagrams & Charts (6 templates):**
- Flowchart - Advanced flowchart with decision branches and loops
- Sequence - Sequence diagrams for User-System-Database interactions
- Network - Server-client network topology
- Hierarchy - Organizational tree structures
- Timeline - Milestone visualization with dates
- Table Simple - Basic table template with borders
**Boxes & Containers (4 templates):**
- Header - Section header with decorative borders
- Note Box - Important notes with rounded corners (┏━━┓)
- Warning Box - Warning messages with bold borders (╔═══╗)
- Info Box - Information boxes with subtle styling (╭───╮)
**Decorative Elements (6 templates):**
- Divider - Horizontal section separator (═══)
- Separator Fancy - Elegant rounded divider
- Brackets - Japanese-style brackets 【 】
- Banner Stars - Star-bordered banners
- Checklist - Task lists with ✓ checkmarks
- Progress Bar - Visual progress indicators
**Features:**
- All ASCII art automatically wrapped in code blocks for proper rendering
- Preserved formatting in markdown preview and all export formats
- Categorized template selection interface
- Real-time preview generation
**Access**: Tools → ASCII Art Generator
**Files**: `src/renderer.js:3513-3671`, `src/index.html:427-466`
### 📝 Technical Improvements
- Enhanced ASCII art detection in Word template exporter
- Improved monospace font rendering across all export formats
- Better code block preservation in PDF and Word exports
- Optimized template categorization and organization
### 🔧 Files Modified
- `src/styles.css` - Preview popout button styling
- `src/styles-modern.css` - Table header simplification
- `src/main.js` - Enhanced import function, version update
- `src/renderer.js` - ASCII art generator enhancements
- `src/index.html` - ASCII template UI organization
- `package.json` - Version bump to 2.1.0
---
## Version 2.0.0 (Previous Release)
### Major Features
- Export Profiles - Save and reuse export configurations
- Mermaid.js diagram support
- Command Palette (Ctrl+Shift+P)
- GitHub Light/Dark preview themes
- Table Generator
- ASCII Art Generator (basic)
- Resizable Preview Pane
- Pop-out Preview Window
- Configurable page sizes (A3-A5, B4-B5, Letter, Legal, Tabloid, Custom)
- Custom Headers & Footers for exports
- Enhanced PDF and Word export with templates
- 22 beautiful themes
### Core Capabilities
- Cross-platform markdown editor with live preview
- Universal document conversion (30+ formats)
- PDF Editor (merge, split, compress, rotate, watermark, encrypt)
- Batch file conversion
- File association support
- Advanced export options
- Multi-tab interface
---
## Installation & Usage
### Prerequisites
- **Pandoc** - Required for document conversion
- **Optional**: LibreOffice, ImageMagick, FFmpeg for universal converter
### Download
Get the latest release from: https://github.com/amitwh/pan-converter/releases
### Supported Platforms
- Windows (x64)
- Linux (AppImage, .deb, .snap)
- macOS (planned)
---
## Contributing
Contributions are welcome! Please see [CLAUDE.md](CLAUDE.md) for development guidelines.
**Author**: Amit Haridas (amit.wh@gmail.com)
**License**: MIT
**Repository**: https://github.com/amitwh/pan-converter
Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.
-93
View File
@@ -1,93 +0,0 @@
Copyright (c) 2014, The Fira Code Project Authors (https://github.com/tonsky/FiraCode)
This Font Software is licensed under the SIL Open Font License, Version 1.1.
This license is copied below, and is also available with a FAQ at:
http://scripts.sil.org/OFL
-----------------------------------------------------------
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
-----------------------------------------------------------
PREAMBLE
The goals of the Open Font License (OFL) are to stimulate worldwide
development of collaborative font projects, to support the font creation
efforts of academic and linguistic communities, and to provide a free and
open framework in which fonts may be shared and improved in partnership
with others.
The OFL allows the licensed fonts to be used, studied, modified and
redistributed freely as long as they are not sold by themselves. The
fonts, including any derivative works, can be bundled, embedded,
redistributed and/or sold with any software provided that any reserved
names are not used by derivative works. The fonts and derivatives,
however, cannot be released under any other type of license. The
requirement for fonts to remain under this license does not apply
to any document created using the fonts or their derivatives.
DEFINITIONS
"Font Software" refers to the set of files released by the Copyright
Holder(s) under this license and clearly marked as such. This may
include source files, build scripts and documentation.
"Reserved Font Name" refers to any names specified as such after the
copyright statement(s).
"Original Version" refers to the collection of Font Software components as
distributed by the Copyright Holder(s).
"Modified Version" refers to any derivative made by adding to, deleting,
or substituting -- in part or in whole -- any of the components of the
Original Version, by changing formats or by porting the Font Software to a
new environment.
"Author" refers to any designer, engineer, programmer, technical
writer or other person who contributed to the Font Software.
PERMISSION & CONDITIONS
Permission is hereby granted, free of charge, to any person obtaining
a copy of the Font Software, to use, study, copy, merge, embed, modify,
redistribute, and sell modified and unmodified copies of the Font
Software, subject to the following conditions:
1) Neither the Font Software nor any of its individual components,
in Original or Modified Versions, may be sold by itself.
2) Original or Modified Versions of the Font Software may be bundled,
redistributed and/or sold with any software, provided that each copy
contains the above copyright notice and this license. These can be
included either as stand-alone text files, human-readable headers or
in the appropriate machine-readable metadata fields within text or
binary files as long as those fields can be easily viewed by the user.
3) No Modified Version of the Font Software may use the Reserved Font
Name(s) unless explicit written permission is granted by the corresponding
