Compare commits

..
288 Commits
Author SHA1 Message Date
amitwh 111d36bf3d refactor(flowchart): build script generates bundle from pure modules (D1)
Before this commit, src/renderer/flowchart-bundle.js was a 1700+
line hand-maintained file with ~1100 lines of inlined copies of the
pure modules (shapes, mermaid, mermaid-parse, store, canvas,
clipboard, align). Every change to a pure module required a manual
re-sync, and the C17 multi-select commit had to be applied in two
places — drift between source and bundle was a real risk.

This refactor introduces scripts/build-flowchart-bundle.js that
reads each pure module from src/flowchart/ and concatenates them
into the final src/renderer/flowchart-bundle.js that the standalone
window loads as a single <script> tag.

Architecture:

  - src/renderer/flowchart-bundle.js — now auto-generated, gitignored
    only conceptually (still tracked so the standalone window works
    without running a build step in dev).
  - src/renderer/flowchart-bundle-tail.js — the unique code that
    was previously buried in the middle of the hand-maintained bundle:
    IIFE open, defensive checks, pure-module destructure, controller
    bootstrap, modal helpers, node-list panel, closing IIFE, and
    DOMContentLoaded bootstrap trigger.
  - scripts/build-flowchart-bundle.js — the generator. Reads 8 pure
    modules in dependency order (vsdx-export excluded — main-process
    only), wraps each in its own IIFE for scope isolation, rewrites
    canvas's CommonJS require() lines to use window globals, and
    rewrites bare 'module.exports = X' to 'window.FlowchartX = X'
    for modules without UMD guards.

Tests: 1386/1386 passing (no regressions). The pre-existing per-node
fill color test that was passing before now passes for the right
reason — the canvas source was updated to pass node.color through
to shapeSvg, which it always should have. The hand-maintained bundle
had been silently carrying a patched version that passed color but
was never backported to src/.

Amit Haridas
2026-10-01 07:31:37 +05:30
amitwh a13a87c499 chore(deps): npm update + Node 22 LTS engines
Brings the dependency tree up to the latest in-range versions of every
package: codemirror ^6.43.13, dompurify ^3.4.16, mermaid stays at
^11.17.2 (v12 needs a rendering QA pass before bumping), highlight.js
^11.12.0, jszip ^3.10.2, katex ^0.18.10, prettier ^3.9.9, etc.

Also pins the dev Node version to >=22 LTS via the engines field.
Currently running on Node 22.22.1.

Deliberately deferred (would each need a QA pass):

  - Electron 41 -> 44 (3 majors; would need to re-validate every
    IPC + BrowserWindow API used in main.js / preload.js / the
    standalone windows).
  - Mermaid 11 -> 12 (major rendering pipeline change).
  - Marked 17 -> 18 (markdown renderer rewrite).
  - ESLint 9 -> 10 (flat-config breaking changes).
  - pdfjs-dist 5 -> 6 (worker pipeline rework).
  - electron-store 10 -> 11 (storage backend swap).

In-range updates verified by the full test suite (1386/1386).

Amit Haridas
2026-10-01 07:11:18 +05:30
amitwh bd620284ab test: fix Windows-only test failures so CI matrix runs clean
Two pre-existing Windows-specific failures blocked the CI release
matrix from publishing the Windows build:

  - tests/main/DailyNotes.test.js: 'joins dir + YYYY-MM-DD.md' used
    a hard-coded '/tmp/notes/2026-09-13.md' expected value. On
    POSIX path.join returns '/' and the test passes; on Windows
    path.join returns '\' and the test fails. Fix: build the
    expected value via path.join so it matches the platform.

  - tests/main/PDFBatchOperations.test.js: 'watermarks every PDF
    including subfolders' used the default 5s Jest timeout. Windows
    CI runners are slower at pdf-lib / pdfjs-dist cold-start and the
    test regularly exceeded 5s. Fix: jest.setTimeout(30000) at the
    start of the watermark describe block.

Neither is a regression — both predate this session. The fix gets
the Windows job green so the release matrix completes 3/3.

Amit Haridas
2026-09-30 23:12:59 +05:30
amitwh a6407b5839 build: regenerate package-lock.json with electron-updater deps
The CI release workflow has been failing on every v4.13.0 push with
'package.json and package-lock.json are out of sync', specifically
missing:

  - electron-updater@6.8.9
  - lodash.escaperegexp@4.1.2
  - lodash.isequal@4.5.0
  - semver@7.7.4
  - tiny-typed-emitter@2.1.0

These were added when electron-updater was wired up (commit 47315ad,
the auto-updater feature) but the lockfile was never regenerated to
match the new top-level dependency. npm install on a fresh checkout
sees the missing transitive deps and bails before the build matrix
can even start.

Fix: run 'npm install' against the current package.json to regenerate
package-lock.json with the correct dep graph. No package.json change
needed — the lockfile was simply stale.

Amit Haridas
2026-09-30 23:00:25 +05:30
amitwh 1a357bbd6a feat(flowchart): keyboard shortcuts overlay (C19)
After 17 commits of feature work the standalone window had a lot of
hidden keyboard shortcuts (Cmd+Z, Cmd+C/V/D, Delete, Alt+drag, etc.)
that no user could discover. This adds:

  - 'Shortcuts (?)' toolbar button next to Export Visio.
  - '?' key (or Shift+/) toggles the overlay; Esc closes it.
  - A read-only modal that lists every canvas-relevant shortcut in
    a 2-column table (Action / Shortcut) with <kbd> tags for the
    key combos, styled to look like physical keys.
  - Click on the dimmed overlay backdrop also closes it.
  - Reuses the existing .fc-modal fade + scale-in animation.

The overlay sits inside #fc-left so it overlays the canvas, not the
side panel. Hidden by default via the HTML hidden attribute.

Implementation: btnHelp / shortcutsModal / shortcutsOverlay /
shortcutsClose are added to the bundle's els bag. A small
showShortcutsOverlay / hideShortcutsOverlay pair toggles their
.hidden. The keydown handler gets two new branches at the top:

  - Esc: close the overlay if open.
  - ? (computed from ev.key === '?' or 'Shift+/', no modifier
    keys held): toggle the overlay.

Both branches return early so the existing Cmd+Z / Cmd+C / etc.
handlers below them still work.

Tests: 3 new (1386 total) covering the toolbar toggle, the
? + Esc keyboard flow, and that every shortcut the user can
trigger is listed in the modal.

Amit Haridas
2026-09-30 22:43:05 +05:30
amitwh dfce7fd3ac test(flowchart): cover multi-select API + onSelectionChange callback (C18)
Seven new jsdom tests for the canvas multi-select primitives
added in C17. Until now, setMultiSelection, getMultiSelection,
clearMultiSelection, and the shift+click toggle had zero test
coverage — every canvas change was a regression risk.

New tests:

  - getMultiSelection returns the Set as an array.
  - setMultiSelection replaces the existing selection.
  - clearMultiSelection empties node + edge selection.
  - setOnSelectionChange fires after every mutation (3 calls
    for 3 mutations in the test).
  - A throwing callback doesn't crash the canvas (defensive
    try/catch around emit).
  - applySelectionHighlight adds .selected to every node in
    the Set (verified via classList on the rendered <g>).
  - setMultiSelection rejects non-string / empty ids.

1383 total tests, was 1376. All passing.

Amit Haridas
2026-09-30 22:40:02 +05:30
amitwh fc017e0101 feat(flowchart): multi-select + drag-rect selection (C17)
Item 1 from the polish list. The canvas previously supported
single-selection only; this adds:

  - Shift+click on a node toggles its membership in a multi-
    selection Set. Plain click still replaces with a single node.
  - Plain drag on empty canvas draws a translucent blue
    selection rectangle; on pointerup, every node whose centre
    falls inside the rect joins the selection (or replaces it).
  - Shift+drag on empty canvas adds the rect-intersected nodes
    to the existing selection.
  - A bare click (no drag, no shift) on empty canvas falls back
    to the legacy 'click adds a process node' behaviour, so we
    don't accidentally lose the single-click affordance.
  - 'Select All' button on the alignment toolbar picks up every
    node; the alignment + distribute buttons then operate on the
    resulting set.
  - The canvas notifies the bundle via a new
    setOnSelectionChange callback so the bundle's _selectedNodeIds
    stays in sync with the canvas's selection.

Architecture changes:

  - src/flowchart/flowchart-canvas.js: new selectedNodeIds Set,
    onSelectionChange callback, getMultiSelection /
    setMultiSelection / clearMultiSelection /
    setOnSelectionChange exports. Drag-rect state machine lives
    alongside panState / dragState. applySelectionHighlight now
    uses Set membership rather than equality with a primary id.
  - src/renderer/flowchart-bundle.js: mirrored the same state
    machine in the inlined canvas so the standalone window gets
    the same behaviour without a rebuild step. The bundle's
    _selectedNodeIds is the source of truth for the alignment /
    distribute buttons; the canvas selection changes push updates
    to it via the onSelectionChange callback.

Tests: no new pure tests (multi-select is interactive canvas
behaviour; the existing 14 canvas tests still pass). 1376 total.

Amit Haridas
2026-09-30 22:35:44 +05:30
amitwh bf12996a40 feat(flowchart): visual polish — selection ring, hover, resize grip (C16)
Adds the visual feedback that was missing from the C10 resize + C2
selection commits. The canvas previously set the .selected class but
no CSS rule styled it, so a selected node looked identical to an
unselected one. Same for hover and the resize handle.

CSS additions (src/flowchart-generator.html):

  - .flowchart-node: cursor:grab + 0.12s filter transition for the
    hover tint (drop-shadow blue glow).
  - .flowchart-node:hover .flowchart-node-shape: blue glow.
  - .flowchart-node.selected .flowchart-node-shape: 2.25px blue
    stroke — replaces the (previously invisible) .selected class.
  - .flowchart-edge:hover and .flowchart-edge.selected: blue
    stroke + 2.5px width for the same reason.
  - .flowchart-resize-handle-hit: 24px transparent rect for an
    enlarged hit area (the visible grip stays 10px).
  - .flowchart-resize-handle-grip: blue square with stroke, styled
    via CSS instead of inline fill/stroke (which were overriding
    the rest of the file's theme).
  - .flowchart-edge-label-bg: opaque white pill behind edge labels,
    so labels stay readable when an edge curves under them.
  - .fc-modal / .fc-modal-overlay: fade + scale-in keyframes
    (0.15s ease-out) so the promptInline / confirmInline modals
    animate in instead of popping in instantly.

Canvas (src/flowchart/flowchart-canvas.js): the resize handle now
emits two rects — a 24px transparent hit area (data-resize-node
attribute preserved) and a smaller 10px visible grip styled via
.flowchart-resize-handle-grip. Cursor stays nwse-resize via CSS.

Tests: no new tests (visual); existing 14 canvas tests still pass.
1376 total.

Amit Haridas
2026-09-30 22:29:35 +05:30
amitwh f133efe025 feat(flowchart): alignment + distribution tools (C15)
8 new toolbar buttons (Align L/R/T/B, Center H/V, Distribute H/V)
plus a Select All button. Each operation takes the current
selection and applies a pure-function transform to the (x, y)
positions, then commits each result via store.moveNode().

Architecture:

  - src/flowchart/flowchart-align.js: pure module with 8 helpers
    + nodeWidth / nodeHeight utility. UMD wrapper for browser
    global + CommonJS, same pattern as the other pure modules.
  - src/renderer/flowchart-bundle.js: pure module inlined so the
    standalone window doesn't need a separate bundle build; the
    inlined functions are exposed as window.FlowchartAlign for
    jsdom tests.
  - Bundle's _selectedNodeIds Set tracks the alignment selection.
    Empty by default; populated by Select All or by future
    canvas-side shift+click (item 1: multi-select).
  - Each align button no-ops with a status hint if fewer than 2
    nodes are selected. Distribute needs 3+.
  - Each moveNode call creates its own undo snapshot, which is
    fine for typical 2-10 node selections and lets the user undo
    a misalignment one node at a time.

Tests: 14 new (1376 total) covering all 8 functions plus
immutability, no-op for insufficient nodes, and unsorted-input
sorting for distribute.

Amit Haridas
2026-09-30 22:28:13 +05:30
amitwh 7bb062a464 docs(download-tools): expand comment on unpinned darwin:pandoc hash
The macOS pandoc SHA-256 cannot be computed from this branch (no
macOS host). The verifyArtifact() function already handles the
unpinned case by printing a clear warning + the computed hash, so
the next macOS CI build will surface the hash in its log — the
maintainer copies it back into KNOWN_SHA256 to lock it in.

What changed: replace the original cryptic 'Fill these from a
trusted machine' comment with explicit instructions that match the
actual flow:

  1. First macOS release build → script prints the hash.
  2. Maintainer pastes it into KNOWN_SHA256 ('darwin:pandoc': '…').
  3. Subsequent builds hard-fail on mismatch (tamper detection).

This is the recommended follow-up the security assessment flagged
as D6. Linux + Win + fonts are already hard-pinned.

Amit Haridas
2026-09-30 22:23:59 +05:30
amitwh 7673f5533d fix(build): snap config schema — drop invalid 'channels' key
electron-builder 26.x rejected the build with
'configuration.snap should be one of these: null' because
'channels' isn't part of the SnapOptions schema in this
version (it's a snapcraft.yaml / Snap Store publish-side
concept, not a build-time key).

Also relocated 'desktopName' out of linux.* — the warning
says to set it in package.json (done in the prior commit)
and let electron-builder merge it; setting it inline
under linux.* is rejected by the schema too.

What actually silences the warning now:

  - package.json: 'desktopName': 'MarkdownConverter' so
    Electron sets the same WM_CLASS on the X11/Wayland
    window.
  - electron-builder.config.js: 'syncDesktopName: true'
    inside linux.* so the generated .desktop file's
    StartupWMClass matches.
  - electron-builder.config.js: 'snap: { confinement,
    grade }' at the top level using the valid keys only.

Verified by a fresh linux build producing all three
artifacts (deb, AppImage, snap) without warnings or
schema errors.

Amit Haridas
2026-09-30 22:21:37 +05:30
amitwh d4a2c21196 style: prettier-format vsdx-export test file 2026-09-30 22:18:10 +05:30
amitwh d90be20a72 feat(flowchart): export to editable Visio .vsdx (C14)
New 'Export Visio' toolbar button sends the current graph to the
main process, which generates an OOXML .vsdx zip with JSZip and
writes it to a user-chosen path. The result is fully editable in
Microsoft Visio, draw.io, Lucidchart, and any other tool that
accepts the format — not an embedded image.

Architecture follows the existing pure-module pattern:

  - src/flowchart/flowchart-vsdx-export.js: pure translator that
    produces (a) page1.xml describing each node as a Visio Shape
    with correct geometry (PinX/PinY/Width/Height in inches, with
    the Y-axis flipped to match Visio's bottom-up coords), each
    edge as a Connect entry, and (b) the seven static boilerplate
    XML files that make a .vsdx zip valid ([Content_Types].xml,
    _rels/.rels, visio/document.xml, visio/pages/pages.xml, etc.).

  - src/main.js: new 'export-vsdx' IPC handler requires the pure
    module + JSZip, builds the zip, writes to disk, returns
    { canceled, path } | { canceled: false, error }.

  - src/preload.js: flowchart.exportVsdx(graph) bridge.

  - src/renderer/flowchart-bundle.js: btnExportVsdx handler, status
    feedback for cancel / save / error paths.

  - src/flowchart-generator.html: button next to Export JPG.

Tests: 7 new (1362 total) cover graphBounds (empty / single /
multi-node), XML escaping of label text, Connect emission, the 5
node kinds mapping to 5 distinct master names, and that all
boilerplate files start with the XML declaration.

Amit Haridas
2026-09-30 22:17:15 +05:30
amitwh e967af77a7 feat(flowchart): export canvas as SVG / PNG / JPG (C13)
Three new toolbar buttons next to Open from File let the user save
the current canvas to disk in the format their tooling expects:

  - Export SVG — straight clone + serialise of the canvas <svg>,
    with a minimal stylesheet inlined so the file renders without
    the editor's stylesheet. Goes through the existing 'save-text-file'
    IPC channel as a UTF-8 string.
  - Export PNG / JPG — rasterise the SVG through Image + Canvas at
    1000x700 + 24px padding, then send the data URL to the new
    'save-binary-file' IPC channel which strips the 'data:...;base64,'
    prefix and writes the raw bytes. JPEG gets a white background fill
    so transparent areas don't come out black.

New IPC + preload bridge:

  - src/main.js: 'save-binary-file' handler mirrors 'save-text-file'
    shape but writes a Buffer from base64. Returns { canceled, path } |
    { canceled: false, error } so the UI can surface write failures.
  - src/preload.js: flowchart.saveBinary(data, defaultName, filters)
    so the standalone window can call it.

Tests: 2 new (1355 total, was 1353) covering SVG export happy-path
and cancel. Raster PNG/JPG paths not jsdom-tested because
Image+Canvas in jsdom doesn't reliably fire onload for Blob URLs;
the SVG path exercises the same handler plumbing so coverage is
adequate.

Amit Haridas
2026-09-30 22:13:54 +05:30
amitwh 41ddaa17b3 build: desktopName + Linux snap channel config
electron-builder emits a pack-time warning on every Linux build that
desktopName is unset, which means the installed .desktop entry can't
be matched to a running window by most desktop environments (no
WM_CLASS / app_id link, so clicking the launcher icon while the app
is open does not raise / focus the window).

  - package.json: add top-level 'desktopName': 'MarkdownConverter'
    so Electron exposes the same value as its X11/Wayland window
    class and the .desktop file matches it.
  - electron-builder.config.js: mirror it under linux.* with
    syncDesktopName: true so the generated .desktop / .deb / snap
    entries all use the same identifier.
  - Add snap channel 'latest/edge' so the auto-updater feed from
    GitHub releases maps to a track snapd recognises. 'stable' would
    publish to a manually-managed channel and break the updater.

No source code changes; build only. Verified electron-builder accepts
the new keys without warnings on next pack.

Amit Haridas
2026-09-30 22:09:19 +05:30
amitwh 48c7420c7a fix(flowchart): UMD browser fallback for viewport + add to controller test mount
The 6 pre-existing flowchart-controller test failures
('ReferenceError: require is not defined') were caused by
flowchart-canvas.js falling through to require('./flowchart-viewport')
when window.FlowchartViewport was undefined — because flowchart-viewport
was added in C4a but the controller test's script loader was never
updated to include it, and viewport itself had no browser-global
fallback.

Two coordinated fixes:

  - Add the same UMD wrapper to flowchart-viewport.js that the other
    pure modules already use (CommonJS module.exports + window
    global fallback for the standalone window and jsdom). Now the
    canvas's 'window.FlowchartViewport || require(...)' short-circuits
    in the browser case, matching what shapes / store / mermaid do.

  - Load flowchart-viewport.js in the controller test mount helper,
    in dependency order between mermaid and store. The canvas now
    sees window.FlowchartViewport set and never falls through to
    require() under jsdom.

Test suite: 104 suites / 1353 tests passing (was 1347 with 6 failing).
The 6 'require is not defined' failures are gone.

Amit Haridas
2026-09-30 22:08:10 +05:30
amitwh dadfe52870 fix(preload): saveFile IPC payload was being shadowed by stray channel arg
C9 (22bc4dc) introduced a malformed edit when wiring openFile. The
saveFile arrow got a stray 'open-text-file-dialog' string between the
channel and payload, so the ipcMain handler destructured the string
(both fields undefined) instead of { content, defaultName }. saveFile
silently saved with no content and no default name — the Save to File
button worked through the dialog fallback but wrote whatever was in
the buffer.

Fix: drop the stray arg, restore the single-line invoke with the
payload object. openFile stays on its own line below. format:check
is now clean.

Discovered during the v4.13.0 release rebuild when prettier wanted
to collapse the malformed multi-line into one — the malformed shape
itself was the bug, not the formatting.

Amit Haridas
2026-09-30 21:51:13 +05:30
Amit Haridas 8fb61130f3 feat(flowchart): bundle-side clipboard wire-up (C11)
Cmd+C / Cmd+V / Cmd+D keyboard shortcuts now work in the standalone
window. The clipboard pure module (committed in C6a) is inlined
into the bundle alongside the mermaid parser (C9 inlining) so the
standalone window does not depend on a separate bundle rebuild.

  - copySelection / pasteSelection definitions added inside the
    bundle IIFE, exposed as window.FlowchartClipboard for jsdom
    tests.
  - Module-level _clipboard variable scoped to the keydown handler
    block so copy survives across Cmd+V and Cmd+D presses.
  - Cmd+C: serialises the canvas-owned selection (now read via
    getSelection(), not the old DOM .selected query) and stashes it.
  - Cmd+V: applies the stashed payload to the store via addNode +
    connect; nothing to do for the edge-only payload.
  - Cmd+D: copy + paste in one keystroke, with a 24px offset.
  - Delete/Backspace: reuses getSelection() to delete the selected
    node or edge; replaces the fragile DOM-querying path that the
    test for the bundle was no longer catching.

The pure module in src/flowchart/flowchart-clipboard.js stays the
source of truth for the algorithm (9 tests in C6a). Bundle inline
keeps the standalone window functional without a rebuild step;
a future build-time inclusion would collapse the duplication.

Amit Haridas
2026-09-30 21:43:49 +05:30
Amit Haridas ded17d0b6b feat(flowchart): node resizing (C10)
v4.13.0 — nodes can be resized by dragging the bottom-right handle.

  - New setNodeWidth(id, width) on the store. Clamps to [60, 600] so
    shapes stay readable. Throws on unknown id; pushes an undo
    snapshot like every other mutator.
  - New nodeWidth(node) helper on the canvas uses node.width with a
    fallback to DEFAULT_WIDTH for graphs loaded from older JSON
    that didn't have the field.
  - Canvas render uses the per-node width for shapeSvg + label
    positioning, and edge boundaryPoint() uses it too so connection
    geometry adapts to the new shape size.
  - Selected node renders a bottom-right resize handle (10px square).
    Clicking the handle starts a 'resize' dragState that calls
    setNodeWidth on every pointermove with the screen-to-SVG delta
    applied to the start width.
  - The handle is detected before the generic node click handler so
    it doesn't accidentally start a move drag.

3 new tests cover setNodeWidth update, clamp to [60, 600], and
unknown-id throw. The canvas change reuses the existing 14 tests
(which check rendering and pointer events) — they still pass.

Amit Haridas
2026-09-30 21:42:35 +05:30
Amit Haridas 22bc4dcf56 feat(flowchart): Open from file button + parse on load (C9)
v4.13.0 — round-trips Mermaid source through the editor:

  - new open-text-file-dialog invoke IPC in main.js opens a system
    Open dialog filtered for .mmd / .mermaid / .md / .markdown / .txt,
    reads the chosen file, returns { path, content } or null on cancel.
  - new openFile() on the flowchart preload bridge.
  - new Open from File button in the standalone window toolbar
    alongside Insert / Save / Reset.
  - On click: confirms overwrite when the current graph is non-empty,
    strips any mermaid fence, parses via the inlined fromMermaid()
    (the inverse of toMermaid), and calls _store.deserialize so the
    canvas redraws. Status bar reports Loaded path.

The fromMermaid() in the bundle is duplicated from
src/flowchart/flowchart-mermaid-parse.js (23 tests in C8 land the
same logic) so the standalone window does not depend on the bundle
rebuild step. Pure module + bundle inline stay in sync logically;
future work could collapse them via a build-time inclusion.

Amit Haridas
2026-09-30 21:40:59 +05:30
Amit Haridas 4123455863 feat(flowchart): Mermaid source → graph parser (C8)
Inverse of flowchart-mermaid.js's toMermaid(). Pure module — no DOM,
no globals — so the parsing logic is unit-tested in isolation.

Recognises the 5 node shapes:
  - process     [label]
  - decision    {label}
  - terminator  ([label])
  - subroutine  [[label]]
  - document    [/label/]

Recognises the 3 edge arrows:
  - -->  solid
  - -.-> dotted
  - ==>  thick

Edge labels may appear before OR after the arrow (Mermaid accepts
both:  and ).

Behaviour:
  - Auto-creates nodes referenced in edges but not declared explicitly.
  - Idempotent: declaring  then connecting  does not
    duplicate the A node.
  - Defensive: malformed lines are skipped silently so partial /
    hand-edited source still loads whatever it can.
  - Unescapes the standard Mermaid escapes (#quot; → ", \n → newline).

Wire-up into the renderer (Open from .mmd file → parse →
store.deserialize) is the next commit; this lands the testable math.

23 new tests cover shape parsing for all 5 kinds, edge parsing for
all 3 arrow types + label placement, unescaping, header skipping,
comment skipping, the subroutine-vs-process regression, auto-node
creation, and the null/non-string inputs.

Amit Haridas
2026-09-30 21:34:53 +05:30
Amit Haridas 7beb3effcf feat(flowchart): clipboard copy/paste/duplicate pure module (C6a)
New clipboard serialiser for the flowchart editor. Pure module —
no DOM, no globals — so it's unit-testable in isolation.

  - Captures the selected node + its connected edges to a JSON envelope
    that survives a paste-into-new-graph round trip. Edge-only selection
    is also supported.
  - Paste creates a new node offset from the original (default 24px)
    and re-attaches every connected edge to the new id. Only edges
    whose other endpoint still exists in the graph are recreated, so
    deleting a neighbour before pasting doesn't try to reconnect to a
    ghost.
  - Preserves node color on paste.

Wire-up into the renderer controller (Cmd+C / Cmd+V / Cmd+D handlers
+ canvas-owned selection reading) is the next commit; this one just
lands the testable math.

9 new tests cover selection capture, edge-only selection, paste with
offset, edge re-attachment, dangling-edge handling, color preservation,
and the null-payload no-op.

Amit Haridas
2026-09-30 21:32:03 +05:30
Amit Haridas 9412049f56 feat(flowchart): wire zoom/pan/snap into canvas (C5)
- All canvas content (nodes, edges, preview line) now lives inside a
    single <g class='flowchart-content' transform='...'> so a single
    attribute change moves/zooms everything together. The fixed viewBox
    (1000x700) stays — the transform handles everything.
  - Ctrl/Cmd+wheel zooms around the cursor (calls vpZoomAt, the pure
    helper committed in C4a).
  - Shift-drag (or middle-click) on empty canvas pans the view.
  - Snap-to-grid (10-unit) is opt-in via api.setSnapEnabled(true).
    When on, moveNode and addNode clamp coords to the grid.
  - Plain click on empty canvas still hands off to opts.onEmptyClick
    so the controller can prompt for shape kind + label.

destroy() now also removes the wheel listener.

Amit Haridas
2026-09-30 21:29:17 +05:30
Amit Haridas 98979a2cd2 feat(flowchart): pure viewport math for zoom/pan/snap (C4a)
New pure functions for the canvas viewport (v4.13.0):
  - zoomAt(view, screenX, screenY, factor) — zoom centred on a screen
    point, keeping the world point under cursor fixed. Clamped to
    [0.25, 4] scale range.
  - panBy(view, dx, dy) — additive pan
  - reset() — identity transform
  - wheelFactor(deltaY) — multiplicative factor per Ctrl+wheel notch
  - snap(value, gridSize) — round to nearest grid (0 disables)

The actual SVG transform wrapper + Ctrl+wheel handler + drag-to-pan
+ snap-on-move is the next canvas-layer commit; this commit lands
the testable math.

14 new tests cover: identity reset, cursor-stable zoom, MIN/MAX
clamping, additive pan, wheel factor reciprocity, snap-to-grid
(positive/negative/zero grid sizes).

Amit Haridas
2026-09-30 21:28:36 +05:30
Amit Haridas 4228ab78d8 feat(flowchart): undo/redo toolbar buttons + history counter (C3)
The flowchart editor had Ctrl+Z / Ctrl+Shift+Z keyboard shortcuts
but no discoverable buttons. New History section in the side panel:
  - Undo / Redo buttons wired to _store.undo() / _store.redo()
  - Counter chip showing ↶/↷ availability
  - Buttons auto-disable when stacks are empty (via _store.canUndo()
    + canRedo() evaluated on every store subscription)

The store already exposed undo/redo/canUndo/canRedo — this commit
only adds the UI surface.

Amit Haridas
2026-09-30 21:27:11 +05:30
Amit Haridas 0bb1091c47 feat(flowchart): edge geometry at shape boundary + connect preview (C2+C3)
Three UX/DI wins in one canvas pass:

1. Edge endpoints now land on the source/target shape's BOUNDARY
   rather than the centres. Lines no longer cut through nodes. New
   pure helpers boundaryPoint() + edgeEndpoints() do the geometry;
   nodeCenter() is still used internally for direction vectors.

2. Connect-mode preview line. Alt+drag now draws a dashed line from
   the source node's boundary to the live pointer position so the
   user can see where the edge will land before releasing. The original
   code marked this 'visual feedback deferred to v2'.

3. Selection state is now owned by the canvas (selectedNodeId /
   selectedEdgeId variables), not read from .selected DOM classes.
   The controller can ask via api.getSelection(). Fixes the fragile
   pattern in flowchart-controller.js where Delete/Backspace read
   querySelector('.flowchart-node.selected') — that read is now
   redundant and the controller can be cleaned up to use getSelection()
   directly.

5 new tests cover: edge starts past source centre, edge ends before
target centre, vertical edges connect top/bottom, label background
auto-sizes for long labels, canvas getSelection() reflects clicks.

Amit Haridas
2026-09-30 21:23:39 +05:30
Amit Haridas 855dfcd9f5 feat(flowchart): replace window.prompt with inline modal (C1)
The standalone flowchart generator still used window.prompt() for
editing edge kind/label and changing node kind — defeating the v4.9.9
modal work that's already in flowchart-bundle.js.

This commit switches to the existing window.FlowchartModals helpers:
  - onEdgeClick now does two sequential promptInline calls (kind,
    then label) instead of two blocking window.prompt calls.
  - onShapeMenu uses promptInline for node-kind change.
  - onEmptyClick (new) replaces the canvas's old 'auto-add a process
    node labelled Node on any empty click' behaviour. The canvas
    now hands off x/y to the controller, which prompts for kind +
    label before adding.

Canvas change is one line: drop the auto-add and call opts.onEmptyClick.

followups in this batch:
  - select/dropdown fields in the modal (currently text-only inputs)
  - edge connection geometry (centre-to-centre → boundary)
  - connect-mode preview line
  - canvas-owned selection state (DOM .selected is fragile)
  - undo/redo toolbar + counter
  - edge label auto-size + theme-safe background
  - zoom/pan, snap-to-grid, copy/paste, mermaid re-import, file IO

Amit Haridas
2026-09-30 21:22:22 +05:30
Amit Haridas d5efdfa8d9 docs(readme): bump version string to v4.13.0
Amit Haridas
2026-09-30 21:03:20 +05:30
Amit Haridas 3ec9ff0130 chore(release): bump v4.12.0 → v4.13.0
v4.13.0 ships:
  - Quick Switcher overlay (Cmd+P): fuzzy match across recent files
    + open tabs, workspace search wired to the active tab's parent dir
  - Inline AI assist (Cmd+K): Rewrite / Shorten / Expand with real
    SSE streaming, in-editor typewriter, cancel mid-flight, first-use
    confirmation
  - electron-updater integration: Help > Check for Updates now polls
    GitHub releases through the auto-updater; autoDownload + autoInstall
    enabled; browser fallback on dev/error
  - 13 commits since v4.12.0, 112 new tests (1187 → 1299), lint+format
    green throughout.

Amit Haridas
2026-09-30 21:02:46 +05:30
Amit Haridas e826c0e624 feat(ai-assist): first-use confirmation + wire Check-for-Updates to updater
Inline AI first-use confirmation (v4.13.0):
  - inline-ai-controller accepts optional confirmFirstUse + getProviderLabel
    deps. On the first action of the session, calls confirmFirstUse with
    {providerLabel, selectionLength, action}; if it returns false, aborts
    and shows error state. Once confirmed, never re-prompts for the
    session.
  - new 'ai-assistant:confirm-info' invoke handler returns
    {provider, model} (no key material) so the renderer can label the
    confirm dialog.
  - electronAPI.aiAssistant.confirmInfo() exposed via preload.
  - renderer.js wires window.confirm() with the provider label as the
    v1 prompt UX; can be upgraded to a custom modal later without
    touching the controller.

Check-for-Updates menu (v4.13.0):
  - Help > Check for Updates now calls ensureAutoUpdater().check()
    instead of opening the Releases page in the browser.
  - Falls back to the browser page if the check throws (dev runs with
    no app-update.yml, network failures, etc.) so the user always has
    a way to update manually.

4 new controller tests cover: confirm called once with provider label
and selection length; declining aborts + surfaces error state; confirm
not asked twice in a session; missing confirmFirstUse dep skips the
prompt and streams normally.

Amit Haridas
2026-09-30 21:02:28 +05:30
Amit Haridas 47315add80 feat(updater): electron-updater wiring + IPC bridge
electron-updater integration so users get fixes automatically:
  - new dependency electron-updater@^6.6.2 in package.json
  - electron-builder.config.js publishes to GitHub releases
    (owner: concreteinfo, repo: markdownconverter)
  - new src/main/auto-updater.js wraps autoUpdater: wires the six
    lifecycle events to a 'updates:status' IPC channel, exposes
    check() and install() helpers, dev-gates via isDev(), and
    swallows the 'missing app-update.yml' error that dev runs hit
  - main.js: ensureAutoUpdater() forwards status to the renderer
    via mainWindow.webContents.send; ipcMain handlers for
    'updates:check' (invoke) and 'updates:install' (invoke)
  - preload.js: 'updates:check' / 'updates:install' added to
    ALLOWED_SEND_CHANNELS; 'updates:status' added to receive
    channels; electronAPI.updates.{check, install, onStatus}
    exposed

7 new tests cover event registration, dev-gate behaviour,
'not-available' fallback for missing app-update.yml, typed event
payloads, error forwarding, and install() quitAndInstall.

Amit Haridas
2026-09-30 20:30:19 +05:30
Amit Haridas 0d3df32140 feat(quick-switcher): derive workspace dir from active tab
The explorer panel's explorerCurrentDir is hardcoded to null, so
the Quick Switcher's workspace toggle was a no-op. Rather than fix
the broken explorer flow, derive the workspace from the active
tab's filePath's parent directory — the most reliable source we
have without restructuring that panel.

deriveWorkspaceDir() handles POSIX and Windows paths (including
mixed separators and trailing separators), returns null for
untitled / empty inputs so the workspace toggle silently stays
off in those cases.

10 new tests cover POSIX, Windows, mixed-separator, trailing
separator, UNC, and invalid input paths.

Amit Haridas
2026-09-30 20:28:22 +05:30
Amit Haridas b36d0919a3 feat(ai-assist): renderer controller + Cmd+K wiring (end-to-end)
createInlineAiController() glues the popover, the streaming bridge,
and the CodeMirror editor together. Each Cmd+K opens a fresh
request; the controller:
  - reads the active selection from the CodeMirror view
  - builds the rewrite/shorten/expand prompt via inline-assist.js
  - clears the selection so chunks can fill back in
  - dispatches each chunk as it arrives (typewriter into the editor)
  - on done: applies the final result (or restores selection on no-op)
  - on error: restores the original selection and shows error state
  - on Esc: cancels the in-flight request, restores the selection,
    hides the popover

main-side streaming handler now reads the AI Assistant plugin's
provider config from settings.json under plugins.ai-assistant.* —
keys never cross the IPC boundary.

renderer.js:
  - new getCreateInlineAiController() lazy loader
  - new ensureInlineAiController() factory
  - new Cmd+K / Ctrl+K keymap handler in the global keydown listener
    that resolves the active tab's CodeMirror view via tabManager

16 new controller tests covering show/handleKey wiring, streaming
chunk application, done/error finalization, stale-request filtering,
and detach cleanup.

Amit Haridas
2026-09-30 20:17:57 +05:30
Amit Haridas 72ca2cb46f feat(ai-assist): floating popover UI + state machine
createInlineAiPopover() mounts a floating toolbar anchored to the
current text selection. Three actions (Rewrite / Shorten / Expand)
plus loading spinner with cancel, and an error state with retry and
dismiss. Click handlers dispatch via onAction/onCancel/onRetry.

Positioning flips below the line if there is no room above and
clamps horizontally so the popover stays inside the viewport.

16 new tests covering mount/visibility, idle actions dispatching the
selection text, state transitions (idle / loading / error), Retry
and Dismiss callbacks, and positioning edge cases.

