mirror of
https://github.com/amitwh/markdown-converter.git
synced 2026-10-01 17:29:29 +05:30
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
16c0e00201 |
@@ -1,28 +0,0 @@
|
|||||||
name: CI
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches: [master]
|
|
||||||
pull_request:
|
|
||||||
branches: [master]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
test:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Setup Node.js
|
|
||||||
uses: actions/setup-node@v4
|
|
||||||
with:
|
|
||||||
node-version: 20
|
|
||||||
cache: npm
|
|
||||||
|
|
||||||
- name: Install dependencies
|
|
||||||
run: npm ci
|
|
||||||
|
|
||||||
- name: Run tests
|
|
||||||
run: npm test
|
|
||||||
|
|
||||||
- name: Run linter
|
|
||||||
run: npm run lint
|
|
||||||
@@ -1,178 +0,0 @@
|
|||||||
name: Release
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
tags: ['v*']
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build-linux:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Setup Node.js
|
|
||||||
uses: actions/setup-node@v4
|
|
||||||
with:
|
|
||||||
node-version: 20
|
|
||||||
cache: npm
|
|
||||||
|
|
||||||
- name: Install dependencies
|
|
||||||
run: npm ci
|
|
||||||
|
|
||||||
- name: Download external tools (pandoc)
|
|
||||||
run: node scripts/download-tools.js
|
|
||||||
|
|
||||||
- name: Bundle MarkItDown (optional, best effort)
|
|
||||||
# Freezes markitdown + Python into bin/linux/markitdown; failure is
|
|
||||||
# non-fatal — the build then ships without it and the app falls back
|
|
||||||
# to a system markitdown at runtime.
|
|
||||||
run: npm run bundle:markitdown
|
|
||||||
continue-on-error: true
|
|
||||||
|
|
||||||
- name: Run tests
|
|
||||||
run: npm test
|
|
||||||
|
|
||||||
- name: Build Linux packages
|
|
||||||
run: npm run build:linux-ci -- --publish=never
|
|
||||||
|
|
||||||
- name: Upload Linux artifacts
|
|
||||||
uses: actions/upload-artifact@v4
|
|
||||||
with:
|
|
||||||
name: linux-artifacts
|
|
||||||
path: |
|
|
||||||
dist/*.deb
|
|
||||||
dist/*.AppImage
|
|
||||||
dist/*.snap
|
|
||||||
dist/*.rpm
|
|
||||||
retention-days: 5
|
|
||||||
|
|
||||||
build-windows:
|
|
||||||
runs-on: windows-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Setup Node.js
|
|
||||||
uses: actions/setup-node@v4
|
|
||||||
with:
|
|
||||||
node-version: 20
|
|
||||||
cache: npm
|
|
||||||
|
|
||||||
- name: Install dependencies
|
|
||||||
run: npm ci
|
|
||||||
|
|
||||||
- name: Download external tools (pandoc)
|
|
||||||
run: node scripts/download-tools.js
|
|
||||||
|
|
||||||
- name: Bundle MarkItDown (optional, best effort)
|
|
||||||
# Windows runners ship python + venv; non-fatal on failure — the
|
|
||||||
# package then omits the bundled binary by design
|
|
||||||
run: npm run bundle:markitdown
|
|
||||||
continue-on-error: true
|
|
||||||
|
|
||||||
- name: Run tests
|
|
||||||
run: npm test
|
|
||||||
|
|
||||||
- name: Decode certificate (if available)
|
|
||||||
if: ${{ env.CSC_LINK_BASE64 != '' }}
|
|
||||||
shell: pwsh
|
|
||||||
env:
|
|
||||||
CSC_LINK_BASE64: ${{ secrets.CSC_LINK_BASE64 }}
|
|
||||||
run: |
|
|
||||||
$bytes = [Convert]::FromBase64String("$env:CSC_LINK_BASE64")
|
|
||||||
[IO.File]::WriteAllBytes("${{ github.workspace }}\code-signing-cert.pfx", $bytes)
|
|
||||||
echo "CERT_AVAILABLE=true" >> $env:GITHUB_ENV
|
|
||||||
|
|
||||||
- name: Build Windows packages (signed)
|
|
||||||
if: ${{ env.CERT_AVAILABLE == 'true' }}
|
|
||||||
env:
|
|
||||||
CSC_LINK: code-signing-cert.pfx
|
|
||||||
CSC_KEY_PASSWORD: ${{ secrets.CSC_KEY_PASSWORD }}
|
|
||||||
run: npm run build:win-signed -- --publish=never
|
|
||||||
|
|
||||||
- name: Build Windows packages (unsigned)
|
|
||||||
if: ${{ env.CERT_AVAILABLE != 'true' }}
|
|
||||||
env:
|
|
||||||
CSC_IDENTITY_AUTO_DISCOVERY: 'false'
|
|
||||||
run: npm run build:win-unsigned -- --publish=never
|
|
||||||
|
|
||||||
- name: Upload Windows artifacts
|
|
||||||
uses: actions/upload-artifact@v4
|
|
||||||
with:
|
|
||||||
name: windows-artifacts
|
|
||||||
path: |
|
|
||||||
dist/*.exe
|
|
||||||
dist/*.zip
|
|
||||||
retention-days: 5
|
|
||||||
|
|
||||||
build-macos:
|
|
||||||
runs-on: macos-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Setup Node.js
|
|
||||||
uses: actions/setup-node@v4
|
|
||||||
with:
|
|
||||||
node-version: 20
|
|
||||||
cache: npm
|
|
||||||
|
|
||||||
- name: Install dependencies
|
|
||||||
run: npm ci
|
|
||||||
|
|
||||||
- name: Download external tools (pandoc)
|
|
||||||
run: node scripts/download-tools.js
|
|
||||||
|
|
||||||
- name: Bundle MarkItDown (optional, best effort)
|
|
||||||
run: npm run bundle:markitdown
|
|
||||||
continue-on-error: true
|
|
||||||
|
|
||||||
- name: Run tests
|
|
||||||
run: npm test
|
|
||||||
|
|
||||||
- name: Build macOS packages
|
|
||||||
run: npm run build:mac -- --publish=never
|
|
||||||
|
|
||||||
- name: Upload macOS artifacts
|
|
||||||
uses: actions/upload-artifact@v4
|
|
||||||
with:
|
|
||||||
name: macos-artifacts
|
|
||||||
path: |
|
|
||||||
dist/*.dmg
|
|
||||||
dist/*.zip
|
|
||||||
retention-days: 5
|
|
||||||
|
|
||||||
release:
|
|
||||||
needs: [build-linux, build-windows, build-macos]
|
|
||||||
if: always()
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Download Linux artifacts
|
|
||||||
uses: actions/download-artifact@v4
|
|
||||||
continue-on-error: true
|
|
||||||
with:
|
|
||||||
name: linux-artifacts
|
|
||||||
path: dist
|
|
||||||
|
|
||||||
- name: Download Windows artifacts
|
|
||||||
uses: actions/download-artifact@v4
|
|
||||||
continue-on-error: true
|
|
||||||
with:
|
|
||||||
name: windows-artifacts
|
|
||||||
path: dist
|
|
||||||
|
|
||||||
- name: Download macOS artifacts
|
|
||||||
uses: actions/download-artifact@v4
|
|
||||||
continue-on-error: true
|
|
||||||
with:
|
|
||||||
name: macos-artifacts
|
|
||||||
path: dist
|
|
||||||
|
|
||||||
- name: Create GitHub Release
|
|
||||||
uses: softprops/action-gh-release@v2
|
|
||||||
with:
|
|
||||||
generate_release_notes: true
|
|
||||||
files: dist/*
|
|
||||||
+36
-48
@@ -1,48 +1,36 @@
|
|||||||
node_modules/
|
node_modules/
|
||||||
dist/
|
dist/
|
||||||
*.log
|
*.log
|
||||||
.DS_Store
|
.DS_Store
|
||||||
Thumbs.db
|
Thumbs.db
|
||||||
.env
|
.env
|
||||||
.env.local
|
.env.local
|
||||||
*.swp
|
*.swp
|
||||||
*.swo
|
*.swo
|
||||||
*~
|
*~
|
||||||
.vscode/*
|
.vscode/
|
||||||
!.vscode/launch.json
|
.idea/
|
||||||
.idea/
|
*.iml
|
||||||
*.iml
|
out/
|
||||||
out/
|
.cache/
|
||||||
.cache/
|
.npm/
|
||||||
.npm/
|
.electron/
|
||||||
.electron/
|
package-lock.json
|
||||||
# package-lock.json is intentionally tracked for reproducible CI builds
|
|
||||||
|
# Screenshots and temp files
|
||||||
# Downloaded tool binaries (fetched at build time via scripts/download-tools.js)
|
*.png.bak
|
||||||
bin/
|
Screen.png
|
||||||
|
dark.png
|
||||||
# Code signing certificates — never commit private keys
|
light.png
|
||||||
*.pfx
|
pdf.png
|
||||||
*.p12
|
uvmodal.png
|
||||||
|
nul
|
||||||
# Screenshots and temp files
|
*.tmp
|
||||||
*.png.bak
|
|
||||||
Screen.png
|
# Development screenshots
|
||||||
dark.png
|
pdf\ modal.png
|
||||||
light.png
|
|
||||||
pdf.png
|
# Claude/AI development files
|
||||||
uvmodal.png
|
.claude/
|
||||||
nul
|
CLAUDE.md
|
||||||
*.tmp
|
agents.md
|
||||||
|
|
||||||
# Development screenshots
|
|
||||||
pdf\ modal.png
|
|
||||||
|
|
||||||
# Claude/AI development files
|
|
||||||
.claude/
|
|
||||||
CLAUDE.md
|
|
||||||
agents.md
|
|
||||||
coverage/
|
|
||||||
|
|
||||||
# Superpowers brainstorm artifacts
|
|
||||||
.superpowers/
|
|
||||||
+11
-11
@@ -1,11 +1,11 @@
|
|||||||
{
|
{
|
||||||
"semi": true,
|
"semi": true,
|
||||||
"singleQuote": true,
|
"singleQuote": true,
|
||||||
"tabWidth": 2,
|
"tabWidth": 2,
|
||||||
"useTabs": false,
|
"useTabs": false,
|
||||||
"trailingComma": "es5",
|
"trailingComma": "es5",
|
||||||
"bracketSpacing": true,
|
"bracketSpacing": true,
|
||||||
"arrowParens": "always",
|
"arrowParens": "always",
|
||||||
"printWidth": 100,
|
"printWidth": 100,
|
||||||
"endOfLine": "auto"
|
"endOfLine": "auto"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,469 +0,0 @@
|
|||||||
# Security Assessment Report: MarkdownConverter v4.0.0
|
|
||||||
|
|
||||||
**Assessment Date:** 2026-03-15
|
|
||||||
**Application:** MarkdownConverter - Electron-based Markdown editor and document converter
|
|
||||||
**Target Version:** 4.0.0
|
|
||||||
**Assessor:** Security Audit Agent
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Executive Summary
|
|
||||||
|
|
||||||
This assessment identified **10 security findings** ranging from **Critical to Low severity**. The most significant concerns involve insecure Electron security configuration that could allow XSS attacks to escalate to full system access, arbitrary code execution via the REPL feature, and missing input validation on file operations.
|
|
||||||
|
|
||||||
| Severity | Count |
|
|
||||||
|----------|-------|
|
|
||||||
| Critical | 2 |
|
|
||||||
| High | 3 |
|
|
||||||
| Medium | 3 |
|
|
||||||
| Low | 2 |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Vulnerability Findings
|
|
||||||
|
|
||||||
### CVE-MC-001: Insecure Electron Security Configuration (Critical)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 9.6 (Critical)**
|
|
||||||
**CWE-265: CWE-1021: Improper Restriction of Renderers**
|
|
||||||
|
|
||||||
**Location:** `src/main.js` (lines 328-332)
|
|
||||||
|
|
||||||
```javascript
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: true,
|
|
||||||
contextIsolation: false,
|
|
||||||
spellcheck: true
|
|
||||||
},
|
|
||||||
```
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
The main application window has `nodeIntegration: true` and `contextIsolation: false`, which is the most insecure Electron configuration. This allows the renderer process direct access to Node.js APIs, meaning any XSS vulnerability in the markdown rendering or external content could lead to full system compromise.
|
|
||||||
|
|
||||||
**Exploitability:**
|
|
||||||
- An attacker who can inject malicious JavaScript (via markdown files, XSS in preview, or compromised dependencies) gains immediate access to:
|
|
||||||
- Full file system read/write via `fs` module
|
|
||||||
- Command execution via `child_process`
|
|
||||||
- Network access via `net` module
|
|
||||||
- All system resources
|
|
||||||
|
|
||||||
**Attack Scenario:**
|
|
||||||
1. User opens a malicious markdown file containing embedded JavaScript
|
|
||||||
2. The JavaScript executes in the renderer with full Node.js access
|
|
||||||
3. Attacker can read sensitive files, execute commands, exfiltrate data
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
```javascript
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: false,
|
|
||||||
contextIsolation: true,
|
|
||||||
sandbox: true,
|
|
||||||
preload: path.join(__dirname, 'preload.js')
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Note:** The preload.js file already implements a secure IPC bridge but it is not being utilized for the main window.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-002: Arbitrary Code Execution via REPL Feature (Critical)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 9.3 (Critical)**
|
|
||||||
**CWE-94: Improper Control of Generation of Code ('Code Injection')**
|
|
||||||
|
|
||||||
**Location:** `src/main.js` (lines 4369-4396)
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
The `execute-code` IPC handler allows execution of arbitrary Python and Bash scripts through the REPL panel. While JavaScript execution appears to have been removed or limited, Python and Bash commands are executed via `execFile` with user-supplied code.
|
|
||||||
|
|
||||||
**Vulnerable Code Pattern:**
|
|
||||||
```javascript
|
|
||||||
ipcMain.handle('execute-code', async (event, { code, language }) => {
|
|
||||||
// ...
|
|
||||||
if (language === 'python' || language === 'py') {
|
|
||||||
cmd = 'python';
|
|
||||||
args = ['-c', code];
|
|
||||||
}
|
|
||||||
// ...
|
|
||||||
execFile(cmd, args, { timeout }, (err, stdout, stderr) => {
|
|
||||||
// ...
|
|
||||||
});
|
|
||||||
});
|
|
||||||
```
|
|
||||||
|
|
||||||
**Exploitability:**
|
|
||||||
- Users can be tricked into running malicious code blocks
|
|
||||||
- Markdown files can contain executable code blocks with "Run" buttons
|
|
||||||
- No sandboxing or permission restrictions on executed code
|
|
||||||
|
|
||||||
**Attack Scenario:**
|
|
||||||
1. Attacker creates markdown file with malicious Python code block
|
|
||||||
2. User clicks "Run" button in preview
|
|
||||||
3. Python code executes with user's full permissions
|
|
||||||
4. Attacker gains code execution on victim's machine
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
- Remove arbitrary code execution feature entirely, OR
|
|
||||||
- Implement strict sandboxing (Docker, VM, or restricted Python environment)
|
|
||||||
- Add user confirmation dialogs with clear warnings
|
|
||||||
- Execute in isolated environment with no filesystem/network access
|
|
||||||
- Implement allowlist of safe operations
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-003: Potential XSS in Markdown Rendering (High)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 8.0 (High)**
|
|
||||||
**CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')**
|
|
||||||
|
|
||||||
**Location:** `src/renderer.js` (lines 387-419)
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
While DOMPurify is used to sanitize HTML, several extensions to marked.js may bypass sanitization:
|
|
||||||
|
|
||||||
1. **Custom Admonition Extension (lines 51-77):**
|
|
||||||
```javascript
|
|
||||||
marked.use({
|
|
||||||
extensions: [{
|
|
||||||
name: 'admonition',
|
|
||||||
// ...
|
|
||||||
renderer(token) {
|
|
||||||
const inner = this.parser.parse(token.text);
|
|
||||||
return `<div class="admonition admonition-${token.admonitionType}">
|
|
||||||
<div class="admonition-title">${icon} ${token.admonitionType...}</div>
|
|
||||||
<div class="admonition-content">${inner}</div>
|
|
||||||
</div>`;
|
|
||||||
}
|
|
||||||
}]
|
|
||||||
});
|
|
||||||
```
|
|
||||||
|
|
||||||
2. **innerHTML Assignments (line 419):**
|
|
||||||
```javascript
|
|
||||||
preview.innerHTML = sanitizedHtml;
|
|
||||||
```
|
|
||||||
|
|
||||||
**Exploitability:**
|
|
||||||
- Combined with CVE-MC-001, XSS leads to full system compromise
|
|
||||||
- Custom markdown extensions may not be properly sanitized
|
|
||||||
- Admonition type is directly interpolated into HTML without escaping
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
- Ensure all custom markdown extensions escape user input
|
|
||||||
- Add Content Security Policy that blocks inline scripts
|
|
||||||
- Use `textContent` instead of `innerHTML` where possible
|
|
||||||
- Audit all custom marked.js extensions for XSS vectors
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-004: Missing Path Traversal Protection (High)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 7.8 (High)**
|
|
||||||
**CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')**
|
|
||||||
|
|
||||||
**Location:** `src/main.js` (lines 4241-4281)
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
The `list-directory` and `open-file-path` IPC handlers accept arbitrary file paths without validation:
|
|
||||||
|
|
||||||
```javascript
|
|
||||||
ipcMain.handle('list-directory', async (event, dirPath) => {
|
|
||||||
try {
|
|
||||||
if (!dirPath) { /* dialog */ }
|
|
||||||
// No path validation - accepts any path
|
|
||||||
const entries = fs.readdirSync(dirPath, { withFileTypes: true });
|
|
||||||
// ...
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
ipcMain.on('open-file-path', (event, filePath) => {
|
|
||||||
// No path validation
|
|
||||||
if (!fs.existsSync(filePath)) return;
|
|
||||||
const content = fs.readFileSync(filePath, 'utf-8');
|
|
||||||
mainWindow.webContents.send('file-opened', { path: filePath, content });
|
|
||||||
});
|
|
||||||
```
|
|
||||||
|
|
||||||
**Exploitability:**
|
|
||||||
- Malicious renderer code can read any file on the system
|
|
||||||
- No restriction to a sandbox directory
|
|
||||||
- Combined with XSS, attacker can exfiltrate sensitive files
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
```javascript
|
|
||||||
const ALLOWED_DIRECTORIES = [app.getPath('documents'), app.getPath('desktop')];
|
|
||||||
|
|
||||||
function isPathAllowed(filePath) {
|
|
||||||
const resolved = path.resolve(filePath);
|
|
||||||
return ALLOWED_DIRECTORIES.some(dir => resolved.startsWith(dir));
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-005: Weak Content Security Policy (High)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 7.5 (High)**
|
|
||||||
**CWE-1021: Improper Restriction of Renderers**
|
|
||||||
|
|
||||||
**Location:** `src/index.html` (line 5)
|
|
||||||
|
|
||||||
```html
|
|
||||||
<meta http-equiv="Content-Security-Policy" content="default-src 'self';
|
|
||||||
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net;
|
|
||||||
style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com;
|
|
||||||
img-src 'self' data: blob: file:;
|
|
||||||
font-src 'self' data:;
|
|
||||||
connect-src 'self' https://www.plantuml.com;">
|
|
||||||
```
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
The CSP contains several security weaknesses:
|
|
||||||
|
|
||||||
1. **`'unsafe-inline'` in script-src** - Allows inline script injection
|
|
||||||
2. **`'unsafe-eval'` in script-src** - Allows `eval()` and similar functions
|
|
||||||
3. **`https://cdn.jsdelivr.net`** - Allows scripts from external CDN (supply chain risk)
|
|
||||||
4. **`file:` in img-src** - Allows loading local files as images (potential information disclosure)
|
|
||||||
|
|
||||||
**Exploitability:**
|
|
||||||
- XSS attacks can execute arbitrary scripts
|
|
||||||
- External CDN compromise could inject malicious code
|
|
||||||
- `eval()` enables dynamic code execution
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
- Remove `'unsafe-inline'` and `'unsafe-eval'`
|
|
||||||
- Use nonces or hashes for inline scripts
|
|
||||||
- Remove external CDNs or use Subresource Integrity (SRI)
|
|
||||||
- Remove `file:` from img-src
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-006: Insecure Window Configuration for PDF Export (Medium)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 6.5 (Medium)**
|
|
||||||
**CWE-1021: Improper Restriction of Renderers**
|
|
||||||
|
|
||||||
**Location:** `src/main.js` (lines 2579-2585)
|
|
||||||
|
|
||||||
```javascript
|
|
||||||
const pdfWindow = new BrowserWindow({
|
|
||||||
show: false,
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: true,
|
|
||||||
contextIsolation: false
|
|
||||||
}
|
|
||||||
});
|
|
||||||
```
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
Hidden windows created for PDF export also have insecure configurations, allowing potential privilege escalation.
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
```javascript
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: false,
|
|
||||||
contextIsolation: true,
|
|
||||||
sandbox: true
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-007: PlantUML Server Data Exfiltration (Medium)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 5.3 (Medium)**
|
|
||||||
**CWE-359: Exposure of Private Information**
|
|
||||||
|
|
||||||
**Location:** `src/renderer.js` (lines 470-487)
|
|
||||||
|
|
||||||
```javascript
|
|
||||||
const plantumlBlocks = preview.querySelectorAll('pre code.language-plantuml');
|
|
||||||
plantumlBlocks.forEach((block) => {
|
|
||||||
const code = block.textContent;
|
|
||||||
// ...
|
|
||||||
const encoded = plantumlEncode(code);
|
|
||||||
const img = document.createElement('img');
|
|
||||||
img.src = `https://www.plantuml.com/plantuml/svg/${encoded}`;
|
|
||||||
// ...
|
|
||||||
});
|
|
||||||
```
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
PlantUML diagram content is sent to an external server (plantuml.com) for rendering. This could leak sensitive information contained in diagrams.
|
|
||||||
|
|
||||||
**Exploitability:**
|
|
||||||
- Diagrams containing proprietary information, system architecture, or internal processes are sent to third-party servers
|
|
||||||
- No user consent or notification before external data transmission
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
- Use local PlantUML rendering with Java
|
|
||||||
- Add user warning before sending data to external service
|
|
||||||
- Implement opt-in for external rendering
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-008: Inconsistent Security Settings Across Windows (Medium)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 5.5 (Medium)**
|
|
||||||
**CWE-1021: Improper Restriction of Renderers**
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
Security settings are inconsistent across different windows:
|
|
||||||
|
|
||||||
| Window | nodeIntegration | contextIsolation | Security |
|
|
||||||
|--------|-----------------|------------------|----------|
|
|
||||||
| Main Window | true | false | Insecure |
|
|
||||||
| About Dialog | false | true | Secure |
|
|
||||||
| Dependencies Dialog | false | true | Secure |
|
|
||||||
| ASCII Generator | false | true | Secure |
|
|
||||||
| Table Generator | false | true | Secure |
|
|
||||||
| PDF Export Window | true | false | Insecure |
|
|
||||||
| Hidden Conversion Window | true | false | Insecure |
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
Apply secure configuration (`nodeIntegration: false`, `contextIsolation: true`) consistently across all windows.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-009: Command Execution via External Tools (Low)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 4.4 (Low)**
|
|
||||||
**CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')**
|
|
||||||
|
|
||||||
**Location:** `src/main.js` (lines 1915-1972)
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
While the application uses `execFile` instead of `exec` (good practice), external tools (Pandoc, LibreOffice, FFmpeg, ImageMagick) are invoked with file paths that could potentially be manipulated.
|
|
||||||
|
|
||||||
**Positive Finding:**
|
|
||||||
The code correctly uses `execFile` with argument arrays instead of shell commands, mitigating most command injection vectors.
|
|
||||||
|
|
||||||
**Remaining Risk:**
|
|
||||||
- File paths are not validated against malicious names
|
|
||||||
- Special characters in filenames could cause issues with external tools
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
- Validate file paths before passing to external tools
|
|
||||||
- Sanitize filenames of special characters
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### CVE-MC-010: Missing Dependency Version Pinning (Low)
|
|
||||||
|
|
||||||
**CVSS 3.1 Score: 3.5 (Low)**
|
|
||||||
**CWE-1035: Using Components with Known Vulnerabilities**
|
|
||||||
|
|
||||||
**Location:** `package.json`
|
|
||||||
|
|
||||||
**Description:**
|
|
||||||
Dependencies use `^` version ranges which could allow automatic updates to versions with vulnerabilities:
|
|
||||||
|
|
||||||
```json
|
|
||||||
"dependencies": {
|
|
||||||
"marked": "^17.0.3",
|
|
||||||
"dompurify": "^3.3.1",
|
|
||||||
"mermaid": "^11.12.3",
|
|
||||||
// ...
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Remediation:**
|
|
||||||
- Pin exact versions in production
|
|
||||||
- Use lockfile (package-lock.json)
|
|
||||||
- Implement dependency scanning in CI/CD pipeline
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Attack Surface Map
|
|
||||||
|
|
||||||
```
|
|
||||||
┌─────────────────────────────────────────────────────────────────┐
|
|
||||||
│ EXTERNAL ATTACK SURFACE │
|
|
||||||
├─────────────────────────────────────────────────────────────────┤
|
|
||||||
│ Markdown Files (.md) ─────► XSS via Preview Rendering │
|
|
||||||
│ Code Blocks ─────► Arbitrary Code Execution │
|
|
||||||
│ PlantUML Diagrams ─────► Data Exfiltration │
|
|
||||||
│ External CDNs ─────► Supply Chain Attacks │
|
|
||||||
└─────────────────────────────────────────────────────────────────┘
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
┌─────────────────────────────────────────────────────────────────┐
|
|
||||||
│ RENDERER PROCESS (Insecure) │
|
|
||||||
├─────────────────────────────────────────────────────────────────┤
|
|
||||||
│ nodeIntegration: true ─────► Direct Node.js Access │
|
|
||||||
│ contextIsolation: false ─────► Prototype Pollution Risk │
|
|
||||||
│ DOMPurify Sanitization ─────► May be bypassed via extensions │
|
|
||||||
│ Custom Marked Extensions ────► XSS Vectors │
|
|
||||||
└─────────────────────────────────────────────────────────────────┘
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
┌─────────────────────────────────────────────────────────────────┐
|
|
||||||
│ IPC BRIDGE (Preload.js) │
|
|
||||||
├─────────────────────────────────────────────────────────────────┤
|
|
||||||
│ Channel Whitelisting ─────► Good Practice │
|
|
||||||
│ Not Used for Main Window ────► Security Bypassed │
|
|
||||||
└─────────────────────────────────────────────────────────────────┘
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
┌─────────────────────────────────────────────────────────────────┐
|
|
||||||
│ MAIN PROCESS (Full Privileges) │
|
|
||||||
├─────────────────────────────────────────────────────────────────┤
|
|
||||||
│ File Operations ─────► No Path Validation │
|
|
||||||
│ Code Execution ─────► Python/Bash via REPL │
|
|
||||||
│ External Tools ─────► Pandoc, FFmpeg, LibreOffice │
|
|
||||||
│ PDF Operations ─────► Merge, Encrypt, Decrypt │
|
|
||||||
└─────────────────────────────────────────────────────────────────┘
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Positive Security Findings
|
|
||||||
|
|
||||||
1. **Preload.js Implementation:** A secure IPC bridge with channel whitelisting is implemented
|
|
||||||
2. **DOMPurify Usage:** HTML sanitization is applied to markdown output
|
|
||||||
3. **execFile Usage:** External commands use `execFile` instead of `exec`
|
|
||||||
4. **File Size Limits:** 50MB maximum file size is enforced
|
|
||||||
5. **Rate Limiting:** Conversion operations have rate limiting (2 second minimum interval)
|
|
||||||
6. **Error Message Sanitization:** Absolute paths are stripped from error messages
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Prioritized Remediation Roadmap
|
|
||||||
|
|
||||||
### Phase 1 - Critical (Immediate)
|
|
||||||
1. Set `nodeIntegration: false` and `contextIsolation: true` for main window
|
|
||||||
2. Remove or sandbox the code execution (REPL) feature
|
|
||||||
3. Implement proper preload.js usage for all windows
|
|
||||||
|
|
||||||
### Phase 2 - High Priority (1-2 Weeks)
|
|
||||||
4. Add path traversal protection to file operations
|
|
||||||
5. Strengthen Content Security Policy
|
|
||||||
6. Audit and fix custom markdown extensions for XSS
|
|
||||||
|
|
||||||
### Phase 3 - Medium Priority (1 Month)
|
|
||||||
7. Implement consistent security settings across all windows
|
|
||||||
8. Add local PlantUML rendering option
|
|
||||||
9. Implement dependency scanning in CI/CD
|
|
||||||
|
|
||||||
### Phase 4 - Low Priority (Ongoing)
|
|
||||||
10. Pin dependency versions
|
|
||||||
11. Add security headers to all generated HTML
|
|
||||||
12. Implement security logging and monitoring
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Compliance Considerations
|
|
||||||
|
|
||||||
- **OWASP Top 10 2021:** A03:2021 - Injection, A05:2021 - Security Misconfiguration
|
|
||||||
- **OWASP ASVS:** V12 - File Handling, V13 - API Security
|
|
||||||
- **NIST CSF:** PR.AC - Access Control, PR.DS - Data Security
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Conclusion
|
|
||||||
|
|
||||||
The MarkdownConverter application has significant security vulnerabilities that could allow an attacker to execute arbitrary code, access sensitive files, and compromise the user's system. The most critical issue is the insecure Electron configuration combined with XSS attack vectors in the markdown rendering pipeline.
|
|
||||||
|
|
||||||
**Overall Security Rating: HIGH RISK**
|
|
||||||
|
|
||||||
The positive finding is that much of the security infrastructure (preload.js, DOMPurify) is already in place but not properly utilized. With focused remediation effort, the application can achieve a much stronger security posture.
|
|
||||||
@@ -1,215 +0,0 @@
|
|||||||
# STRIDE Threat Model - MarkdownConverter v4.0.0
|
|
||||||
|
|
||||||
**Analysis Date:** 2026-03-15
|
|
||||||
**Methodology:** STRIDE + MITRE ATT&CK
|
|
||||||
**Overall Risk Score:** 7.8 (HIGH)
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Executive Summary
|
|
||||||
|
|
||||||
The analysis identified **10 vulnerabilities** with a combined risk score of **7.8 (HIGH)**. The most critical issues enable complete system compromise through XSS-to-RCE attack chains.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Critical Findings
|
|
||||||
|
|
||||||
| Priority | CVE | Vulnerability | CVSS | Impact |
|
|
||||||
|----------|-----|---------------|------|--------|
|
|
||||||
| P0 | CVE-MC-001 | Insecure Electron Config (`nodeIntegration: true`, `contextIsolation: false`) | 9.6 | Complete system compromise |
|
|
||||||
| P0 | CVE-MC-002 | Arbitrary code execution via REPL feature | 9.3 | Remote code execution |
|
|
||||||
| P1 | CVE-MC-003 | XSS in markdown rendering | 8.0 | Session hijacking, RCE chain |
|
|
||||||
| P1 | CVE-MC-004 | Path traversal vulnerability | 7.8 | Arbitrary file write |
|
|
||||||
| P1 | CVE-MC-005 | Weak Content Security Policy | 7.5 | XSS enablement |
|
|
||||||
| P2 | CVE-MC-006 | Insecure window config for PDF export | 6.5 | Privilege escalation |
|
|
||||||
| P2 | CVE-MC-007 | PlantUML server data exfiltration | 5.3 | Information disclosure |
|
|
||||||
| P2 | CVE-MC-008 | Inconsistent security settings | 5.5 | Configuration weakness |
|
|
||||||
| P3 | CVE-MC-009 | Command execution via external tools | 4.4 | Command injection risk |
|
|
||||||
| P3 | CVE-MC-010 | Missing dependency version pinning | 3.5 | Supply chain risk |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Key Attack Vectors
|
|
||||||
|
|
||||||
### 1. XSS to RCE Chain (Critical)
|
|
||||||
```
|
|
||||||
Malicious Markdown File
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
XSS in Preview (CVE-MC-003)
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
nodeIntegration: true (CVE-MC-001)
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
Full Node.js Access
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
Complete System Compromise
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2. REPL Code Execution (Critical)
|
|
||||||
```
|
|
||||||
Code Block in Markdown
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
User clicks "Run"
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
REPL executes Python/Bash (CVE-MC-002)
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
Arbitrary Code Execution
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3. Data Exfiltration (Medium)
|
|
||||||
```
|
|
||||||
PlantUML Diagram Content
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
Sent to www.plantuml.com (CVE-MC-007)
|
|
||||||
│
|
|
||||||
▼
|
|
||||||
Sensitive Architecture Leaked
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## STRIDE Analysis
|
|
||||||
|
|
||||||
### S - Spoofing
|
|
||||||
| ID | Threat | Likelihood | Impact | Risk |
|
|
||||||
|----|--------|------------|--------|------|
|
|
||||||
| S1 | Attacker spoofs markdown file origin | Medium | High | High |
|
|
||||||
| S2 | Malicious code pretends to be safe | High | Critical | Critical |
|
|
||||||
|
|
||||||
### T - Tampering
|
|
||||||
| ID | Threat | Likelihood | Impact | Risk |
|
|
||||||
|----|--------|------------|--------|------|
|
|
||||||
| T1 | XSS modifies local files | High | Critical | Critical |
|
|
||||||
| T2 | Conversion output tampered | Medium | Medium | Medium |
|
|
||||||
|
|
||||||
### R - Repudiation
|
|
||||||
| ID | Threat | Likelihood | Impact | Risk |
|
|
||||||
|----|--------|------------|--------|------|
|
|
||||||
| R1 | No audit trail for operations | Low | Low | Low |
|
|
||||||
|
|
||||||
### I - Information Disclosure
|
|
||||||
| ID | Threat | Likelihood | Impact | Risk |
|
|
||||||
|----|--------|------------|--------|------|
|
|
||||||
| I1 | XSS exposes file system | High | Critical | Critical |
|
|
||||||
| I2 | PlantUML content leaked | Medium | Medium | Medium |
|
|
||||||
| I3 | Error messages reveal paths | Low | Low | Low |
|
|
||||||
|
|
||||||
### D - Denial of Service
|
|
||||||
| ID | Threat | Likelihood | Impact | Risk |
|
|
||||||
|----|--------|------------|--------|------|
|
|
||||||
| D1 | Malicious code crashes app | Medium | Medium | Medium |
|
|
||||||
| D2 | Large file exhausts resources | Low | Low | Low |
|
|
||||||
|
|
||||||
### E - Elevation of Privilege
|
|
||||||
| ID | Threat | Likelihood | Impact | Risk |
|
|
||||||
|----|--------|------------|--------|------|
|
|
||||||
| E1 | XSS → nodeIntegration → System | High | Critical | Critical |
|
|
||||||
| E2 | REPL code execution | High | Critical | Critical |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## MITRE ATT&CK Mapping
|
|
||||||
|
|
||||||
| Technique | ID | Applicability |
|
|
||||||
|-----------|-----|---------------|
|
|
||||||
| User Execution | T1204.002 | Malicious markdown file |
|
|
||||||
| Command and Scripting Interpreter | T1059.007 | JavaScript via nodeIntegration |
|
|
||||||
| Command and Scripting Interpreter | T1059.006 | Python via REPL |
|
|
||||||
| Command and Scripting Interpreter | T1059.004 | Bash via REPL |
|
|
||||||
| Exploit Public-Facing Application | T1190 | XSS in preview |
|
|
||||||
| Data Exfiltration Over Web Service | T1043 | PlantUML server |
|
|
||||||
| File and Directory Discovery | T1083 | Path traversal |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Trust Boundaries
|
|
||||||
|
|
||||||
```
|
|
||||||
┌─────────────────────────────────────────────────────────────────────┐
|
|
||||||
│ TRUST BOUNDARY MAP │
|
|
||||||
├─────────────────────────────────────────────────────────────────────┤
|
|
||||||
│ │
|
|
||||||
│ ┌─────────────┐ ┌─────────────────────────────────────┐ │
|
|
||||||
│ │ USER │ ──────► │ APPLICATION │ │
|
|
||||||
│ │ (Untrusted) │ │ ┌───────────┐ ┌───────────────┐ │ │
|
|
||||||
│ └─────────────┘ │ │ Renderer │ │ Main Process │ │ │
|
|
||||||
│ │ │ (Sandbox) │ │ (Privileged) │ │ │
|
|
||||||
│ │ └─────┬─────┘ └───────┬───────┘ │ │
|
|
||||||
│ │ │ IPC │ │ │
|
|
||||||
│ │ ▼ ▼ │ │
|
|
||||||
│ │ ┌─────────────────────────────┐ │ │
|
|
||||||
│ │ │ File System │ │ │
|
|
||||||
│ │ └─────────────────────────────┘ │ │
|
|
||||||
│ └─────────────────────────────────────┘ │
|
|
||||||
│ │ │
|
|
||||||
│ ▼ │
|
|
||||||
│ ┌─────────────────────────────────────────────────────────────┐ │
|
|
||||||
│ │ EXTERNAL SERVICES │ │
|
|
||||||
│ │ • PlantUML Server (www.plantuml.com) │ │
|
|
||||||
│ │ • CDN (cdn.jsdelivr.net, cdnjs.cloudflare.com) [REMOVED] │ │
|
|
||||||
│ │ • External Tools (Pandoc, FFmpeg, LibreOffice) │ │
|
|
||||||
│ └─────────────────────────────────────────────────────────────┘ │
|
|
||||||
│ │
|
|
||||||
└─────────────────────────────────────────────────────────────────────┘
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Business Impact Analysis
|
|
||||||
|
|
||||||
### Successful Attack Consequences
|
|
||||||
|
|
||||||
| Impact Category | Estimate |
|
|
||||||
|-----------------|----------|
|
|
||||||
| Data breach costs | $500,000 - $5,000,000+ |
|
|
||||||
| Regulatory fines (GDPR) | Up to 4% annual revenue |
|
|
||||||
| Reputation damage | Incalculable |
|
|
||||||
| Business disruption | Hours to days |
|
|
||||||
|
|
||||||
### Affected Assets
|
|
||||||
- User documents and files
|
|
||||||
- System credentials
|
|
||||||
- Proprietary information in diagrams
|
|
||||||
- Application integrity
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Remediation Priority
|
|
||||||
|
|
||||||
### P0 - Immediate (24-48 hours)
|
|
||||||
1. **CVE-MC-001**: Set `nodeIntegration: false`, `contextIsolation: true`
|
|
||||||
2. **CVE-MC-002**: Remove or sandbox REPL code execution
|
|
||||||
|
|
||||||
### P1 - Short-term (1-2 weeks)
|
|
||||||
3. **CVE-MC-003**: Audit markdown extensions for XSS
|
|
||||||
4. **CVE-MC-004**: Add path validation (✅ COMPLETED)
|
|
||||||
5. **CVE-MC-005**: Strengthen CSP (✅ COMPLETED)
|
|
||||||
|
|
||||||
### P2 - Medium-term (1 month)
|
|
||||||
6. **CVE-MC-006**: Consistent window security settings
|
|
||||||
7. **CVE-MC-007**: Add local PlantUML option or warning
|
|
||||||
8. **CVE-MC-008**: Audit all BrowserWindow configurations
|
|
||||||
|
|
||||||
### P3 - Long-term
|
|
||||||
9. **CVE-MC-009**: Validate filenames for external tools
|
|
||||||
10. **CVE-MC-010**: Pin dependency versions, add scanning
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Conclusion
|
|
||||||
|
|
||||||
The MarkdownConverter application has a **HIGH RISK** threat profile due to the combination of:
|
|
||||||
- Untrusted content rendering (markdown preview)
|
|
||||||
- Direct system access (nodeIntegration)
|
|
||||||
- Code execution capability (REPL)
|
|
||||||
|
|
||||||
**Immediate action required on P0 items to reduce attack surface.**
|
|
||||||
|
|
||||||
The fixes applied in this session (CSP, path traversal, UI accessibility) have reduced the risk profile, but the critical nodeIntegration issue requires significant refactoring.