Copyright Holder. This restriction only applies to the primary font name as
presented to the users.
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
Software shall not be used to promote, endorse or advertise any
Modified Version, except to acknowledge the contribution(s) of the
Copyright Holder(s) and the Author(s) or with their explicit written
permission.
5) The Font Software, modified or unmodified, in part or in whole,
must be distributed entirely under this license, and must not be
distributed under any other license. The requirement for fonts to
remain under this license does not apply to any document created
using the Font Software.
TERMINATION
This license becomes null and void if any of the above conditions are
not met.
DISCLAIMER
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
OTHER DEALINGS IN THE FONT SOFTWARE.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
-93
View File
@@ -1,93 +0,0 @@
Copyright 2020 The JetBrains Mono Project Authors (https://github.com/JetBrains/JetBrainsMono)
This Font Software is licensed under the SIL Open Font License, Version 1.1.
This license is copied below, and is also available with a FAQ at:
https://scripts.sil.org/OFL
-----------------------------------------------------------
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
-----------------------------------------------------------
PREAMBLE
The goals of the Open Font License (OFL) are to stimulate worldwide
development of collaborative font projects, to support the font creation
efforts of academic and linguistic communities, and to provide a free and
open framework in which fonts may be shared and improved in partnership
with others.
The OFL allows the licensed fonts to be used, studied, modified and
redistributed freely as long as they are not sold by themselves. The
fonts, including any derivative works, can be bundled, embedded,
redistributed and/or sold with any software provided that any reserved
names are not used by derivative works. The fonts and derivatives,
however, cannot be released under any other type of license. The
requirement for fonts to remain under this license does not apply
to any document created using the fonts or their derivatives.
DEFINITIONS
"Font Software" refers to the set of files released by the Copyright
Holder(s) under this license and clearly marked as such. This may
include source files, build scripts and documentation.
"Reserved Font Name" refers to any names specified as such after the
copyright statement(s).
"Original Version" refers to the collection of Font Software components as
distributed by the Copyright Holder(s).
"Modified Version" refers to any derivative made by adding to, deleting,
or substituting -- in part or in whole -- any of the components of the
Original Version, by changing formats or by porting the Font Software to a
new environment.
"Author" refers to any designer, engineer, programmer, technical
writer or other person who contributed to the Font Software.
PERMISSION & CONDITIONS
Permission is hereby granted, free of charge, to any person obtaining
a copy of the Font Software, to use, study, copy, merge, embed, modify,
redistribute, and sell modified and unmodified copies of the Font
Software, subject to the following conditions:
1) Neither the Font Software nor any of its individual components,
in Original or Modified Versions, may be sold by itself.
2) Original or Modified Versions of the Font Software may be bundled,
redistributed and/or sold with any software, provided that each copy
contains the above copyright notice and this license. These can be
included either as stand-alone text files, human-readable headers or
in the appropriate machine-readable metadata fields within text or
binary files as long as those fields can be easily viewed by the user.
3) No Modified Version of the Font Software may use the Reserved Font
Name(s) unless explicit written permission is granted by the corresponding
Copyright Holder. This restriction only applies to the primary font name as
presented to the users.
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
Software shall not be used to promote, endorse or advertise any
Modified Version, except to acknowledge the contribution(s) of the
Copyright Holder(s) and the Author(s) or with their explicit written
permission.
5) The Font Software, modified or unmodified, in part or in whole,
must be distributed entirely under this license, and must not be
distributed under any other license. The requirement for fonts to
remain under this license does not apply to any document created
using the Font Software.
TERMINATION
This license becomes null and void if any of the above conditions are
not met.
DISCLAIMER
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
OTHER DEALINGS IN THE FONT SOFTWARE.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.

After

Width:  |  Height:  |  Size: 5.5 KiB

BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 8.6 KiB

BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 5.5 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 38 KiB

After

Width:  |  Height:  |  Size: 8.6 KiB

+8
View File
@@ -0,0 +1,8 @@
<svg width="256" height="256" viewBox="0 0 256 256" xmlns="http://www.w3.org/2000/svg">
<rect width="256" height="256" rx="32" fill="#4A90E2"/>
<g transform="translate(40, 40)">
<path d="M20 40 L20 136 L80 136 L80 100 L56 100 L56 76 L80 76 L80 40 Z" fill="white" opacity="0.9"/>
<path d="M96 40 L96 136 L156 136 L156 100 L132 100 L132 88 L156 88 L156 52 L132 52 L132 40 Z" fill="white" opacity="0.9"/>
</g>
<text x="128" y="200" font-family="Arial, sans-serif" font-size="24" font-weight="bold" text-anchor="middle" fill="white">PAN</text>
</svg>

After

Width:  |  Height:  |  Size: 562 B

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

After

Width:  |  Height:  |  Size: 20 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 10 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 655 B

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.1 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 21 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 38 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.1 KiB

Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.

Some files were not shown because too many files have changed in this diff Show More