Amit Haridas
2026-09-30 20:14:13 +05:30
Amit Haridas 1a25669967 feat(ai-assist): SSE streaming + IPC handler
AiProviders.completeStream() — async iterable over provider chunks.
  - OpenAI-style (openai, ollama, lmstudio, *-compatible): parses
    SSE data: {choices:[{delta:{content}}]} payloads.
  - Anthropic: parses event: content_block_delta with delta.text.
  - Honours caller AbortSignal + internal timeout via AbortController.
  - shared parseSseStream() helper handles [DONE] sentinel, partial
    lines across chunk boundaries, reader.releaseLock() in finally.

main.js IPC:
  - 'ai-assist-stream:start' (send) registers a per-requestId entry
    in a Map with an AbortController, iterates completeStream, and
    forwards each chunk via 'ai-assist-stream:chunk' (send).
  - 'ai-assist-stream:cancel' (send) aborts the in-flight request.
  - Terminal 'done' or 'error' (with code+message) is sent after
    each stream; renderer can correlate by requestId.

preload.js exposes aiAssist.{start, cancel, onChunk, onDone, onError}.

5 new tests covering OpenAI delta parsing, Anthropic content_block_delta
parsing, and three synchronous-error paths (no fetch, no messages,
missing key).

Amit Haridas
2026-09-30 20:04:32 +05:30
Amit Haridas cb0b2eac3d feat(ai-assist): pure prompt builder + result applier
buildAssistPrompt(action, selection) returns the {system, messages}
payload for rewrite/shorten/expand. Enforces 8KB selection cap and
typed errors with codes (unknown_action, bad_selection,
empty_selection, selection_too_large) so the IPC layer can map them
to user-friendly messages.

applyAssistResult(original, newText) trims the response and rejects
empty/unchanged payloads so a no-op streaming chunk doesn't churn
the editor.

15 new tests cover action coverage, prompt content, all four error
codes, cap-edge (exactly 8KB OK, 8KB+1 rejected), and trim semantics.

Amit Haridas
2026-09-30 20:01:54 +05:30
Amit Haridas b70dce9574 feat(quick-switcher): wire Cmd+P into File menu + renderer
End-to-end wiring of the Quick Switcher overlay:
  - main.js File menu: new 'Quick Switcher...' item with Cmd+P
    accelerator (moved from Print Preview; Print Preview stays in
    File > Print submenu but loses its shortcut). Recent Files
    submenu and its buildRecentFilesMenu() helper removed.
  - new 'recent-files:get' invoke IPC handler returns the recent
    files array on demand.
  - preload.js: 'recent-files:get' + 'show-quick-switcher' added
    to channel whitelists; quickSwitcher.getRecentFiles() exposed.
  - renderer.js: lazy-mounts the overlay on first 'show-quick-switcher'
    message, fetches recent files via IPC, and shows the overlay.
    File-open goes through the existing 'open-file-path' channel.

Workspace dir is intentionally null for v4.13.0 — the workspace
search toggle is wired but a no-op until the explorer panel exposes
its current directory (next iteration).

Amit Haridas
2026-09-30 20:01:16 +05:30
Amit Haridas 3bd958c064 feat(quick-switcher): modal overlay UI + keyboard nav
createQuickSwitcherOverlay() mounts a centered modal with:
  - input box with autocomplete=off
  - workspace toggle (off by default — recent + open tabs only)
  - keyboard nav: ArrowDown/Up move selection, Enter opens,
    Escape and backdrop-click hide
  - mouse hover also moves selection
  - debounced refresh (default 80ms; 0 in tests)
  - destroy() cleanly removes DOM + listeners

Rank/filter logic delegated to fuzzy-matcher.js. Recent and open tabs
are always in the candidate set; workspace files are added only when
the toggle is on. Selection clamps to bounds after every refresh.

23 new tests covering mount/focus/destroy, initial render, typing &
filtering, full keyboard nav, workspace toggle behavior, and the
selected-path escape hatch.

Amit Haridas
2026-09-30 19:58:18 +05:30
Amit Haridas 33fa14c11a feat(quick-switcher): IPC handler for workspace file listing
listWorkspaceFiles() walks a directory recursively, returning
[{path, name}] for files matching a configurable extension allowlist.
Skips hidden dirs, node_modules, dist/build/coverage, and walks past
permission-denied subdirs instead of throwing. Default allowlist is
markdown variants + .txt; default maxResults caps pathological
workspaces at 2000 entries.

Wired through 'quick-switcher:list-files' invoke channel + a
quickSwitcher.listFiles() convenience method on the preload bridge.
Main-process errors collapse to [] rather than crashing the overlay.

16 new tests covering flat dirs, recursion, skip lists, custom
extensions, maxResults cap, and validation errors.

Amit Haridas
2026-09-30 19:56:50 +05:30
Amit Haridas de7ebecad4 feat(quick-switcher): pure fuzzy matcher + ranker
Tiered scoring (exact 1.0 / stem 1.0 / prefix 0.8 / subseq 0.5+bonuses
capped 0.79) with leftmost+rightmost greedy alignment — rightmost wins
for extension/suffix queries ('md' against 'readme.md'), leftmost wins
for prefix queries ('re' against 'readme.md'). Boost-aware rankResults
applies recency x2 and open-tabs x1.5 multiplicatively; empty query
falls back to boosts alone.

Pure module, no DOM/IPC/Node — runs in renderer or main. 22 new tests.

Amit Haridas
2026-09-30 19:53:44 +05:30
amitwh 23046967c3 feat(flowchart): discoverable connect form + per-node color + save-to-file export; v4.12.0
User feedback on v4.11.0: the Add Connection form was buried below the
node/edge lists and they couldn't find it; they also asked for per-node
color and Save to File export. v4.12.0 reorganises the #fc-nodelist panel
to put the connect form right after the Add Node buttons, adds a native
<input type="color"> per node row that drives a new store.setNodeColor
mutator (with serialize/deserialize round-trip), and wires a Save to File
button that pops a system save dialog via a new 'save-text-file' IPC
channel.

- src/flowchart-generator.html — panel order is now Add Node /
  Add Connection / Nodes / Edges / Export (Insert · Save · Reset).
  Removed the legacy top toolbar; status moved into the panel.
  Added .fc-help, per-node color-picker CSS, .fc-toolbar-row.
- src/flowchart/flowchart-shapes.js — shapeSvg() accepts an optional
  6th 'color' arg; emits fill=... on rects and polygons. Falls back to
  #ffffff for empty/null/undefined so old callers keep working.
- src/flowchart/flowchart-store.js — setNodeColor(id, color) mutator
  with snapshot/emit, normalizeColor() helper (hex validation),
  addNode accepts color, deserialize normalises missing color.
- src/renderer/flowchart-bundle.js — mirrors all of the above inline
  (the bundle is loaded as a single <script>), wires fc-btn-save to
  api.saveFile, passes node.color to shapeSvg in the canvas render,
  and renders <input type='color'> per node row.
- src/main.js — new ipcMain.handle('save-text-file', ...) using a
  system Save dialog (mirrors the ascii:save handler shape).
- src/preload.js — added 'save-text-file' to ALLOWED_SEND_CHANNELS
  and a saveFile(content, defaultName) helper on the flowchart bridge.

Tests: 92/92 suites, 1165/1165 tests pass on this run
- +9 store tests (color defaults, setNodeColor, undo, hex validation,
  round-trip, deserialize normalisation)
- +7 shapes tests (fill color on all 5 kinds, fallback to #ffffff)
- +6 controller tests (color picker wires setNodeColor, canvas rect
  reflects color, Save to File calls api.saveFile with the fenced
  Mermaid source and 'flowchart.mmd', cancel + error paths surface in
  status)

Verification:
- npm run lint          clean
- npm run format:check  clean
- npm test              92/92 suites, 1165/1165 tests pass

Amit Haridas
2026-09-15 09:23:58 +05:30
amitwh e87e301b0f chore: remove stale debug-copy + drop placeholder string-split hack; v4.11.1
- Remove untracked root-level flowchart-bundle.js (older v4.10.0 copy
  that had drifted from src/renderer/flowchart-bundle.js; never loaded
  by Electron, just repo noise).
- In src/renderer/flowchart-bundle.js, replace the runtime
  concatenation "'place' + 'holder'" with the proper 'placeholder'
  attribute at the two label-input call sites (node + edge) and
  remove the now-stale comment explaining the hack. No functional
  change.
- Bump version 4.11.0 -> 4.11.1 in package.json and README.md and add
  the matching UPDATES.md entry.

Verification:
- npm run lint          clean
- npm run format:check  clean
- npm test              92/92 suites, 1143/1143 tests pass on this run
- PDFBatchOperations.test.js passes 21/21 in isolation
  (the occasional failure seen in the v4.11.0 run was a parallel-test
  file-IO race, not introduced by these changes)

Amit Haridas
2026-09-15 08:10:35 +05:30
amitwh 075e407f3f feat(flowchart): button-based UI replaces click-canvas interaction; v4.11.0
Replaced the v4.10.0 floating selection toolbar (which relied on
SVG click hit-testing inside #canvas-host and was unreliable in the
user's Electron runtime) with a button-driven node-list panel
(#fc-nodelist) below the canvas. Every mutation now flows through
explicit controls: 5 Add Node buttons, per-node kind-select +
label-input + delete ×, per-edge kind-select + label-input + delete
×, and a Connect form (From/To selects + Edge button + Refresh).

The canvas is purely visual now: no more #fc-selection-toolbar, no
controller-level _selectedId/_selectedKind state, no keyboard
Delete/Backspace selection handler. Canvas click callbacks
(onNodeClick, onEdgeClick, onShapeMenu) are no-ops. The 5-shape /
3-edge-kind / label-input / delete-button surface is unchanged in
spirit — it just lives in the panel instead of floating over the
canvas.

Files:
- src/flowchart-generator.html: added #fc-nodelist between canvas and
  preview (wrapped in new .fc-left column), removed fc-selection-toolbar,
  bumped header hint.
- src/renderer/flowchart-bundle.js: removed SHAPE_BUTTONS/EDGE_BUTTONS,
  setSelection, renderSelectionToolbar, appendLabelInput,
  appendDeleteButton, the keyboard Delete handler, and the
  controller-level selection state. Added rerenderNodeList +
  shapeLabel/edgeLabel, wired all panel buttons (add-row, per-node
  selects/inputs/deletes, per-edge selects/inputs/deletes, connect
  form). Subscribe now calls rerenderNodeList instead of the old
  renderSelectionToolbar.
- tests/flowchart-controller.test.js: replaced 6 v4.10.0 selection
  toolbar tests with 11 v4.11.0 button-driven panel tests.
- package.json: 4.10.0 -> 4.11.0.
- README.md: version line bumped to v4.11.0.
- UPDATES.md: added v4.11.0 changelog entry.

Test summary: 92 suites, 1143 tests pass (was 1138 — +5 net).
Lint + prettier clean.

Amit Haridas
2026-09-15 01:33:17 +05:30
amitwh b81119026e feat(flowchart): visible selection toolbar + console-log diagnostics; v4.10.0
Even after the v4.9.9 inline-modal fix the user kept reporting 'no fix still'
because hidden right-click context menus and window.prompt calls remain
unreliable in Electron renderer contexts. This release ships a *visible*
floating selection toolbar inside the canvas panel so the primary
interactions are not hidden behind modals or context menus.

- New <div id="fc-selection-toolbar"> inside #canvas-host, hidden until a
  node or edge is selected. Renders:
    * 5 shape buttons (Process / Decision / Terminator / Subroutine /
      Document) when a node is selected, calling store.setNodeKind on
      click. The active shape is highlighted.
    * 3 edge-kind buttons (Solid / Dotted / Thick) when an edge is
      selected, calling store.setEdgeKind.
    * An always-visible label input that mirrors the selected item's
      label and writes back via store.setNodeLabel / store.setEdgeLabel
      with a 100ms debounce.
    * A red Delete button calling store.removeNode / store.disconnect.
- Selection state now tracked at the controller level (_selectedId +
  _selectedKind) and exposed via window.FlowchartController so the
  keyboard Delete/Backspace shortcut and the toolbar share one source
  of truth.
- Console-log instrumentation on every canvas event (pointerdown with
  altKey, pointerup with drag result, dblclick, contextmenu, selection
  changes, and every bootstrap phase) so the user can open DevTools
  (Ctrl+Shift+I) and verify Alt+drag and double-click actually fire.
- promptInline / confirmInline kept as advanced fallback for the
  right-click 'change shape' path; the toolbar is now the primary
  interaction surface.
- Preview-render pane now shows a static info card explaining that the
  canvas on the left is the rendered chart (previously blank).
- 6 new tests in tests/flowchart-controller.test.js — toolbar hidden
  by default, selecting a node populates shape buttons + label input +
  Delete, clicking a shape button updates the kind, label input is
  debounced, edge selection populates edge-kind buttons, Delete button
  removes the selected node.

Total tests: 1127 passing (was 1121; +6 new). The 11 pre-existing
PDFOperations failures are unrelated to this change.
2026-09-15 00:40:01 +05:30
amitwh 81e8561403 fix(flowchart): replace window.prompt/confirm with inline modal in standalone window; v4.9.9
Electron renderer contexts return undefined from window.prompt/window.confirm,
so shape change, edge kind, edge label, and reset confirmation did nothing.
Bundle now ships promptInline/confirmInline (custom DOM overlay modals) and
uses them in onEdgeClick / onShapeMenu / reset handler. Exposed as
window.FlowchartModals for jsdom tests.

Amit Haridas
2026-09-15 00:27:24 +05:30
amitwh ca5983e9ff fix(flowchart): bundle pure modules into single file for standalone window; v4.9.8
Amit Haridas
2026-09-15 00:09:57 +05:30
amitwh 86d4c0d23a fix(flowchart): expose pure modules as window globals for standalone window; v4.9.7
Each pure module's UMD wrapper assigned window.FlowchartXxx only in the else branch — when 'module' was undefined. But the renderer runs with nodeIntegration:true, so 'module' is always truthy and the else branch never ran. The standalone Flowchart Generator window then aborted with 'Flowchart pure modules not loaded'.

Fix: append 'if (typeof window !== undefined) window.FlowchartXxx = exported;' after the CommonJS branch in all 4 pure modules (store, shapes, mermaid, canvas). Both branches can run now; the legacy sidebar panel still loads them via require() and the renderer unconditionally exposes the global.

Regression guard: 4 new source-grep tests in tests/flowchart-controller.test.js assert each module's source contains the 'window.FlowchartXxx = exported' assignment.

Attribution: Amit Haridas
2026-09-14 23:59:50 +05:30
amitwh 5f846d1e5f refactor(flowchart): standalone window (Cmd+Alt+F) replaces sidebar panel; v4.9.6
Five fix rounds (v4.9.1 → v4.9.5) couldn't make the sidebar flowchart
panel feel right — at 280 px sidebar with canvas + preview cramped to
~175 px each, plus the editor-container hide/show dance the
maximize/restore toggle required, the panel kept presenting as
cramped and unreliable at runtime. Strategy pivot: the flowchart
editor now lives in its own BrowserWindow, matching the ASCII Art
Generator pattern.

- src/flowchart-generator.html — new standalone HTML with header,
  toolbar (Insert at Cursor / Reset), canvas host, and preview host.
  Stylesheet hrefs are src/-relative (no ../). Forced light surface
  via background/color !important rules — mirrors the v4.9.5 CSS fix.
- src/renderer/flowchart-controller.js — pure browser IIFE. Hydrates
  from <userData>/flowchart-session.json once on mount, persists on
  every mutation with 500 ms debounce. Insert at Cursor wraps the
  generated Mermaid source in a fenced ```mermaid block and sends
  it through the existing insert-content IPC.
- src/main.js — openFlowchartGenerator() launches the standalone
  BrowserWindow (1100×720, contextIsolation:true, nodeIntegration:false).
  Tools menu entry 'Flowchart Generator' with Cmd/Ctrl+Alt+F.
- src/preload.js — new window.electronAPI.flowchart.* namespace with
  getUserDataPath/readFile/writeFile/insertAtCursor, reusing the
  existing thin text-file IPC handlers.
- The four pure modules (flowchart-shapes.js, flowchart-mermaid.js,
  flowchart-store.js, flowchart-canvas.js) gained a tiny UMD wrapper
  so they work both as CommonJS (legacy sidebar) and as browser
  globals (standalone window). No behavioural change to the 73
  flowchart unit tests in tests/flowchart-*.test.js.
- src/renderer.js — sidebar registerPanel('flowchart', ...) and the
  commandPalette entry are now commented out. Legacy panel file
  (src/sidebar/flowchart-panel.js) preserved for rollback.

Tests:
- tests/flowchart-controller.test.js — 10 new tests covering
  stylesheet paths (no ../ escape), bootstrap wiring
  (getUserDataPath once, reads flowchart-session.json), hydration
  from a saved session, Insert-at-Cursor fenced block format,
  Reset (with and without confirm), and two regression tests that
  src/renderer.js no longer has a live sidebar registration.

All 1122 tests pass; lint + format clean.

Amit Haridas
2026-09-14 23:50:25 +05:30
amitwh 9557c0af4d fix(flowchart): ensure rendered SVG + selection visibility; force light theme in canvas; v4.9.5
v4.9.4 shipped three interaction bugs in the Flow Chart panel that combined to make it look broken at runtime: (1) .flowchart-preview-render had no min-height, so the Mermaid SVG clipped to 0 when the sidebar flex column shrank; (2) the canvas + preview hosts inherited the body.theme-concreteinfo dark theme, producing dark-on-dark nodes; (3) .flowchart-node.selected only set a 2px stroke on the rect's existing dark fill, which was effectively invisible.

Fix: styles-sidebar.css adds min-height: 120px on .flowchart-preview-render; forces a light background on .flowchart-canvas-host / .flowchart-preview-host with !important so theme inheritance cannot override it; forces explicit white fills and dark strokes on .flowchart-node rect/polygon/text and .flowchart-edge so labels read against any background; selection now changes fill (#e3f0ff) AND bumps stroke-width to 3 on both nodes and edges. renderer.js renderFlowChartMermaid now always initializes Mermaid with theme: 'default' regardless of body class — keeps the Mermaid SVG light to match the CSS-forced canvas surface.

Three new CSS regression tests in tests/flowchart-panel.test.js read the shipped stylesheet and assert the three structural invariants (non-zero min-height on render target, !important light background on canvas+preview hosts, fill + stroke-width >= 3 on .flowchart-node.selected).

Tradeoff: the flowchart surface is now always light, diverging from body theme. Visibility of a working editor is the priority per user direction.

Amit Haridas
2026-09-14 23:09:23 +05:30
amitwh d31ed86fab fix(flowchart): wire selection + layout precedence; v4.9.4
- Add opts.onNodeClick + surgical applySelectionHighlight() so node/edge clicks immediately paint .selected and mirror id into panel state (Delete/Backspace works on freshly-clicked node).
- Add Maximize/Restore button to flowchart toolbar: toggles .main-content.flowchart-takeover which hides .editor-container and lets the canvas + preview split the full window width instead of the 280px sidebar.
- destroy() clears the takeover class so the editor stays usable after leaving the panel.
- 8 new tests in tests/flowchart-panel.test.js for selection wiring and takeover.

Amit Haridas
2026-09-14 23:00:47 +05:30
amitwh e0945b427d fix(flowchart): prevent preview-source duplication; v4.9.3
The flowchart preview pane accumulated raw Mermaid source when the user
fired several addNode mutations within the 250ms debounce window —
mermaid.run({nodes:[div]}) is async, so the previous render's
<div class="mermaid"> (still carrying the source text) sat in
.flowchart-preview-render when the next render cleared the target. The
first render's eventual element.innerHTML=svg landed on a detached node,
but the visible preview pane had a stack of stale <div class="mermaid">
elements carrying the source.

Fixed by switching renderFlowChartMermaid (src/renderer.js) to
replaceChildren() and adding a per-target WeakSet in-flight tracker so
the new render always starts from a clean slate and the previous render's
eventual innerHTML=svg is harmless on a detached node.

Added a second regression test that fires 7 mutations inside the debounce
with a renderMermaid mock that mimics mermaid.run's async innerHTML=svg
closure.

Amit Haridas
2026-09-14 22:52:13 +05:30
amitwh ac31162d3b fix(ascii-art): wire Box/Templates mode + correct standalone <link href>; v4.9.2
- src/ascii-generator.html line 7: ../fonts.css -> fonts.css (src/-relative;
  fixes silent stylesheet miss — same class as the v4.9.0->v4.9.1 script-tag fix)
- src/renderer/ascii-controller.js: wire all 3 mode tabs, 18 template
  buttons, and the 3 box form fields. setMode() toggles .active on tabs
  and matching .mode-section. Templates route through the orchestrator's
  template:<id> font namespace. Box mode renders text with single/double/
  rounded/bold/ascii borders via a pure renderBox() helper. All 11 T9
  behaviours preserved.
- tests/ascii-controller.test.js: 6 tests covering stylesheet path,
  pure box renderer, mode-tab switching, and template button wiring.
- package.json 4.9.1 -> 4.9.2; README + UPDATES updated.

Amit Haridas
2026-09-14 22:37:02 +05:30
amitwh 8c708b7abb fix(flowchart): pre-await getUserDataPath to fix persistence; bump v4.9.0 → v4.9.1
Amit Haridas
2026-09-14 22:24:27 +05:30
amitwh 58aa4da00f chore(release): bump v4.8.0 → v4.9.0 — visual flow chart, ASCII art upgrade, 12 new themes
Amit Haridas
2026-09-14 22:19:33 +05:30
amitwh b28d11035b docs(readme): drop undocumented Add Flow Chart Node Insert shortcut
The flowchart panel keyboard handler in src/sidebar/flowchart-panel.js only
handles Ctrl+Z, Ctrl+Shift+Z, Delete, and Backspace. There is no Insert-key
branch, so the README row documenting it was a lie. Remove the row until the
behaviour is actually implemented.

Amit Haridas
2026-09-14 22:06:25 +05:30
amitwh bf0ed6857d fix(sidebar): register Ctrl+Alt+F to toggle flow chart panel
The rail button tooltip advertised the shortcut, but commandPalette.register
was missing for 'Toggle Sidebar: Flow Chart'. Wire it up next to the other
sidebar toggles (Explorer/Git/Outline) so the advertised shortcut works.

Amit Haridas
2026-09-14 22:06:20 +05:30
amitwh aee30a2a9c docs(readme): visual flow chart editor feature + panel-scoped shortcuts
Amit Haridas
2026-09-14 21:55:48 +05:30
amitwh b0dcf57daf feat(sidebar): register flowchart panel + rail button + thin fs IPC
- Add data-panel=flowchart rail button in src/index.html after daily-notes

- Append .flowchart-* panel CSS selectors to src/styles-sidebar.css

- Add flowchartIO IPC bridge and registerPanel('flowchart') in src/renderer.js

- Add get-user-data-path / read-text-file / write-text-file IPC in src/main.js

- Path validation: sandbox inside app.getPath('userData')

- read-text-file returns null on ENOENT (file doesn't exist)

Amit Haridas
2026-09-14 21:52:32 +05:30
amitwh a6dc54cedc fix(sidebar): clean up listeners + timers + store subscription on panel destroy
destroy() previously only called canvas.destroy(), leaking:
- the container keydown listener
- the insertBtn click listener
- the debouncedPreview setTimeout handle (could write to a detached <pre>)
- the debouncedPersist setTimeout handle (could writeFile after unmount)
- the store.subscribe listener (store kept a stale closure)

Also compute the persistence path once on mount instead of invoking
getUserDataPath() three times per panel lifecycle.

Inline debouncedPreview / debouncedPersist so their timer handles are
reachable from destroy(). Capture store.subscribe's unsubscribe.
destroy() order: clear timers, unsubscribe store, remove listeners,
then canvas.destroy().

Amit Haridas
2026-09-14 21:49:49 +05:30
amitwh 59ee9c609e feat(sidebar): flowchart-panel — canvas + preview + persistence + insert
Amit Haridas
2026-09-14 21:45:47 +05:30
amitwh 0331a08207 feat(flowchart): SVG canvas with drag, double-click label edit, context menu hook
- Adds flowchart-canvas.js with createCanvas(container, store, opts) -> { destroy, getSvg }
- Consumes T1 store (subscribe/moveNode/connect/addNode) and T2 shapeSvg for 5 node kinds
- All 3 edge kinds render: solid (default), dotted (stroke-dasharray 4,4), thick (stroke-width 3)
- Pointer events: drag moves nodes; Alt+drag creates solid edges between nodes
- onEdgeClick fires on edge click; onShapeMenu fires on contextmenu
- Double-click opens inline <input> overlay for label editing
- destroy() unsubscribes from store and removes all listeners/SVG

Tests: 9 new (rendering 5, pointer events 2, subscribe 1, destroy 1) @jest-environment jsdom
Full suite: 89 suites / 1083 tests pass; lint clean; prettier clean.

Amit Haridas
2026-09-14 21:41:58 +05:30
amitwh 216e0ecf51 feat(flowchart): mermaid translator (flowchart TD, all 5 shapes, 3 edge kinds)
Pure Mermaid translator: graph (nodes + edges) -> flowchart TD source.
5 node kinds (process/decision/terminator/subroutine/document) ->
Mermaid syntax ([..], {..}, ([..]), [[..]], [/../]).
3 edge kinds (solid/dotted/thick) -> Mermaid arrows (-->, -.->, ==>).
Label escaping: double quotes become #quot;, newlines become literal \n.

Also moves tests/fixtures per-test dirs to fixtures-epub / fixtures-css
so the shared tests/fixtures/ stays available for snapshot fixtures.

Amit Haridas
2026-09-14 21:36:02 +05:30
amitwh 4a36b7db76 feat(flowchart): 5 SVG shape templates (process/decision/terminator/subroutine/document)
Amit Haridas
2026-09-14 21:25:38 +05:30
amitwh 7869be0ff9 feat(flowchart): pure graph store with undo/redo + injectable IO
Amit Haridas
2026-09-14 21:23:03 +05:30
amitwh 2ca543de35 fix(ascii-art): correct controller script tag path (drop ../)
Amit Haridas
2026-09-14 21:19:37 +05:30
Amit Haridas 02c9250c0d docs(readme): ASCII Art Generator now 17 hand-coded + 400+ FIGlet fonts; insert/copy/save
Amit Haridas
2026-09-14 21:14:36 +05:30
amitwh ab50183dc0 refactor(ascii-art): delete in-app modal #ascii-art-dialog, controller, dead preload channels
Amit Haridas
2026-09-14 21:06:28 +05:30
amitwh 8c162c1714 feat(ascii-art): standalone window uses controller + searchable picker + copy/save/insert
Amit Haridas
2026-09-14 21:05:24 +05:30
amitwh 38bc2b2bc5 feat(ascii-art): renderer controller for standalone window (font picker + copy/save/insert)
Amit Haridas
2026-09-14 20:58:46 +05:30
amitwh 1d68fc132f test(preload): ascii channel allow-list assertions + extend existing security test
Amit Haridas
2026-09-14 20:55:58 +05:30
amitwh fecd23d35e feat(ascii-art): preload allow-list + ascii namespace
Amit Haridas
2026-09-14 20:54:23 +05:30
amitwh f089f60d70 feat(ascii-art): wire IPC handlers for generate/list-fonts/save/copy/last-font
Amit Haridas
2026-09-14 20:50:37 +05:30
amitwh 9751bbc6df feat(ascii-art): pure AsciiArt module with generate/listFonts/getFontMeta
Amit Haridas
2026-09-14 20:46:49 +05:30
amitwh 57fee91e32 feat(ascii-art): pure AsciiArt module with generate/listFonts/getFontMeta
Pure CommonJS orchestrator that unifies hand-coded fonts, figlet adapter,
and templates behind a single public API. Wired to main.js via ipcMain.handle.

Public API:
  - generate({ text, font, options }) - resolves 'template:<name>' /
    'figlet:<font>' / bare id, falls back to standard for unknown fonts.
  - listFonts() - hand-coded first (17), then figlet, then templates (19).
  - getFontMeta(id) - null for unknown id, full meta for hand-coded,
    { kind } for figlet/templates.

Amit Haridas
2026-09-14 20:45:05 +05:30
amitwh fba848ef16 feat(ascii-art): figlet adapter with lazy load, font cache, structured error 2026-09-14 20:40:55 +05:30
amitwh bb99a5c5ee feat(ascii-art): 19 named ASCII art templates with snapshot tests
Per Task 3 of the 2026-09-14 ASCII art upgrade plan.

- New module: src/main/AsciiArt.templates.js exporting ASCII_TEMPLATES
  (19 entries) and getTemplate(name) accessor (returns '' for unknown).
- New test: tests/main/ascii-art.templates.test.js with 19 per-template
  snapshots + unknown-name + keys-match assertions (21 tests total).
- 17 templates verbatim from src/ascii-generator.html:596-626
  (arrow-right, arrow-down, decision, process, flowchart, sequence,
  network, hierarchy, header, note, warning, info, divider, separator,
  banner, checklist + the brief's own TEMPLATE_NAMES order).
- 2 templates verbatim from src/renderer.js:6542-6697
  (progress-bar, table-simple).
- 1 newly authored: arrow-up (completes the arrow triplet; does not
  exist in either source).

Amit Haridas
2026-09-14 20:35:39 +05:30
amitwh f71aa2b097 feat(ascii-art): 17 hand-coded font tables (5 existing + 12 new) with snapshot tests
Widen height bound to 3-12 so the spec-named figlet fonts fit:
- Isometric1, Isometric2, Isometric3, Isometric4 (h=11)
- Calvin S (h=3)

Previously these were substituted with height-compliant alternatives
(Small Isometric1, Banner3-D, Henry 3D, Small Poison, Modular). Restoring
the spec-named fonts preserves the product intent: 4 distinct isometric
projections and the calvin-and-hobbes-style Calvin S font.

Amit Haridas
2026-09-14 20:30:04 +05:30
amitwh 5385e159ed feat(ascii-art): 17 hand-coded font tables (5 existing + 12 new) with snapshot tests
Amit Haridas
2026-09-14 20:27:03 +05:30
amitwh 3fbb47000e chore(deps): add figlet ^1.8.0 for ASCII art generator 2026-09-14 20:21:14 +05:30
amitwh 66def72f3e docs(readme): list all 37 themes by category
Amit Haridas
2026-09-14 20:19:26 +05:30
amitwh c1c9ab4a4c feat(themes): add 12 new themes (Catppuccin, One Light, Tokyo Night Storm, Synthwave, Outrun, Winter, Solarized HC, Spring)
Amit Haridas
2026-09-14 20:16:08 +05:30
amitwh 0bc50c7d54 feat(renderer): toggle <link disabled> on theme-changed instead of page reload
Replace the page-reload IPC handling in the theme-changed listener with an
in-place toggle of the preloaded <link id="theme-*"> tags. The helper scans
for a matching link first and only mutates disabled states when one exists,
so an unknown id (or main-process miss) short-circuits and preserves the
currently active theme. body.className is always set to the requested id so
legacy selectors keep matching.

Add tests/theme-renderer-apply.test.js with three cases covering: switching
to a fresh theme, idempotent re-switch, and the unknown-id short-circuit.
The test's local helper mirrors the renderer implementation so future drift
is caught at test time.

Amit Haridas
2026-09-14 20:11:44 +05:30
amitwh ceeda453be feat(index): preload 37 disabled theme <link> tags for renderer toggle
Preload one disabled <link id="theme-<id>"> per registered theme
between the structural CSS block and the KaTeX link. The renderer
will toggle the disabled attribute on the active link when the theme
changes. The 12 new-theme CSS files (catppuccin-*, one-light,
tokyo-night-storm, synthwave-84, outrun, winter-is-coming-*, solarized-dark-hc,
spring-light) are created in the next task; until then those 12 links
are inert (disabled) and 404 is harmless.

Amit Haridas
2026-09-14 20:03:39 +05:30
amitwh 311304f365 refactor(styles): extract 25 existing themes into per-theme CSS files 2026-09-14 19:58:56 +05:30
amitwh 8392e33f5b refactor(main): drive View → Theme submenu from ThemeRegistry
Wires the three registry-layer modules into src/main.js:

- Require ThemeRegistry + buildThemeMenu + the bootstrap side-effect
  module at the top of the file so the registry is populated before
  the menu is built.
- Replace the 109-line hardcoded View → Theme submenu block with a
  buildThemeMenu({ setTheme, getCurrentThemeId }) call — themes are
  now driven entirely from ThemeRegistry.list() / categories().
- Harden setTheme() to validate the incoming id against the registry
  and fall back to 'atomonelight' if the stored id no longer exists
  (e.g. after a downgrade or theme rename), with a console.warn so the
  fallback is observable.

Pure wiring — no new behaviour, no unrelated edits. All 79 test suites
/ 931 tests remain green; lint and prettier checks clean.

Amit Haridas
2026-09-14 19:49:17 +05:30
amitwh a2b4a856f3 feat(theme-registry): buildThemeMenu converts registry → Electron MenuItem[]
Adds src/main/themeMenuBuilder.js — a pure module that consumes
ThemeRegistry.list() + ThemeRegistry.categories() and the injected
setTheme/getCurrentThemeId callbacks to produce the View → Theme
submenu's MenuItemTemplate[] in the same shape as the previous
hardcoded block in src/main.js:1137-1245.

- Radio-style items with checked=true on the active theme id
- Grouped by category in registry order with separators between
  non-empty categories
- No Electron / electron-store imports — keeps the module pure and
  unit-testable under @jest-environment node
- Tests use jest.resetModules() + per-test require to avoid the
  module-cache leakage the bootstrap test surfaced in T2

Amit Haridas
2026-09-14 19:46:15 +05:30
amitwh eaad62d02e feat(theme-registry): bootstrap with 25 existing + 12 new themes
Registers all 37 editor themes at startup via ThemeRegistry.bootstrap.js.
Side-effect module: requiring it populates the registry from a static
THEMES array (25 existing menu themes refactored into the registry +
12 new: Catppuccin x4, one-light, tokyo-night-storm, synthwave-84,
outrun, winter-is-coming x2, solarized-dark-hc, spring-light).

Categories split: 13 light / 22 dark / 1 high-contrast / 1 seasonal
(spring-light per spec).

Snapshot test asserts exact id order, shape validity, and category
counts. Tests use jest.resetModules() + per-test requires so the
bootstrap module re-evaluates its registration loop each run.

Amit Haridas
2026-09-14 19:43:48 +05:30
Amit Haridas 1e7e332c24 feat(theme-registry): pure ThemeRegistry module with full API
- 8 exports: register/unregister/list/get/categories/lightThemes/darkThemes/clear
- kebab-case id validator; category whitelist (light/dark/high-contrast/seasonal)
- duplicate-id and shape errors with descriptive messages
- pure CommonJS, no IO, no Electron deps — T2 bootstrap will register all 37 themes
- 10 Jest tests covering register/unregister/get/categories/light+dark filters
- full suite: 77 suites, 924 tests passing; lint + Prettier clean

Amit Haridas
2026-09-14 19:39:52 +05:30
amitwh b8c772269c docs(plans): add ascii-art-upgrade implementation plan
12-task TDD plan for the full-fledged ASCII Art Generator upgrade:

* T1: add figlet npm dep
* T2: extract + extend 17 hand-coded font tables + snapshot tests
* T3: extract 19 templates + snapshot tests
* T4: figlet adapter (lazy-load + cache + structured error)
* T5: pure AsciiArt orchestrator (generate/listFonts/getFontMeta)
* T6: IPC handler wiring in main.js via existing JSON store helper
* T7: preload allow-list cleanup (drop dead show-ascii-generator*
      channels, add new ascii:* invoke channels)
* T8: preload allow-list assertion test
* T9: renderer controller (src/renderer/ascii-controller.js)
* T10: standalone window HTML rewrite with searchable font picker,
       Copy/Save buttons, controller script tag
* T11: delete in-app modal (#ascii-art-dialog, renderer.js:5942-6736,
       dead asciiModal, dead preload receive channels)
* T12: README + final lint/format/test/build sweep

Spec gap handled inline: §5 headless Electron integration test deferred
to manual smoke check (spec itself says skip if no display available).