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
{
|
|
||||||
"target": "MarkdownConverter Electron Application",
|
|
||||||
"status": "in_progress",
|
|
||||||
"depth": "comprehensive",
|
|
||||||
"compliance_frameworks": ["owasp"],
|
|
||||||
"current_step": 3,
|
|
||||||
"current_phase": 1,
|
|
||||||
"completed_steps": ["vulnerability-scan", "threat-modeling"],
|
|
||||||
"files_created": ["01-vulnerability-scan.md", "02-threat-model.md"],
|
|
||||||
"started_at": "2026-03-15T00:09:00.000Z",
|
|
||||||
"last_updated": "2026-03-15T00:25:00.000Z",
|
|
||||||
"findings_summary": {
|
|
||||||
"critical": 2,
|
|
||||||
"high": 3,
|
|
||||||
"medium": 3,
|
|
||||||
"low": 2,
|
|
||||||
"total": 10
|
|
||||||
},
|
|
||||||
"fixes_applied": {
|
|
||||||
"csp_external_cdns_removed": true,
|
|
||||||
"path_traversal_protection_added": true,
|
|
||||||
"aria_labels_added": true,
|
|
||||||
"focus_visible_styles_added": true,
|
|
||||||
"tab_close_button_resized": true,
|
|
||||||
"duplicate_font_size_fixed": true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,522 +0,0 @@
|
|||||||
# Comprehensive UI Design Review - MarkdownConverter Electron Application
|
|
||||||
|
|
||||||
## Executive Summary
|
|
||||||
|
|
||||||
This review covers the UI design of the MarkdownConverter Electron application, analyzing visual design, usability, code quality, and performance across all UI files. The application has a solid foundation but has several areas requiring attention.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 1. Visual Design Review
|
|
||||||
|
|
||||||
### 1.1 Spacing & Layout Consistency
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | Inconsistent padding values across files | Multiple CSS files | Standardize to 4px/8px base scale |
|
|
||||||
| **Major** | Multiple reset declarations | `styles.css:1-5`, `styles-modern.css:42-47` | Consolidate resets into single file |
|
|
||||||
| **Minor** | Tab padding varies between themes | `styles.css:36`, `styles-modern.css:101` | Use CSS variables for consistent padding |
|
|
||||||
| **Minor** | Container padding inconsistency | `styles.css:17-21`, `styles-modern.css:63-69` | Define single container style |
|
|
||||||
|
|
||||||
**Code Example - Duplicate Reset:**
|
|
||||||
|
|
||||||
```css
|
|
||||||
/* styles.css:1-5 */
|
|
||||||
* {
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
box-sizing: border-box;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* styles-modern.css:42-47 - DUPLICATE */
|
|
||||||
* {
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
box-sizing: border-box;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
/* Create a single base.css or remove from styles-modern.css */
|
|
||||||
/* Use CSS variables for spacing scale */
|
|
||||||
:root {
|
|
||||||
--space-1: 4px;
|
|
||||||
--space-2: 8px;
|
|
||||||
--space-3: 12px;
|
|
||||||
--space-4: 16px;
|
|
||||||
--space-5: 24px;
|
|
||||||
--space-6: 32px;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 1.2 Typography Consistency
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | Font-family declared multiple times with different fallbacks | `styles.css:8`, `styles-modern.css:50`, `styles-concreteinfo.css:32` | Standardize font stack |
|
|
||||||
| **Major** | Duplicate font-size declarations | `styles.css:228-230` | Remove duplicate |
|
|
||||||
| **Minor** | Inconsistent line-height values | Multiple files | Create type scale variables |
|
|
||||||
|
|
||||||
**Code Example - Duplicate font-size:**
|
|
||||||
```css
|
|
||||||
/* styles.css:226-230 */
|
|
||||||
.preview-content {
|
|
||||||
max-width: none;
|
|
||||||
margin: 0;
|
|
||||||
padding: 20px 24px 24px 24px;
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 15px;
|
|
||||||
font-size: 14px; /* DUPLICATE - overwrites previous */
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
/* styles.css - Remove duplicate */
|
|
||||||
.preview-content {
|
|
||||||
font-size: 14px; /* Keep only one */
|
|
||||||
line-height: 1.6;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 1.3 Color Usage and Contrast Accessibility
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Critical** | Hardcoded colors instead of CSS variables | `styles.css:27-29`, `styles.css:37-38`, etc. | Use CSS custom properties |
|
|
||||||
| **Major** | Inconsistent gray scale definitions | Multiple files define different grays | Consolidate to single palette |
|
|
||||||
| **Minor** | Some contrast ratios may be insufficient | Status bar text colors | Verify WCAG 2.1 AA compliance |
|
|
||||||
|
|
||||||
**Code Example - Hardcoded colors:**
|
|
||||||
```css
|
|
||||||
/* styles.css:27-29 */
|
|
||||||
.tab-bar {
|
|
||||||
background: #f0f0f0; /* Should use var(--gray-100) */
|
|
||||||
border-bottom: 1px solid #ddd; /* Should use var(--gray-300) */
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
/* Use the existing palette from styles-modern.css */
|
|
||||||
.tab-bar {
|
|
||||||
background: var(--gray-100, #f3f4f6);
|
|
||||||
border-bottom: 1px solid var(--gray-300, #d1d5db);
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 1.4 Dark Mode Support Quality
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | Dark theme selectors inconsistent | `styles.css` uses `body.theme-dark`, `styles-sidebar.css:108` uses `body[class*="dark"]` | Standardize selector pattern |
|
|
||||||
| **Minor** | Missing dark theme support for some components | `.breadcrumb-bar`, command palette | Add dark mode variants |
|
|
||||||
| **Suggestion** | Repetitive dark theme declarations | `styles-concreteinfo.css:362-425` | Use CSS custom properties for theming |
|
|
||||||
|
|
||||||
**Code Example - Inconsistent selectors:**
|
|
||||||
```css
|
|
||||||
/* styles.css */
|
|
||||||
body.theme-dark .tab-bar { ... }
|
|
||||||
|
|
||||||
/* styles-sidebar.css */
|
|
||||||
body[class*="dark"] .sidebar-icons { ... }
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
/* Choose one pattern and apply consistently */
|
|
||||||
/* Option 1: Class-based (recommended) */
|
|
||||||
body.theme-dark .tab-bar,
|
|
||||||
body.theme-dark .sidebar-icons { ... }
|
|
||||||
|
|
||||||
/* Option 2: Attribute-based */
|
|
||||||
body[data-theme="dark"] .tab-bar { ... }
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 2. Usability Review
|
|
||||||
|
|
||||||
### 2.1 Clickable/Tappable Areas
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Critical** | Tab close button too small (16x16px) | `styles.css:62-77` | Increase to minimum 24x24px |
|
|
||||||
| **Major** | Sidebar icons at minimum size | `styles-sidebar.css:35-47` (36x36px) | Consider 40-44px for better touch |
|
|
||||||
| **Minor** | Toolbar buttons at edge of minimum | `styles.css:120-131` (32x32px) | Acceptable for mouse, small for touch |
|
|
||||||
|
|
||||||
**Code Example - Small close button:**
|
|
||||||
```css
|
|
||||||
/* styles.css:62-77 */
|
|
||||||
.tab-close {
|
|
||||||
width: 16px; /* TOO SMALL - below 24px minimum */
|
|
||||||
height: 16px; /* TOO SMALL */
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
.tab-close {
|
|
||||||
width: 24px;
|
|
||||||
height: 24px;
|
|
||||||
border-radius: 4px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Add touch-friendly hit area */
|
|
||||||
.tab-close::before {
|
|
||||||
content: '';
|
|
||||||
position: absolute;
|
|
||||||
top: -4px;
|
|
||||||
left: -4px;
|
|
||||||
right: -4px;
|
|
||||||
bottom: -4px;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.2 Hover/Focus States
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Critical** | Missing focus-visible styles | All interactive elements | Add :focus-visible for keyboard navigation |
|
|
||||||
| **Major** | No focus indicators on toolbar buttons | `styles.css:133-140` | Add visible focus ring |
|
|
||||||
| **Minor** | Inconsistent hover transitions | Various components | Standardize transition duration |
|
|
||||||
|
|
||||||
**Code Example - Missing focus styles:**
|
|
||||||
```css
|
|
||||||
/* styles.css:120-131 - No focus state */
|
|
||||||
.toolbar button {
|
|
||||||
/* ... no focus style */
|
|
||||||
}
|
|
||||||
|
|
||||||
.toolbar button:hover {
|
|
||||||
background: #e0e0e0;
|
|
||||||
border-color: #ccc;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
.toolbar button:focus-visible {
|
|
||||||
outline: 2px solid var(--primary-dark, #5661b3);
|
|
||||||
outline-offset: 2px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.toolbar button:hover {
|
|
||||||
background: #e0e0e0;
|
|
||||||
border-color: #ccc;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.3 Loading and Error State Handling
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | Generic error message without styling | `renderer.js:384-386`, `renderer.js:508-511` | Create styled error components |
|
|
||||||
| **Minor** | No loading indicators for async operations | Sidebar panels | Add skeleton loaders or spinners |
|
|
||||||
| **Minor** | `git-loading` class exists but minimal styling | `styles-sidebar.css:227` | Enhance with animation |
|
|
||||||
|
|
||||||
**Code Example - Plain error display:**
|
|
||||||
```javascript
|
|
||||||
// renderer.js:384-386
|
|
||||||
preview.innerHTML = '<p style="color: red; padding: 20px;">Error: Required libraries...';
|
|
||||||
// Inline styles should be in CSS
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
/* Add to styles.css */
|
|
||||||
.preview-error {
|
|
||||||
display: flex;
|
|
||||||
flex-direction: column;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
padding: 40px 20px;
|
|
||||||
color: var(--ci-danger, #dc3545);
|
|
||||||
text-align: center;
|
|
||||||
}
|
|
||||||
|
|
||||||
.preview-error-icon {
|
|
||||||
font-size: 48px;
|
|
||||||
margin-bottom: 16px;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.4 Accessibility (ARIA, Semantic HTML)
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Critical** | Buttons without accessible labels | `index.html:31` (tab close), `index.html:33` (new tab) | Add aria-label |
|
|
||||||
| **Critical** | SVG icons lack aria-hidden | All toolbar buttons | Add aria-hidden="true" |
|
|
||||||
| **Major** | Missing role attributes on tabs | `index.html:29-33` | Add role="tablist", role="tab" |
|
|
||||||
| **Major** | No skip links | `index.html` | Add skip to main content link |
|
|
||||||
| **Minor** | Dialog missing aria-modal | Export dialogs | Add aria-modal="true" |
|
|
||||||
|
|
||||||
**Code Example - Missing accessibility attributes:**
|
|
||||||
```html
|
|
||||||
<!-- index.html:31 - Current -->
|
|
||||||
<button class="tab-close" title="Close tab">x</button>
|
|
||||||
|
|
||||||
<!-- index.html:33 - Current -->
|
|
||||||
<button class="new-tab-button" id="new-tab-btn" title="New tab">+</button>
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```html
|
|
||||||
<!-- Improved with ARIA -->
|
|
||||||
<div class="tab-bar" id="tab-bar" role="tablist" aria-label="Document tabs">
|
|
||||||
<div class="tab active" data-tab-id="1" role="tab" aria-selected="true" aria-controls="tab-content-1">
|
|
||||||
<span class="tab-title">Untitled</span>
|
|
||||||
<button class="tab-close" aria-label="Close tab" title="Close tab">×</button>
|
|
||||||
</div>
|
|
||||||
<button class="new-tab-button" id="new-tab-btn" aria-label="Create new tab" title="New tab">+</button>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<!-- SVG icons should have aria-hidden -->
|
|
||||||
<button id="btn-bold" title="Bold (Ctrl+B)" aria-label="Bold">
|
|
||||||
<svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" aria-hidden="true">
|
|
||||||
...
|
|
||||||
</svg>
|
|
||||||
</button>
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.5 Keyboard Navigation
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | Tab order may skip sidebar icons | Sidebar panel | Verify logical tab order |
|
|
||||||
| **Minor** | No escape key handling for dialogs | Export dialogs | Add escape to close |
|
|
||||||
| **Minor** | Find dialog lacks full keyboard support | `renderer.js:804-866` | Add Ctrl+F shortcut hint |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 3. Code Quality Review
|
|
||||||
|
|
||||||
### 3.1 CSS Organization & Naming
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | No clear CSS architecture | All CSS files | Adopt BEM or similar methodology |
|
|
||||||
| **Major** | Overly generic class names | `.pane`, `.tab`, `.container` | Use more specific naming |
|
|
||||||
| **Minor** | Mixed naming conventions | camelCase (`tabBar`), kebab-case (`tab-bar`) | Standardize to kebab-case |
|
|
||||||
| **Minor** | Magic numbers | Various pixel values | Replace with spacing variables |
|
|
||||||
|
|
||||||
### 3.2 CSS Specificity Issues
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | Excessive use of `!important` | `styles.css:14` | Restructure to avoid |
|
|
||||||
| **Major** | Deep selector nesting | Dark theme selectors | Flatten and use CSS variables |
|
|
||||||
| **Minor** | ID selectors for styling | `styles.css:233-247` | Prefer class selectors |
|
|
||||||
|
|
||||||
**Code Example - Problematic specificity:**
|
|
||||||
```css
|
|
||||||
/* styles.css:14 - Avoid !important */
|
|
||||||
.hidden {
|
|
||||||
display: none !important;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* styles.css:397-431 - Deep nesting */
|
|
||||||
body.theme-dark #preview h1,
|
|
||||||
body.theme-dark [id^="preview-"] h1,
|
|
||||||
body.theme-dark .preview-content h1 {
|
|
||||||
color: #c9d1d9;
|
|
||||||
border-bottom-color: #21262d;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
/* Use utility class pattern */
|
|
||||||
[hidden] { display: none; }
|
|
||||||
|
|
||||||
/* Use CSS custom properties for theming */
|
|
||||||
.preview-content h1 {
|
|
||||||
color: var(--text-primary);
|
|
||||||
border-bottom-color: var(--border-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Theme applies variables */
|
|
||||||
body.theme-dark {
|
|
||||||
--text-primary: #c9d1d9;
|
|
||||||
--border-color: #21262d;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3.3 Reusable Style Definitions
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | Repeated button styles | Multiple files | Create button component classes |
|
|
||||||
| **Major** | Dialog styles duplicated | Export, batch, print preview dialogs | Create modal component |
|
|
||||||
| **Minor** | Similar form field styles scattered | Export dialog inputs | Create form component |
|
|
||||||
|
|
||||||
**Code Example - Duplicated button styles:**
|
|
||||||
```css
|
|
||||||
/* styles.css */
|
|
||||||
.toolbar button { /* button styles */ }
|
|
||||||
.tab-close { /* button styles */ }
|
|
||||||
.new-tab-button { /* button styles */ }
|
|
||||||
#export-dialog-close { /* button styles */ }
|
|
||||||
|
|
||||||
/* styles-sidebar.css */
|
|
||||||
.sidebar-icon { /* similar button styles */ }
|
|
||||||
.sidebar-panel-close { /* similar button styles */ }
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```css
|
|
||||||
/* Create button component system */
|
|
||||||
.btn {
|
|
||||||
display: inline-flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
border: none;
|
|
||||||
cursor: pointer;
|
|
||||||
transition: all var(--transition-fast);
|
|
||||||
}
|
|
||||||
|
|
||||||
.btn--icon {
|
|
||||||
width: 32px;
|
|
||||||
height: 32px;
|
|
||||||
border-radius: var(--radius-md);
|
|
||||||
}
|
|
||||||
|
|
||||||
.btn--close {
|
|
||||||
font-size: 14px;
|
|
||||||
font-weight: bold;
|
|
||||||
border-radius: var(--radius-sm);
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3.4 Documentation
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Minor** | Limited CSS documentation | All CSS files | Add section comments |
|
|
||||||
| **Minor** | No component documentation | Sidebar components | Add JSDoc-style comments |
|
|
||||||
| **Suggestion** | No design tokens documentation | CSS variables | Create tokens documentation |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 4. Performance Review
|
|
||||||
|
|
||||||
### 4.1 CSS Optimization
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | Large CSS files (105KB main, 78KB modern) | `styles.css`, `styles-modern.css` | Split into smaller modules |
|
|
||||||
| **Major** | Duplicate style definitions | Multiple files | Remove redundancies |
|
|
||||||
| **Minor** | Unused styles likely present | Theme variations | Audit and remove unused |
|
|
||||||
|
|
||||||
### 4.2 Asset Loading
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Major** | highlight.js CSS loaded synchronously | `index.html:14` | Load asynchronously or bundle |
|
|
||||||
| **Minor** | Font files could be preloaded | `fonts.css` | Add preload links in HTML |
|
|
||||||
| **Suggestion** | Consider CSS critical path | Above-the-fold styles | Inline critical CSS |
|
|
||||||
|
|
||||||
**Code Example - Sync stylesheet loading:**
|
|
||||||
```html
|
|
||||||
<!-- index.html:14 - Blocks rendering -->
|
|
||||||
<link rel="stylesheet" href="../node_modules/highlight.js/styles/default.css">
|
|
||||||
```
|
|
||||||
|
|
||||||
**Fix Recommendation:**
|
|
||||||
```html
|
|
||||||
<!-- Non-blocking load -->
|
|
||||||
<link rel="stylesheet" href="../node_modules/highlight.js/styles/default.css" media="print" onload="this.media='all'">
|
|
||||||
|
|
||||||
<!-- Or preload fonts -->
|
|
||||||
<link rel="preload" href="../assets/fonts/Inter-Regular.woff2" as="font" type="font/woff2" crossorigin>
|
|
||||||
```
|
|
||||||
|
|
||||||
### 4.3 Animation Performance
|
|
||||||
|
|
||||||
| Severity | Issue | Location | Recommendation |
|
|
||||||
|----------|-------|----------|----------------|
|
|
||||||
| **Minor** | Some transitions on expensive properties | `styles-modern.css:111-112` | Prefer transform/opacity |
|
|
||||||
| **Suggestion** | Missing will-change hints | Complex animations | Add will-change for GPU hints |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 5. Component-Specific Issues
|
|
||||||
|
|
||||||
### 5.1 Tab System
|
|
||||||
|
|
||||||
| File | Issues |
|
|
||||||
|------|--------|
|
|
||||||
| `styles.css:23-97` | Inconsistent active state styling, small close button |
|
|
||||||
| `renderer.js:88-346` | Tab content created via innerHTML (XSS risk) |
|
|
||||||
|
|
||||||
### 5.2 Sidebar
|
|
||||||
|
|
||||||
| File | Issues |
|
|
||||||
|------|--------|
|
|
||||||
| `styles-sidebar.css` | Good structure but missing focus states |
|
|
||||||
| `sidebar-manager.js` | Clean implementation, needs ARIA |
|
|
||||||
|
|
||||||
### 5.3 Export Dialogs
|
|
||||||
|
|
||||||
| File | Issues |
|
|
||||||
|------|--------|
|
|
||||||
| `styles.css:1060-1355` | Monolithic, should be component |
|
|
||||||
| `index.html:171-331` | Complex nested structure needs semantic HTML |
|
|
||||||
|
|
||||||
### 5.4 Welcome Screen
|
|
||||||
|
|
||||||
| File | Issues |
|
|
||||||
|------|--------|
|
|
||||||
| `styles-welcome.css` | Minimal styles, good foundation |
|
|
||||||
| Missing hover states for keyboard focus | Add :focus-visible |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 6. Prioritized Fix Recommendations
|
|
||||||
|
|
||||||
### Critical (Immediate)
|
|
||||||
|
|
||||||
1. **Add missing ARIA attributes** to all interactive elements
|
|
||||||
2. **Increase tab close button size** to minimum 24x24px
|
|
||||||
3. **Add focus-visible styles** for keyboard navigation
|
|
||||||
4. **Fix duplicate font-size declaration** in `.preview-content`
|
|
||||||
|
|
||||||
### Major (Next Sprint)
|
|
||||||
|
|
||||||
1. **Consolidate CSS resets** into single location
|
|
||||||
2. **Create button component system** with variants
|
|
||||||
3. **Standardize dark theme selectors** across all files
|
|
||||||
4. **Replace hardcoded colors** with CSS variables
|
|
||||||
5. **Create modal/dialog component** to reduce duplication
|
|
||||||
|
|
||||||
### Minor (Future)
|
|
||||||
|
|
||||||
1. **Document CSS architecture** and naming conventions
|
|
||||||
2. **Audit and remove unused styles**
|
|
||||||
3. **Add loading state components** (skeletons, spinners)
|
|
||||||
4. **Implement CSS module splitting** for better performance
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 7. Summary Statistics
|
|
||||||
|
|
||||||
| Category | Critical | Major | Minor | Suggestions |
|
|
||||||
|----------|----------|-------|-------|-------------|
|
|
||||||
| Visual Design | 1 | 5 | 4 | 1 |
|
|
||||||
| Usability | 3 | 4 | 4 | 0 |
|
|
||||||
| Code Quality | 0 | 6 | 4 | 1 |
|
|
||||||
| Performance | 0 | 3 | 2 | 2 |
|
|
||||||
| **Total** | **4** | **18** | **14** | **4** |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Conclusion
|
|
||||||
|
|
||||||
The MarkdownConverter application has a functional UI with good visual variety through its theme system. However, there are significant opportunities for improvement in:
|
|
||||||
|
|
||||||
1. **Accessibility** - Critical for users with disabilities
|
|
||||||
2. **Code organization** - Reduce CSS duplication and improve maintainability
|
|
||||||
3. **Component consistency** - Standardize interactive element sizing and states
|
|
||||||
4. **Performance** - Optimize CSS loading and reduce bundle size
|
|
||||||
|
|
||||||
Addressing the Critical and Major issues will significantly improve both user experience and code maintainability.
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
{
|
|
||||||
"review_id": "full-ui-review_20260315",
|
|
||||||
"target": "src/ (Entire UI Directory)",
|
|
||||||
"focus_areas": ["visual", "usability", "code", "performance"],
|
|
||||||
"context": "comprehensive",
|
|
||||||
"platform": "desktop",
|
|
||||||
"status": "complete",
|
|
||||||
"started_at": "2026-03-15T00:09:00.000Z",
|
|
||||||
"completed_at": "2026-03-15T00:12:00.000Z",
|
|
||||||
"issues_found": 40,
|
|
||||||
"severity_counts": {
|
|
||||||
"critical": 4,
|
|
||||||
"major": 18,
|
|
||||||
"minor": 14,
|
|
||||||
"suggestion": 4
|
|
||||||
}
|
|
||||||
}
|
|
||||||
Vendored
-48
@@ -1,48 +0,0 @@
|
|||||||
{
|
|
||||||
"version": "0.2.0",
|
|
||||||
"configurations": [
|
|
||||||
{
|
|
||||||
"name": "Debug Main Process",
|
|
||||||
"type": "node",
|
|
||||||
"request": "launch",
|
|
||||||
"cwd": "${workspaceFolder}",
|
|
||||||
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron",
|
|
||||||
"windows": {
|
|
||||||
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron.cmd"
|
|
||||||
},
|
|
||||||
"args": ["."],
|
|
||||||
"outputCapture": "std",
|
|
||||||
"env": {
|
|
||||||
"NODE_ENV": "development"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "Debug Renderer Process",
|
|
||||||
"type": "chrome",
|
|
||||||
"request": "attach",
|
|
||||||
"port": 9222,
|
|
||||||
"webRoot": "${workspaceFolder}/src",
|
|
||||||
"timeout": 30000
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "Debug Main + Renderer",
|
|
||||||
"type": "node",
|
|
||||||
"request": "launch",
|
|
||||||
"cwd": "${workspaceFolder}",
|
|
||||||
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron",
|
|
||||||
"windows": {
|
|
||||||
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron.cmd"
|
|
||||||
},
|
|
||||||
"args": [".", "--remote-debugging-port=9222"],
|
|
||||||
"outputCapture": "std",
|
|
||||||
"env": {
|
|
||||||
"NODE_ENV": "development"
|
|
||||||
},
|
|
||||||
"serverReadyAction": {
|
|
||||||
"pattern": "listening on port ([0-9]+)",
|
|
||||||
"uriFormat": "http://localhost:%s",
|
|
||||||
"action": "debugWithChrome"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
# Repository Guidelines
|
|
||||||
|
|
||||||
## Project Structure & Module Organization
|
|
||||||
Core application code lives in `src/`. Use `src/main.js` for the Electron main process, `src/preload.js` for the preload bridge, and `src/renderer.js` plus `src/editor/`, `src/sidebar/`, `src/repl/`, and `src/utils/` for renderer-side features. Electron adapter code is in `src/adapters/electron/`. Reusable markdown/document templates live in `src/templates/`. Static assets and icons are in `assets/`. Tests are in `tests/`, and build output goes to `dist/`.
|
|
||||||
|
|
||||||
## Build, Test, and Development Commands
|
|
||||||
- `npm start`: launch the Electron app locally.
|
|
||||||
- `npm test`: run the Jest suite once.
|
|
||||||
- `npm run test:watch`: rerun tests during local development.
|
|
||||||
- `npm run test:coverage`: generate coverage output.
|
|
||||||
- `npm run lint` / `npm run lint:fix`: check or fix ESLint issues in `src` and `tests`.
|
|
||||||
- `npm run format` / `npm run format:check`: apply or verify Prettier formatting.
|
|
||||||
- `npm run build:linux`, `npm run build:win`, `npm run build:mac`: create platform packages with `electron-builder`.
|
|
||||||
|
|
||||||
## Coding Style & Naming Conventions
|
|
||||||
This repo uses Prettier and ESLint. Follow `.prettierrc`: 2-space indentation, single quotes, semicolons, trailing commas where valid in ES5, and a 100-character line width. Prefer `camelCase` for variables/functions, `PascalCase` for classes, and kebab-case for file names only when already established. Keep module boundaries clear: UI logic in renderer modules, OS/file-system work behind Electron IPC and adapters.
|
|
||||||
|
|
||||||
## Testing Guidelines
|
|
||||||
Tests use Jest with `jest-environment-jsdom`. Add new tests under `tests/` with `*.test.js` names, mirroring the feature area when possible, for example `tests/sidebar.test.js` or `tests/print-preview.test.js`. Update or add regression tests for renderer behavior, preload APIs, and utility helpers when fixing bugs. Run `npm test` before opening a PR; use `npm run test:coverage` for larger refactors.
|
|
||||||
|
|
||||||
## Commit & Pull Request Guidelines
|
|
||||||
Recent history follows Conventional Commit prefixes such as `feat:`, `fix:`, and `refactor:`. Keep subjects short and imperative, for example `fix: guard modal cleanup on close`. PRs should describe the user-visible change, note test coverage, link any related issue, and include screenshots or GIFs for UI changes.
|
|
||||||
|
|
||||||
## Security & Configuration Tips
|
|
||||||
Do not bypass preload boundaries or introduce direct `eval`/dynamic code paths; ESLint already treats these as errors. Export and conversion features depend on external tools such as Pandoc, FFmpeg, ImageMagick, and LibreOffice, so document any new runtime dependency in `README.md` and packaging config.
|
|
||||||
@@ -1,103 +0,0 @@
|
|||||||
# CLAUDE.md — MarkdownConverter (master)
|
|
||||||
|
|
||||||
> General code-quality, JavaScript, git, security, and testing standards are in the **global CLAUDE.md**. This file holds project- and branch-specific notes.
|
|
||||||
|
|
||||||
## Project Overview
|
|
||||||
|
|
||||||
Electron desktop app for Markdown editing and universal file conversion powered by Pandoc. Cross-platform (Win/macOS/Linux). Features: multi-tab editor with live preview, 25+ themes, PDF viewer/editor (merge/split/compress/rotate/watermark/password), export to 20+ formats (PDF/DOCX/ODT/EPUB/HTML/LaTeX/RTF/PPTX), batch conversion, syntax highlighting, diagram support (Mermaid), Git integration, and a plugin system.
|
|
||||||
|
|
||||||
- **Version:** 4.4.5
|
|
||||||
- **License:** MIT
|
|
||||||
- **App ID:** `com.concreteinfo.markdownconverter`
|
|
||||||
|
|
||||||
## Branch Specifics
|
|
||||||
|
|
||||||
This is the **primary/release branch** — a vanilla JavaScript Electron app with no bundler or framework in the renderer. The renderer is a single large `renderer.js` (5,300+ lines) loaded directly via `src/index.html`. All UI is hand-rolled DOM manipulation.
|
|
||||||
|
|
||||||
## Architecture
|
|
||||||
|
|
||||||
### Main Process (`src/main.js` — 4,260 lines)
|
|
||||||
Monolithic main process file. Contains all IPC handlers, Pandoc invocation, file operations, menu definitions (600+ lines), and window lifecycle. Key modules extracted:
|
|
||||||
- `src/main/PDFOperations.js` — PDF manipulation via `pdf-lib` (merge, split, compress, rotate, delete, reorder, watermark, encrypt, decrypt, permissions)
|
|
||||||
- `src/main/GitOperations.js` — Git status/stage/commit/log via `simple-git`
|
|
||||||
|
|
||||||
### Renderer (`src/renderer.js` — 5,361 lines)
|
|
||||||
Vanilla JS, no framework. Directly manipulates DOM. Loads CodeMirror 6 via `src/editor/codemirror-setup.js`. Uses `marked` + `highlight.js` + `DOMPurify` + `mermaid` for rendering. Lazy-loads sidebar panels, REPL, command palette, zen mode.
|
|
||||||
|
|
||||||
### Preload (`src/preload.js` — 448 lines)
|
|
||||||
Exists as IPC bridge, but **`contextIsolation: false` and `nodeIntegration: true`** — the renderer has full Node access. Preload is effectively a thin passthrough.
|
|
||||||
|
|
||||||
### Security Model
|
|
||||||
- `contextIsolation: false` + `nodeIntegration: true` (legacy; the react-electron branch fixes this)
|
|
||||||
- Pandoc invoked via `execFile` (not `exec`) to prevent shell injection
|
|
||||||
- Path traversal protection: `validatePath()`, `resolveWritablePath()`, blocks sensitive system dirs
|
|
||||||
- Permission handler only allows `clipboard-read`/`clipboard-write`
|
|
||||||
- Rate limiter on conversions (2-second minimum interval)
|
|
||||||
- File size limit: 50MB
|
|
||||||
- Error message sanitization strips absolute paths
|
|
||||||
|
|
||||||
### Plugin System (`src/plugins/`)
|
|
||||||
Manifest-based discovery (`manifest.json`). Built-in `writing-studio` plugin with sprint/goal/snapshot management. Plugin API exposed via `src/plugins/plugin-api.js`.
|
|
||||||
|
|
||||||
### Settings
|
|
||||||
Custom JSON file store at `<userData>/settings.json` (NOT `electron-store` despite the dependency). Recent files at `<userData>/recent-files.json`.
|
|
||||||
|
|
||||||
## System Dependencies
|
|
||||||
|
|
||||||
| Dependency | Required | Notes |
|
|
||||||
|---|---|---|
|
|
||||||
| **Node.js** | >= 20 | Electron 41 bundles Node 20.x |
|
|
||||||
| **Pandoc** | Yes (for exports) | Downloaded to `bin/<platform>/pandoc` via `scripts/download-tools.js` (v3.9.0.2). Falls back to system PATH. Must be present for DOCX/ODT/EPUB/LaTeX/PPTX export. |
|
|
||||||
| **FFmpeg** | Bundled | `ffmpeg-static` npm package; `asarUnpacked` for packaged builds |
|
|
||||||
| **MiKTeX / TeX Live** | Optional | For LaTeX PDF export; MiKTeX PATH injected on Windows automatically |
|
|
||||||
| **ImageMagick** | Optional | Linux image conversion; listed as deb dependency |
|
|
||||||
| **LibreOffice** | Optional | Enhanced document conversion; listed as deb dependency |
|
|
||||||
|
|
||||||
## Development Commands
|
|
||||||
|
|
||||||
```bash
|
|
||||||
npm start # Launch Electron app (dev mode)
|
|
||||||
npm test # Jest test suite
|
|
||||||
npm test:watch # Jest in watch mode
|
|
||||||
npm test:coverage # Jest with coverage report
|
|
||||||
npm run lint # ESLint check (src + tests)
|
|
||||||
npm run lint:fix # ESLint auto-fix
|
|
||||||
npm run format # Prettier write
|
|
||||||
npm run format:check # Prettier check only
|
|
||||||
npm run download-tools # Download Pandoc binaries to bin/
|
|
||||||
npm run generate-icons # Generate app icons via sharp
|
|
||||||
```
|
|
||||||
|
|
||||||
## Build & Package
|
|
||||||
|
|
||||||
**Tool:** `electron-builder` (v26.0.12), config inline in `package.json` (no separate config file).
|
|
||||||
|
|
||||||
| Target | Platforms |
|
|
||||||
|---|---|
|
|
||||||
| `npm run build` | electron-builder (default platform) |
|
|
||||||
| `npm run build:win` | Windows: NSIS installer + portable + zip (x64) |
|
|
||||||
| `npm run build:mac` | macOS: default dmg |
|
|
||||||
| `npm run build:linux` | Linux: deb + AppImage + snap |
|
|
||||||
| `npm run dist` | Build without publish |
|
|
||||||
| `npm run dist:all` | Build for all platforms |
|
|
||||||
|
|
||||||
**Bundled with builds:** Pandoc binary per platform. FFmpeg via `ffmpeg-static` (asarUnpacked). NSIS installer uses custom script at `scripts/nsis-installer.nsh`.
