mirror of
https://github.com/amitwh/markdown-converter.git
synced 2026-10-01 17:29:29 +05:30
Compare commits
176
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
efca458495 | ||
|
|
c4dcbd8caf | ||
|
|
b83ba91731 | ||
|
|
0babf97f0e | ||
|
|
eeda3f28eb | ||
|
|
4c00406bcd | ||
|
|
363de75375 | ||
|
|
2e16868f59 | ||
|
|
dd6d97c35d | ||
|
|
0604c65683 | ||
|
|
c43caf3902 | ||
|
|
25dcaaa816 | ||
|
|
c6ec1cef64 | ||
|
|
5fcc282fe0 | ||
|
|
8a95144bf3 | ||
|
|
bc47316746 | ||
|
|
02ce06d364 | ||
|
|
2e3af826f7 | ||
|
|
758dcb4166 | ||
|
|
1f5db511ba | ||
|
|
63c35ef2dc | ||
|
|
c8883e77fe | ||
|
|
8a28c21512 | ||
|
|
d6baa2daf7 | ||
|
|
44624cd4bf | ||
|
|
2334ab30ed | ||
|
|
abcfb03e52 | ||
|
|
6ba3174480 | ||
|
|
b83b86b31e | ||
|
|
f271e27177 | ||
|
|
8dc1ae1c45 | ||
|
|
a353a695b5 | ||
|
|
174eb3d6e9 | ||
|
|
8bada008b3 | ||
|
|
949053a7c5 | ||
|
|
b80e34fcf5 | ||
|
|
11b1c9e13e | ||
|
|
e09853952b | ||
|
|
d43fbaea59 | ||
|
|
66938968db | ||
|
|
5d9c46afc3 | ||
|
|
bf3438902b | ||
|
|
edb5db358a | ||
|
|
6d564261b2 | ||
|
|
f5dcffeb8d | ||
|
|
7095b34280 | ||
|
|
58868eece0 | ||
|
|
cd3385ec69 | ||
|
|
f04a20252f | ||
|
|
e5e14c88ce | ||
|
|
7a5a2ecba6 | ||
|
|
fac0d3d4a6 | ||
|
|
269d4ac028 | ||
|
|
cdc318ebc7 | ||
|
|
0c4043121f | ||
|
|
151be60b03 | ||
|
|
228ee04b09 | ||
|
|
9fd81ff5a0 | ||
|
|
f22cacd554 | ||
|
|
2f3b552608 | ||
|
|
cb27b47b91 | ||
|
|
01e2df44ed | ||
|
|
adfa43c278 | ||
|
|
879600da46 | ||
|
|
7b73ab07d7 | ||
|
|
57bbf91245 | ||
|
|
5178d91187 | ||
|
|
3f0bf911a0 | ||
|
|
2cac075c0e | ||
|
|
94906a068a | ||
|
|
e72b863362 | ||
|
|
d705cfc30b | ||
|
|
02e307f758 | ||
|
|
5ad1d1d4b3 | ||
|
|
f480449301 | ||
|
|
96df5652d6 | ||
|
|
a9e05d2c0f | ||
|
|
c982b3e90f | ||
|
|
cfaafc07b2 | ||
|
|
94ad99dc4d | ||
|
|
baf644d62b | ||
|
|
f9a5420ad2 | ||
|
|
f8361174f2 | ||
|
|
64df0660c8 | ||
|
|
bbfa2a38e9 | ||
|
|
94ec3f45ce | ||
|
|
a6747b12f0 | ||
|
|
7a641b2618 | ||
|
|
edefcb8409 | ||
|
|
5ee986fab8 | ||
|
|
c1573dba08 | ||
|
|
9576abc979 | ||
|
|
caa3f3d35a | ||
|
|
2a6f0fc302 | ||
|
|
4da5b7b9c4 | ||
|
|
1ba42592d7 | ||
|
|
bc6f1a7d41 | ||
|
|
539502d7ff | ||
|
|
b5771dd914 | ||
|
|
a816b6ec32 | ||
|
|
54c9484cb5 | ||
|
|
36e26318cd | ||
|
|
8abd580295 | ||
|
|
80294c9876 | ||
|
|
148b549c83 | ||
|
|
a3b4065984 | ||
|
|
620227307d | ||
|
|
4426b75c6f | ||
|
|
b7e12f7010 | ||
|
|
f0ab54cd60 | ||
|
|
72a7a854d0 | ||
|
|
50d0638c5c | ||
|
|
7a3493e54f | ||
|
|
b1a5784bcc | ||
|
|
24cb99658e | ||
|
|
c042cf4580 | ||
|
|
ed4279f4df | ||
|
|
adc8dabda1 | ||
|
|
5911a7501b | ||
|
|
d998b03ca1 | ||
|
|
31468e77c5 | ||
|
|
2022352ed1 | ||
|
|
6bac18d270 | ||
|
|
fdfd778d94 | ||
|
|
30f6198f1d | ||
|
|
253608e17f | ||
|
|
763bea2a87 | ||
|
|
73795d1ad8 | ||
|
|
f81426f019 | ||
|
|
fe4d634163 | ||
|
|
3bc703d8dc | ||
|
|
78200b8d6a | ||
|
|
0987058aa2 | ||
|
|
cbf0b4897d | ||
|
|
f1740c6bb6 | ||
|
|
8319953ccf | ||
|
|
95ea870039 | ||
|
|
d1c2c1c109 | ||
|
|
daae83bcf4 | ||
|
|
7723b302ea | ||
|
|
94506ccb00 | ||
|
|
01d833f520 | ||
|
|
10d2fc8b8f | ||
|
|
0344a48f20 | ||
|
|
3c11ac15ce | ||
|
|
c5a9881d8d | ||
|
|
15903e782a | ||
|
|
336b24365d | ||
|
|
b5409b7754 | ||
|
|
d3afd7ad86 | ||
|
|
59ef2028f8 | ||
|
|
f62a6b7e59 | ||
|
|
f650b04685 | ||
|
|
04480c1243 | ||
|
|
81a78412fd | ||
|
|
12dcd2d1a3 | ||
|
|
ae7b333cea | ||
|
|
e2703d8c57 | ||
|
|
ca0b250506 | ||
|
|
9348b2bd1d | ||
|
|
200e800eb2 | ||
|
|
a6456a7b4c | ||
|
|
3908df8b1d | ||
|
|
72ee803a95 | ||
|
|
37502fb733 | ||
|
|
affe1a7e33 | ||
|
|
ed48f254f1 | ||
|
|
0c2b6fe5cc | ||
|
|
233225f12c | ||
|
|
47f3b7557e | ||
|
|
7678c61602 | ||
|
|
6e7460def7 | ||
|
|
bf67156b9c | ||
|
|
824f659e13 | ||
|
|
e7eff01db6 | ||
|
|
7b15b2808e |
@@ -0,0 +1,28 @@
|
|||||||
|
name: CI
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [master]
|
||||||
|
pull_request:
|
||||||
|
branches: [master]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Setup Node.js
|
||||||
|
uses: actions/setup-node@v4
|
||||||
|
with:
|
||||||
|
node-version: 20
|
||||||
|
cache: npm
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: npm ci
|
||||||
|
|
||||||
|
- name: Run tests
|
||||||
|
run: npm test
|
||||||
|
|
||||||
|
- name: Run linter
|
||||||
|
run: npm run lint
|
||||||
@@ -0,0 +1,122 @@
|
|||||||
|
name: Release
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
tags: ['v*']
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build-linux:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Setup Node.js
|
||||||
|
uses: actions/setup-node@v4
|
||||||
|
with:
|
||||||
|
node-version: 20
|
||||||
|
cache: npm
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: npm ci
|
||||||
|
|
||||||
|
- name: Download external tools (pandoc)
|
||||||
|
run: node scripts/download-tools.js
|
||||||
|
|
||||||
|
- name: Run tests
|
||||||
|
run: npm test
|
||||||
|
|
||||||
|
- name: Build Linux packages
|
||||||
|
run: npm run build:linux-ci -- --publish=never
|
||||||
|
|
||||||
|
- name: Upload Linux artifacts
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: linux-artifacts
|
||||||
|
path: |
|
||||||
|
dist/*.deb
|
||||||
|
dist/*.AppImage
|
||||||
|
dist/*.snap
|
||||||
|
dist/*.rpm
|
||||||
|
retention-days: 5
|
||||||
|
|
||||||
|
build-windows:
|
||||||
|
runs-on: windows-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Setup Node.js
|
||||||
|
uses: actions/setup-node@v4
|
||||||
|
with:
|
||||||
|
node-version: 20
|
||||||
|
cache: npm
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: npm ci
|
||||||
|
|
||||||
|
- name: Download external tools (pandoc)
|
||||||
|
run: node scripts/download-tools.js
|
||||||
|
|
||||||
|
- name: Run tests
|
||||||
|
run: npm test
|
||||||
|
|
||||||
|
- name: Decode certificate (if available)
|
||||||
|
if: ${{ env.CSC_LINK_BASE64 != '' }}
|
||||||
|
shell: pwsh
|
||||||
|
env:
|
||||||
|
CSC_LINK_BASE64: ${{ secrets.CSC_LINK_BASE64 }}
|
||||||
|
run: |
|
||||||
|
$bytes = [Convert]::FromBase64String("$env:CSC_LINK_BASE64")
|
||||||
|
[IO.File]::WriteAllBytes("${{ github.workspace }}\code-signing-cert.pfx", $bytes)
|
||||||
|
echo "CERT_AVAILABLE=true" >> $env:GITHUB_ENV
|
||||||
|
|
||||||
|
- name: Build Windows packages (signed)
|
||||||
|
if: ${{ env.CERT_AVAILABLE == 'true' }}
|
||||||
|
env:
|
||||||
|
CSC_LINK: code-signing-cert.pfx
|
||||||
|
CSC_KEY_PASSWORD: ${{ secrets.CSC_KEY_PASSWORD }}
|
||||||
|
run: npm run build:win-signed -- --publish=never
|
||||||
|
|
||||||
|
- name: Build Windows packages (unsigned)
|
||||||
|
if: ${{ env.CERT_AVAILABLE != 'true' }}
|
||||||
|
env:
|
||||||
|
CSC_IDENTITY_AUTO_DISCOVERY: 'false'
|
||||||
|
run: npm run build:win-unsigned -- --publish=never
|
||||||
|
|
||||||
|
- name: Upload Windows artifacts
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: windows-artifacts
|
||||||
|
path: |
|
||||||
|
dist/*.exe
|
||||||
|
dist/*.zip
|
||||||
|
retention-days: 5
|
||||||
|
|
||||||
|
release:
|
||||||
|
needs: [build-linux, build-windows]
|
||||||
|
if: always()
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Download Linux artifacts
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
continue-on-error: true
|
||||||
|
with:
|
||||||
|
name: linux-artifacts
|
||||||
|
path: dist
|
||||||
|
|
||||||
|
- name: Download Windows artifacts
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
continue-on-error: true
|
||||||
|
with:
|
||||||
|
name: windows-artifacts
|
||||||
|
path: dist
|
||||||
|
|
||||||
|
- name: Create GitHub Release
|
||||||
|
uses: softprops/action-gh-release@v2
|
||||||
|
with:
|
||||||
|
generate_release_notes: true
|
||||||
|
files: dist/*
|
||||||
+14
-2
@@ -8,14 +8,22 @@ Thumbs.db
|
|||||||
*.swp
|
*.swp
|
||||||
*.swo
|
*.swo
|
||||||
*~
|
*~
|
||||||
.vscode/
|
.vscode/*
|
||||||
|
!.vscode/launch.json
|
||||||
.idea/
|
.idea/
|
||||||
*.iml
|
*.iml
|
||||||
out/
|
out/
|
||||||
.cache/
|
.cache/
|
||||||
.npm/
|
.npm/
|
||||||
.electron/
|
.electron/
|
||||||
package-lock.json
|
# package-lock.json is intentionally tracked for reproducible CI builds
|
||||||
|
|
||||||
|
# Downloaded tool binaries (fetched at build time via scripts/download-tools.js)
|
||||||
|
bin/
|
||||||
|
|
||||||
|
# Code signing certificates — never commit private keys
|
||||||
|
*.pfx
|
||||||
|
*.p12
|
||||||
|
|
||||||
# Screenshots and temp files
|
# Screenshots and temp files
|
||||||
*.png.bak
|
*.png.bak
|
||||||
@@ -34,3 +42,7 @@ pdf\ modal.png
|
|||||||
.claude/
|
.claude/
|
||||||
CLAUDE.md
|
CLAUDE.md
|
||||||
agents.md
|
agents.md
|
||||||
|
coverage/
|
||||||
|
|
||||||
|
# Superpowers brainstorm artifacts
|
||||||
|
.superpowers/
|
||||||
|
|||||||
@@ -0,0 +1,469 @@
|
|||||||
|
# Security Assessment Report: MarkdownConverter v4.0.0
|
||||||
|
|
||||||
|
**Assessment Date:** 2026-03-15
|
||||||
|
**Application:** MarkdownConverter - Electron-based Markdown editor and document converter
|
||||||
|
**Target Version:** 4.0.0
|
||||||
|
**Assessor:** Security Audit Agent
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Executive Summary
|
||||||
|
|
||||||
|
This assessment identified **10 security findings** ranging from **Critical to Low severity**. The most significant concerns involve insecure Electron security configuration that could allow XSS attacks to escalate to full system access, arbitrary code execution via the REPL feature, and missing input validation on file operations.