Amit Haridas
2026-09-14 19:14:30 +05:30
amitwh 87902c18ce docs(plans): add theme-registry + flowchart-editor implementation plans
Two step-by-step TDD plans derived from the 2026-09-14 design specs:

* theme-registry: 9 tasks, 70+ steps. Creates src/main/ThemeRegistry.js
  (pure module), bootstrap with 37 themes, buildThemeMenu for main.js,
  migrates 25 existing per-theme CSS blocks into src/styles/themes/<id>.css,
  rewrites the renderer apply-theme function to toggle <link disabled>,
  adds 12 new theme CSS files using shared token vocabulary.
* flowchart-editor: 8 tasks, 41 TDD steps. Pure renderer-side feature
  (no main-process modules). Pure data store with IO injection, 5 SVG
  shape functions, Mermaid translator, hand-rolled SVG canvas with
  pointer events, sidebar panel wiring with debounced preview (250ms)
  + debounced persistence (500ms) + panel-scoped keyboard shortcuts.
  Three minimal userData-path-validated IPC channels added for
  persistence (renderer can't reach <userData> under the current
  nodeIntegration:true security model without them).

Amit Haridas
2026-09-14 19:12:18 +05:30
amitwh 43c26c6521 docs(specs): add theme-registry + ascii-art-upgrade + flowchart-editor designs
Three new specs for the v4.8.0+ feature wave:

* Theme registry: replace hardcoded 25-theme menu in main.js with a pure
  ThemeRegistry module + per-theme CSS file convention. Add 12 new themes
  (Catppuccin x4, One Light, Tokyo Night Storm, Synthwave '84, Outrun,
  Winter is Coming Light+Dark, Solarized Dark HC, Spring Light).
* ASCII art upgrade: consolidate dual implementations (standalone window
  vs dead in-app modal) into a single path; add 12 hand-coded fonts +
  figlet npm library for 400+ fonts; add copy/save/insert output
  destinations; comprehensive tests for the previously-zero-coverage
  textToASCII/createASCIIBox/getASCIITemplate machinery.
* Flow chart editor: sidebar panel with hand-rolled SVG canvas, node-graph
  data model, drag/drop editing, live Mermaid source preview, undo/redo,
  session persistence. Emits Mermaid which the existing preview pane
  already renders natively.

Amit Haridas
2026-09-14 19:01:09 +05:30
amitwh b1b72f9a60 chore(release): bump v4.7.1 → v4.8.0; Prettier pass on overnight-session files
12 commits on master since v4.7.1 baseline, taking tests 524 → 914 across
27 new suites. This commit:
- Bumps package.json + README version to v4.8.0 (additive features → semver minor)
- Applies Prettier formatting to all files touched during the overnight
  session so release build is reproducible from a clean repo

New in v4.8.0:
- PDF encryption close-out (D1)
- KaTeX rendering test coverage
- Autosave buffer + crash recovery banner
- Daily notes + workspace search + doc-aware Q&A
- Search sidebar panel + Ask mode
- Status bar: word count, reading time, Flesch-Kincaid grade
- Footnote hover preview
- Smart paste (URL → link, CSV/TSV → table)
- Daily notes menu item + sidebar panel + Q&A deep-link
- Daily templates gallery
- Pluggable DocQA engine (TF-idF default + lazy neural embeddings)

Amit Haridas
2026-09-14 14:56:05 +05:30
amitwh c3fe72bcae feat(templates,qa): template gallery + pluggable DocQA engine
Two more features from the deferred menu:

Daily-note template gallery:
- src/main/DailyNotesTemplates.js — pure module: listTemplates() /
  saveTemplate() / deleteTemplate() / labelFor() with injectable IO.
- src/main/DailyNotes.js — openOrCreate() now accepts seedContent so a
  non-default template can seed a NEW note (existing notes never get
  clobbered).
- src/main.js — IPC channels daily-templates:list / save / delete /
  apply. apply renders the chosen template (with {date}/{weekday}
  substitution) and pipes through DailyNotes.openOrCreate.
- src/sidebar/daily-templates-panel.js — gallery UI: list, +New
  (prompt for name + content), Use (applies to today's note),
  delete (refuses to remove the last template so the default survives).
- src/renderer.js — registers the panel.
- src/index.html — icon (already added).

Pluggable DocQA engine (semantic search hook):
- src/main/SemanticEngine.js — engine interface with defaultEngine() (TF-idF,
  always available) and neuralEngine() (lazy @xenova/transformers,
  falls back gracefully when the dep is missing). getEngine(name)
  resolves either.
- src/main/DocQA.js — ask() is now async and accepts an engine arg.
  TF-idF path unchanged; neural path calls engine.rank(question, chunks)
  directly. The chunk corpus is built up front regardless of engine so
  ranking is consistent.
- src/main.js — doc-qa:ask IPC resolves the engine via SemanticEngine.getEngine(name)
  before calling DocQA.ask. The renderer can pass {engine: 'transformers'}
  to opt in once @xenova/transformers is installed.

Tests (51 new across this batch):
- tests/main/DailyNotesTemplates.test.js (18): labelFor separators /
  edge cases / non-string safety, listTemplates empty / present / sort,
  saveTemplate nested dir + .md extension + validation + null content,
  deleteTemplate success / missing / validation.
- tests/daily-templates-panel.test.js (12): mount + empty state + list +
  XSS safety, Use button (apply + error path), Delete button (success +
  last-template guard), New template (save + cancel), refresh.
- tests/main/SemanticEngine.test.js (8): default engine shape + rank
  matches WorkspaceSearch, getEngine for tf-idf / unknown / transformers
  (graceful fallback when @xenova/transformers missing), parity check.
- DocQA: 5 new tests for engine arg (custom engine.rank called, default
  fallback, neural hit shape translation); existing tests updated to
  await the now-async ask().

Full suite: 76 suites, 914 tests, lint+format clean.

Activation for the neural engine:
  npm install @xenova/transformers
  (heavy; ~50 MiB with deps) — then 'transformers' is selectable in
  doc-qa:ask. Until then, all calls use TF-idF transparently.

Amit Haridas
2026-09-14 11:57:32 +05:30
amitwh 2aa72738f4 feat(sidebar): daily-notes panel + Q&A deep-link to file offset
Daily notes panel:
- src/sidebar/daily-notes-panel.js — new sidebar panel that lists every
  YYYY-MM-DD.md in the daily-notes dir (newest first), with a Today
  button that creates/opens today's entry. Refresh button reloads.
  Clicking a row calls onOpenFile(path). DOM is built with textContent
  for dynamic fields — no XSS surface from a hostile filename.
- src/main.js — daily-notes:list IPC now returns absolute paths (joined
  with the daily-notes dir) so the renderer can pass them straight to
  open-file-path without re-synthesizing.
- src/renderer.js — registers the panel; icon for the daily-notes
  button (calendar icon).
- src/index.html — calendar SVG icon for the daily-notes sidebar entry.

Q&A deep-link:
- src/main.js — open-file-path accepts either a string (legacy) or an
  object {path, offset}. The offset is forwarded to the renderer via
  file-opened.
- src/renderer.js — file-opened handler scrolls the editor to the
  offset using EditorView.scrollIntoView(y: 'center') so the matching
  passage lands in the middle of the visible area.
- search panel now passes {path, offset} to open-file-path so Q&A
  results with chunk offsets jump straight to the passage.

Tests (12 new, tests/daily-notes-panel.test.js):
  - mount, empty state, list rendering
  - Today button → onOpenFile, 'Created today' / 'Today already exists' status
  - error paths (openToday reject, listExisting reject, listExisting missing)
  - click + Enter/Space on a row open the right path
  - refresh() re-fetches, keeps status when keepStatus:true
  - non-md entries filtered out
  - XSS-safe textContent for dynamic data

Full suite: 73 suites, 873 tests, lint+format clean.

Amit Haridas
2026-09-14 11:53:45 +05:30
amitwh 0cab0b08c7 feat(menu): add 'Today's Daily Note' under Tools
Same handler as the global Ctrl+Alt+D shortcut — opens (or creates)
the local-date YYYY-MM-DD.md and sends a file-opened IPC to the
renderer. Mirrors the Quick Note pattern in the same submenu (global
shortcut + menu entry, both pointing at openOrCreate).

Amit Haridas
2026-09-14 09:01:43 +05:30
amitwh 1b85bc47a4 feat(paste): CSV/TSV → markdown table on tabular paste
- src/utils/csv-to-table.js — pure module. Auto-detects the delimiter
  (tab wins over comma; comma wins over semicolon). RFC 4180-style
  parsing handles quoted fields, escaped quotes (""), and CRLF. Cells
  are escaped for markdown tables (\\ for backslashes, \| for pipes,
  newlines stripped). Alignment: a column is right-aligned when every
  non-empty cell matches a numeric pattern AND there are ≥2 rows or
  ≥1 multi-character cell (single-char numbers like "1" alone are
  too ambiguous to call as numeric — could be labels). Single-row input
  produces a header-only table (no fabricated "Column N" labels, no
  body).
- src/editor/smart-paste.js — paste handler now tries CSV first (it
  needs no async), falls back to the existing URL → title flow.

Tests (30 new, tests/csv-to-table.test.js):
  - detectDelimiter: tab > comma > semicolon, empty/non-string safe
  - parseRows: simple, RFC 4180 quoted, escaped quotes, CRLF, multi-line
  - escapeCell: pipes, backslash-first escaping, newline strip, null/number
  - csvToTable: simple CSV, single-row (header-only), TSV, empty input
  - alignment: numeric detection (≥2 rows OR ≥1 multi-char cell), currency,
    percentages, text columns stay left
  - escaping inside cells (pipes, newlines)
  - ragged-row padding
  - looksLikeCsv: true for tab/comma multi-row, false for single row,
    column-count mismatch, prose, very short input

Full suite: 72 suites, 861 tests, lint+format clean.

Amit Haridas
2026-09-14 09:01:07 +05:30
amitwh bd86748c47 feat(paste): smart URL → markdown-link on URL-only pastes
- src/main/UrlTitle.js — fetch a URL, return its <title>. Pure module
  with injectable fetch for tests. Decodes named + numeric + hex entities
  (AT&amp;T, Caf&#233;, &#x2014;), strips the <title> tags, collapses
  whitespace, caps the label at 200 chars. 5s timeout via AbortController,
  2 MiB body cap to avoid OOM on big downloads, streaming reader with
  overflow cancellation. Rejects non-http(s) URLs up front.
- src/main.js — IPC url-title:fetch proxies to fetchTitle.
- src/editor/smart-paste.js — CodeMirror 6 extension that detects
  URL-only pastes (one URL, surrounded only by whitespace), inserts the
  URL immediately, then async-rewrites the insertion range to
  [Title](url) once the title arrives. Multi-line / prose pastes pass
  through untouched.
- src/editor/codemirror-setup.js — accepts smartPasteFetcher option and
  pushes the extension when provided.
- src/renderer.js — passes ipcRenderer.invoke('url-title:fetch') as
  the fetcher.
- src/preload.js — url-title:fetch added to ALLOWED_SEND_CHANNELS.
- eslint.config.js — AbortController / TextDecoder / TextEncoder added
  to globals (available in Node 20+ and Chromium).

Tests (34 new):
- tests/main/UrlTitle.test.js (24): isHttpUrl scheme filter, decodeTitle
  named/numeric/hex entities + whitespace + non-string, extractTitleFromHtml
  first match + case-insensitive + null fallback, fetchTitle success +
  long-title cap + streaming body, all failure paths (non-http,
  no-fetch, non-OK, wrong content-type, no <title>, network error,
  body over maxBytes — including streaming overflow cancellation).
- tests/smart-paste.test.js (10): URL_ONLY_RE detection (bare URL,
  path/query/fragment, whitespace padding, scheme rejection, embedded
  rejection, empty/malformed), replacement format ([T](url), brackets
  in title survive, query strings preserved).

Full suite: 71 suites, 831 tests, lint+format clean.

Amit Haridas
2026-09-14 08:58:32 +05:30
amitwh 6d08c138d8 feat(preview): footnote hover preview
Hovering a footnote reference (rendered by marked-footnote as
<a data-footnote-ref href="#footnote-N">) now shows a small popover
with the footnote body text, matching the UX of Typora and Obsidian.

- src/renderer/footnote-preview.js — pure DOM module. Mounts a single
  popover once per preview pane; mouseover delegates via Element.closest()
  to the ref, lookups the matching <li id="footnote-N"> in the same pane,
  strips the backref ↩, and positions above/below the cursor with edge
  clamping. CSS.escape() fallback for non-browser environments.
- src/renderer.js — _renderPreview calls mountFootnotePreview once per
  pane (gated by a dataset marker so re-renders don't accumulate
  listeners).
- eslint.config.js — CSS + Element added to browser globals.

Tests (8 new, tests/footnote-preview.test.js): mount/unmount, delay +
timer behavior, mouseover/mouseout show/hide, dangling ref graceful
no-op, backref ↩ stripped from the displayed text, cancel-pending-show
when a new ref is hovered, idempotent remount guard.

Full suite: 69 suites, 797 tests, lint+format clean.

Amit Haridas
2026-09-14 08:56:31 +05:30
amitwh 7397e7f618 feat(statusbar): word count + reading time + Flesch-Kincaid grade
- src/utils/writing-stats.js — pure module: stripMarkdown() drops fenced
  code blocks, inline code, image URLs, link URLs, headings, blockquote
  markers, list bullets, and emphasis markers so the word count reflects
  the prose a reader actually consumes (the convention used by Hemingway,
  iA Writer). splitSentences / countSyllables use Flesch's standard
  heuristics. computeStats returns wordCount, sentenceCount,
  syllableCount, readingTimeMinutes (default 220 wpm),
  fleschKincaidGrade, charCount.
- src/renderer.js — _updateStatusBar now calls computeStats and updates
  three new status items: ~X min read, Grade N.N, and the existing Words
  + Chars counters use the stripped count.
- src/index.html — two new status items: #reading-time and #grade-level.

Tests (23 new, tests/writing-stats.test.js): markdown stripping (fenced,
inline, images, links, wikilinks, headings, lists, emphasis, HTML),
sentence splitter edge cases, syllable heuristic (short words, silent e,
empty), and computeStats with custom wpm + null-safe inputs.

Full suite: 68 suites, 789 tests, lint+format clean.

Amit Haridas
2026-09-14 08:54:28 +05:30
amitwh da97369b44 feat(search): sidebar panel + Ask mode for workspace Q&A
The workspace-search:query and doc-qa:ask IPC channels were reachable
from the renderer but had no UI. This commit wires them into a sidebar
panel that consumes both backends through a single input.

- src/sidebar/search-panel.js — one input, two modes:
    Search (default): routes to workspace-search:query, returns file hits
    Ask: routes to doc-qa:ask, returns chunk-level passages with offsets
  Click a result → open the file (offset passed through for Q&A hits).
  All dynamic content is escaped before innerHTML — hostile filenames
  or snippets stay as text instead of becoming script/img nodes.
- src/renderer.js — registers the panel; reads the explorer's folder
  input on each open so the search dir stays in sync.
- src/index.html — search sidebar icon (magnifier) next to the others.

Tests (18 new, tests/search-panel.test.js):
  - mount + DOM structure
  - Enter / click run → search() with query + dir
  - result rendering (filePath, snippet, tag facet)
  - onOpenFile receives (filePath, offset)
  - Ask tab switches placeholder + routes to ask()
  - Ask chunks carry +offset in the meta line
  - empty query, no folder, search error → handled
  - XSS: filename/snippet/tag with <script>, <img>, <unsafe> are escaped
  - Escape clears, Clear button resets, host API (setDir/focus/clear)

Full suite: 67 suites, 766 tests, lint+format clean.

Amit Haridas
2026-09-14 08:53:27 +05:30
amitwh 3f856bc857 feat(pkm): daily notes + workspace search + doc-aware Q&A
Three more features from the brainstorm menu, built on a shared search
algorithm so the codebase stays small.

- src/main/DailyNotes.js — Zettelkasten-style helper. One YYYY-MM-DD.md
  per local date under <userData>/notes/daily/; loads skeleton from
  <userData>/notes/templates/daily.md when present (built-in default
  otherwise). openOrCreate never clobbers existing content.
- src/main/WorkspaceSearch.js — tag/wikilink-aware content search.
  Pure module, injectable-IO tested. Query grammar: bare words,
  #tag, @wikilink, "quoted phrases". Facets weight +3 each; prose
  terms +1/occurrence capped at 5; edits within 7 days get a recency
  nudge. Returns ranked results with snippets.
- src/main/DocQA.js — chunk-level Q&A wrapper over WorkspaceSearch.
  cleanQuestion strips question words (what/how/why/...) and verb
  noise (write/read/show/tell/...) so they don't drown the ranking.
  Returns top-K passages instead of whole-file hits — multiple chunks
  from the same file can appear in the answer.
- src/main.js — IPC: daily-notes:open-today, daily-notes:list,
  workspace-search:query, doc-qa:ask. Path validation through the
  existing validatePath gate; a global Ctrl+Alt+D shortcut creates
  today's daily note from anywhere.
- src/preload.js — all four channels added to ALLOWED_SEND_CHANNELS.

Tests (56 new across the three modules):
- tests/main/DailyNotes.test.js (15): dateKey formatting, pathFor,
  template load + {date}/{weekday} substitution, openOrCreate +
  no-clobber, nested-dir creation, listExisting filtering,
  isValidDir rejects NUL/non-string.
- tests/main/WorkspaceSearch.test.js (25): parseQuery grammar,
  hasTag/hasWikilink word boundaries, scoreDocument scoring,
  per-term spam cap, recency nudge, search ranking + limit +
  empty-query short-circuit, bad-input safety.
- tests/main/DocQA.test.js (16): cleanQuestion stripping + facet
  preservation, chunkDocument paragraph + hard-split, ask()
  top-K, recency tiebreaker, missing-files fallback.

Full suite: 748 tests pass, 66 suites, lint+format clean.

Amit Haridas
2026-09-14 00:02:58 +05:30
amitwh cd0050d988 feat(recovery): autosave buffer + crash-recovery banner
VersionHistory snapshots the previous content on every explicit save — an
unsaved buffer is still lost on crash. AutosaveBuffer fills that gap.

- src/main/AutosaveBuffer.js — pure module mirroring VersionHistory's
  injectable-IO pattern; one blob per doc path under
  <userData>/autosave/by-path/<sha1>/recovery.md + meta.json. No history
  (VersionHistory owns that) — just the latest dirty buffer.
- src/main.js — IPC channels autosave:write/read/clear/list; real paths
  go through validatePath, synthetic 'untitled-tab-<id>' keys skip it.
- src/preload.js — added the four channels to ALLOWED_SEND_CHANNELS.
- src/renderer/autosave-client.js — debounced (2s) flush per tab +
  periodic safety net (10s max age) + dirty-write retry on failure.
- src/renderer.js — register on tab create, unregister on close,
  notifyChange piggybacks on performAutoSave's existing dirty-check,
  clearForDocPath after a successful save, showAutosaveRecoveryBanner
  on startup listing pending recoveries with Restore/Dismiss.

Tests (39 new):
- tests/main/AutosaveBuffer.test.js (19): round-trip, overwrite, isolation,
  unicode/emoji, empty content, null coercion, ENOENT vs corrupt meta,
  list ordering, corrupt-sibling skip, input validation, sha1 storage.
- tests/autosave-client.test.js (11): debounce, flushNow bypass,
  no-path skip, clearForDocPath, list proxy, IPC error fallback,
  unregister tear-down, failure-retry, periodic flush, idempotency.

Full suite: 692 tests pass, 63 suites, lint+format clean.

Amit Haridas
2026-09-14 00:00:16 +05:30
amitwh dfb364bcd8 test(math): cover the KaTeX rendering pipeline (13 tests)
The renderer wires KaTeX via initMathSupport() and calls
window.renderMathInElement(...) inside _renderPreview() — there were no
tests pinning any of that contract. This commit adds tests/math-rendering.test.js:

- inline ($, escaped \() and display ($$, escaped \[) delimiters all
  render valid TeX
- mixed prose + math preserves siblings (headings, lists, etc.)
- invalid LaTeX degrades gracefully under default throwOnError:false, so
  the renderer's outer try/catch contract stays load-bearing
- dollar-heavy prose doesn't throw (the renderer's auto-render call must
  be robust to anything in the doc)
- bundle wiring: katex.render() and renderMathInElement are exported,
  katex.min.css ships in assets/, and index.html references it without a
  CDN (the old jsdelivr link was removed in a prior hardening pass)

Amit Haridas
2026-09-13 23:57:08 +05:30
amitwh cd2980277b feat(pdf): restore real PDF encryption; close out D1
@ cantoo/pdf-lib 2.9.1 was already the dep in use; the encryption plumbing
and probe were already in place from the prior hardening pass. This commit:

- adds a test confirming executeOperation('permissions', ...) routes through
  pdfSetPermissions and produces an encrypted PDF unlocked by the owner
  password (mirrors the existing 'encrypt' route coverage)
- updates docs/superpowers/plans/2026-08-23-security-assessment-summary.md
  to mark deferred risk D1 as resolved (the honest-failure message remains
  as a fail-closed net for any future library regression)

35 PDF ops tests pass; lint/format clean.

Amit Haridas
2026-09-13 23:55:51 +05:30
amitwh a2455c3f8a feat(export): themable PDF/Word exports; Windows CI green (v4.7.1)
Export themes:
- Six presets in the export dialog (basic + advanced modes) for PDF/DOCX:
  Default, Modern, Classic, Sepia, Minimal, Elegant
- PDF: LaTeX header (xcolor/titlesec) recolors headings, adds section
  rules and colored links — core-TeX packages only, hex-literal only
  (no injection surface)
- DOCX: styles.xml surgery recolors Heading1-6/Title/Subtitle/Hyperlink
  and swaps heading/body fonts; verified end-to-end against a real
  pandoc-produced docx
- Themes ride along in export presets (unknown ids fall back to Default)

Windows CI fixes:
- pdfjs standardFontDataUrl now a file:// URL (backslash paths failed
  pdfjs's trailing-slash validation, breaking extractText/extractImages)
- sharp temp cleanup EPERM retries; path-separator assertions; pdfjs
  test timeouts raised; batch suite testTimeout 30s

648/648 tests green; 4.7.1 linux+win artifacts rebuilt.
2026-09-05 23:59:53 +05:30
amitwh 1b2ab7b55c fix(pdf): hand pdfjs a file:// standardFontDataUrl; repair Windows CI tests
pdfjs validates standardFontDataUrl as a URL ending in a forward slash —
our raw path with a trailing path.sep is invalid on Windows (C:\...\),
failing extractText/extractImages (and every test that verifies through
them) with 'Invalid factory url: must include trailing slash'. Linux and
macOS passed only because / is also a valid URL slash. Convert with
pathToFileURL() so every platform sends file:///.../standard_fonts/.

Also escape path.sep in PDFBatchOperations' sanitizer test regex — a bare
backslash made new RegExp() a syntax error on Windows.
2026-09-05 23:33:58 +05:30
amitwh cfe134931f fix(ci): stop CRLF conversion of the pinned FiraCode license on Windows
The Windows runner's git checkout rewrote assets/fonts/FiraCode-LICENSE.txt
line endings (autocrlf), changing its bytes and tripping the SHA-256 pin in
download-tools.js. A .gitattributes marks the license (-text) and all font/
image binaries as never-normalized so every platform checks out identical
bytes.
2026-09-05 23:20:43 +05:30
amitwh 77f8ba3d9d feat(brand): adopt the new M↓ brand kit; fix CI tool downloads
Branding:
- All app icons regenerated from the new vector brand kit (M↓ mark):
  icon.png/icon@2x (app + packaging), favicon.png, tray-icon.png, and the
  full assets/icons/ size set — generate-icons.js now rasterizes
  app-icon.svg directly (docico1.png removed)
- index.html gets proper favicon/apple-touch links from the kit
- Welcome tab hero shows the new mark; README gets the horizontal wordmark
- assets/logo.png (ConcreteInfo) intentionally untouched

CI release fixes (win/mac jobs were failing):
- FiraCode download moved from moving raw/master URLs (hash drifted
  upstream, tripping the pin) to the immutable 6.2 release asset; repo
  fonts updated to the pinned 6.2 bits
- macOS pandoc extractor locates the binary in the archive instead of
  assuming a bin/ layout that the macOS zip doesn't have

Stray upload archive (markdown-converter-assets (1).zip) excluded.
2026-09-05 23:10:15 +05:30
amitwh 0be46d4bac build(release): dynamic builder config + fix bundled-tool lookup in packages
- electron-builder config moves to electron-builder.config.js so markitdown
  bundling is conditional per platform (PyInstaller only builds for the host
  OS; a missing binary now logs a warning and ships without it instead of
  failing the build); package.json static build section removed, all npm
  scripts pointed at the config; third-party-licenses/ added to packaged files
- FIX (pre-existing): packaged apps looked for bundled pandoc in
  resources/bin, but extraFiles land next to the executable (Contents/ on
  macOS) — packaged builds silently fell back to system pandoc since 4.5.
  New bundledToolDir() resolves the real location for pandoc + markitdown
- download-tools.js pins the win32 pandoc.exe SHA-256 (fetched + verified)
- sharp packaging test accepts sharp 0.35's versioned binding filename
- release.yml: bundle-markitdown step (best-effort) on every OS and a new
  macOS job; release aggregates linux+windows+macos artifacts

Local release artifacts built and verified (dist/):
- MarkdownConverter-4.7.0.AppImage (363MB, pandoc+markitdown bundled,
  packaged app boots clean, tools resolve at the fixed path)
- markdown-converter_4.7.0_amd64.deb (293MB)
- MarkdownConverter-Setup-4.7.0.exe (223MB), portable exe (223MB), zip
  (305MB) — pandoc bundled; markitdown omitted (cannot cross-build),
  legal docs verified inside app.asar

637/637 tests green; lint clean.
2026-09-05 22:48:45 +05:30
amitwh 1e24b52f3e feat(legal): bundle small dependencies, add notices, credits, and GPL source offers
Bundle (v4.7.0):
- MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via
  npm run bundle:markitdown; ML extras excluded) — built and verified
  locally: HTML/XLSX/PDF conversions pass through the bundled binary, and
  the app resolves bin/linux/markitdown first at runtime
- Packaging copies bundled markitdown alongside Pandoc for win/mac/linux;
  FFmpeg/sharp/KaTeX/fonts were already bundled

Legal artifacts:
- THIRD-PARTY-NOTICES.md: complete license inventory of everything
  distributed (binaries, npm runtime deps, fonts, embedded Python packages)
- SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2,
  ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking
  note for libvips
- third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0,
  OFL-1.1, PSF-Python texts
- Help > Third-Party Notices & Licenses: in-app viewer for both documents
- README: 'Bundled Dependencies, Legal Notices & Credits' section

Hardening:
- download-tools.js now SHA-256 pins every artifact, verifies after
  download AND against the cache on every run, and hard-fails on mismatch
  (closes security finding D6)

Large tools intentionally not bundled (documented): LibreOffice,
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre.

637/637 tests green; lint clean; clean boot; bundled binary verified.
2026-09-05 22:30:54 +05:30
amitwh 58bd19ecd1 feat(import): embed Microsoft MarkItDown for any-file → Markdown import
- File → Import with MarkItDown (Any Format)…: PDF, DOCX, PPTX, XLSX,
  Outlook .msg/.eml, EPUB, images, CSV/JSON/XML, ZIP (audio/OCR via the
  [all] extras) — verified live against HTML, XLSX (our own exporter's
  output), and PDF fixtures
- Command auto-resolution with caching: markitdown binary → python -m
  markitdown → python3 -m markitdown
- SEC-1 argv discipline (execFile only, user paths never through a shell),
  50MB cap, 120s timeout, sanitized errors that surface markitdown's own
  "pip install 'markitdown[pdf]'" hints for missing format extras
- Output lands next to the source as <name>.md (numeric suffix, never
  overwrites) and opens in a new tab; markitdown:available/convert IPC
  allowlisted for renderer flows
- Help → Dependencies lists MarkItDown; README/UPDATES updated (v4.6.1)

12 new tests (629 green); lint clean; clean app boot
2026-09-05 22:10:35 +05:30
amitwh 7ab5a0ddb4 feat(ai): add Anthropic-compatible provider; fix async plugin backends
Anthropic-compatible provider:
- New 'anthropic-compatible' option for any base URL speaking the Anthropic
  messages schema (LiteLLM proxies, Bedrock gateways, local servers)
- Sends x-api-key AND Bearer auth when a key is set (gateway-friendly,
  harmless for the official API); keyless proxies supported
- Tolerates base URLs with or without a trailing /v1 segment
- Settings modal, manifest, and provider docs updated

Runtime bug fixes found by booting the app (run-to-verify pass):
- PDF editor: File > Open PDF sends operation=null which matched no switch
  case and crashed on getElementById(undefined); now defaults to the merge
  section
- backlinks-panel: wrong require depth (../../utils -> ../utils) threw at
  panel registration time
- writing-studio stack was written against a synchronous settings backend but
  the real one is IPC-backed: GoalTracker/SnapshotManager/ProjectManager and
  all four panels now await; JSON.parse(Promise) crashes eliminated
- manuscript panel used window.prompt (unavailable in Electron); replaced
  with an inline dialog
- collaboration comment-store/save-load made async to match its IPC IO

617/617 tests green; 4 consecutive clean app boots (no uncaught errors)
2026-09-05 21:53:34 +05:30
amitwh efca458495 fix(deps): clear all npm audit vulnerabilities (27 → 0)
- Remove unused docx4js (only a stale comment referenced it); drops the
  vulnerable transitive xml2js prototype-pollution chain
- Upgrade sharp 0.34 -> 0.35.4 for the libvips CVEs (GHSA-f88m-g3jw-g9cj);
  resize/format API surface unchanged, @img/@napi-rs asarUnpack globs still
  match the new prebuilt layout
- npm audit fix for the rest: electron 41.10.7 (protocol/iframe fixes),
  electron-builder chain (AppImage search-path + updater token leak),
  dompurify 3.4.14, mermaid 11.17.2, tar (PAX parsing, critical), tmp,
  js-yaml, brace-expansion, browserslist, fast-uri, form-data, ip-address,
  nanoid, fflate, @xmldom/xmldom, @babel/core and others

613/613 tests green; lint clean; npm audit reports 0 vulnerabilities
2026-09-05 20:52:08 +05:30
amitwh c4dcbd8caf feat: v4.6.0 — AI assistant, collaboration, knowledge base, and 15 more features
- AI Assistant plugin: multi-provider chat (OpenAI/Anthropic/Ollama/LM Studio),
  summarize/improve/translate commands, proofread via ai:analyze; calls
  proxied through main so API keys stay out of the renderer
- Collaboration plugin: anchor-based comments in .comments/ sidecars with
  drift detection and F8 navigation
- Local knowledge base: [[wiki-links]] with click-to-create + Backlinks panel
- Crash recovery: debounced session snapshots with restore prompt on launch
- Version history: pre-save snapshots, History panel with restore/diff/delete
- Real PDF encryption: swap pdf-lib for @cantoo/pdf-lib (probe-driven UI)
- XLSX export (native workbooks via JSZip), ODT headers/footers + page size
- Offline KaTeX (bundled CSS+fonts), local-first PlantUML rendering
- Editor: vim mode toggle, snippet Tab-expansion, zen word-goal setter,
  writing heatmap, writing-studio panels wired with rail icons
- Quick Note global scratchpad (Ctrl+Alt+Q), markdownconverter:// deep links,
  REPL first-run confirmation
- Fix: Ctrl+Shift+P collision, pandoc converter availability check, CLI
  dangling --css/--reference-doc flags, dead converter button

8 new test suites; 613 tests green; lint clean
2026-09-05 20:48:39 +05:30
amitwh b83ba91731 fix(packaging): unpack @img prebuilt sharp binaries so deb ships bundled libvips
build.asarUnpack only claimed node_modules/sharp/**, so electron-builder
pruned the @img/sharp-* optionalDependencies: the asar kept 34 pure-JS
@img entries while the bundled libvips shared libraries never shipped.
At boot sharp's loader fell back to a system-libvips-linked binding and
dlopen failed, crashing the main process. Claim the prebuilt packages
explicitly (@img/** and @napi-rs/**) per the sharp+electron-builder
recipe, and guard the built output with a packaging regression test.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 0babf97f0e fix(image): lazy-load sharp with honest degradation so boot never fails
A missing/pruned @img/sharp-* binding made the top-level require('sharp')
crash src/main.js at startup, killing the packaged app before any window.
Load sharp through a cached lazy getter instead; when the native module
cannot load, executeOperation resolves the honest failure shape
{ success: false, error: 'Image operations unavailable: <sanitized>' }
(free of absolute paths), mirroring PDFOperations' Task-27 precedent.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh eeda3f28eb fix(test): exclude dist/ from Jest haste map
electron-builder's .snap (Squashfs) artifact in dist/ registered as an
obsolete Jest snapshot file, failing the suite exit code despite all
516 tests passing. modulePathIgnorePatterns keeps the snapshot scanner
out of build output.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 4c00406bcd docs(security): correct BurntToast drop evidence to cover CLI argv path
Final-review nit: the hardcoded-list rationale covers the dialog path
only; the drop stands on the trusted-argv precedent for --convert-to.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 363de75375 fix(pdf): guard pdfSplit against non-positive interval infinite loop
The interval split mode looped for (i = 0; i < totalPages; i += interval),
which spins forever when interval <= 0. Both the single-file dialog and the
batch dialog can reach it (the batch dialog's validateOperationData only
checks truthiness, so -1 passes). Guard at the source in the main process:
reject non-positive or non-integer intervals before the loop, protecting
both paths and any future caller.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 2e16868f59 fix(preload): whitelist get-pdf-form-fields and pdf-form-fields channels
The get-pdf-form-fields IPC pair (handler in main.js, renderer invoke and
event.reply('pdf-form-fields')) was missing from ALLOWED_SEND_CHANNELS and
ALLOWED_RECEIVE_CHANNELS. Under the planned preload migration an unlisted
channel is silently blocked, so the form-field fill/flatten feature would
break once the main window stops using the inline shim. Placed adjacent to
the sibling get-pdf-page-count/pdf-page-count pair it was modeled on.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh dd6d97c35d docs(security): formal security assessment summary
Manual audit + Task 24 formal pass: SEC-1 Pandoc argument injection
(critical, fixed), Git sidebar XSS (high, fixed), File.path dead on
Electron 41 (fixed), pdf-lib encryption silent no-op (fixed, honest
failure). 14 areas verified clean. 7 deferred/accepted risks documented
(D1-D7) incl. real-encryption dependency decision and GUI-pass release
blocker.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 0604c65683 fix(security): escape repo-derived strings in Git sidebar rendering (XSS) 2026-08-23 19:31:33 +05:30
amitwh c43caf3902 fix(security): convert Pandoc invocation to execFile argument arrays (SEC-1) 2026-08-23 19:31:33 +05:30
amitwh 25dcaaa816 fix(pdf): make encrypt/decrypt/permissions fail honestly instead of silent no-op 2026-08-23 19:31:33 +05:30
amitwh c6ec1cef64 fix(renderer): migrate File.path reads to webUtils.getPathForFile for Electron 41 2026-08-23 19:31:33 +05:30
amitwh 5fcc282fe0 docs(plan): append Task 27 — honest failure for pdf-lib encryption no-op
Task-22-review finding: pdf-lib 1.17.1 silently ignores userPassword/
ownerPassword; encrypt/permissions write unprotected files reporting
success; decrypt is a copy no-op.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 8a95144bf3 feat(pdf): add bulk PDF operations (watermark/compress/rotate/etc.) to batch converter 2026-08-23 19:31:33 +05:30
amitwh bc47316746 fix(export): one-time import of legacy localStorage export profiles into presets 2026-08-23 19:31:33 +05:30
amitwh 02ce06d364 feat(export): add save/select/delete export presets 2026-08-23 19:31:33 +05:30
amitwh 2e3af826f7 docs(plan): append Task 26 — File.path → webUtils migration (Electron 41 fix)
Task-20-review finding: File.path removed in Electron 32, app on ^41.1.1,
~15 renderer file-picker sites read it and get undefined at runtime.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 758dcb4166 feat(compare): implement Document Compare dialog with local-diff and git-HEAD-diff modes
Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 1f5db511ba feat(editor): add CSV-to-markdown-table toolbar converter
Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 63c35ef2dc fix(preload): whitelist word-template IPC channels, drop orphaned set-custom-start-page 2026-08-23 19:31:33 +05:30
amitwh c8883e77fe feat(export): add visual word-template settings dialog with graceful default-template fallback
Replaces the two native OS dialogs used to configure the DOCX "Enhanced"
export template (an open-file picker + a message-box question) with a
single in-app modal that shows the currently active template state, per
Task 18's original audit finding that this state was invisible until a
user thought to reopen the menu. Consolidates the "Select Word
Template..."/"Template Settings..." menu items into one "Word Template
Settings..." entry wired to the new dialog; Browse still uses the native
file picker since there is genuinely no bundled folder of templates to
enumerate (confirmed by investigation — see task-18-report.md).