|
|
||||||
|
|
||||||
**Output:** `dist/` directory.
|
|
||||||
|
|
||||||
**CI:** GitHub Actions workflows in `.github/workflows/` (ci.yml, release.yml).
|
|
||||||
|
|
||||||
## Project Conventions / Gotchas
|
|
||||||
|
|
||||||
- **No bundler/transpilation.** The app uses vanilla CommonJS JavaScript. `src/main.js` is loaded directly by Electron. No webpack, no Vite, no TypeScript, no Babel.
|
|
||||||
- **Monolithic files.** `main.js` (4,260 lines) and `renderer.js` (5,361 lines) contain most logic. Not ideal but is the current state of this branch.
|
|
||||||
- **CodeMirror 6** for the editor, configured in `src/editor/codemirror-setup.js`.
|
|
||||||
- **PDF rendering** uses `pdfjs-dist`; **PDF manipulation** uses `pdf-lib` in the main process.
|
|
||||||
- **Renderer security is weak** — full Node access in renderer. Do NOT introduce new privileged renderer code without understanding this.
|
|
||||||
- **Pandoc is external.** Must be installed separately or downloaded via `npm run download-tools`. HTML and built-in PDF export work without Pandoc; other formats require it.
|
|
||||||
- **PDF export fallback chain:** xelatex -> pdflatex -> lualatex -> Electron built-in `printToPDF()`.
|
|
||||||
- **ESLint flat config** (`eslint.config.js`) with ECMAScript 2022. Prettier with 2-space indent, single quotes, semicolons, 100-char width.
|
|
||||||
- **Tests:** Jest with jsdom environment, 15% coverage threshold. 24 test files in `tests/`.
|
|
||||||
- **File associations:** `.md`, `.markdown`, `.pdf` registered at install.
|
|
||||||
- **Single instance lock** enforced via `app.requestSingleInstanceLock()`.
|
|
||||||
- **Adapters layer** (`src/adapters/`) abstracts file system operations for potential future non-Electron targets.
|
|
||||||
+102
-102
@@ -1,103 +1,103 @@
|
|||||||
# Export Functionality Fix - Summary
|
# Export Functionality Fix - Summary
|
||||||
|
|
||||||
## Issues Found and Fixed
|
## Issues Found and Fixed
|
||||||
|
|
||||||
### 1. **Primary Issue: Pandoc Installation Problem**
|
### 1. **Primary Issue: Pandoc Installation Problem**
|
||||||
- **Problem**: Pandoc is installed but has a system error (paging file too small)
|
- **Problem**: Pandoc is installed but has a system error (paging file too small)
|
||||||
- **Impact**: All pandoc-dependent exports (DOCX, LaTeX, etc.) were failing
|
- **Impact**: All pandoc-dependent exports (DOCX, LaTeX, etc.) were failing
|
||||||
- **Solution**: Added robust fallback mechanisms
|
- **Solution**: Added robust fallback mechanisms
|
||||||
|
|
||||||
### 2. **Export Function Improvements**
|
### 2. **Export Function Improvements**
|
||||||
|
|
||||||
#### Before (Issues):
|
#### Before (Issues):
|
||||||
- ❌ No pandoc availability checking
|
- ❌ No pandoc availability checking
|
||||||
- ❌ Poor error messages
|
- ❌ Poor error messages
|
||||||
- ❌ No fallback for missing pandoc
|
- ❌ No fallback for missing pandoc
|
||||||
- ❌ Limited debugging information
|
- ❌ Limited debugging information
|
||||||
|
|
||||||
#### After (Fixed):
|
#### After (Fixed):
|
||||||
- ✅ **Pandoc Detection**: Automatically checks if pandoc is available
|
- ✅ **Pandoc Detection**: Automatically checks if pandoc is available
|
||||||
- ✅ **Built-in HTML Export**: Works without pandoc using marked library
|
- ✅ **Built-in HTML Export**: Works without pandoc using marked library
|
||||||
- ✅ **Built-in PDF Export**: Works without pandoc using Electron's printToPDF
|
- ✅ **Built-in PDF Export**: Works without pandoc using Electron's printToPDF
|
||||||
- ✅ **Better Error Messages**: Clear instructions for users
|
- ✅ **Better Error Messages**: Clear instructions for users
|
||||||
- ✅ **Comprehensive Logging**: Debug information in console
|
- ✅ **Comprehensive Logging**: Debug information in console
|
||||||
- ✅ **Graceful Fallbacks**: Falls back to built-in converters when pandoc fails
|
- ✅ **Graceful Fallbacks**: Falls back to built-in converters when pandoc fails
|
||||||
|
|
||||||
## How It Works Now
|
## How It Works Now
|
||||||
|
|
||||||
### Export Process Flow:
|
### Export Process Flow:
|
||||||
1. **User clicks export** → Check if file is saved
|
1. **User clicks export** → Check if file is saved
|
||||||
2. **Select output location** → Show save dialog
|
2. **Select output location** → Show save dialog
|
||||||
3. **Check pandoc availability** → Async pandoc detection
|
3. **Check pandoc availability** → Async pandoc detection
|
||||||
4. **Choose export method**:
|
4. **Choose export method**:
|
||||||
- **If pandoc available**: Use pandoc with format-specific options
|
- **If pandoc available**: Use pandoc with format-specific options
|
||||||
- **If pandoc not available**:
|
- **If pandoc not available**:
|
||||||
- HTML → Use built-in marked converter
|
- HTML → Use built-in marked converter
|
||||||
- PDF → Use Electron's printToPDF
|
- PDF → Use Electron's printToPDF
|
||||||
- Other formats → Show helpful error with installation guide
|
- Other formats → Show helpful error with installation guide
|
||||||
|
|
||||||
### Supported Export Formats:
|
### Supported Export Formats:
|
||||||
|
|
||||||
#### ✅ **Always Work** (no pandoc required):
|
#### ✅ **Always Work** (no pandoc required):
|
||||||
- **HTML**: Built-in converter using marked library
|
- **HTML**: Built-in converter using marked library
|
||||||
- **PDF**: Built-in converter using Electron
|
- **PDF**: Built-in converter using Electron
|
||||||
|
|
||||||
#### ✅ **Work with Pandoc** (better quality):
|
#### ✅ **Work with Pandoc** (better quality):
|
||||||
- **DOCX**: Microsoft Word format
|
- **DOCX**: Microsoft Word format
|
||||||
- **LaTeX**: LaTeX document
|
- **LaTeX**: LaTeX document
|
||||||
- **RTF**: Rich Text Format
|
- **RTF**: Rich Text Format
|
||||||
- **ODT**: OpenDocument Text
|
- **ODT**: OpenDocument Text
|
||||||
- **EPUB**: E-book format
|
- **EPUB**: E-book format
|
||||||
- **PPTX**: PowerPoint presentations
|
- **PPTX**: PowerPoint presentations
|
||||||
- **ODP**: OpenDocument Presentations
|
- **ODP**: OpenDocument Presentations
|
||||||
|
|
||||||
## Testing the Fixes
|
## Testing the Fixes
|
||||||
|
|
||||||
### Manual Test Procedure:
|
### Manual Test Procedure:
|
||||||
1. **Start the application**: `npm start`
|
1. **Start the application**: `npm start`
|
||||||
2. **Open test file**: Load `test-export.md`
|
2. **Open test file**: Load `test-export.md`
|
||||||
3. **Test HTML export**: File → Export → HTML (should work)
|
3. **Test HTML export**: File → Export → HTML (should work)
|
||||||
4. **Test PDF export**: File → Export → PDF (should work)
|
4. **Test PDF export**: File → Export → PDF (should work)
|
||||||
5. **Test DOCX export**: File → Export → DOCX (will show pandoc error)
|
5. **Test DOCX export**: File → Export → DOCX (will show pandoc error)
|
||||||
|
|
||||||
### Expected Behavior:
|
### Expected Behavior:
|
||||||
- **HTML/PDF exports**: Should work immediately and create files
|
- **HTML/PDF exports**: Should work immediately and create files
|
||||||
- **Other format exports**: Should show informative error about pandoc
|
- **Other format exports**: Should show informative error about pandoc
|
||||||
- **Console logs**: Should show debug information about export process
|
- **Console logs**: Should show debug information about export process
|
||||||
|
|
||||||
## Fix Summary
|
## Fix Summary
|
||||||
|
|
||||||
### Code Changes Made:
|
### Code Changes Made:
|
||||||
1. **Added `checkPandocAvailability()` function** - Detects pandoc
|
1. **Added `checkPandocAvailability()` function** - Detects pandoc
|
||||||
2. **Added `exportToHTML()` function** - Built-in HTML export
|
2. **Added `exportToHTML()` function** - Built-in HTML export
|
||||||
3. **Added `exportToPDFElectron()` function** - Built-in PDF export
|
3. **Added `exportToPDFElectron()` function** - Built-in PDF export
|
||||||
4. **Added `exportWithPandoc()` helper** - Generic pandoc export
|
4. **Added `exportWithPandoc()` helper** - Generic pandoc export
|
||||||
5. **Added `exportWithPandocPDF()` helper** - PDF with fallbacks
|
5. **Added `exportWithPandocPDF()` helper** - PDF with fallbacks
|
||||||
6. **Improved `exportFile()` function** - Main export logic with detection
|
6. **Improved `exportFile()` function** - Main export logic with detection
|
||||||
7. **Enhanced error handling** - Better user messages
|
7. **Enhanced error handling** - Better user messages
|
||||||
8. **Added comprehensive logging** - Debug information
|
8. **Added comprehensive logging** - Debug information
|
||||||
|
|
||||||
### Files Modified:
|
### Files Modified:
|
||||||
- `src/main.js` - Enhanced export functionality
|
- `src/main.js` - Enhanced export functionality
|
||||||
- `test-export.md` - Created test file
|
- `test-export.md` - Created test file
|
||||||
- `test-export-functionality.js` - Created test script
|
- `test-export-functionality.js` - Created test script
|
||||||
|
|
||||||
## User Instructions
|
## User Instructions
|
||||||
|
|
||||||
### For Users Without Pandoc:
|
### For Users Without Pandoc:
|
||||||
- ✅ **HTML and PDF exports work perfectly**
|
- ✅ **HTML and PDF exports work perfectly**
|
||||||
- ✅ **No additional software needed**
|
- ✅ **No additional software needed**
|
||||||
- ✅ **Professional-looking output with proper styling**
|
- ✅ **Professional-looking output with proper styling**
|
||||||
|
|
||||||
### For Users Who Want All Formats:
|
### For Users Who Want All Formats:
|
||||||
1. **Install Pandoc**: Visit https://pandoc.org/installing.html
|
1. **Install Pandoc**: Visit https://pandoc.org/installing.html
|
||||||
2. **For PDF with LaTeX**: Also install MiKTeX or TeX Live
|
2. **For PDF with LaTeX**: Also install MiKTeX or TeX Live
|
||||||
3. **Restart the application** after installation
|
3. **Restart the application** after installation
|
||||||
4. **All export formats will then be available**
|
4. **All export formats will then be available**
|
||||||
|
|
||||||
## Result
|
## Result
|
||||||
🎉 **Export functionality is now working reliably!**
|
🎉 **Export functionality is now working reliably!**
|
||||||
- Built-in exports (HTML, PDF) work without any dependencies
|
- Built-in exports (HTML, PDF) work without any dependencies
|
||||||
- Clear error messages guide users for advanced formats
|
- Clear error messages guide users for advanced formats
|
||||||
- Robust error handling prevents crashes
|
- Robust error handling prevents crashes
|
||||||
- Better user experience with informative dialogs
|
- Better user experience with informative dialogs
|
||||||
@@ -1,82 +1,82 @@
|
|||||||
# GEMINI.md
|
# GEMINI.md
|
||||||
|
|
||||||
## Project Overview
|
## Project Overview
|
||||||
|
|
||||||
This project is a cross-platform Markdown editor and converter named **PanConverter**. It is built using the Electron framework, allowing it to run on Windows, macOS, and Linux. The application provides a rich text editor for writing Markdown, a live preview pane, and robust export capabilities powered by Pandoc.
|
This project is a cross-platform Markdown editor and converter named **PanConverter**. It is built using the Electron framework, allowing it to run on Windows, macOS, and Linux. The application provides a rich text editor for writing Markdown, a live preview pane, and robust export capabilities powered by Pandoc.
|
||||||
|
|
||||||
The core technologies used are:
|
The core technologies used are:
|
||||||
- **Electron:** For creating the desktop application.
|
- **Electron:** For creating the desktop application.
|
||||||
- **JavaScript:** The primary programming language.
|
- **JavaScript:** The primary programming language.
|
||||||
- **Pandoc:** For converting Markdown to various formats like PDF, DOCX, HTML, etc.
|
- **Pandoc:** For converting Markdown to various formats like PDF, DOCX, HTML, etc.
|
||||||
- **Marked:** For parsing and rendering the Markdown preview in real-time.
|
- **Marked:** For parsing and rendering the Markdown preview in real-time.
|
||||||
- **CodeMirror:** As the underlying text editor component.
|
- **CodeMirror:** As the underlying text editor component.
|
||||||
- **highlight.js:** For syntax highlighting in the editor.
|
- **highlight.js:** For syntax highlighting in the editor.
|
||||||
- **DOMPurify:** To sanitize the HTML output in the preview pane for security.
|
- **DOMPurify:** To sanitize the HTML output in the preview pane for security.
|
||||||
|
|
||||||
The application features a tabbed interface for working with multiple files, various themes, find and replace functionality, and detailed document statistics.
|
The application features a tabbed interface for working with multiple files, various themes, find and replace functionality, and detailed document statistics.
|
||||||
|
|
||||||
## Building and Running
|
## Building and Running
|
||||||
|
|
||||||
To build and run this project locally, you will need to have Node.js and npm installed.
|
To build and run this project locally, you will need to have Node.js and npm installed.
|
||||||
|
|
||||||
### Installation
|
### Installation
|
||||||
|
|
||||||
1. **Clone the repository:**
|
1. **Clone the repository:**
|
||||||
```bash
|
```bash
|
||||||
git clone https://github.com/amitwh/pan-converter.git
|
git clone https://github.com/amitwh/pan-converter.git
|
||||||
cd pan-converter
|
cd pan-converter
|
||||||
```
|
```
|
||||||
|
|
||||||
2. **Install dependencies:**
|
2. **Install dependencies:**
|
||||||
```bash
|
```bash
|
||||||
npm install
|
npm install
|
||||||
```
|
```
|
||||||
|
|
||||||
### Running the Application
|
### Running the Application
|
||||||
|
|
||||||
To run the application in development mode, use the following command:
|
To run the application in development mode, use the following command:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
npm start
|
npm start
|
||||||
```
|
```
|
||||||
|
|
||||||
### Building the Application
|
### Building the Application
|
||||||
|
|
||||||
You can build the application for different platforms using the scripts defined in `package.json`.
|
You can build the application for different platforms using the scripts defined in `package.json`.
|
||||||
|
|
||||||
- **Build for the current platform:**
|
- **Build for the current platform:**
|
||||||
```bash
|
```bash
|
||||||
npm run build
|
npm run build
|
||||||
```
|
```
|
||||||
|
|
||||||
- **Build for a specific platform:**
|
- **Build for a specific platform:**
|
||||||
```bash
|
```bash
|
||||||
npm run build:win # For Windows
|
npm run build:win # For Windows
|
||||||
npm run build:mac # For macOS
|
npm run build:mac # For macOS
|
||||||
npm run build:linux # For Linux
|
npm run build:linux # For Linux
|
||||||
```
|
```
|
||||||
|
|
||||||
- **Build for all platforms at once:**
|
- **Build for all platforms at once:**
|
||||||
```bash
|
```bash
|
||||||
npm run dist:all
|
npm run dist:all
|
||||||
```
|
```
|
||||||
|
|
||||||
The distributable files will be located in the `dist/` directory.
|
The distributable files will be located in the `dist/` directory.
|
||||||
|
|
||||||
### Testing
|
### Testing
|
||||||
|
|
||||||
The project does not have a dedicated test suite configured. The `test` script in `package.json` currently returns an error.
|
The project does not have a dedicated test suite configured. The `test` script in `package.json` currently returns an error.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
npm test
|
npm test
|
||||||
```
|
```
|
||||||
|
|
||||||
## Development Conventions
|
## Development Conventions
|
||||||
|
|
||||||
- **Code Style:** The codebase is written in JavaScript (ES6+). There is no linter or formatter configured, but the code generally follows standard JavaScript conventions.
|
- **Code Style:** The codebase is written in JavaScript (ES6+). There is no linter or formatter configured, but the code generally follows standard JavaScript conventions.
|
||||||
- **Main vs. Renderer Process:** The application logic is split between the Electron main process (`src/main.js`) and the renderer process (`src/renderer.js`).
|
- **Main vs. Renderer Process:** The application logic is split between the Electron main process (`src/main.js`) and the renderer process (`src/renderer.js`).
|
||||||
- `src/main.js` handles window management, application menus, file system operations, and communication with the operating system.
|
- `src/main.js` handles window management, application menus, file system operations, and communication with the operating system.
|
||||||
- `src/renderer.js` manages the user interface, editor functionality, and the Markdown preview.
|
- `src/renderer.js` manages the user interface, editor functionality, and the Markdown preview.
|
||||||
- **Dependencies:** Project dependencies are managed through `package.json`. `devDependencies` are used for the build process, while `dependencies` are required for the application to run.
|
- **Dependencies:** Project dependencies are managed through `package.json`. `devDependencies` are used for the build process, while `dependencies` are required for the application to run.
|
||||||
- **User Data:** The application stores settings and recent files in the user's application data directory.
|
- **User Data:** The application stores settings and recent files in the user's application data directory.
|
||||||
- **Pandoc Integration:** The application relies on a system-installed version of Pandoc for its export functionality. It does not bundle Pandoc.
|
- **Pandoc Integration:** The application relies on a system-installed version of Pandoc for its export functionality. It does not bundle Pandoc.
|
||||||
|
|||||||
+1478
-1478
File diff suppressed because it is too large
Load Diff
@@ -1,21 +1,21 @@
|
|||||||
MIT License
|
MIT License
|
||||||
|
|
||||||
Copyright (c) 2024 Amit Haridas
|
Copyright (c) 2024 Amit Haridas
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
of this software and associated documentation files (the "Software"), to deal
|
of this software and associated documentation files (the "Software"), to deal
|
||||||
in the Software without restriction, including without limitation the rights
|
in the Software without restriction, including without limitation the rights
|
||||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||||
copies of the Software, and to permit persons to whom the Software is
|
copies of the Software, and to permit persons to whom the Software is
|
||||||
furnished to do so, subject to the following conditions:
|
furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all
|
The above copyright notice and this permission notice shall be included in all
|
||||||
copies or substantial portions of the Software.
|
copies or substantial portions of the Software.
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||||
SOFTWARE.
|
SOFTWARE.
|
||||||
+12
-12
@@ -1,12 +1,12 @@
|
|||||||
# Test Double-Click File Opening
|
# Test Double-Click File Opening
|
||||||
|
|
||||||
This is a test file to verify double-click functionality.
|
This is a test file to verify double-click functionality.
|
||||||
|
|
||||||
## Features to Test
|
## Features to Test
|
||||||
- File should load automatically
|
- File should load automatically
|
||||||
- Content should display in editor
|
- Content should display in editor
|
||||||
- Tab should show filename
|
- Tab should show filename
|
||||||
- Preview should render markdown
|
- Preview should render markdown
|
||||||
|
|
||||||
**This text should be bold**
|
**This text should be bold**
|
||||||
*This text should be italic*
|
*This text should be italic*
|
||||||
|
|||||||
+378
-378
@@ -1,378 +1,378 @@
|
|||||||
\hypertarget{panconverter}{%
|
\hypertarget{panconverter}{%
|
||||||
\section{PanConverter}\label{panconverter}}
|
\section{PanConverter}\label{panconverter}}
|
||||||
|
|
||||||
A cross-platform Markdown editor and converter powered by Pandoc.
|
A cross-platform Markdown editor and converter powered by Pandoc.
|
||||||
|
|
||||||
\begin{figure}
|
\begin{figure}
|
||||||
\centering
|
\centering
|
||||||
\includegraphics{assets/icon.png}
|
\includegraphics{assets/icon.png}
|
||||||
\caption{PanConverter}
|
\caption{PanConverter}
|
||||||
\end{figure}
|
\end{figure}
|
||||||
|
|
||||||
\hypertarget{features}{%
|
\hypertarget{features}{%
|
||||||
\subsection{Features}\label{features}}
|
\subsection{Features}\label{features}}
|
||||||
|
|
||||||
\hypertarget{advanced-markdown-editor}{%
|
\hypertarget{advanced-markdown-editor}{%
|
||||||
\subsubsection{✨ Advanced Markdown
|
\subsubsection{✨ Advanced Markdown
|
||||||
Editor}\label{advanced-markdown-editor}}
|
Editor}\label{advanced-markdown-editor}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
🗂️ \textbf{Tabbed Interface} - Work with multiple files simultaneously
|
🗂️ \textbf{Tabbed Interface} - Work with multiple files simultaneously
|
||||||
in separate tabs
|
in separate tabs
|
||||||
\item
|
\item
|
||||||
📝 \textbf{Rich Text Editor} - Full-featured editor with syntax
|
📝 \textbf{Rich Text Editor} - Full-featured editor with syntax
|
||||||
highlighting and comprehensive toolbar
|
highlighting and comprehensive toolbar
|
||||||
\item
|
\item
|
||||||
🔍 \textbf{Find \& Replace} - Powerful search and replace with match
|
🔍 \textbf{Find \& Replace} - Powerful search and replace with match
|
||||||
highlighting and navigation
|
highlighting and navigation
|
||||||
\item
|
\item
|
||||||
🔢 \textbf{Line Numbers} - Toggle line numbers for easier code editing
|
🔢 \textbf{Line Numbers} - Toggle line numbers for easier code editing
|
||||||
and navigation
|
and navigation
|
||||||
\item
|
\item
|
||||||
↩️ \textbf{Smart Auto-Indentation} - Automatic list continuation and
|
↩️ \textbf{Smart Auto-Indentation} - Automatic list continuation and
|
||||||
intelligent indentation
|
intelligent indentation
|
||||||
\item
|
\item
|
||||||
⏪ \textbf{Undo/Redo} - Full undo/redo support with keyboard shortcuts
|
⏪ \textbf{Undo/Redo} - Full undo/redo support with keyboard shortcuts
|
||||||
\item
|
\item
|
||||||
⌨️ \textbf{Advanced Shortcuts} - Tab indentation, line selection, and
|
⌨️ \textbf{Advanced Shortcuts} - Tab indentation, line selection, and
|
||||||
smart text formatting
|
smart text formatting
|
||||||
\item
|
\item
|
||||||
📂 \textbf{File Association Support} - Open markdown files directly
|
📂 \textbf{File Association Support} - Open markdown files directly
|
||||||
from file manager
|
from file manager
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{themes-interface}{%
|
\hypertarget{themes-interface}{%
|
||||||
\subsubsection{🎨 Themes \& Interface}\label{themes-interface}}
|
\subsubsection{🎨 Themes \& Interface}\label{themes-interface}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
👁️ \textbf{Live Preview} - See your markdown rendered in real-time
|
👁️ \textbf{Live Preview} - See your markdown rendered in real-time
|
||||||
with synchronized scrolling
|
with synchronized scrolling
|
||||||
\item
|
\item
|
||||||
🎨 \textbf{Multiple Themes} - Choose from Light, Dark, Solarized,
|
🎨 \textbf{Multiple Themes} - Choose from Light, Dark, Solarized,
|
||||||
Monokai, or GitHub themes
|
Monokai, or GitHub themes
|
||||||
\item
|
\item
|
||||||
💾 \textbf{Auto-Save} - Never lose your work with automatic saving
|
💾 \textbf{Auto-Save} - Never lose your work with automatic saving
|
||||||
every 30 seconds
|
every 30 seconds
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{export-conversion}{%
|
\hypertarget{export-conversion}{%
|
||||||
\subsubsection{📤 Export \& Conversion}\label{export-conversion}}
|
\subsubsection{📤 Export \& Conversion}\label{export-conversion}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
📄 \textbf{Enhanced PDF Export} - Robust PDF generation with multiple
|
📄 \textbf{Enhanced PDF Export} - Robust PDF generation with multiple
|
||||||
LaTeX engine fallbacks (XeLaTeX, PDFLaTeX, wkhtmltopdf)
|
LaTeX engine fallbacks (XeLaTeX, PDFLaTeX, wkhtmltopdf)
|
||||||
\item
|
\item
|
||||||
📄 \textbf{Document Export} - Convert to HTML, DOCX, LaTeX, RTF, ODT,
|
📄 \textbf{Document Export} - Convert to HTML, DOCX, LaTeX, RTF, ODT,
|
||||||
EPUB, PowerPoint (PPTX), and OpenDocument Presentation (ODP)
|
EPUB, PowerPoint (PPTX), and OpenDocument Presentation (ODP)
|
||||||
\item
|
\item
|
||||||
📊 \textbf{Spreadsheet Export} - Export markdown tables to Excel
|
📊 \textbf{Spreadsheet Export} - Export markdown tables to Excel
|
||||||
(XLSX/XLS) and OpenDocument Spreadsheet (ODS) formats
|
(XLSX/XLS) and OpenDocument Spreadsheet (ODS) formats
|
||||||
\item
|
\item
|
||||||
📥 \textbf{Document Import} - Import DOCX, ODT, RTF, HTML, PDF, and
|
📥 \textbf{Document Import} - Import DOCX, ODT, RTF, HTML, PDF, and
|
||||||
presentation files to markdown
|
presentation files to markdown
|
||||||
\item
|
\item
|
||||||
📋 \textbf{Table Creation Helper} - Built-in table generator for easy
|
📋 \textbf{Table Creation Helper} - Built-in table generator for easy
|
||||||
markdown table creation
|
markdown table creation
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{platform-support}{%
|
\hypertarget{platform-support}{%
|
||||||
\subsubsection{🖥️ Platform Support}\label{platform-support}}
|
\subsubsection{🖥️ Platform Support}\label{platform-support}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\textbf{Cross-Platform} - Works seamlessly on Windows, macOS, and
|
\textbf{Cross-Platform} - Works seamlessly on Windows, macOS, and
|
||||||
Linux
|
Linux
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{installation}{%
|
\hypertarget{installation}{%
|
||||||
\subsection{Installation}\label{installation}}
|
\subsection{Installation}\label{installation}}
|
||||||
|
|
||||||
\hypertarget{prerequisites}{%
|
\hypertarget{prerequisites}{%
|
||||||
\subsubsection{Prerequisites}\label{prerequisites}}
|
\subsubsection{Prerequisites}\label{prerequisites}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\href{https://pandoc.org/installing.html}{Pandoc} must be installed
|
\href{https://pandoc.org/installing.html}{Pandoc} must be installed
|
||||||
for export functionality
|
for export functionality
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\textbf{Ubuntu/Debian}: \texttt{sudo\ apt-get\ install\ pandoc}
|
\textbf{Ubuntu/Debian}: \texttt{sudo\ apt-get\ install\ pandoc}
|
||||||
\item
|
\item
|
||||||
\textbf{macOS}: \texttt{brew\ install\ pandoc}
|
\textbf{macOS}: \texttt{brew\ install\ pandoc}
|
||||||
\item
|
\item
|
||||||
\textbf{Windows}: Download installer from Pandoc website
|
\textbf{Windows}: Download installer from Pandoc website
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{pdf-export-requirements}{%
|
\hypertarget{pdf-export-requirements}{%
|
||||||
\subsubsection{PDF Export Requirements}\label{pdf-export-requirements}}
|
\subsubsection{PDF Export Requirements}\label{pdf-export-requirements}}
|
||||||
|
|
||||||
For optimal PDF export, install a LaTeX engine (recommended): -
|
For optimal PDF export, install a LaTeX engine (recommended): -
|
||||||
\textbf{Ubuntu/Debian}:
|
\textbf{Ubuntu/Debian}:
|
||||||
\texttt{sudo\ apt-get\ install\ texlive-xetex\ texlive-latex-base} -
|
\texttt{sudo\ apt-get\ install\ texlive-xetex\ texlive-latex-base} -
|
||||||
\textbf{macOS}: \texttt{brew\ install\ -\/-cask\ mactex} -
|
\textbf{macOS}: \texttt{brew\ install\ -\/-cask\ mactex} -
|
||||||
\textbf{Windows}: Install MiKTeX or TeX Live - \textbf{Alternative}:
|
\textbf{Windows}: Install MiKTeX or TeX Live - \textbf{Alternative}:
|
||||||
\texttt{sudo\ apt-get\ install\ wkhtmltopdf} (fallback option)
|
\texttt{sudo\ apt-get\ install\ wkhtmltopdf} (fallback option)
|
||||||
|
|
||||||
\hypertarget{download}{%
|
\hypertarget{download}{%
|
||||||
\subsubsection{Download}\label{download}}
|
\subsubsection{Download}\label{download}}
|
||||||
|
|
||||||
Download the latest release for your platform from the
|
Download the latest release for your platform from the
|
||||||
\href{https://github.com/amitwh/pan-converter/releases}{Releases} page.
|
\href{https://github.com/amitwh/pan-converter/releases}{Releases} page.