|
||||||
|
|
||||||
|
| Severity | Count |
|
||||||
|
|----------|-------|
|
||||||
|
| Critical | 2 |
|
||||||
|
| High | 3 |
|
||||||
|
| Medium | 3 |
|
||||||
|
| Low | 2 |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Vulnerability Findings
|
||||||
|
|
||||||
|
### CVE-MC-001: Insecure Electron Security Configuration (Critical)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 9.6 (Critical)**
|
||||||
|
**CWE-265: CWE-1021: Improper Restriction of Renderers**
|
||||||
|
|
||||||
|
**Location:** `src/main.js` (lines 328-332)
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: true,
|
||||||
|
contextIsolation: false,
|
||||||
|
spellcheck: true
|
||||||
|
},
|
||||||
|
```
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
The main application window has `nodeIntegration: true` and `contextIsolation: false`, which is the most insecure Electron configuration. This allows the renderer process direct access to Node.js APIs, meaning any XSS vulnerability in the markdown rendering or external content could lead to full system compromise.
|
||||||
|
|
||||||
|
**Exploitability:**
|
||||||
|
- An attacker who can inject malicious JavaScript (via markdown files, XSS in preview, or compromised dependencies) gains immediate access to:
|
||||||
|
- Full file system read/write via `fs` module
|
||||||
|
- Command execution via `child_process`
|
||||||
|
- Network access via `net` module
|
||||||
|
- All system resources
|
||||||
|
|
||||||
|
**Attack Scenario:**
|
||||||
|
1. User opens a malicious markdown file containing embedded JavaScript
|
||||||
|
2. The JavaScript executes in the renderer with full Node.js access
|
||||||
|
3. Attacker can read sensitive files, execute commands, exfiltrate data
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
```javascript
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: false,
|
||||||
|
contextIsolation: true,
|
||||||
|
sandbox: true,
|
||||||
|
preload: path.join(__dirname, 'preload.js')
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Note:** The preload.js file already implements a secure IPC bridge but it is not being utilized for the main window.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-002: Arbitrary Code Execution via REPL Feature (Critical)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 9.3 (Critical)**
|
||||||
|
**CWE-94: Improper Control of Generation of Code ('Code Injection')**
|
||||||
|
|
||||||
|
**Location:** `src/main.js` (lines 4369-4396)
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
The `execute-code` IPC handler allows execution of arbitrary Python and Bash scripts through the REPL panel. While JavaScript execution appears to have been removed or limited, Python and Bash commands are executed via `execFile` with user-supplied code.
|
||||||
|
|
||||||
|
**Vulnerable Code Pattern:**
|
||||||
|
```javascript
|
||||||
|
ipcMain.handle('execute-code', async (event, { code, language }) => {
|
||||||
|
// ...
|
||||||
|
if (language === 'python' || language === 'py') {
|
||||||
|
cmd = 'python';
|
||||||
|
args = ['-c', code];
|
||||||
|
}
|
||||||
|
// ...
|
||||||
|
execFile(cmd, args, { timeout }, (err, stdout, stderr) => {
|
||||||
|
// ...
|
||||||
|
});
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
**Exploitability:**
|
||||||
|
- Users can be tricked into running malicious code blocks
|
||||||
|
- Markdown files can contain executable code blocks with "Run" buttons
|
||||||
|
- No sandboxing or permission restrictions on executed code
|
||||||
|
|
||||||
|
**Attack Scenario:**
|
||||||
|
1. Attacker creates markdown file with malicious Python code block
|
||||||
|
2. User clicks "Run" button in preview
|
||||||
|
3. Python code executes with user's full permissions
|
||||||
|
4. Attacker gains code execution on victim's machine
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
- Remove arbitrary code execution feature entirely, OR
|
||||||
|
- Implement strict sandboxing (Docker, VM, or restricted Python environment)
|
||||||
|
- Add user confirmation dialogs with clear warnings
|
||||||
|
- Execute in isolated environment with no filesystem/network access
|
||||||
|
- Implement allowlist of safe operations
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-003: Potential XSS in Markdown Rendering (High)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 8.0 (High)**
|
||||||
|
**CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')**
|
||||||
|
|
||||||
|
**Location:** `src/renderer.js` (lines 387-419)
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
While DOMPurify is used to sanitize HTML, several extensions to marked.js may bypass sanitization:
|
||||||
|
|
||||||
|
1. **Custom Admonition Extension (lines 51-77):**
|
||||||
|
```javascript
|
||||||
|
marked.use({
|
||||||
|
extensions: [{
|
||||||
|
name: 'admonition',
|
||||||
|
// ...
|
||||||
|
renderer(token) {
|
||||||
|
const inner = this.parser.parse(token.text);
|
||||||
|
return `<div class="admonition admonition-${token.admonitionType}">
|
||||||
|
<div class="admonition-title">${icon} ${token.admonitionType...}</div>
|
||||||
|
<div class="admonition-content">${inner}</div>
|
||||||
|
</div>`;
|
||||||
|
}
|
||||||
|
}]
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
2. **innerHTML Assignments (line 419):**
|
||||||
|
```javascript
|
||||||
|
preview.innerHTML = sanitizedHtml;
|
||||||
|
```
|
||||||
|
|
||||||
|
**Exploitability:**
|
||||||
|
- Combined with CVE-MC-001, XSS leads to full system compromise
|
||||||
|
- Custom markdown extensions may not be properly sanitized
|
||||||
|
- Admonition type is directly interpolated into HTML without escaping
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
- Ensure all custom markdown extensions escape user input
|
||||||
|
- Add Content Security Policy that blocks inline scripts
|
||||||
|
- Use `textContent` instead of `innerHTML` where possible
|
||||||
|
- Audit all custom marked.js extensions for XSS vectors
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-004: Missing Path Traversal Protection (High)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 7.8 (High)**
|
||||||
|
**CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')**
|
||||||
|
|
||||||
|
**Location:** `src/main.js` (lines 4241-4281)
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
The `list-directory` and `open-file-path` IPC handlers accept arbitrary file paths without validation:
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
ipcMain.handle('list-directory', async (event, dirPath) => {
|
||||||
|
try {
|
||||||
|
if (!dirPath) { /* dialog */ }
|
||||||
|
// No path validation - accepts any path
|
||||||
|
const entries = fs.readdirSync(dirPath, { withFileTypes: true });
|
||||||
|
// ...
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
ipcMain.on('open-file-path', (event, filePath) => {
|
||||||
|
// No path validation
|
||||||
|
if (!fs.existsSync(filePath)) return;
|
||||||
|
const content = fs.readFileSync(filePath, 'utf-8');
|
||||||
|
mainWindow.webContents.send('file-opened', { path: filePath, content });
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
**Exploitability:**
|
||||||
|
- Malicious renderer code can read any file on the system
|
||||||
|
- No restriction to a sandbox directory
|
||||||
|
- Combined with XSS, attacker can exfiltrate sensitive files
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
```javascript
|
||||||
|
const ALLOWED_DIRECTORIES = [app.getPath('documents'), app.getPath('desktop')];
|
||||||
|
|
||||||
|
function isPathAllowed(filePath) {
|
||||||
|
const resolved = path.resolve(filePath);
|
||||||
|
return ALLOWED_DIRECTORIES.some(dir => resolved.startsWith(dir));
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-005: Weak Content Security Policy (High)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 7.5 (High)**
|
||||||
|
**CWE-1021: Improper Restriction of Renderers**
|
||||||
|
|
||||||
|
**Location:** `src/index.html` (line 5)
|
||||||
|
|
||||||
|
```html
|
||||||
|
<meta http-equiv="Content-Security-Policy" content="default-src 'self';
|
||||||
|
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net;
|
||||||
|
style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com;
|
||||||
|
img-src 'self' data: blob: file:;
|
||||||
|
font-src 'self' data:;
|
||||||
|
connect-src 'self' https://www.plantuml.com;">
|
||||||
|
```
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
The CSP contains several security weaknesses:
|
||||||
|
|
||||||
|
1. **`'unsafe-inline'` in script-src** - Allows inline script injection
|
||||||
|
2. **`'unsafe-eval'` in script-src** - Allows `eval()` and similar functions
|
||||||
|
3. **`https://cdn.jsdelivr.net`** - Allows scripts from external CDN (supply chain risk)
|
||||||
|
4. **`file:` in img-src** - Allows loading local files as images (potential information disclosure)
|
||||||
|
|
||||||
|
**Exploitability:**
|
||||||
|
- XSS attacks can execute arbitrary scripts
|
||||||
|
- External CDN compromise could inject malicious code
|
||||||
|
- `eval()` enables dynamic code execution
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
- Remove `'unsafe-inline'` and `'unsafe-eval'`
|
||||||
|
- Use nonces or hashes for inline scripts
|
||||||
|
- Remove external CDNs or use Subresource Integrity (SRI)
|
||||||
|
- Remove `file:` from img-src
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-006: Insecure Window Configuration for PDF Export (Medium)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 6.5 (Medium)**
|
||||||
|
**CWE-1021: Improper Restriction of Renderers**
|
||||||
|
|
||||||
|
**Location:** `src/main.js` (lines 2579-2585)
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
const pdfWindow = new BrowserWindow({
|
||||||
|
show: false,
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: true,
|
||||||
|
contextIsolation: false
|
||||||
|
}
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
Hidden windows created for PDF export also have insecure configurations, allowing potential privilege escalation.