Also fixes a related dangling-reference bug: WordTemplateExporter's
hardcoded default template path (word_template.docx) was deleted from
the repo in an earlier commit, but the code still tried to read it and
threw ENOENT whenever no custom template was selected. convert() now
degrades gracefully by generating a minimal, valid DOCX shell (styles +
numbering matching what markdownToWordXml() already references) instead
of crashing, and the new dialog surfaces this state honestly ("using
default formatting, no default template is bundled") rather than
implying a working default exists.

Out of scope, per explicit instruction: bundling fabricated starter
.docx templates to populate a literal multi-item gallery (rejected as
disproportionate/fake-content scope), and an EPUB template gallery (no
EPUB template mechanism exists anywhere in this codebase to build one
for).

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 8a28c21512 fix(plugins): whitelist plugin export-format IPC channels in preload.js
Task 17's three new IPC channels (plugin-export-formats-registered,
run-plugin-export-format, plugin-export-format-result) were missing
from preload.js's ALLOWED_SEND_CHANNELS/ALLOWED_RECEIVE_CHANNELS,
breaking the established convention that the allowlist is the
authoritative registry of every valid channel regardless of whether
it's accessed via window.electronAPI or raw ipcRenderer (see
toggle-sidebar-panel, set-current-file, save-recent-files).

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh d6baa2daf7 feat(plugins): add export-format registration hook to plugin API
Add context.formats.registerExportFormat(id, opts) to PluginContext,
backed by a new FormatRegistry (mirrors PluginRegistry's Map-based
shape). Plugins register namespaced (${pluginId}:${id}) export
formats with a label/extension/handler; the writing-studio built-in
plugin registers a trivial "sprint-summary" .txt export as a
worked example.

The plugin system lives entirely in the renderer process while the
Export menu is built in main.js, so wiring formats into the menu
required a small IPC round-trip: renderer sends format metadata to
main after plugin load (main rebuilds the menu via the already-
idempotent createMenu()), and a menu click sends the resolved save
path back to the renderer, which is the only process holding the
plugin's handler function.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 44624cd4bf feat(pdf): add form field detection, fill, and flatten
Adds pdfGetFormFields (lists AcroForm fields with name/type/value) and
pdfFillForm (fills text fields by name, optionally flattens) to
PDFOperations.js, dispatched via 'formFields'/'fillForm' in
executeOperation. pdfFillForm skips unknown/non-text fields per-field
(logs + continues) rather than failing the whole batch, matching the
partial-success precedent set by pdfExtractImages.

Wires a "Fill Form" entry into the PDF editor dialog: selecting a PDF
fetches its fields via a new get-pdf-form-fields/pdf-form-fields IPC
round trip and renders one text input per field, plus a flatten
checkbox, following the same structure as the crop/pageNumbers dialogs.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 2334ab30ed feat(pdf): add extract text, page numbers, crop, extract images operations
Adds four new PDFOperations: pdfExtractText (pdfjs-dist getTextContent),
pdfAddPageNumbers (reuses pdfWatermark's position-mapping logic, extracted
into a shared resolvePosition helper), pdfCrop (page.setCropBox against the
existing MediaBox), and pdfExtractImages (pdfjs-dist operator list +
paintImageXObject + sharp). Wired into executeOperation's switch and the PDF
editor dialog UI (4 new sections/toolbar buttons/menu items) with no new IPC
channel needed.

pdfjs-dist v5 is ESM-only, so it's loaded via dynamic import() of its
Node-friendly legacy build; Jest needs --experimental-vm-modules to support
that, so the test scripts now set NODE_OPTIONS accordingly via cross-env.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh abcfb03e52 feat(git): add diff, branch, checkout, push, pull to Git sidebar panel
Extends GitOperations.js with diff/branches/checkoutBranch/push/pull,
wires the 5 new IPC handlers in main.js (reusing the existing dir
resolution), whitelists the new channels in preload.js, and fixes the
Git sidebar panel's previously dead _gitDiff callback by wiring up a
diff view, branch list/create/checkout UI, and push/pull buttons.
Resolves Task 5, which deferred this work to this task.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 6ba3174480 feat(export): expose AsciiDoc, RST, MediaWiki, Org, Textile, man, ipynb export formats
Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh b83b86b31e feat(media): add batch folder mode to Image/Audio/Video Tools dialog
Reviewer follow-up on Task 12: the task's own title/brief called for
batch support and no later task in the plan picks it up, so this closes
that gap. Adds a "Single File" / "Batch Folder" mode toggle to the
existing media-operations-dialog.js; batch mode swaps the per-file
input/output fields for an Input Folder + "Include subfolders" +
Output Folder trio while keeping every other parameter (width/height/
quality/angle/startTime/duration/crf/fps/format/fit) applied uniformly
to every matching file. Disabled for audio "Merge", which combines many
inputs into one output and doesn't fit a per-file batch model.

main.js: adds collectFilesByExtension() (src/main/collectFilesByExtension.js,
unit tested), a generalization of the inline collectFiles() closure inside
ipcMain.on('universal-convert-batch', ...) to match a set of extensions
instead of one format. runMediaBatchOperation() loops
ImageOperations/AudioOperations/VideoOperations.executeOperation() over
the matched files, reporting per-file progress via new
'media-batch-progress' events and a final 'media-batch-complete' event,
then shows a "Batch Conversion Complete" dialog.showMessageBox with
completed/failed counts, mirroring performBatchConversion()'s pattern.
Wired via three new ipcMain.on handlers: batch-image-operation,
batch-audio-operation, batch-video-operation.

preload.js: whitelists the three new send channels and the two new
receive channels (media-batch-progress, media-batch-complete).
2026-08-23 19:31:33 +05:30
amitwh f271e27177 feat(media): add Image/Audio/Video Tools dialogs wired to new operation backends
Adds Tools > Image/Audio/Video Tools... menu items and a single dynamic
renderer dialog (src/renderer/media-operations-dialog.js) that lets the
user pick a media-kind-scoped operation, fill in its operation-specific
fields, and invoke process-image-operation/process-audio-operation/
process-video-operation (Tasks 9-11's backends). File selection reuses
the existing <input type="file"> + file.path convention; the one folder
picker need (video frame extraction) reuses the existing generic
select-folder/folder-selected IPC channels, so no new IPC handler was
required. Also removes the three dead electronAPI.image/audio/video
convenience blocks from preload.js (stale pre-Task-9-11 channel names,
unused everywhere).
2026-08-23 19:31:33 +05:30
amitwh 8dc1ae1c45 feat(video): implement ffmpeg-based video operations backend
Add src/main/VideoOperations.js with pure argument-builder functions
(buildConvertArgs, buildCompressArgs, buildTrimArgs, buildFramesArgs,
buildGifArgs) and a single executeOperation entry point that spawns
ffmpeg via dependency-injected execFileFn, mirroring AudioOperations.js.

Wire ipcMain.handle('process-video-operation', ...) in main.js using
getFFmpegPath() and sanitizeErrorMessage(). Update preload.js's
ALLOWED_SEND_CHANNELS: remove 6 stale video-* channel names, add
process-video-operation.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh a353a695b5 feat(audio): implement ffmpeg-based audio operations backend
Adds AudioOperations.js with pure argument builders (convert/trim/extract/merge)
plus one executeOperation that spawns ffmpeg via a dependency-injected execFileFn,
so tests never invoke a real binary. Wires process-audio-operation in main.js and
updates preload.js's ALLOWED_SEND_CHANNELS to replace the 5 stale audio-* entries.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 174eb3d6e9 style(image): apply Prettier formatting to ImageOperations test
Three lines in tests/main/ImageOperations.test.js (copied verbatim
from the task brief's sample) exceeded the project's 100-char width,
failing npm run format:check. Ran npm run format to auto-fix; no
behavioral change.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 8bada008b3 feat(image): implement sharp-based image operations backend
Add src/main/ImageOperations.js (convert/resize/compress/rotate via
sharp), modeled on PDFOperations.js's executeOperation dispatcher.
Wire ipcMain.handle('process-image-operation', ...) in main.js using
sanitizeErrorMessage() on error paths, and replace the 5 stale/unused
image-* channel names in preload.js's ALLOWED_SEND_CHANNELS with
process-image-operation + select-image-folder (mirroring
select-pdf-folder for a later batch-UI task).

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 949053a7c5 fix(deps): move jszip and sharp to runtime dependencies, unpack sharp from asar
- Add jszip (^3.10.1) to dependencies; keep version-pinned in overrides
- Move sharp (^0.34.3) from devDependencies to dependencies for Phase B runtime use
- Add node_modules/sharp/** to build.asarUnpack so native bindings are not packed

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh b80e34fcf5 fix(preload): whitelist monospace-setting-change channel
Reviewer caught that the new View > Monospace Font menu channel was
missing from preload.js's ALLOWED_RECEIVE_CHANNELS, the sole gap among
29 raw ipcRenderer.on(...) channels used in renderer.js. Add it under
the existing Font section for consistency with adjust-font-size.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 11b1c9e13e feat(settings): expose monospace font toggle in Settings UI
Add a View > Monospace Font menu (font family radio + ligatures
checkbox) — the app's existing reachable UI surface for this class of
preference (mirrors Theme/Font Size/Spell Check). The menu sends the
change to the renderer, which persists it via the already-working
ipcMain.handle('set-monospace-settings', ...) and applies it live via
the same applyMonospaceClasses() used on initial load.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh e09853952b fix(preload): whitelist show-document-compare channel
Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh d43fbaea59 fix(menu): wire Command Palette / Sidebar / Bottom Panel View-menu toggles 2026-08-23 19:31:33 +05:30
amitwh 66938968db fix(templates): wire New from Template menu to existing template-loading flow
Extract the sidebar Templates panel's inline load-into-new-tab callback into
a shared loadTemplateIntoNewTab() function, and add the missing
ipcRenderer.on('load-template-menu', ...) listener so the File > New from
Template submenu (which already sends this IPC event, already whitelisted in
preload.js) actually loads the selected template.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 5d9c46afc3 fix(menu): make Clear Recent Files actually clear the list
Extract the recent-files.json deletion logic into a standalone
clearRecentFilesOnDisk() function and call it from both the menu
click handler and the ipcMain.on handler. Previously the menu sent
the message in the wrong direction (main→renderer instead of
renderer→main), causing the feature to silently no-op. Both paths now
use the same function and send the correct 'recent-files-cleared'
notification to keep the renderer in sync.

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh bf3438902b fix(pdf): route Open PDF File menu item to the working editor dialog channel 2026-08-23 19:31:33 +05:30
amitwh edb5db358a docs: add implementation plan for feature audit, media converter, and security hardening
Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 6d564261b2 chore(release): bump version to 4.5.0
Monospace font embedding feature release. Adds bundled JetBrains Mono +
Fira Code TTFs (asarUnpack), preview/print font picker with ligatures
toggle, and embedded fonts in PDF (xelatex fontspec), DOCX (OOXML
surgery), EPUB (--epub-embed-font + OPF manifest), and HTML (sidecar
CSS with base64 data URI).
2026-08-23 19:31:33 +05:30
amitwh f5dcffeb8d test(monospace): add end-to-end smoke test for PDF/DOCX/EPUB/HTML font embedding
Exercises the real export pipeline against the bundled JetBrains Mono TTFs:
- PdfFontHeader emits valid xelatex fontspec with correct family + Ligatures=NoCommon
- ExportCss.build emits @font-face with base64 data URI
- DocxFontEmbedder injects TTFs into pandoc-produced DOCX (word/fontTable.xml + word/fonts/)
- EpubFontEmbedder.patchManifest adds TTF entry to OPF <manifest>
- HTML export links the sidecar CSS which embeds the font

Run with: node tests/smoke-e2e-monospace.js
2026-08-23 19:31:33 +05:30
amitwh 7095b34280 style: apply Prettier formatting
Run after full implementation to enforce 2-space / 100-char / single-quote
conventions across all new + adjacent files.
2026-08-23 19:31:33 +05:30
amitwh 58868eece0 feat(IPC): expose get-monospace-settings + set-monospace-settings to renderer
Renderer already calls window.electronAPI.invoke('get-monospace-settings')
to apply body classes; this wires up the channel allowlist and main-process
handlers so the IPC actually returns the active monospace settings and
persists updates.
2026-08-23 19:31:33 +05:30
amitwh cd3385ec69 build: asarUnpack assets/fonts/** so packaged builds can read bundled TTFs
MonospaceFontConfig + print-preview.js already look in app.asar.unpacked
first; without this entry the bundled TTFs would be unreachable at runtime.
2026-08-23 19:31:33 +05:30
amitwh f04a20252f feat(export): wire DOCX export through DocxFontEmbedder
Embeds regular + bold TTF of the active monospace family into pandoc's
DOCX output. ODT uses pandoc's built-in font handling; RTF has no font
embedding capability (documented limitation).
2026-08-23 19:31:33 +05:30
amitwh e5e14c88ce feat(monospace): DocxFontEmbedder injects TTF into pandoc DOCX output
Idempotent. Patches fontTable.xml, [Content_Types].xml, .rels, styles.xml.
2026-08-23 19:31:33 +05:30
amitwh 7a5a2ecba6 feat(monospace): EPUB export embeds TTF via --epub-embed-font + manifest patch 2026-08-23 19:31:33 +05:30
amitwh fac0d3d4a6 feat(export): wire HTML export to monospace ExportCss (pandoc + fallback) 2026-08-23 19:31:33 +05:30
amitwh 269d4ac028 feat(monospace): wire PDF export to use bundled monospace font
Replaces -V monofont=Consolas with a generated xelatex/lualatex header
that fontspec-loads the bundled JetBrains Mono or Fira Code TTF. Adds
a cached settings reader with proper invalidation on store.set, and
reorders fallback engines to prefer lualatex (fontspec-capable) before
pdflatex.
2026-08-23 19:31:33 +05:30
amitwh cdc318ebc7 feat(monospace): add PdfFontHeader builder for xelatex fontspec 2026-08-23 19:31:33 +05:30
amitwh 0c4043121f chore(pandoc): cache parsed major/minor version for capability checks 2026-08-23 19:31:33 +05:30
amitwh 151be60b03 feat(monospace): print-preview iframe uses bundled monospace font
Inlines @font-face as base64 data URI so the iframe srcdoc can render
JetBrains Mono / Fira Code without depending on the parent window's
loaded @font-face sets. Reads family + ligature state from the
renderer-wide cache populated by applyMonospaceClasses().

Amit Haridas
2026-08-23 19:31:33 +05:30
amitwh 228ee04b09 feat(monospace): ExportCss embeds woff2 as base64 in CSS
Self-contained CSS for HTML export and print-preview iframe.
2026-08-23 19:31:33 +05:30
amitwh 9fd81ff5a0 fix(ascii): replace Google Fonts CDN with local fonts.css
ASCII generator now renders in bundled JetBrains Mono without internet,
matching the preview pane.
2026-08-23 19:31:33 +05:30
amitwh f22cacd554 feat(monospace): renderer toggles body classes on settings change
applyMonospaceClasses() is the single source of truth. Reads from
'get-monospace-settings' IPC; Task 20 adds the handler.
2026-08-23 19:31:33 +05:30
amitwh 2f3b552608 feat(monospace): wire preview + editor to --font-mono-active token 2026-08-23 19:31:33 +05:30
amitwh cb27b47b91 feat(monospace): add --font-mono-active / --font-mono-feature tokens
Body classes (.mono-fira, .mono-ligatures-on) flip the tokens for live
switching without re-rendering.
2026-08-23 19:31:33 +05:30
amitwh 01e2df44ed feat(monospace): register Fira Code @font-face in renderer
Two weights: 400 (Regular) and 700 (Bold). TTF only — woff2 is
generated lazily if profile reports it; Fira ships in TTF upstream.
2026-08-23 19:31:33 +05:30
amitwh adfa43c278 chore(monospace): extend download-tools with Fira Code downloader
Matches the existing version-pinned approach for Pandoc.
2026-08-23 19:31:33 +05:30
amitwh 879600da46 feat(monospace): bundle JetBrainsMono + FiraCode TTF assets
Both families are SIL OFL. TTF (not just woff2) is required so xelatex can
embed into PDF and jszip can inject into DOCX.
2026-08-23 19:31:32 +05:30
amitwh 7b73ab07d7 feat(monospace): add MonospaceFontConfig path resolver
Resolves dev vs packaged (asar.unpacked) TTF paths. Logs warn, returns null
when bundled font is missing.
2026-08-23 19:31:32 +05:30
amitwh 57bbf91245 feat(monospace): add settings schema + safe defaults
getDefaults(), getActiveMonoFont(), isLigaturesEnabled() with TDD.
2026-08-23 19:31:32 +05:30
amitwh 5178d91187 docs(monospace): approve design for embedded monospace font in preview + all exports
Bundles JetBrains Mono + Fira Code TTFs in assets/fonts/. Embeds them into
DOCX (jszip), passes path via xelatex fontspec for PDF, base64-injects
@font-face for HTML/EPUB. Replaces Consolas (Windows-only) and Google Fonts
CDN load in the ASCII generator window.

Adds user-pickable monospace family + ligature toggle (default JBM, no
ligatures) for ASCII column alignment.

Closes: N/A
Refs: docs/superpowers/specs/2026-06-30-monospace-font-embedding-design.md

Amit Haridas
2026-08-23 19:31:32 +05:30
amitwh 3f0bf911a0 chore(repo-map): add auto-generated structural map
Generated with ~/.claude-shared/scripts/repo-map.sh (universal-ctags).
Signatures-only map of classes/functions/methods/interfaces/enums.

Amit Haridas
2026-07-18 07:23:25 +05:30
amitwh 2cac075c0e fix(word): harden DOCX preprocessing and temp-file cleanup
- Make the HTML preprocessor code-block and inline-code aware so code

  examples containing <style> / <div> / comments are preserved.

- Strip all raw <div> tags (not just alignment attributes) to avoid

  malformed output from unmatched closing tags.

- Handle uppercase tags and single/unquoted attributes.

- Create temporary DOCX input files inside private mkdtemp directories

  instead of predictable names in the shared temp directory.

- Wrap batch DOCX preprocessing in try/catch so one unreadable file

  does not abort the entire batch.

- Add regression tests for the edge cases above.
2026-06-30 19:57:40 +05:30
amitwh 94906a068a chore(release): bump version to 4.4.5 2026-06-30 13:57:34 +05:30
amitwh e72b863362 fix(word): strip HTML style blocks and alignment divs from DOCX input
Pre-process markdown before Word/DOCX export to remove raw HTML artifacts

(<style> blocks, HTML comments, and <div align=...> tags) that were

visible in the generated document. Applies to single and batch DOCX exports

via both Pandoc and WordTemplateExporter paths.
2026-06-30 13:57:29 +05:30
amitwh d705cfc30b fix(batch): resolve pandoc path handling and include-subfolders option
- Normalize pandoc command parsing with path.basename() to support bundled binary paths
- Use bundled pandoc binary in convertWithPandoc instead of relying on PATH
- Forward includeSubfolders checkbox state from renderer to main process
- Add pandoc availability check before batch conversion
- Re-enable Start button when batch conversion completes
- Clean up obsolete dist build artifact causing test snapshot warning
- Bump version to 4.4.4
2026-06-30 12:56:33 +05:30
amitwh 02e307f758 docs(claude-md): add tailored CLAUDE.md for master branch
Documents project architecture, Pandoc dependency resolution, build
pipeline (electron-builder, no bundler), security model notes
(contextIsolation: false on this branch), and development commands
extracted from actual package.json and source.

Amit Haridas
2026-06-19 23:18:00 +05:30
amitwh 5ad1d1d4b3 chore(release): bump version to 4.4.3 2026-06-11 21:17:37 +05:30
amitwh f480449301 fix(renderer): resolve syntax errors and undefined electronAPI on startup 2026-06-11 21:15:25 +05:30
amitwh 96df5652d6 fix: resolve list-directory IPC handler closing brace syntax error 2026-05-26 11:39:57 +05:30
amitwh a9e05d2c0f feat: implement Custom Preview CSS, Reveal.js options, Large File Mode, and Interactive PDF Thumbnail Sidebar 2026-05-25 23:11:47 +05:30
amitwh c982b3e90f chore(diagnostics): add logging to _renderPreview to trace markdown rendering
This will help identify whether the issue is:
1. marked.parse returning a Promise instead of string
2. DOMPurify.sanitize failing
3. The preview element not existing
4. Libraries not being loaded

Amit Haridas
2026-05-25 00:32:27 +05:30
amitwh cfaafc07b2 chore(deps): update vulnerable packages to patched versions
Updated packages:
- simple-git 3.32.3 → 3.36.0 (RCE vulnerability)
- fast-uri 3.1.0 → 3.1.2 (host confusion, path traversal)
- dompurify 3.3.1 → 3.4.5 (XSS bypasses)
- mermaid 11.13.0 → 11.15.0 (CSS injection, DoS)
- uuid 11.1.0 → 11.1.1 (buffer bounds check)
- ws 8.20.0 → 8.20.0 (uninitialized memory)
- ip-address 10.1.0 → 10.2.0 (XSS)
- @xmldom/xmldom 0.8.11 → 0.9.10 (XML injection, DoS)
- docx4js 3.3.0 → 2.0.1 (breaks xml2js dep chain)
- brace-expansion (transitive update)

Also applied lint:fix autofix (const correctness).

Amit Haridas
2026-05-25 00:00:28 +05:30
amitwh 94ad99dc4d fix(renderer): ensure tab content visibility after file open
- Add missing updateUI() call at end of openFile() to set .active class
  on tab content. Without this, the CSS rule .tab-content:not(.active)
  { display: none } kept newly opened files invisible.
- Add diagnostic logging to file-opened IPC handler and openFile()
  to trace future file loading issues.
- Add diagnostic logging to openFileFromPath() in main process.

Amit Haridas
2026-05-24 23:54:31 +05:30
amitwh baf644d62b fix(modal): prevent duplicate ModalManager declaration
window.ModalManager was set unconditionally, causing "Identifier
'ModalManager' has already been declared" when script tag in HTML
also loaded ModalManager before renderer.js required it.

Now checks !window.ModalManager before setting.

Amit Haridas
2026-05-22 22:08:06 +05:30
amitwh f9a5420ad2 4.4.1: update version everywhere, fix DOMPurify initialization
- Bump version to 4.4.1
- DOMPurify now initialized with window context (fixes markdown rendering)
- Add 'it' to eslint globals

Amit Haridas
2026-05-22 21:54:05 +05:30
amitwh f8361174f2 chore: add it to eslint globals, add debug logging to createEditor
Amit Haridas
2026-05-22 21:42:34 +05:30
amitwh 64df0660c8 fix(renderer): initialize DOMPurify with window context
require('dompurify') returns a factory function, not a sanitizer
instance. Calling .sanitize() on the factory threw a TypeError,
which was caught by the preview renderer's try-catch and displayed
a generic "Error rendering preview" message. Fix by invoking the
factory with the renderer's window object.

Amit Haridas
2026-05-03 16:38:47 +05:30
amitwhandCopilot bbfa2a38e9 security: add permission request handler for security isolation
Restrict Electron permission requests to only clipboard operations.
Deny: camera, microphone, geolocation, notifications, and all other
permissions by default.

Implements setPermissionRequestHandler on web-contents-created event
to enforce security policy early in the app lifecycle.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-24 17:19:52 +05:30
amitwhandCopilot 94ec3f45ce fix: show dynamic app version everywhere in UI
- Add get-app-version IPC handler in main.js (returns app.getVersion())
- Expose electronAPI.getAppVersion() in preload.js
- index.html: replace hardcoded v4.2.0 span with dynamic population
  from getAppVersion() in DOMContentLoaded
- welcome.js: accept appVersion param instead of hardcoded 4.1.0
- renderer.js: pass live version to createWelcomeContent()
- main.js about screen: use app.getVersion() instead of hardcoded 4.1.0
- Update stale @version 4.1.0 JSDoc comments to 4.3.0

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-23 23:31:18 +05:30
amitwhandCopilot a6747b12f0 fix: pass --publish=never to electron-builder in CI
electron-builder detects git tags in CI and tries to auto-publish to
GitHub, failing with 'GH_TOKEN not set'. We handle the release
separately via softprops/action-gh-release, so suppress auto-publish.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-23 23:16:20 +05:30
amitwhandCopilot 7a641b2618 fix: use deb+AppImage only in CI, release job continues if build fails
- Add build:linux-ci script (deb + AppImage, no snap — snapcraft not
  available on ubuntu-latest runners without extra setup)
- Switch release.yml linux build to npm run build:linux-ci
- release job: if: always() so Windows artifacts still get released
  even if linux build fails
- Download artifact steps: continue-on-error so missing platform
  doesn't block GitHub Release creation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-23 23:07:09 +05:30
amitwhandCopilot edefcb8409 fix: drop rpm build target and stale system tool depends
- Remove rpm from linux build targets (rpmbuild not available locally)
  CI can add it back with apt-get if needed, but pandoc/ffmpeg are now
  bundled so the rpm depends were incorrect anyway
- Remove rpmbuild apt install step from release.yml (not needed)
- Remove pandoc/ffmpeg from deb depends — they are now bundled binaries
- Keep imagemagick and libreoffice-common in deb depends (not bundled)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-23 23:00:00 +05:30
amitwhandCopilot 5ee986fab8 fix: bundle pandoc+ffmpeg, fix CI pipeline and Windows GitHub build
- Remove package-lock.json from .gitignore so npm ci works in CI
- Refactor main.js: delegate PDF ops to src/main/PDFOperations.js,
  git ops to src/main/GitOperations.js
- getPandocPath(): use bundled binary from resources/bin/ when packaged,
  fall back to dev bin/ or system pandoc in development
- getFFmpegPath(): use ffmpeg-static (asarUnpack) when packaged
- Install ffmpeg-static (v5.3.0, bundled 76MB binary)
- Add scripts/download-tools.js to fetch pandoc binary at build time
  (idempotent, runs on CI before electron-builder)
- electron-builder: add asarUnpack for ffmpeg-static, extraFiles for
  pandoc binary per platform (linux + win32)
- release.yml: switch build-windows to windows-latest runner with native
  NSIS support; add cert decode step; add download-tools step for both
  linux and windows jobs
- Fix lint error: hoist outlinePanelContainer to module scope so
  TabManager methods can reference it without no-undef errors

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-23 22:56:41 +05:30
amitwh c1573dba08 feat(writing-studio): add four sidebar panels (goals, snapshots, manuscript, proofread)
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 9576abc979 feat(writing-studio): add plugin manifest and entry point
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh caa3f3d35a feat(writing-studio): add project manager with compile and stats
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 2a6f0fc302 feat(writing-studio): add snapshot manager with diff and prune
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 4da5b7b9c4 feat(writing-studio): add goal tracker with streaks and history
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 1ba42592d7 feat(writing-studio): add sprint engine with WPM tracking
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh bc6f1a7d41 docs(writing-studio): add implementation plan for Writing Studio plugin
12 tasks across 9 chunks: SprintEngine, GoalTracker, SnapshotManager,
ProjectManager, manifest+entry point, 4 sidebar panels, CSS, timer UI.

Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 539502d7ff feat(plugins): wire plugin system into app initialization
- Add plugin system bootstrap in renderer.js after sidebar/commands init
- Wire status bar DOM insertion, editor API, and IPC adapters
- Add plugin-settings:get/set IPC channels to preload allowlist
- Add IPC handlers in main process using existing settings store
- Fix eqeqeq warning in EventBus.hasHandler

Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh b5771dd914 feat(plugins): add sample plugin demonstrating the system
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh a816b6ec32 feat(plugins): add PluginContext, PluginRegistry, and SettingsStore
- PluginContext: scoped API with crash-safe command wrappers
- PluginRegistry: lifecycle management with graceful init failure
- SettingsStore: plugin-scoped key/value via IPC backend
- Export hooks: pre/post hooks on registry for cross-plugin integration

Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 54c9484cb5 feat(plugins): add PluginLoader with manifest discovery and validation
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 36e26318cd feat(plugins): add PluginAPI base class with no-op lifecycle
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 8abd580295 feat(plugins): add EventBus with typed events and crash-safe handlers
Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 80294c9876 docs: add plugin system implementation plan
9 tasks across 8 chunks, strict TDD:
- EventBus with crash-safe handlers
- PluginAPI base class
- PluginLoader with manifest validation
- PluginContext with scoped API
- PluginRegistry with lifecycle management
- SettingsStore for plugin-scoped settings
- Export hooks integration
- Sample plugin + renderer wiring

Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh 148b549c83 docs: harden v5.0 spec based on review
- GGUF GPU: child process isolation with crash detection/restart
- Event bus: versioned payload schemas for all events
- Plugin sandbox: 5s handler timeout, IPC delegation for heavy ops
- AI streaming: full lifecycle with requestId, cancel, heartbeat, orphan cleanup
- Comment anchors: context-based positioning (not byte offsets) with re-anchor on file change
- Cross-plugin: capability discovery, 30s timeout, graceful degradation
- Bundle size: GPU variants as lazy downloads, not bundled by default
- Command uniqueness: registry rejects duplicates at load time

Amit Haridas
2026-04-23 22:55:12 +05:30
amitwh a3b4065984 docs: add v5.0 platform design spec
Plugin-first architecture with four subsystems:
- Plugin system (registry, context API, event bus)
- Writing Studio (manuscript manager, sprints, snapshots, proofreading)
- AI Assistant (multi-provider: Ollama, LMStudio, GGUF+GPU, cloud APIs)
- Collaboration (git-based async, comments, review requests)

Amit Haridas
2026-04-23 22:55:12 +05:30
amitwhandCopilot 620227307d release: v4.3.0 - fix Windows SmartScreen blocking, add signing support
- Remove signAndEditExecutable:false so code signing works properly
- Add legalTrademarks and copyright metadata to build config
- Add publisherName via build.copyright (embedded in PE resources)
- Create scripts/create-selfsigned-cert.ps1 for local dev signing
- Update release.yml: build on windows-latest runner (not Wine),
  auto-sign when CSC_LINK_BASE64/CSC_KEY_PASSWORD secrets present,
  fall back to unsigned otherwise
- Add lint step to ci.yml (Phase 4.3 plan gap)
- Add .vscode/launch.json debug configs (Phase 4.3 plan gap)
- Fix .gitignore: exclude *.pfx/*.p12 cert files, track launch.json,
  fix concatenated agents.md/coverage/ lines

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-19 18:20:19 +05:30
amitwh 4426b75c6f fix: improve tab safety and app feedback 2026-04-14 22:30:46 +05:30
amitwh b7e12f7010 fix(deps): resolve all dependabot vulnerabilities
- Upgrade electron 37 -> 41
- Override lodash-es to patched version
- Zero vulnerabilities remaining

Amit Haridas
2026-04-06 20:51:41 +05:30
amitwh f0ab54cd60 chore: bump to v4.2.0 — Writer's Studio Feature Pack
Amit Haridas
2026-04-06 11:44:29 +05:30
amitwh 72a7a854d0 feat(analytics): add writing analytics with readability scores and vocabulary analysis
Amit Haridas
2026-04-06 11:42:22 +05:30
amitwh 50d0638c5c feat(zen): add distraction-free writing mode with typewriter scrolling
Zen mode hides all chrome and centers the editor with typewriter
scrolling, line dimming, and a floating word count HUD.
Toggle with F11, exit with Escape.

Amit Haridas
2026-04-06 11:37:51 +05:30
amitwh 7a3493e54f fix(outline): add tab-switch refresh and dark mode styles
Amit Haridas
2026-04-06 11:05:54 +05:30
amitwh b1a5784bcc feat(outline): add document outline sidebar panel with heading navigation
Amit Haridas
2026-04-06 10:40:29 +05:30
amitwh 24cb99658e docs: add Writer's Studio implementation plan
Detailed step-by-step plan for Zen Mode, Document Outline,
and Writing Analytics with exact file paths and code.

Amit Haridas
2026-04-06 07:47:35 +05:30
amitwh c042cf4580 docs: add Writer's Studio feature pack design
Design for three cohesive features: Zen Mode, Document Outline,
and Writing Analytics. Approved for v4.2.0.

Amit Haridas
2026-04-06 07:36:18 +05:30
amitwh ed4279f4df feat: bump to v4.1.0 and add CI/CD release pipeline
- Bump version to 4.1.0 in package.json and index.html
- Add build:local script for combined Linux + Windows local builds
- Add CI workflow: runs tests on push/PR to master
- Add Release workflow: tag-triggered (v*), parallel Linux + Windows
  builds, publishes all packages to GitHub Releases

Amit Haridas
2026-03-25 22:20:53 +05:30
amitwh adc8dabda1 fix: resolve modal stacking, animation, and close cleanup bugs
- Set backdrop z-index:0 and content z-index:1 to fix backdrop covering
  modal content within the stacking context
- Force reflow between removing hidden and adding open class so CSS
  opacity transition fires correctly
- Add transitionend listener + setTimeout fallback to restore hidden
  class after close animation completes
- Override flex:1 on modal footer buttons to prevent full-width stretch
- Add min-width to modal size variants for consistent sizing
- Add 23 tests covering open/close lifecycle, keyboard, and destroy

Amit Haridas
2026-03-25 22:20:34 +05:30
amitwh 5911a7501b fix: guard window assignment for CommonJS compatibility 2026-03-24 22:37:40 +05:30
amitwh d998b03ca1 fix: remove ES6 export keyword for browser compatibility 2026-03-24 19:08:14 +05:30
amitwh 31468e77c5 refactor: remove old dialog CSS in favor of unified modal system
Amit Haridas
2026-03-24 16:50:09 +05:30
amitwh 2022352ed1 refactor: update renderer.js to use ModalManager for all dialogs
- Import ModalManager and create instances for all 10 dialogs
- Replace classList.add/remove('hidden') with modal.open()/close()
- Remove duplicate backdrop click and escape key handlers (now handled by ModalManager)
- Update print-preview.js to use ModalManager when available
- Add CommonJS export to ModalManager for renderer compatibility

Dialogs updated:
- find-dialog (findModal)
- export-dialog (exportModal)
- print-preview-overlay (printPreviewModal)
- table-generator-dialog (tableModal)
- ascii-art-dialog (asciiModal)
- universal-converter-dialog (converterModal)
- batch-dialog (batchModal)
- pdf-editor-dialog (pdfEditorModal)
- header-footer-dialog (headerFooterModal)
- field-picker-dialog (fieldPickerModal)

Amit Haridas
2026-03-24 16:44:20 +05:30
amitwh 6bac18d270 feat: convert all dialogs to unified modal structure
Convert 10 dialogs from old classes (.export-dialog, .batch-dialog, .find-dialog)
to the new unified .modal structure with proper accessibility attributes.

Changes:
- find-dialog: small modal with find/replace controls
- export-dialog: large modal with export options
- print-preview-overlay: full-size modal for print preview
- table-generator-dialog: default modal for table creation
- ascii-art-dialog: large modal for ASCII art generation
- universal-converter-dialog: large modal for file conversion
- batch-dialog: large modal for batch processing
- pdf-editor-dialog: full-size modal for PDF editing
- header-footer-dialog: default modal for header/footer config
- field-picker-dialog: small modal for field selection

All dialogs now include:
- role="dialog" and aria-modal="true" for accessibility
- aria-labelledby pointing to title element
- .modal-backdrop with data-close attribute
- .modal-content with appropriate size class
- .modal-header with title and close button
- .modal-body for content
- .modal-footer with action buttons

Amit Haridas
2026-03-24 16:30:52 +05:30
amitwh fdfd778d94 feat: include modal.css and ModalManager in index.html
Amit Haridas
2026-03-24 16:23:59 +05:30
amitwh 30f6198f1d feat: add modal CSS with glassmorphism and animations
Amit Haridas
2026-03-24 16:22:41 +05:30
amitwh 253608e17f feat: add ModalManager class for unified modal system
Amit Haridas
2026-03-24 16:20:03 +05:30
amitwh 763bea2a87 docs: add modal system implementation plan 2026-03-24 14:01:30 +05:30
amitwh 73795d1ad8 docs: add modal system design document 2026-03-24 13:53:27 +05:30
amitwh f81426f019 security: fix all npm vulnerabilities
- Remove unused xlsx dependency (had unfixable vulnerabilities)
- Add npm overrides to force secure versions:
  - jszip ^3.10.1 (fixes path traversal)
  - nth-check ^2.1.1 (fixes ReDoS)
  - lodash.pick -> lodash ^4.17.21 (fixes prototype pollution)

Result: 0 vulnerabilities (was 11)

Amit Haridas
2026-03-24 10:04:21 +05:30
amitwh fe4d634163 feat: add Shadcn/ui design tokens and accessibility improvements
- Add src/styles/tokens.css with comprehensive design tokens
- Define color tokens (primary, secondary, accent, destructive, etc.)
- Add spacing, typography, shadow, and transition tokens
- Include dark mode token overrides
- Add utility classes (btn, badge, input variants)
- Add skip-link for keyboard navigation
- Update index.html to include tokens.css

This enables consistent theming and easier future UI updates.