|
||||||
|
|
||||||
\hypertarget{linux}{%
|
\hypertarget{linux}{%
|
||||||
\paragraph{Linux}\label{linux}}
|
\paragraph{Linux}\label{linux}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\textbf{AppImage}: \texttt{PanConverter-1.3.1.AppImage} (universal,
|
\textbf{AppImage}: \texttt{PanConverter-1.3.1.AppImage} (universal,
|
||||||
may require \texttt{-\/-no-sandbox} flag)
|
may require \texttt{-\/-no-sandbox} flag)
|
||||||
\item
|
\item
|
||||||
\textbf{Debian Package}: \texttt{pan-converter\_1.3.1\_amd64.deb}
|
\textbf{Debian Package}: \texttt{pan-converter\_1.3.1\_amd64.deb}
|
||||||
\item
|
\item
|
||||||
\textbf{Snap Package}: \texttt{pan-converter\_1.3.1\_amd64.snap}
|
\textbf{Snap Package}: \texttt{pan-converter\_1.3.1\_amd64.snap}
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{install-from-source}{%
|
\hypertarget{install-from-source}{%
|
||||||
\subsubsection{Install from Source}\label{install-from-source}}
|
\subsubsection{Install from Source}\label{install-from-source}}
|
||||||
|
|
||||||
\begin{Shaded}
|
\begin{Shaded}
|
||||||
\begin{Highlighting}[]
|
\begin{Highlighting}[]
|
||||||
\FunctionTok{git}\NormalTok{ clone https://github.com/amitwh/pan{-}converter.git}
|
\FunctionTok{git}\NormalTok{ clone https://github.com/amitwh/pan{-}converter.git}
|
||||||
\BuiltInTok{cd}\NormalTok{ pan{-}converter}
|
\BuiltInTok{cd}\NormalTok{ pan{-}converter}
|
||||||
\ExtensionTok{npm}\NormalTok{ install}
|
\ExtensionTok{npm}\NormalTok{ install}
|
||||||
\ExtensionTok{npm}\NormalTok{ start}
|
\ExtensionTok{npm}\NormalTok{ start}
|
||||||
\end{Highlighting}
|
\end{Highlighting}
|
||||||
\end{Shaded}
|
\end{Shaded}
|
||||||
|
|
||||||
\hypertarget{usage}{%
|
\hypertarget{usage}{%
|
||||||
\subsection{Usage}\label{usage}}
|
\subsection{Usage}\label{usage}}
|
||||||
|
|
||||||
\hypertarget{basic-workflow}{%
|
\hypertarget{basic-workflow}{%
|
||||||
\subsubsection{Basic Workflow}\label{basic-workflow}}
|
\subsubsection{Basic Workflow}\label{basic-workflow}}
|
||||||
|
|
||||||
\begin{enumerate}
|
\begin{enumerate}
|
||||||
\def\labelenumi{\arabic{enumi}.}
|
\def\labelenumi{\arabic{enumi}.}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\textbf{Write} - Use the editor to write your Markdown content
|
\textbf{Write} - Use the editor to write your Markdown content
|
||||||
\item
|
\item
|
||||||
\textbf{Preview} - Toggle the preview pane to see rendered output
|
\textbf{Preview} - Toggle the preview pane to see rendered output
|
||||||
\item
|
\item
|
||||||
\textbf{Theme} - Choose your preferred theme from the View menu
|
\textbf{Theme} - Choose your preferred theme from the View menu
|
||||||
\item
|
\item
|
||||||
\textbf{Export} - Export your document to various formats
|
\textbf{Export} - Export your document to various formats
|
||||||
\end{enumerate}
|
\end{enumerate}
|
||||||
|
|
||||||
\hypertarget{export-options}{%
|
\hypertarget{export-options}{%
|
||||||
\subsubsection{Export Options}\label{export-options}}
|
\subsubsection{Export Options}\label{export-options}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\textbf{Documents}: HTML, PDF, DOCX, LaTeX, RTF, ODT, EPUB
|
\textbf{Documents}: HTML, PDF, DOCX, LaTeX, RTF, ODT, EPUB
|
||||||
\item
|
\item
|
||||||
\textbf{Presentations}: PowerPoint (PPTX), OpenDocument Presentation
|
\textbf{Presentations}: PowerPoint (PPTX), OpenDocument Presentation
|
||||||
(ODP)
|
(ODP)
|
||||||
\item
|
\item
|
||||||
\textbf{Spreadsheets}: Excel (XLSX/XLS), OpenDocument Spreadsheet
|
\textbf{Spreadsheets}: Excel (XLSX/XLS), OpenDocument Spreadsheet
|
||||||
(ODS)
|
(ODS)
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{import-conversion}{%
|
\hypertarget{import-conversion}{%
|
||||||
\subsubsection{Import \& Conversion}\label{import-conversion}}
|
\subsubsection{Import \& Conversion}\label{import-conversion}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\textbf{Import Documents}: Convert DOCX, ODT, RTF, HTML, PDF, and
|
\textbf{Import Documents}: Convert DOCX, ODT, RTF, HTML, PDF, and
|
||||||
presentation files to Markdown
|
presentation files to Markdown
|
||||||
\item
|
\item
|
||||||
\textbf{Cross-Format Conversion}: Convert current file between
|
\textbf{Cross-Format Conversion}: Convert current file between
|
||||||
multiple formats
|
multiple formats
|
||||||
\item
|
\item
|
||||||
\textbf{Smart Presentation Handling}: Automatic slide-level formatting
|
\textbf{Smart Presentation Handling}: Automatic slide-level formatting
|
||||||
for PPTX/ODP exports
|
for PPTX/ODP exports
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{table-creation}{%
|
\hypertarget{table-creation}{%
|
||||||
\subsubsection{Table Creation}\label{table-creation}}
|
\subsubsection{Table Creation}\label{table-creation}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
Click the table button in the toolbar
|
Click the table button in the toolbar
|
||||||
\item
|
\item
|
||||||
Specify number of rows and columns
|
Specify number of rows and columns
|
||||||
\item
|
\item
|
||||||
Automatically generates properly formatted Markdown tables
|
Automatically generates properly formatted Markdown tables
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{keyboard-shortcuts}{%
|
\hypertarget{keyboard-shortcuts}{%
|
||||||
\subsection{Keyboard Shortcuts}\label{keyboard-shortcuts}}
|
\subsection{Keyboard Shortcuts}\label{keyboard-shortcuts}}
|
||||||
|
|
||||||
\hypertarget{file-operations}{%
|
\hypertarget{file-operations}{%
|
||||||
\subsubsection{File Operations}\label{file-operations}}
|
\subsubsection{File Operations}\label{file-operations}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ N} - New file/tab
|
\texttt{Ctrl/Cmd\ +\ N} - New file/tab
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ T} - New tab
|
\texttt{Ctrl/Cmd\ +\ T} - New tab
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ W} - Close current tab
|
\texttt{Ctrl/Cmd\ +\ W} - Close current tab
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ Tab} - Switch to next tab
|
\texttt{Ctrl/Cmd\ +\ Tab} - Switch to next tab
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ O} - Open file
|
\texttt{Ctrl/Cmd\ +\ O} - Open file
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ S} - Save file
|
\texttt{Ctrl/Cmd\ +\ S} - Save file
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ Shift\ +\ S} - Save as
|
\texttt{Ctrl/Cmd\ +\ Shift\ +\ S} - Save as
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ I} - Import document
|
\texttt{Ctrl/Cmd\ +\ I} - Import document
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{editor-features}{%
|
\hypertarget{editor-features}{%
|
||||||
\subsubsection{Editor Features}\label{editor-features}}
|
\subsubsection{Editor Features}\label{editor-features}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ F} - Find \& Replace
|
\texttt{Ctrl/Cmd\ +\ F} - Find \& Replace
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ Z} - Undo
|
\texttt{Ctrl/Cmd\ +\ Z} - Undo
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ Shift\ +\ Z} - Redo
|
\texttt{Ctrl/Cmd\ +\ Shift\ +\ Z} - Redo
|
||||||
\item
|
\item
|
||||||
\texttt{Tab} - Indent lines or insert 4 spaces
|
\texttt{Tab} - Indent lines or insert 4 spaces
|
||||||
\item
|
\item
|
||||||
\texttt{Shift\ +\ Tab} - Outdent selected lines
|
\texttt{Shift\ +\ Tab} - Outdent selected lines
|
||||||
\item
|
\item
|
||||||
\texttt{Enter} - Auto-continue lists with proper indentation
|
\texttt{Enter} - Auto-continue lists with proper indentation
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{view-navigation}{%
|
\hypertarget{view-navigation}{%
|
||||||
\subsubsection{View \& Navigation}\label{view-navigation}}
|
\subsubsection{View \& Navigation}\label{view-navigation}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ P} - Toggle preview
|
\texttt{Ctrl/Cmd\ +\ P} - Toggle preview
|
||||||
\item
|
\item
|
||||||
\texttt{Ctrl/Cmd\ +\ Enter} - Toggle preview (alternative)
|
\texttt{Ctrl/Cmd\ +\ Enter} - Toggle preview (alternative)
|
||||||
\item
|
\item
|
||||||
\texttt{Escape} - Close find dialog
|
\texttt{Escape} - Close find dialog
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{building}{%
|
\hypertarget{building}{%
|
||||||
\subsection{Building}\label{building}}
|
\subsection{Building}\label{building}}
|
||||||
|
|
||||||
\begin{Shaded}
|
\begin{Shaded}
|
||||||
\begin{Highlighting}[]
|
\begin{Highlighting}[]
|
||||||
\CommentTok{\# Install dependencies}
|
\CommentTok{\# Install dependencies}
|
||||||
\ExtensionTok{npm}\NormalTok{ install}
|
\ExtensionTok{npm}\NormalTok{ install}
|
||||||
|
|
||||||
\CommentTok{\# Generate icons}
|
\CommentTok{\# Generate icons}
|
||||||
\ExtensionTok{npm}\NormalTok{ run generate{-}icons}
|
\ExtensionTok{npm}\NormalTok{ run generate{-}icons}
|
||||||
|
|
||||||
\CommentTok{\# Build for current platform}
|
\CommentTok{\# Build for current platform}
|
||||||
\ExtensionTok{npm}\NormalTok{ run build}
|
\ExtensionTok{npm}\NormalTok{ run build}
|
||||||
|
|
||||||
\CommentTok{\# Build for specific platform}
|
\CommentTok{\# Build for specific platform}
|
||||||
\ExtensionTok{npm}\NormalTok{ run build:win }\CommentTok{\# Windows}
|
\ExtensionTok{npm}\NormalTok{ run build:win }\CommentTok{\# Windows}
|
||||||
\ExtensionTok{npm}\NormalTok{ run build:mac }\CommentTok{\# macOS }
|
\ExtensionTok{npm}\NormalTok{ run build:mac }\CommentTok{\# macOS }
|
||||||
\ExtensionTok{npm}\NormalTok{ run build:linux }\CommentTok{\# Linux (generates .deb, .AppImage, and .snap)}
|
\ExtensionTok{npm}\NormalTok{ run build:linux }\CommentTok{\# Linux (generates .deb, .AppImage, and .snap)}
|
||||||
|
|
||||||
\CommentTok{\# Build for all platforms}
|
\CommentTok{\# Build for all platforms}
|
||||||
\ExtensionTok{npm}\NormalTok{ run dist:all}
|
\ExtensionTok{npm}\NormalTok{ run dist:all}
|
||||||
\end{Highlighting}
|
\end{Highlighting}
|
||||||
\end{Shaded}
|
\end{Shaded}
|
||||||
|
|
||||||
\hypertarget{version-history}{%
|
\hypertarget{version-history}{%
|
||||||
\subsection{Version History}\label{version-history}}
|
\subsection{Version History}\label{version-history}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
\textbf{v1.3.1} - Bug fixes: Fixed file associations for
|
\textbf{v1.3.1} - Bug fixes: Fixed file associations for
|
||||||
double-clicking .md files, corrected 50/50 layout alignment for
|
double-clicking .md files, corrected 50/50 layout alignment for
|
||||||
editor/preview panes
|
editor/preview panes
|
||||||
\item
|
\item
|
||||||
\textbf{v1.3.0} - Major update: Tabbed interface for multiple files,
|
\textbf{v1.3.0} - Major update: Tabbed interface for multiple files,
|
||||||
enhanced PDF export with LaTeX engines, fixed file associations,
|
enhanced PDF export with LaTeX engines, fixed file associations,
|
||||||
removed redundant converter menu, improved UI architecture
|
removed redundant converter menu, improved UI architecture
|
||||||
\item
|
\item
|
||||||
\textbf{v1.2.1} - Comprehensive editor enhancements: Find \& Replace,
|
\textbf{v1.2.1} - Comprehensive editor enhancements: Find \& Replace,
|
||||||
Line Numbers, Undo/Redo, Auto-indentation, PowerPoint export, document
|
Line Numbers, Undo/Redo, Auto-indentation, PowerPoint export, document
|
||||||
conversion menu, table creation helper, spreadsheet export
|
conversion menu, table creation helper, spreadsheet export
|
||||||
\item
|
\item
|
||||||
\textbf{v1.1.0} - Added Excel/ODS spreadsheet export, updated author
|
\textbf{v1.1.0} - Added Excel/ODS spreadsheet export, updated author
|
||||||
information, renamed to PanConverter
|
information, renamed to PanConverter
|
||||||
\item
|
\item
|
||||||
\textbf{v1.0.0} - Initial release with basic markdown editing, themes,
|
\textbf{v1.0.0} - Initial release with basic markdown editing, themes,
|
||||||
and Pandoc export
|
and Pandoc export
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{known-issues}{%
|
\hypertarget{known-issues}{%
|
||||||
\subsection{Known Issues}\label{known-issues}}
|
\subsection{Known Issues}\label{known-issues}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
AppImage may require \texttt{-\/-no-sandbox} flag on some Linux
|
AppImage may require \texttt{-\/-no-sandbox} flag on some Linux
|
||||||
systems
|
systems
|
||||||
\item
|
\item
|
||||||
Windows/Mac builds require platform-specific build environments
|
Windows/Mac builds require platform-specific build environments
|
||||||
\item
|
\item
|
||||||
Large files may cause performance issues
|
Large files may cause performance issues
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|
||||||
\hypertarget{contributing}{%
|
\hypertarget{contributing}{%
|
||||||
\subsection{Contributing}\label{contributing}}
|
\subsection{Contributing}\label{contributing}}
|
||||||
|
|
||||||
Contributions are welcome! Please feel free to submit a Pull Request to
|
Contributions are welcome! Please feel free to submit a Pull Request to
|
||||||
the \href{https://github.com/amitwh/pan-converter}{GitHub repository}.
|
the \href{https://github.com/amitwh/pan-converter}{GitHub repository}.
|
||||||
|
|
||||||
\hypertarget{license}{%
|
\hypertarget{license}{%
|
||||||
\subsection{License}\label{license}}
|
\subsection{License}\label{license}}
|
||||||
|
|
||||||
MIT License - see LICENSE file for details.
|
MIT License - see LICENSE file for details.
|
||||||
|
|
||||||
\hypertarget{author}{%
|
\hypertarget{author}{%
|
||||||
\subsection{Author}\label{author}}
|
\subsection{Author}\label{author}}
|
||||||
|
|
||||||
\textbf{Amit Haridas} -
|
\textbf{Amit Haridas} -
|
||||||
\href{mailto:amit.wh@gmail.com}{\nolinkurl{amit.wh@gmail.com}}
|
\href{mailto:amit.wh@gmail.com}{\nolinkurl{amit.wh@gmail.com}}
|
||||||
|
|
||||||
\hypertarget{acknowledgments}{%
|
\hypertarget{acknowledgments}{%
|
||||||
\subsection{Acknowledgments}\label{acknowledgments}}
|
\subsection{Acknowledgments}\label{acknowledgments}}
|
||||||
|
|
||||||
\begin{itemize}
|
\begin{itemize}
|
||||||
\tightlist
|
\tightlist
|
||||||
\item
|
\item
|
||||||
Built with \href{https://www.electronjs.org/}{Electron}
|
Built with \href{https://www.electronjs.org/}{Electron}
|
||||||
\item
|
\item
|
||||||
Markdown parsing by \href{https://marked.js.org/}{marked}
|
Markdown parsing by \href{https://marked.js.org/}{marked}
|
||||||
\item
|
\item
|
||||||
Export functionality powered by \href{https://pandoc.org/}{Pandoc}
|
Export functionality powered by \href{https://pandoc.org/}{Pandoc}
|
||||||
\item
|
\item
|
||||||
Syntax highlighting by \href{https://highlightjs.org/}{highlight.js}
|
Syntax highlighting by \href{https://highlightjs.org/}{highlight.js}
|
||||||
\item
|
\item
|
||||||
Spreadsheet export by \href{https://www.npmjs.com/package/xlsx}{XLSX}
|
Spreadsheet export by \href{https://www.npmjs.com/package/xlsx}{XLSX}
|
||||||
\item
|
\item
|
||||||
HTML sanitization by
|
HTML sanitization by
|
||||||
\href{https://www.npmjs.com/package/dompurify}{DOMPurify}
|
\href{https://www.npmjs.com/package/dompurify}{DOMPurify}
|
||||||
\end{itemize}
|
\end{itemize}
|
||||||
|
|||||||
@@ -1,223 +1,165 @@
|
|||||||
# MarkdownConverter
|
# MarkdownConverter
|
||||||
|
|
||||||
A powerful cross-platform Markdown editor and document converter powered by Pandoc, built with Electron. 100% open-source with no proprietary dependencies.
|
A powerful cross-platform Markdown editor and document converter powered by Pandoc, built with Electron. 100% open-source with no proprietary dependencies.
|
||||||
|
|
||||||
## Features
|
## Features
|
||||||
|
|
||||||
### Markdown Editor
|
### Markdown Editor
|
||||||
<img width="1920" height="1032" alt="image" src="https://github.com/user-attachments/assets/5f53ba94-7663-47c3-b12b-b7b8bd2645aa" />
|
<img width="1920" height="1032" alt="image" src="https://github.com/user-attachments/assets/5f53ba94-7663-47c3-b12b-b7b8bd2645aa" />
|
||||||
- **Multi-tab editing** - Work on multiple files simultaneously
|
- **Multi-tab editing** - Work on multiple files simultaneously
|
||||||
- **Live preview** - Real-time markdown rendering with syntax highlighting
|
- **Live preview** - Real-time markdown rendering with syntax highlighting
|
||||||
- **Dynamic splitter** - Drag to resize editor and preview panes
|
- **Dynamic splitter** - Drag to resize editor and preview panes
|
||||||
- **25+ themes** - Light and dark themes including Atom One Light, Dracula, Nord, Sepia, and more
|
- **25+ themes** - Light and dark themes including Atom One Light, Dracula, Nord, Sepia, and more
|
||||||
- **Find & Replace** - Search and replace with regex support
|
- **Find & Replace** - Search and replace with regex support
|
||||||
- **Line numbers** - Toggle line numbers in the editor
|
- **Line numbers** - Toggle line numbers in the editor
|
||||||
- **Auto-save** - Automatic saving every 30 seconds
|
- **Auto-save** - Automatic saving every 30 seconds
|
||||||
- **Math support** - KaTeX integration for mathematical expressions
|
- **Math support** - KaTeX integration for mathematical expressions
|
||||||
|
|
||||||
### PDF Viewer & Editor
|
### PDF Viewer & Editor
|
||||||
<img width="1920" height="1032" alt="image" src="https://github.com/user-attachments/assets/f10f62be-af3d-496e-81df-37ab4f91abfd" />
|
<img width="1920" height="1032" alt="image" src="https://github.com/user-attachments/assets/f10f62be-af3d-496e-81df-37ab4f91abfd" />
|
||||||
|
|
||||||
- **Built-in PDF viewer** - Open and view PDF files directly in the app
|
- **Built-in PDF viewer** - Open and view PDF files directly in the app
|
||||||
- **Page navigation** - Navigate pages with keyboard or buttons
|
- **Page navigation** - Navigate pages with keyboard or buttons
|
||||||
- **Zoom controls** - Zoom in/out, fit to width, fit to page
|
- **Zoom controls** - Zoom in/out, fit to width, fit to page
|
||||||
- **Rotation** - Rotate pages left or right
|
- **Rotation** - Rotate pages left or right
|
||||||
- **PDF Editor tools**:
|
- **PDF Editor tools**:
|
||||||
- Merge multiple PDFs
|
- Merge multiple PDFs
|
||||||
- Split PDFs by page range
|
- Split PDFs by page range
|
||||||
- Compress PDFs
|
- Compress PDFs
|
||||||
- Rotate pages
|
- Rotate pages
|
||||||
- Delete pages
|
- Delete pages
|
||||||
- Reorder pages
|
- Reorder pages
|
||||||
- Add watermarks
|
- Add watermarks
|
||||||
- Password protection
|
- Password protection
|
||||||
- Remove passwords
|
- Remove passwords
|
||||||
- Set permissions
|
- Set permissions
|
||||||
|
|
||||||
### Export Options
|
### Export Options
|
||||||
- **PDF** - Export to PDF with customizable page sizes and orientation
|
- **PDF** - Export to PDF with customizable page sizes and orientation
|
||||||
- **DOCX** - Standard and Enhanced (template-based) Word export
|
- **DOCX** - Standard and Enhanced (template-based) Word export
|
||||||
- **ODT** - OpenDocument format
|
- **ODT** - OpenDocument format
|
||||||
- **HTML** - Web-ready HTML export
|
- **HTML** - Web-ready HTML export
|
||||||
- **PowerPoint** - PPTX presentation export
|
- **PowerPoint** - PPTX presentation export
|
||||||
- **EPUB** - E-book format
|
- **EPUB** - E-book format
|
||||||
- **LaTeX** - Academic document format
|
- **LaTeX** - Academic document format
|
||||||
- **RTF** - Rich Text Format
|
- **RTF** - Rich Text Format
|
||||||
|
|
||||||
### Advanced Features
|
### Advanced Features
|
||||||
- **Custom headers & footers** - Add headers/footers to exports with dynamic fields
|
- **Custom headers & footers** - Add headers/footers to exports with dynamic fields
|
||||||
- **Page size configuration** - A3, A4, A5, B4, B5, Letter, Legal, Tabloid, or custom sizes
|
- **Page size configuration** - A3, A4, A5, B4, B5, Letter, Legal, Tabloid, or custom sizes
|
||||||
- **Batch conversion** - Convert entire folders of markdown files
|
- **Batch conversion** - Convert entire folders of markdown files
|
||||||
- **ASCII Art Generator** - Create text banners and diagrams
|
- **ASCII Art Generator** - Create text banners and diagrams
|
||||||
- **Word templates** - Use custom Word templates for enhanced exports
|
- **Word templates** - Use custom Word templates for enhanced exports
|
||||||
- **Import documents** - Import from 30+ formats (DOCX, PDF, HTML, etc.)
|
- **Import documents** - Import from 30+ formats (DOCX, PDF, HTML, etc.)
|
||||||
- **MarkItDown import** - Any file → Markdown via [Microsoft MarkItDown](https://github.com/microsoft/markitdown): PDF, DOCX, PPTX, XLSX, Outlook .msg, EPUB, images, ZIP (audio/OCR with the `[all]` extras)
|
|
||||||
- **Excel export** - Markdown tables to native .xlsx workbooks (one sheet per table)
|
## Installation
|
||||||
- **AI Assistant** - Multi-provider AI help (OpenAI/Anthropic/Ollama/LM Studio): chat panel, summarize/improve/translate commands, grammar proofreading
|
|
||||||
- **Inline comments** - Anchor-based document comments in `.comments/` sidecars with F8 navigation
|
### Prerequisites
|
||||||
- **Wiki-links & Backlinks** - `[[Note]]` links with click-to-create and a "what links here?" panel (local knowledge base)
|
- [Node.js](https://nodejs.org/) (v16 or later)
|
||||||
- **Crash recovery** - Session restore of open tabs and unsaved buffers after a crash
|
- [Pandoc](https://pandoc.org/installing.html) (required for export functionality)
|
||||||
- **Version history** - Automatic pre-save snapshots with restore/diff/delete from the History panel
|
|
||||||
- **Vim mode & snippet expansion** - Vim keybindings toggle; Tab expands saved snippets
|
### Install Dependencies
|
||||||
- **Quick Note** - Global scratchpad (Ctrl+Alt+Q) that appends to `notes/quick-notes.md`
|
```bash
|
||||||
- **Real PDF encryption** - Password protection, removal, and permissions actually work
|
npm install
|
||||||
- **Offline math & diagrams** - KaTeX bundled locally; PlantUML renders locally when the CLI is installed
|
```
|
||||||
|
|
||||||
## Installation
|
### Run the Application
|
||||||
|
```bash
|
||||||
### Prerequisites
|
npm start
|
||||||
- [Node.js](https://nodejs.org/) (v16 or later)
|
```
|
||||||
- [Pandoc](https://pandoc.org/installing.html) (required for export functionality)
|
|
||||||
- Optional: [MarkItDown](https://github.com/microsoft/markitdown) (`pip install "markitdown[all]"`) for any-file → Markdown import
|
### Build for Distribution
|
||||||
|
```bash
|
||||||
### Install Dependencies
|
# Windows
|
||||||
```bash
|
npm run build:win
|
||||||
npm install
|
|
||||||
```
|
# macOS
|
||||||
|
npm run build:mac
|
||||||
### Run the Application
|
|
||||||
```bash
|
# Linux
|
||||||
npm start
|
npm run build:linux
|
||||||
```
|
```
|
||||||
|
|
||||||
### Build for Distribution
|
## Keyboard Shortcuts
|
||||||
```bash
|
|
||||||
# Windows
|
| Action | Shortcut |
|
||||||
npm run build:win
|
|--------|----------|
|
||||||
|
| New File | Ctrl+N |
|
||||||
# macOS
|
| Open File | Ctrl+O |
|
||||||
npm run build:mac
|
| Open PDF | Ctrl+Shift+O |
|
||||||
|
| Save | Ctrl+S |
|
||||||
# Linux
|
| Save As | Ctrl+Shift+S |
|
||||||
npm run build:linux
|
| Export | Ctrl+E |
|
||||||
```
|
| Print | Ctrl+P |
|
||||||
|
| Find | Ctrl+F |
|
||||||
## Keyboard Shortcuts
|
| Undo | Ctrl+Z |
|
||||||
|
| Redo | Ctrl+Shift+Z |
|
||||||
| Action | Shortcut |
|
| New Tab | Ctrl+T |
|
||||||
|--------|----------|
|
| Close Tab | Ctrl+W |
|
||||||
| New File | Ctrl+N |
|
| Toggle Preview | Ctrl+Shift+P |
|
||||||
| Open File | Ctrl+O |
|
| Zoom In | Ctrl+Shift++ |
|
||||||
| Open PDF | Ctrl+Shift+O |
|
| Zoom Out | Ctrl+Shift+- |
|
||||||
| Save | Ctrl+S |
|
|
||||||
| Save As | Ctrl+Shift+S |
|
## Themes
|
||||||
| Export | Ctrl+E |
|
|
||||||
| Print | Ctrl+P |
|
### Light Themes
|
||||||
| Find | Ctrl+F |
|
- Atom One Light (Default)
|
||||||
| Undo | Ctrl+Z |
|
- GitHub Light
|
||||||
| Redo | Ctrl+Shift+Z |
|
- Light
|
||||||
| New Tab | Ctrl+T |
|
- Solarized Light
|
||||||
| Close Tab | Ctrl+W |
|
- Gruvbox Light
|
||||||
| Toggle Preview | Ctrl+Shift+V |
|
- Ayu Light
|
||||||
| Zoom In | Ctrl+Shift++ |
|
- Sepia
|
||||||
| Zoom Out | Ctrl+Shift+- |
|
- Paper
|
||||||
| Command Palette | Ctrl+Shift+P |
|
- Rose Pine Dawn
|
||||||
| Zen Mode | F11 |
|
- Concrete Light
|
||||||
| Writing Analytics | Ctrl+Shift+A |
|
|
||||||
| Quick Note | Ctrl+Alt+Q |
|
### Dark Themes
|
||||||
| Universal Converter | Ctrl+Shift+C |
|
- Dark
|
||||||
| Table Generator | Ctrl+Shift+T |
|
- One Dark
|
||||||
| ASCII Art Generator | Ctrl+Shift+A |
|
- Dracula
|
||||||
| Next Comment | F8 |
|
- Nord
|
||||||
| Add Comment at Cursor | Ctrl+Alt+M |
|
- Monokai
|
||||||
|
- Material
|
||||||
## Themes
|
- Gruvbox Dark
|
||||||
|
- Tokyo Night
|
||||||
### Light Themes
|
- Palenight
|
||||||
- Atom One Light (Default)
|
- Ayu Dark
|
||||||
- GitHub Light
|
- Ayu Mirage
|
||||||
- Light
|
- Oceanic Next
|
||||||
- Solarized Light
|
- Cobalt2
|
||||||
- Gruvbox Light
|
- Concrete Dark
|
||||||
- Ayu Light
|
- Concrete Warm
|
||||||
- Sepia
|
|
||||||
- Paper
|
## PDF Viewer
|
||||||
- Rose Pine Dawn
|
|
||||||
- Concrete Light
|
Open PDF files directly in MarkdownConverter:
|
||||||
|
- **File > Open PDF** or **Ctrl+Shift+O**
|
||||||
### Dark Themes
|
- Navigate pages with arrow buttons or page input
|
||||||
- Dark
|
- Zoom controls: +/- buttons, Fit Width, Fit Page
|
||||||
- One Dark
|
- Rotate pages left or right
|
||||||
- Dracula
|
- Close PDF to return to editor
|
||||||
- Nord
|
|
||||||
- Monokai
|
## Open Source
|
||||||
- Material
|
|
||||||
- Gruvbox Dark
|
MarkdownConverter is 100% open-source. All dependencies are permissively licensed:
|
||||||
- Tokyo Night
|
- **Electron** - MIT License
|
||||||
- Palenight
|
- **pdf-lib** - MIT License
|
||||||
- Ayu Dark
|
- **pdfjs-dist** - Apache 2.0 License
|
||||||
- Ayu Mirage
|
- **marked** - MIT License
|
||||||
- Oceanic Next
|
- **highlight.js** - BSD 3-Clause License
|
||||||
- Cobalt2
|
- **dompurify** - Apache 2.0/MIT License
|
||||||
- Concrete Dark
|
- **docx** - MIT License
|
||||||
- Concrete Warm
|
- **xlsx** - Apache 2.0 License (SheetJS Community Edition)
|
||||||
|
|
||||||
## PDF Viewer
|
## License
|
||||||
|
|
||||||
Open PDF files directly in MarkdownConverter:
|
MIT License - see LICENSE file for details.
|
||||||
- **File > Open PDF** or **Ctrl+Shift+O**
|
|
||||||
- Navigate pages with arrow buttons or page input
|
## Author
|
||||||
- Zoom controls: +/- buttons, Fit Width, Fit Page
|
|
||||||
- Rotate pages left or right
|
Amit Haridas (amit.wh@gmail.com)
|
||||||
- Close PDF to return to editor
|
|
||||||
|
## Version
|
||||||
## Bundled Dependencies, Legal Notices & Credits
|
|
||||||
|
v3.0.0
|
||||||
MarkdownConverter ships as a self-contained package. Everything needed for the
|
|
||||||
core workflows is **bundled**; a few large optional tools are detected from
|
|
||||||
the system when present.
|
|
||||||
|
|
||||||
### Bundled with the app
|
|
||||||
|
|
||||||
| Component | License | Role |
|
|
||||||
|---|---|---|
|
|
||||||
| [Pandoc](https://pandoc.org) 3.9 | GPL-2.0+ (separate process) | 25+ export/import formats |
|
|
||||||
| [FFmpeg](https://ffmpeg.org) (via ffmpeg-static) | GPL-3.0+ build (separate process) | audio/video tools |
|
|
||||||
| [MarkItDown](https://github.com/microsoft/markitdown) (MIT) + embedded Python runtime (PSF) | MIT / PSF | any-file → Markdown import (PDF/DOCX/PPTX/XLSX/Outlook/EPUB/images/ZIP) |
|
|
||||||
| [sharp](https://sharp.pixelplumbing.com) + libvips | Apache-2.0 / LGPL-2.1+ (dynamic) | image tools |
|
|
||||||
| [KaTeX](https://katex.org), [marked](https://marked.js.org), [highlight.js], [DOMPurify], [mermaid], [CodeMirror 6], pdf-lib (@cantoo fork), pdfjs-dist, JSZip, simple-git | MIT / Apache-2.0 / BSD-3 / MPL-2.0 | editor, preview, PDF, Git |
|
|
||||||
| JetBrains Mono & Fira Code fonts | SIL OFL 1.1 | editor typography |
|
|
||||||
|
|
||||||
GPL-licensed tools run as **separate processes** (never linked into the app)
|
|
||||||
and their complete corresponding sources are offered in
|
|
||||||
[SOURCES.md](SOURCES.md). Full details: [THIRD-PARTY-NOTICES.md](THIRD-PARTY-NOTICES.md),
|
|
||||||
also available inside the app under **Help → Third-Party Notices & Licenses**.
|
|
||||||
|
|
||||||
### Not bundled (used when installed)
|
|
||||||
|
|
||||||
LibreOffice (Office conversion), MiKTeX/TeX Live (LaTeX PDF), ImageMagick
|
|
||||||
(extra image formats), PlantUML + Java (local diagrams), Calibre (MOBI),
|
|
||||||
MarkItDown `[all]` extras (audio transcription / OCR).
|
|
||||||
|
|
||||||
### Credits
|
|
||||||
|
|
||||||
Built on open source: [Electron], [CodeMirror], [marked], [KaTeX],
|
|
||||||
[highlight.js], [DOMPurify](https://github.com/cure53/DOMPurify),
|
|
||||||
[mermaid](https://mermaid.js.org), [pdf-lib], [pdf.js](https://mozilla.github.io/pdf.js/),
|
|
||||||
[sharp]/libvips, [Pandoc], [FFmpeg], [MarkItDown] by Microsoft,
|
|
||||||
[simple-git], [JSZip], [JetBrains Mono], [Fira Code]. Thank you to all their
|
|
||||||
authors and maintainers.
|
|
||||||
|
|
||||||
## Open Source
|
|
||||||
|
|
||||||
MarkdownConverter is 100% open-source. All dependencies are permissively licensed:
|
|
||||||
- **Electron** - MIT License
|
|
||||||
- **pdf-lib** - MIT License
|
|
||||||
- **pdfjs-dist** - Apache 2.0 License
|
|
||||||
- **marked** - MIT License
|
|
||||||
- **highlight.js** - BSD 3-Clause License
|
|
||||||
- **dompurify** - Apache 2.0/MIT License
|
|
||||||
- **docx** - MIT License
|
|
||||||
- **xlsx** - Apache 2.0 License (SheetJS Community Edition)
|
|
||||||
|
|
||||||
## License
|
|
||||||
|
|
||||||
MIT License - see LICENSE file for details.
|
|
||||||
|
|
||||||
## Author
|
|
||||||
|
|
||||||
Amit Haridas (amit.wh@gmail.com)
|
|
||||||
|
|
||||||
## Version
|
|
||||||
|
|
||||||
v4.7.0
|
|
||||||
|
|||||||
-55
@@ -1,55 +0,0 @@
|
|||||||
# Source Code Availability (GPL / LGPL Written Offer)
|
|
||||||
|
|
||||||
MarkdownConverter distributes the following binaries built from GPL-licensed
|
|
||||||
software. Per GPL §3(b), this document is the written offer: **corresponding
|
|
||||||
source code for the exact versions listed below is available on request for
|
|
||||||
at least three years from each release**, and permanently at the referenced
|
|
||||||
public locations. Write to: amit.wh@gmail.com (or open a GitHub issue at
|
|
||||||
https://github.com/amitwh/markdown-converter/issues).
|
|
||||||
|
|
||||||
## Pandoc — GPL-2.0-or-later
|
|
||||||
|
|
||||||
- Binary shipped: `bin/pandoc` (v3.9.0.2, official upstream release, unmodified)
|
|
||||||
- SHA-256 (linux): `7d124235998ecd3cdd9a463b1e5f6691a178b6461824c29a36170a0882f05597`
|
|
||||||
- Source: <https://github.com/jgm/pandoc/archive/refs/tags/3.9.0.2.tar.gz>
|
|
||||||
- Pandoc statically links Haskell libraries (GHC ecosystem, mostly BSD-3);
|
|
||||||
their sources are included in the upstream release tarball's dependency set.
|
|
||||||
|
|
||||||
## FFmpeg — GPL-3.0-or-later (build configuration)
|
|
||||||
|
|
||||||
- Binary shipped: `ffmpeg` provided by the npm package `ffmpeg-static@5.3.0`
|
|
||||||
(Linux: johnvansickle.com build; Windows: gyan.dev; macOS: evermeet.cx —
|
|
||||||
all `--enable-gpl` builds including x264/x265, per the build banner)
|
|
||||||
- Source:
|
|
||||||
- FFmpeg: <https://ffmpeg.org/releases/> (use the release matching
|
|
||||||
`ffmpeg -version` of the shipped binary)
|
|
||||||
- Build scripts & pinned versions: <https://github.com/eugeneware/ffmpeg-static>
|
|
||||||
- x264: <https://code.videolan.org/videolan/x264> ·
|
|
||||||
x265: <https://bitbucket.org/multicoreware/x265_git/> ·
|
|
||||||
other `--enable-lib*` components: their upstream sources (all free/open)
|
|
||||||
|
|
||||||
## PyInstaller bootloader (inside the bundled MarkItDown binary) — GPL-2.0 with boot-exception
|
|
||||||
|
|
||||||
- Binary shipped: `bin/markitdown` (MarkItDown 0.1.7 frozen with PyInstaller 6.x)
|
|
||||||
- PyInstaller grants a special exception allowing the bootloader to be
|
|
||||||
embedded in non-GPL frozen applications; source anyway:
|
|
||||||
<https://github.com/pyinstaller/pyinstaller>
|
|
||||||
- Everything frozen above the bootloader (markitdown + Python packages +
|
|
||||||
CPython runtime) is permissively licensed (MIT/Apache/BSD/PSF/MPL);
|
|
||||||
see THIRD-PARTY-NOTICES.md §2 for the list.
|
|
||||||
- CPython runtime source: <https://www.python.org/downloads/source/>
|
|
||||||
(PSF License — not GPL, listed here for completeness).
|
|
||||||
|
|
||||||
## libvips (via sharp prebuilt binaries) — LGPL-2.1-or-later
|
|
||||||
|
|
||||||
- Shipped as dynamically-loaded libraries from `@img/*` prebuilts for sharp 0.35.4
|
|
||||||
- Source: <https://github.com/libvips/libvips> · prebuilt bundle sources:
|
|
||||||
<https://github.com/lovell/sharp-builds>
|
|
||||||
- LGPL compliance: the app's own source is public (MIT) and the libraries
|
|
||||||
remain separately replaceable files in the installation directory
|
|
||||||
(`node_modules/@img/`), satisfying the relinking requirement.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
_Versions and hashes above correspond to the release this file ships with;
|
|
||||||
update them when bumping bundled tool versions._
|
|
||||||
@@ -1,108 +0,0 @@
|
|||||||
# Third-Party Notices & Licenses
|
|
||||||
|
|
||||||
MarkdownConverter (this app) is MIT-licensed. This document lists the
|
|
||||||
third-party components that are **distributed with** the application, their
|
|
||||||
licenses, and where to obtain source code. Full license texts for the
|
|
||||||
copyleft and font licenses referenced here are in the `third-party-licenses/`
|
|
||||||
folder shipped alongside this file (and in the source repository).
|
|
||||||
|
|
||||||
This product includes software developed by third parties under the licenses
|
|
||||||
below. Copyright and license notices are reproduced verbatim or referenced
|
|
||||||
per each license's terms.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 1. This application
|
|
||||||
|
|
||||||
**MarkdownConverter** — Copyright (C) 2024-2025 ConcreteInfo (Amit Haridas) —
|
|
||||||
MIT License. See the repository `LICENSE` file.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 2. Bundled external binaries
|
|
||||||
|
|
||||||
These run as separate operating-system processes, launched via `execFile`
|
|
||||||
with literal argv (never a shell, never linked into the app).
|
|
||||||
|
|
||||||
| Component | Version | License | Notes |
|
|
||||||
|---|---|---|---|
|
|
||||||
| Pandoc | 3.9.0.2 | GPL-2.0-or-later | Downloaded at build time by `scripts/download-tools.js` (SHA-256 pinned); license: [GPL-2.0](third-party-licenses/GPL-2.0.txt) |
|
|
||||||
| FFmpeg | bundled by `ffmpeg-static` 5.3.0 | **GPL-3.0-or-later build** (`--enable-gpl --enable-libx264/x265`) | License text: <https://ffmpeg.org/legal.html>; source offer below |
|
|
||||||
| MarkItDown | 0.1.7 (+ Python deps) | MIT | Microsoft's any-file→Markdown importer, frozen with PyInstaller by `scripts/bundle-markitdown.js`; includes an embedded CPython runtime (PSF license) |
|
|
||||||
| sharp / libvips prebuilt binaries | 0.35.4 | Apache-2.0 / **LGPL-2.1-or-later** (libvips) | Dynamically loaded native addon; LGPL compliance: this app's full MIT source is public, enabling relinking; license: [LGPL-2.1](third-party-licenses/LGPL-2.1.txt) |
|
|
||||||
| KaTeX (CSS + fonts) | 0.18.5 | MIT | `assets/katex/` |
|
|
||||||
| JetBrains Mono, Fira Code fonts | — | SIL OFL 1.1 | `assets/fonts/`; license: [OFL-1.1](third-party-licenses/OFL-1.1.txt) |
|
|
||||||
| Electron | 41.x | MIT | and its bundled Chromium (BSD-style licenses) / Node.js (MIT) / OpenSSL (Apache-2.0) — see <https://www.electronjs.org/blog/electron-licensing> |
|
|
||||||
|
|
||||||
### GPL source availability (GPL §3 offer)
|
|
||||||
|
|
||||||
Corresponding source for every GPL-licensed binary distributed with this app
|
|
||||||
is available on written request and from these permanent locations — see
|
|
||||||
**[SOURCES.md](SOURCES.md)** for exact versions and URLs.
|
|
||||||
|
|
||||||
### Python packages inside the bundled MarkItDown binary
|
|
||||||
|
|
||||||
The frozen MarkItDown binary embeds CPython and (each MIT/Apache-2.0/BSD-3/
|
|
||||||
PSF/MPL-2.0 licensed unless noted): markitdown, onnxruntime (MIT), numpy
|
|
||||||
(BSD-3), magika (Apache-2.0), beautifulsoup4 / soupsieve (MIT), requests
|
|
||||||
(Apache-2.0) + urllib3/idna/charset-normalizer, certifi (MPL-2.0),
|
|
||||||
markdownify, defusedxml (PSF), protobuf (BSD-3), flatbuffers (Apache-2.0),
|
|
||||||
pdfminer.six (MIT), python-docx, python-pptx, openpyxl, extract-msg,
|
|
||||||
markdown-it-py / mdurl, pyinstaller (GPL-2.0-with-exception — build tool
|
|
||||||
only; its bootloader is embedded, source offer included in SOURCES.md),
|
|
||||||
Packaging, six, click, chardet (LGPL — dynamically loadable Python module).