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
```javascript
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: false,
|
||||||
|
contextIsolation: true,
|
||||||
|
sandbox: true
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-007: PlantUML Server Data Exfiltration (Medium)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 5.3 (Medium)**
|
||||||
|
**CWE-359: Exposure of Private Information**
|
||||||
|
|
||||||
|
**Location:** `src/renderer.js` (lines 470-487)
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
const plantumlBlocks = preview.querySelectorAll('pre code.language-plantuml');
|
||||||
|
plantumlBlocks.forEach((block) => {
|
||||||
|
const code = block.textContent;
|
||||||
|
// ...
|
||||||
|
const encoded = plantumlEncode(code);
|
||||||
|
const img = document.createElement('img');
|
||||||
|
img.src = `https://www.plantuml.com/plantuml/svg/${encoded}`;
|
||||||
|
// ...
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
PlantUML diagram content is sent to an external server (plantuml.com) for rendering. This could leak sensitive information contained in diagrams.
|
||||||
|
|
||||||
|
**Exploitability:**
|
||||||
|
- Diagrams containing proprietary information, system architecture, or internal processes are sent to third-party servers
|
||||||
|
- No user consent or notification before external data transmission
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
- Use local PlantUML rendering with Java
|
||||||
|
- Add user warning before sending data to external service
|
||||||
|
- Implement opt-in for external rendering
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-008: Inconsistent Security Settings Across Windows (Medium)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 5.5 (Medium)**
|
||||||
|
**CWE-1021: Improper Restriction of Renderers**
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
Security settings are inconsistent across different windows:
|
||||||
|
|
||||||
|
| Window | nodeIntegration | contextIsolation | Security |
|
||||||
|
|--------|-----------------|------------------|----------|
|
||||||
|
| Main Window | true | false | Insecure |
|
||||||
|
| About Dialog | false | true | Secure |
|
||||||
|
| Dependencies Dialog | false | true | Secure |
|
||||||
|
| ASCII Generator | false | true | Secure |
|
||||||
|
| Table Generator | false | true | Secure |
|
||||||
|
| PDF Export Window | true | false | Insecure |
|
||||||
|
| Hidden Conversion Window | true | false | Insecure |
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
Apply secure configuration (`nodeIntegration: false`, `contextIsolation: true`) consistently across all windows.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-009: Command Execution via External Tools (Low)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 4.4 (Low)**
|
||||||
|
**CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')**
|
||||||
|
|
||||||
|
**Location:** `src/main.js` (lines 1915-1972)
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
While the application uses `execFile` instead of `exec` (good practice), external tools (Pandoc, LibreOffice, FFmpeg, ImageMagick) are invoked with file paths that could potentially be manipulated.
|
||||||
|
|
||||||
|
**Positive Finding:**
|
||||||
|
The code correctly uses `execFile` with argument arrays instead of shell commands, mitigating most command injection vectors.
|
||||||
|
|
||||||
|
**Remaining Risk:**
|
||||||
|
- File paths are not validated against malicious names
|
||||||
|
- Special characters in filenames could cause issues with external tools
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
- Validate file paths before passing to external tools
|
||||||
|
- Sanitize filenames of special characters
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CVE-MC-010: Missing Dependency Version Pinning (Low)
|
||||||
|
|
||||||
|
**CVSS 3.1 Score: 3.5 (Low)**
|
||||||
|
**CWE-1035: Using Components with Known Vulnerabilities**
|
||||||
|
|
||||||
|
**Location:** `package.json`
|
||||||
|
|
||||||
|
**Description:**
|
||||||
|
Dependencies use `^` version ranges which could allow automatic updates to versions with vulnerabilities:
|
||||||
|
|
||||||
|
```json
|
||||||
|
"dependencies": {
|
||||||
|
"marked": "^17.0.3",
|
||||||
|
"dompurify": "^3.3.1",
|
||||||
|
"mermaid": "^11.12.3",
|
||||||
|
// ...
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Remediation:**
|
||||||
|
- Pin exact versions in production
|
||||||
|
- Use lockfile (package-lock.json)
|
||||||
|
- Implement dependency scanning in CI/CD pipeline
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Attack Surface Map
|
||||||
|
|
||||||
|
```
|
||||||
|
┌─────────────────────────────────────────────────────────────────┐
|
||||||
|
│ EXTERNAL ATTACK SURFACE │
|
||||||
|
├─────────────────────────────────────────────────────────────────┤
|
||||||
|
│ Markdown Files (.md) ─────► XSS via Preview Rendering │
|
||||||
|
│ Code Blocks ─────► Arbitrary Code Execution │
|
||||||
|
│ PlantUML Diagrams ─────► Data Exfiltration │
|
||||||
|
│ External CDNs ─────► Supply Chain Attacks │
|
||||||
|
└─────────────────────────────────────────────────────────────────┘
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
┌─────────────────────────────────────────────────────────────────┐
|
||||||
|
│ RENDERER PROCESS (Insecure) │
|
||||||
|
├─────────────────────────────────────────────────────────────────┤
|
||||||
|
│ nodeIntegration: true ─────► Direct Node.js Access │
|
||||||
|
│ contextIsolation: false ─────► Prototype Pollution Risk │
|
||||||
|
│ DOMPurify Sanitization ─────► May be bypassed via extensions │
|
||||||
|
│ Custom Marked Extensions ────► XSS Vectors │
|
||||||
|
└─────────────────────────────────────────────────────────────────┘
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
┌─────────────────────────────────────────────────────────────────┐
|
||||||
|
│ IPC BRIDGE (Preload.js) │
|
||||||
|
├─────────────────────────────────────────────────────────────────┤
|
||||||
|
│ Channel Whitelisting ─────► Good Practice │
|
||||||
|
│ Not Used for Main Window ────► Security Bypassed │
|
||||||
|
└─────────────────────────────────────────────────────────────────┘
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
┌─────────────────────────────────────────────────────────────────┐
|
||||||
|
│ MAIN PROCESS (Full Privileges) │
|
||||||
|
├─────────────────────────────────────────────────────────────────┤
|
||||||
|
│ File Operations ─────► No Path Validation │
|
||||||
|
│ Code Execution ─────► Python/Bash via REPL │
|
||||||
|
│ External Tools ─────► Pandoc, FFmpeg, LibreOffice │
|
||||||
|
│ PDF Operations ─────► Merge, Encrypt, Decrypt │
|
||||||
|
└─────────────────────────────────────────────────────────────────┘
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Positive Security Findings
|
||||||
|
|
||||||
|
1. **Preload.js Implementation:** A secure IPC bridge with channel whitelisting is implemented
|
||||||
|
2. **DOMPurify Usage:** HTML sanitization is applied to markdown output
|
||||||
|
3. **execFile Usage:** External commands use `execFile` instead of `exec`
|
||||||
|
4. **File Size Limits:** 50MB maximum file size is enforced
|
||||||
|
5. **Rate Limiting:** Conversion operations have rate limiting (2 second minimum interval)
|
||||||
|
6. **Error Message Sanitization:** Absolute paths are stripped from error messages
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Prioritized Remediation Roadmap
|
||||||
|
|
||||||
|
### Phase 1 - Critical (Immediate)
|
||||||
|
1. Set `nodeIntegration: false` and `contextIsolation: true` for main window
|
||||||
|
2. Remove or sandbox the code execution (REPL) feature
|
||||||
|
3. Implement proper preload.js usage for all windows
|
||||||
|
|
||||||
|
### Phase 2 - High Priority (1-2 Weeks)
|
||||||
|
4. Add path traversal protection to file operations
|
||||||
|
5. Strengthen Content Security Policy
|
||||||
|
6. Audit and fix custom markdown extensions for XSS
|
||||||
|
|
||||||
|
### Phase 3 - Medium Priority (1 Month)
|
||||||
|
7. Implement consistent security settings across all windows
|
||||||
|
8. Add local PlantUML rendering option
|
||||||
|
9. Implement dependency scanning in CI/CD
|
||||||
|
|
||||||
|
### Phase 4 - Low Priority (Ongoing)
|
||||||
|
10. Pin dependency versions
|
||||||
|
11. Add security headers to all generated HTML
|
||||||
|
12. Implement security logging and monitoring
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Compliance Considerations
|
||||||
|
|
||||||
|
- **OWASP Top 10 2021:** A03:2021 - Injection, A05:2021 - Security Misconfiguration
|
||||||
|
- **OWASP ASVS:** V12 - File Handling, V13 - API Security
|
||||||
|
- **NIST CSF:** PR.AC - Access Control, PR.DS - Data Security
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Conclusion
|
||||||
|
|
||||||
|
The MarkdownConverter application has significant security vulnerabilities that could allow an attacker to execute arbitrary code, access sensitive files, and compromise the user's system. The most critical issue is the insecure Electron configuration combined with XSS attack vectors in the markdown rendering pipeline.
|
||||||
|
|
||||||
|
**Overall Security Rating: HIGH RISK**
|
||||||
|
|
||||||
|
The positive finding is that much of the security infrastructure (preload.js, DOMPurify) is already in place but not properly utilized. With focused remediation effort, the application can achieve a much stronger security posture.