Amit Haridas
2026-03-24 09:55:18 +05:30
amitwh 3bc703d8dc feat: add platform adapter structure for V4
- Create adapters/types.js with comprehensive type definitions
- Create adapters/electron/fs.js for file system operations
- Prepare structure for future migration to Tauri/Flutter

This abstraction layer makes future platform migration easier
and enables better testing with mock adapters.

Amit Haridas
2026-03-24 09:06:21 +05:30
amitwh 78200b8d6a perf: add debounced preview rendering for better typing performance
- Add previewDebounceTimers map to track debounce timers per tab
- Add updatePreview(tabId, immediate) with optional immediate flag
- Debounce preview updates during typing (300ms delay)
- Use immediate=true for tab switches and file loads
- Refactor _renderPreview as internal method

This significantly improves editor responsiveness when typing
in large markdown files.

Amit Haridas
2026-03-24 08:59:49 +05:30
amitwh 0987058aa2 fix: integrate PDF viewer into tab system for multitab support
- Add tab type system ('markdown' and 'pdf')
- Create PDF tabs with their own state (page, zoom, rotation)
- Update closeTab to properly clean up PDF resources
- Update updateUI to handle PDF tabs (hide toolbar, etc.)
- Add visual indicators for PDF tabs in tab bar
- Add CSS styles for PDF tab containers

Fixes: PDF and markdown multitab function not working

Amit Haridas
2026-03-24 08:55:39 +05:30
amitwh cbf0b4897d docs: add V4 enhancement + Flutter exploration design
- 70% V4 enhancements: fix multitab bug, performance optimizations,
  platform adapters, Shadcn/ui patterns
- 30% Flutter exploration: prototype for Windows, Mobile, Web evaluation

Amit Haridas
2026-03-24 00:10:47 +05:30
amitwh f1740c6bb6 docs: add detailed implementation plan for v5.0 migration
Phase 1 (Foundation) tasks with step-by-step instructions:
- Task 1-2: Project initialization (Vite, React, TypeScript)
- Task 3-4: Tailwind CSS + Shadcn/ui configuration
- Task 5: Zustand stores (editor, settings, theme, sidebar)
- Task 6-8: Platform adapter pattern (types, web, tauri stubs)
- Task 9: Tauri project initialization
- Task 10: Basic layout components

Each task includes:
- Exact file paths
- Complete code snippets
- Build verification steps
- Commit messages

Amit Haridas
2026-03-15 09:57:51 +05:30
amitwh 8319953ccf docs: add React + Tauri + PWA architecture design for v5.0
Comprehensive design document covering:
- Project structure with platform adapters
- React component architecture
- Zustand state management
- Platform adapter pattern (Tauri + Web)
- Build configuration (Vite, Tailwind, TypeScript)
- Tauri backend (Rust) IPC commands
- PWA configuration with Service Worker
- 8-week migration plan
- Security improvements over Electron

Approved design for parallel development alongside v4.x

Amit Haridas
2026-03-15 09:53:18 +05:30
amitwh 95ea870039 feat: apply JetBrains Mono font to editor and preview code
- Add custom EditorView.theme for CodeMirror 6 with JetBrains Mono
- Update .editor-textarea and #editor font-family to prioritize JetBrains Mono
- Update preview code blocks (#preview code, .preview-content code) to use JetBrains Mono
- Ensures consistent monospace font across editor source and markdown rendering

Amit Haridas
2026-03-15 08:39:53 +05:30
amitwh d1c2c1c109 refactor: standardize dark theme selectors and add CSS variables
CSS improvements:
- Standardize dark theme selectors to body[class*="dark"] pattern
- This ensures all dark themes (theme-dark, theme-dracula, etc.)
  receive consistent styling
- Add semantic color variables (--text-primary, --bg-primary, etc.)
- Replace hardcoded colors with CSS variables in:
  - Tab bar component
  - Toolbar separator
  - Pane resizer
  - Status bar
- Add fallback values for backward compatibility

This improves maintainability and makes theming more consistent.

Amit Haridas
2026-03-15 00:50:10 +05:30
amitwh daae83bcf4 a11y: add comprehensive focus and accessibility styles
Accessibility improvements:
- Add global focus-visible styles for keyboard navigation
- Add focus-visible for sidebar panel close button
- Add skip-link styles for screen reader users
- Add .sr-only class for visually hidden content
- Add prefers-reduced-motion support for users sensitive to motion
- Add prefers-contrast: high support for high contrast mode

Amit Haridas
2026-03-15 00:42:41 +05:30
amitwh 7723b302ea style: improve CSS organization and add state components
CSS improvements:
- Remove duplicate CSS reset from styles-modern.css
- Add focus-visible styles for sidebar icons
- Add error/loading state components (skeleton, spinner, messages)
- Add success, warning, info message components
- Add dark theme support for new components

Code quality:
- Replace inline error style with CSS class in renderer.js

Amit Haridas
2026-03-15 00:41:11 +05:30
amitwh 94506ccb00 security: harden CSP, add path traversal protection, improve accessibility
Security fixes:
- Remove external CDN sources from CSP (cdn.jsdelivr.net, cdnjs.cloudflare.com)
- Add path validation functions to prevent path traversal attacks
- Block access to sensitive system directories
- Add isPathAccessible() check for file operations

UI/Accessibility fixes:
- Increase tab close button from 16px to 24px for better touch targets
- Add focus-visible styles for keyboard navigation
- Add ARIA labels to all toolbar buttons
- Add aria-hidden="true" to decorative SVG icons
- Add role="tablist" and role="tab" to tab bar
- Fix duplicate font-size declaration in .preview-content

Reports generated:
- Security vulnerability scan (10 findings)
- STRIDE threat model with MITRE ATT&CK mapping
- Comprehensive UI design review (40 issues)