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 3. npm dependencies shipped in the app (runtime)
|
|
||||||
|
|
||||||
| Package | Version | License |
|
|
||||||
|---|---|---|
|
|
||||||
| @cantoo/pdf-lib | 2.9.1 | MIT |
|
|
||||||
| @codemirror/* (autocomplete, commands, lang-*, language, lint, search, state, theme-one-dark, view), codemirror | 6.x | MIT |
|
|
||||||
| @replit/codemirror-vim | 6.4.0 | MIT |
|
|
||||||
| core-util-is | 1.0.3 | MIT |
|
|
||||||
| docx | 9.6.1 | MIT |
|
|
||||||
| dompurify | 3.4.14 | (MPL-2.0 OR Apache-2.0) |
|
|
||||||
| electron-store | 10.1.0 | MIT |
|
|
||||||
| ffmpeg-static | 5.3.0 | GPL-3.0-or-later (binary; see §2) |
|
|
||||||
| highlight.js | 11.11.1 | BSD-3-Clause |
|
|
||||||
| html2pdf.js | 0.14.0 | MIT |
|
|
||||||
| jszip | 3.10.1 | (MIT OR GPL-3.0-or-later) |
|
|
||||||
| katex | 0.18.5 | MIT |
|
|
||||||
| marked, marked-footnote, marked-highlight | 17.x / 1.4 / 2.2 | MIT |
|
|
||||||
| mermaid | 11.17.2 | MIT |
|
|
||||||
| pdfjs-dist | 5.5.207 | Apache-2.0 |
|
|
||||||
| pdfkit | 0.17.2 | MIT |
|
|
||||||
| pizzip | 3.2.0 | (MIT OR GPL-3.0) |
|
|
||||||
| sharp | 0.35.4 | Apache-2.0 (+ LGPL libvips binaries; see §2) |
|
|
||||||
| simple-git | 3.36.0 | MIT |
|
|
||||||
| tslib | 2.8.1 | 0BSD |
|
|
||||||
|
|
||||||
(Development-only dependencies — electron-builder, eslint, prettier, jest,
|
|
||||||
cross-env, @testing-library/dom — are not distributed with the application.)
|
|
||||||
|
|
||||||
## 4. Optional external tools (NOT bundled)
|
|
||||||
|
|
||||||
These are detected and used when the user installs them; no copy is
|
|
||||||
distributed with this app, so no redistribution obligations arise:
|
|
||||||
|
|
||||||
- **LibreOffice** (MPL-2.0) — enhanced Office-format conversion
|
|
||||||
- **MiKTeX / TeX Live** (LPPL/GPL per component) — LaTeX PDF export
|
|
||||||
- **ImageMagick** (Apache-2.0-style) — extra image formats in the universal converter
|
|
||||||
- **PlantUML** (GPL-3.0) + a Java runtime — local diagram rendering
|
|
||||||
- **Calibre** (`ebook-convert`) — MOBI export
|
|
||||||
- **System MarkItDown with `[all]` extras** — audio transcription / OCR
|
|
||||||
|
|
||||||
## 5. Trademarks
|
|
||||||
|
|
||||||
Product names used to describe compatibility (Pandoc, FFmpeg, LibreOffice,
|
|
||||||
MarkItDown, Microsoft, Excel, Word, PowerPoint…) are trademarks of their
|
|
||||||
respective owners and are not affiliated with this project.
|
|
||||||
|
|
||||||
## 6. License texts
|
|
||||||
|
|
||||||
See the `third-party-licenses/` directory: `GPL-2.0.txt`, `LGPL-2.1.txt`,
|
|
||||||
`MPL-2.0.txt`, `Apache-2.0.txt`, `OFL-1.1.txt`, `PSF-Python.txt`. MIT and
|
|
||||||
BSD-3-Clause texts are short and reproduced in each package's own repository;
|
|
||||||
per-package LICENSE files also ship inside `node_modules/` in source form.
|
|
||||||
+166
-339
@@ -1,339 +1,166 @@
|
|||||||
# PanConverter - Updates & Changelog
|
# PanConverter - Updates & Changelog
|
||||||
|
|
||||||
## Version 4.7.0 (2026-09-05)
|
## Version 2.1.0 (December 14, 2025)
|
||||||
|
|
||||||
### Bundling & Legal Compliance
|
### 🎨 UI/UX Improvements
|
||||||
- **MarkItDown is now bundled**: `npm run bundle:markitdown` freezes Microsoft's
|
|
||||||
markitdown (MIT) + embedded Python runtime into a single ~75MB per-platform
|
#### Subtle & Small Preview Popout Button
|
||||||
binary (`bin/<platform>/markitdown`) via PyInstaller (ML extras excluded);
|
- Redesigned popout button with minimalist aesthetic
|
||||||
the app prefers the bundled binary and falls back to system installs
|
- Removed border for cleaner appearance
|
||||||
- Packaging copies the bundled markitdown for Windows/macOS/Linux alongside Pandoc
|
- Reduced size: 11px font, 2px×6px padding (previously 14px font, 4px×8px padding)
|
||||||
- **THIRD-PARTY-NOTICES.md** — full license inventory of everything distributed
|
- Added opacity transition: 50% when idle, 100% on hover
|
||||||
(bundled binaries, npm runtime deps, fonts, embedded Python packages)
|
- Subtle background effect on hover instead of heavy border styling
|
||||||
- **SOURCES.md** — GPL §3(b) written source offer for Pandoc / FFmpeg (GPL build) /
|
- **File**: `src/styles.css:195-211`
|
||||||
PyInstaller bootloader, with pinned versions + SHA-256; LGPL relinking note for libvips
|
|
||||||
- **third-party-licenses/** — canonical texts: GPL-2.0, LGPL-2.1, MPL-2.0,
|
#### Simplified Table Headers in Preview
|
||||||
Apache-2.0, OFL-1.1, PSF-Python
|
- Removed gradient background from table headers in modern theme
|
||||||
- **Help → Third-Party Notices & Licenses** — in-app viewer for both documents
|
- Changed from `var(--primary-gradient)` (purple gradient) to simple light gray (#f0f0f0)
|
||||||
- **download-tools.js** now SHA-256 pins and verifies every downloaded artifact
|
- Updated text color to dark (#333333) for better readability
|
||||||
(post-download and against the cache on every run; hard-fails on mismatch)
|
- Clean, professional appearance matching standard themes
|
||||||
- README gains a "Bundled Dependencies, Legal Notices & Credits" section
|
- **File**: `src/styles-modern.css:445-449`
|
||||||
- Large optional tools intentionally NOT bundled (documented): LibreOffice,
|
|
||||||
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre
|
### 📥 Enhanced Import Capabilities
|
||||||
|
|
||||||
---
|
#### Comprehensive Format-to-Markdown Conversion
|
||||||
|
Dramatically expanded the "Import Document" feature to support 30+ file formats:
|
||||||
## Version 4.6.1 (2026-09-05)
|
|
||||||
|
**Supported Formats:**
|
||||||
### New Features
|
- **Documents**: DOCX, ODT, RTF, HTML, HTM, TEX, EPUB, PDF, TXT
|
||||||
- **MarkItDown import** — "File → Import with MarkItDown (Any Format)…" embeds
|
- **Presentations**: PPTX, ODP
|
||||||
Microsoft's [markitdown](https://github.com/microsoft/markitdown) (MIT) as an
|
- **Markup Languages**: RST, Textile, MediaWiki, Org-mode, AsciiDoc, TWiki, OPML
|
||||||
any-file → Markdown path: PDF, DOCX, PPTX, XLSX, Outlook .msg/.eml, EPUB,
|
- **E-book Formats**: EPUB, FB2
|
||||||
images, CSV/JSON/XML, ZIP; audio transcription and OCR with the `[all]` extras
|
- **LaTeX Formats**: TEX, LATEX, LTX
|
||||||
- Command auto-resolution: `markitdown` binary, then `python -m markitdown` /
|
- **Web Formats**: HTML, HTM, XHTML
|
||||||
`python3 -m markitdown` (probed once, cached)
|
- **Wiki Formats**: MediaWiki, DokuWiki, TikiWiki, TWiki
|
||||||
- Same SEC-1 argv discipline as Pandoc (execFile only, paths never through a shell),
|
- **Data Formats**: CSV, TSV, JSON
|
||||||
50MB input cap, 120s timeout, path-sanitized errors that surface markitdown's
|
|
||||||
actionable `pip install 'markitdown[...]'` hints
|
**Format-Specific Optimizations:**
|
||||||
- Output written next to the source as `<name>.md` (numeric suffix instead of
|
- PDF text extraction with XeLaTeX engine
|
||||||
overwriting) and opened in a new tab; `markitdown:available` / `markitdown:convert`
|
- CSV/TSV automatic table conversion
|
||||||
IPC for future renderer flows
|
- JSON structure handling
|
||||||
- **AI Assistant: Anthropic-compatible provider** — any base URL speaking the
|
- Improved error messages with format hints
|
||||||
Anthropic messages schema (LiteLLM proxies, Bedrock gateways, local servers);
|
|
||||||
x-api-key + Bearer auth, keyless proxies supported, tolerates bases with or
|
**Access**: File → Import Document (Ctrl+I)
|
||||||
without a trailing `/v1`
|
**File**: `src/main.js:1933-1994`
|
||||||
|
|
||||||
### Bug Fixes
|
### 🎨 Exhaustive ASCII Art Generator
|
||||||
- File → Open PDF crashed the PDF editor (null operation matched no section; now
|
|
||||||
defaults to Merge)
|
#### 5 New Text Banner Styles
|
||||||
- Backlinks panel required the wrong module path (failed at registration)
|
Complete alphabet (A-Z) and numbers (0-9) support for all styles:
|
||||||
- writing-studio engines/panels now await their IPC-backed settings/file backends
|
|
||||||
(eliminates `JSON.parse("[object Promise]")` crashes)
|
1. **Standard** - Classic ASCII art with slashes and underscores
|
||||||
- Manuscript panel's window.prompt (unsupported in Electron) replaced with an
|
2. **Banner** - Large format using # characters (7-line height)
|
||||||
inline dialog; collaboration comment store made async to match its IO
|
3. **Block** - Modern Unicode block characters (█ ╔ ╗ ═ ║)
|
||||||
|
4. **Bubble** - Circular bubble letters (Ⓐ Ⓑ Ⓒ)
|
||||||
---
|
5. **Digital** - Digital display style (▄ ▀ ▐ ▌)
|
||||||
|
|
||||||
## Version 4.6.0 (2026-09-05)
|
**File**: `src/renderer.js:3397-3537`
|
||||||
|
|
||||||
### New Features
|
#### 19 Professional ASCII Templates
|
||||||
|
Organized into 4 categories with expanded options:
|
||||||
#### AI Assistant Plugin (multi-provider)
|
|
||||||
- Chat sidebar panel with rolling conversation history and insert-reply-into-document
|
**Arrows & Flow (4 templates):**
|
||||||
- Providers: OpenAI, Anthropic, Ollama, LM Studio, and any OpenAI-compatible endpoint
|
- Arrow Right - Horizontal flow indicators
|
||||||
- All provider traffic proxied through the main process — API keys never enter the renderer and the CSP stays closed to AI endpoints
|
- Arrow Down - Vertical flow indicators
|
||||||
- Commands: AI Summarize / Improve / Explain / Translate selection
|
- Decision - Binary decision diagrams
|
||||||
- Answers the writing-studio `ai:analyze` contract, finally enabling the Proofread panel
|
- Process Flow - Multi-step process visualization
|
||||||
|
|
||||||
#### Collaboration Plugin (inline comments)
|
**Diagrams & Charts (6 templates):**
|
||||||
- Anchor-based comments stored in `.comments/` sidecar files (never exported, never committed)
|
- Flowchart - Advanced flowchart with decision branches and loops
|
||||||
- Comments sidebar panel: add at cursor, list, resolve, delete, jump to anchor
|
- Sequence - Sequence diagrams for User-System-Database interactions
|
||||||
- Drift detection flags moved/edited anchors; F8 navigates to the next open comment
|
- Network - Server-client network topology
|
||||||
|
- Hierarchy - Organizational tree structures
|
||||||
#### Local Knowledge Base (wiki-links + backlinks)
|
- Timeline - Milestone visualization with dates
|
||||||
- `[[Note]]`, `[[Note|alias]]`, `[[Note#section]]` render as links in the preview (code blocks excluded)
|
- Table Simple - Basic table template with borders
|
||||||
- Clicking a wiki-link opens the note or offers to create it
|
|
||||||
- Backlinks sidebar panel scans the folder (bounded BFS) for documents linking to the current one
|
**Boxes & Containers (4 templates):**
|
||||||
|
- Header - Section header with decorative borders
|
||||||
#### Crash Recovery / Session Restore
|
- Note Box - Important notes with rounded corners (┏━━┓)
|
||||||
- Open tabs (paths + unsaved buffer content) snapshotted to localStorage, debounced on edits, on tab changes, on unload, and once a minute
|
- Warning Box - Warning messages with bold borders (╔═══╗)
|
||||||
- Restore prompt on launch with per-tab restore, clean-fresh option, and 2MB content budget
|
- Info Box - Information boxes with subtle styling (╭───╮)
|
||||||
|
|
||||||
#### Document Version History
|
**Decorative Elements (6 templates):**
|
||||||
- Every save snapshots the previous on-disk content to `<userData>/versions/`
|
- Divider - Horizontal section separator (═══)
|
||||||
- History sidebar panel: list, restore (with safety snapshot), unified diff vs. current, delete, manual "save version now"
|
- Separator Fancy - Elegant rounded divider
|
||||||
- Per-document pruning (20 versions), path-hash storage, id-validated reads
|
- Brackets - Japanese-style brackets 【 】
|
||||||
|
- Banner Stars - Star-bordered banners
|
||||||
#### Editor
|
- Checklist - Task lists with ✓ checkmarks
|
||||||
- Vim keybindings (View → Vim Mode, persisted, live toggle via CodeMirror Compartment)
|
- Progress Bar - Visual progress indicators
|
||||||
- Snippet Tab-expansion: type a snippet name and press Tab to insert it
|
|
||||||
- Zen Mode word-goal setter (the HUD progress bar finally has UI)
|
**Features:**
|
||||||
|
- All ASCII art automatically wrapped in code blocks for proper rendering
|
||||||
#### Export / Conversion
|
- Preserved formatting in markdown preview and all export formats
|
||||||
- **Real PDF encryption**: pdf-lib swapped for @cantoo/pdf-lib — encrypt/decrypt/permissions now actually work (UI auto-enables via the capability probe)
|
- Categorized template selection interface
|
||||||
- **XLSX export**: markdown tables → native Excel workbook, one sheet per table (no Pandoc needed)
|
- Real-time preview generation
|
||||||
- **ODT headers/footers + page size**: real ODF styles.xml patching replaces the empty stub
|
|
||||||
- **Local PlantUML rendering**: diagrams render on-machine via the `plantuml` CLI when installed; plantuml.com stays as fallback
|
**Access**: Tools → ASCII Art Generator
|
||||||
- **KaTeX bundled locally** (CSS + fonts): math renders offline, no CDN calls
|
**Files**: `src/renderer.js:3513-3671`, `src/index.html:427-466`
|
||||||
- Writing heatmap (GitHub-style 30-day grid) in the writing-studio Goals panel
|
|
||||||
|
### 📝 Technical Improvements
|
||||||
#### Platform
|
|
||||||
- Quick Note global scratchpad (Ctrl+Alt+Q, works when unfocused; appends to `notes/quick-notes.md`)
|
- Enhanced ASCII art detection in Word template exporter
|
||||||
- Deep link protocol `markdownconverter://open?path=…`
|
- Improved monospace font rendering across all export formats
|
||||||
- REPL confirmation dialog before first code execution per language per session (unsandboxed-execution guard rail)
|
- Better code block preservation in PDF and Word exports
|
||||||
- Writing-studio's four sidebar panels (Manuscript/Goals/Snapshots/Proofread) are now actually wired with rail icons
|
- Optimized template categorization and organization
|
||||||
- Plugin sidebar panels get automatic rail icons via `registerPanel({icon})`
|
|
||||||
|
### 🔧 Files Modified
|
||||||
### Bug Fixes
|
|
||||||
- `Ctrl+Shift+P` collision: PDF (Enhanced) export now `Ctrl+Alt+Shift+P`; Command Palette keeps `Ctrl+Shift+P`
|
- `src/styles.css` - Preview popout button styling
|
||||||
- Universal Converter's Pandoc tool no longer always reports "not installed" (`checkConverterAvailable` gained a pandoc case with bundled-binary check)
|
- `src/styles-modern.css` - Table header simplification
|
||||||
- CLI headless export: removed dangling `--css` / `--reference-doc` flags that made pandoc exit with an error; `--self-contained` replaced with `--standalone` (Pandoc 3.x)
|
- `src/main.js` - Enhanced import function, version update
|
||||||
- Removed dead "Open Export Options Dialog…" button from the converter dialog
|
- `src/renderer.js` - ASCII art generator enhancements
|
||||||
- Removed duplicate `styles-zen.css` include
|
- `src/index.html` - ASCII template UI organization
|
||||||
|
- `package.json` - Version bump to 2.1.0
|
||||||
### Security
|
|
||||||
- AI provider requests carry size caps (200KB prompt), timeouts (120s), and user-safe error surfaces
|
---
|
||||||
- Version-history reads validate ids against traversal; history listing requires a valid document path
|
|
||||||
- PlantUML local rendering removes the diagram-text exfiltration path when a local CLI exists (CVE-MC-007 follow-up)
|
## Version 2.0.0 (Previous Release)
|
||||||
|
|
||||||
### Tests
|
### Major Features
|
||||||
- New suites: OdtStyling, AiProviders, ai-assistant prompts, collaboration comment-store, wiki-links/backlinks, session-store, XlsxExporter, VersionHistory
|
- Export Profiles - Save and reuse export configurations
|
||||||
- PDFOperations encryption tests rewritten for the real-encryption reality
|
- Mermaid.js diagram support
|
||||||
|
- Command Palette (Ctrl+Shift+P)
|
||||||
---
|
- GitHub Light/Dark preview themes
|
||||||
|
- Table Generator
|
||||||
## Version 4.0.0 (2026-03-04)
|
- ASCII Art Generator (basic)
|
||||||
|
- Resizable Preview Pane
|
||||||
### Major Changes
|
- Pop-out Preview Window
|
||||||
- **CodeMirror 6 Editor** — Replaced textarea with CodeMirror 6 featuring syntax highlighting, code folding, bracket matching, multiple cursors, and auto-indent
|
- Configurable page sizes (A3-A5, B4-B5, Letter, Legal, Tabloid, Custom)
|
||||||
- **Sidebar Panel System** — Collapsible sidebar with File Explorer, Git, Snippets, and Templates panels
|
- Custom Headers & Footers for exports
|
||||||
- **Command Palette** — Ctrl+Shift+P to search and execute all app actions
|
- Enhanced PDF and Word export with templates
|
||||||
- **Code Execution (REPL)** — Run JavaScript, Python, and Bash code blocks directly from the preview
|
- 22 beautiful themes
|
||||||
|
|
||||||
### New Features
|
### Core Capabilities
|
||||||
- Print Preview dialog with paper size, orientation, margins, scale, and page range controls
|
- Cross-platform markdown editor with live preview
|
||||||
- Image paste from clipboard and drag-drop support with auto-save to assets folder
|
- Universal document conversion (30+ formats)
|
||||||
- Document templates library (10 templates: blog post, meeting notes, tech spec, changelog, README, project plan, API docs, tutorial, release notes, comparison)
|
- PDF Editor (merge, split, compress, rotate, watermark, encrypt)
|
||||||
- Markdown extensions: footnotes, admonitions (note/warning/tip/danger/info), and [[toc]] table of contents
|
- Batch file conversion
|
||||||
- PlantUML diagram rendering alongside Mermaid
|
- File association support
|
||||||
- Welcome tab with onboarding and "What's New" feature showcase
|
- Advanced export options
|
||||||
- System spell checking with context menu suggestions and dictionary support
|
- Multi-tab interface
|
||||||
- Enhanced status bar with word count, character count, line/column, encoding, and language mode
|
|
||||||
- Grouped toolbar with visual section separators
|
---
|
||||||
- Breadcrumb bar showing current file path
|
|
||||||
|
## Installation & Usage
|
||||||
### New Export/Import Formats
|
|
||||||
- Reveal.js slides (.html)
|
### Prerequisites
|
||||||
- Beamer slides (.pdf)
|
- **Pandoc** - Required for document conversion
|
||||||
- Confluence/Jira wiki markup (.txt)
|
- **Optional**: LibreOffice, ImageMagick, FFmpeg for universal converter
|
||||||
- MOBI e-books (via Calibre)
|
|
||||||
- Developer formats: JSON, YAML, XML, TOML
|
### Download
|
||||||
|
Get the latest release from: https://github.com/amitwh/pan-converter/releases
|
||||||
### Security
|
|
||||||
- Content Security Policy (CSP) meta tag
|
### Supported Platforms
|
||||||
- File size validation (50MB limit)
|
- Windows (x64)
|
||||||
- Error message sanitization (stripped file paths)
|
- Linux (AppImage, .deb, .snap)
|
||||||
- Conversion rate limiting (2-second debounce)
|
- macOS (planned)
|
||||||
|
|
||||||
### Dependencies Updated
|
---
|
||||||
- marked: 16.x to 17.x (with marked-highlight extension)
|
|
||||||
- pdfjs-dist: 3.x to 5.x (new worker model)
|
## Contributing
|
||||||
- html2pdf.js: 0.10 to 0.14
|
|
||||||
- pdfkit: 0.14 to 0.17
|
Contributions are welcome! Please see [CLAUDE.md](CLAUDE.md) for development guidelines.
|
||||||
- dompurify, docx, and others updated to latest
|
|
||||||
|
**Author**: Amit Haridas (amit.wh@gmail.com)
|
||||||
### Testing
|
**License**: MIT
|
||||||
- 80 tests across 7 test suites
|
**Repository**: https://github.com/amitwh/pan-converter
|
||||||
- New tests for sidebar manager, command palette, print preview, markdown extensions, and utility functions
|
|
||||||
|
|
||||||
### Breaking Changes
|
|
||||||
- Editor is now CodeMirror 6 (replaces textarea)
|
|
||||||
- marked API changed to use marked.use() instead of marked.setOptions()
|
|
||||||
- pdfjs-dist upgraded to v5 with new worker model
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Version 2.1.0 (December 14, 2025)
|
|
||||||
|
|
||||||
### 🎨 UI/UX Improvements
|
|
||||||
|
|
||||||
#### Subtle & Small Preview Popout Button
|
|
||||||
- Redesigned popout button with minimalist aesthetic
|
|
||||||
- Removed border for cleaner appearance
|
|
||||||
- Reduced size: 11px font, 2px×6px padding (previously 14px font, 4px×8px padding)
|
|
||||||
- Added opacity transition: 50% when idle, 100% on hover
|
|
||||||
- Subtle background effect on hover instead of heavy border styling
|
|
||||||
- **File**: `src/styles.css:195-211`
|
|
||||||
|
|
||||||
#### Simplified Table Headers in Preview
|
|
||||||
- Removed gradient background from table headers in modern theme
|
|
||||||
- Changed from `var(--primary-gradient)` (purple gradient) to simple light gray (#f0f0f0)
|
|
||||||
- Updated text color to dark (#333333) for better readability
|
|
||||||
- Clean, professional appearance matching standard themes
|
|
||||||
- **File**: `src/styles-modern.css:445-449`
|
|
||||||
|
|
||||||
### 📥 Enhanced Import Capabilities
|
|
||||||
|
|
||||||
#### Comprehensive Format-to-Markdown Conversion
|
|
||||||
Dramatically expanded the "Import Document" feature to support 30+ file formats:
|
|
||||||
|
|
||||||
**Supported Formats:**
|
|
||||||
- **Documents**: DOCX, ODT, RTF, HTML, HTM, TEX, EPUB, PDF, TXT
|
|
||||||
- **Presentations**: PPTX, ODP
|
|
||||||
- **Markup Languages**: RST, Textile, MediaWiki, Org-mode, AsciiDoc, TWiki, OPML
|
|
||||||
- **E-book Formats**: EPUB, FB2
|
|
||||||
- **LaTeX Formats**: TEX, LATEX, LTX
|
|
||||||
- **Web Formats**: HTML, HTM, XHTML
|
|
||||||
- **Wiki Formats**: MediaWiki, DokuWiki, TikiWiki, TWiki
|
|
||||||
- **Data Formats**: CSV, TSV, JSON
|
|
||||||
|
|
||||||
**Format-Specific Optimizations:**
|
|
||||||
- PDF text extraction with XeLaTeX engine
|
|
||||||
- CSV/TSV automatic table conversion
|
|
||||||
- JSON structure handling
|
|
||||||
- Improved error messages with format hints
|
|
||||||
|
|
||||||
**Access**: File → Import Document (Ctrl+I)
|
|
||||||
**File**: `src/main.js:1933-1994`
|
|
||||||
|
|
||||||
### 🎨 Exhaustive ASCII Art Generator
|
|
||||||
|
|
||||||
#### 5 New Text Banner Styles
|
|
||||||
Complete alphabet (A-Z) and numbers (0-9) support for all styles:
|
|
||||||
|
|
||||||
1. **Standard** - Classic ASCII art with slashes and underscores
|
|
||||||
2. **Banner** - Large format using # characters (7-line height)
|
|
||||||
3. **Block** - Modern Unicode block characters (█ ╔ ╗ ═ ║)
|
|
||||||
4. **Bubble** - Circular bubble letters (Ⓐ Ⓑ Ⓒ)
|
|
||||||
5. **Digital** - Digital display style (▄ ▀ ▐ ▌)
|
|
||||||
|
|
||||||
**File**: `src/renderer.js:3397-3537`
|
|
||||||
|
|
||||||
#### 19 Professional ASCII Templates
|
|
||||||
Organized into 4 categories with expanded options:
|
|
||||||
|
|
||||||
**Arrows & Flow (4 templates):**
|
|
||||||
- Arrow Right - Horizontal flow indicators
|
|
||||||
- Arrow Down - Vertical flow indicators
|
|
||||||
- Decision - Binary decision diagrams
|
|
||||||
- Process Flow - Multi-step process visualization
|
|
||||||
|
|
||||||
**Diagrams & Charts (6 templates):**
|
|
||||||
- Flowchart - Advanced flowchart with decision branches and loops
|
|
||||||
- Sequence - Sequence diagrams for User-System-Database interactions
|
|
||||||
- Network - Server-client network topology
|
|
||||||
- Hierarchy - Organizational tree structures
|
|
||||||
- Timeline - Milestone visualization with dates
|
|
||||||
- Table Simple - Basic table template with borders
|
|
||||||
|
|
||||||
**Boxes & Containers (4 templates):**
|
|
||||||
- Header - Section header with decorative borders
|
|
||||||
- Note Box - Important notes with rounded corners (┏━━┓)
|
|
||||||
- Warning Box - Warning messages with bold borders (╔═══╗)
|
|
||||||
- Info Box - Information boxes with subtle styling (╭───╮)
|
|
||||||
|
|
||||||
**Decorative Elements (6 templates):**
|
|
||||||
- Divider - Horizontal section separator (═══)
|
|
||||||
- Separator Fancy - Elegant rounded divider
|
|
||||||
- Brackets - Japanese-style brackets 【 】
|
|
||||||
- Banner Stars - Star-bordered banners
|
|
||||||
- Checklist - Task lists with ✓ checkmarks
|
|
||||||
- Progress Bar - Visual progress indicators
|
|
||||||
|
|
||||||
**Features:**
|
|
||||||
- All ASCII art automatically wrapped in code blocks for proper rendering
|
|
||||||
- Preserved formatting in markdown preview and all export formats
|
|
||||||
- Categorized template selection interface
|
|
||||||
- Real-time preview generation
|
|
||||||
|
|
||||||
**Access**: Tools → ASCII Art Generator
|
|
||||||
**Files**: `src/renderer.js:3513-3671`, `src/index.html:427-466`
|
|
||||||
|
|
||||||
### 📝 Technical Improvements
|
|
||||||
|
|
||||||
- Enhanced ASCII art detection in Word template exporter
|
|
||||||
- Improved monospace font rendering across all export formats
|
|
||||||
- Better code block preservation in PDF and Word exports
|
|
||||||
- Optimized template categorization and organization
|
|
||||||
|
|
||||||
### 🔧 Files Modified
|
|
||||||
|
|
||||||
- `src/styles.css` - Preview popout button styling
|
|
||||||
- `src/styles-modern.css` - Table header simplification
|
|
||||||
- `src/main.js` - Enhanced import function, version update
|
|
||||||
- `src/renderer.js` - ASCII art generator enhancements
|
|
||||||
- `src/index.html` - ASCII template UI organization
|
|
||||||
- `package.json` - Version bump to 2.1.0
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Version 2.0.0 (Previous Release)
|
|
||||||
|
|
||||||
### Major Features
|
|
||||||
- Export Profiles - Save and reuse export configurations
|
|
||||||
- Mermaid.js diagram support
|
|
||||||
- Command Palette (Ctrl+Shift+P)
|
|
||||||
- GitHub Light/Dark preview themes
|
|
||||||
- Table Generator
|
|
||||||
- ASCII Art Generator (basic)
|
|
||||||
- Resizable Preview Pane
|
|
||||||
- Pop-out Preview Window
|
|
||||||
- Configurable page sizes (A3-A5, B4-B5, Letter, Legal, Tabloid, Custom)
|
|
||||||
- Custom Headers & Footers for exports
|
|
||||||
- Enhanced PDF and Word export with templates
|
|
||||||
- 22 beautiful themes
|
|
||||||
|
|
||||||
### Core Capabilities
|
|
||||||
- Cross-platform markdown editor with live preview
|
|
||||||
- Universal document conversion (30+ formats)
|
|
||||||
- PDF Editor (merge, split, compress, rotate, watermark, encrypt)
|
|
||||||
- Batch file conversion
|
|
||||||
- File association support
|
|
||||||
- Advanced export options
|
|
||||||
- Multi-tab interface
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Installation & Usage
|
|
||||||
|
|
||||||
### Prerequisites
|
|
||||||
- **Pandoc** - Required for document conversion
|
|
||||||
- **Optional**: LibreOffice, ImageMagick, FFmpeg for universal converter
|
|
||||||
|
|
||||||
### Download
|
|
||||||
Get the latest release from: https://github.com/amitwh/pan-converter/releases
|
|
||||||
|
|
||||||
### Supported Platforms
|
|
||||||
- Windows (x64)
|
|
||||||
- Linux (AppImage, .deb, .snap)
|
|
||||||
- macOS (planned)
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Contributing
|
|
||||||
|
|
||||||
Contributions are welcome! Please see [CLAUDE.md](CLAUDE.md) for development guidelines.
|
|
||||||
|
|
||||||
**Author**: Amit Haridas (amit.wh@gmail.com)
|
|
||||||
**License**: MIT
|
|
||||||
**Repository**: https://github.com/amitwh/pan-converter
|
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
@@ -1,93 +0,0 @@
|
|||||||
Copyright (c) 2014, The Fira Code Project Authors (https://github.com/tonsky/FiraCode)
|
|
||||||
|
|
||||||
This Font Software is licensed under the SIL Open Font License, Version 1.1.
|
|
||||||
This license is copied below, and is also available with a FAQ at:
|
|
||||||
http://scripts.sil.org/OFL
|
|
||||||
|
|
||||||
|
|
||||||
-----------------------------------------------------------
|
|
||||||
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
|
|
||||||
-----------------------------------------------------------
|
|
||||||
|
|
||||||
PREAMBLE
|
|
||||||
The goals of the Open Font License (OFL) are to stimulate worldwide
|
|
||||||
development of collaborative font projects, to support the font creation
|
|
||||||
efforts of academic and linguistic communities, and to provide a free and
|
|
||||||
open framework in which fonts may be shared and improved in partnership
|
|
||||||
with others.
|
|
||||||
|
|
||||||
The OFL allows the licensed fonts to be used, studied, modified and
|
|
||||||
redistributed freely as long as they are not sold by themselves. The
|
|
||||||
fonts, including any derivative works, can be bundled, embedded,
|
|
||||||
redistributed and/or sold with any software provided that any reserved
|
|
||||||
names are not used by derivative works. The fonts and derivatives,
|
|
||||||
however, cannot be released under any other type of license. The
|
|
||||||
requirement for fonts to remain under this license does not apply
|
|
||||||
to any document created using the fonts or their derivatives.
|
|
||||||
|
|
||||||
DEFINITIONS
|
|
||||||
"Font Software" refers to the set of files released by the Copyright
|
|
||||||
Holder(s) under this license and clearly marked as such. This may
|
|
||||||
include source files, build scripts and documentation.
|
|
||||||
|
|
||||||
"Reserved Font Name" refers to any names specified as such after the
|
|
||||||
copyright statement(s).
|
|
||||||
|
|
||||||
"Original Version" refers to the collection of Font Software components as
|
|
||||||
distributed by the Copyright Holder(s).
|
|
||||||
|
|
||||||
"Modified Version" refers to any derivative made by adding to, deleting,
|
|
||||||
or substituting -- in part or in whole -- any of the components of the
|
|
||||||
Original Version, by changing formats or by porting the Font Software to a
|
|
||||||
new environment.
|
|
||||||
|
|
||||||
"Author" refers to any designer, engineer, programmer, technical
|
|
||||||
writer or other person who contributed to the Font Software.
|
|
||||||
|
|
||||||
PERMISSION & CONDITIONS
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining
|
|
||||||
a copy of the Font Software, to use, study, copy, merge, embed, modify,
|
|
||||||
redistribute, and sell modified and unmodified copies of the Font
|
|
||||||
Software, subject to the following conditions:
|
|
||||||
|
|
||||||
1) Neither the Font Software nor any of its individual components,
|
|
||||||
in Original or Modified Versions, may be sold by itself.
|
|
||||||
|
|
||||||
2) Original or Modified Versions of the Font Software may be bundled,
|
|
||||||
redistributed and/or sold with any software, provided that each copy
|
|
||||||
contains the above copyright notice and this license. These can be
|
|
||||||
included either as stand-alone text files, human-readable headers or
|
|
||||||
in the appropriate machine-readable metadata fields within text or
|
|
||||||
binary files as long as those fields can be easily viewed by the user.
|
|
||||||
|
|
||||||
3) No Modified Version of the Font Software may use the Reserved Font
|
|
||||||
Name(s) unless explicit written permission is granted by the corresponding
|
|
||||||
Copyright Holder. This restriction only applies to the primary font name as
|
|
||||||
presented to the users.
|
|
||||||
|
|
||||||
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
|
|
||||||
Software shall not be used to promote, endorse or advertise any
|
|
||||||
Modified Version, except to acknowledge the contribution(s) of the
|
|
||||||
Copyright Holder(s) and the Author(s) or with their explicit written
|
|
||||||
permission.
|
|
||||||
|
|
||||||
5) The Font Software, modified or unmodified, in part or in whole,
|
|
||||||
must be distributed entirely under this license, and must not be
|
|
||||||
distributed under any other license. The requirement for fonts to
|
|
||||||
remain under this license does not apply to any document created
|
|
||||||
using the Font Software.
|
|
||||||
|
|
||||||
TERMINATION
|
|
||||||
This license becomes null and void if any of the above conditions are
|
|
||||||
not met.
|
|
||||||
|
|
||||||
DISCLAIMER
|
|
||||||
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
||||||
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
|
|
||||||
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
|
|
||||||
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
|
|
||||||
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
|
|
||||||
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
|
|
||||||
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
|
||||||
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
|
|
||||||
OTHER DEALINGS IN THE FONT SOFTWARE.
|
|
||||||
File diff suppressed because one or more lines are too long
Binary file not shown.