|
||||||
@@ -0,0 +1,215 @@
|
|||||||
|
# STRIDE Threat Model - MarkdownConverter v4.0.0
|
||||||
|
|
||||||
|
**Analysis Date:** 2026-03-15
|
||||||
|
**Methodology:** STRIDE + MITRE ATT&CK
|
||||||
|
**Overall Risk Score:** 7.8 (HIGH)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Executive Summary
|
||||||
|
|
||||||
|
The analysis identified **10 vulnerabilities** with a combined risk score of **7.8 (HIGH)**. The most critical issues enable complete system compromise through XSS-to-RCE attack chains.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Critical Findings
|
||||||
|
|
||||||
|
| Priority | CVE | Vulnerability | CVSS | Impact |
|
||||||
|
|----------|-----|---------------|------|--------|
|
||||||
|
| P0 | CVE-MC-001 | Insecure Electron Config (`nodeIntegration: true`, `contextIsolation: false`) | 9.6 | Complete system compromise |
|
||||||
|
| P0 | CVE-MC-002 | Arbitrary code execution via REPL feature | 9.3 | Remote code execution |
|
||||||
|
| P1 | CVE-MC-003 | XSS in markdown rendering | 8.0 | Session hijacking, RCE chain |
|
||||||
|
| P1 | CVE-MC-004 | Path traversal vulnerability | 7.8 | Arbitrary file write |
|
||||||
|
| P1 | CVE-MC-005 | Weak Content Security Policy | 7.5 | XSS enablement |
|
||||||
|
| P2 | CVE-MC-006 | Insecure window config for PDF export | 6.5 | Privilege escalation |
|
||||||
|
| P2 | CVE-MC-007 | PlantUML server data exfiltration | 5.3 | Information disclosure |
|
||||||
|
| P2 | CVE-MC-008 | Inconsistent security settings | 5.5 | Configuration weakness |
|
||||||
|
| P3 | CVE-MC-009 | Command execution via external tools | 4.4 | Command injection risk |
|
||||||
|
| P3 | CVE-MC-010 | Missing dependency version pinning | 3.5 | Supply chain risk |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Key Attack Vectors
|
||||||
|
|
||||||
|
### 1. XSS to RCE Chain (Critical)
|
||||||
|
```
|
||||||
|
Malicious Markdown File
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
XSS in Preview (CVE-MC-003)
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
nodeIntegration: true (CVE-MC-001)
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
Full Node.js Access
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
Complete System Compromise
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2. REPL Code Execution (Critical)
|
||||||
|
```
|
||||||
|
Code Block in Markdown
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
User clicks "Run"
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
REPL executes Python/Bash (CVE-MC-002)
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
Arbitrary Code Execution
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3. Data Exfiltration (Medium)
|
||||||
|
```
|
||||||
|
PlantUML Diagram Content
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
Sent to www.plantuml.com (CVE-MC-007)
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
Sensitive Architecture Leaked
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## STRIDE Analysis
|
||||||
|
|
||||||
|
### S - Spoofing
|
||||||
|
| ID | Threat | Likelihood | Impact | Risk |
|
||||||
|
|----|--------|------------|--------|------|
|
||||||
|
| S1 | Attacker spoofs markdown file origin | Medium | High | High |
|
||||||
|
| S2 | Malicious code pretends to be safe | High | Critical | Critical |
|
||||||
|
|
||||||
|
### T - Tampering
|
||||||
|
| ID | Threat | Likelihood | Impact | Risk |
|
||||||
|
|----|--------|------------|--------|------|
|
||||||
|
| T1 | XSS modifies local files | High | Critical | Critical |
|
||||||
|
| T2 | Conversion output tampered | Medium | Medium | Medium |
|
||||||
|
|
||||||
|
### R - Repudiation
|
||||||
|
| ID | Threat | Likelihood | Impact | Risk |
|
||||||
|
|----|--------|------------|--------|------|
|
||||||
|
| R1 | No audit trail for operations | Low | Low | Low |
|
||||||
|
|
||||||
|
### I - Information Disclosure
|
||||||
|
| ID | Threat | Likelihood | Impact | Risk |
|
||||||
|
|----|--------|------------|--------|------|
|
||||||
|
| I1 | XSS exposes file system | High | Critical | Critical |
|
||||||
|
| I2 | PlantUML content leaked | Medium | Medium | Medium |
|
||||||
|
| I3 | Error messages reveal paths | Low | Low | Low |
|
||||||
|
|
||||||
|
### D - Denial of Service
|
||||||
|
| ID | Threat | Likelihood | Impact | Risk |
|
||||||
|
|----|--------|------------|--------|------|
|
||||||
|
| D1 | Malicious code crashes app | Medium | Medium | Medium |
|
||||||
|
| D2 | Large file exhausts resources | Low | Low | Low |
|
||||||
|
|
||||||
|
### E - Elevation of Privilege
|
||||||
|
| ID | Threat | Likelihood | Impact | Risk |
|
||||||
|
|----|--------|------------|--------|------|
|
||||||
|
| E1 | XSS → nodeIntegration → System | High | Critical | Critical |
|
||||||
|
| E2 | REPL code execution | High | Critical | Critical |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## MITRE ATT&CK Mapping
|
||||||
|
|
||||||
|
| Technique | ID | Applicability |
|
||||||
|
|-----------|-----|---------------|
|
||||||
|
| User Execution | T1204.002 | Malicious markdown file |
|
||||||
|
| Command and Scripting Interpreter | T1059.007 | JavaScript via nodeIntegration |
|
||||||
|
| Command and Scripting Interpreter | T1059.006 | Python via REPL |
|
||||||
|
| Command and Scripting Interpreter | T1059.004 | Bash via REPL |
|
||||||
|
| Exploit Public-Facing Application | T1190 | XSS in preview |
|
||||||
|
| Data Exfiltration Over Web Service | T1043 | PlantUML server |
|
||||||
|
| File and Directory Discovery | T1083 | Path traversal |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Trust Boundaries
|
||||||
|
|
||||||
|
```
|
||||||
|
┌─────────────────────────────────────────────────────────────────────┐
|
||||||
|
│ TRUST BOUNDARY MAP │
|
||||||
|
├─────────────────────────────────────────────────────────────────────┤
|
||||||
|
│ │
|
||||||
|
│ ┌─────────────┐ ┌─────────────────────────────────────┐ │
|
||||||
|
│ │ USER │ ──────► │ APPLICATION │ │
|
||||||
|
│ │ (Untrusted) │ │ ┌───────────┐ ┌───────────────┐ │ │
|
||||||
|
│ └─────────────┘ │ │ Renderer │ │ Main Process │ │ │
|
||||||
|
│ │ │ (Sandbox) │ │ (Privileged) │ │ │
|
||||||
|
│ │ └─────┬─────┘ └───────┬───────┘ │ │
|
||||||
|
│ │ │ IPC │ │ │
|
||||||
|
│ │ ▼ ▼ │ │
|
||||||
|
│ │ ┌─────────────────────────────┐ │ │
|
||||||
|
│ │ │ File System │ │ │
|
||||||
|
│ │ └─────────────────────────────┘ │ │
|
||||||
|
│ └─────────────────────────────────────┘ │
|
||||||
|
│ │ │
|
||||||
|
│ ▼ │
|
||||||
|
│ ┌─────────────────────────────────────────────────────────────┐ │
|
||||||
|
│ │ EXTERNAL SERVICES │ │
|
||||||
|
│ │ • PlantUML Server (www.plantuml.com) │ │
|
||||||
|
│ │ • CDN (cdn.jsdelivr.net, cdnjs.cloudflare.com) [REMOVED] │ │
|
||||||
|
│ │ • External Tools (Pandoc, FFmpeg, LibreOffice) │ │
|
||||||
|
│ └─────────────────────────────────────────────────────────────┘ │
|
||||||
|
│ │
|
||||||
|
└─────────────────────────────────────────────────────────────────────┘
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Business Impact Analysis
|
||||||
|
|
||||||
|
### Successful Attack Consequences
|
||||||
|
|
||||||
|
| Impact Category | Estimate |
|
||||||
|
|-----------------|----------|
|
||||||
|
| Data breach costs | $500,000 - $5,000,000+ |
|
||||||
|
| Regulatory fines (GDPR) | Up to 4% annual revenue |
|
||||||
|
| Reputation damage | Incalculable |
|
||||||
|
| Business disruption | Hours to days |
|
||||||
|
|
||||||
|
### Affected Assets
|
||||||
|
- User documents and files
|
||||||
|
- System credentials
|
||||||
|
- Proprietary information in diagrams
|
||||||
|
- Application integrity
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Remediation Priority
|
||||||
|
|
||||||
|
### P0 - Immediate (24-48 hours)
|
||||||
|
1. **CVE-MC-001**: Set `nodeIntegration: false`, `contextIsolation: true`
|
||||||
|
2. **CVE-MC-002**: Remove or sandbox REPL code execution
|
||||||
|
|
||||||
|
### P1 - Short-term (1-2 weeks)
|
||||||
|
3. **CVE-MC-003**: Audit markdown extensions for XSS
|
||||||
|
4. **CVE-MC-004**: Add path validation (✅ COMPLETED)
|
||||||
|
5. **CVE-MC-005**: Strengthen CSP (✅ COMPLETED)
|
||||||
|
|
||||||
|
### P2 - Medium-term (1 month)
|
||||||
|
6. **CVE-MC-006**: Consistent window security settings
|
||||||
|
7. **CVE-MC-007**: Add local PlantUML option or warning
|
||||||
|
8. **CVE-MC-008**: Audit all BrowserWindow configurations
|
||||||
|
|
||||||
|
### P3 - Long-term
|
||||||
|
9. **CVE-MC-009**: Validate filenames for external tools
|
||||||
|
10. **CVE-MC-010**: Pin dependency versions, add scanning
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Conclusion
|
||||||
|
|
||||||
|
The MarkdownConverter application has a **HIGH RISK** threat profile due to the combination of:
|
||||||
|
- Untrusted content rendering (markdown preview)
|
||||||
|
- Direct system access (nodeIntegration)
|
||||||
|
- Code execution capability (REPL)
|
||||||
|
|
||||||
|
**Immediate action required on P0 items to reduce attack surface.**
|
||||||
|
|
||||||
|
The fixes applied in this session (CSP, path traversal, UI accessibility) have reduced the risk profile, but the critical nodeIntegration issue requires significant refactoring.