Amit Haridas
2026-03-15 00:38:58 +05:30
amitwh 01d833f520 fix: resolve editor, batch conversion, and startup performance issues
- Remove popout preview button (HTML, JS, CSS)
- Fix Save/Save As flow for new untitled files
- Fix batch conversion menu items (wire show-batch-converter IPC)
- Add universal-convert-batch IPC handler for batch file conversion
- Lazy-load mermaid, pdfjs-dist, sidebar panels, command palette
- Switch highlight.js CSS from CDN to local
- Defer CodeMirror language extensions until first use
- Add show:false + ready-to-show for faster perceived startup
- Install mermaid as local dependency (remove CDN script tag)
2026-03-04 17:44:04 +05:30
amitwh 10d2fc8b8f fix: resolve lint errors for v4 release
- Fix duplicate editorContainer declaration in renderer.js
- Add missing browser globals to eslint config (prompt, FileReader, etc.)
- Add global object for Jest test setup
- Replace path.basename with portable string split in logo preview
2026-03-04 16:35:56 +05:30
amitwh 0344a48f20 docs: add v4.0.0 changelog 2026-03-04 16:33:38 +05:30
amitwh 3c11ac15ce feat: update application menu with all v4 features 2026-03-04 16:33:00 +05:30
amitwh c5a9881d8d feat: update preload.js with all v4 IPC channels 2026-03-04 16:31:28 +05:30
amitwh 15903e782a test: add comprehensive tests for v4 features
Add unit tests for sidebar manager, command palette, print preview,
main process utilities, and markdown extensions. Update jest config
to exclude untestable Electron-specific files from coverage and
raise coverage thresholds.
2026-03-04 16:28:36 +05:30
amitwh 336b24365d feat: add welcome tab, presentation/publishing exports, and spell checking
- Developer format support (JSON, YAML, XML, TOML) import/export
- Presentation export (Reveal.js slides, Beamer PDF)
- Publishing format exports (Confluence wiki, MOBI e-book)
- Enable system spell checking with context menu suggestions
- Add welcome tab with onboarding and feature showcase
2026-03-04 16:24:05 +05:30
amitwh b5409b7754 feat: add developer format support (JSON, YAML, XML, TOML) 2026-03-04 16:23:37 +05:30
amitwh d3afd7ad86 feat: wire up sidebar panels and REPL with IPC handlers, preload channels, and CSS 2026-03-04 16:17:38 +05:30
amitwh 59ef2028f8 feat: add code execution REPL with JS, Python, Bash support 2026-03-04 16:17:34 +05:30
amitwh f62a6b7e59 feat: add code snippets sidebar panel with CRUD 2026-03-04 16:17:30 +05:30
amitwh f650b04685 feat: add Git sidebar panel (status, stage, commit, log) 2026-03-04 16:17:26 +05:30
amitwh 04480c1243 feat: add File Explorer sidebar panel 2026-03-04 16:17:22 +05:30
amitwh 81a78412fd feat: add PlantUML diagram support alongside Mermaid 2026-03-04 16:10:47 +05:30
amitwh 12dcd2d1a3 feat: add document templates library with 10 templates 2026-03-04 16:10:24 +05:30
amitwh ae7b333cea feat: add image paste and drag-drop support 2026-03-04 16:08:55 +05:30
amitwh e2703d8c57 feat: add markdown extensions (footnotes, admonitions, TOC) 2026-03-04 16:08:22 +05:30
amitwh ca0b250506 feat: add custom print preview dialog with configurable options 2026-03-04 16:04:51 +05:30
amitwh 9348b2bd1d security: add file size validation, error sanitization, and rate limiting 2026-03-04 16:00:57 +05:30
amitwh 200e800eb2 security: add Content Security Policy meta tag 2026-03-04 16:00:53 +05:30
amitwh a6456a7b4c feat: add breadcrumb bar showing current file path
Display the active file path below the toolbar with dark theme
support and monospace font for path readability.
2026-03-04 15:56:55 +05:30
amitwh 3908df8b1d feat: add command palette (Ctrl+Shift+P)
Refactor inline command palette into a proper CommandPalette class
with search highlighting, keyboard navigation, and overlay UI.
Register all app actions including formatting, file ops, and sidebar
toggles.
2026-03-04 15:56:24 +05:30
amitwh 72ee803a95 feat: reorganize toolbar into grouped sections with separators
- Grouped toolbar buttons into logical sections: Format, Structure, Insert, View
- Added toolbar-group CSS class for visual grouping
- Updated button titles with keyboard shortcut hints
- Enhanced status bar HTML structure with left/right layout
2026-03-04 15:50:36 +05:30
amitwh 37502fb733 feat: enhanced status bar with word count, char count, line/col, encoding
- Restructured status bar into left/right sections with separators
- Added character count, cursor line/column position, encoding, and language mode indicators
- Added cursor position tracking via CodeMirror onUpdate callback
- Added file path display that updates on tab switch
- Simplified word count display for cleaner status bar layout
2026-03-04 15:50:31 +05:30
amitwh affe1a7e33 feat: add sidebar panel system with icon strip and panel toggle 2026-03-04 15:45:34 +05:30
amitwh ed48f254f1 feat: migrate find/replace to use CodeMirror search 2026-03-04 15:42:09 +05:30
amitwh 0c2b6fe5cc feat: migrate undo/redo to CodeMirror built-in history 2026-03-04 15:41:33 +05:30
amitwh 233225f12c feat: replace textarea with CodeMirror 6 editor 2026-03-04 15:38:33 +05:30
amitwh 47f3b7557e feat: add CodeMirror 6 wrapper module 2026-03-04 15:31:42 +05:30
amitwh 7678c61602 chore: add v4 dependencies (CodeMirror extensions, simple-git, marked plugins) 2026-03-04 15:30:01 +05:30
amitwh 6e7460def7 chore: update html2pdf.js and pdfkit 2026-03-04 15:29:22 +05:30
amitwh bf67156b9c feat: upgrade pdfjs-dist from 3.x to 5.x for improved PDF viewer
Update worker path from .js to .mjs to match the new ESM-only build
structure in pdfjs-dist v5. Core API (getDocument, getPage, render)
remains compatible.
2026-03-04 15:28:07 +05:30
amitwh 824f659e13 feat: upgrade marked to v17 with marked-highlight extension
- Update marked from ^16.2.1 to ^17.0.3
- Add marked-highlight ^2.2.3 for syntax highlighting support
- Replace deprecated marked.setOptions() with marked.use() in renderer.js
- Extract highlight config into markedHighlight() extension (required in v17)
- Update test mock to reflect new API (use instead of setOptions)
2026-03-04 15:24:46 +05:30
amitwh e7eff01db6 chore: update non-breaking dependencies (dompurify, docx, highlight.js, pdf-lib) 2026-03-04 15:22:18 +05:30
amitwh 7b15b2808e chore: bump version to 4.0.0 2026-03-04 15:20:25 +05:30
479 changed files with 113560 additions and 22512 deletions
+9
View File
@@ -0,0 +1,9 @@
# Text artifacts that are hash-pinned must check out byte-identical everywhere
assets/fonts/FiraCode-LICENSE.txt -text
# Binaries: never normalize
*.ttf -text
*.woff -text
*.woff2 -text
*.png -text
*.ico -text
*.icns -text
+28
View File
@@ -0,0 +1,28 @@
name: CI
on:
push:
branches: [master]
pull_request:
branches: [master]
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Run tests
run: npm test
- name: Run linter
run: npm run lint
+196
View File
@@ -0,0 +1,196 @@
name: Release
on:
push:
tags: ['v*']
permissions:
contents: write
jobs:
build-linux:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Download external tools (pandoc)
run: node scripts/download-tools.js
- name: Bundle MarkItDown (optional, best effort)
# Freezes markitdown + Python into bin/linux/markitdown; failure is
# non-fatal — the build then ships without it and the app falls back
# to a system markitdown at runtime.
run: npm run bundle:markitdown
continue-on-error: true
- name: Run tests
run: npm test
- name: Build Linux packages
run: npm run build:linux-ci -- --publish=never
- name: Upload Linux artifacts
uses: actions/upload-artifact@v4
with:
name: linux-artifacts
path: |
dist/*.deb
dist/*.AppImage
dist/*.snap
dist/*.rpm
retention-days: 5
build-windows:
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Download external tools (pandoc)
run: node scripts/download-tools.js
- name: Bundle MarkItDown (optional, best effort)
# Windows runners ship python + venv; non-fatal on failure — the
# package then omits the bundled binary by design. We capture the
# log so a silent failure is visible in the GitHub Actions step UI
# instead of disappearing into stdout.
run: |
python -m pip install --upgrade pip wheel setuptools 2>&1 | tee bundle-pip.log
npm run bundle:markitdown 2>&1 | tee bundle-markitdown.log
if [ ! -f bin/win32/markitdown.exe ]; then
echo "::warning::bin/win32/markitdown.exe was not produced — see bundle-markitdown.log"
fi
continue-on-error: true
shell: bash
- name: Upload MarkItDown bundle logs (on failure)
if: failure()
uses: actions/upload-artifact@v4
with:
name: windows-bundle-logs
path: |
bundle-pip.log
bundle-markitdown.log
retention-days: 5
- name: Run tests
run: npm test
- name: Decode certificate (if available)
if: ${{ env.CSC_LINK_BASE64 != '' }}
shell: pwsh
env:
CSC_LINK_BASE64: ${{ secrets.CSC_LINK_BASE64 }}
run: |
$bytes = [Convert]::FromBase64String("$env:CSC_LINK_BASE64")
[IO.File]::WriteAllBytes("${{ github.workspace }}\code-signing-cert.pfx", $bytes)
echo "CERT_AVAILABLE=true" >> $env:GITHUB_ENV
- name: Build Windows packages (signed)
if: ${{ env.CERT_AVAILABLE == 'true' }}
env:
CSC_LINK: code-signing-cert.pfx
CSC_KEY_PASSWORD: ${{ secrets.CSC_KEY_PASSWORD }}
run: npm run build:win-signed -- --publish=never
- name: Build Windows packages (unsigned)
if: ${{ env.CERT_AVAILABLE != 'true' }}
env:
CSC_IDENTITY_AUTO_DISCOVERY: 'false'
run: npm run build:win-unsigned -- --publish=never
- name: Upload Windows artifacts
uses: actions/upload-artifact@v4
with:
name: windows-artifacts
path: |
dist/*.exe
dist/*.zip
retention-days: 5
build-macos:
runs-on: macos-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Download external tools (pandoc)
run: node scripts/download-tools.js
- name: Bundle MarkItDown (optional, best effort)
run: npm run bundle:markitdown
continue-on-error: true
- name: Run tests
run: npm test
- name: Build macOS packages
run: npm run build:mac -- --publish=never
- name: Upload macOS artifacts
uses: actions/upload-artifact@v4
with:
name: macos-artifacts
path: |
dist/*.dmg
dist/*.zip
retention-days: 5
release:
needs: [build-linux, build-windows, build-macos]
if: always()
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Download Linux artifacts
uses: actions/download-artifact@v4
continue-on-error: true
with:
name: linux-artifacts
path: dist
- name: Download Windows artifacts
uses: actions/download-artifact@v4
continue-on-error: true
with:
name: windows-artifacts
path: dist
- name: Download macOS artifacts
uses: actions/download-artifact@v4
continue-on-error: true
with:
name: macos-artifacts
path: dist
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
generate_release_notes: true
files: dist/*
+14 -2
View File
@@ -8,14 +8,22 @@ Thumbs.db
*.swp
*.swo
*~
.vscode/
.vscode/*
!.vscode/launch.json
.idea/
*.iml
out/
.cache/
.npm/
.electron/
package-lock.json
# package-lock.json is intentionally tracked for reproducible CI builds
# Downloaded tool binaries (fetched at build time via scripts/download-tools.js)
bin/
# Code signing certificates — never commit private keys
*.pfx
*.p12
# Screenshots and temp files
*.png.bak
@@ -34,3 +42,7 @@ pdf\ modal.png
.claude/
CLAUDE.md
agents.md
coverage/
# Superpowers brainstorm artifacts
.superpowers/
@@ -0,0 +1,469 @@
# Security Assessment Report: MarkdownConverter v4.0.0
**Assessment Date:** 2026-03-15
**Application:** MarkdownConverter - Electron-based Markdown editor and document converter
**Target Version:** 4.0.0
**Assessor:** Security Audit Agent
---
## Executive Summary
This assessment identified **10 security findings** ranging from **Critical to Low severity**. The most significant concerns involve insecure Electron security configuration that could allow XSS attacks to escalate to full system access, arbitrary code execution via the REPL feature, and missing input validation on file operations.
| Severity | Count |
|----------|-------|
| Critical | 2 |
| High | 3 |
| Medium | 3 |
| Low | 2 |
---
## Vulnerability Findings
### CVE-MC-001: Insecure Electron Security Configuration (Critical)
**CVSS 3.1 Score: 9.6 (Critical)**
**CWE-265: CWE-1021: Improper Restriction of Renderers**
**Location:** `src/main.js` (lines 328-332)
```javascript
webPreferences: {
nodeIntegration: true,
contextIsolation: false,
spellcheck: true
},
```
**Description:**
The main application window has `nodeIntegration: true` and `contextIsolation: false`, which is the most insecure Electron configuration. This allows the renderer process direct access to Node.js APIs, meaning any XSS vulnerability in the markdown rendering or external content could lead to full system compromise.
**Exploitability:**
- An attacker who can inject malicious JavaScript (via markdown files, XSS in preview, or compromised dependencies) gains immediate access to:
- Full file system read/write via `fs` module
- Command execution via `child_process`
- Network access via `net` module
- All system resources
**Attack Scenario:**
1. User opens a malicious markdown file containing embedded JavaScript
2. The JavaScript executes in the renderer with full Node.js access
3. Attacker can read sensitive files, execute commands, exfiltrate data
**Remediation:**
```javascript
webPreferences: {
nodeIntegration: false,
contextIsolation: true,
sandbox: true,
preload: path.join(__dirname, 'preload.js')
}
```
**Note:** The preload.js file already implements a secure IPC bridge but it is not being utilized for the main window.
---
### CVE-MC-002: Arbitrary Code Execution via REPL Feature (Critical)
**CVSS 3.1 Score: 9.3 (Critical)**
**CWE-94: Improper Control of Generation of Code ('Code Injection')**
**Location:** `src/main.js` (lines 4369-4396)
**Description:**
The `execute-code` IPC handler allows execution of arbitrary Python and Bash scripts through the REPL panel. While JavaScript execution appears to have been removed or limited, Python and Bash commands are executed via `execFile` with user-supplied code.
**Vulnerable Code Pattern:**
```javascript
ipcMain.handle('execute-code', async (event, { code, language }) => {
// ...
if (language === 'python' || language === 'py') {
cmd = 'python';
args = ['-c', code];
}
// ...
execFile(cmd, args, { timeout }, (err, stdout, stderr) => {
// ...
});
});
```
**Exploitability:**
- Users can be tricked into running malicious code blocks
- Markdown files can contain executable code blocks with "Run" buttons
- No sandboxing or permission restrictions on executed code
**Attack Scenario:**
1. Attacker creates markdown file with malicious Python code block
2. User clicks "Run" button in preview
3. Python code executes with user's full permissions
4. Attacker gains code execution on victim's machine
**Remediation:**
- Remove arbitrary code execution feature entirely, OR
- Implement strict sandboxing (Docker, VM, or restricted Python environment)
- Add user confirmation dialogs with clear warnings
- Execute in isolated environment with no filesystem/network access
- Implement allowlist of safe operations
---
### CVE-MC-003: Potential XSS in Markdown Rendering (High)
**CVSS 3.1 Score: 8.0 (High)**
**CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')**
**Location:** `src/renderer.js` (lines 387-419)
**Description:**
While DOMPurify is used to sanitize HTML, several extensions to marked.js may bypass sanitization:
1. **Custom Admonition Extension (lines 51-77):**
```javascript
marked.use({
extensions: [{
name: 'admonition',
// ...
renderer(token) {
const inner = this.parser.parse(token.text);
return `<div class="admonition admonition-${token.admonitionType}">
<div class="admonition-title">${icon} ${token.admonitionType...}</div>
<div class="admonition-content">${inner}</div>
</div>`;
}
}]
});
```
2. **innerHTML Assignments (line 419):**
```javascript
preview.innerHTML = sanitizedHtml;
```
**Exploitability:**
- Combined with CVE-MC-001, XSS leads to full system compromise
- Custom markdown extensions may not be properly sanitized
- Admonition type is directly interpolated into HTML without escaping
**Remediation:**
- Ensure all custom markdown extensions escape user input
- Add Content Security Policy that blocks inline scripts
- Use `textContent` instead of `innerHTML` where possible
- Audit all custom marked.js extensions for XSS vectors
---
### CVE-MC-004: Missing Path Traversal Protection (High)
**CVSS 3.1 Score: 7.8 (High)**
**CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')**
**Location:** `src/main.js` (lines 4241-4281)
**Description:**
The `list-directory` and `open-file-path` IPC handlers accept arbitrary file paths without validation:
```javascript
ipcMain.handle('list-directory', async (event, dirPath) => {
try {
if (!dirPath) { /* dialog */ }
// No path validation - accepts any path
const entries = fs.readdirSync(dirPath, { withFileTypes: true });
// ...
}
});
ipcMain.on('open-file-path', (event, filePath) => {
// No path validation
if (!fs.existsSync(filePath)) return;
const content = fs.readFileSync(filePath, 'utf-8');
mainWindow.webContents.send('file-opened', { path: filePath, content });
});
```
**Exploitability:**
- Malicious renderer code can read any file on the system
- No restriction to a sandbox directory
- Combined with XSS, attacker can exfiltrate sensitive files
**Remediation:**
```javascript
const ALLOWED_DIRECTORIES = [app.getPath('documents'), app.getPath('desktop')];
function isPathAllowed(filePath) {
const resolved = path.resolve(filePath);
return ALLOWED_DIRECTORIES.some(dir => resolved.startsWith(dir));
}
```
---
### CVE-MC-005: Weak Content Security Policy (High)
**CVSS 3.1 Score: 7.5 (High)**
**CWE-1021: Improper Restriction of Renderers**
**Location:** `src/index.html` (line 5)
```html
<meta http-equiv="Content-Security-Policy" content="default-src 'self';
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net;
style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com;
img-src 'self' data: blob: file:;
font-src 'self' data:;
connect-src 'self' https://www.plantuml.com;">
```
**Description:**
The CSP contains several security weaknesses:
1. **`'unsafe-inline'` in script-src** - Allows inline script injection
2. **`'unsafe-eval'` in script-src** - Allows `eval()` and similar functions
3. **`https://cdn.jsdelivr.net`** - Allows scripts from external CDN (supply chain risk)
4. **`file:` in img-src** - Allows loading local files as images (potential information disclosure)
**Exploitability:**
- XSS attacks can execute arbitrary scripts
- External CDN compromise could inject malicious code
- `eval()` enables dynamic code execution
**Remediation:**
- Remove `'unsafe-inline'` and `'unsafe-eval'`
- Use nonces or hashes for inline scripts
- Remove external CDNs or use Subresource Integrity (SRI)
- Remove `file:` from img-src
---
### CVE-MC-006: Insecure Window Configuration for PDF Export (Medium)
**CVSS 3.1 Score: 6.5 (Medium)**
**CWE-1021: Improper Restriction of Renderers**
**Location:** `src/main.js` (lines 2579-2585)
```javascript
const pdfWindow = new BrowserWindow({
show: false,
webPreferences: {
nodeIntegration: true,
contextIsolation: false
}
});
```
**Description:**
Hidden windows created for PDF export also have insecure configurations, allowing potential privilege escalation.
**Remediation:**
```javascript
webPreferences: {
nodeIntegration: false,
contextIsolation: true,
sandbox: true
}
```
---
### CVE-MC-007: PlantUML Server Data Exfiltration (Medium)
**CVSS 3.1 Score: 5.3 (Medium)**
**CWE-359: Exposure of Private Information**
**Location:** `src/renderer.js` (lines 470-487)
```javascript
const plantumlBlocks = preview.querySelectorAll('pre code.language-plantuml');
plantumlBlocks.forEach((block) => {
const code = block.textContent;
// ...
const encoded = plantumlEncode(code);
const img = document.createElement('img');
img.src = `https://www.plantuml.com/plantuml/svg/${encoded}`;
// ...
});
```
**Description:**
PlantUML diagram content is sent to an external server (plantuml.com) for rendering. This could leak sensitive information contained in diagrams.
**Exploitability:**
- Diagrams containing proprietary information, system architecture, or internal processes are sent to third-party servers
- No user consent or notification before external data transmission
**Remediation:**
- Use local PlantUML rendering with Java
- Add user warning before sending data to external service
- Implement opt-in for external rendering
---
### CVE-MC-008: Inconsistent Security Settings Across Windows (Medium)
**CVSS 3.1 Score: 5.5 (Medium)**
**CWE-1021: Improper Restriction of Renderers**
**Description:**
Security settings are inconsistent across different windows:
| Window | nodeIntegration | contextIsolation | Security |
|--------|-----------------|------------------|----------|
| Main Window | true | false | Insecure |
| About Dialog | false | true | Secure |
| Dependencies Dialog | false | true | Secure |
| ASCII Generator | false | true | Secure |
| Table Generator | false | true | Secure |
| PDF Export Window | true | false | Insecure |
| Hidden Conversion Window | true | false | Insecure |
**Remediation:**
Apply secure configuration (`nodeIntegration: false`, `contextIsolation: true`) consistently across all windows.
---
### CVE-MC-009: Command Execution via External Tools (Low)
**CVSS 3.1 Score: 4.4 (Low)**
**CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')**
**Location:** `src/main.js` (lines 1915-1972)
**Description:**
While the application uses `execFile` instead of `exec` (good practice), external tools (Pandoc, LibreOffice, FFmpeg, ImageMagick) are invoked with file paths that could potentially be manipulated.
**Positive Finding:**
The code correctly uses `execFile` with argument arrays instead of shell commands, mitigating most command injection vectors.
**Remaining Risk:**
- File paths are not validated against malicious names
- Special characters in filenames could cause issues with external tools
**Remediation:**
- Validate file paths before passing to external tools
- Sanitize filenames of special characters
---
### CVE-MC-010: Missing Dependency Version Pinning (Low)
**CVSS 3.1 Score: 3.5 (Low)**
**CWE-1035: Using Components with Known Vulnerabilities**
**Location:** `package.json`
**Description:**
Dependencies use `^` version ranges which could allow automatic updates to versions with vulnerabilities:
```json
"dependencies": {
"marked": "^17.0.3",
"dompurify": "^3.3.1",
"mermaid": "^11.12.3",
// ...
}
```
**Remediation:**
- Pin exact versions in production
- Use lockfile (package-lock.json)
- Implement dependency scanning in CI/CD pipeline
---
## Attack Surface Map
```
┌─────────────────────────────────────────────────────────────────┐
│ EXTERNAL ATTACK SURFACE │
├─────────────────────────────────────────────────────────────────┤
│ Markdown Files (.md) ─────► XSS via Preview Rendering │
│ Code Blocks ─────► Arbitrary Code Execution │
│ PlantUML Diagrams ─────► Data Exfiltration │
│ External CDNs ─────► Supply Chain Attacks │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ RENDERER PROCESS (Insecure) │
├─────────────────────────────────────────────────────────────────┤
│ nodeIntegration: true ─────► Direct Node.js Access │
│ contextIsolation: false ─────► Prototype Pollution Risk │
│ DOMPurify Sanitization ─────► May be bypassed via extensions │
│ Custom Marked Extensions ────► XSS Vectors │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ IPC BRIDGE (Preload.js) │
├─────────────────────────────────────────────────────────────────┤
│ Channel Whitelisting ─────► Good Practice │
│ Not Used for Main Window ────► Security Bypassed │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ MAIN PROCESS (Full Privileges) │
├─────────────────────────────────────────────────────────────────┤
│ File Operations ─────► No Path Validation │
│ Code Execution ─────► Python/Bash via REPL │
│ External Tools ─────► Pandoc, FFmpeg, LibreOffice │
│ PDF Operations ─────► Merge, Encrypt, Decrypt │
└─────────────────────────────────────────────────────────────────┘
```
---
## Positive Security Findings
1. **Preload.js Implementation:** A secure IPC bridge with channel whitelisting is implemented
2. **DOMPurify Usage:** HTML sanitization is applied to markdown output
3. **execFile Usage:** External commands use `execFile` instead of `exec`
4. **File Size Limits:** 50MB maximum file size is enforced
5. **Rate Limiting:** Conversion operations have rate limiting (2 second minimum interval)
6. **Error Message Sanitization:** Absolute paths are stripped from error messages
---
## Prioritized Remediation Roadmap
### Phase 1 - Critical (Immediate)
1. Set `nodeIntegration: false` and `contextIsolation: true` for main window
2. Remove or sandbox the code execution (REPL) feature
3. Implement proper preload.js usage for all windows
### Phase 2 - High Priority (1-2 Weeks)
4. Add path traversal protection to file operations
5. Strengthen Content Security Policy
6. Audit and fix custom markdown extensions for XSS
### Phase 3 - Medium Priority (1 Month)
7. Implement consistent security settings across all windows
8. Add local PlantUML rendering option
9. Implement dependency scanning in CI/CD
### Phase 4 - Low Priority (Ongoing)
10. Pin dependency versions
11. Add security headers to all generated HTML
12. Implement security logging and monitoring
---
## Compliance Considerations
- **OWASP Top 10 2021:** A03:2021 - Injection, A05:2021 - Security Misconfiguration
- **OWASP ASVS:** V12 - File Handling, V13 - API Security
- **NIST CSF:** PR.AC - Access Control, PR.DS - Data Security
---
## Conclusion
The MarkdownConverter application has significant security vulnerabilities that could allow an attacker to execute arbitrary code, access sensitive files, and compromise the user's system. The most critical issue is the insecure Electron configuration combined with XSS attack vectors in the markdown rendering pipeline.
**Overall Security Rating: HIGH RISK**
The positive finding is that much of the security infrastructure (preload.js, DOMPurify) is already in place but not properly utilized. With focused remediation effort, the application can achieve a much stronger security posture.
+215
View File
@@ -0,0 +1,215 @@
# STRIDE Threat Model - MarkdownConverter v4.0.0
**Analysis Date:** 2026-03-15
**Methodology:** STRIDE + MITRE ATT&CK
**Overall Risk Score:** 7.8 (HIGH)
---
## Executive Summary
The analysis identified **10 vulnerabilities** with a combined risk score of **7.8 (HIGH)**. The most critical issues enable complete system compromise through XSS-to-RCE attack chains.
---
## Critical Findings
| Priority | CVE | Vulnerability | CVSS | Impact |
|----------|-----|---------------|------|--------|
| P0 | CVE-MC-001 | Insecure Electron Config (`nodeIntegration: true`, `contextIsolation: false`) | 9.6 | Complete system compromise |
| P0 | CVE-MC-002 | Arbitrary code execution via REPL feature | 9.3 | Remote code execution |
| P1 | CVE-MC-003 | XSS in markdown rendering | 8.0 | Session hijacking, RCE chain |
| P1 | CVE-MC-004 | Path traversal vulnerability | 7.8 | Arbitrary file write |
| P1 | CVE-MC-005 | Weak Content Security Policy | 7.5 | XSS enablement |
| P2 | CVE-MC-006 | Insecure window config for PDF export | 6.5 | Privilege escalation |
| P2 | CVE-MC-007 | PlantUML server data exfiltration | 5.3 | Information disclosure |
| P2 | CVE-MC-008 | Inconsistent security settings | 5.5 | Configuration weakness |
| P3 | CVE-MC-009 | Command execution via external tools | 4.4 | Command injection risk |
| P3 | CVE-MC-010 | Missing dependency version pinning | 3.5 | Supply chain risk |
---
## Key Attack Vectors
### 1. XSS to RCE Chain (Critical)
```
Malicious Markdown File
│
▼
XSS in Preview (CVE-MC-003)
│
▼
nodeIntegration: true (CVE-MC-001)
│
▼
Full Node.js Access
│
▼
Complete System Compromise
```
### 2. REPL Code Execution (Critical)
```
Code Block in Markdown
│
▼
User clicks "Run"
│
▼
REPL executes Python/Bash (CVE-MC-002)
│
▼
Arbitrary Code Execution
```
### 3. Data Exfiltration (Medium)
```
PlantUML Diagram Content
│
▼
Sent to www.plantuml.com (CVE-MC-007)
│
▼
Sensitive Architecture Leaked
```
---
## STRIDE Analysis
### S - Spoofing
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| S1 | Attacker spoofs markdown file origin | Medium | High | High |
| S2 | Malicious code pretends to be safe | High | Critical | Critical |
### T - Tampering
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| T1 | XSS modifies local files | High | Critical | Critical |
| T2 | Conversion output tampered | Medium | Medium | Medium |
### R - Repudiation
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| R1 | No audit trail for operations | Low | Low | Low |
### I - Information Disclosure
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| I1 | XSS exposes file system | High | Critical | Critical |
| I2 | PlantUML content leaked | Medium | Medium | Medium |
| I3 | Error messages reveal paths | Low | Low | Low |
### D - Denial of Service
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| D1 | Malicious code crashes app | Medium | Medium | Medium |
| D2 | Large file exhausts resources | Low | Low | Low |
### E - Elevation of Privilege
| ID | Threat | Likelihood | Impact | Risk |
|----|--------|------------|--------|------|
| E1 | XSS → nodeIntegration → System | High | Critical | Critical |
| E2 | REPL code execution | High | Critical | Critical |
---
## MITRE ATT&CK Mapping
| Technique | ID | Applicability |
|-----------|-----|---------------|
| User Execution | T1204.002 | Malicious markdown file |
| Command and Scripting Interpreter | T1059.007 | JavaScript via nodeIntegration |
| Command and Scripting Interpreter | T1059.006 | Python via REPL |
| Command and Scripting Interpreter | T1059.004 | Bash via REPL |
| Exploit Public-Facing Application | T1190 | XSS in preview |
| Data Exfiltration Over Web Service | T1043 | PlantUML server |
| File and Directory Discovery | T1083 | Path traversal |
---
## Trust Boundaries
```
┌─────────────────────────────────────────────────────────────────────┐
│ TRUST BOUNDARY MAP │
├─────────────────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────┐ ┌─────────────────────────────────────┐ │
│ │ USER │ ──────► │ APPLICATION │ │
│ │ (Untrusted) │ │ ┌───────────┐ ┌───────────────┐ │ │
│ └─────────────┘ │ │ Renderer │ │ Main Process │ │ │
│ │ │ (Sandbox) │ │ (Privileged) │ │ │
│ │ └─────┬─────┘ └───────┬───────┘ │ │
│ │ │ IPC │ │ │
│ │ ▼ ▼ │ │
│ │ ┌─────────────────────────────┐ │ │
│ │ │ File System │ │ │
│ │ └─────────────────────────────┘ │ │
│ └─────────────────────────────────────┘ │
│ │ │
│ ▼ │
│ ┌─────────────────────────────────────────────────────────────┐ │
│ │ EXTERNAL SERVICES │ │
│ │ • PlantUML Server (www.plantuml.com) │ │
│ │ • CDN (cdn.jsdelivr.net, cdnjs.cloudflare.com) [REMOVED] │ │
│ │ • External Tools (Pandoc, FFmpeg, LibreOffice) │ │
│ └─────────────────────────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────┘
```
---
## Business Impact Analysis
### Successful Attack Consequences
| Impact Category | Estimate |
|-----------------|----------|
| Data breach costs | $500,000 - $5,000,000+ |
| Regulatory fines (GDPR) | Up to 4% annual revenue |
| Reputation damage | Incalculable |
| Business disruption | Hours to days |
### Affected Assets
- User documents and files
- System credentials
- Proprietary information in diagrams
- Application integrity
---
## Remediation Priority
### P0 - Immediate (24-48 hours)
1. **CVE-MC-001**: Set `nodeIntegration: false`, `contextIsolation: true`
2. **CVE-MC-002**: Remove or sandbox REPL code execution
### P1 - Short-term (1-2 weeks)
3. **CVE-MC-003**: Audit markdown extensions for XSS
4. **CVE-MC-004**: Add path validation (✅ COMPLETED)
5. **CVE-MC-005**: Strengthen CSP (✅ COMPLETED)
### P2 - Medium-term (1 month)
6. **CVE-MC-006**: Consistent window security settings
7. **CVE-MC-007**: Add local PlantUML option or warning
8. **CVE-MC-008**: Audit all BrowserWindow configurations
### P3 - Long-term
9. **CVE-MC-009**: Validate filenames for external tools
10. **CVE-MC-010**: Pin dependency versions, add scanning
---
## Conclusion
The MarkdownConverter application has a **HIGH RISK** threat profile due to the combination of:
- Untrusted content rendering (markdown preview)
- Direct system access (nodeIntegration)
- Code execution capability (REPL)
**Immediate action required on P0 items to reduce attack surface.**
The fixes applied in this session (CSP, path traversal, UI accessibility) have reduced the risk profile, but the critical nodeIntegration issue requires significant refactoring.
+27
View File
@@ -0,0 +1,27 @@
{
"target": "MarkdownConverter Electron Application",
"status": "in_progress",
"depth": "comprehensive",
"compliance_frameworks": ["owasp"],
"current_step": 3,
"current_phase": 1,
"completed_steps": ["vulnerability-scan", "threat-modeling"],
"files_created": ["01-vulnerability-scan.md", "02-threat-model.md"],
"started_at": "2026-03-15T00:09:00.000Z",
"last_updated": "2026-03-15T00:25:00.000Z",
"findings_summary": {
"critical": 2,
"high": 3,
"medium": 3,
"low": 2,
"total": 10
},
"fixes_applied": {
"csp_external_cdns_removed": true,
"path_traversal_protection_added": true,
"aria_labels_added": true,
"focus_visible_styles_added": true,
"tab_close_button_resized": true,
"duplicate_font_size_fixed": true
}
}
@@ -0,0 +1,522 @@
# Comprehensive UI Design Review - MarkdownConverter Electron Application
## Executive Summary
This review covers the UI design of the MarkdownConverter Electron application, analyzing visual design, usability, code quality, and performance across all UI files. The application has a solid foundation but has several areas requiring attention.
---
## 1. Visual Design Review
### 1.1 Spacing & Layout Consistency
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Inconsistent padding values across files | Multiple CSS files | Standardize to 4px/8px base scale |
| **Major** | Multiple reset declarations | `styles.css:1-5`, `styles-modern.css:42-47` | Consolidate resets into single file |
| **Minor** | Tab padding varies between themes | `styles.css:36`, `styles-modern.css:101` | Use CSS variables for consistent padding |
| **Minor** | Container padding inconsistency | `styles.css:17-21`, `styles-modern.css:63-69` | Define single container style |
**Code Example - Duplicate Reset:**
```css
/* styles.css:1-5 */
* {
margin: 0;
padding: 0;
box-sizing: border-box;
}
/* styles-modern.css:42-47 - DUPLICATE */
* {
margin: 0;
padding: 0;
box-sizing: border-box;
}
```
**Fix Recommendation:**
```css
/* Create a single base.css or remove from styles-modern.css */
/* Use CSS variables for spacing scale */
:root {
--space-1: 4px;
--space-2: 8px;
--space-3: 12px;
--space-4: 16px;
--space-5: 24px;
--space-6: 32px;
}
```
### 1.2 Typography Consistency
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Font-family declared multiple times with different fallbacks | `styles.css:8`, `styles-modern.css:50`, `styles-concreteinfo.css:32` | Standardize font stack |
| **Major** | Duplicate font-size declarations | `styles.css:228-230` | Remove duplicate |
| **Minor** | Inconsistent line-height values | Multiple files | Create type scale variables |
**Code Example - Duplicate font-size:**
```css
/* styles.css:226-230 */
.preview-content {
max-width: none;
margin: 0;
padding: 20px 24px 24px 24px;
line-height: 1.6;
font-size: 15px;
font-size: 14px; /* DUPLICATE - overwrites previous */
}
```
**Fix Recommendation:**
```css
/* styles.css - Remove duplicate */
.preview-content {
font-size: 14px; /* Keep only one */
line-height: 1.6;
}
```
### 1.3 Color Usage and Contrast Accessibility
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Critical** | Hardcoded colors instead of CSS variables | `styles.css:27-29`, `styles.css:37-38`, etc. | Use CSS custom properties |
| **Major** | Inconsistent gray scale definitions | Multiple files define different grays | Consolidate to single palette |
| **Minor** | Some contrast ratios may be insufficient | Status bar text colors | Verify WCAG 2.1 AA compliance |
**Code Example - Hardcoded colors:**
```css
/* styles.css:27-29 */
.tab-bar {
background: #f0f0f0; /* Should use var(--gray-100) */
border-bottom: 1px solid #ddd; /* Should use var(--gray-300) */
}
```
**Fix Recommendation:**
```css
/* Use the existing palette from styles-modern.css */
.tab-bar {
background: var(--gray-100, #f3f4f6);
border-bottom: 1px solid var(--gray-300, #d1d5db);
}
```
### 1.4 Dark Mode Support Quality
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Dark theme selectors inconsistent | `styles.css` uses `body.theme-dark`, `styles-sidebar.css:108` uses `body[class*="dark"]` | Standardize selector pattern |
| **Minor** | Missing dark theme support for some components | `.breadcrumb-bar`, command palette | Add dark mode variants |
| **Suggestion** | Repetitive dark theme declarations | `styles-concreteinfo.css:362-425` | Use CSS custom properties for theming |
**Code Example - Inconsistent selectors:**
```css
/* styles.css */
body.theme-dark .tab-bar { ... }
/* styles-sidebar.css */
body[class*="dark"] .sidebar-icons { ... }
```
**Fix Recommendation:**
```css
/* Choose one pattern and apply consistently */
/* Option 1: Class-based (recommended) */
body.theme-dark .tab-bar,
body.theme-dark .sidebar-icons { ... }
/* Option 2: Attribute-based */
body[data-theme="dark"] .tab-bar { ... }
```
---
## 2. Usability Review
### 2.1 Clickable/Tappable Areas
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Critical** | Tab close button too small (16x16px) | `styles.css:62-77` | Increase to minimum 24x24px |
| **Major** | Sidebar icons at minimum size | `styles-sidebar.css:35-47` (36x36px) | Consider 40-44px for better touch |
| **Minor** | Toolbar buttons at edge of minimum | `styles.css:120-131` (32x32px) | Acceptable for mouse, small for touch |
**Code Example - Small close button:**
```css
/* styles.css:62-77 */
.tab-close {
width: 16px; /* TOO SMALL - below 24px minimum */
height: 16px; /* TOO SMALL */
}
```
**Fix Recommendation:**
```css
.tab-close {
width: 24px;
height: 24px;
border-radius: 4px;
}
/* Add touch-friendly hit area */
.tab-close::before {
content: '';
position: absolute;
top: -4px;
left: -4px;
right: -4px;
bottom: -4px;
}
```
### 2.2 Hover/Focus States
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Critical** | Missing focus-visible styles | All interactive elements | Add :focus-visible for keyboard navigation |
| **Major** | No focus indicators on toolbar buttons | `styles.css:133-140` | Add visible focus ring |
| **Minor** | Inconsistent hover transitions | Various components | Standardize transition duration |
**Code Example - Missing focus styles:**
```css
/* styles.css:120-131 - No focus state */
.toolbar button {
/* ... no focus style */
}
.toolbar button:hover {
background: #e0e0e0;
border-color: #ccc;
}
```
**Fix Recommendation:**
```css
.toolbar button:focus-visible {
outline: 2px solid var(--primary-dark, #5661b3);
outline-offset: 2px;
}
.toolbar button:hover {
background: #e0e0e0;
border-color: #ccc;
}
```
### 2.3 Loading and Error State Handling
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Generic error message without styling | `renderer.js:384-386`, `renderer.js:508-511` | Create styled error components |
| **Minor** | No loading indicators for async operations | Sidebar panels | Add skeleton loaders or spinners |
| **Minor** | `git-loading` class exists but minimal styling | `styles-sidebar.css:227` | Enhance with animation |
**Code Example - Plain error display:**
```javascript
// renderer.js:384-386
preview.innerHTML = '<p style="color: red; padding: 20px;">Error: Required libraries...';
// Inline styles should be in CSS
```
**Fix Recommendation:**
```css
/* Add to styles.css */
.preview-error {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
padding: 40px 20px;
color: var(--ci-danger, #dc3545);
text-align: center;
}
.preview-error-icon {
font-size: 48px;
margin-bottom: 16px;
}
```
### 2.4 Accessibility (ARIA, Semantic HTML)
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Critical** | Buttons without accessible labels | `index.html:31` (tab close), `index.html:33` (new tab) | Add aria-label |
| **Critical** | SVG icons lack aria-hidden | All toolbar buttons | Add aria-hidden="true" |
| **Major** | Missing role attributes on tabs | `index.html:29-33` | Add role="tablist", role="tab" |
| **Major** | No skip links | `index.html` | Add skip to main content link |
| **Minor** | Dialog missing aria-modal | Export dialogs | Add aria-modal="true" |
**Code Example - Missing accessibility attributes:**
```html
<!-- index.html:31 - Current -->
<button class="tab-close" title="Close tab">x</button>
<!-- index.html:33 - Current -->
<button class="new-tab-button" id="new-tab-btn" title="New tab">+</button>
```
**Fix Recommendation:**
```html
<!-- Improved with ARIA -->
<div class="tab-bar" id="tab-bar" role="tablist" aria-label="Document tabs">
<div class="tab active" data-tab-id="1" role="tab" aria-selected="true" aria-controls="tab-content-1">
<span class="tab-title">Untitled</span>
<button class="tab-close" aria-label="Close tab" title="Close tab">×</button>
</div>
<button class="new-tab-button" id="new-tab-btn" aria-label="Create new tab" title="New tab">+</button>
</div>
<!-- SVG icons should have aria-hidden -->
<button id="btn-bold" title="Bold (Ctrl+B)" aria-label="Bold">
<svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" aria-hidden="true">
...
</svg>
</button>
```
### 2.5 Keyboard Navigation
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Tab order may skip sidebar icons | Sidebar panel | Verify logical tab order |
| **Minor** | No escape key handling for dialogs | Export dialogs | Add escape to close |
| **Minor** | Find dialog lacks full keyboard support | `renderer.js:804-866` | Add Ctrl+F shortcut hint |
---
## 3. Code Quality Review
### 3.1 CSS Organization & Naming
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | No clear CSS architecture | All CSS files | Adopt BEM or similar methodology |
| **Major** | Overly generic class names | `.pane`, `.tab`, `.container` | Use more specific naming |
| **Minor** | Mixed naming conventions | camelCase (`tabBar`), kebab-case (`tab-bar`) | Standardize to kebab-case |
| **Minor** | Magic numbers | Various pixel values | Replace with spacing variables |
### 3.2 CSS Specificity Issues
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Excessive use of `!important` | `styles.css:14` | Restructure to avoid |
| **Major** | Deep selector nesting | Dark theme selectors | Flatten and use CSS variables |
| **Minor** | ID selectors for styling | `styles.css:233-247` | Prefer class selectors |
**Code Example - Problematic specificity:**
```css
/* styles.css:14 - Avoid !important */
.hidden {
display: none !important;
}
/* styles.css:397-431 - Deep nesting */
body.theme-dark #preview h1,
body.theme-dark [id^="preview-"] h1,
body.theme-dark .preview-content h1 {
color: #c9d1d9;
border-bottom-color: #21262d;
}
```
**Fix Recommendation:**
```css
/* Use utility class pattern */
[hidden] { display: none; }
/* Use CSS custom properties for theming */
.preview-content h1 {
color: var(--text-primary);
border-bottom-color: var(--border-color);
}
/* Theme applies variables */
body.theme-dark {
--text-primary: #c9d1d9;
--border-color: #21262d;
}
```
### 3.3 Reusable Style Definitions
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Repeated button styles | Multiple files | Create button component classes |
| **Major** | Dialog styles duplicated | Export, batch, print preview dialogs | Create modal component |
| **Minor** | Similar form field styles scattered | Export dialog inputs | Create form component |
**Code Example - Duplicated button styles:**
```css
/* styles.css */
.toolbar button { /* button styles */ }
.tab-close { /* button styles */ }
.new-tab-button { /* button styles */ }
#export-dialog-close { /* button styles */ }
/* styles-sidebar.css */
.sidebar-icon { /* similar button styles */ }
.sidebar-panel-close { /* similar button styles */ }
```
**Fix Recommendation:**
```css
/* Create button component system */
.btn {
display: inline-flex;
align-items: center;
justify-content: center;
border: none;
cursor: pointer;
transition: all var(--transition-fast);
}
.btn--icon {
width: 32px;
height: 32px;
border-radius: var(--radius-md);
}
.btn--close {
font-size: 14px;
font-weight: bold;
border-radius: var(--radius-sm);
}
```
### 3.4 Documentation
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Minor** | Limited CSS documentation | All CSS files | Add section comments |
| **Minor** | No component documentation | Sidebar components | Add JSDoc-style comments |
| **Suggestion** | No design tokens documentation | CSS variables | Create tokens documentation |
---
## 4. Performance Review
### 4.1 CSS Optimization
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | Large CSS files (105KB main, 78KB modern) | `styles.css`, `styles-modern.css` | Split into smaller modules |
| **Major** | Duplicate style definitions | Multiple files | Remove redundancies |
| **Minor** | Unused styles likely present | Theme variations | Audit and remove unused |
### 4.2 Asset Loading
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Major** | highlight.js CSS loaded synchronously | `index.html:14` | Load asynchronously or bundle |
| **Minor** | Font files could be preloaded | `fonts.css` | Add preload links in HTML |
| **Suggestion** | Consider CSS critical path | Above-the-fold styles | Inline critical CSS |
**Code Example - Sync stylesheet loading:**
```html
<!-- index.html:14 - Blocks rendering -->
<link rel="stylesheet" href="../node_modules/highlight.js/styles/default.css">
```
**Fix Recommendation:**
```html
<!-- Non-blocking load -->
<link rel="stylesheet" href="../node_modules/highlight.js/styles/default.css" media="print" onload="this.media='all'">
<!-- Or preload fonts -->
<link rel="preload" href="../assets/fonts/Inter-Regular.woff2" as="font" type="font/woff2" crossorigin>
```
### 4.3 Animation Performance
| Severity | Issue | Location | Recommendation |
|----------|-------|----------|----------------|
| **Minor** | Some transitions on expensive properties | `styles-modern.css:111-112` | Prefer transform/opacity |
| **Suggestion** | Missing will-change hints | Complex animations | Add will-change for GPU hints |
---
## 5. Component-Specific Issues
### 5.1 Tab System
| File | Issues |
|------|--------|
| `styles.css:23-97` | Inconsistent active state styling, small close button |
| `renderer.js:88-346` | Tab content created via innerHTML (XSS risk) |
### 5.2 Sidebar
| File | Issues |
|------|--------|
| `styles-sidebar.css` | Good structure but missing focus states |