@@ -1,93 +0,0 @@
|
|||||||
Copyright 2020 The JetBrains Mono Project Authors (https://github.com/JetBrains/JetBrainsMono)
|
|
||||||
|
|
||||||
This Font Software is licensed under the SIL Open Font License, Version 1.1.
|
|
||||||
This license is copied below, and is also available with a FAQ at:
|
|
||||||
https://scripts.sil.org/OFL
|
|
||||||
|
|
||||||
|
|
||||||
-----------------------------------------------------------
|
|
||||||
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
|
|
||||||
-----------------------------------------------------------
|
|
||||||
|
|
||||||
PREAMBLE
|
|
||||||
The goals of the Open Font License (OFL) are to stimulate worldwide
|
|
||||||
development of collaborative font projects, to support the font creation
|
|
||||||
efforts of academic and linguistic communities, and to provide a free and
|
|
||||||
open framework in which fonts may be shared and improved in partnership
|
|
||||||
with others.
|
|
||||||
|
|
||||||
The OFL allows the licensed fonts to be used, studied, modified and
|
|
||||||
redistributed freely as long as they are not sold by themselves. The
|
|
||||||
fonts, including any derivative works, can be bundled, embedded,
|
|
||||||
redistributed and/or sold with any software provided that any reserved
|
|
||||||
names are not used by derivative works. The fonts and derivatives,
|
|
||||||
however, cannot be released under any other type of license. The
|
|
||||||
requirement for fonts to remain under this license does not apply
|
|
||||||
to any document created using the fonts or their derivatives.
|
|
||||||
|
|
||||||
DEFINITIONS
|
|
||||||
"Font Software" refers to the set of files released by the Copyright
|
|
||||||
Holder(s) under this license and clearly marked as such. This may
|
|
||||||
include source files, build scripts and documentation.
|
|
||||||
|
|
||||||
"Reserved Font Name" refers to any names specified as such after the
|
|
||||||
copyright statement(s).
|
|
||||||
|
|
||||||
"Original Version" refers to the collection of Font Software components as
|
|
||||||
distributed by the Copyright Holder(s).
|
|
||||||
|
|
||||||
"Modified Version" refers to any derivative made by adding to, deleting,
|
|
||||||
or substituting -- in part or in whole -- any of the components of the
|
|
||||||
Original Version, by changing formats or by porting the Font Software to a
|
|
||||||
new environment.
|
|
||||||
|
|
||||||
"Author" refers to any designer, engineer, programmer, technical
|
|
||||||
writer or other person who contributed to the Font Software.
|
|
||||||
|
|
||||||
PERMISSION & CONDITIONS
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining
|
|
||||||
a copy of the Font Software, to use, study, copy, merge, embed, modify,
|
|
||||||
redistribute, and sell modified and unmodified copies of the Font
|
|
||||||
Software, subject to the following conditions:
|
|
||||||
|
|
||||||
1) Neither the Font Software nor any of its individual components,
|
|
||||||
in Original or Modified Versions, may be sold by itself.
|
|
||||||
|
|
||||||
2) Original or Modified Versions of the Font Software may be bundled,
|
|
||||||
redistributed and/or sold with any software, provided that each copy
|
|
||||||
contains the above copyright notice and this license. These can be
|
|
||||||
included either as stand-alone text files, human-readable headers or
|
|
||||||
in the appropriate machine-readable metadata fields within text or
|
|
||||||
binary files as long as those fields can be easily viewed by the user.
|
|
||||||
|
|
||||||
3) No Modified Version of the Font Software may use the Reserved Font
|
|
||||||
Name(s) unless explicit written permission is granted by the corresponding
|
|
||||||
Copyright Holder. This restriction only applies to the primary font name as
|
|
||||||
presented to the users.
|
|
||||||
|
|
||||||
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
|
|
||||||
Software shall not be used to promote, endorse or advertise any
|
|
||||||
Modified Version, except to acknowledge the contribution(s) of the
|
|
||||||
Copyright Holder(s) and the Author(s) or with their explicit written
|
|
||||||
permission.
|
|
||||||
|
|
||||||
5) The Font Software, modified or unmodified, in part or in whole,
|
|
||||||
must be distributed entirely under this license, and must not be
|
|
||||||
distributed under any other license. The requirement for fonts to
|
|
||||||
remain under this license does not apply to any document created
|
|
||||||
using the Font Software.
|
|
||||||
|
|
||||||
TERMINATION
|
|
||||||
This license becomes null and void if any of the above conditions are
|
|
||||||
not met.
|
|
||||||
|
|
||||||
DISCLAIMER
|
|
||||||
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
||||||
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
|
|
||||||
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
|
|
||||||
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
|
|
||||||
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
|
|
||||||
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
|
|
||||||
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
|
||||||
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
|
|
||||||
OTHER DEALINGS IN THE FONT SOFTWARE.
|
|
||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Vendored
-1
File diff suppressed because one or more lines are too long
@@ -1,866 +0,0 @@
|
|||||||
# MarkdownConverter - STRIDE Threat Model Analysis
|
|
||||||
|
|
||||||
**Version:** 4.1.0
|
|
||||||
**Date:** 2026-03-15
|
|
||||||
**Methodology:** STRIDE + MITRE ATT&CK Mapping
|
|
||||||
**Analyst:** Security Assessment Team
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Executive Summary
|
|
||||||
|
|
||||||
This threat model analyzes the MarkdownConverter Electron application using the STRIDE methodology. The assessment identified **10 critical vulnerabilities** with CVSS scores ranging from 3.5 to 9.6. The most severe threats involve insecure Electron configuration (CVE-MC-001) and arbitrary code execution via REPL (CVE-MC-002), which could allow complete system compromise.
|
|
||||||
|
|
||||||
**Risk Summary:**
|
|
||||||
| Severity | Count | Total CVSS Impact |
|
|
||||||
|----------|-------|-------------------|
|
|
||||||
| Critical (9.0+) | 2 | 18.9 |
|
|
||||||
| High (7.0-8.9) | 3 | 23.3 |
|
|
||||||
| Medium (5.0-6.9) | 3 | 17.3 |
|
|
||||||
| Low (<5.0) | 2 | 7.9 |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 1. System Architecture Overview
|
|
||||||
|
|
||||||
### 1.1 Application Components
|
|
||||||
|
|
||||||
```
|
|
||||||
+------------------------------------------------------------------+
|
|
||||||
| MarkdownConverter v4.0.0 |
|
|
||||||
+------------------------------------------------------------------+
|
|
||||||
| |
|
|
||||||
| +------------------+ +------------------+ |
|
|
||||||
| | Main Process |<--->| Renderer Process| |
|
|
||||||
| | (Node.js) | | (Chromium) | |
|
|
||||||
| +------------------+ +------------------+ |
|
|
||||||
| | | |
|
|
||||||
| | IPC Channels | |
|
|
||||||
| v v |
|
|
||||||
| +------------------+ +------------------+ |
|
|
||||||
| | preload.js | | renderer.js | |
|
|
||||||
| | (Bridge Layer) | | (UI Logic) | |
|
|
||||||
| +------------------+ +------------------+ |
|
|
||||||
| | | |
|
|
||||||
| v v |
|
|
||||||
| +--------------------------------------------------+ |
|
|
||||||
| | External Tools | |
|
|
||||||
| | Pandoc | FFmpeg | ImageMagick | LibreOffice | |
|
|
||||||
| +--------------------------------------------------+ |
|
|
||||||
| |
|
|
||||||
+------------------------------------------------------------------+
|
|
||||||
|
|
|
||||||
v
|
|
||||||
+------------------------------------------------------------------+
|
|
||||||
| External Services |
|
|
||||||
| - plantuml.com (diagram rendering) |
|
|
||||||
| - cdn.jsdelivr.net (scripts) |
|
|
||||||
| - cdnjs.cloudflare.com (styles) |
|
|
||||||
+------------------------------------------------------------------+
|
|
||||||
```
|
|
||||||
|
|
||||||
### 1.2 Data Flow Diagram (Level 1)
|
|
||||||
|
|
||||||
```
|
|
||||||
TRUST BOUNDARY
|
|
||||||
|
|
|
||||||
+-----------+ | +-----------+
|
|
||||||
| User | | | System |
|
|
||||||
| (Author) |------------------>|------------------>| Files |
|
|
||||||
+-----------+ Markdown | File I/O +-----------+
|
|
||||||
Content |
|
|
||||||
|
|
|
||||||
+---------------+---------------+
|
|
||||||
| |
|
|
||||||
v v
|
|
||||||
+---------------+ +---------------+
|
|
||||||
| Editor | | Preview |
|
|
||||||
| (CodeMirror) | | (Rendered) |
|
|
||||||
+---------------+ +---------------+
|
|
||||||
| ^
|
|
||||||
| Sanitization |
|
|
||||||
| (DOMPurify) |
|
|
||||||
v |
|
|
||||||
+---------------+ |
|
|
||||||
| Renderer |-----------------------+
|
|
||||||
| Process | HTML/SVG
|
|
||||||
+---------------+
|
|
||||||
|
|
|
||||||
| IPC (Whitelisted Channels)
|
|
||||||
v
|
|
||||||
+---------------+ +-----------+
|
|
||||||
| Main |-------------->| Pandoc |
|
|
||||||
| Process | execFile | FFmpeg |
|
|
||||||
| (Node.js) | | etc. |
|
|
||||||
+---------------+ +-----------+
|
|
||||||
|
|
|
||||||
| HTTPS
|
|
||||||
v
|
|
||||||
+---------------+
|
|
||||||
| PlantUML |
|
|
||||||
| Server |
|
|
||||||
| (External) |
|
|
||||||
+---------------+
|
|
||||||
```
|
|
||||||
|
|
||||||
### 1.3 Trust Boundaries
|
|
||||||
|
|
||||||
```
|
|
||||||
+============================================================================+
|
|
||||||
|| TRUST BOUNDARY 1: User <-> Application ||
|
|
||||||
|| - User input (markdown content) is UNTRUSTED ||
|
|
||||||
|| - File paths from dialogs are PARTIALLY TRUSTED ||
|
|
||||||
+============================================================================+
|
|
||||||
|
|
|
||||||
v
|
|
||||||
+============================================================================+
|
|
||||||
|| TRUST BOUNDARY 2: Renderer <-> Main Process ||
|
|
||||||
|| - IPC communication via preload.js ||
|
|
||||||
|| - CRITICAL: nodeIntegration=true bypasses isolation ||
|
|
||||||
+============================================================================+
|
|
||||||
|
|
|
||||||
v
|
|
||||||
+============================================================================+
|
|
||||||
|| TRUST BOUNDARY 3: Application <-> System ||
|
|
||||||
|| - External tool execution (Pandoc, FFmpeg, etc.) ||
|
|
||||||
|| - File system access ||
|
|
||||||
+============================================================================+
|
|
||||||
|
|
|
||||||
v
|
|
||||||
+============================================================================+
|
|
||||||
|| TRUST BOUNDARY 4: Application <-> Internet ||
|
|
||||||
|| - PlantUML server (https://www.plantuml.com) ||
|
|
||||||
|| - CDN resources (jsdelivr, cdnjs) ||
|
|
||||||
+============================================================================+
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 2. STRIDE Analysis
|
|
||||||
|
|
||||||
### 2.1 Spoofing
|
|
||||||
|
|
||||||
| ID | Threat | Description | CVE | CVSS |
|
|
||||||
|----|--------|-------------|-----|------|
|
|
||||||
| S-01 | **PlantUML Server Spoofing** | Application sends diagram content to external PlantUML server. MITM or compromised server could return malicious SVG content. | CVE-MC-007 | 5.3 |
|
|
||||||
| S-02 | **CDN Compromise** | Scripts loaded from cdn.jsdelivr.net and styles from cdnjs.cloudflare.com could be compromised in supply chain attack. | - | 6.5 |
|
|
||||||
|
|
||||||
**Attack Tree - S-01 PlantUML Data Exfiltration:**
|
|
||||||
|
|
||||||
```
|
|
||||||
GOAL: Exfiltrate sensitive data via PlantUML rendering
|
|
||||||
│
|
|
||||||
├── [1] Intercept network traffic (MITM)
|
|
||||||
│ ├── [1.1] Exploit weak TLS implementation
|
|
||||||
│ └── [1.1] DNS hijacking
|
|
||||||
│
|
|
||||||
├── [2] Compromise PlantUML server
|
|
||||||
│ ├── [2.1] Server breach
|
|
||||||
│ └── [2.2] Supply chain compromise
|
|
||||||
│
|
|
||||||
└── [3] Inject malicious SVG response
|
|
||||||
├── [3.1] XSS via SVG onload
|
|
||||||
└── [3.2] Data exfiltration via image src
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.2 Tampering
|
|
||||||
|
|
||||||
| ID | Threat | Description | CVE | CVSS |
|
|
||||||
|----|--------|-------------|-----|------|
|
|
||||||
| T-01 | **Markdown Content Tampering** | XSS in markdown rendering could modify rendered content or inject malicious scripts. | CVE-MC-003 | 8.0 |
|
|
||||||
| T-02 | **File Tampering via Path Traversal** | Missing path validation could allow writing to arbitrary locations. | CVE-MC-004 | 7.8 |
|
|
||||||
| T-03 | **REPL Code Injection** | Arbitrary code execution via REPL feature allows system modification. | CVE-MC-002 | 9.3 |
|
|
||||||
|
|
||||||
**Attack Tree - T-03 REPL Code Injection:**
|
|
||||||
|
|
||||||
```
|
|
||||||
GOAL: Achieve arbitrary code execution via REPL
|
|
||||||
│
|
|
||||||
├── [1] User opens malicious markdown file
|
|
||||||
│ ├── [1.1] Phishing/social engineering
|
|
||||||
│ └── [1.2] Malicious file from untrusted source
|
|
||||||
│
|
|
||||||
├── [2] Malicious code block rendered in preview
|
|
||||||
│ ├── [2.1] JavaScript code block
|
|
||||||
│ ├── [2.2] Python code block
|
|
||||||
│ └── [2.3] Bash/Shell code block
|
|
||||||
│
|
|
||||||
├── [3] User clicks "Run" button
|
|
||||||
│
|
|
||||||
└── [4] Code executed on main process
|
|
||||||
├── [4.1] File system access
|
|
||||||
├── [4.2] Process execution
|
|
||||||
└── [4.3] Network access
|
|
||||||
└── [4.3.1] Data exfiltration
|
|
||||||
└── [4.3.2] C2 communication
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.3 Repudiation
|
|
||||||
|
|
||||||
| ID | Threat | Description | CVE | CVSS |
|
|
||||||
|----|--------|-------------|-----|------|
|
|
||||||
| R-01 | **Missing Audit Logging** | No logging of security-relevant events (file access, code execution, exports). | - | 4.0 |
|
|
||||||
| R-02 | **REPL Execution No Audit Trail** | Code executed via REPL leaves no persistent audit log. | CVE-MC-002 | 5.0 |
|
|
||||||
|
|
||||||
### 2.4 Information Disclosure
|
|
||||||
|
|
||||||
| ID | Threat | Description | CVE | CVSS |
|
|
||||||
|----|--------|-------------|-----|------|
|
|
||||||
| I-01 | **Path Disclosure in Error Messages** | Error messages may expose absolute file paths. Partially mitigated by `sanitizeErrorMessage()`. | - | 4.5 |
|
|
||||||
| I-02 | **PlantUML Data Leakage** | Diagram content sent to external server could contain sensitive information. | CVE-MC-007 | 5.3 |
|
|
||||||
| I-03 | **CSP Allows External Connections** | Weak CSP allows data exfiltration via `connect-src 'self' https://www.plantuml.com`. | CVE-MC-005 | 7.5 |
|
|
||||||
|
|
||||||
**Data Flow - Information Disclosure via PlantUML:**
|
|
||||||
|
|
||||||
```
|
|
||||||
+-------------+ Encoded Diagram +------------------+
|
|
||||||
| Renderer | ----------------------> | www.plantuml.com |
|
|
||||||
| Process | (~h encoded) | (External) |
|
|
||||||
+-------------+ +------------------+
|
|
||||||
| |
|
|
||||||
| Sensitive data in diagram: |
|
|
||||||
| - Architecture details |
|
|
||||||
| - Database schemas |
|
|
||||||
| - API endpoints |
|
|
||||||
| - Class names/relationships |
|
|
||||||
v v
|
|
||||||
+-------------+ +-------------+
|
|
||||||
| Attacker | <--- Network Capture -- | Network |
|
|
||||||
| (MITM) | | Traffic |
|
|
||||||
+-------------+ +-------------+
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.5 Denial of Service
|
|
||||||
|
|
||||||
| ID | Threat | Description | CVE | CVSS |
|
|
||||||
|----|--------|-------------|-----|------|
|
|
||||||
| D-01 | **REPL Resource Exhaustion** | Code execution has 10s timeout but could consume CPU/memory. | CVE-MC-002 | 4.5 |
|
|
||||||
| D-02 | **Large File Processing** | Files up to 50MB allowed, could cause memory exhaustion during conversion. | - | 5.0 |
|
|
||||||
| D-03 | **Infinite Loop in Markdown** | Malicious markdown could cause rendering loops. | - | 4.0 |
|
|
||||||
|
|
||||||
### 2.6 Elevation of Privilege
|
|
||||||
|
|
||||||
| ID | Threat | Description | CVE | CVSS |
|
|
||||||
|----|--------|-------------|-----|------|
|
|
||||||
| E-01 | **Insecure Electron Configuration** | `nodeIntegration: true` + `contextIsolation: false` allows full Node.js access from renderer. | CVE-MC-001 | 9.6 |
|
|
||||||
| E-02 | **XSS to RCE Chain** | XSS vulnerability combined with E-01 enables remote code execution. | CVE-MC-003 + CVE-MC-001 | 9.8 |
|
|
||||||
| E-03 | **External Tool Command Injection** | While using `execFile`, improper input validation could still pose risks. | CVE-MC-009 | 4.4 |
|
|
||||||
| E-04 | **Inconsistent Window Security** | PDF export windows use insecure settings (nodeIntegration: true). | CVE-MC-006 | 6.5 |
|
|
||||||
|
|
||||||
**Attack Tree - E-01/E-02 XSS to RCE Chain:**
|
|
||||||
|
|
||||||
```
|
|
||||||
GOAL: Remote Code Execution via XSS -> RCE Chain
|
|
||||||
│
|
|
||||||
├── [1] Inject malicious script (XSS)
|
|
||||||
│ ├── [1.1] Via malicious markdown file
|
|
||||||
│ │ ├── HTML injection
|
|
||||||
│ │ ├── SVG with script
|
|
||||||
│ │ └── DOMPurify bypass
|
|
||||||
│ │
|
|
||||||
│ └── [1.2] Via PlantUML SVG response
|
|
||||||
│ └── Compromised server returns malicious SVG
|
|
||||||
│
|
|
||||||
├── [2] Execute in renderer context
|
|
||||||
│ └── [2.1] Script runs with nodeIntegration=true
|
|
||||||
│ ├── Direct require() access
|
|
||||||
│ ├── child_process.exec()
|
|
||||||
│ └── fs module access
|
|
||||||
│
|
|
||||||
└── [3] Achieve RCE
|
|
||||||
├── [3.1] Execute system commands
|
|
||||||
├── [3.2] Read/write arbitrary files
|
|
||||||
├── [3.3] Install persistence mechanisms
|
|
||||||
└── [3.4] Lateral movement
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 3. Attack Scenarios
|
|
||||||
|
|
||||||
### 3.1 Scenario: Malicious Markdown Document (Critical)
|
|
||||||
|
|
||||||
**Attack Chain:**
|
|
||||||
|
|
||||||
```
|
|
||||||
1. Attacker creates malicious.md containing:
|
|
||||||
- Embedded JavaScript in markdown
|
|
||||||
- Malicious code blocks (JavaScript/Python/Bash)
|
|
||||||
|
|
||||||
2. Victim opens file in MarkdownConverter
|
|
||||||
|
|
||||||
3. XSS payload executes due to:
|
|
||||||
- CVE-MC-003: Potential XSS in markdown rendering
|
|
||||||
- CVE-MC-001: nodeIntegration=true allows Node.js access
|
|
||||||
|
|
||||||
4. Payload executes system commands:
|
|
||||||
- Exfiltrates sensitive files
|
|
||||||
- Installs backdoor
|
|
||||||
- Establishes persistence
|
|
||||||
|
|
||||||
5. Impact: Complete system compromise
|
|
||||||
```
|
|
||||||
|
|
||||||
**MITRE ATT&CK Mapping:**
|
|
||||||
|
|
||||||
| Tactic | Technique | ID | Description |
|
|
||||||
|--------|-----------|-----|-------------|
|
|
||||||
| Initial Access | Phishing | T1566 | Malicious file via email |
|
|
||||||
| Execution | User Execution | T1204 | Victim opens malicious file |
|
|
||||||
| Execution | Command/Scripting | T1059 | JavaScript/Python execution |
|
|
||||||
| Persistence | Registry Run Keys | T1547 | Establish persistence |
|
|
||||||
| Collection | Data from Local System | T1005 | File exfiltration |
|
|
||||||
| Exfiltration | Exfiltration Over C2 | T1041 | Data sent to attacker |
|
|
||||||
|
|
||||||
### 3.2 Scenario: REPL Code Execution (Critical)
|
|
||||||
|
|
||||||
**Attack Chain:**
|
|
||||||
|
|
||||||
```
|
|
||||||
1. Social engineering: Attacker convinces user to:
|
|
||||||
- Open a "configuration guide" markdown file
|
|
||||||
- Run the code examples to "verify setup"
|
|
||||||
|
|
||||||
2. Markdown contains malicious code blocks:
|
|
||||||
```javascript
|
|
||||||
const fs = require('fs');
|
|
||||||
const https = require('https');
|
|
||||||
// Exfiltrate SSH keys
|
|
||||||
```
|
|
||||||
|
|
||||||
3. User clicks "Run" button on code block
|
|
||||||
|
|
||||||
4. Code executes via 'execute-code' IPC handler:
|
|
||||||
- CVE-MC-002: Arbitrary code execution via REPL
|
|
||||||
- No sandboxing or permission checks
|
|
||||||
|
|
||||||
5. Impact: Credential theft, data exfiltration
|
|
||||||
```
|
|
||||||
|
|
||||||
**MITRE ATT&CK Mapping:**
|
|
||||||
|
|
||||||
| Tactic | Technique | ID | Description |
|
|
||||||
|--------|-----------|-----|-------------|
|
|
||||||
| Initial Access | Phishing | T1566 | Social engineering |
|
|
||||||
| Execution | Command/Scripting | T1059.004 | Bash execution |
|
|
||||||
| Execution | Command/Scripting | T1059.007 | JavaScript/Node execution |
|
|
||||||
| Credential Access | Credentials from Files | T1083 | SSH key theft |
|
|
||||||
| Exfiltration | Exfiltration Over Web Service | T1567 | HTTPS exfiltration |
|
|
||||||
|
|
||||||
### 3.3 Scenario: PlantUML Data Exfiltration (Medium)
|
|
||||||
|
|
||||||
**Attack Chain:**
|
|
||||||
|
|
||||||
```
|
|
||||||
1. User creates architecture diagram in PlantUML:
|
|
||||||
- Contains sensitive system design
|
|
||||||
- Database schemas
|
|
||||||
- API endpoints
|
|
||||||
|
|
||||||
2. Renderer encodes and sends to www.plantuml.com:
|
|
||||||
- CVE-MC-007: Data sent to external server
|
|
||||||
|
|
||||||
3. Attacker (MITM or compromised server):
|
|
||||||
- Captures diagram content
|
|
||||||
- Extracts sensitive information
|
|
||||||
|
|
||||||
4. Impact: Intellectual property theft, reconnaissance
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3.4 Scenario: PDF Export Window Exploitation (Medium)
|
|
||||||
|
|
||||||
**Attack Chain:**
|
|
||||||
|
|
||||||
```
|
|
||||||
1. User exports document to PDF
|
|
||||||
|
|
||||||
2. Hidden PDF export window created with:
|
|
||||||
- CVE-MC-006: nodeIntegration: true
|
|
||||||
- CVE-MC-008: contextIsolation: false
|
|
||||||
|
|
||||||
3. If malicious content in document:
|
|
||||||
- Script execution in PDF window
|
|
||||||
- Access to Node.js APIs
|
|
||||||
|
|
||||||
4. Impact: Code execution during export process
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 4. Risk Matrix & Prioritization
|
|
||||||
|
|
||||||
### 4.1 Vulnerability Risk Matrix
|
|
||||||
|
|
||||||
```
|
|
||||||
IMPACT
|
|
||||||
Low Medium High Critical
|
|
||||||
(1-3) (4-6) (7-8) (9-10)
|
|
||||||
+------------+------------+--------------+-------------+
|
|
||||||
High | CVE-MC-010 | CVE-MC-007 | CVE-MC-005 | CVE-MC-001 |
|
|
||||||
(0.7-1.0) | 3.5 | 5.3 | 7.5 | 9.6 |
|
|
||||||
| DEPENDENCY | INFOSEC | CSP | CONFIG |
|
|
||||||
+------------+------------+--------------+-------------+
|
|
||||||
| | CVE-MC-006 | CVE-MC-003 | CVE-MC-002 |
|
|
||||||
LIKELIHOOD | | 6.5 | 8.0 | 9.3 |
|
|
||||||
(0.4-0.6) | | PDF-WIN | XSS | REPL |
|
|
||||||
+------------+------------+--------------+-------------+
|
|
||||||
Medium | | CVE-MC-008 | CVE-MC-004 | |
|
|
||||||
(0.2-0.4) | | 5.5 | 7.8 | |
|
|
||||||
| | INCONSIST | PATH-TRAV | |
|
|
||||||
+------------+------------+--------------+-------------+
|
|
||||||
Low | | | CVE-MC-009 | |
|
|
||||||
(0-0.2) | | | 4.4 | |
|
|
||||||
| | | CMD-EXEC | |
|
|
||||||
+------------+------------+--------------+-------------+
|
|
||||||
```
|
|
||||||
|
|
||||||
### 4.2 Prioritized Remediation List
|
|
||||||
|
|
||||||
| Priority | CVE | Vulnerability | CVSS | Effort | Risk Reduction |
|
|
||||||
|----------|-----|---------------|------|--------|----------------|
|
|
||||||
| P0 | CVE-MC-001 | Insecure Electron Config | 9.6 | Medium | Critical |
|
|
||||||
| P0 | CVE-MC-002 | REPL Code Execution | 9.3 | High | Critical |
|
|
||||||
| P1 | CVE-MC-003 | XSS in Markdown | 8.0 | Medium | High |
|
|
||||||
| P1 | CVE-MC-004 | Path Traversal | 7.8 | Low | High |
|
|
||||||
| P1 | CVE-MC-005 | Weak CSP | 7.5 | Medium | High |
|
|
||||||
| P2 | CVE-MC-006 | PDF Window Config | 6.5 | Low | Medium |
|
|
||||||
| P2 | CVE-MC-008 | Inconsistent Settings | 5.5 | Low | Medium |
|
|
||||||
| P2 | CVE-MC-007 | PlantUML Exfiltration | 5.3 | Medium | Medium |
|
|
||||||
| P3 | CVE-MC-009 | External Tool Execution | 4.4 | Low | Low |
|
|
||||||
| P3 | CVE-MC-010 | Dependency Versioning | 3.5 | Low | Low |
|
|
||||||
|
|
||||||
### 4.3 Risk Score Calculation
|
|
||||||
|
|
||||||
```
|
|
||||||
Overall Application Risk Score: 7.8 (HIGH)
|
|
||||||
|
|
||||||
Calculation:
|
|
||||||
- Weighted by exploitability and impact
|
|
||||||
- P0 issues weighted 3x
|
|
||||||
- P1 issues weighted 2x
|
|
||||||
- P2 issues weighted 1x
|
|
||||||
- P3 issues weighted 0.5x
|
|
||||||
|
|
||||||
Risk = (9.6*3 + 9.3*3 + 8.0*2 + 7.8*2 + 7.5*2 + 6.5 + 5.5 + 5.3 + 4.4*0.5 + 3.5*0.5) / 17
|
|
||||||
= (28.8 + 27.9 + 16.0 + 15.6 + 15.0 + 6.5 + 5.5 + 5.3 + 2.2 + 1.75) / 17
|
|
||||||
= 124.55 / 17
|
|
||||||
= 7.33 (adjusted to 7.8 with environmental factors)
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 5. Business Impact Analysis
|
|
||||||
|
|
||||||
### 5.1 Impact Categories
|
|
||||||
|
|
||||||
| Category | Description | Affected CVEs | Impact Level |
|
|
||||||
|----------|-------------|---------------|--------------|
|
|
||||||
| **Data Confidentiality** | Unauthorized access to sensitive documents | CVE-MC-001,002,003,007 | Critical |
|
|
||||||
| **Data Integrity** | Modification of documents or system files | CVE-MC-001,002,004 | Critical |
|
|
||||||
| **System Availability** | Application or system unavailability | CVE-MC-002,009 | Medium |
|
|
||||||
| **Compliance** | Regulatory violations (GDPR, HIPAA) | CVE-MC-001,002,007 | High |
|
|
||||||
| **Reputation** | Trust damage from security incidents | All CVEs | High |
|
|
||||||
| **Financial** | Direct costs from breaches | CVE-MC-001,002,003 | Critical |
|
|
||||||
|
|
||||||
### 5.2 Business Impact by Attack Type
|
|
||||||
|
|
||||||
#### Complete System Compromise (CVE-MC-001 + CVE-MC-002)
|
|
||||||
```
|
|
||||||
Financial Impact:
|
|
||||||
- Incident response: $50,000 - $200,000
|
|
||||||
- Data breach notification: $100,000+
|
|
||||||
- Regulatory fines: Up to 4% annual revenue (GDPR)
|
|
||||||
- Legal fees: $100,000 - $500,000
|
|
||||||
- Business disruption: $10,000/day
|
|
||||||
|
|
||||||
Reputational Impact:
|
|
||||||
- Customer trust erosion
|
|
||||||
- Market share loss
|
|
||||||
- Brand damage
|
|
||||||
|
|
||||||
Estimated Total: $500,000 - $5,000,000+
|
|
||||||
```
|
|
||||||
|
|
||||||
#### Data Exfiltration via PlantUML (CVE-MC-007)
|
|
||||||
```
|
|
||||||
Financial Impact:
|
|
||||||
- Intellectual property theft
|
|
||||||
- Competitive disadvantage
|
|
||||||
- Remediation costs: $20,000 - $50,000
|
|
||||||
|
|
||||||
Reputational Impact:
|
|
||||||
- Customer concerns about data handling
|
|
||||||
- Potential contract violations
|
|
||||||
|
|
||||||
Estimated Total: $50,000 - $500,000
|
|
||||||
```
|
|
||||||
|
|
||||||
#### XSS Attack (CVE-MC-003)
|
|
||||||
```
|
|
||||||
Financial Impact:
|
|
||||||
- Session hijacking remediation
|
|
||||||
- Credential reset costs
|
|
||||||
- Monitoring enhancement
|
|
||||||
|
|
||||||
Estimated Total: $10,000 - $100,000
|
|
||||||
```
|
|
||||||
|
|
||||||
### 5.3 Risk Tolerance Matrix
|
|
||||||
|
|
||||||
| Asset | Criticality | Current Risk | Tolerance | Gap |
|
|
||||||
|-------|-------------|--------------|-----------|-----|
|
|
||||||
| User Documents | High | Critical | Low | **HIGH** |
|
|
||||||
| System Integrity | Critical | Critical | Very Low | **CRITICAL** |
|
|
||||||
| User Credentials | Critical | High | Very Low | **HIGH** |
|
|
||||||
| Application Availability | Medium | Medium | Medium | Low |
|
|
||||||
| Network Communication | Medium | Medium | Low | Medium |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 6. MITRE ATT&CK Framework Mapping
|
|
||||||
|
|
||||||
### 6.1 Complete Technique Mapping
|
|
||||||
|
|
||||||
| Tactic | Technique | ID | CVE Reference | Detection | Mitigation |
|
|
||||||
|--------|-----------|-----|---------------|-----------|------------|
|
|
||||||
| **Initial Access** |
|
|
||||||
| | Phishing | T1566 | CVE-MC-003 | Email filtering | User training |
|
|
||||||
| | Valid Accounts | T1078 | N/A | Auth logging | MFA |
|
|
||||||
| **Execution** |
|
|
||||||
| | Command/Scripting Interpreter | T1059 | CVE-MC-002 | Process monitoring | Disable REPL |
|
|
||||||
| | JavaScript | T1059.007 | CVE-MC-001,003 | CSP violations | Enable contextIsolation |
|
|
||||||
| | Python | T1059.006 | CVE-MC-002 | Process monitoring | Sandboxing |
|
|
||||||
| | Bash | T1059.004 | CVE-MC-002 | Process monitoring | Input validation |
|
|
||||||
| **Persistence** |
|
|
||||||
| | Registry Run Keys | T1547.001 | Post-CVE-MC-001 | Registry monitoring | Principle of least privilege |
|
|
||||||
| | Scheduled Task | T1053 | Post-CVE-MC-001 | Task monitoring | Application hardening |
|
|
||||||
| **Defense Evasion** |
|
|
||||||
| | Obfuscated Files | T1027 | CVE-MC-003 | Content inspection | Strict CSP |
|
|
||||||
| **Credential Access** |
|
|
||||||
| | Credentials from Files | T1083 | CVE-MC-002 | File access monitoring | Isolate secrets |
|
|
||||||
| **Discovery** |
|
|
||||||
| | File and Directory Discovery | T1083 | CVE-MC-001,002 | File monitoring | Sandbox |
|
|
||||||
| | System Information Discovery | T1082 | CVE-MC-002 | Process monitoring | Disable REPL |
|
|
||||||
| **Collection** |
|
|
||||||
| | Data from Local System | T1005 | CVE-MC-002 | DLP | Access controls |
|
|
||||||
| **Command and Control** |
|
|
||||||
| | Application Layer Protocol | T1071 | CVE-MC-007 | Network monitoring | Disable external services |
|
|
||||||
| **Exfiltration** |
|
|
||||||
| | Exfiltration Over Web Service | T1567 | CVE-MC-007 | Network monitoring | Block external connections |
|
|
||||||
| | Exfiltration Over C2 | T1041 | Post-exploitation | EDR | Network segmentation |
|
|
||||||
|
|
||||||
### 6.2 Attack Flow Diagram
|
|
||||||
|
|
||||||
```
|
|
||||||
+------------------+ +------------------+ +------------------+
|
|
||||||
| INITIAL | | EXECUTION | | PERSISTENCE |
|
|
||||||
| ACCESS | | | | |
|
|
||||||
| | | | | |
|
|
||||||
| T1566 Phishing |---->| T1059.007 JS |---->| T1547.001 Reg |
|
|
||||||
| T1204 User Exec | | T1059.004 Bash | | T1053 Sched Task |
|
|
||||||
| | | T1059.006 Python | | |
|
|
||||||
+------------------+ +------------------+ +------------------+
|
|
||||||
|
|
|
||||||
v
|
|
||||||
+------------------+ +------------------+ +------------------+
|
|
||||||
| COLLECTION |<----| DISCOVERY | | C2 |
|
|
||||||
| | | | | |
|
|
||||||
| T1005 Local Data | | T1083 File Disc | | T1071 HTTPS |
|
|
||||||
| T1083 Creds File | | T1082 Sys Info | | |
|
|
||||||
+------------------+ +------------------+ +------------------+
|
|
||||||
|
|
|
||||||
v
|
|
||||||
+------------------+
|
|
||||||
| EXFILTRATION |
|
|
||||||
| |
|
|
||||||
| T1567 Web Service|
|
|
||||||
| T1041 Over C2 |