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
{
|
||||||
|
"target": "MarkdownConverter Electron Application",
|
||||||
|
"status": "in_progress",
|
||||||
|
"depth": "comprehensive",
|
||||||
|
"compliance_frameworks": ["owasp"],
|
||||||
|
"current_step": 3,
|
||||||
|
"current_phase": 1,
|
||||||
|
"completed_steps": ["vulnerability-scan", "threat-modeling"],
|
||||||
|
"files_created": ["01-vulnerability-scan.md", "02-threat-model.md"],
|
||||||
|
"started_at": "2026-03-15T00:09:00.000Z",
|
||||||
|
"last_updated": "2026-03-15T00:25:00.000Z",
|
||||||
|
"findings_summary": {
|
||||||
|
"critical": 2,
|
||||||
|
"high": 3,
|
||||||
|
"medium": 3,
|
||||||
|
"low": 2,
|
||||||
|
"total": 10
|
||||||
|
},
|
||||||
|
"fixes_applied": {
|
||||||
|
"csp_external_cdns_removed": true,
|
||||||
|
"path_traversal_protection_added": true,
|
||||||
|
"aria_labels_added": true,
|
||||||
|
"focus_visible_styles_added": true,
|
||||||
|
"tab_close_button_resized": true,
|
||||||
|
"duplicate_font_size_fixed": true
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,522 @@
|
|||||||
|
# Comprehensive UI Design Review - MarkdownConverter Electron Application
|
||||||
|
|
||||||
|
## Executive Summary
|
||||||
|
|
||||||
|
This review covers the UI design of the MarkdownConverter Electron application, analyzing visual design, usability, code quality, and performance across all UI files. The application has a solid foundation but has several areas requiring attention.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 1. Visual Design Review
|
||||||
|
|
||||||
|
### 1.1 Spacing & Layout Consistency
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | Inconsistent padding values across files | Multiple CSS files | Standardize to 4px/8px base scale |
|
||||||
|
| **Major** | Multiple reset declarations | `styles.css:1-5`, `styles-modern.css:42-47` | Consolidate resets into single file |
|
||||||
|
| **Minor** | Tab padding varies between themes | `styles.css:36`, `styles-modern.css:101` | Use CSS variables for consistent padding |
|
||||||
|
| **Minor** | Container padding inconsistency | `styles.css:17-21`, `styles-modern.css:63-69` | Define single container style |
|
||||||
|
|
||||||
|
**Code Example - Duplicate Reset:**
|
||||||
|
|
||||||
|
```css
|
||||||
|
/* styles.css:1-5 */
|
||||||
|
* {
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
|
box-sizing: border-box;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* styles-modern.css:42-47 - DUPLICATE */
|
||||||
|
* {
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
|
box-sizing: border-box;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
/* Create a single base.css or remove from styles-modern.css */
|
||||||
|
/* Use CSS variables for spacing scale */
|
||||||
|
:root {
|
||||||
|
--space-1: 4px;
|
||||||
|
--space-2: 8px;
|
||||||
|
--space-3: 12px;
|
||||||
|
--space-4: 16px;
|
||||||
|
--space-5: 24px;
|
||||||
|
--space-6: 32px;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 1.2 Typography Consistency
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | Font-family declared multiple times with different fallbacks | `styles.css:8`, `styles-modern.css:50`, `styles-concreteinfo.css:32` | Standardize font stack |
|
||||||
|
| **Major** | Duplicate font-size declarations | `styles.css:228-230` | Remove duplicate |
|
||||||
|
| **Minor** | Inconsistent line-height values | Multiple files | Create type scale variables |
|
||||||
|
|
||||||
|
**Code Example - Duplicate font-size:**
|
||||||
|
```css
|
||||||
|
/* styles.css:226-230 */
|
||||||
|
.preview-content {
|
||||||
|
max-width: none;
|
||||||
|
margin: 0;
|
||||||
|
padding: 20px 24px 24px 24px;
|
||||||
|
line-height: 1.6;
|
||||||
|
font-size: 15px;
|
||||||
|
font-size: 14px; /* DUPLICATE - overwrites previous */
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
/* styles.css - Remove duplicate */
|
||||||
|
.preview-content {
|
||||||
|
font-size: 14px; /* Keep only one */
|
||||||
|
line-height: 1.6;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 1.3 Color Usage and Contrast Accessibility
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Critical** | Hardcoded colors instead of CSS variables | `styles.css:27-29`, `styles.css:37-38`, etc. | Use CSS custom properties |
|
||||||
|
| **Major** | Inconsistent gray scale definitions | Multiple files define different grays | Consolidate to single palette |
|
||||||
|
| **Minor** | Some contrast ratios may be insufficient | Status bar text colors | Verify WCAG 2.1 AA compliance |
|
||||||
|
|
||||||
|
**Code Example - Hardcoded colors:**
|
||||||
|
```css
|
||||||
|
/* styles.css:27-29 */
|
||||||
|
.tab-bar {
|
||||||
|
background: #f0f0f0; /* Should use var(--gray-100) */
|
||||||
|
border-bottom: 1px solid #ddd; /* Should use var(--gray-300) */
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
/* Use the existing palette from styles-modern.css */
|
||||||
|
.tab-bar {
|
||||||
|
background: var(--gray-100, #f3f4f6);
|
||||||
|
border-bottom: 1px solid var(--gray-300, #d1d5db);
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 1.4 Dark Mode Support Quality
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | Dark theme selectors inconsistent | `styles.css` uses `body.theme-dark`, `styles-sidebar.css:108` uses `body[class*="dark"]` | Standardize selector pattern |
|
||||||
|
| **Minor** | Missing dark theme support for some components | `.breadcrumb-bar`, command palette | Add dark mode variants |
|
||||||
|
| **Suggestion** | Repetitive dark theme declarations | `styles-concreteinfo.css:362-425` | Use CSS custom properties for theming |
|
||||||
|
|
||||||
|
**Code Example - Inconsistent selectors:**
|
||||||
|
```css
|
||||||
|
/* styles.css */
|
||||||
|
body.theme-dark .tab-bar { ... }
|
||||||
|
|
||||||
|
/* styles-sidebar.css */
|
||||||
|
body[class*="dark"] .sidebar-icons { ... }
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
/* Choose one pattern and apply consistently */
|
||||||
|
/* Option 1: Class-based (recommended) */
|
||||||
|
body.theme-dark .tab-bar,
|
||||||
|
body.theme-dark .sidebar-icons { ... }
|
||||||
|
|
||||||
|
/* Option 2: Attribute-based */
|
||||||
|
body[data-theme="dark"] .tab-bar { ... }
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 2. Usability Review
|
||||||
|
|
||||||
|
### 2.1 Clickable/Tappable Areas
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Critical** | Tab close button too small (16x16px) | `styles.css:62-77` | Increase to minimum 24x24px |
|
||||||
|
| **Major** | Sidebar icons at minimum size | `styles-sidebar.css:35-47` (36x36px) | Consider 40-44px for better touch |
|
||||||
|
| **Minor** | Toolbar buttons at edge of minimum | `styles.css:120-131` (32x32px) | Acceptable for mouse, small for touch |
|
||||||
|
|
||||||
|
**Code Example - Small close button:**
|
||||||
|
```css
|
||||||
|
/* styles.css:62-77 */
|
||||||
|
.tab-close {
|
||||||
|
width: 16px; /* TOO SMALL - below 24px minimum */
|
||||||
|
height: 16px; /* TOO SMALL */
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
.tab-close {
|
||||||
|
width: 24px;
|
||||||
|
height: 24px;
|
||||||
|
border-radius: 4px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Add touch-friendly hit area */
|
||||||
|
.tab-close::before {
|
||||||
|
content: '';
|
||||||
|
position: absolute;
|
||||||
|
top: -4px;
|
||||||
|
left: -4px;
|
||||||
|
right: -4px;
|
||||||
|
bottom: -4px;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.2 Hover/Focus States
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Critical** | Missing focus-visible styles | All interactive elements | Add :focus-visible for keyboard navigation |
|
||||||
|
| **Major** | No focus indicators on toolbar buttons | `styles.css:133-140` | Add visible focus ring |
|
||||||
|
| **Minor** | Inconsistent hover transitions | Various components | Standardize transition duration |
|
||||||
|
|
||||||
|
**Code Example - Missing focus styles:**
|
||||||
|
```css
|
||||||
|
/* styles.css:120-131 - No focus state */
|
||||||
|
.toolbar button {
|
||||||
|
/* ... no focus style */
|
||||||
|
}
|
||||||
|
|
||||||
|
.toolbar button:hover {
|
||||||
|
background: #e0e0e0;
|
||||||
|
border-color: #ccc;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
.toolbar button:focus-visible {
|
||||||
|
outline: 2px solid var(--primary-dark, #5661b3);
|
||||||
|
outline-offset: 2px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.toolbar button:hover {
|
||||||
|
background: #e0e0e0;
|
||||||
|
border-color: #ccc;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.3 Loading and Error State Handling
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | Generic error message without styling | `renderer.js:384-386`, `renderer.js:508-511` | Create styled error components |
|
||||||
|
| **Minor** | No loading indicators for async operations | Sidebar panels | Add skeleton loaders or spinners |
|
||||||
|
| **Minor** | `git-loading` class exists but minimal styling | `styles-sidebar.css:227` | Enhance with animation |
|
||||||
|
|
||||||
|
**Code Example - Plain error display:**
|
||||||
|
```javascript
|
||||||
|
// renderer.js:384-386
|
||||||
|
preview.innerHTML = '<p style="color: red; padding: 20px;">Error: Required libraries...';
|
||||||
|
// Inline styles should be in CSS
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
/* Add to styles.css */
|
||||||
|
.preview-error {
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
padding: 40px 20px;
|
||||||
|
color: var(--ci-danger, #dc3545);
|
||||||
|
text-align: center;
|
||||||
|
}
|
||||||
|
|
||||||
|
.preview-error-icon {
|
||||||
|
font-size: 48px;
|
||||||
|
margin-bottom: 16px;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.4 Accessibility (ARIA, Semantic HTML)
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Critical** | Buttons without accessible labels | `index.html:31` (tab close), `index.html:33` (new tab) | Add aria-label |
|
||||||
|
| **Critical** | SVG icons lack aria-hidden | All toolbar buttons | Add aria-hidden="true" |
|
||||||
|
| **Major** | Missing role attributes on tabs | `index.html:29-33` | Add role="tablist", role="tab" |
|
||||||
|
| **Major** | No skip links | `index.html` | Add skip to main content link |
|
||||||
|
| **Minor** | Dialog missing aria-modal | Export dialogs | Add aria-modal="true" |
|
||||||
|
|
||||||
|
**Code Example - Missing accessibility attributes:**
|
||||||
|
```html
|
||||||
|
<!-- index.html:31 - Current -->
|
||||||
|
<button class="tab-close" title="Close tab">x</button>
|
||||||
|
|
||||||
|
<!-- index.html:33 - Current -->
|
||||||
|
<button class="new-tab-button" id="new-tab-btn" title="New tab">+</button>
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```html
|
||||||
|
<!-- Improved with ARIA -->
|
||||||
|
<div class="tab-bar" id="tab-bar" role="tablist" aria-label="Document tabs">
|
||||||
|
<div class="tab active" data-tab-id="1" role="tab" aria-selected="true" aria-controls="tab-content-1">
|
||||||
|
<span class="tab-title">Untitled</span>
|
||||||
|
<button class="tab-close" aria-label="Close tab" title="Close tab">×</button>
|
||||||
|
</div>
|
||||||
|
<button class="new-tab-button" id="new-tab-btn" aria-label="Create new tab" title="New tab">+</button>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<!-- SVG icons should have aria-hidden -->
|
||||||
|
<button id="btn-bold" title="Bold (Ctrl+B)" aria-label="Bold">
|
||||||
|
<svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" aria-hidden="true">
|
||||||
|
...