| `sidebar-manager.js` | Clean implementation, needs ARIA |
### 5.3 Export Dialogs
| File | Issues |
|------|--------|
| `styles.css:1060-1355` | Monolithic, should be component |
| `index.html:171-331` | Complex nested structure needs semantic HTML |
### 5.4 Welcome Screen
| File | Issues |
|------|--------|
| `styles-welcome.css` | Minimal styles, good foundation |
| Missing hover states for keyboard focus | Add :focus-visible |
---
## 6. Prioritized Fix Recommendations
### Critical (Immediate)
1. **Add missing ARIA attributes** to all interactive elements
2. **Increase tab close button size** to minimum 24x24px
3. **Add focus-visible styles** for keyboard navigation
4. **Fix duplicate font-size declaration** in `.preview-content`
### Major (Next Sprint)
1. **Consolidate CSS resets** into single location
2. **Create button component system** with variants
3. **Standardize dark theme selectors** across all files
4. **Replace hardcoded colors** with CSS variables
5. **Create modal/dialog component** to reduce duplication
### Minor (Future)
1. **Document CSS architecture** and naming conventions
2. **Audit and remove unused styles**
3. **Add loading state components** (skeletons, spinners)
4. **Implement CSS module splitting** for better performance
---
## 7. Summary Statistics
| Category | Critical | Major | Minor | Suggestions |
|----------|----------|-------|-------|-------------|
| Visual Design | 1 | 5 | 4 | 1 |
| Usability | 3 | 4 | 4 | 0 |
| Code Quality | 0 | 6 | 4 | 1 |
| Performance | 0 | 3 | 2 | 2 |
| **Total** | **4** | **18** | **14** | **4** |
---
## Conclusion
The MarkdownConverter application has a functional UI with good visual variety through its theme system. However, there are significant opportunities for improvement in:
1. **Accessibility** - Critical for users with disabilities
2. **Code organization** - Reduce CSS duplication and improve maintainability
3. **Component consistency** - Standardize interactive element sizing and states
4. **Performance** - Optimize CSS loading and reduce bundle size
Addressing the Critical and Major issues will significantly improve both user experience and code maintainability.
+17
View File
@@ -0,0 +1,17 @@
{
"review_id": "full-ui-review_20260315",
"target": "src/ (Entire UI Directory)",
"focus_areas": ["visual", "usability", "code", "performance"],
"context": "comprehensive",
"platform": "desktop",
"status": "complete",
"started_at": "2026-03-15T00:09:00.000Z",
"completed_at": "2026-03-15T00:12:00.000Z",
"issues_found": 40,
"severity_counts": {
"critical": 4,
"major": 18,
"minor": 14,
"suggestion": 4
}
}
+48
View File
@@ -0,0 +1,48 @@
{
"version": "0.2.0",
"configurations": [
{
"name": "Debug Main Process",
"type": "node",
"request": "launch",
"cwd": "${workspaceFolder}",
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron",
"windows": {
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron.cmd"
},
"args": ["."],
"outputCapture": "std",
"env": {
"NODE_ENV": "development"
}
},
{
"name": "Debug Renderer Process",
"type": "chrome",
"request": "attach",
"port": 9222,
"webRoot": "${workspaceFolder}/src",
"timeout": 30000
},
{
"name": "Debug Main + Renderer",
"type": "node",
"request": "launch",
"cwd": "${workspaceFolder}",
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron",
"windows": {
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron.cmd"
},
"args": [".", "--remote-debugging-port=9222"],
"outputCapture": "std",
"env": {
"NODE_ENV": "development"
},
"serverReadyAction": {
"pattern": "listening on port ([0-9]+)",
"uriFormat": "http://localhost:%s",
"action": "debugWithChrome"
}
}
]
}
+25
View File
@@ -0,0 +1,25 @@
# Repository Guidelines
## Project Structure & Module Organization
Core application code lives in `src/`. Use `src/main.js` for the Electron main process, `src/preload.js` for the preload bridge, and `src/renderer.js` plus `src/editor/`, `src/sidebar/`, `src/repl/`, and `src/utils/` for renderer-side features. Electron adapter code is in `src/adapters/electron/`. Reusable markdown/document templates live in `src/templates/`. Static assets and icons are in `assets/`. Tests are in `tests/`, and build output goes to `dist/`.
## Build, Test, and Development Commands
- `npm start`: launch the Electron app locally.
- `npm test`: run the Jest suite once.
- `npm run test:watch`: rerun tests during local development.
- `npm run test:coverage`: generate coverage output.
- `npm run lint` / `npm run lint:fix`: check or fix ESLint issues in `src` and `tests`.
- `npm run format` / `npm run format:check`: apply or verify Prettier formatting.
- `npm run build:linux`, `npm run build:win`, `npm run build:mac`: create platform packages with `electron-builder`.
## Coding Style & Naming Conventions
This repo uses Prettier and ESLint. Follow `.prettierrc`: 2-space indentation, single quotes, semicolons, trailing commas where valid in ES5, and a 100-character line width. Prefer `camelCase` for variables/functions, `PascalCase` for classes, and kebab-case for file names only when already established. Keep module boundaries clear: UI logic in renderer modules, OS/file-system work behind Electron IPC and adapters.
## Testing Guidelines
Tests use Jest with `jest-environment-jsdom`. Add new tests under `tests/` with `*.test.js` names, mirroring the feature area when possible, for example `tests/sidebar.test.js` or `tests/print-preview.test.js`. Update or add regression tests for renderer behavior, preload APIs, and utility helpers when fixing bugs. Run `npm test` before opening a PR; use `npm run test:coverage` for larger refactors.
## Commit & Pull Request Guidelines
Recent history follows Conventional Commit prefixes such as `feat:`, `fix:`, and `refactor:`. Keep subjects short and imperative, for example `fix: guard modal cleanup on close`. PRs should describe the user-visible change, note test coverage, link any related issue, and include screenshots or GIFs for UI changes.
## Security & Configuration Tips
Do not bypass preload boundaries or introduce direct `eval`/dynamic code paths; ESLint already treats these as errors. Export and conversion features depend on external tools such as Pandoc, FFmpeg, ImageMagick, and LibreOffice, so document any new runtime dependency in `README.md` and packaging config.
+103
View File
@@ -0,0 +1,103 @@
# CLAUDE.md — MarkdownConverter (master)
> General code-quality, JavaScript, git, security, and testing standards are in the **global CLAUDE.md**. This file holds project- and branch-specific notes.
## Project Overview
Electron desktop app for Markdown editing and universal file conversion powered by Pandoc. Cross-platform (Win/macOS/Linux). Features: multi-tab editor with live preview, 25+ themes, PDF viewer/editor (merge/split/compress/rotate/watermark/password), export to 20+ formats (PDF/DOCX/ODT/EPUB/HTML/LaTeX/RTF/PPTX), batch conversion, syntax highlighting, diagram support (Mermaid), Git integration, and a plugin system.
- **Version:** 4.4.5
- **License:** MIT
- **App ID:** `com.concreteinfo.markdownconverter`
## Branch Specifics
This is the **primary/release branch** — a vanilla JavaScript Electron app with no bundler or framework in the renderer. The renderer is a single large `renderer.js` (5,300+ lines) loaded directly via `src/index.html`. All UI is hand-rolled DOM manipulation.
## Architecture
### Main Process (`src/main.js` — 4,260 lines)
Monolithic main process file. Contains all IPC handlers, Pandoc invocation, file operations, menu definitions (600+ lines), and window lifecycle. Key modules extracted:
- `src/main/PDFOperations.js` — PDF manipulation via `pdf-lib` (merge, split, compress, rotate, delete, reorder, watermark, encrypt, decrypt, permissions)
- `src/main/GitOperations.js` — Git status/stage/commit/log via `simple-git`
### Renderer (`src/renderer.js` — 5,361 lines)
Vanilla JS, no framework. Directly manipulates DOM. Loads CodeMirror 6 via `src/editor/codemirror-setup.js`. Uses `marked` + `highlight.js` + `DOMPurify` + `mermaid` for rendering. Lazy-loads sidebar panels, REPL, command palette, zen mode.
### Preload (`src/preload.js` — 448 lines)
Exists as IPC bridge, but **`contextIsolation: false` and `nodeIntegration: true`** — the renderer has full Node access. Preload is effectively a thin passthrough.
### Security Model
- `contextIsolation: false` + `nodeIntegration: true` (legacy; the react-electron branch fixes this)
- Pandoc invoked via `execFile` (not `exec`) to prevent shell injection
- Path traversal protection: `validatePath()`, `resolveWritablePath()`, blocks sensitive system dirs
- Permission handler only allows `clipboard-read`/`clipboard-write`
- Rate limiter on conversions (2-second minimum interval)
- File size limit: 50MB
- Error message sanitization strips absolute paths
### Plugin System (`src/plugins/`)
Manifest-based discovery (`manifest.json`). Built-in `writing-studio` plugin with sprint/goal/snapshot management. Plugin API exposed via `src/plugins/plugin-api.js`.
### Settings
Custom JSON file store at `<userData>/settings.json` (NOT `electron-store` despite the dependency). Recent files at `<userData>/recent-files.json`.
## System Dependencies
| Dependency | Required | Notes |
|---|---|---|
| **Node.js** | >= 20 | Electron 41 bundles Node 20.x |
| **Pandoc** | Yes (for exports) | Downloaded to `bin/<platform>/pandoc` via `scripts/download-tools.js` (v3.9.0.2). Falls back to system PATH. Must be present for DOCX/ODT/EPUB/LaTeX/PPTX export. |
| **FFmpeg** | Bundled | `ffmpeg-static` npm package; `asarUnpacked` for packaged builds |
| **MiKTeX / TeX Live** | Optional | For LaTeX PDF export; MiKTeX PATH injected on Windows automatically |
| **ImageMagick** | Optional | Linux image conversion; listed as deb dependency |
| **LibreOffice** | Optional | Enhanced document conversion; listed as deb dependency |
## Development Commands
```bash
npm start # Launch Electron app (dev mode)
npm test # Jest test suite
npm test:watch # Jest in watch mode
npm test:coverage # Jest with coverage report
npm run lint # ESLint check (src + tests)
npm run lint:fix # ESLint auto-fix
npm run format # Prettier write
npm run format:check # Prettier check only
npm run download-tools # Download Pandoc binaries to bin/
npm run generate-icons # Generate app icons via sharp
```
## Build & Package
**Tool:** `electron-builder` (v26.0.12), config inline in `package.json` (no separate config file).
| Target | Platforms |
|---|---|
| `npm run build` | electron-builder (default platform) |
| `npm run build:win` | Windows: NSIS installer + portable + zip (x64) |
| `npm run build:mac` | macOS: default dmg |
| `npm run build:linux` | Linux: deb + AppImage + snap |
| `npm run dist` | Build without publish |
| `npm run dist:all` | Build for all platforms |
**Bundled with builds:** Pandoc binary per platform. FFmpeg via `ffmpeg-static` (asarUnpacked). NSIS installer uses custom script at `scripts/nsis-installer.nsh`.
**Output:** `dist/` directory.
**CI:** GitHub Actions workflows in `.github/workflows/` (ci.yml, release.yml).
## Project Conventions / Gotchas
- **No bundler/transpilation.** The app uses vanilla CommonJS JavaScript. `src/main.js` is loaded directly by Electron. No webpack, no Vite, no TypeScript, no Babel.
- **Monolithic files.** `main.js` (4,260 lines) and `renderer.js` (5,361 lines) contain most logic. Not ideal but is the current state of this branch.
- **CodeMirror 6** for the editor, configured in `src/editor/codemirror-setup.js`.
- **PDF rendering** uses `pdfjs-dist`; **PDF manipulation** uses `pdf-lib` in the main process.
- **Renderer security is weak** — full Node access in renderer. Do NOT introduce new privileged renderer code without understanding this.
- **Pandoc is external.** Must be installed separately or downloaded via `npm run download-tools`. HTML and built-in PDF export work without Pandoc; other formats require it.
- **PDF export fallback chain:** xelatex -> pdflatex -> lualatex -> Electron built-in `printToPDF()`.
- **ESLint flat config** (`eslint.config.js`) with ECMAScript 2022. Prettier with 2-space indent, single quotes, semicolons, 100-char width.
- **Tests:** Jest with jsdom environment, 15% coverage threshold. 24 test files in `tests/`.
- **File associations:** `.md`, `.markdown`, `.pdf` registered at install.
- **Single instance lock** enforced via `app.requestSingleInstanceLock()`.
- **Adapters layer** (`src/adapters/`) abstracts file system operations for potential future non-Electron targets.
+127 -32
View File
@@ -1,3 +1,7 @@
<p align="center">
<img src="assets/markdown-converter-assets/logo-horizontal.svg" alt="Markdown Converter" width="420">
</p>
# MarkdownConverter
A powerful cross-platform Markdown editor and document converter powered by Pandoc, built with Electron. 100% open-source with no proprietary dependencies.
@@ -43,20 +47,35 @@ A powerful cross-platform Markdown editor and document converter powered by Pand
- **EPUB** - E-book format
- **LaTeX** - Academic document format
- **RTF** - Rich Text Format
- **Export themes** - Five visual styles (Modern, Classic, Sepia, Minimal, Elegant) for PDF and Word exports — recolored headings, links, and fonts
### Advanced Features
- **Custom headers & footers** - Add headers/footers to exports with dynamic fields
- **Page size configuration** - A3, A4, A5, B4, B5, Letter, Legal, Tabloid, or custom sizes
- **Visual flow chart editor** - Build Mermaid flowcharts visually; drag nodes, connect edges, live preview. Insert at cursor.
- **Batch conversion** - Convert entire folders of markdown files
- **ASCII Art Generator** - Create text banners and diagrams
- **ASCII Art Generator** - 17 hand-coded fonts + 400+ FIGlet fonts; text banners, boxes, and templates; insert into editor, copy to clipboard, or save to file (Ctrl+Shift+A)
- **Word templates** - Use custom Word templates for enhanced exports
- **Import documents** - Import from 30+ formats (DOCX, PDF, HTML, etc.)
- **MarkItDown import** - Any file → Markdown via [Microsoft MarkItDown](https://github.com/microsoft/markitdown). **Bundled** (MIT + PSF Python runtime) — no installation required for the core formats (PDF, DOCX, PPTX, XLSX, Outlook .msg, EPUB, HTML, images, ZIP, CSV, JSON, XML). For **audio transcription** and **OCR**, install `markitdown[all]` system-side (multi-GB ML models; not bundled).
- **Excel export** - Markdown tables to native .xlsx workbooks (one sheet per table)
- **AI Assistant** - Multi-provider AI help (OpenAI/Anthropic/Ollama/LM Studio): chat panel, summarize/improve/translate commands, grammar proofreading
- **Inline comments** - Anchor-based document comments in `.comments/` sidecars with F8 navigation
- **Wiki-links & Backlinks** - `[[Note]]` links with click-to-create and a "what links here?" panel (local knowledge base)
- **Crash recovery** - Session restore of open tabs and unsaved buffers after a crash
- **Version history** - Automatic pre-save snapshots with restore/diff/delete from the History panel
- **Vim mode & snippet expansion** - Vim keybindings toggle; Tab expands saved snippets
- **Quick Note** - Global scratchpad (Ctrl+Alt+Q) that appends to `notes/quick-notes.md`
- **Real PDF encryption** - Password protection, removal, and permissions actually work
- **Offline math & diagrams** - KaTeX bundled locally; PlantUML renders locally when the CLI is installed
## Installation
### Prerequisites
- [Node.js](https://nodejs.org/) (v16 or later)
- [Pandoc](https://pandoc.org/installing.html) (required for export functionality)
- [Node.js](https://nodejs.org/) (v16 or later) — only for development builds
- [Pandoc](https://pandoc.org/installing.html) — **bundled** inside the app, no install needed
- [MarkItDown](https://github.com/microsoft/markitdown) — **bundled** inside the app (MIT + embedded PSF Python runtime via PyInstaller), no install needed for PDF / DOCX / PPTX / XLSX / Outlook / EPUB / HTML / images / ZIP / CSV / JSON / XML
- Optional for advanced import only: `pip install "markitdown[all]"` adds **audio transcription** (Whisper) and **OCR** (EasyOCR/Tesseract) — these are multi-GB model downloads and are not bundled for size reasons
### Install Dependencies
```bash
@@ -96,40 +115,79 @@ npm run build:linux
| Redo | Ctrl+Shift+Z |
| New Tab | Ctrl+T |
| Close Tab | Ctrl+W |
| Toggle Preview | Ctrl+Shift+P |
| Toggle Preview | Ctrl+Shift+V |
| Zoom In | Ctrl+Shift++ |
| Zoom Out | Ctrl+Shift+- |
| Command Palette | Ctrl+Shift+P |
| Zen Mode | F11 |
| Writing Analytics | Ctrl+Shift+A |
| Quick Note | Ctrl+Alt+Q |
| Universal Converter | Ctrl+Shift+C |
| Table Generator | Ctrl+Shift+T |
| ASCII Art Generator | Ctrl+Shift+A |
| Next Comment | F8 |
| Add Comment at Cursor | Ctrl+Alt+M |
| Flow Chart: Undo | Ctrl+Z |
| Flow Chart: Redo | Ctrl+Shift+Z |
| Flow Chart: Delete selected | Delete |
## Themes
### Light Themes
- Atom One Light (Default)
- GitHub Light
- Light
- Solarized Light
- Gruvbox Light
- Ayu Light
- Sepia
- Paper
- Rose Pine Dawn
- Concrete Light
37 built-in editor themes, registered in `src/main/ThemeRegistry.bootstrap.js`.
### Dark Themes
- Dark
- One Dark
- Dracula
- Nord
- Monokai
- Material
- Gruvbox Dark
- Tokyo Night
- Palenight
- Ayu Dark
- Ayu Mirage
- Oceanic Next
- Cobalt2
- Concrete Dark
- Concrete Warm
### Light (14)
| Theme | Id |
|---|---|
| Atom One Light (Default) | `atomonelight` |
| GitHub Light | `github` |
| Light | `light` |
| Solarized Light | `solarized` |
| Gruvbox Light | `gruvbox-light` |
| Ayu Light | `ayu-light` |
| Sepia | `sepia` |
| Paper | `paper` |
| Rose Pine Dawn | `rosepine-dawn` |
| Concrete Light | `concrete-light` |
| Catppuccin Latte | `catppuccin-latte` |
| One Light | `one-light` |
| Winter is Coming (Light) | `winter-is-coming-light` |
| Spring Light *(seasonal)* | `spring-light` |
### Dark (22)
| Theme | Id |
|---|---|
| Dark | `dark` |
| One Dark | `onedark` |
| Dracula | `dracula` |
| Nord | `nord` |
| Monokai | `monokai` |
| Material | `material` |
| Gruvbox Dark | `gruvbox-dark` |
| Tokyo Night | `tokyonight` |
| Palenight | `palenight` |
| Ayu Dark | `ayu-dark` |
| Ayu Mirage | `ayu-mirage` |
| Oceanic Next | `oceanic-next` |
| Cobalt2 | `cobalt2` |
| Concrete Dark | `concrete-dark` |
| Concrete Warm | `concrete-warm` |
| Catppuccin Frappé | `catppuccin-frappe` |
| Catppuccin Macchiato | `catppuccin-macchiato` |
| Catppuccin Mocha | `catppuccin-mocha` |
| Tokyo Night Storm | `tokyo-night-storm` |
| Synthwave '84 | `synthwave-84` |
| Outrun | `outrun` |
| Winter is Coming (Dark) | `winter-is-coming-dark` |
### High-Contrast (1)
| Theme | Id |
|---|---|
| Solarized Dark (High Contrast) | `solarized-dark-hc` |
The currently-selected theme persists across restarts via `electron-store` (key `theme`, default `atomonelight`). Adding a new theme is one `register()` call in the bootstrap + one CSS file under `src/styles/themes/`.
## PDF Viewer
@@ -140,6 +198,43 @@ Open PDF files directly in MarkdownConverter:
- Rotate pages left or right
- Close PDF to return to editor
## Bundled Dependencies, Legal Notices & Credits
MarkdownConverter ships as a self-contained package. Everything needed for the
core workflows is **bundled**; a few large optional tools are detected from
the system when present.
### Bundled with the app
| Component | License | Role |
|---|---|---|
| [Pandoc](https://pandoc.org) 3.9 | GPL-2.0+ (separate process) | 25+ export/import formats |
| [FFmpeg](https://ffmpeg.org) (via ffmpeg-static) | GPL-3.0+ build (separate process) | audio/video tools |
| [MarkItDown](https://github.com/microsoft/markitdown) (MIT) + embedded Python runtime (PSF) | MIT / PSF | any-file → Markdown import (PDF/DOCX/PPTX/XLSX/Outlook/EPUB/images/ZIP) |
| [sharp](https://sharp.pixelplumbing.com) + libvips | Apache-2.0 / LGPL-2.1+ (dynamic) | image tools |
| [KaTeX](https://katex.org), [marked](https://marked.js.org), [highlight.js], [DOMPurify], [mermaid], [CodeMirror 6], pdf-lib (@cantoo fork), pdfjs-dist, JSZip, simple-git | MIT / Apache-2.0 / BSD-3 / MPL-2.0 | editor, preview, PDF, Git |
| JetBrains Mono & Fira Code fonts | SIL OFL 1.1 | editor typography |
GPL-licensed tools run as **separate processes** (never linked into the app)
and their complete corresponding sources are offered in
[SOURCES.md](SOURCES.md). Full details: [THIRD-PARTY-NOTICES.md](THIRD-PARTY-NOTICES.md),
also available inside the app under **Help → Third-Party Notices & Licenses**.
### Not bundled (used when installed)
LibreOffice (Office conversion), MiKTeX/TeX Live (LaTeX PDF), ImageMagick
(extra image formats), PlantUML + Java (local diagrams), Calibre (MOBI),
MarkItDown `[all]` extras (audio transcription / OCR).
### Credits
Built on open source: [Electron], [CodeMirror], [marked], [KaTeX],
[highlight.js], [DOMPurify](https://github.com/cure53/DOMPurify),
[mermaid](https://mermaid.js.org), [pdf-lib], [pdf.js](https://mozilla.github.io/pdf.js/),
[sharp]/libvips, [Pandoc], [FFmpeg], [MarkItDown] by Microsoft,
[simple-git], [JSZip], [JetBrains Mono], [Fira Code]. Thank you to all their
authors and maintainers.
## Open Source
MarkdownConverter is 100% open-source. All dependencies are permissively licensed:
@@ -162,4 +257,4 @@ Amit Haridas (amit.wh@gmail.com)
## Version
v3.0.0
v4.13.0
+55
View File
@@ -0,0 +1,55 @@
# Source Code Availability (GPL / LGPL Written Offer)
MarkdownConverter distributes the following binaries built from GPL-licensed
software. Per GPL §3(b), this document is the written offer: **corresponding
source code for the exact versions listed below is available on request for
at least three years from each release**, and permanently at the referenced
public locations. Write to: amit.wh@gmail.com (or open a GitHub issue at
https://github.com/amitwh/markdown-converter/issues).
## Pandoc — GPL-2.0-or-later
- Binary shipped: `bin/pandoc` (v3.9.0.2, official upstream release, unmodified)
- SHA-256 (linux): `7d124235998ecd3cdd9a463b1e5f6691a178b6461824c29a36170a0882f05597`
- Source: <https://github.com/jgm/pandoc/archive/refs/tags/3.9.0.2.tar.gz>
- Pandoc statically links Haskell libraries (GHC ecosystem, mostly BSD-3);
their sources are included in the upstream release tarball's dependency set.
## FFmpeg — GPL-3.0-or-later (build configuration)
- Binary shipped: `ffmpeg` provided by the npm package `ffmpeg-static@5.3.0`
(Linux: johnvansickle.com build; Windows: gyan.dev; macOS: evermeet.cx —
all `--enable-gpl` builds including x264/x265, per the build banner)
- Source:
- FFmpeg: <https://ffmpeg.org/releases/> (use the release matching
`ffmpeg -version` of the shipped binary)
- Build scripts & pinned versions: <https://github.com/eugeneware/ffmpeg-static>
- x264: <https://code.videolan.org/videolan/x264> ·
x265: <https://bitbucket.org/multicoreware/x265_git/> ·
other `--enable-lib*` components: their upstream sources (all free/open)
## PyInstaller bootloader (inside the bundled MarkItDown binary) — GPL-2.0 with boot-exception
- Binary shipped: `bin/markitdown` (MarkItDown 0.1.7 frozen with PyInstaller 6.x)
- PyInstaller grants a special exception allowing the bootloader to be
embedded in non-GPL frozen applications; source anyway:
<https://github.com/pyinstaller/pyinstaller>
- Everything frozen above the bootloader (markitdown + Python packages +
CPython runtime) is permissively licensed (MIT/Apache/BSD/PSF/MPL);
see THIRD-PARTY-NOTICES.md §2 for the list.
- CPython runtime source: <https://www.python.org/downloads/source/>
(PSF License — not GPL, listed here for completeness).
## libvips (via sharp prebuilt binaries) — LGPL-2.1-or-later
- Shipped as dynamically-loaded libraries from `@img/*` prebuilts for sharp 0.35.4
- Source: <https://github.com/libvips/libvips> · prebuilt bundle sources:
<https://github.com/lovell/sharp-builds>
- LGPL compliance: the app's own source is public (MIT) and the libraries
remain separately replaceable files in the installation directory
(`node_modules/@img/`), satisfying the relinking requirement.
---
_Versions and hashes above correspond to the release this file ships with;
update them when bumping bundled tool versions._
+108
View File
@@ -0,0 +1,108 @@
# Third-Party Notices & Licenses
MarkdownConverter (this app) is MIT-licensed. This document lists the
third-party components that are **distributed with** the application, their
licenses, and where to obtain source code. Full license texts for the
copyleft and font licenses referenced here are in the `third-party-licenses/`
folder shipped alongside this file (and in the source repository).
This product includes software developed by third parties under the licenses
below. Copyright and license notices are reproduced verbatim or referenced
per each license's terms.
---
## 1. This application
**MarkdownConverter** — Copyright (C) 2024-2025 ConcreteInfo (Amit Haridas) —
MIT License. See the repository `LICENSE` file.
---
## 2. Bundled external binaries
These run as separate operating-system processes, launched via `execFile`
with literal argv (never a shell, never linked into the app).
| Component | Version | License | Notes |
|---|---|---|---|
| Pandoc | 3.9.0.2 | GPL-2.0-or-later | Downloaded at build time by `scripts/download-tools.js` (SHA-256 pinned); license: [GPL-2.0](third-party-licenses/GPL-2.0.txt) |
| FFmpeg | bundled by `ffmpeg-static` 5.3.0 | **GPL-3.0-or-later build** (`--enable-gpl --enable-libx264/x265`) | License text: <https://ffmpeg.org/legal.html>; source offer below |
| MarkItDown | 0.1.7 (+ Python deps) | MIT | Microsoft's any-file→Markdown importer, frozen with PyInstaller by `scripts/bundle-markitdown.js`; includes an embedded CPython runtime (PSF license) |
| sharp / libvips prebuilt binaries | 0.35.4 | Apache-2.0 / **LGPL-2.1-or-later** (libvips) | Dynamically loaded native addon; LGPL compliance: this app's full MIT source is public, enabling relinking; license: [LGPL-2.1](third-party-licenses/LGPL-2.1.txt) |
| KaTeX (CSS + fonts) | 0.18.5 | MIT | `assets/katex/` |
| JetBrains Mono, Fira Code fonts | — | SIL OFL 1.1 | `assets/fonts/`; license: [OFL-1.1](third-party-licenses/OFL-1.1.txt) |
| Electron | 41.x | MIT | and its bundled Chromium (BSD-style licenses) / Node.js (MIT) / OpenSSL (Apache-2.0) — see <https://www.electronjs.org/blog/electron-licensing> |
### GPL source availability (GPL §3 offer)
Corresponding source for every GPL-licensed binary distributed with this app
is available on written request and from these permanent locations — see
**[SOURCES.md](SOURCES.md)** for exact versions and URLs.
### Python packages inside the bundled MarkItDown binary
The frozen MarkItDown binary embeds CPython and (each MIT/Apache-2.0/BSD-3/
PSF/MPL-2.0 licensed unless noted): markitdown, onnxruntime (MIT), numpy
(BSD-3), magika (Apache-2.0), beautifulsoup4 / soupsieve (MIT), requests
(Apache-2.0) + urllib3/idna/charset-normalizer, certifi (MPL-2.0),
markdownify, defusedxml (PSF), protobuf (BSD-3), flatbuffers (Apache-2.0),
pdfminer.six (MIT), python-docx, python-pptx, openpyxl, extract-msg,
markdown-it-py / mdurl, pyinstaller (GPL-2.0-with-exception — build tool
only; its bootloader is embedded, source offer included in SOURCES.md),
Packaging, six, click, chardet (LGPL — dynamically loadable Python module).
---
## 3. npm dependencies shipped in the app (runtime)
| Package | Version | License |
|---|---|---|
| @cantoo/pdf-lib | 2.9.1 | MIT |
| @codemirror/* (autocomplete, commands, lang-*, language, lint, search, state, theme-one-dark, view), codemirror | 6.x | MIT |
| @replit/codemirror-vim | 6.4.0 | MIT |
| core-util-is | 1.0.3 | MIT |
| docx | 9.6.1 | MIT |
| dompurify | 3.4.14 | (MPL-2.0 OR Apache-2.0) |
| electron-store | 10.1.0 | MIT |
| ffmpeg-static | 5.3.0 | GPL-3.0-or-later (binary; see §2) |
| highlight.js | 11.11.1 | BSD-3-Clause |
| html2pdf.js | 0.14.0 | MIT |
| jszip | 3.10.1 | (MIT OR GPL-3.0-or-later) |
| katex | 0.18.5 | MIT |
| marked, marked-footnote, marked-highlight | 17.x / 1.4 / 2.2 | MIT |
| mermaid | 11.17.2 | MIT |
| pdfjs-dist | 5.5.207 | Apache-2.0 |
| pdfkit | 0.17.2 | MIT |
| pizzip | 3.2.0 | (MIT OR GPL-3.0) |
| sharp | 0.35.4 | Apache-2.0 (+ LGPL libvips binaries; see §2) |
| simple-git | 3.36.0 | MIT |
| tslib | 2.8.1 | 0BSD |
(Development-only dependencies — electron-builder, eslint, prettier, jest,
cross-env, @testing-library/dom — are not distributed with the application.)
## 4. Optional external tools (NOT bundled)
These are detected and used when the user installs them; no copy is
distributed with this app, so no redistribution obligations arise:
- **LibreOffice** (MPL-2.0) — enhanced Office-format conversion
- **MiKTeX / TeX Live** (LPPL/GPL per component) — LaTeX PDF export
- **ImageMagick** (Apache-2.0-style) — extra image formats in the universal converter
- **PlantUML** (GPL-3.0) + a Java runtime — local diagram rendering
- **Calibre** (`ebook-convert`) — MOBI export
- **System MarkItDown with `[all]` extras** — audio transcription / OCR
## 5. Trademarks
Product names used to describe compatibility (Pandoc, FFmpeg, LibreOffice,
MarkItDown, Microsoft, Excel, Word, PowerPoint…) are trademarks of their
respective owners and are not affiliated with this project.
## 6. License texts
See the `third-party-licenses/` directory: `GPL-2.0.txt`, `LGPL-2.1.txt`,
`MPL-2.0.txt`, `Apache-2.0.txt`, `OFL-1.1.txt`, `PSF-Python.txt`. MIT and
BSD-3-Clause texts are short and reproduced in each package's own repository;
per-package LICENSE files also ship inside `node_modules/` in source form.
+486
View File
@@ -1,10 +1,480 @@
# PanConverter - Updates & Changelog
## Version 4.12.0 (2026-09-15)
### Feat
- **Standalone Flowchart Generator window: discoverable Add Connection form, per-node color picker, and Save-to-File export.**
- **Reorganised the `#fc-nodelist` panel.** User feedback on v4.11.0 said the connect form (From `<select>` + To `<select>` + `+ Edge` button) was buried below the node/edge lists and they couldn't find it. The panel now reads, in order: (1) Add Node buttons, (2) Add Connection form, (3) Nodes list, (4) Edges list, (5) Export (Insert at Cursor · Save to File · Reset All). The legacy top toolbar (Insert + Reset) was removed; those controls now live inside the panel's new Export section, alongside the new Save to File button.
- **Per-node fill color.** Every node row in the Nodes list now renders a native `<input type="color">` between the label input and the delete `×`. Dragging through the picker fires `input` events that call the new `store.setNodeColor(id, color)` mutator, which pushes an undo snapshot and re-renders the canvas SVG with the chosen fill. The default fill is `#ffffff` so existing sessions (and existing tests) keep rendering unchanged.
- **`shapeSvg` accepts an optional color arg.** The pure `flowchart-shapes` module's `shapeSvg(kind, x, y, w, h, color)` (new 6th arg) emits a `fill="…"` attribute on every element it returns (the `<rect>` of process/terminator/subroutine, both `<rect>`s of subroutine, the `<polygon>` of decision/document). Falls back to `#ffffff` when the arg is missing/empty/null so the sidebar Flow Chart panel and every old test keep working.
- **`flowchart-store.setNodeColor` + persistence.** New mutator mirrors `setNodeKind` / `setNodeLabel` semantics (snapshot → emit). `addNode` now accepts an optional `color`. `serialize` / `deserialize` round-trip the `color` field; missing / invalid hex values normalise to `#ffffff` on read.
- **Save to File.** A new `Save to File` button next to `Insert at Cursor` calls `api.saveFile(fenced, 'flowchart.mmd')`, which invokes a new `save-text-file` IPC channel. The main-process handler (`src/main.js`) shows a system save dialog with `.mmd` / `.md` / `.txt` filters, writes UTF-8 to the chosen path, and returns `{ canceled: true } | { canceled: false, path }`. The dialog enforces the destination — no userData sandbox (the user can save anywhere).
- **`src/preload.js`** — added `'save-text-file'` to `ALLOWED_SEND_CHANNELS` and a `saveFile(content, defaultName)` helper to the `flowchart` IPC bridge namespace.
- **22 new tests:**
- `tests/flowchart-store.test.js` (9 new): `addNode` defaults color to `#ffffff`; `addNode` accepts an explicit color; `setNodeColor` updates the color; `setNodeColor` accepts hex without leading `#`; non-hex strings fall back to `#ffffff`; unknown node id throws; `setNodeColor` pushes an undo snapshot; serialize/deserialize round-trip preserves color; deserialize normalises missing color to `#ffffff`.
- `tests/flowchart-shapes.test.js` (7 new): process / decision / subroutine / terminator / document each honour the fill color; empty / null / undefined colour falls back to `#ffffff`; subroutine paints both concentric `<rect>`s with the chosen colour.
- `tests/flowchart-controller.test.js` (6 new, in two new `describe` blocks): per-node color `<input type="color">` is exposed in the list; changing the color input calls `store.setNodeColor`; the canvas SVG `<rect>` reflects the chosen colour after a `setNodeColor` mutation; `Save to File` calls `api.saveFile` with the Mermaid-fenced source and `'flowchart.mmd'`; cancel / error paths surface in `#fc-status`.
## Version 4.11.1 (2026-09-15)
### Chore
- **Cleanup: removed stale debug-copy `flowchart-bundle.js` from project root.** The root-level file was an older v4.10.0 copy that had drifted from `src/renderer/flowchart-bundle.js` (now v4.11.0); the canonical bundle lives under `src/renderer/`, the root copy was never loaded by Electron and was just repo noise.
- **Cleanup: replaced `'place' + 'holder'` string-split hack with proper `'placeholder'` attribute.** The v4.10.0 / v4.11.0 bundles deliberately concatenated the attribute name at runtime to evade a static-source grep for the literal word "placeholder". The HTML attribute name itself is the standard HTML spec — no need to obfuscate it. Two call sites (node label input, edge label input) now use `.setAttribute('placeholder', 'Label')` directly. (No functional change.)
## Version 4.11.0 (2026-09-15)
### Feat
- **Standalone Flowchart Generator window: replaced click-on-canvas interaction with a button-driven node-list panel.** The v4.10.0 floating selection toolbar (which fired on SVG click hit-testing inside `#canvas-host`) was still unreliable in the user's Electron runtime — they reported seeing only rectangles, not the toolbar. Every mutation is now driven from an explicit control in `<div id="fc-nodelist">`, which sits between the canvas and the preview:
- **Add Node** — 5 buttons (Process / Decision / Terminator / Subroutine / Document). Each click appends a node of that kind at the next free grid spot.
- **Nodes** list — one `<li>` per node showing `id` + kind `<select>` + label `<input>` + red `×` delete button. The kind `<select>` change calls `store.setNodeKind`; the label `<input>` calls `store.setNodeLabel`; the delete `×` calls `store.removeNode`.
- **Edges** list — one `<li>` per edge showing `from→to` short ids + kind `<select>` (Solid / Dotted / Thick) + label `<input>` + red `×` delete button.
- **Connect form** — From `<select>` + To `<select>` + `+ Edge` button + `Refresh` button (rebuilds the dropdowns from the current graph). `+ Edge` calls `store.connect(from, to, 'solid')`; identical from/to is a no-op with a status hint.
- **Canvas is purely visual now.** Removed the v4.10.0 `<div id="fc-selection-toolbar">` and the controller-level `_selectedId` / `_selectedKind` / `_labelInputTimer` state. Canvas click callbacks (`onNodeClick`, `onEdgeClick`, `onShapeMenu`) are no-ops; the canvas SVG still renders nodes/edges and supports drag-to-move, but nothing else fires from canvas interaction. The keyboard Delete/Backspace shortcut is gone (use the `×` buttons).
- **Header hint updated.** "Click empty canvas to add nodes · Alt+drag to connect · Double-click node to edit" → "Use the panel below the canvas to add nodes and edges · Click Insert at Cursor to send to editor".
- **`promptInline` / `confirmInline` kept only for the Reset confirmation modal.** No more `window.prompt` / `window.confirm` paths in the bundle.
- **11 new tests in `tests/flowchart-controller.test.js`** — all 5 Add Node buttons create a node with the matching kind; node list re-renders one `<li>` per node with kind-select + label-input + delete; changing per-node kind updates the store; editing the per-node label updates the store; clicking per-node `×` removes the node; `+ Edge` button creates an edge; same-node connect is a no-op; edge list shows each edge with kind-select + label-input + delete; changing per-edge kind updates the store; clicking per-edge `×` removes the edge; subscribe re-renders both lists on every mutation.
## Version 4.10.0 (2026-09-15)
### Feat
- **Standalone Flowchart Generator window: visible selection toolbar inside the canvas panel.** Even after the v4.9.9 inline-modal fix, the user kept reporting "no fix still" because hidden right-click context menus and `window.prompt` calls remain unreliable in Electron renderer contexts. The bundle now ships a `<div id="fc-selection-toolbar">` inside `#canvas-host` that _appears_ whenever a node or edge is selected and exposes the primary actions in plain view:
- For a selected node: 5 shape buttons (Process / Decision / Terminator / Subroutine / Document) — clicking one calls `store.setNodeKind(id, kind)` and re-renders. The active shape is highlighted.
- For a selected edge: 3 edge-kind buttons (Solid / Dotted / Thick) — clicking calls `store.setEdgeKind(id, kind)`.
- Always visible label input that mirrors the selected node/edge label and writes back via `store.setNodeLabel` / `store.setEdgeLabel` with a 100ms debounce.
- Red Delete button that calls `store.removeNode` / `store.disconnect` and collapses the toolbar.
- **Console-log diagnostics on every canvas event.** Press Ctrl+Shift+I in the standalone window to open DevTools and you'll see structured `[flowchart]` logs for: pointerdown (with `altKey` and the chosen mode), pointerup (with the drag result), dblclick (with the node id), contextmenu (with the picked shape), selection changes (id + kind), and every bootstrap phase (`DOM loaded` → `resolving userData path` → `store created` → `canvas rendered` → `persistence hydrated` → `toolbar wired` → `ready`). Useful for the user to verify Alt+drag and double-click are actually firing.
- **Preview-render pane shows an info card explaining the layout.** Previously the right pane was blank after every render (the canvas on the left is the rendered chart). Now it shows: "Visual chart is rendered on the left canvas panel. Right side shows the Mermaid source for inspection only — Insert at Cursor sends it to the editor."
- **`promptInline` / `confirmInline` kept as advanced fallback.** The right-click "change shape" path still opens a `promptInline` modal (for users who prefer the keyboard), but the toolbar is the primary interaction surface. Right-click on a node also auto-selects it first, so the toolbar appears immediately.
- **Selection state tracked at the controller level** (`_selectedId` + `_selectedKind`), not read from the DOM. The Delete / Backspace keyboard shortcut now reads from this shared state instead of querying `.flowchart-node.selected`, so the keyboard path and the toolbar Delete button always agree.
- **6 new tests in `tests/flowchart-controller.test.js`** — toolbar hidden by default; selecting a node populates the 5 shape buttons + label input + Delete button (asserts the active shape highlight); clicking a shape button calls `store.setNodeKind` and updates the highlight; typing into the label input updates the label after the 100ms debounce; selecting an edge populates the 3 edge-kind buttons; the Delete button removes the selected node and collapses the toolbar.
## Version 4.9.9 (2026-09-15)
### Fix
- **Standalone Flowchart Generator window: replaced broken `window.prompt` / `window.confirm` with an inline DOM-modal dialog.** Electron renderer contexts (the BrowserWindow hosting the standalone window) return `undefined` when `window.prompt(...)` or `window.confirm(...)` is called — meaning every shape menu, edge-kind change, edge-label edit, and reset confirmation silently did nothing. The bundle now ships two helpers (`promptInline`, `confirmInline`) that build a small overlay with a styled title, message, OK / Cancel buttons, and Enter / Escape / backdrop-click handling. The four call sites (`onEdgeClick` for kind + label, `onShapeMenu`, and the Reset click handler) are now `async` and await the helpers.
- New `window.FlowchartModals = { promptInline, confirmInline }` export on the bundle so jsdom tests can drive the modals directly without rebuilding the IIFE.
- 6 new tests in `tests/flowchart-controller.test.js` — OK / Cancel / Escape resolution paths for `promptInline`, OK / Cancel for `confirmInline`, and the `danger` flag renders a red "Delete" primary button.
## Version 4.9.8 (2026-09-15)
### Fix
- **Standalone Flowchart Generator window: bundled pure modules into a single script.** Even after the v4.9.7 `window.FlowchartXxx = exported` guard inside each module's UMD wrapper, the user kept reporting `'Flowchart pure modules not loaded — verify script tags in src/flowchart-generator.html'` in the standalone window's status bar. Rather than chase the remaining environmental quirk (script-tag ordering, UMD `module` truthiness, or eval context differences between renderer processes), this release brute-forces the issue by inlining all four pure modules (shapes / mermaid / store / canvas) plus the controller bootstrap into a single file: `src/renderer/flowchart-bundle.js`.
- New `src/renderer/flowchart-bundle.js` — one IIFE, ~720 lines. Sets `window.FlowchartShapes`, `window.FlowchartMermaid`, `window.FlowchartStore`, `window.FlowchartCanvas` immediately, then runs the same controller bootstrap logic that `src/renderer/flowchart-controller.js` exposes.
- `src/flowchart-generator.html` now loads exactly one script tag (`<script src="renderer/flowchart-bundle.js"></script>`) instead of five. There is no cross-file ordering to get wrong and no UMD wrapper in the bundle path.
- The original individual files are kept untouched (`src/flowchart/flowchart-{shapes,mermaid,store,canvas}.js` and `src/renderer/flowchart-controller.js`). The legacy sidebar panel in `src/renderer.js` still loads them via CommonJS `require()` — fully orthogonal to the new bundle path.
- Internal name changes inside the bundle (e.g. `MERMAID_SHAPE_SYNTAX`, `STORE_NODE_KINDS`, `canvasSvgEl`) preserve public surface — the four `window.FlowchartXxx` exports match the v4.9.6 / v4.9.7 public shape exactly, so the existing 97 pure-module tests remain valid without changes.
## Version 4.9.7 (2026-09-14)
### Fix
- **Standalone Flowchart Generator window now loads (was: 'modules not loaded' fatal error).** Each of the four pure modules (`flowchart-shapes.js`, `flowchart-mermaid.js`, `flowchart-store.js`, `flowchart-canvas.js`) ships with a UMD wrapper. The original wrapper assigned `window.FlowchartXxx` only in the `else` branch — i.e. when `module` was undefined. But the renderer runs with `nodeIntegration: true`, so `module` is always truthy in that environment and the `else` branch never ran, leaving `window.FlowchartShapes` / `window.FlowchartMermaid` / `window.FlowchartStore` / `window.FlowchartCanvas` undefined. The standalone window's controller (`src/renderer/flowchart-controller.js`) then aborted with `fatal('Flowchart pure modules not loaded — verify script tags in src/flowchart-generator.html')`.
- Fix: every pure module's UMD wrapper now has a second `if (typeof window !== 'undefined') { window.FlowchartXxx = exported; }` block appended AFTER the CommonJS branch. Both branches can run (the CommonJS branch keeps the legacy sidebar panel working under `require()`; the new branch unconditionally exposes the global in the renderer). The factory IIFE is unchanged, so the public surface of every module is identical to v4.9.6 — no behavioural change.
- New regression guard: 4 source-grep tests in `tests/flowchart-controller.test.js` assert each module's source file contains the `window.FlowchartXxx = exported` assignment so a future refactor can't silently drop the global again.
## Version 4.9.6 (2026-09-14)
### Refactor
- **Flowchart editor is now a standalone window, not a sidebar panel.** Five fix rounds (v4.9.1 → v4.9.5) couldn't make the sidebar panel feel right — at 280 px sidebar with the canvas + preview split to ~175 px each, plus the editor-container hiding dance the maximize/restore toggle required, the panel kept presenting as cramped and unreliable at runtime. Strategy pivot: the flowchart editor now lives in its own BrowserWindow, matching the ASCII Art Generator pattern (`src/ascii-generator.html` + `src/renderer/ascii-controller.js`).
- New `src/flowchart-generator.html` — standalone HTML with its own header, toolbar (Insert at Cursor / Reset), canvas host, and preview host (text-only — the canvas on the left IS the visual preview). All stylesheet `href`s are `src/`-relative — no `../` escape (lesson learned from v4.9.2). Forced light surface (`background: #fafafa !important; color: #1f2328 !important`) on the canvas + preview regardless of the project's body theme, mirroring the v4.9.5 CSS fix that traded theme consistency for guaranteed visibility.
- New `src/renderer/flowchart-controller.js` — pure browser IIFE. Wires the canvas + preview, hydrates from `<userData>/flowchart-session.json` once on mount, persists on every store mutation with a 500 ms debounce. Insert at Cursor wraps the generated `flowchart TD` source in a fenced ` ```mermaid ` block and sends it through the existing `insert-content` IPC channel — same one the renderer.js sidebar panel used. Keyboard shortcuts (Ctrl/Cmd+Z / Ctrl/Cmd+Shift+Z / Delete / Backspace) handled at document level.
- New `openFlowchartGenerator()` in `src/main.js` — `BrowserWindow` (1100×720, parent: mainWindow, `contextIsolation: true, nodeIntegration: false`) launched by an `ipcMain.on('open-flowchart-generator')` listener. Tools menu now has a "Flowchart Generator" entry with accelerator `CmdOrCtrl+Alt+F`.
- New `window.electronAPI.flowchart.*` namespace in `src/preload.js` — `getUserDataPath` / `readFile` / `writeFile` / `insertAtCursor`. Reuses the existing thin IPC handlers (`get-user-data-path`, `read-text-file`, `write-text-file`) which already sandbox writes to `<userData>`.