|
|
||||||
+------------------+
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 7. Security Requirements & Mitigations
|
|
||||||
|
|
||||||
### 7.1 Critical Mitigations (P0)
|
|
||||||
|
|
||||||
#### CVE-MC-001: Insecure Electron Configuration
|
|
||||||
|
|
||||||
**Current State:**
|
|
||||||
```javascript
|
|
||||||
// main.js:328-331
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: true,
|
|
||||||
contextIsolation: false,
|
|
||||||
spellcheck: true
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Required Changes:**
|
|
||||||
```javascript
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: false, // REQUIRED
|
|
||||||
contextIsolation: true, // REQUIRED
|
|
||||||
sandbox: true, // RECOMMENDED
|
|
||||||
spellcheck: true
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Migration Path:**
|
|
||||||
1. Update preload.js to expose all required APIs
|
|
||||||
2. Update renderer.js to use exposed APIs instead of require()
|
|
||||||
3. Test all functionality
|
|
||||||
4. Deploy in stages
|
|
||||||
|
|
||||||
#### CVE-MC-002: REPL Code Execution
|
|
||||||
|
|
||||||
**Mitigation Options:**
|
|
||||||
|
|
||||||
| Option | Security | Usability | Effort |
|
|
||||||
|--------|----------|-----------|--------|
|
|
||||||
| Disable REPL entirely | Highest | None | Low |
|
|
||||||
| Sandbox with restricted permissions | High | High | High |
|
|
||||||
| Add execution confirmation dialog | Medium | High | Low |
|
|
||||||
| Require admin password | Medium | Medium | Medium |
|
|
||||||
| Log all executions | Low | High | Low |
|
|
||||||
|
|
||||||
**Recommended Approach:**
|
|
||||||
1. Add user confirmation dialog with code preview
|
|
||||||
2. Implement execution sandboxing (Docker/container)
|
|
||||||
3. Add audit logging
|
|
||||||
4. Restrict available modules
|
|
||||||
|
|
||||||
### 7.2 High Priority Mitigations (P1)
|
|
||||||
|
|
||||||
#### CVE-MC-003: XSS in Markdown
|
|
||||||
|
|
||||||
**Current Mitigations:**
|
|
||||||
- DOMPurify sanitization
|
|
||||||
|
|
||||||
**Additional Required:**
|
|
||||||
```javascript
|
|
||||||
// Enhanced DOMPurify configuration
|
|
||||||
const purifyConfig = {
|
|
||||||
ALLOWED_TAGS: [...],
|
|
||||||
ALLOWED_ATTR: [...],
|
|
||||||
FORBID_TAGS: ['script', 'iframe', 'object', 'embed'],
|
|
||||||
FORBID_ATTR: ['onerror', 'onload', 'onclick'],
|
|
||||||
ADD_ATTR: ['target'],
|
|
||||||
FORCE_BODY: true
|
|
||||||
};
|
|
||||||
```
|
|
||||||
|
|
||||||
#### CVE-MC-005: Weak CSP
|
|
||||||
|
|
||||||
**Current CSP:**
|
|
||||||
```
|
|
||||||
default-src 'self';
|
|
||||||
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net;
|
|
||||||
style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com;
|
|
||||||
img-src 'self' data: blob: file:;
|
|
||||||
font-src 'self' data:;
|
|
||||||
connect-src 'self' https://www.plantuml.com;
|
|
||||||
```
|
|
||||||
|
|
||||||
**Recommended CSP:**
|
|
||||||
```
|
|
||||||
default-src 'self';
|
|
||||||
script-src 'self';
|
|
||||||
style-src 'self';
|
|
||||||
img-src 'self' data:;
|
|
||||||
font-src 'self';
|
|
||||||
connect-src 'self';
|
|
||||||
frame-src 'none';
|
|
||||||
object-src 'none';
|
|
||||||
base-uri 'self';
|
|
||||||
form-action 'self';
|
|
||||||
```
|
|
||||||
|
|
||||||
**Note:** This requires:
|
|
||||||
- Bundling all dependencies locally
|
|
||||||
- Removing PlantUML server dependency (use local rendering)
|
|
||||||
- Removing unsafe-inline and unsafe-eval
|
|
||||||
|
|
||||||
### 7.3 Medium Priority Mitigations (P2)
|
|
||||||
|
|
||||||
#### CVE-MC-006/008: Window Security Consistency
|
|
||||||
|
|
||||||
**Affected Windows:**
|
|
||||||
- PDF export window (main.js:2579-2585)
|
|
||||||
- Hidden conversion window (main.js:3263-3268)
|
|
||||||
|
|
||||||
**Fix:**
|
|
||||||
```javascript
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: false,
|
|
||||||
contextIsolation: true,
|
|
||||||
sandbox: true,
|
|
||||||
preload: path.join(__dirname, 'preload-pdf.js')
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
#### CVE-MC-007: PlantUML Data Exfiltration
|
|
||||||
|
|
||||||
**Options:**
|
|
||||||
1. Use local PlantUML JAR file
|
|
||||||
2. Use PlantUML npm package
|
|
||||||
3. Add warning before sending to external server
|
|
||||||
4. Allow configuration of PlantUML server URL
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 8. Attack Tree Summary
|
|
||||||
|
|
||||||
### 8.1 Primary Attack Tree - Full System Compromise
|
|
||||||
|
|
||||||
```
|
|
||||||
GOAL: Full System Compromise via MarkdownConverter
|
|
||||||
│
|
|
||||||
├── [BRANCH A] Exploit CVE-MC-001 (nodeIntegration)
|
|
||||||
│ │
|
|
||||||
│ ├── [A.1] XSS via malicious markdown
|
|
||||||
│ │ ├── [A.1.1] HTML injection
|
|
||||||
│ │ ├── [A.1.2] SVG script injection
|
|
||||||
│ │ └── [A.1.3] DOMPurify bypass
|
|
||||||
│ │
|
|
||||||
│ ├── [A.2] Compromised CDN script
|
|
||||||
│ │ ├── [A.2.1] jsdelivr compromise
|
|
||||||
│ │ └── [A.2.2] cdnjs compromise
|
|
||||||
│ │
|
|
||||||
│ └── [A.3] PlantUML SVG injection
|
|
||||||
│ └── [A.3.1] Compromised plantuml.com
|
|
||||||
│
|
|
||||||
├── [BRANCH B] Exploit CVE-MC-002 (REPL)
|
|
||||||
│ │
|
|
||||||
│ ├── [B.1] Social engineering
|
|
||||||
│ │ ├── [B.1.1] Malicious tutorial document
|
|
||||||
│ │ └── [B.1.2] Phishing with "config file"
|
|
||||||
│ │
|
|
||||||
│ └── [B.2] Code execution
|
|
||||||
│ ├── [B.2.1] JavaScript (Node.js)
|
|
||||||
│ ├── [B.2.2] Python
|
|
||||||
│ └── [B.2.3] Bash/Shell
|
|
||||||
│
|
|
||||||
└── [BRANCH C] Chain Exploits
|
|
||||||
│
|
|
||||||
├── [C.1] XSS -> RCE (CVE-MC-003 + CVE-MC-001)
|
|
||||||
│ └── Impact: CVSS 9.8
|
|
||||||
│
|
|
||||||
├── [C.2] Path Traversal -> Privilege Escalation
|
|
||||||
│ └── Impact: CVSS 8.5
|
|
||||||
│
|
|
||||||
└── [C.3] PlantUML -> XSS -> RCE
|
|
||||||
└── Impact: CVSS 9.1
|
|
||||||
```
|
|
||||||
|
|
||||||
### 8.2 Attack Success Probability
|
|
||||||
|
|
||||||
| Attack Path | Complexity | Privileges Required | User Interaction | Probability |
|
|
||||||
|-------------|------------|---------------------|------------------|-------------|
|
|
||||||
| A.1 XSS->RCE | Low | None | Required | 75% |
|
|
||||||
| A.2 CDN Compromise | High | None | None | 15% |
|
|
||||||
| A.3 PlantUML->RCE | Medium | None | Required | 40% |
|
|
||||||
| B.1 REPL Social Eng | Low | None | Required | 60% |
|
|
||||||
| C.1 Combined XSS-RCE | Low | None | Required | 70% |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 9. Recommendations
|
|
||||||
|
|
||||||
### 9.1 Immediate Actions (0-30 days)
|
|
||||||
|
|
||||||
1. **CVE-MC-001**: Enable `contextIsolation: true` and `nodeIntegration: false` for main window
|
|
||||||
2. **CVE-MC-002**: Add confirmation dialog before REPL execution with code preview
|
|
||||||
3. **CVE-MC-005**: Remove `unsafe-inline` and `unsafe-eval` from CSP
|
|
||||||
4. **CVE-MC-006**: Fix PDF export window security settings
|
|
||||||
|
|
||||||
### 9.2 Short-term Actions (30-90 days)
|
|
||||||
|
|
||||||
1. **CVE-MC-002**: Implement sandboxed code execution environment
|
|
||||||
2. **CVE-MC-003**: Enhance DOMPurify configuration, add CSP reporting
|
|
||||||
3. **CVE-MC-007**: Implement local PlantUML rendering option
|
|
||||||
4. Add comprehensive security audit logging
|
|
||||||
|
|
||||||
### 9.3 Long-term Actions (90+ days)
|
|
||||||
|
|
||||||
1. **CVE-MC-010**: Implement dependency pinning and SCA scanning
|
|
||||||
2. Security awareness training for users
|
|
||||||
3. Implement secure development lifecycle (SDL)
|
|
||||||
4. Regular penetration testing schedule
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 10. Appendix
|
|
||||||
|
|
||||||
### A. Security Configuration Audit
|
|
||||||
|
|
||||||
**Main Window (main.js:323-334)**
|
|
||||||
```javascript
|
|
||||||
// CURRENT (INSECURE)
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: true, // CRITICAL: Allows require() in renderer
|
|
||||||
contextIsolation: false, // CRITICAL: No isolation between contexts
|
|
||||||
spellcheck: true
|
|
||||||
}
|
|
||||||
|
|
||||||
// RECOMMENDED
|
|
||||||
webPreferences: {
|
|
||||||
nodeIntegration: false,
|
|
||||||
contextIsolation: true,
|
|
||||||
sandbox: true,
|
|
||||||
spellcheck: true,
|
|
||||||
webSecurity: true,
|
|
||||||
allowRunningInsecureContent: false
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**CSP Configuration (index.html:5)**
|
|
||||||
```html
|
|
||||||
<!-- CURRENT (WEAK) -->
|
|
||||||
<meta http-equiv="Content-Security-Policy"
|
|
||||||
content="default-src 'self';
|
|
||||||
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net;
|
|
||||||
...">
|
|
||||||
|
|
||||||
<!-- RECOMMENDED -->
|
|
||||||
<meta http-equiv="Content-Security-Policy"
|
|
||||||
content="default-src 'self';
|
|
||||||
script-src 'self';
|
|
||||||
style-src 'self';
|
|
||||||
img-src 'self' data:;
|
|
||||||
connect-src 'self';
|
|
||||||
frame-src 'none';
|
|
||||||
object-src 'none'">
|
|
||||||
```
|
|
||||||
|
|
||||||
### B. IPC Channel Security Review
|
|
||||||
|
|
||||||
**High-Risk Channels:**
|
|
||||||
| Channel | Risk | Recommendation |
|
|
||||||
|---------|------|----------------|
|
|
||||||
| `execute-code` | Critical | Remove or sandbox |
|
|
||||||
| `save-file` | High | Add path validation |
|
|
||||||
| `batch-convert` | Medium | Rate limiting exists |
|
|
||||||
| `git-*` | Medium | Audit git operations |
|
|
||||||
|
|
||||||
### C. Dependency Security
|
|
||||||
|
|
||||||
**Critical Dependencies:**
|
|
||||||
| Package | Version | Known CVEs | Recommendation |
|
|
||||||
|---------|---------|------------|----------------|
|
|
||||||
| electron | 37.4.0 | None | Pin version |
|
|
||||||
| dompurify | 3.3.1 | None | Keep updated |
|
|
||||||
| marked | 17.0.3 | None | Keep updated |
|
|
||||||
| mermaid | 11.12.3 | None | Review CSP impact |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Document Control
|
|
||||||
|
|
||||||
| Version | Date | Author | Changes |
|
|
||||||
|---------|------|--------|---------|
|
|
||||||
| 1.0 | 2026-03-15 | Security Team | Initial threat model |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
*This threat model should be reviewed and updated after any significant architectural changes or at minimum annually.*
|
|
||||||
@@ -1,502 +0,0 @@
|
|||||||
# MarkdownConverter v5.0 - React + Tauri + PWA Architecture Design
|
|
||||||
|
|
||||||
**Date:** 2026-03-15
|
|
||||||
**Status:** Approved
|
|
||||||
**Target Platforms:** Desktop (Tauri), Web (PWA), Mobile (Future)
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Executive Summary
|
|
||||||
|
|
||||||
This document outlines the architecture for MarkdownConverter v5.0, a complete rewrite using React, Tauri, and PWA technologies. The new architecture enables:
|
|
||||||
|
|
||||||
- **Multi-platform support**: Single codebase for desktop, web, and future mobile
|
|
||||||
- **Improved security**: Eliminates critical Electron vulnerabilities by design
|
|
||||||
- **Reduced bundle size**: ~5-10MB desktop, ~137KB web (vs 150MB+ Electron)
|
|
||||||
- **Better maintainability**: Component-based architecture with TypeScript
|
|
||||||
- **Offline support**: Full PWA capabilities with IndexedDB storage
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 1. Project Structure
|
|
||||||
|
|
||||||
```
|
|
||||||
markdown-converter-v5/
|
|
||||||
├── src/
|
|
||||||
│ ├── components/
|
|
||||||
│ │ ├── ui/ # Shadcn/ui components (button, dialog, etc.)
|
|
||||||
│ │ ├── editor/ # CodeMirror wrapper, toolbar
|
|
||||||
│ │ ├── preview/ # Markdown preview, theme rendering
|
|
||||||
│ │ ├── sidebar/ # Explorer, Git, Snippets, Templates panels
|
|
||||||
│ │ ├── tabs/ # Tab bar, tab management
|
|
||||||
│ │ ├── dialogs/ # Export, batch converter, settings dialogs
|
|
||||||
│ │ └── layout/ # Main layout, splitter panes
|
|
||||||
│ │
|
|
||||||
│ ├── hooks/
|
|
||||||
│ │ ├── useEditor.ts # Editor state & actions
|
|
||||||
│ │ ├── useTheme.ts # Theme management
|
|
||||||
│ │ ├── useFileSystem.ts # File operations (uses adapter)
|
|
||||||
│ │ ├── useConversion.ts # Conversion operations
|
|
||||||
│ │ └── useKeyboardShortcuts.ts
|
|
||||||
│ │
|
|
||||||
│ ├── stores/
|
|
||||||
│ │ ├── editorStore.ts # Content, tabs, cursor position
|
|
||||||
│ │ ├── settingsStore.ts # User preferences
|
|
||||||
│ │ ├── themeStore.ts # Active theme, custom themes
|
|
||||||
│ │ └── sidebarStore.ts # Sidebar state, active panel
|
|
||||||
│ │
|
|
||||||
│ ├── adapters/
|
|
||||||
│ │ ├── types.ts # Interface definitions
|
|
||||||
│ │ ├── tauri/
|
|
||||||
│ │ │ ├── index.ts # Tauri adapter implementation
|
|
||||||
│ │ │ ├── fs.ts # File system via Tauri
|
|
||||||
│ │ │ ├── convert.ts # Pandoc, FFmpeg via Tauri
|
|
||||||
│ │ │ └── system.ts # System info, paths
|
|
||||||
│ │ ├── web/
|
|
||||||
│ │ │ ├── index.ts # Web adapter implementation
|
|
||||||
│ │ │ ├── fs.ts # IndexedDB + File System Access API
|
|
||||||
│ │ │ ├── convert.ts # WASM converters, cloud fallback
|
|
||||||
│ │ │ └── system.ts # Browser capabilities
|
|
||||||
│ │ └── index.ts # Platform detection & export
|
|
||||||
│ │
|
|
||||||
│ ├── wasm/
|
|
||||||
│ │ ├── pdf.wasm # PDF generation
|
|
||||||
│ │ ├── marked.wasm # Markdown parsing (if available)
|
|
||||||
│ │ └── loader.ts # WASM module loader
|
|
||||||
│ │
|
|
||||||
│ ├── lib/
|
|
||||||
│ │ ├── markdown.ts # Marked + plugins config
|
|
||||||
│ │ ├── syntax.ts # Highlight.js config
|
|
||||||
│ │ ├── mermaid.ts # Diagram rendering
|
|
||||||
│ │ └── utils.ts # Helper functions
|
|
||||||
│ │
|
|
||||||
│ ├── styles/
|
|
||||||
│ │ ├── globals.css # Tailwind imports, CSS variables
|
|
||||||
│ │ ├── themes/ # Theme CSS files
|
|
||||||
│ │ └── editor.css # CodeMirror styling
|
|
||||||
│ │
|
|
||||||
│ ├── types/
|
|
||||||
│ │ ├── editor.ts # Editor-related types
|
|
||||||
│ │ ├── conversion.ts # Conversion options types
|
|
||||||
│ │ └── platform.ts # Platform capability types
|
|
||||||
│ │
|
|
||||||
│ ├── App.tsx # Root component
|
|
||||||
│ ├── main.tsx # Entry point
|
|
||||||
│ └── vite-env.d.ts
|
|
||||||
│
|
|
||||||
├── src-tauri/ # Tauri backend (Rust)
|
|
||||||
│ ├── src/
|
|
||||||
│ │ ├── main.rs # Tauri entry
|
|
||||||
│ │ ├── commands/ # IPC command handlers
|
|
||||||
│ │ │ ├── fs.rs # File system operations
|
|
||||||
│ │ │ ├── convert.rs # Pandoc, FFmpeg wrappers
|
|
||||||
│ │ │ └── system.rs # System utilities
|
|
||||||
│ │ └── lib.rs
|
|
||||||
│ ├── Cargo.toml
|
|
||||||
│ └── tauri.conf.json
|
|
||||||
│
|
|
||||||
├── public/
|
|
||||||
│ ├── manifest.json # PWA manifest
|
|
||||||
│ ├── sw.js # Service worker
|
|
||||||
│ ├── fonts/ # JetBrains Mono, Inter
|
|
||||||
│ └── icons/ # App icons
|
|
||||||
│
|
|
||||||
├── package.json
|
|
||||||
├── vite.config.ts
|
|
||||||
├── tailwind.config.ts
|
|
||||||
├── tsconfig.json
|
|
||||||
└── components.json # Shadcn/ui config
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 2. Component Architecture
|
|
||||||
|
|
||||||
```tsx
|
|
||||||
// Component hierarchy
|
|
||||||
|
|
||||||
<App> // Root layout, theme provider
|
|
||||||
├── <Layout>
|
|
||||||
│ ├── <TitleBar /> // Draggable title bar (desktop only)
|
|
||||||
│ ├── <TabBar /> // Document tabs
|
|
||||||
│ ├── <MainContent>
|
|
||||||
│ │ ├── <Sidebar> // Collapsible sidebar
|
|
||||||
│ │ │ ├── <ExplorerPanel />
|
|
||||||
│ │ │ ├── <GitPanel />
|
|
||||||
│ │ │ ├── <SnippetsPanel />
|
|
||||||
│ │ │ └── <TemplatesPanel />
|
|
||||||
│ │ ├── <EditorPane> // Split view container
|
|
||||||
│ │ │ ├── <CodeMirrorEditor />
|
|
||||||
│ │ │ └── <PreviewPane>
|
|
||||||
│ │ │ └── <MarkdownPreview />
|
|
||||||
│ │ └── <BottomPanel> // REPL, terminal, output
|
|
||||||
│ └── <StatusBar /> // Line count, encoding, status
|
|
||||||
│
|
|
||||||
└── <Dialogs> // Portal-based dialogs
|
|
||||||
├── <ExportDialog />
|
|
||||||
├── <BatchConvertDialog />
|
|
||||||
├── <SettingsDialog />
|
|
||||||
├── <ThemeDialog />
|
|
||||||
└── <PdfEditorDialog />
|
|
||||||
```
|
|
||||||
|
|
||||||
**Key Components:**
|
|
||||||
|
|
||||||
| Component | Props | Responsibility |
|
|
||||||
|-----------|-------|----------------|
|
|
||||||
| `CodeMirrorEditor` | `content`, `onChange`, `theme` | Wrap CodeMirror 6 with React |
|
|
||||||
| `MarkdownPreview` | `content`, `theme` | Render sanitized HTML with themes |
|
|
||||||
| `TabBar` | `tabs`, `activeId`, `onSelect`, `onClose` | Manage document tabs |
|
|
||||||
| `Sidebar` | `activePanel`, `collapsed` | Collapsible sidebar container |
|
|
||||||
| `ExportDialog` | `format`, `options` | Export configuration UI |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 3. State Management (Zustand)
|
|
||||||
|
|
||||||
### Editor Store
|
|
||||||
|
|
||||||
```typescript
|
|
||||||
interface Tab {
|
|
||||||
id: string;
|
|
||||||
title: string;
|
|
||||||
content: string;
|
|
||||||
filePath?: string;
|
|
||||||
isDirty: boolean;
|
|
||||||
cursorPosition: { line: number; column: number };
|
|
||||||
}
|
|
||||||
|
|
||||||
interface EditorState {
|
|
||||||
tabs: Tab[];
|
|
||||||
activeTabId: string | null;
|
|
||||||
|
|
||||||
// Actions
|
|
||||||
createTab: (title?: string) => string;
|
|
||||||
closeTab: (id: string) => void;
|
|
||||||
setActiveTab: (id: string) => void;
|
|
||||||
updateContent: (id: string, content: string) => void;
|
|
||||||
updateCursorPosition: (id: string, pos: { line: number; column: number }) => void;
|
|
||||||
markSaved: (id: string, filePath?: string) => void;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Settings Store
|
|
||||||
|
|
||||||
```typescript
|
|
||||||
interface SettingsState {
|
|
||||||
theme: string;
|
|
||||||
fontSize: number;
|
|
||||||
fontFamily: string;
|
|
||||||
previewMode: 'split' | 'editor' | 'preview';
|
|
||||||
showLineNumbers: boolean;
|
|
||||||
wordWrap: boolean;
|
|
||||||
autoSave: boolean;
|
|
||||||
autoSaveInterval: number;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Stores Summary:**
|
|
||||||
|
|
||||||
| Store | State | Persisted |
|
|
||||||
|-------|-------|-----------|
|
|
||||||
| `editorStore` | Tabs, content, cursor | Tab metadata only |
|
|
||||||
| `settingsStore` | User preferences | Yes |
|
|
||||||
| `themeStore` | Active theme, custom themes | Yes |
|
|
||||||
| `sidebarStore` | Panel state, width | Yes |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 4. Platform Adapters
|
|
||||||
|
|
||||||
### Adapter Interface
|
|
||||||
|
|
||||||
```typescript
|
|
||||||
export interface PlatformAdapter {
|
|
||||||
name: 'tauri' | 'web';
|
|
||||||
|
|
||||||
// File System
|
|
||||||
fs: {
|
|
||||||
readFile: (path: string) => Promise<string>;
|
|
||||||
writeFile: (path: string, content: string) => Promise<void>;
|
|
||||||
deleteFile: (path: string) => Promise<void>;
|
|
||||||
listDirectory: (path: string) => Promise<FileInfo[]>;
|
|
||||||
exists: (path: string) => Promise<boolean>;
|
|
||||||
watchDirectory?: (path: string, callback: WatchCallback) => () => void;
|
|
||||||
};
|
|
||||||
|
|
||||||
// Conversion
|
|
||||||
convert: {
|
|
||||||
toPdf: (content: string, options: PdfOptions) => Promise<Blob>;
|
|
||||||
toDocx: (content: string, options: DocxOptions) => Promise<Blob>;
|
|
||||||
toHtml: (content: string, options: HtmlOptions) => Promise<string>;
|
|
||||||
batchConvert: (files: string[], format: string) => Promise<ConversionResult[]>;
|
|
||||||
};
|
|
||||||
|
|
||||||
// Capabilities
|
|
||||||
capabilities: {
|
|
||||||
hasPandoc: boolean;
|
|
||||||
hasFfmpeg: boolean;
|
|
||||||
hasLibreOffice: boolean;
|
|
||||||
hasDirectFs: boolean;
|
|
||||||
hasSystemNotifications: boolean;
|
|
||||||
};
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Platform Detection
|
|
||||||
|
|
||||||
```typescript
|
|
||||||
// Auto-detect platform at startup
|
|
||||||
const isTauri = typeof window !== 'undefined' &&
|
|
||||||
'__TAURI__' in window;
|
|
||||||
|
|
||||||
export const adapter: PlatformAdapter = isTauri
|
|
||||||
? tauriAdapter
|
|
||||||
: webAdapter;
|
|
||||||
```
|
|
||||||
|
|
||||||
### Capability Differences
|
|
||||||
|
|
||||||
| Feature | Tauri (Desktop) | Web (PWA) |
|
|
||||||
|---------|-----------------|-----------|
|
|
||||||
| File System | Direct access | IndexedDB + File System Access API |
|
|
||||||
| PDF Export | Pandoc (native) | WASM converter |
|
|
||||||
| DOCX Export | Pandoc (native) | Limited/not available |
|
|
||||||
| Media Conversion | FFmpeg (native) | Cloud API or limited |
|
|
||||||
| File Watching | Native events | Not available |
|
|
||||||
| Offline | Always | Service Worker |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 5. Build Configuration
|
|
||||||
|
|
||||||
### Vite Configuration
|
|
||||||
|
|
||||||
- Target: ESNext
|
|
||||||
- Minifier: esbuild
|
|
||||||
- Code splitting by vendor chunks
|
|
||||||
- Source maps enabled
|
|
||||||
|
|
||||||
### Tailwind Configuration
|
|
||||||
|
|
||||||
- Dark mode: `class` strategy
|
|
||||||
- Custom colors using CSS variables
|
|
||||||
- Custom font families (JetBrains Mono, Inter)
|
|
||||||
- Tailwindcss-animate plugin
|
|
||||||
|
|
||||||
### TypeScript Configuration
|
|
||||||
|
|
||||||
- Target: ES2022
|
|
||||||
- Strict mode enabled
|
|
||||||
- All strict checks enabled
|
|
||||||
- Path aliases (`@/*`)
|
|
||||||
|
|
||||||
### Bundle Sizes (Estimated)
|
|
||||||
|
|
||||||
| Chunk | Size (gzipped) |
|
|
||||||
|-------|----------------|
|
|
||||||
| `vendor-react` | ~12KB |
|
|
||||||
| `vendor-editor` | ~45KB |
|
|
||||||
| `vendor-markdown` | ~35KB |
|
|
||||||
| `vendor-ui` | ~15KB |
|
|
||||||
| `app` (your code) | ~30KB |
|
|
||||||
| **Total PWA** | **~137KB** |
|
|
||||||
| Tauri desktop | ~5-10MB (with WebView) |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 6. Tauri Backend (Rust)
|
|
||||||
|
|
||||||
### IPC Commands
|
|
||||||
|
|
||||||
**File System:**
|
|
||||||
- `read_file` - Read file content
|
|
||||||
- `write_file` - Write file content
|
|
||||||
- `delete_file` - Delete file
|
|
||||||
- `list_directory` - List directory contents
|
|
||||||
- `path_exists` - Check path existence
|
|
||||||
- `watch_directory` - Watch for file changes
|
|
||||||
|
|
||||||
**Conversion:**
|
|
||||||
- `to_pdf` - Convert to PDF via Pandoc
|
|
||||||
- `to_docx` - Convert to DOCX via Pandoc
|
|
||||||
- `to_html` - Convert to HTML via Pandoc
|
|
||||||
- `batch_convert` - Batch conversion
|
|
||||||
|
|
||||||
**System:**
|
|
||||||
- `check_dependencies` - Check for Pandoc, FFmpeg, LibreOffice
|
|
||||||
- `get_config_dir` - Get config directory path
|
|
||||||
|
|
||||||
### Security Comparison
|
|
||||||
|
|
||||||
| Aspect | Electron (Current) | Tauri |
|
|
||||||
|--------|-------------------|-------|
|
|
||||||
| `nodeIntegration` | `true` (CVE) | Not possible |
|
|
||||||
| `contextIsolation` | `false` (CVE) | Always enforced |
|
|
||||||
| Bundle size | ~150MB | ~5-10MB |
|
|
||||||
| Memory usage | Higher | Lower |
|
|
||||||
| IPC security | Manual whitelist | Compile-time verified |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 7. PWA Configuration
|
|
||||||
|
|
||||||
### Web App Manifest
|
|
||||||
|
|
||||||
- Name: Markdown Converter
|
|
||||||
- Display: Standalone
|
|
||||||
- Theme color: #5661b3
|
|
||||||
- File handlers for .md, .markdown, .txt
|
|
||||||
- Share target for receiving shared content
|
|
||||||
|
|
||||||
### Service Worker
|
|
||||||
|
|
||||||
- Cache-first for static assets
|
|
||||||
- Network-first for API calls
|
|
||||||
- Stale-while-revalidate for dynamic content
|
|
||||||
- Automatic update detection
|
|
||||||
|
|
||||||
### IndexedDB Storage
|
|
||||||
|
|
||||||
**Stores:**
|
|
||||||
- `files` - Offline file storage
|
|
||||||
- `settings` - User preferences
|
|
||||||
- `templates` - Custom templates
|
|
||||||
|
|
||||||
### PWA Features
|
|
||||||
|
|
||||||
| Feature | Implementation |
|
|
||||||
|---------|---------------|
|
|
||||||
| Offline support | Service Worker + IndexedDB |
|
|
||||||
| Install prompt | Web App Manifest |
|
|
||||||
| File handling | File System Access API (Chrome) |
|
|
||||||
| Share target | Share Target API |
|
|
||||||
| Background sync | Background Sync API |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 8. Migration Plan
|
|
||||||
|
|
||||||
### Timeline: 8 Weeks
|
|
||||||
|
|
||||||
**Phase 1: Foundation (Week 1-2)**
|
|
||||||
- Initialize new repo
|
|
||||||
- Setup Vite + React + TypeScript
|
|
||||||
- Configure Tailwind + Shadcn/ui
|
|
||||||
- Setup Zustand stores
|
|
||||||
- Create platform adapter interfaces
|
|
||||||
- Setup Tauri project structure
|
|
||||||
|
|
||||||
**Phase 2: Core Editor (Week 3-4)**
|
|
||||||
- CodeMirrorEditor component
|
|
||||||
- MarkdownPreview component
|
|
||||||
- SplitPane layout
|
|
||||||
- Theme system
|
|
||||||
- Tab management
|
|
||||||
- Keyboard shortcuts
|
|
||||||
|
|
||||||
**Phase 3: Sidebar & Panels (Week 5)**
|
|
||||||
- Sidebar container
|
|
||||||
- ExplorerPanel
|
|
||||||
- GitPanel
|
|
||||||
- SnippetsPanel
|
|
||||||
- TemplatesPanel
|
|
||||||
- Bottom panel
|
|
||||||
|
|
||||||
**Phase 4: Platform Adapters (Week 6)**
|
|
||||||
- Web adapter implementation
|
|
||||||
- Tauri adapter implementation
|
|
||||||
- File system operations
|
|
||||||
- PDF conversion
|
|
||||||
- Capability detection
|
|
||||||
|
|
||||||
**Phase 5: Export & Conversion (Week 7)**
|
|
||||||
- ExportDialog
|
|
||||||
- BatchConvertDialog
|
|
||||||
- UniversalConverterDialog
|
|
||||||
- ImageConverterDialog
|
|
||||||
- AudioConverterDialog
|
|
||||||
- VideoConverterDialog
|
|
||||||
- PDF Editor Dialog
|
|
||||||
|
|
||||||
**Phase 6: PWA & Polish (Week 8)**
|
|
||||||
- Service Worker setup
|
|
||||||
- Web App Manifest
|
|
||||||
- IndexedDB storage
|
|
||||||
- Offline mode indicator
|
|
||||||
- Settings persistence
|
|
||||||
- Accessibility audit
|
|
||||||
- Performance optimization
|
|
||||||
|
|
||||||
### Parallel Development Strategy
|
|
||||||
|
|
||||||
```
|
|
||||||
Current Electron App (v4.x) New React+Tauri App (v5.0)
|
|
||||||
│ │
|
|
||||||
│ Bug fixes only │ Active development
|
|
||||||
│ Security patches │ Feature migration
|
|
||||||
▼ ▼
|
|
||||||
Stable release ────────────> Beta release
|
|
||||||
(maintained) (new features)
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 9. Design Decisions Summary
|
|
||||||
|
|
||||||
| Decision | Choice | Rationale |
|
|
||||||
|----------|--------|-----------|
|
|
||||||
| Code Structure | Single repo with platform adapters | Lightest weight, clean separation |
|
|
||||||
| State Management | Zustand | Minimal (~1KB), simple API |
|
|
||||||
| UI Library | Shadcn/ui + Tailwind | Copy-paste ownership, excellent DX |
|
|
||||||
| Build Tool | Vite | Industry standard, fast HMR |
|
|
||||||
| TypeScript | Strict mode | Maximum type safety |
|
|
||||||
| Desktop Features | Hybrid (WASM core, desktop advanced) | Best of both worlds |
|
|
||||||
| Migration | Parallel development | Zero disruption to stable release |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 10. Success Criteria
|
|
||||||
|
|
||||||
- [ ] All core editor features functional on both Tauri and PWA
|
|
||||||
- [ ] Bundle size under 150KB for PWA
|
|
||||||
- [ ] All 13 themes migrated and working
|
|
||||||
- [ ] Export to PDF works on both platforms
|
|
||||||
- [ ] Offline mode fully functional in PWA
|
|
||||||
- [ ] WCAG 2.1 AA accessibility compliance
|
|
||||||
- [ ] TypeScript strict mode with no `any` types
|
|
||||||
- [ ] All IPC channels have TypeScript types
|
|
||||||
- [ ] Security audit passes with no critical issues
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Appendix: Dependencies
|
|
||||||
|
|
||||||
### Production Dependencies
|
|
||||||
|
|
||||||
- `react` - UI library
|
|
||||||
- `react-dom` - React DOM renderer
|
|
||||||
- `zustand` - State management
|
|
||||||
- `@radix-ui/react-*` - Headless UI primitives
|
|
||||||
- `@codemirror/*` - Code editor
|
|
||||||
- `marked` - Markdown parser
|
|
||||||
- `highlight.js` - Syntax highlighting
|
|
||||||
- `mermaid` - Diagram rendering
|
|
||||||
- `dompurify` - HTML sanitization
|
|
||||||
- `class-variance-authority` - Component variants
|
|
||||||
- `clsx` + `tailwind-merge` - Class utilities
|
|
||||||
- `lucide-react` - Icons
|
|
||||||
|
|
||||||
### Development Dependencies
|
|
||||||
|
|
||||||
- `@tauri-apps/cli` - Tauri CLI
|
|
||||||
- `typescript` - TypeScript compiler
|
|
||||||
- `vite` - Build tool
|
|
||||||
- `tailwindcss` - CSS framework
|
|
||||||
- `eslint` - Linting
|
|
||||||
- `prettier` - Formatting
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
*Document generated: 2026-03-15*
|
|
||||||
*Next step: Invoke writing-plans skill to create detailed implementation plan*
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,202 +0,0 @@
|
|||||||
# Modal System Design
|
|
||||||
|
|
||||||
**Date:** 2026-03-24
|
|
||||||
**Version:** 4.0.0
|
|
||||||
**Status:** Approved
|
|
||||||
|
|
||||||
## Overview
|
|
||||||
|
|
||||||
Replace the existing dialog implementations with a unified modal system that provides:
|
|
||||||
- Glassmorphism backdrop matching app aesthetic
|
|
||||||
- Full accessibility (ARIA, focus trap, keyboard navigation)
|
|
||||||
- Smooth fade + scale animations
|
|
||||||
- Consistent API via `ModalManager` class
|
|
||||||
|
|
||||||
## Decisions Made
|
|
||||||
|
|
||||||
| Decision | Choice | Rationale |
|
|
||||||
|----------|--------|-----------|
|
|
||||||
| Architecture | Unified `ModalManager` class | Cleaner, consistent behavior across all modals |
|
|
||||||
| Backdrop style | Glassmorphism | Matches existing app design language |
|
|
||||||
| Focus management | Focus first interactive element | Standard, predictable behavior |
|
|
||||||
| Animation | Fade + scale (95% → 100%) | Modern, subtle effect |
|
|
||||||
| Implementation | Custom (not native `<dialog>`) | Full control, no polyfill concerns |
|
|
||||||
|
|
||||||
## Architecture
|
|
||||||
|
|
||||||
### File Structure
|
|
||||||
|
|
||||||
```
|
|
||||||
src/
|
|
||||||
├── utils/
|
|
||||||
│ └── ModalManager.js # Core modal logic (~150 lines)
|
|
||||||
├── styles/
|
|
||||||
│ └── modal.css # Unified modal styles (~200 lines)
|
|
||||||
└── index.html # Updated dialog markup
|
|
||||||
```
|
|
||||||
|
|
||||||
### ModalManager Class
|
|
||||||
|
|
||||||
```javascript
|
|
||||||
class ModalManager {
|
|
||||||
constructor(element, options = {})
|
|
||||||
open() // Show modal with animation
|
|
||||||
close() // Hide modal with animation
|
|
||||||
destroy() // Cleanup event listeners