|
||||||
|
</svg>
|
||||||
|
</button>
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.5 Keyboard Navigation
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | Tab order may skip sidebar icons | Sidebar panel | Verify logical tab order |
|
||||||
|
| **Minor** | No escape key handling for dialogs | Export dialogs | Add escape to close |
|
||||||
|
| **Minor** | Find dialog lacks full keyboard support | `renderer.js:804-866` | Add Ctrl+F shortcut hint |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 3. Code Quality Review
|
||||||
|
|
||||||
|
### 3.1 CSS Organization & Naming
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | No clear CSS architecture | All CSS files | Adopt BEM or similar methodology |
|
||||||
|
| **Major** | Overly generic class names | `.pane`, `.tab`, `.container` | Use more specific naming |
|
||||||
|
| **Minor** | Mixed naming conventions | camelCase (`tabBar`), kebab-case (`tab-bar`) | Standardize to kebab-case |
|
||||||
|
| **Minor** | Magic numbers | Various pixel values | Replace with spacing variables |
|
||||||
|
|
||||||
|
### 3.2 CSS Specificity Issues
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | Excessive use of `!important` | `styles.css:14` | Restructure to avoid |
|
||||||
|
| **Major** | Deep selector nesting | Dark theme selectors | Flatten and use CSS variables |
|
||||||
|
| **Minor** | ID selectors for styling | `styles.css:233-247` | Prefer class selectors |
|
||||||
|
|
||||||
|
**Code Example - Problematic specificity:**
|
||||||
|
```css
|
||||||
|
/* styles.css:14 - Avoid !important */
|
||||||
|
.hidden {
|
||||||
|
display: none !important;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* styles.css:397-431 - Deep nesting */
|
||||||
|
body.theme-dark #preview h1,
|
||||||
|
body.theme-dark [id^="preview-"] h1,
|
||||||
|
body.theme-dark .preview-content h1 {
|
||||||
|
color: #c9d1d9;
|
||||||
|
border-bottom-color: #21262d;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
/* Use utility class pattern */
|
||||||
|
[hidden] { display: none; }
|
||||||
|
|
||||||
|
/* Use CSS custom properties for theming */
|
||||||
|
.preview-content h1 {
|
||||||
|
color: var(--text-primary);
|
||||||
|
border-bottom-color: var(--border-color);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Theme applies variables */
|
||||||
|
body.theme-dark {
|
||||||
|
--text-primary: #c9d1d9;
|
||||||
|
--border-color: #21262d;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.3 Reusable Style Definitions
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | Repeated button styles | Multiple files | Create button component classes |
|
||||||
|
| **Major** | Dialog styles duplicated | Export, batch, print preview dialogs | Create modal component |
|
||||||
|
| **Minor** | Similar form field styles scattered | Export dialog inputs | Create form component |
|
||||||
|
|
||||||
|
**Code Example - Duplicated button styles:**
|
||||||
|
```css
|
||||||
|
/* styles.css */
|
||||||
|
.toolbar button { /* button styles */ }
|
||||||
|
.tab-close { /* button styles */ }
|
||||||
|
.new-tab-button { /* button styles */ }
|
||||||
|
#export-dialog-close { /* button styles */ }
|
||||||
|
|
||||||
|
/* styles-sidebar.css */
|
||||||
|
.sidebar-icon { /* similar button styles */ }
|
||||||
|
.sidebar-panel-close { /* similar button styles */ }
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```css
|
||||||
|
/* Create button component system */
|
||||||
|
.btn {
|
||||||
|
display: inline-flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
border: none;
|
||||||
|
cursor: pointer;
|
||||||
|
transition: all var(--transition-fast);
|
||||||
|
}
|
||||||
|
|
||||||
|
.btn--icon {
|
||||||
|
width: 32px;
|
||||||
|
height: 32px;
|
||||||
|
border-radius: var(--radius-md);
|
||||||
|
}
|
||||||
|
|
||||||
|
.btn--close {
|
||||||
|
font-size: 14px;
|
||||||
|
font-weight: bold;
|
||||||
|
border-radius: var(--radius-sm);
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.4 Documentation
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Minor** | Limited CSS documentation | All CSS files | Add section comments |
|
||||||
|
| **Minor** | No component documentation | Sidebar components | Add JSDoc-style comments |
|
||||||
|
| **Suggestion** | No design tokens documentation | CSS variables | Create tokens documentation |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 4. Performance Review
|
||||||
|
|
||||||
|
### 4.1 CSS Optimization
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | Large CSS files (105KB main, 78KB modern) | `styles.css`, `styles-modern.css` | Split into smaller modules |
|
||||||
|
| **Major** | Duplicate style definitions | Multiple files | Remove redundancies |
|
||||||
|
| **Minor** | Unused styles likely present | Theme variations | Audit and remove unused |
|
||||||
|
|
||||||
|
### 4.2 Asset Loading
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Major** | highlight.js CSS loaded synchronously | `index.html:14` | Load asynchronously or bundle |
|
||||||
|
| **Minor** | Font files could be preloaded | `fonts.css` | Add preload links in HTML |
|
||||||
|
| **Suggestion** | Consider CSS critical path | Above-the-fold styles | Inline critical CSS |
|
||||||
|
|
||||||
|
**Code Example - Sync stylesheet loading:**
|
||||||
|
```html
|
||||||
|
<!-- index.html:14 - Blocks rendering -->
|
||||||
|
<link rel="stylesheet" href="../node_modules/highlight.js/styles/default.css">
|
||||||
|
```
|
||||||
|
|
||||||
|
**Fix Recommendation:**
|
||||||
|
```html
|
||||||
|
<!-- Non-blocking load -->
|
||||||
|
<link rel="stylesheet" href="../node_modules/highlight.js/styles/default.css" media="print" onload="this.media='all'">
|
||||||
|
|
||||||
|
<!-- Or preload fonts -->
|
||||||
|
<link rel="preload" href="../assets/fonts/Inter-Regular.woff2" as="font" type="font/woff2" crossorigin>
|
||||||
|
```
|
||||||
|
|
||||||
|
### 4.3 Animation Performance
|
||||||
|
|
||||||
|
| Severity | Issue | Location | Recommendation |
|
||||||
|
|----------|-------|----------|----------------|
|
||||||
|
| **Minor** | Some transitions on expensive properties | `styles-modern.css:111-112` | Prefer transform/opacity |
|
||||||
|
| **Suggestion** | Missing will-change hints | Complex animations | Add will-change for GPU hints |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 5. Component-Specific Issues
|
||||||
|
|
||||||
|
### 5.1 Tab System
|
||||||
|
|
||||||
|
| File | Issues |
|
||||||
|
|------|--------|
|
||||||
|
| `styles.css:23-97` | Inconsistent active state styling, small close button |
|
||||||
|
| `renderer.js:88-346` | Tab content created via innerHTML (XSS risk) |
|
||||||
|
|
||||||
|
### 5.2 Sidebar
|
||||||
|
|
||||||
|
| File | Issues |
|
||||||
|
|------|--------|
|
||||||
|
| `styles-sidebar.css` | Good structure but missing focus states |
|
||||||
|
| `sidebar-manager.js` | Clean implementation, needs ARIA |
|
||||||
|
|
||||||
|
### 5.3 Export Dialogs
|
||||||
|
|
||||||
|
| File | Issues |
|
||||||
|
|------|--------|
|
||||||
|
| `styles.css:1060-1355` | Monolithic, should be component |
|
||||||
|
| `index.html:171-331` | Complex nested structure needs semantic HTML |
|
||||||
|
|
||||||
|
### 5.4 Welcome Screen
|
||||||
|
|
||||||
|
| File | Issues |
|
||||||
|
|------|--------|
|
||||||
|
| `styles-welcome.css` | Minimal styles, good foundation |
|
||||||
|
| Missing hover states for keyboard focus | Add :focus-visible |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 6. Prioritized Fix Recommendations
|
||||||
|
|
||||||
|
### Critical (Immediate)
|
||||||
|
|
||||||
|
1. **Add missing ARIA attributes** to all interactive elements
|
||||||
|
2. **Increase tab close button size** to minimum 24x24px
|
||||||
|
3. **Add focus-visible styles** for keyboard navigation
|
||||||
|
4. **Fix duplicate font-size declaration** in `.preview-content`
|
||||||
|
|
||||||
|
### Major (Next Sprint)
|
||||||
|
|
||||||
|
1. **Consolidate CSS resets** into single location
|
||||||
|
2. **Create button component system** with variants
|
||||||
|
3. **Standardize dark theme selectors** across all files
|
||||||
|
4. **Replace hardcoded colors** with CSS variables
|
||||||
|
5. **Create modal/dialog component** to reduce duplication
|
||||||
|
|
||||||
|
### Minor (Future)
|
||||||
|
|
||||||
|
1. **Document CSS architecture** and naming conventions
|
||||||
|
2. **Audit and remove unused styles**
|
||||||
|
3. **Add loading state components** (skeletons, spinners)
|
||||||
|
4. **Implement CSS module splitting** for better performance
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 7. Summary Statistics
|
||||||
|
|
||||||
|
| Category | Critical | Major | Minor | Suggestions |
|
||||||
|
|----------|----------|-------|-------|-------------|
|
||||||
|
| Visual Design | 1 | 5 | 4 | 1 |
|
||||||
|
| Usability | 3 | 4 | 4 | 0 |
|
||||||
|
| Code Quality | 0 | 6 | 4 | 1 |
|
||||||
|
| Performance | 0 | 3 | 2 | 2 |
|
||||||
|
| **Total** | **4** | **18** | **14** | **4** |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Conclusion
|
||||||
|
|
||||||
|
The MarkdownConverter application has a functional UI with good visual variety through its theme system. However, there are significant opportunities for improvement in:
|
||||||
|
|
||||||
|
1. **Accessibility** - Critical for users with disabilities
|
||||||
|
2. **Code organization** - Reduce CSS duplication and improve maintainability
|
||||||
|
3. **Component consistency** - Standardize interactive element sizing and states
|
||||||
|
4. **Performance** - Optimize CSS loading and reduce bundle size
|
||||||
|
|
||||||
|
Addressing the Critical and Major issues will significantly improve both user experience and code maintainability.
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
{
|
||||||
|
"review_id": "full-ui-review_20260315",
|
||||||
|
"target": "src/ (Entire UI Directory)",
|
||||||
|
"focus_areas": ["visual", "usability", "code", "performance"],
|
||||||
|
"context": "comprehensive",
|
||||||
|
"platform": "desktop",
|
||||||
|
"status": "complete",
|
||||||
|
"started_at": "2026-03-15T00:09:00.000Z",
|
||||||
|
"completed_at": "2026-03-15T00:12:00.000Z",
|
||||||
|
"issues_found": 40,
|
||||||
|
"severity_counts": {
|
||||||
|
"critical": 4,
|
||||||
|
"major": 18,
|
||||||
|
"minor": 14,
|
||||||
|
"suggestion": 4
|
||||||
|
}
|
||||||
|
}
|
||||||
Vendored
+48
@@ -0,0 +1,48 @@
|
|||||||
|
{
|
||||||
|
"version": "0.2.0",
|
||||||
|
"configurations": [
|
||||||
|
{
|
||||||
|
"name": "Debug Main Process",
|
||||||
|
"type": "node",
|
||||||
|
"request": "launch",
|
||||||
|
"cwd": "${workspaceFolder}",
|
||||||
|
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron",
|
||||||
|
"windows": {
|
||||||
|
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron.cmd"
|
||||||
|
},
|
||||||
|
"args": ["."],
|
||||||
|
"outputCapture": "std",
|
||||||
|
"env": {
|
||||||
|
"NODE_ENV": "development"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "Debug Renderer Process",
|
||||||
|
"type": "chrome",
|
||||||
|
"request": "attach",
|
||||||
|
"port": 9222,
|
||||||
|
"webRoot": "${workspaceFolder}/src",
|
||||||
|
"timeout": 30000
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "Debug Main + Renderer",
|
||||||
|
"type": "node",
|
||||||
|
"request": "launch",
|
||||||
|
"cwd": "${workspaceFolder}",
|
||||||
|
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron",
|
||||||
|
"windows": {
|
||||||
|
"runtimeExecutable": "${workspaceFolder}/node_modules/.bin/electron.cmd"
|
||||||
|
},
|
||||||
|
"args": [".", "--remote-debugging-port=9222"],
|
||||||
|
"outputCapture": "std",
|
||||||
|
"env": {
|
||||||
|
"NODE_ENV": "development"
|
||||||
|
},
|
||||||
|
"serverReadyAction": {
|
||||||
|
"pattern": "listening on port ([0-9]+)",
|
||||||
|
"uriFormat": "http://localhost:%s",
|
||||||
|
"action": "debugWithChrome"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
# Repository Guidelines
|
||||||
|
|
||||||
|
## Project Structure & Module Organization
|
||||||
|
Core application code lives in `src/`. Use `src/main.js` for the Electron main process, `src/preload.js` for the preload bridge, and `src/renderer.js` plus `src/editor/`, `src/sidebar/`, `src/repl/`, and `src/utils/` for renderer-side features. Electron adapter code is in `src/adapters/electron/`. Reusable markdown/document templates live in `src/templates/`. Static assets and icons are in `assets/`. Tests are in `tests/`, and build output goes to `dist/`.
|
||||||
|
|
||||||
|
## Build, Test, and Development Commands
|
||||||
|
- `npm start`: launch the Electron app locally.