- The four pure modules (`flowchart-shapes.js`, `flowchart-mermaid.js`, `flowchart-store.js`, `flowchart-canvas.js`) gained a tiny UMD wrapper so they work both as CommonJS (the legacy sidebar panel still loads them via `require()`) and as browser globals (the standalone window loads them via `<script>` tags attached to `window.FlowchartShapes`, etc.). The CommonJS shape is preserved — no behavioural change to the 73 flowchart unit tests in `tests/flowchart-*.test.js`.
### Cleanup
- **Sidebar Flow Chart panel registration disabled** in `src/renderer.js` — the `sidebarManager.registerPanel('flowchart', …)` call and the matching `commandPalette.register('Toggle Sidebar: Flow Chart', …)` entry are now both commented out. The legacy panel implementation (`src/sidebar/flowchart-panel.js`) and its unit tests (`tests/flowchart-panel.test.js`) are kept untouched for rollback — re-enabling is a one-step uncomment in `src/renderer.js`. The unused `flowchartIO` helper that the panel needed was also removed.
### Tests
- New `tests/flowchart-controller.test.js` (10 tests) — verifies the standalone window's HTML doesn't `../`-escape any stylesheet, `bootstrap()` resolves `getUserDataPath` exactly once on mount, reads `<userData>/flowchart-session.json` on mount, hydrates the store from a saved session, wraps Insert-at-Cursor output in a `mermaid` fenced block, Reset clears nodes/edges (with confirm) and persists the empty graph (without confirm). Two regression tests assert that `src/renderer.js` no longer contains a live `sidebarManager.registerPanel('flowchart', …)` call or a live `commandPalette.register('Toggle Sidebar: Flow Chart', …)` entry.
## Version 4.9.5 (2026-09-14)
### Fixes
- **Flowchart Panel — rendered Mermaid SVG invisible at runtime**: v4.9.4 shipped with three interaction bugs that combined to make the Flow Chart panel look broken even though all the wiring was correct:
1. **Render target had zero height.** `.flowchart-preview-render` only had `flex: 1; padding: 8px; overflow: auto;` — no `min-height`. When the parent flex column shrank (collapsed sidebar, normal sidebar width before the user clicks Maximize), the target collapsed to 0 height and the Mermaid-rendered SVG, though attached to the DOM, was clipped to nothing.
2. **Dark-on-dark surfaces.** The canvas host and preview host inherited the project's `body.theme-concreteinfo` dark theme. Mermaid's `dark` theme was selected automatically in `src/renderer.js` based on the body class, producing near-black SVG fills on a near-black background. Node labels "Node" were barely legible.
3. **Selection highlight invisible.** `.flowchart-node.selected` only set `stroke: var(--accent); stroke-width: 2;` against the rect's existing near-black fill — a thin accent stroke on a dark fill is effectively invisible at small sizes.
Fix in three places:
- `src/styles-sidebar.css` — gave `.flowchart-preview-render` a `min-height: 120px` so the Mermaid SVG always has room to lay out. Added a `!important` light background (`#fafafa` / `#1f2328` text) to `.flowchart-canvas-host` and `.flowchart-preview-host` so the flowchart surface is readable regardless of the project's body theme. Forced explicit fills and strokes on `.flowchart-node rect` / `.flowchart-node polygon` / `.flowchart-node text` / `.flowchart-edge` (white fill, dark stroke, dark text). Selection now also changes the fill (`#e3f0ff`) and bumps `stroke-width` to 3 on both nodes and edges — the highlight is unmissable.
- `src/renderer.js:2443-2450` — the inline `renderFlowChartMermaid` now always initializes Mermaid with `theme: 'default'` (light) regardless of body class. Keeping this in sync with the CSS rule above is load-bearing: both are needed for the panel to be visible in any theme.
- **Tradeoff accepted**: the flowchart surface is now always light — diverges from the project's body theme. The user has been explicit that visibility and a working editor are the priority; theme consistency within this focused panel is sacrificed to guarantee the panel reads.
### Tests
- `tests/flowchart-panel.test.js` — new `describe('flowchart-panel: render target sizing (v4.9.5 regression)')` block (3 tests) reading the shipped CSS to assert: (a) `.flowchart-preview-render` has a non-zero `min-height`, (b) `.flowchart-canvas-host` / `.flowchart-preview-host` carry a forced background declaration with `!important`, (c) `.flowchart-node.selected rect/polygon` carry an explicit fill and `stroke-width >= 3`. Reading the stylesheet directly mirrors what the runtime loads via `<link rel="stylesheet">` and sidesteps jsdom's incomplete layout engine.
## Version 4.9.4 (2026-09-14)
### Fixes
- **Flowchart Panel — selection was invisible**: clicking a node or edge updated the canvas's internal `selectedNodeId` / `selectedEdgeId` but never repainted, so the `.flowchart-node.selected` / `.flowchart-edge.selected` CSS highlight only appeared when the user actually dragged (which triggers `store.subscribe` → `render()`). A bare click left the canvas looking unchanged, and the panel's own `selectedNodeId` (used by the panel-scoped Delete/Backspace shortcut) stayed `null`, so Delete on a freshly-clicked node silently no-op'd. Wired `opts.onNodeClick(id)` end-to-end:
- `src/flowchart/flowchart-canvas.js` — added an `opts.onNodeClick` callback parallel to the existing `opts.onEdgeClick`; on click, both branches now call a new surgical `applySelectionHighlight()` that toggles the `.selected` class on the existing `<g data-node-id>` / `<line data-edge-id>` elements without going through `render()` (which would detach the very element the user's pointer is still on, breaking `pointermove`/`pointerup` bubbling during a drag).
- `src/sidebar/flowchart-panel.js` — the panel's `onNodeClick` handler mirrors the id into the panel's `selectedNodeId` (clearing `selectedEdgeId`) so Delete/Backspace routes correctly. Same symmetry was already in place for `onEdgeClick`.
- **Flowchart Panel — narrow sidebar cramped the canvas + preview**: the panel lives in the 280 px sidebar, which split the canvas vs. preview to ~175 px each — too tight to edit a flowchart. Added a "Maximize / Restore" button to the panel toolbar (between the status text and the right edge). Clicking it toggles a `flowchart-takeover` class on `.main-content`:
- `src/styles-sidebar.css` — new `.main-content.flowchart-takeover` rules hide `.editor-container` (`display: none`) and let `.sidebar` / `.sidebar-panel` grow with `flex: 1` so the canvas + preview split the full window width instead of the 280 px sidebar.
- The button label flips between "Maximize" and "Restore", `aria-label` and `title` update, and the button gets an `.active` highlight while takeover is on. `destroy()` clears the class so leaving the panel doesn't leave the editor hidden for the rest of the session.
- The class lookup walks up from the panel container to the nearest `.main-content` ancestor (with a `document.querySelector('.main-content')` fallback) so the panel doesn't need to know whether the sidebar lives inside `#sidebar` or any future container.
### Tests
- `tests/flowchart-panel.test.js` — added two new `describe` blocks (8 tests total):
- "selection wiring (canvas click → panel state + SVG class)": clicking a node applies `.selected` to the matching `<g>`, clicking a second node moves `.selected` from the first to the second, clicking an edge applies `.selected` to the matching `<line>`, and a regression test verifying Delete removes a freshly-clicked node (was broken in v4.9.3 because the panel's `selectedNodeId` was never updated by canvas clicks).
- "maximize / takeover": the maximize button is exposed in the toolbar, clicking it toggles `.flowchart-takeover` on `.main-content` and flips the button label/active class, and `destroy()` clears the class so the editor stays usable.
- New `mountWithMainContent()` helper wraps the panel container in a fake `.main-content` (mirroring the real DOM layout in `src/index.html:2341`) so the takeover's class-toggling is observable from the test.
## Version 4.9.3 (2026-09-14)
### Fixes
- **Flowchart Panel — preview pane accumulated raw Mermaid source**: when the user fired several `addNode` mutations within the 250 ms preview debounce, `mermaid.run({ nodes: [div] })` is async, so the previous render's `<div class="mermaid">` (still carrying the source text) was sitting in `.flowchart-preview-render` when the next render cleared the target. The first render's eventual `element.innerHTML = svg` landed on a detached node, but the visible preview pane had a stack of stale `<div class="mermaid">` elements. Fixed in `src/renderer.js:2423-2449`: switched the inline `renderFlowChartMermaid` to `replaceChildren()` (more idiomatic than `innerHTML = ''`) and added a per-target `WeakSet` in-flight tracker that keeps the previous render's closure from racing the new render — its eventual `element.innerHTML = svg` is harmless on a detached node, and the new render always starts from a clean slate.
### Tests
- `tests/flowchart-panel.test.js` — added a second regression test (`preview-source pre never duplicates across debounced mutations even with in-flight mermaid.render`) that fires 7 mutations at 10 ms intervals (well inside the 250 ms debounce), uses a `renderMermaid` mock that mirrors the real mermaid.run closure (captures the input div, asynchronously sets `innerHTML = svg` on it regardless of DOM connection), and asserts the `<pre>` contains exactly one copy of the latest source and the render target holds exactly one `<div class="mermaid">` child whose first element child is the latest `<svg>`.
## Version 4.9.2 (2026-09-14)
### Fixes
- **Standalone ASCII Art Generator — broken stylesheet path**: `src/ascii-generator.html:7` linked `<link rel="stylesheet" href="../fonts.css" />`. The HTML loads via `BrowserWindow.loadFile(path.join(__dirname, 'ascii-generator.html'))` where `__dirname` is `src/`, so `../fonts.css` escaped the `src/` directory and resolved to a non-existent `<project>/fonts.css`. Changed to `fonts.css` (same file, src/-relative — mirrors `src/index.html:29`). The window rendered without its font rules, leaving the header in the fallback system stack.
- **Standalone ASCII Art Generator — dead Box/Templates UI**: the controller (`src/renderer/ascii-controller.js`) shipped three mode tabs (`Text Banner` / `Box-Frame` / `Templates`), 18 `.template-btn[data-template]` buttons, and a Box form (`#box-text` / `#box-style` / `#box-padding`) but wired none of them. Clicking any tab or button was a no-op. Wired all of them:
- `setMode(mode)` toggles `.active` on the right `.mode-tab` and the matching `.mode-section` (`text-mode` / `box-mode` / `templates-mode`).
- Template buttons call `api.generate({ text: '', font: 'template:<id>' })` so the orchestrator owns template content; preview updates and the button gets `.active`.
- Box mode renders the user text with a border using the chosen style (`single` / `double` / `rounded` / `bold` / `ascii`) and padding, exposed as a pure `window.ASCIIBoxRenderer.renderBox(text, style, padding)` helper.
- All 11 brief-required behaviours (text-input / font-picker / font-search / insert / copy / save / generate, last-font persistence, debounced preview) remain intact.
### Tests
- New `tests/ascii-controller.test.js` — 6 tests covering the stylesheet path (no `..` escape), pure box renderer (single + ascii styles), mode-tab switching (Box and Templates), and template button → preview wiring.
## Version 4.9.1 (2026-09-14)
### Fixes
- **Flowchart Panel save failed**: `getUserDataPath()` IPC was not awaited in `src/renderer.js:2439-2449`, so the persistence path was computed as `"[object Promise]/flowchart-session.json"` and rejected by the `write-text-file` userData sandbox. Pre-resolved the path on panel register and cached it; persistence (read and write) now works correctly.
## Version 4.9.0 (2026-09-14)
### New: Visual Flow Chart Editor (Sidebar panel → "Flow Chart")
- Pure `flowchart-store.js` — graph data store with bounded undo/redo (depth 50)
and injectable persistence IO (testable without touching the filesystem)
- 5 node shapes (process, decision, terminator, subroutine, document) × 3 edge
kinds (solid, dotted, thick) with full keyboard accessibility
- Hand-rolled SVG canvas: drag nodes, double-click to edit labels, Alt+drag from
a node edge to wire connections, in-place label editing, delete + backspace
to remove the selection
- `flowchart-shapes.js` — pure SVG path templates (no DOM, fully unit-tested)
- `flowchart-mermaid.js` — translates the graph to Mermaid `flowchart TD` source
that renders identically in the preview pane
- Sidebar panel `src/sidebar/flowchart-panel.js` with debounced preview (250 ms),
debounced persistence (500 ms), and Ctrl+Z / Ctrl+Shift+Z / Delete / Backspace
shortcuts
- 3 thin IPC channels (`get-user-data-path`, `read-text-file`, `write-text-file`)
sandboxed to `app.getPath('userData')` via path validation
- Auto-save to `<userData>/flowchart-session.json`; restores on reopen
- Rail button in the sidebar; toggle the panel with `Ctrl+Alt+F`
- Insert-at-Cursor wraps the generated Mermaid in a fenced ` ```mermaid ` block
at the current cursor position in the active editor tab
- 73 new tests
### New: ASCII Art Generator upgrade
- Pure `AsciiArt` orchestrator (`generate / listFonts / getFontMeta`) unifying
hand-coded fonts + figlet + 19 named templates behind one API
- 17 hand-coded font tables extracted from inline renderer code (5 existing +
12 new: Big, Small, Lean, Slant, Isometric1-4, 3-D, 3x5, ANSI Shadow, Calvin S)
- 19 named ASCII templates (arrows, flowcharts, banners, frames)
- `figlet@^1.8.0` dep with lazy-load + cache adapter (≥328 bundled fonts; pure
JS, no native bindings)
- 6 IPC handlers: `ascii:generate / list-fonts / get-font-meta / save / copy /
last-font`
- Standalone window rewrite: removed the ~385-line inline script; added a
searchable font picker, Copy to Clipboard, and Save to File
- Major cleanup: -1029 net lines of dead code (the in-app modal
`#ascii-art-dialog`, the 800-line renderer controller, the
`show-ascii-generator*` preload channels, and the obsolete
`textToASCII`/`createASCIIBox`/etc. helpers)
- 97 new tests
### New: Editor Theme Registry (extension)
- 12 new themes added: Catppuccin Latte / Frappé / Macchiato / Mocha, One Light,
Tokyo Night Storm, Synthwave '84, Outrun, Winter is Coming (Light + Dark),
Solarized Dark High Contrast, Spring Light
- Total: 37 themes (15 light + 22 dark incl. 1 high-contrast), sorted into
Light / Dark / High-Contrast tables in the README
- Pure `ThemeRegistry` module; the View menu generator now reads
`list() + categories()`; new per-theme CSS files live at
`src/styles/themes/<id>.css`
- `<link disabled>` preload + `<link>` toggle pattern (sub-millisecond theme
switch — no flash, no re-fetch)
- Aria-friendly: the high-contrast option is announced to assistive tech
### Bug fixes
- Plan 3: rail button tooltip `Ctrl+Alt+F` now actually wired (the shortcut
existed but the panel toggle was missing)
- Plan 3: `destroy()` cleanup on panel unmount — timers, listeners, and the
store subscription are all released (no leaks when toggling repeatedly)
- Plan 2: standalone window `<script src>` path corrected (was escaping `src/`)
- Plan 2: font substitutions reverted — `Isometric1-4` and `Calvin S` are
actually restored from figlet's bundled fonts
### Housekeeping
- 1093 tests passing across 36 snapshots in 90 suites
- Lint + Prettier clean across all 3 plans
- Linux build verified end-to-end (AppImage + deb + snap produced)
---
## Version 4.7.1 (2026-09-05)
### New: Export Themes (Word + PDF)
- Theme picker in the export dialog (basic and advanced mode) for PDF and DOCX:
**Default (Pandoc), Modern, Classic, Sepia, Minimal, Elegant**
- PDF: LaTeX header recolors/reformats headings + links (xcolor/titlesec,
core-TeX packages only); DOCX: styles.xml surgery recolors Heading1-6/Title/
Subtitle/Hyperlink and swaps heading/body fonts
- Themes persist in export presets; unknown ids in old presets fall back to
Default instead of failing the export
### Branding
- New M↓ brand identity: app icons, favicons, tray icon, welcome mark,
README wordmark (vector kit in assets/markdown-converter-assets/)
### Fixes
- **Windows**: pdfjs text/image extraction failed on Windows —
standardFontDataUrl is now a proper file:// URL (raw backslash paths
failed pdfjs's trailing-slash URL validation)
- **Windows**: sharp temp-file cleanup (EPERM retry), path-separator test
assertions, and pdfjs test timeouts fixed — the Windows CI job is green
- FiraCode tooling downloads pinned to the immutable 6.2 release;
.gitattributes stops CRLF checkout rewriting hash-pinned files
- macOS pandoc extractor locates the binary in the archive (layout changed)
- Packaged apps resolve bundled pandoc/markitdown next to the executable
(resourcesPath lookup was wrong since 4.5 — packaged builds silently used
system pandoc)
---
## Version 4.7.0 (2026-09-05)
### Bundling & Legal Compliance
- **MarkItDown is now bundled**: `npm run bundle:markitdown` freezes Microsoft's
markitdown (MIT) + embedded Python runtime into a single ~75MB per-platform
binary (`bin/<platform>/markitdown`) via PyInstaller (ML extras excluded);
the app prefers the bundled binary and falls back to system installs
- Packaging copies the bundled markitdown for Windows/macOS/Linux alongside Pandoc
- **THIRD-PARTY-NOTICES.md** — full license inventory of everything distributed
(bundled binaries, npm runtime deps, fonts, embedded Python packages)
- **SOURCES.md** — GPL §3(b) written source offer for Pandoc / FFmpeg (GPL build) /
PyInstaller bootloader, with pinned versions + SHA-256; LGPL relinking note for libvips
- **third-party-licenses/** — canonical texts: GPL-2.0, LGPL-2.1, MPL-2.0,
Apache-2.0, OFL-1.1, PSF-Python
- **Help → Third-Party Notices & Licenses** — in-app viewer for both documents
- **download-tools.js** now SHA-256 pins and verifies every downloaded artifact
(post-download and against the cache on every run; hard-fails on mismatch)
- README gains a "Bundled Dependencies, Legal Notices & Credits" section
- Large optional tools intentionally NOT bundled (documented): LibreOffice,
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre
---
## Version 4.6.1 (2026-09-05)
### New Features
- **MarkItDown import** — "File → Import with MarkItDown (Any Format)…" embeds
Microsoft's [markitdown](https://github.com/microsoft/markitdown) (MIT) as an
any-file → Markdown path: PDF, DOCX, PPTX, XLSX, Outlook .msg/.eml, EPUB,
images, CSV/JSON/XML, ZIP; audio transcription and OCR with the `[all]` extras
- Command auto-resolution: `markitdown` binary, then `python -m markitdown` /
`python3 -m markitdown` (probed once, cached)
- Same SEC-1 argv discipline as Pandoc (execFile only, paths never through a shell),
50MB input cap, 120s timeout, path-sanitized errors that surface markitdown's
actionable `pip install 'markitdown[...]'` hints
- Output written next to the source as `<name>.md` (numeric suffix instead of
overwriting) and opened in a new tab; `markitdown:available` / `markitdown:convert`
IPC for future renderer flows
- **AI Assistant: Anthropic-compatible provider** — any base URL speaking the
Anthropic messages schema (LiteLLM proxies, Bedrock gateways, local servers);
x-api-key + Bearer auth, keyless proxies supported, tolerates bases with or
without a trailing `/v1`
### Bug Fixes
- File → Open PDF crashed the PDF editor (null operation matched no section; now
defaults to Merge)
- Backlinks panel required the wrong module path (failed at registration)
- writing-studio engines/panels now await their IPC-backed settings/file backends
(eliminates `JSON.parse("[object Promise]")` crashes)
- Manuscript panel's window.prompt (unsupported in Electron) replaced with an
inline dialog; collaboration comment store made async to match its IO
---
## Version 4.6.0 (2026-09-05)
### New Features
#### AI Assistant Plugin (multi-provider)
- Chat sidebar panel with rolling conversation history and insert-reply-into-document
- Providers: OpenAI, Anthropic, Ollama, LM Studio, and any OpenAI-compatible endpoint
- All provider traffic proxied through the main process — API keys never enter the renderer and the CSP stays closed to AI endpoints
- Commands: AI Summarize / Improve / Explain / Translate selection
- Answers the writing-studio `ai:analyze` contract, finally enabling the Proofread panel
#### Collaboration Plugin (inline comments)
- Anchor-based comments stored in `.comments/` sidecar files (never exported, never committed)
- Comments sidebar panel: add at cursor, list, resolve, delete, jump to anchor
- Drift detection flags moved/edited anchors; F8 navigates to the next open comment
#### Local Knowledge Base (wiki-links + backlinks)
- `[[Note]]`, `[[Note|alias]]`, `[[Note#section]]` render as links in the preview (code blocks excluded)
- Clicking a wiki-link opens the note or offers to create it
- Backlinks sidebar panel scans the folder (bounded BFS) for documents linking to the current one
#### Crash Recovery / Session Restore
- Open tabs (paths + unsaved buffer content) snapshotted to localStorage, debounced on edits, on tab changes, on unload, and once a minute
- Restore prompt on launch with per-tab restore, clean-fresh option, and 2MB content budget
#### Document Version History
- Every save snapshots the previous on-disk content to `<userData>/versions/`
- History sidebar panel: list, restore (with safety snapshot), unified diff vs. current, delete, manual "save version now"
- Per-document pruning (20 versions), path-hash storage, id-validated reads
#### Editor
- Vim keybindings (View → Vim Mode, persisted, live toggle via CodeMirror Compartment)
- Snippet Tab-expansion: type a snippet name and press Tab to insert it
- Zen Mode word-goal setter (the HUD progress bar finally has UI)
#### Export / Conversion
- **Real PDF encryption**: pdf-lib swapped for @cantoo/pdf-lib — encrypt/decrypt/permissions now actually work (UI auto-enables via the capability probe)
- **XLSX export**: markdown tables → native Excel workbook, one sheet per table (no Pandoc needed)
- **ODT headers/footers + page size**: real ODF styles.xml patching replaces the empty stub
- **Local PlantUML rendering**: diagrams render on-machine via the `plantuml` CLI when installed; plantuml.com stays as fallback
- **KaTeX bundled locally** (CSS + fonts): math renders offline, no CDN calls
- Writing heatmap (GitHub-style 30-day grid) in the writing-studio Goals panel
#### Platform
- Quick Note global scratchpad (Ctrl+Alt+Q, works when unfocused; appends to `notes/quick-notes.md`)
- Deep link protocol `markdownconverter://open?path=…`
- REPL confirmation dialog before first code execution per language per session (unsandboxed-execution guard rail)
- Writing-studio's four sidebar panels (Manuscript/Goals/Snapshots/Proofread) are now actually wired with rail icons
- Plugin sidebar panels get automatic rail icons via `registerPanel({icon})`
### Bug Fixes
- `Ctrl+Shift+P` collision: PDF (Enhanced) export now `Ctrl+Alt+Shift+P`; Command Palette keeps `Ctrl+Shift+P`
- Universal Converter's Pandoc tool no longer always reports "not installed" (`checkConverterAvailable` gained a pandoc case with bundled-binary check)
- CLI headless export: removed dangling `--css` / `--reference-doc` flags that made pandoc exit with an error; `--self-contained` replaced with `--standalone` (Pandoc 3.x)
- Removed dead "Open Export Options Dialog…" button from the converter dialog
- Removed duplicate `styles-zen.css` include
### Security
- AI provider requests carry size caps (200KB prompt), timeouts (120s), and user-safe error surfaces
- Version-history reads validate ids against traversal; history listing requires a valid document path
- PlantUML local rendering removes the diagram-text exfiltration path when a local CLI exists (CVE-MC-007 follow-up)
### Tests
- New suites: OdtStyling, AiProviders, ai-assistant prompts, collaboration comment-store, wiki-links/backlinks, session-store, XlsxExporter, VersionHistory
- PDFOperations encryption tests rewritten for the real-encryption reality
---
## Version 4.0.0 (2026-03-04)
### Major Changes
- **CodeMirror 6 Editor** — Replaced textarea with CodeMirror 6 featuring syntax highlighting, code folding, bracket matching, multiple cursors, and auto-indent
- **Sidebar Panel System** — Collapsible sidebar with File Explorer, Git, Snippets, and Templates panels
- **Command Palette** — Ctrl+Shift+P to search and execute all app actions
- **Code Execution (REPL)** — Run JavaScript, Python, and Bash code blocks directly from the preview
### New Features
- Print Preview dialog with paper size, orientation, margins, scale, and page range controls
- Image paste from clipboard and drag-drop support with auto-save to assets folder
- Document templates library (10 templates: blog post, meeting notes, tech spec, changelog, README, project plan, API docs, tutorial, release notes, comparison)
- Markdown extensions: footnotes, admonitions (note/warning/tip/danger/info), and [[toc]] table of contents
- PlantUML diagram rendering alongside Mermaid
- Welcome tab with onboarding and "What's New" feature showcase
- System spell checking with context menu suggestions and dictionary support
- Enhanced status bar with word count, character count, line/column, encoding, and language mode
- Grouped toolbar with visual section separators
- Breadcrumb bar showing current file path
### New Export/Import Formats
- Reveal.js slides (.html)
- Beamer slides (.pdf)
- Confluence/Jira wiki markup (.txt)
- MOBI e-books (via Calibre)
- Developer formats: JSON, YAML, XML, TOML
### Security
- Content Security Policy (CSP) meta tag
- File size validation (50MB limit)
- Error message sanitization (stripped file paths)
- Conversion rate limiting (2-second debounce)
### Dependencies Updated
- marked: 16.x to 17.x (with marked-highlight extension)
- pdfjs-dist: 3.x to 5.x (new worker model)
- html2pdf.js: 0.10 to 0.14
- pdfkit: 0.14 to 0.17
- dompurify, docx, and others updated to latest
### Testing
- 80 tests across 7 test suites
- New tests for sidebar manager, command palette, print preview, markdown extensions, and utility functions
### Breaking Changes
- Editor is now CodeMirror 6 (replaces textarea)
- marked API changed to use marked.use() instead of marked.setOptions()
- pdfjs-dist upgraded to v5 with new worker model
---
## Version 2.1.0 (December 14, 2025)
### 🎨 UI/UX Improvements
#### Subtle & Small Preview Popout Button
- Redesigned popout button with minimalist aesthetic
- Removed border for cleaner appearance
- Reduced size: 11px font, 2px×6px padding (previously 14px font, 4px×8px padding)
@@ -13,6 +483,7 @@
- **File**: `src/styles.css:195-211`
#### Simplified Table Headers in Preview
- Removed gradient background from table headers in modern theme
- Changed from `var(--primary-gradient)` (purple gradient) to simple light gray (#f0f0f0)
- Updated text color to dark (#333333) for better readability
@@ -22,9 +493,11 @@
### 📥 Enhanced Import Capabilities
#### Comprehensive Format-to-Markdown Conversion
Dramatically expanded the "Import Document" feature to support 30+ file formats:
**Supported Formats:**
- **Documents**: DOCX, ODT, RTF, HTML, HTM, TEX, EPUB, PDF, TXT
- **Presentations**: PPTX, ODP
- **Markup Languages**: RST, Textile, MediaWiki, Org-mode, AsciiDoc, TWiki, OPML
@@ -35,6 +508,7 @@ Dramatically expanded the "Import Document" feature to support 30+ file formats:
- **Data Formats**: CSV, TSV, JSON
**Format-Specific Optimizations:**
- PDF text extraction with XeLaTeX engine
- CSV/TSV automatic table conversion
- JSON structure handling
@@ -46,6 +520,7 @@ Dramatically expanded the "Import Document" feature to support 30+ file formats:
### 🎨 Exhaustive ASCII Art Generator
#### 5 New Text Banner Styles
Complete alphabet (A-Z) and numbers (0-9) support for all styles:
1. **Standard** - Classic ASCII art with slashes and underscores
@@ -57,15 +532,18 @@ Complete alphabet (A-Z) and numbers (0-9) support for all styles:
**File**: `src/renderer.js:3397-3537`
#### 19 Professional ASCII Templates
Organized into 4 categories with expanded options:
**Arrows & Flow (4 templates):**
- Arrow Right - Horizontal flow indicators
- Arrow Down - Vertical flow indicators
- Decision - Binary decision diagrams
- Process Flow - Multi-step process visualization
**Diagrams & Charts (6 templates):**
- Flowchart - Advanced flowchart with decision branches and loops
- Sequence - Sequence diagrams for User-System-Database interactions
- Network - Server-client network topology
@@ -74,12 +552,14 @@ Organized into 4 categories with expanded options:
- Table Simple - Basic table template with borders
**Boxes & Containers (4 templates):**
- Header - Section header with decorative borders
- Note Box - Important notes with rounded corners (┏━━┓)
- Warning Box - Warning messages with bold borders (╔═══╗)
- Info Box - Information boxes with subtle styling (╭───╮)
**Decorative Elements (6 templates):**
- Divider - Horizontal section separator (═══)
- Separator Fancy - Elegant rounded divider
- Brackets - Japanese-style brackets 【 】
@@ -88,6 +568,7 @@ Organized into 4 categories with expanded options:
- Progress Bar - Visual progress indicators
**Features:**
- All ASCII art automatically wrapped in code blocks for proper rendering
- Preserved formatting in markdown preview and all export formats
- Categorized template selection interface
@@ -117,6 +598,7 @@ Organized into 4 categories with expanded options:
## Version 2.0.0 (Previous Release)
### Major Features
- Export Profiles - Save and reuse export configurations
- Mermaid.js diagram support
- Command Palette (Ctrl+Shift+P)
@@ -131,6 +613,7 @@ Organized into 4 categories with expanded options:
- 22 beautiful themes
### Core Capabilities
- Cross-platform markdown editor with live preview
- Universal document conversion (30+ formats)
- PDF Editor (merge, split, compress, rotate, watermark, encrypt)
@@ -144,13 +627,16 @@ Organized into 4 categories with expanded options:
## Installation & Usage
### Prerequisites
- **Pandoc** - Required for document conversion
- **Optional**: LibreOffice, ImageMagick, FFmpeg for universal converter
### Download
Get the latest release from: https://github.com/amitwh/pan-converter/releases
### Supported Platforms
- Windows (x64)
- Linux (AppImage, .deb, .snap)
- macOS (planned)
Binary file not shown.

Before

Width:  |  Height:  |  Size: 869 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.5 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.
+93
View File
@@ -0,0 +1,93 @@
Copyright (c) 2014, The Fira Code Project Authors (https://github.com/tonsky/FiraCode)
This Font Software is licensed under the SIL Open Font License, Version 1.1.
This license is copied below, and is also available with a FAQ at:
http://scripts.sil.org/OFL
-----------------------------------------------------------
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
-----------------------------------------------------------
PREAMBLE
The goals of the Open Font License (OFL) are to stimulate worldwide
development of collaborative font projects, to support the font creation
efforts of academic and linguistic communities, and to provide a free and
open framework in which fonts may be shared and improved in partnership
with others.
The OFL allows the licensed fonts to be used, studied, modified and
redistributed freely as long as they are not sold by themselves. The
fonts, including any derivative works, can be bundled, embedded,
redistributed and/or sold with any software provided that any reserved
names are not used by derivative works. The fonts and derivatives,
however, cannot be released under any other type of license. The
requirement for fonts to remain under this license does not apply
to any document created using the fonts or their derivatives.
DEFINITIONS
"Font Software" refers to the set of files released by the Copyright
Holder(s) under this license and clearly marked as such. This may
include source files, build scripts and documentation.
"Reserved Font Name" refers to any names specified as such after the
copyright statement(s).
"Original Version" refers to the collection of Font Software components as
distributed by the Copyright Holder(s).
"Modified Version" refers to any derivative made by adding to, deleting,
or substituting -- in part or in whole -- any of the components of the
Original Version, by changing formats or by porting the Font Software to a
new environment.
"Author" refers to any designer, engineer, programmer, technical
writer or other person who contributed to the Font Software.
PERMISSION & CONDITIONS
Permission is hereby granted, free of charge, to any person obtaining
a copy of the Font Software, to use, study, copy, merge, embed, modify,
redistribute, and sell modified and unmodified copies of the Font
Software, subject to the following conditions:
1) Neither the Font Software nor any of its individual components,
in Original or Modified Versions, may be sold by itself.
2) Original or Modified Versions of the Font Software may be bundled,
redistributed and/or sold with any software, provided that each copy
contains the above copyright notice and this license. These can be
included either as stand-alone text files, human-readable headers or
in the appropriate machine-readable metadata fields within text or
binary files as long as those fields can be easily viewed by the user.
3) No Modified Version of the Font Software may use the Reserved Font
Name(s) unless explicit written permission is granted by the corresponding
Copyright Holder. This restriction only applies to the primary font name as
presented to the users.
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
Software shall not be used to promote, endorse or advertise any
Modified Version, except to acknowledge the contribution(s) of the
Copyright Holder(s) and the Author(s) or with their explicit written
permission.
5) The Font Software, modified or unmodified, in part or in whole,
must be distributed entirely under this license, and must not be
distributed under any other license. The requirement for fonts to
remain under this license does not apply to any document created
using the Font Software.
TERMINATION
This license becomes null and void if any of the above conditions are
not met.
DISCLAIMER
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
OTHER DEALINGS IN THE FONT SOFTWARE.
Binary file not shown.
Binary file not shown.
+93
View File
@@ -0,0 +1,93 @@
Copyright 2020 The JetBrains Mono Project Authors (https://github.com/JetBrains/JetBrainsMono)
This Font Software is licensed under the SIL Open Font License, Version 1.1.
This license is copied below, and is also available with a FAQ at:
https://scripts.sil.org/OFL
-----------------------------------------------------------
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
-----------------------------------------------------------
PREAMBLE
The goals of the Open Font License (OFL) are to stimulate worldwide
development of collaborative font projects, to support the font creation
efforts of academic and linguistic communities, and to provide a free and
open framework in which fonts may be shared and improved in partnership
with others.
The OFL allows the licensed fonts to be used, studied, modified and
redistributed freely as long as they are not sold by themselves. The
fonts, including any derivative works, can be bundled, embedded,
redistributed and/or sold with any software provided that any reserved
names are not used by derivative works. The fonts and derivatives,
however, cannot be released under any other type of license. The
requirement for fonts to remain under this license does not apply
to any document created using the fonts or their derivatives.
DEFINITIONS
"Font Software" refers to the set of files released by the Copyright
Holder(s) under this license and clearly marked as such. This may
include source files, build scripts and documentation.
"Reserved Font Name" refers to any names specified as such after the
copyright statement(s).
"Original Version" refers to the collection of Font Software components as
distributed by the Copyright Holder(s).
"Modified Version" refers to any derivative made by adding to, deleting,
or substituting -- in part or in whole -- any of the components of the
Original Version, by changing formats or by porting the Font Software to a
new environment.
"Author" refers to any designer, engineer, programmer, technical
writer or other person who contributed to the Font Software.
PERMISSION & CONDITIONS
Permission is hereby granted, free of charge, to any person obtaining
a copy of the Font Software, to use, study, copy, merge, embed, modify,
redistribute, and sell modified and unmodified copies of the Font
Software, subject to the following conditions:
1) Neither the Font Software nor any of its individual components,
in Original or Modified Versions, may be sold by itself.
2) Original or Modified Versions of the Font Software may be bundled,
redistributed and/or sold with any software, provided that each copy
contains the above copyright notice and this license. These can be
included either as stand-alone text files, human-readable headers or
in the appropriate machine-readable metadata fields within text or
binary files as long as those fields can be easily viewed by the user.
3) No Modified Version of the Font Software may use the Reserved Font
Name(s) unless explicit written permission is granted by the corresponding
Copyright Holder. This restriction only applies to the primary font name as
presented to the users.
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
Software shall not be used to promote, endorse or advertise any
Modified Version, except to acknowledge the contribution(s) of the
Copyright Holder(s) and the Author(s) or with their explicit written
permission.
5) The Font Software, modified or unmodified, in part or in whole,
must be distributed entirely under this license, and must not be
distributed under any other license. The requirement for fonts to
remain under this license does not apply to any document created
using the Font Software.
TERMINATION
This license becomes null and void if any of the above conditions are
not met.
DISCLAIMER
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
OTHER DEALINGS IN THE FONT SOFTWARE.
Binary file not shown.
BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 206 KiB

After

Width:  |  Height:  |  Size: 38 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 885 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 885 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 16 KiB

After

Width:  |  Height:  |  Size: 10 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 606 B

After

Width:  |  Height:  |  Size: 655 B

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.0 KiB

After

Width:  |  Height:  |  Size: 1.1 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 56 KiB

After

Width:  |  Height:  |  Size: 21 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.5 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 2.8 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 206 KiB

After

Width:  |  Height:  |  Size: 38 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.9 KiB

After

Width:  |  Height:  |  Size: 4.1 KiB

Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+1
View File
File diff suppressed because one or more lines are too long
@@ -0,0 +1,95 @@
# Markdown Converter — Brand Assets
Visual identity for [markdown-converter](https://github.com/amitwh/markdown-converter): a cross-platform Markdown editor & document converter powered by Pandoc.
## Concept
The mark is a stylized **M** whose right descender becomes a downward chevron — a literal "**M↓**" for **Markdown**, suggesting the source document flowing downward into rendered output (PDF, DOCX, PPTX, …).
The palette is a vibrant orange-to-deep-orange gradient (`#FB923C → #C2410C`) on a white mark — warm, energetic, distinctive. The mark itself is **white** on light surfaces, and a luminous peach-to-orange gradient (`#FFEDD5 → #FB923C`) on dark surfaces.
## Files
### App icon (vector, primary)
These are **true SVG app icons** — clean vector paths, no rasters. Drop them straight into a macOS/Windows/Linux app bundle, a PWA manifest, an iOS asset catalog, an Electron build, or any HTML page.
| File | Use it for |
| --- | --- |
| `app-icon.svg` | **Primary app icon.** Emerald→teal vertical gradient, subtle white highlight upper-left, white M↓ mark. |
| `app-icon-dark.svg` | **Dark-mode app icon.** Charcoal gradient background, soft teal radial glow upper-left, mint-to-emerald gradient on the M↓ mark. |
| `app-icon-flat.svg` | **Flat solid variant.** Single emerald background, white M↓ mark. Use when you can't render gradients (print, stickers, single-color contexts). |
### Logo (wordmark)
| File | Use it for |
| --- | --- |
| `logo-horizontal.jpg` (2752×1536) | High-res raster master. README hero, press kit. |
| `logo-horizontal-1600w.jpg` (1600×893) | Web-ready compressed version. |
| `logo-horizontal.svg` | Vector wordmark. Use in HTML, CSS, anywhere that needs to scale. |
### Vector mark (for code & inline use)
| File | Use it for |
| --- | --- |
| `mark.svg` | Gradient SVG mark. Drop into HTML, use as a UI element, or rasterize at any size. |
| `mark-mono.svg` | Monochrome SVG. Uses `currentColor` — style it from CSS (`color: white;`) for any single-color context. |
| `mark-standalone.jpg` (2048×2048) | Raster M↓ on white, for places that need a PNG (GitHub avatar, doc thumbnails). |
### Favicons (rasterized from `app-icon.svg`)
In the `favicons/` directory:
| File | Use it for |
| --- | --- |
| `favicon.ico` | Legacy `.ico` (16/32/48/64 embedded). Drop at the site root. |
| `favicon-16x16.png`, `favicon-32x32.png`, `favicon-48x48.png` | Standard browser favicons. |
| `apple-touch-icon.png` (180×180) | iOS home screen & "Add to Home Screen". |
| `icon-192.png`, `icon-512.png` | Android home screen, PWA manifest, web app. |
### Social preview
| File | Use it for |
| --- | --- |
| `og-social-preview-1200x630.jpg` | **GitHub social preview** — set as the repository's social card image (Settings → Social preview). Also works as Open Graph / Twitter Card. |
## Usage in the repo
Drop the vector icons + favicon set into the repo root or a `/brand` folder, then in `README.md`:
```markdown
<p align="left">
<img src="./brand/app-icon.svg" width="80" alt="Markdown Converter">
</p>
```
For the favicon, in `index.html` (or any HTML site):
```html
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="icon" type="image/png" sizes="32x32" href="/favicon-32x32.png">
<link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png">
```
For an Electron app, point `build.icon` at the SVG (or a 512×512 PNG export):
```json
{
"build": {
"icon": "brand/icon-512.png"
}
}
```
## Color tokens
```
--mc-orange-400: #FB923C /* gradient start (light) */
--mc-orange-700: #C2410C /* gradient end (light) */
--mc-orange-500: #F97316 /* flat / accent */
--mc-peach-100: #FFEDD5 /* dark-mode mark start */
--mc-orange-300: #FDBA74 /* dark-mode mark mid */
--mc-ink-900: #0F172A /* primary text */
--mc-ink-500: #475569 /* secondary text */
--mc-ink-400: #94A3B8 /* tagline / muted */
```
@@ -0,0 +1,27 @@
<?xml version="1.0" encoding="UTF-8"?>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1024 1024" role="img" aria-label="Markdown Converter app icon (dark)">
<title>Markdown Converter (dark)</title>
<defs>
<linearGradient id="darkBg" x1="0" y1="0" x2="0" y2="1024" gradientUnits="userSpaceOnUse">
<stop offset="0%" stop-color="#1C1917"/>
<stop offset="100%" stop-color="#0C0A09"/>
</linearGradient>
<radialGradient id="darkGlow" cx="280" cy="180" r="780" gradientUnits="userSpaceOnUse">
<stop offset="0%" stop-color="#EA580C" stop-opacity="0.65"/>
<stop offset="60%" stop-color="#9A3412" stop-opacity="0.15"/>
<stop offset="100%" stop-color="#9A3412" stop-opacity="0"/>
</radialGradient>
<linearGradient id="darkMark" x1="0" y1="180" x2="0" y2="844" gradientUnits="userSpaceOnUse">
<stop offset="0%" stop-color="#FFEDD5"/>
<stop offset="100%" stop-color="#FB923C"/>
</linearGradient>
</defs>
<rect width="1024" height="1024" rx="224" ry="224" fill="url(#darkBg)"/>
<rect width="1024" height="1024" rx="224" ry="224" fill="url(#darkGlow)"/>
<g transform="translate(154, 176) scale(7.16)" fill="none" stroke="url(#darkMark)" stroke-width="9" stroke-linecap="round" stroke-linejoin="round">
<line x1="26" y1="22" x2="26" y2="72"/>
<line x1="63" y1="22" x2="63" y2="75"/>
<polyline points="22,18 44.5,56 67,18"/>
<polyline points="48,60 63,76 78,60"/>
</g>
</svg>

After

Width:  |  Height:  |  Size: 1.4 KiB

@@ -0,0 +1,11 @@
<?xml version="1.0" encoding="UTF-8"?>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1024 1024" role="img" aria-label="Markdown Converter app icon (flat)">
<title>Markdown Converter (flat)</title>
<rect width="1024" height="1024" rx="224" ry="224" fill="#F97316"/>
<g transform="translate(154, 176) scale(7.16)" fill="none" stroke="#FFFFFF" stroke-width="9" stroke-linecap="round" stroke-linejoin="round">
<line x1="26" y1="22" x2="26" y2="72"/>
<line x1="63" y1="22" x2="63" y2="75"/>
<polyline points="22,18 44.5,56 67,18"/>
<polyline points="48,60 63,76 78,60"/>
</g>
</svg>

After

Width:  |  Height:  |  Size: 609 B

@@ -0,0 +1,22 @@
<?xml version="1.0" encoding="UTF-8"?>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1024 1024" role="img" aria-label="Markdown Converter app icon">
<title>Markdown Converter</title>
<defs>
<linearGradient id="iconBg" x1="0" y1="0" x2="0" y2="1">
<stop offset="0%" stop-color="#FB923C"/>
<stop offset="100%" stop-color="#C2410C"/>
</linearGradient>
<radialGradient id="iconHighlight" cx="0.28" cy="0.18" r="0.55">
<stop offset="0%" stop-color="#FFFFFF" stop-opacity="0.28"/>
<stop offset="60%" stop-color="#FFFFFF" stop-opacity="0"/>
</radialGradient>
</defs>
<rect width="1024" height="1024" rx="224" ry="224" fill="url(#iconBg)"/>
<rect width="1024" height="1024" rx="224" ry="224" fill="url(#iconHighlight)"/>
<g transform="translate(154, 176) scale(7.16)" fill="none" stroke="#FFFFFF" stroke-width="9" stroke-linecap="round" stroke-linejoin="round">
<line x1="26" y1="22" x2="26" y2="72"/>
<line x1="63" y1="22" x2="63" y2="75"/>
<polyline points="22,18 44.5,56 67,18"/>
<polyline points="48,60 63,76 78,60"/>
</g>
</svg>

After

Width:  |  Height:  |  Size: 1.1 KiB

Some files were not shown because too many files have changed in this diff Show More