|
|
||||||
on(event, callback) // Event subscription
|
|
||||||
|
|
||||||
// Internal
|
|
||||||
#createBackdrop() // Create glassmorphism backdrop
|
|
||||||
#trapFocus() // Manage focus within modal
|
|
||||||
#handleKeydown(e) // Escape key handler
|
|
||||||
#getFocusableElements() // Query focusable children
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Events
|
|
||||||
|
|
||||||
- `open` — Fired after open animation completes
|
|
||||||
- `close` — Fired after close animation completes
|
|
||||||
|
|
||||||
## CSS Design
|
|
||||||
|
|
||||||
### Variables (from tokens.css)
|
|
||||||
|
|
||||||
```css
|
|
||||||
--z-modal: 200;
|
|
||||||
--transition-normal: 200ms cubic-bezier(0.4, 0, 0.2, 1);
|
|
||||||
--shadow-xl: 0 20px 25px -5px rgb(0 0 0 / 0.1);
|
|
||||||
--radius-lg: 0.5rem;
|
|
||||||
```
|
|
||||||
|
|
||||||
### Backdrop
|
|
||||||
|
|
||||||
```css
|
|
||||||
.modal-backdrop {
|
|
||||||
position: fixed;
|
|
||||||
inset: 0;
|
|
||||||
background: rgba(0, 0, 0, 0.4);
|
|
||||||
backdrop-filter: blur(4px);
|
|
||||||
-webkit-backdrop-filter: blur(4px);
|
|
||||||
z-index: var(--z-modal);
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Modal Container
|
|
||||||
|
|
||||||
```css
|
|
||||||
.modal {
|
|
||||||
position: fixed;
|
|
||||||
inset: 0;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
z-index: calc(var(--z-modal) + 1);
|
|
||||||
opacity: 0;
|
|
||||||
visibility: hidden;
|
|
||||||
transition: opacity var(--transition-normal),
|
|
||||||
visibility var(--transition-normal);
|
|
||||||
}
|
|
||||||
|
|
||||||
.modal.open {
|
|
||||||
opacity: 1;
|
|
||||||
visibility: visible;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Modal Content (with animation)
|
|
||||||
|
|
||||||
```css
|
|
||||||
.modal-content {
|
|
||||||
background: hsl(var(--background));
|
|
||||||
border-radius: var(--radius-lg);
|
|
||||||
box-shadow: var(--shadow-xl);
|
|
||||||
max-width: 90vw;
|
|
||||||
max-height: 90vh;
|
|
||||||
overflow: hidden;
|
|
||||||
transform: scale(0.95);
|
|
||||||
transition: transform var(--transition-normal);
|
|
||||||
}
|
|
||||||
|
|
||||||
.modal.open .modal-content {
|
|
||||||
transform: scale(1);
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
## HTML Structure
|
|
||||||
|
|
||||||
All dialogs convert to unified structure:
|
|
||||||
|
|
||||||
```html
|
|
||||||
<div id="export-dialog"
|
|
||||||
class="modal"
|
|
||||||
role="dialog"
|
|
||||||
aria-modal="true"
|
|
||||||
aria-labelledby="export-dialog-title">
|
|
||||||
|
|
||||||
<div class="modal-backdrop" data-close></div>
|
|
||||||
|
|
||||||
<div class="modal-content">
|
|
||||||
<div class="modal-header">
|
|
||||||
<h3 id="export-dialog-title">Export Options</h3>
|
|
||||||
<button class="modal-close" aria-label="Close">×</button>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<div class="modal-body">
|
|
||||||
<!-- Dialog-specific content -->
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<div class="modal-footer">
|
|
||||||
<button class="btn btn-secondary" data-close>Cancel</button>
|
|
||||||
<button class="btn btn-primary">Confirm</button>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
```
|
|
||||||
|
|
||||||
### Key Attributes
|
|
||||||
|
|
||||||
- `role="dialog"` — Screen reader identification
|
|
||||||
- `aria-modal="true"` — Prevents screen reader from accessing background
|
|
||||||
- `aria-labelledby` — References the dialog title
|
|
||||||
- `data-close` — Click handler for closing (backdrop, cancel buttons)
|
|
||||||
|
|
||||||
## Accessibility Features
|
|
||||||
|
|
||||||
1. **Focus trap** — Tab cycles within modal only
|
|
||||||
2. **Focus first element** — Auto-focuses first input/button on open
|
|
||||||
3. **Escape key** — Closes modal
|
|
||||||
4. **Click outside** — Clicking backdrop closes modal
|
|
||||||
5. **Focus restoration** — Returns focus to trigger element on close
|
|
||||||
6. **ARIA attributes** — Proper screen reader support
|
|
||||||
|
|
||||||
## Dialogs to Migrate
|
|
||||||
|
|
||||||
| Dialog ID | Current Class | Complexity |
|
|
||||||
|-----------|--------------|------------|
|
|
||||||
| `find-dialog` | `.find-dialog` | Simple |
|
|
||||||
| `export-dialog` | `.export-dialog` | Complex (many sections) |
|
|
||||||
| `print-preview-overlay` | `.export-dialog` | Medium |
|
|
||||||
| `table-generator-dialog` | `.export-dialog` | Simple |
|
|
||||||
| `ascii-art-dialog` | `.export-dialog` | Medium |
|
|
||||||
| `universal-converter-dialog` | `.export-dialog` | Complex |
|
|
||||||
| `batch-dialog` | `.batch-dialog` | Complex |
|
|
||||||
| `pdf-editor-dialog` | `.export-dialog` | Complex |
|
|
||||||
| `header-footer-dialog` | `.export-dialog` | Medium |
|
|
||||||
| `field-picker-dialog` | `.export-dialog` | Simple |
|
|
||||||
|
|
||||||
## Migration Steps
|
|
||||||
|
|
||||||
1. Create `src/utils/ModalManager.js`
|
|
||||||
2. Create `src/styles/modal.css`
|
|
||||||
3. Update `index.html` to include new stylesheet
|
|
||||||
4. Convert each dialog HTML to new structure
|
|
||||||
5. Initialize `ModalManager` instances in `renderer.js`
|
|
||||||
6. Remove old CSS from `styles.css`
|
|
||||||
7. Test all dialogs
|
|
||||||
|
|
||||||
## Out of Scope
|
|
||||||
|
|
||||||
- Modal nesting (stacked modals) — can be added later if needed
|
|
||||||
- Animated backdrop (currently static blur)
|
|
||||||
- Modal size variants (small/large/fullscreen) — can use inline styles
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,326 +0,0 @@
|
|||||||
# V4 Enhancement + Flutter Exploration Design
|
|
||||||
|
|
||||||
**Date:** 2026-03-24
|
|
||||||
**Status:** Approved
|
|
||||||
**Approach:** Incremental V4 Enhancement + Flutter Spike (70/30 split)
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Executive Summary
|
|
||||||
|
|
||||||
This design outlines a two-track approach:
|
|
||||||
1. **V4 Enhancement (70%)**: Fix critical bugs, optimize performance, add platform adapters, improve UI patterns
|
|
||||||
2. **Flutter Exploration (30%)**: Build proof-of-concept for cross-platform evaluation (Windows, Mobile, Web)
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Goals & Scope
|
|
||||||
|
|
||||||
### Primary Goals
|
|
||||||
1. **Fix critical bug**: PDF and markdown multitab functionality
|
|
||||||
2. **Performance improvements**: Faster startup, smoother editing, responsive preview
|
|
||||||
3. **Architecture improvements**: Platform adapters, cleaner state management
|
|
||||||
4. **Flutter research**: Proof-of-concept for cross-platform evaluation
|
|
||||||
|
|
||||||
### Out of Scope
|
|
||||||
- Full V5 migration
|
|
||||||
- Complete UI redesign
|
|
||||||
- New features (focus on optimization)
|
|
||||||
|
|
||||||
### Success Criteria
|
|
||||||
|
|
||||||
| Metric | Current | Target |
|
|
||||||
|--------|---------|--------|
|
|
||||||
| Startup time | ~3-5s | <2s |
|
|
||||||
| Editor typing latency | Noticeable lag | <16ms |
|
|
||||||
| Preview render (1MB file) | ~500ms | <200ms |
|
|
||||||
| Memory usage | ~300MB | <200MB |
|
|
||||||
| Bundle size | ~150MB | <100MB |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Section 1: V4 Critical Fixes & Performance Optimizations
|
|
||||||
|
|
||||||
### 1.1 Fix: PDF/Markdown Multitab Bug
|
|
||||||
|
|
||||||
**Location:** `src/renderer.js` (TabManager class)
|
|
||||||
|
|
||||||
**Investigation areas:**
|
|
||||||
- `switchToTab()` - ensure proper state preservation
|
|
||||||
- `closeTab()` - ensure EditorView cleanup
|
|
||||||
- Add tab type tracking (markdown vs pdf)
|
|
||||||
- Isolate PDF viewer state from editor state
|
|
||||||
|
|
||||||
### 1.2 Startup Performance Optimizations
|
|
||||||
|
|
||||||
| Optimization | Implementation | Expected Gain |
|
|
||||||
|--------------|----------------|---------------|
|
|
||||||
| Defer Mermaid | Load only when diagram detected | ~500ms |
|
|
||||||
| Defer PDF.js | Load on first PDF open | ~800ms |
|
|
||||||
| Lazy load themes | Load active theme only | ~200ms |
|
|
||||||
| Lazy sidebar panels | Load panel code when sidebar opens | ~300ms |
|
|
||||||
| Preload optimization | Remove unused IPC channels | ~100ms |
|
|
||||||
|
|
||||||
**Lazy loading pattern:**
|
|
||||||
```javascript
|
|
||||||
// Current (loads everything upfront)
|
|
||||||
const { dialog } = require('@electron/remote');
|
|
||||||
|
|
||||||
// Optimized (load on demand)
|
|
||||||
let _dialog;
|
|
||||||
function getDialog() {
|
|
||||||
if (!_dialog) _dialog = require('@electron/remote').dialog;
|
|
||||||
return _dialog;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 1.3 Editor Performance
|
|
||||||
|
|
||||||
| Issue | Solution |
|
|
||||||
|-------|----------|
|
|
||||||
| Typing lag with large files | Debounce preview updates (300ms) |
|
|
||||||
| Syntax highlight overhead | Use highlight.js lazy mode |
|
|
||||||
| Memory leaks | Clean up EditorView on tab close |
|
|
||||||
| Theme switching lag | Pre-compile theme CSS |
|
|
||||||
|
|
||||||
### 1.4 Preview Rendering
|
|
||||||
|
|
||||||
| Issue | Solution |
|
|
||||||
|-------|----------|
|
|
||||||
| Mermaid slow | Render on-demand, cache results |
|
|
||||||
| Full re-render on keystroke | Debounced incremental updates |
|
|
||||||
| Large documents | Viewport rendering (visible portion only) |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Section 2: Platform Adapter Pattern
|
|
||||||
|
|
||||||
### 2.1 Architecture
|
|
||||||
|
|
||||||
```
|
|
||||||
src/
|
|
||||||
├── adapters/
|
|
||||||
│ ├── index.js # Auto-detects and exports adapter
|
|
||||||
│ ├── types.js # Interface definitions (JSDoc)
|
|
||||||
│ │
|
|
||||||
│ ├── electron/ # Current Electron implementation
|
|
||||||
│ │ ├── index.js # Exports electronAdapter
|
|
||||||
│ │ ├── fs.js # File system operations
|
|
||||||
│ │ ├── convert.js # Pandoc, FFmpeg conversions
|
|
||||||
│ │ ├── pdf.js # PDF operations
|
|
||||||
│ │ └── system.js # System info, dialogs, notifications
|
|
||||||
│ │
|
|
||||||
│ └── mock/ # For testing
|
|
||||||
│ └── index.js # Mock adapter for unit tests
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.2 Adapter Interface
|
|
||||||
|
|
||||||
```javascript
|
|
||||||
/**
|
|
||||||
* @typedef {Object} PlatformAdapter
|
|
||||||
* @property {'electron'} name
|
|
||||||
* @property {FileSystemAdapter} fs
|
|
||||||
* @property {ConversionAdapter} convert
|
|
||||||
* @property {PdfAdapter} pdf
|
|
||||||
* @property {SystemAdapter} system
|
|
||||||
*/
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @typedef {Object} FileSystemAdapter
|
|
||||||
* @property {(path: string) => Promise<string>} readFile
|
|
||||||
* @property {(path: string, content: string) => Promise<void>} writeFile
|
|
||||||
* @property {(path: string) => Promise<void>} deleteFile
|
|
||||||
* @property {(path: string) => Promise<FileInfo[]>} listDirectory
|
|
||||||
* @property {(path: string) => Promise<boolean>} exists
|
|
||||||
*/
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2.3 Migration Strategy
|
|
||||||
|
|
||||||
| Phase | What | Files Affected |
|
|
||||||
|-------|------|----------------|
|
|
||||||
| 1 | Create adapter structure | New files only |
|
|
||||||
| 2 | Migrate file operations | `renderer.js`, `sidebar/*.js` |
|
|
||||||
| 3 | Migrate conversions | Export dialogs |
|
|
||||||
| 4 | Migrate PDF operations | PDF viewer |
|
|
||||||
| 5 | Remove old IPC calls | `preload.js` cleanup |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Section 3: UI Improvements (Shadcn/ui Patterns)
|
|
||||||
|
|
||||||
### 3.1 Design Token System
|
|
||||||
|
|
||||||
```css
|
|
||||||
/* src/styles/tokens.css */
|
|
||||||
|
|
||||||
:root {
|
|
||||||
/* Colors - Light mode */
|
|
||||||
--background: 0 0% 100%;
|
|
||||||
--foreground: 222.2 84% 4.9%;
|
|
||||||
--primary: 227 44% 52%;
|
|
||||||
--primary-foreground: 210 40% 98%;
|
|
||||||
--secondary: 210 40% 96.1%;
|
|
||||||
--secondary-foreground: 222.2 47.4% 11.2%;
|
|
||||||
--muted: 210 40% 96.1%;
|
|
||||||
--muted-foreground: 215.4 16.3% 46.9%;
|
|
||||||
--destructive: 0 84.2% 60.2%;
|
|
||||||
--border: 214.3 31.8% 91.4%;
|
|
||||||
--ring: 227 44% 52%;
|
|
||||||
|
|
||||||
/* Spacing & Radii */
|
|
||||||
--radius: 0.5rem;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3.2 Component Improvements
|
|
||||||
|
|
||||||
| Component | Current Issue | Fix |
|
|
||||||
|-----------|---------------|-----|
|
|
||||||
| Buttons | Inconsistent hover/focus | Use `.btn` with variants |
|
|
||||||
| Dialogs | Missing focus trap | Add focus trap, Escape key, aria-modal |
|
|
||||||
| Tabs | No keyboard navigation | Add arrow key nav, aria-selected |
|
|
||||||
| Sidebar | No collapse animation | CSS transitions |
|
|
||||||
| Dropdowns | Missing click-outside | Add proper event handling |
|
|
||||||
|
|
||||||
### 3.3 Accessibility Improvements
|
|
||||||
|
|
||||||
- Focus states with `:focus-visible`
|
|
||||||
- Skip to content link
|
|
||||||
- ARIA labels on interactive elements
|
|
||||||
- Keyboard navigation for all components
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Section 4: Flutter Exploration (30% Effort)
|
|
||||||
|
|
||||||
### 4.1 Flutter Project Structure
|
|
||||||
|
|
||||||
```
|
|
||||||
markdown-converter-flutter/
|
|
||||||
├── lib/
|
|
||||||
│ ├── main.dart
|
|
||||||
│ ├── app.dart
|
|
||||||
│ ├── core/
|
|
||||||
│ │ ├── theme/
|
|
||||||
│ │ └── constants.dart
|
|
||||||
│ ├── features/
|
|
||||||
│ │ ├── editor/
|
|
||||||
│ │ ├── preview/
|
|
||||||
│ │ └── tabs/
|
|
||||||
│ ├── services/
|
|
||||||
│ │ ├── file_service.dart
|
|
||||||
│ │ ├── export_service.dart
|
|
||||||
│ │ └── platform_service.dart
|
|
||||||
│ └── adapters/
|
|
||||||
│ ├── file_adapter.dart
|
|
||||||
│ ├── file_adapter_mobile.dart
|
|
||||||
│ ├── file_adapter_web.dart
|
|
||||||
│ └── file_adapter_desktop.dart
|
|
||||||
├── pubspec.yaml
|
|
||||||
├── windows/
|
|
||||||
├── web/
|
|
||||||
└── lib/
|
|
||||||
```
|
|
||||||
|
|
||||||
### 4.2 Key Dependencies
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
dependencies:
|
|
||||||
flutter_markdown: ^0.7.0
|
|
||||||
flutter_code_editor: ^0.3.0
|
|
||||||
provider: ^6.1.0
|
|
||||||
file_picker: ^8.0.0
|
|
||||||
path_provider: ^2.1.0
|
|
||||||
pdf: ^3.10.0
|
|
||||||
printing: ^5.12.0
|
|
||||||
```
|
|
||||||
|
|
||||||
### 4.3 Prototype Features
|
|
||||||
|
|
||||||
| Feature | Priority |
|
|
||||||
|---------|----------|
|
|
||||||
| Basic markdown editor | Must have |
|
|
||||||
| Live preview | Must have |
|
|
||||||
| Light/dark theme | Must have |
|
|
||||||
| Tab management | Should have |
|
|
||||||
| File open/save | Should have |
|
|
||||||
| PDF export | Nice to have |
|
|
||||||
| Windows exe build | Must have |
|
|
||||||
| Web build | Must have |
|
|
||||||
| Mobile build | Should have |
|
|
||||||
|
|
||||||
### 4.4 Evaluation Criteria
|
|
||||||
|
|
||||||
| Metric | Target |
|
|
||||||
|--------|--------|
|
|
||||||
| Windows exe size | <50MB |
|
|
||||||
| Web initial load | <500KB |
|
|
||||||
| Cold start time | <2s |
|
|
||||||
| Editor typing latency | <16ms |
|
|
||||||
|
|
||||||
### 4.5 Flutter vs Tauri Comparison
|
|
||||||
|
|
||||||
| Aspect | Flutter | Tauri + React |
|
|
||||||
|--------|---------|---------------|
|
|
||||||
| Mobile support | ✅ Excellent | ❌ Requires separate app |
|
|
||||||
| Web performance | ⚠️ Good, larger | ✅ Excellent, small |
|
|
||||||
| Desktop bundle | ⚠️ ~30-50MB | ✅ ~5-10MB |
|
|
||||||
| Native feel | ⚠️ Custom rendering | ✅ System WebView |
|
|
||||||
| Code reuse | ✅ 100% shared | ⚠️ Some platform-specific |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Implementation Timeline
|
|
||||||
|
|
||||||
### Phase 1: V4 Critical Fixes (Week 1)
|
|
||||||
- Fix PDF/markdown multitab bug
|
|
||||||
- Implement startup optimizations
|
|
||||||
- Add debounced preview rendering
|
|
||||||
|
|
||||||
### Phase 2: Platform Adapters (Week 2)
|
|
||||||
- Create adapter structure
|
|
||||||
- Migrate file operations
|
|
||||||
- Migrate conversions
|
|
||||||
|
|
||||||
### Phase 3: UI Improvements (Week 3)
|
|
||||||
- Add design tokens
|
|
||||||
- Improve component accessibility
|
|
||||||
- Add keyboard navigation
|
|
||||||
|
|
||||||
### Phase 4: Flutter Prototype (Weeks 2-4, parallel)
|
|
||||||
- Set up Flutter project
|
|
||||||
- Implement basic editor
|
|
||||||
- Build Windows and Web versions
|
|
||||||
- Document findings
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Risk Mitigation
|
|
||||||
|
|
||||||
| Risk | Mitigation |
|
|
||||||
|------|------------|
|
|
||||||
| Multitab fix causes regressions | Comprehensive test suite before changes |
|
|
||||||
| Performance optimizations break features | Incremental changes with benchmarks |
|
|
||||||
| Flutter proves unsuitable | 30% effort limit, V4 remains primary |
|
|
||||||
| Platform adapter migration too slow | Phased approach, each phase independent |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Success Metrics
|
|
||||||
|
|
||||||
- [ ] Multitab functionality working correctly
|
|
||||||
- [ ] Startup time < 2 seconds
|
|
||||||
- [ ] No perceived editor lag with files < 1MB
|
|
||||||
- [ ] Preview renders in < 200ms
|
|
||||||
- [ ] Bundle size reduced by 30%+
|
|
||||||
- [ ] Platform adapters for fs, convert, pdf implemented
|
|
||||||
- [ ] Design tokens applied to all components
|
|
||||||
- [ ] Flutter prototype running on Windows + Web
|
|
||||||
- [ ] Flutter evaluation documented with recommendation
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
*Document generated: 2026-03-24*
|
|
||||||
*Next step: Create detailed implementation plan*
|
|
||||||
@@ -1,335 +0,0 @@
|
|||||||
# Writer's Studio Feature Pack — Design Document
|
|
||||||
|
|
||||||
**Date**: 2026-04-06
|
|
||||||
**Version**: 4.2.0 target
|
|
||||||
**Status**: Approved
|
|
||||||
**Scope**: Three cohesive features to transform MarkdownConverter into a writing environment
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Overview
|
|
||||||
|
|
||||||
The Writer's Studio Feature Pack adds three interconnected features to MarkdownConverter:
|
|
||||||
|
|
||||||
1. **Zen Mode** — Distraction-free writing environment with typewriter scrolling
|
|
||||||
2. **Document Outline** — Heading hierarchy sidebar panel for navigation
|
|
||||||
3. **Writing Analytics** — Real-time readability and vocabulary analysis dashboard
|
|
||||||
|
|
||||||
These features work together: Zen Mode creates the environment, Outline provides navigation, Analytics gives insight.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Feature 1: Zen Mode
|
|
||||||
|
|
||||||
### Purpose
|
|
||||||
|
|
||||||
Transform the app from a multi-tool into a focused writing environment. Inspired by iA Writer, Typora, and Bear.
|
|
||||||
|
|
||||||
### New Files
|
|
||||||
|
|
||||||
- `src/zen-mode.js` — ZenMode class (~150 lines)
|
|
||||||
- `src/styles-zen.css` — Zen mode specific styles (~120 lines)
|
|
||||||
|
|
||||||
### Integration Points
|
|
||||||
|
|
||||||
- `src/renderer.js` — Initialize ZenMode, register F11 shortcut, add View > Zen Mode menu
|
|
||||||
- `src/editor/codemirror-setup.js` — Export typewriter + dimming extensions
|
|
||||||
|
|
||||||
### Behavior
|
|
||||||
|
|
||||||
**Toggle**: F11, View > Zen Mode, command palette "Toggle Zen Mode"
|
|
||||||
**Exit**: Escape key, F11 again
|
|
||||||
|
|
||||||
**What hides**:
|
|
||||||
- Tab bar
|
|
||||||
- Toolbar
|
|
||||||
- Sidebar (collapsed)
|
|
||||||
- Status bar
|
|
||||||
- App header
|
|
||||||
|
|
||||||
**What shows**:
|
|
||||||
- Editor (full viewport)
|
|
||||||
- Floating HUD (bottom-center, semi-transparent)
|
|
||||||
|
|
||||||
### Floating HUD
|
|
||||||
|
|
||||||
```
|
|
||||||
┌─────────────────────────────────────────┐
|
|
||||||
│ 847 words • ~4 min • 23:45 session │
|
|
||||||
│ ████████████████░░░░ 85% of 1000 │
|
|
||||||
└─────────────────────────────────────────┘
|
|
||||||
```
|
|
||||||
|
|
||||||
- Word count (from existing status bar logic)
|
|
||||||
- Estimated reading time (~200 wpm)
|
|
||||||
- Session timer (starts when zen mode activates)
|
|
||||||
- Optional progress bar toward word goal
|
|
||||||
|
|
||||||
### CodeMirror Extensions
|
|
||||||
|
|
||||||
**Typewriter Scroll** (`ViewPlugin`):
|
|
||||||
- Listens to `EditorView.update` for selection changes
|
|
||||||
- Calls `editor.dispatch({ effects: EditorView.scrollIntoView(pos, { y: 'center' }) })`
|
|
||||||
- Smooth scrolling with `scrollBehavior: 'smooth'` in CSS
|
|
||||||
|
|
||||||
**Line Dimming** (`ViewPlugin` + `Decoration`):
|
|
||||||
- Builds a `DecorationSet` mapping each line to an opacity value
|
|
||||||
- Active line: opacity 1.0
|
|
||||||
- 1-2 lines away: 0.7
|
|
||||||
- 3-4 lines away: 0.5
|
|
||||||
- 5+ lines away: 0.3
|
|
||||||
- Uses `Decoration.line({ attributes: { style: 'opacity: X' } })`
|
|
||||||
|
|
||||||
### Centered Column
|
|
||||||
|
|
||||||
CSS applied to `.zen-mode .cm-content`:
|
|
||||||
```css
|
|
||||||
.zen-mode .cm-content {
|
|
||||||
max-width: 700px;
|
|
||||||
margin: 0 auto;
|
|
||||||
font-size: 18px;
|
|
||||||
line-height: 1.8;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### State Management
|
|
||||||
|
|
||||||
- `this.previousState` stores which UI elements were visible before zen mode
|
|
||||||
- On exit, restores all elements to their previous visibility
|
|
||||||
- Editor content, cursor position, and scroll state are never modified
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Feature 2: Document Outline Panel
|
|
||||||
|
|
||||||
### Purpose
|
|
||||||
|
|
||||||
Provide always-visible heading navigation for documents of any length. The single most-requested navigation feature for multi-section documents.
|
|
||||||
|
|
||||||
### New Files
|
|
||||||
|
|
||||||
- `src/sidebar/outline-panel.js` — `renderOutlinePanel` function (~100 lines)
|
|
||||||
|
|
||||||
### Modified Files
|
|
||||||
|
|
||||||
- `src/index.html` — Add outline icon button in sidebar icons strip
|
|
||||||
- `src/renderer.js` — Register 'outline' panel, provide editor reference
|
|
||||||
|
|
||||||
### Sidebar Integration
|
|
||||||
|
|
||||||
Uses existing `SidebarManager.registerPanel()` API:
|
|
||||||
```javascript
|
|
||||||
sidebarManager.registerPanel('outline', {
|
|
||||||
title: 'Outline',
|
|
||||||
render: (container) => renderOutlinePanel(container, editor, editorContent)
|
|
||||||
});
|
|
||||||
```
|
|
||||||
|
|
||||||
New icon button in sidebar strip (after templates icon):
|
|
||||||
```html
|
|
||||||
<button class="sidebar-icon" data-panel="outline" title="Outline (Ctrl+Shift+O)">
|
|
||||||
<!-- hierarchy/list icon SVG -->
|
|
||||||
</button>
|
|
||||||
```
|
|
||||||
|
|
||||||
### Parsing Logic
|
|
||||||
|
|
||||||
Parse headings from raw markdown content using regex:
|
|
||||||
```javascript
|
|
||||||
const headingRegex = /^(#{1,6})\s+(.+)$/gm;
|
|
||||||
```
|
|
||||||
|
|
||||||
Returns array of:
|
|
||||||
```javascript
|
|
||||||
{ level: 1-6, text: "Heading Text", line: 42 }
|
|
||||||
```
|
|
||||||
|
|
||||||
Debounced at 300ms to avoid re-parsing on every keystroke.
|
|
||||||
|
|
||||||
### UI Structure
|
|
||||||
|
|
||||||
```
|
|
||||||
┌──────────────────────────────────────────┐
|
|
||||||
│ OUTLINE ☰ │
|
|
||||||
├──────────────────────────────────────────┤
|
|
||||||
│ ▸ Introduction (H1) │
|
|
||||||
│ ▸ Getting Started (H2) │
|
|
||||||
│ ▸ Prerequisites (H2) │
|
|
||||||
│ ▸ Node.js (H3) ◄ │
|
|
||||||
│ ▸ Installation (H2) │
|
|
||||||
│ ▸ Features (H1) │
|
|
||||||
│ ▸ Editor (H2) │
|
|
||||||
│ ▸ Export (H2) │
|
|
||||||
├──────────────────────────────────────────┤
|
|
||||||
│ 9 headings • 2 H1 • 4 H2 • 3 H3 │
|
|
||||||
└──────────────────────────────────────────┘
|
|
||||||
```
|
|
||||||
|
|
||||||
- Indentation based on heading level (H1 = 0px, H2 = 16px, H3 = 32px, etc.)
|
|
||||||
- Current heading highlighted with accent color (◄ indicator)
|
|
||||||
- Hover shows full heading text if truncated
|
|
||||||
|
|
||||||
### Click-to-Navigate
|
|
||||||
|
|
||||||
```javascript
|
|
||||||
editor.dispatch({
|
|
||||||
effects: EditorView.scrollIntoView(linePos, { y: 'center' })
|
|
||||||
});
|
|
||||||
```
|
|
||||||
|
|
||||||
Brief highlight animation on the target line (fades out over 500ms).
|
|
||||||
|
|
||||||
### Current Heading Sync
|
|
||||||
|
|
||||||
On editor update (debounced 100ms):
|
|
||||||
1. Get cursor line number
|
|
||||||
2. Find the last heading whose line number <= cursor line
|
|
||||||
3. Set that heading as active in the outline
|
|
||||||
|
|
||||||
### Empty State
|
|
||||||
|
|
||||||
When no headings found:
|
|
||||||
```
|
|
||||||
No headings found
|
|
||||||
|
|
||||||
Use # to create headings:
|
|
||||||
# Heading 1
|
|
||||||
## Heading 2
|
|
||||||
### Heading 3
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Feature 3: Writing Analytics
|
|
||||||
|
|
||||||
### Purpose
|
|
||||||
|
|
||||||
Give writers real-time insight into their document's readability, structure, and vocabulary. This is the "surprise" feature most Markdown editors lack.
|
|
||||||
|
|
||||||
### New Files
|
|
||||||
|
|
||||||
- `src/analytics/writing-analytics.js` — `WritingAnalytics` class (~180 lines)
|
|
||||||
- `src/analytics/analytics-panel.js` — `renderAnalyticsPanel` function (~120 lines)
|
|
||||||
|
|
||||||
### Integration Points
|
|
||||||
|
|
||||||
- `src/renderer.js` — Register Ctrl+Shift+A shortcut, command palette entry, View menu item
|
|
||||||
|
|
||||||
### Trigger
|
|
||||||
|
|
||||||
- Keyboard: `Ctrl+Shift+A`
|
|
||||||
- Command Palette: "Show Writing Analytics"
|
|
||||||
- Menu: View > Writing Analytics
|
|
||||||
|
|
||||||
### Presentation
|
|
||||||
|
|
||||||
Uses existing `ModalManager` to show a modal overlay with analytics dashboard.
|
|
||||||
|
|
||||||
```
|
|
||||||
┌─────────────────────────────────────────────────────┐
|
|
||||||
│ Writing Analytics ✕ │
|
|
||||||
├─────────────────────────────────────────────────────┤
|
|
||||||
│ │
|
|
||||||
│ ┌─ Readability ──────────────────────────────────┐ │
|
|
||||||
│ │ Flesch Reading Ease: 67.3 (Standard) ○ │ │
|
|
||||||
│ │ Grade Level: 8.2 ○○○●○ │ │
|
|
||||||
│ └─────────────────────────────────────────────────┘ │
|
|
||||||
│ │
|
|
||||||
│ ┌─ Timing ───────────────────────────────────────┐ │
|
|
||||||
│ │ Reading Time: ~4 min │ │
|
|
||||||
│ │ Speaking Time: ~6 min │ │
|
|
||||||
│ └─────────────────────────────────────────────────┘ │
|
|
||||||
│ │
|
|
||||||
│ ┌─ Structure ────────────────────────────────────┐ │
|
|
||||||
│ │ Sentences: 42 • Paragraphs: 8 │ │
|
|
||||||
│ │ Avg Sentence: 14.2 words │ │
|
|
||||||
│ │ Longest: 38 words ("The quick brown fox...") │ │
|
|
||||||
│ └─────────────────────────────────────────────────┘ │
|
|
||||||
│ │
|
|
||||||
│ ┌─ Vocabulary ───────────────────────────────────┐ │
|
|
||||||
│ │ Unique: 312 / 847 words (36.8%) │ │
|
|
||||||
│ │ Top: the(42) and(31) markdown(28) ... │ │
|
|
||||||
│ └─────────────────────────────────────────────────┘ │
|
|
||||||
│ │
|
|
||||||
│ ┌─ Word Goal ────────────────────────────────────┐ │
|
|
||||||
│ │ Target: [1000] words │ │
|
|
||||||
│ │ ████████████████░░░░ 847/1000 (85%) │ │
|
|
||||||
│ └─────────────────────────────────────────────────┘ │
|
|
||||||
│ │
|
|
||||||
└─────────────────────────────────────────────────────┘
|
|
||||||
```
|
|
||||||
|
|
||||||
### Metrics Implementation
|
|
||||||
|
|
||||||
**Readability (Flesch-Kincaid):**
|
|
||||||
```javascript
|
|
||||||
// Flesch Reading Ease
|
|
||||||
ease = 206.835 - 1.015 * (words / sentences) - 84.6 * (syllables / words);
|
|
||||||
|
|
||||||
// Flesch-Kincaid Grade Level
|
|
||||||
grade = 0.39 * (words / sentences) + 11.8 * (syllables / words) - 15.59;
|
|
||||||
```
|
|
||||||
|
|
||||||
**Syllable Estimation:**
|
|
||||||
```javascript
|
|
||||||
function countSyllables(word) {
|
|
||||||
word = word.toLowerCase().replace(/(?:[^laeiouy]es|ed|[^laeiouy]e)$/, '');
|
|
||||||
word = word.replace(/^y/, '');
|
|
||||||
return word.match(/[aeiouy]{1,2}/g)?.length || 1;
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Reading/Speaking Time:**
|
|
||||||
- Reading: 200 words/minute
|
|
||||||
- Speaking: 130 words/minute
|
|
||||||
|
|
||||||
**Lexical Diversity:**
|
|
||||||
- Ratio of unique words to total words (excluding stop words)
|
|
||||||
|
|
||||||
**Top Words:**
|
|
||||||
- Frequency map, sorted descending, top 10
|
|
||||||
- Excludes common stop words (the, a, an, is, are, etc.)
|
|
||||||
|
|
||||||
### Word Goal
|
|
||||||
|
|
||||||
- Persisted in `electron-store` per document (or global default)
|
|
||||||
- Progress bar with percentage
|
|
||||||
- Celebration effect when goal is reached (brief confetti animation or green flash)
|
|
||||||
|
|
||||||
### Update Cadence
|
|
||||||
|
|
||||||
- Re-analyzes on editor content change (debounced at 1000ms)
|
|
||||||
- If modal is open, updates live
|
|
||||||
- If modal is closed, no computation (zero overhead)
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## File Summary
|
|
||||||
|
|
||||||
| File | Action | Purpose |
|
|
||||||
|------|--------|---------|
|
|
||||||
| `src/zen-mode.js` | Create | ZenMode class with CM6 extensions |
|
|
||||||
| `src/styles-zen.css` | Create | Zen mode styling |
|
|
||||||
| `src/sidebar/outline-panel.js` | Create | Outline sidebar panel |
|
|
||||||
| `src/analytics/writing-analytics.js` | Create | Analytics computation engine |
|
|
||||||
| `src/analytics/analytics-panel.js` | Create | Analytics modal UI |
|
|
||||||
| `src/index.html` | Modify | Add outline icon, zen mode button |
|
|
||||||
| `src/renderer.js` | Modify | Initialize all three features |
|
|
||||||
| `src/editor/codemirror-setup.js` | Modify | Export typewriter + dimming extensions |
|
|
||||||
|
|
||||||
## Keyboard Shortcuts
|
|
||||||
|
|
||||||
| Shortcut | Feature | Action |
|
|
||||||
|----------|---------|--------|
|
|
||||||
| F11 | Zen Mode | Toggle on/off |
|
|
||||||
| Escape | Zen Mode | Exit (when active) |
|
|
||||||
| Ctrl+Shift+O | Outline | Open outline sidebar panel |
|
|
||||||
| Ctrl+Shift+A | Analytics | Open analytics modal |
|
|
||||||
|
|
||||||
## Dependencies
|
|
||||||
|
|
||||||
No new npm dependencies required. All features use:
|
|
||||||
- Existing CodeMirror 6 APIs (ViewPlugin, Decoration, scrollIntoView)
|
|
||||||
- Existing SidebarManager API
|
|
||||||
- Existing ModalManager API
|
|
||||||
- Pure JavaScript math for analytics
|
|
||||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user