|
||||||
|
- `npm test`: run the Jest suite once.
|
||||||
|
- `npm run test:watch`: rerun tests during local development.
|
||||||
|
- `npm run test:coverage`: generate coverage output.
|
||||||
|
- `npm run lint` / `npm run lint:fix`: check or fix ESLint issues in `src` and `tests`.
|
||||||
|
- `npm run format` / `npm run format:check`: apply or verify Prettier formatting.
|
||||||
|
- `npm run build:linux`, `npm run build:win`, `npm run build:mac`: create platform packages with `electron-builder`.
|
||||||
|
|
||||||
|
## Coding Style & Naming Conventions
|
||||||
|
This repo uses Prettier and ESLint. Follow `.prettierrc`: 2-space indentation, single quotes, semicolons, trailing commas where valid in ES5, and a 100-character line width. Prefer `camelCase` for variables/functions, `PascalCase` for classes, and kebab-case for file names only when already established. Keep module boundaries clear: UI logic in renderer modules, OS/file-system work behind Electron IPC and adapters.
|
||||||
|
|
||||||
|
## Testing Guidelines
|
||||||
|
Tests use Jest with `jest-environment-jsdom`. Add new tests under `tests/` with `*.test.js` names, mirroring the feature area when possible, for example `tests/sidebar.test.js` or `tests/print-preview.test.js`. Update or add regression tests for renderer behavior, preload APIs, and utility helpers when fixing bugs. Run `npm test` before opening a PR; use `npm run test:coverage` for larger refactors.
|
||||||
|
|
||||||
|
## Commit & Pull Request Guidelines
|
||||||
|
Recent history follows Conventional Commit prefixes such as `feat:`, `fix:`, and `refactor:`. Keep subjects short and imperative, for example `fix: guard modal cleanup on close`. PRs should describe the user-visible change, note test coverage, link any related issue, and include screenshots or GIFs for UI changes.
|
||||||
|
|
||||||
|
## Security & Configuration Tips
|
||||||
|
Do not bypass preload boundaries or introduce direct `eval`/dynamic code paths; ESLint already treats these as errors. Export and conversion features depend on external tools such as Pandoc, FFmpeg, ImageMagick, and LibreOffice, so document any new runtime dependency in `README.md` and packaging config.
|
||||||
@@ -0,0 +1,103 @@
|
|||||||
|
# CLAUDE.md — MarkdownConverter (master)
|
||||||
|
|
||||||
|
> General code-quality, JavaScript, git, security, and testing standards are in the **global CLAUDE.md**. This file holds project- and branch-specific notes.
|
||||||
|
|
||||||
|
## Project Overview
|
||||||
|
|
||||||
|
Electron desktop app for Markdown editing and universal file conversion powered by Pandoc. Cross-platform (Win/macOS/Linux). Features: multi-tab editor with live preview, 25+ themes, PDF viewer/editor (merge/split/compress/rotate/watermark/password), export to 20+ formats (PDF/DOCX/ODT/EPUB/HTML/LaTeX/RTF/PPTX), batch conversion, syntax highlighting, diagram support (Mermaid), Git integration, and a plugin system.
|
||||||
|
|
||||||
|
- **Version:** 4.4.5
|
||||||
|
- **License:** MIT
|
||||||
|
- **App ID:** `com.concreteinfo.markdownconverter`
|
||||||
|
|
||||||
|
## Branch Specifics
|
||||||
|
|
||||||
|
This is the **primary/release branch** — a vanilla JavaScript Electron app with no bundler or framework in the renderer. The renderer is a single large `renderer.js` (5,300+ lines) loaded directly via `src/index.html`. All UI is hand-rolled DOM manipulation.
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|
### Main Process (`src/main.js` — 4,260 lines)
|
||||||
|
Monolithic main process file. Contains all IPC handlers, Pandoc invocation, file operations, menu definitions (600+ lines), and window lifecycle. Key modules extracted:
|
||||||
|
- `src/main/PDFOperations.js` — PDF manipulation via `pdf-lib` (merge, split, compress, rotate, delete, reorder, watermark, encrypt, decrypt, permissions)
|
||||||
|
- `src/main/GitOperations.js` — Git status/stage/commit/log via `simple-git`
|
||||||
|
|
||||||
|
### Renderer (`src/renderer.js` — 5,361 lines)
|
||||||
|
Vanilla JS, no framework. Directly manipulates DOM. Loads CodeMirror 6 via `src/editor/codemirror-setup.js`. Uses `marked` + `highlight.js` + `DOMPurify` + `mermaid` for rendering. Lazy-loads sidebar panels, REPL, command palette, zen mode.
|
||||||
|
|
||||||
|
### Preload (`src/preload.js` — 448 lines)
|
||||||
|
Exists as IPC bridge, but **`contextIsolation: false` and `nodeIntegration: true`** — the renderer has full Node access. Preload is effectively a thin passthrough.
|
||||||
|
|
||||||
|
### Security Model
|
||||||
|
- `contextIsolation: false` + `nodeIntegration: true` (legacy; the react-electron branch fixes this)
|
||||||
|
- Pandoc invoked via `execFile` (not `exec`) to prevent shell injection
|
||||||
|
- Path traversal protection: `validatePath()`, `resolveWritablePath()`, blocks sensitive system dirs
|
||||||
|
- Permission handler only allows `clipboard-read`/`clipboard-write`
|
||||||
|
- Rate limiter on conversions (2-second minimum interval)
|
||||||
|
- File size limit: 50MB
|
||||||
|
- Error message sanitization strips absolute paths
|
||||||
|
|
||||||
|
### Plugin System (`src/plugins/`)
|
||||||
|
Manifest-based discovery (`manifest.json`). Built-in `writing-studio` plugin with sprint/goal/snapshot management. Plugin API exposed via `src/plugins/plugin-api.js`.
|
||||||
|
|
||||||
|
### Settings
|
||||||
|
Custom JSON file store at `<userData>/settings.json` (NOT `electron-store` despite the dependency). Recent files at `<userData>/recent-files.json`.
|
||||||
|
|
||||||
|
## System Dependencies
|
||||||
|
|
||||||
|
| Dependency | Required | Notes |
|
||||||
|
|---|---|---|
|
||||||
|
| **Node.js** | >= 20 | Electron 41 bundles Node 20.x |
|
||||||
|
| **Pandoc** | Yes (for exports) | Downloaded to `bin/<platform>/pandoc` via `scripts/download-tools.js` (v3.9.0.2). Falls back to system PATH. Must be present for DOCX/ODT/EPUB/LaTeX/PPTX export. |
|
||||||
|
| **FFmpeg** | Bundled | `ffmpeg-static` npm package; `asarUnpacked` for packaged builds |
|
||||||
|
| **MiKTeX / TeX Live** | Optional | For LaTeX PDF export; MiKTeX PATH injected on Windows automatically |
|
||||||
|
| **ImageMagick** | Optional | Linux image conversion; listed as deb dependency |
|
||||||
|
| **LibreOffice** | Optional | Enhanced document conversion; listed as deb dependency |
|
||||||
|
|
||||||
|
## Development Commands
|
||||||
|
|
||||||
|
```bash
|
||||||
|
npm start # Launch Electron app (dev mode)
|
||||||
|
npm test # Jest test suite
|
||||||
|
npm test:watch # Jest in watch mode
|
||||||
|
npm test:coverage # Jest with coverage report
|
||||||
|
npm run lint # ESLint check (src + tests)
|
||||||
|
npm run lint:fix # ESLint auto-fix
|
||||||
|
npm run format # Prettier write
|
||||||
|
npm run format:check # Prettier check only
|
||||||
|
npm run download-tools # Download Pandoc binaries to bin/
|
||||||
|
npm run generate-icons # Generate app icons via sharp
|
||||||
|
```
|
||||||
|
|
||||||
|
## Build & Package
|
||||||
|
|
||||||
|
**Tool:** `electron-builder` (v26.0.12), config inline in `package.json` (no separate config file).
|
||||||
|
|
||||||
|
| Target | Platforms |
|
||||||
|
|---|---|
|
||||||
|
| `npm run build` | electron-builder (default platform) |
|
||||||
|
| `npm run build:win` | Windows: NSIS installer + portable + zip (x64) |
|
||||||
|
| `npm run build:mac` | macOS: default dmg |
|
||||||
|
| `npm run build:linux` | Linux: deb + AppImage + snap |
|
||||||
|
| `npm run dist` | Build without publish |
|
||||||
|
| `npm run dist:all` | Build for all platforms |
|
||||||
|
|
||||||
|
**Bundled with builds:** Pandoc binary per platform. FFmpeg via `ffmpeg-static` (asarUnpacked). NSIS installer uses custom script at `scripts/nsis-installer.nsh`.
|
||||||
|
|
||||||
|
**Output:** `dist/` directory.
|
||||||
|
|
||||||
|
**CI:** GitHub Actions workflows in `.github/workflows/` (ci.yml, release.yml).
|
||||||
|
|
||||||
|
## Project Conventions / Gotchas
|
||||||
|
|
||||||
|
- **No bundler/transpilation.** The app uses vanilla CommonJS JavaScript. `src/main.js` is loaded directly by Electron. No webpack, no Vite, no TypeScript, no Babel.
|
||||||
|
- **Monolithic files.** `main.js` (4,260 lines) and `renderer.js` (5,361 lines) contain most logic. Not ideal but is the current state of this branch.
|
||||||
|
- **CodeMirror 6** for the editor, configured in `src/editor/codemirror-setup.js`.
|
||||||
|
- **PDF rendering** uses `pdfjs-dist`; **PDF manipulation** uses `pdf-lib` in the main process.
|
||||||
|
- **Renderer security is weak** — full Node access in renderer. Do NOT introduce new privileged renderer code without understanding this.
|
||||||
|
- **Pandoc is external.** Must be installed separately or downloaded via `npm run download-tools`. HTML and built-in PDF export work without Pandoc; other formats require it.
|
||||||
|
- **PDF export fallback chain:** xelatex -> pdflatex -> lualatex -> Electron built-in `printToPDF()`.
|
||||||
|
- **ESLint flat config** (`eslint.config.js`) with ECMAScript 2022. Prettier with 2-space indent, single quotes, semicolons, 100-char width.
|
||||||
|
- **Tests:** Jest with jsdom environment, 15% coverage threshold. 24 test files in `tests/`.
|
||||||
|
- **File associations:** `.md`, `.markdown`, `.pdf` registered at install.
|
||||||
|
- **Single instance lock** enforced via `app.requestSingleInstanceLock()`.
|
||||||
|
- **Adapters layer** (`src/adapters/`) abstracts file system operations for potential future non-Electron targets.
|
||||||
@@ -51,6 +51,16 @@ A powerful cross-platform Markdown editor and document converter powered by Pand
|
|||||||
- **ASCII Art Generator** - Create text banners and diagrams
|
- **ASCII Art Generator** - Create text banners and diagrams
|
||||||
- **Word templates** - Use custom Word templates for enhanced exports
|
- **Word templates** - Use custom Word templates for enhanced exports
|
||||||
- **Import documents** - Import from 30+ formats (DOCX, PDF, HTML, etc.)
|
- **Import documents** - Import from 30+ formats (DOCX, PDF, HTML, etc.)
|
||||||
|
- **Excel export** - Markdown tables to native .xlsx workbooks (one sheet per table)
|
||||||
|
- **AI Assistant** - Multi-provider AI help (OpenAI/Anthropic/Ollama/LM Studio): chat panel, summarize/improve/translate commands, grammar proofreading
|
||||||
|
- **Inline comments** - Anchor-based document comments in `.comments/` sidecars with F8 navigation
|
||||||
|
- **Wiki-links & Backlinks** - `[[Note]]` links with click-to-create and a "what links here?" panel (local knowledge base)
|
||||||
|
- **Crash recovery** - Session restore of open tabs and unsaved buffers after a crash
|
||||||
|
- **Version history** - Automatic pre-save snapshots with restore/diff/delete from the History panel
|
||||||
|
- **Vim mode & snippet expansion** - Vim keybindings toggle; Tab expands saved snippets
|
||||||
|
- **Quick Note** - Global scratchpad (Ctrl+Alt+Q) that appends to `notes/quick-notes.md`
|
||||||
|
- **Real PDF encryption** - Password protection, removal, and permissions actually work
|
||||||
|
- **Offline math & diagrams** - KaTeX bundled locally; PlantUML renders locally when the CLI is installed
|
||||||
|
|
||||||
## Installation
|
## Installation
|
||||||
|
|
||||||
@@ -96,9 +106,18 @@ npm run build:linux
|
|||||||
| Redo | Ctrl+Shift+Z |
|
| Redo | Ctrl+Shift+Z |
|
||||||
| New Tab | Ctrl+T |
|
| New Tab | Ctrl+T |
|
||||||
| Close Tab | Ctrl+W |
|
| Close Tab | Ctrl+W |
|
||||||
| Toggle Preview | Ctrl+Shift+P |
|
| Toggle Preview | Ctrl+Shift+V |
|
||||||
| Zoom In | Ctrl+Shift++ |
|
| Zoom In | Ctrl+Shift++ |
|
||||||
| Zoom Out | Ctrl+Shift+- |
|
| Zoom Out | Ctrl+Shift+- |
|
||||||
|
| Command Palette | Ctrl+Shift+P |
|
||||||
|
| Zen Mode | F11 |
|
||||||
|
| Writing Analytics | Ctrl+Shift+A |
|
||||||
|
| Quick Note | Ctrl+Alt+Q |
|
||||||
|
| Universal Converter | Ctrl+Shift+C |
|
||||||
|
| Table Generator | Ctrl+Shift+T |
|
||||||
|
| ASCII Art Generator | Ctrl+Shift+A |
|
||||||
|
| Next Comment | F8 |
|
||||||
|
| Add Comment at Cursor | Ctrl+Alt+M |
|
||||||
|
|
||||||
## Themes
|
## Themes
|
||||||
|
|
||||||
@@ -162,4 +181,4 @@ Amit Haridas (amit.wh@gmail.com)
|
|||||||
|
|
||||||
## Version
|
## Version
|
||||||
|
|
||||||
v3.0.0
|
v4.6.0
|
||||||
|
|||||||
+119
@@ -1,5 +1,124 @@
|
|||||||
# PanConverter - Updates & Changelog
|
# PanConverter - Updates & Changelog
|
||||||
|
|
||||||
|
## Version 4.6.0 (2026-09-05)
|
||||||
|
|
||||||
|
### New Features
|
||||||
|
|
||||||
|
#### AI Assistant Plugin (multi-provider)
|
||||||
|
- Chat sidebar panel with rolling conversation history and insert-reply-into-document
|
||||||
|
- Providers: OpenAI, Anthropic, Ollama, LM Studio, and any OpenAI-compatible endpoint
|
||||||
|
- All provider traffic proxied through the main process — API keys never enter the renderer and the CSP stays closed to AI endpoints
|
||||||
|
- Commands: AI Summarize / Improve / Explain / Translate selection
|
||||||
|
- Answers the writing-studio `ai:analyze` contract, finally enabling the Proofread panel
|
||||||
|
|
||||||
|
#### Collaboration Plugin (inline comments)
|
||||||
|
- Anchor-based comments stored in `.comments/` sidecar files (never exported, never committed)
|
||||||
|
- Comments sidebar panel: add at cursor, list, resolve, delete, jump to anchor
|
||||||
|
- Drift detection flags moved/edited anchors; F8 navigates to the next open comment
|
||||||
|
|
||||||
|
#### Local Knowledge Base (wiki-links + backlinks)
|
||||||
|
- `[[Note]]`, `[[Note|alias]]`, `[[Note#section]]` render as links in the preview (code blocks excluded)
|
||||||
|
- Clicking a wiki-link opens the note or offers to create it
|
||||||
|
- Backlinks sidebar panel scans the folder (bounded BFS) for documents linking to the current one
|
||||||
|
|
||||||
|
#### Crash Recovery / Session Restore
|
||||||
|
- Open tabs (paths + unsaved buffer content) snapshotted to localStorage, debounced on edits, on tab changes, on unload, and once a minute
|
||||||
|
- Restore prompt on launch with per-tab restore, clean-fresh option, and 2MB content budget
|
||||||
|
|
||||||
|
#### Document Version History
|
||||||
|
- Every save snapshots the previous on-disk content to `<userData>/versions/`
|
||||||
|
- History sidebar panel: list, restore (with safety snapshot), unified diff vs. current, delete, manual "save version now"
|
||||||
|
- Per-document pruning (20 versions), path-hash storage, id-validated reads
|
||||||
|
|
||||||
|
#### Editor
|
||||||
|
- Vim keybindings (View → Vim Mode, persisted, live toggle via CodeMirror Compartment)
|
||||||
|
- Snippet Tab-expansion: type a snippet name and press Tab to insert it
|
||||||
|
- Zen Mode word-goal setter (the HUD progress bar finally has UI)
|
||||||
|
|
||||||
|
#### Export / Conversion
|
||||||
|
- **Real PDF encryption**: pdf-lib swapped for @cantoo/pdf-lib — encrypt/decrypt/permissions now actually work (UI auto-enables via the capability probe)
|
||||||
|
- **XLSX export**: markdown tables → native Excel workbook, one sheet per table (no Pandoc needed)
|
||||||
|
- **ODT headers/footers + page size**: real ODF styles.xml patching replaces the empty stub
|
||||||
|
- **Local PlantUML rendering**: diagrams render on-machine via the `plantuml` CLI when installed; plantuml.com stays as fallback
|
||||||
|
- **KaTeX bundled locally** (CSS + fonts): math renders offline, no CDN calls
|
||||||
|
- Writing heatmap (GitHub-style 30-day grid) in the writing-studio Goals panel
|
||||||
|
|
||||||
|
#### Platform
|
||||||
|
- Quick Note global scratchpad (Ctrl+Alt+Q, works when unfocused; appends to `notes/quick-notes.md`)
|
||||||
|
- Deep link protocol `markdownconverter://open?path=…`
|
||||||
|
- REPL confirmation dialog before first code execution per language per session (unsandboxed-execution guard rail)
|
||||||
|
- Writing-studio's four sidebar panels (Manuscript/Goals/Snapshots/Proofread) are now actually wired with rail icons
|
||||||
|
- Plugin sidebar panels get automatic rail icons via `registerPanel({icon})`
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
- `Ctrl+Shift+P` collision: PDF (Enhanced) export now `Ctrl+Alt+Shift+P`; Command Palette keeps `Ctrl+Shift+P`
|
||||||
|
- Universal Converter's Pandoc tool no longer always reports "not installed" (`checkConverterAvailable` gained a pandoc case with bundled-binary check)
|
||||||
|
- CLI headless export: removed dangling `--css` / `--reference-doc` flags that made pandoc exit with an error; `--self-contained` replaced with `--standalone` (Pandoc 3.x)
|
||||||
|
- Removed dead "Open Export Options Dialog…" button from the converter dialog
|
||||||
|
- Removed duplicate `styles-zen.css` include
|
||||||
|
|
||||||
|
### Security
|
||||||
|
- AI provider requests carry size caps (200KB prompt), timeouts (120s), and user-safe error surfaces
|
||||||
|
- Version-history reads validate ids against traversal; history listing requires a valid document path
|
||||||
|
- PlantUML local rendering removes the diagram-text exfiltration path when a local CLI exists (CVE-MC-007 follow-up)
|
||||||
|
|
||||||
|
### Tests
|
||||||
|
- New suites: OdtStyling, AiProviders, ai-assistant prompts, collaboration comment-store, wiki-links/backlinks, session-store, XlsxExporter, VersionHistory
|
||||||
|
- PDFOperations encryption tests rewritten for the real-encryption reality
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Version 4.0.0 (2026-03-04)
|
||||||
|
|
||||||
|
### Major Changes
|
||||||
|
- **CodeMirror 6 Editor** — Replaced textarea with CodeMirror 6 featuring syntax highlighting, code folding, bracket matching, multiple cursors, and auto-indent
|
||||||
|
- **Sidebar Panel System** — Collapsible sidebar with File Explorer, Git, Snippets, and Templates panels
|
||||||
|
- **Command Palette** — Ctrl+Shift+P to search and execute all app actions
|
||||||
|
- **Code Execution (REPL)** — Run JavaScript, Python, and Bash code blocks directly from the preview
|
||||||
|
|
||||||
|
### New Features
|
||||||
|
- Print Preview dialog with paper size, orientation, margins, scale, and page range controls
|
||||||
|
- Image paste from clipboard and drag-drop support with auto-save to assets folder
|
||||||
|
- Document templates library (10 templates: blog post, meeting notes, tech spec, changelog, README, project plan, API docs, tutorial, release notes, comparison)
|
||||||
|
- Markdown extensions: footnotes, admonitions (note/warning/tip/danger/info), and [[toc]] table of contents
|
||||||
|
- PlantUML diagram rendering alongside Mermaid
|
||||||
|
- Welcome tab with onboarding and "What's New" feature showcase
|
||||||
|
- System spell checking with context menu suggestions and dictionary support
|
||||||
|
- Enhanced status bar with word count, character count, line/column, encoding, and language mode
|
||||||
|
- Grouped toolbar with visual section separators
|
||||||
|
- Breadcrumb bar showing current file path
|
||||||
|
|
||||||
|
### New Export/Import Formats
|
||||||
|
- Reveal.js slides (.html)
|
||||||
|
- Beamer slides (.pdf)
|
||||||
|
- Confluence/Jira wiki markup (.txt)
|
||||||
|
- MOBI e-books (via Calibre)
|
||||||
|
- Developer formats: JSON, YAML, XML, TOML
|
||||||
|
|
||||||
|
### Security
|
||||||
|
- Content Security Policy (CSP) meta tag
|
||||||
|
- File size validation (50MB limit)
|
||||||
|
- Error message sanitization (stripped file paths)
|
||||||
|
- Conversion rate limiting (2-second debounce)
|
||||||
|
|
||||||
|
### Dependencies Updated
|
||||||
|
- marked: 16.x to 17.x (with marked-highlight extension)
|
||||||
|
- pdfjs-dist: 3.x to 5.x (new worker model)
|
||||||
|
- html2pdf.js: 0.10 to 0.14
|
||||||
|
- pdfkit: 0.14 to 0.17
|
||||||
|
- dompurify, docx, and others updated to latest
|
||||||
|
|
||||||
|
### Testing
|
||||||
|
- 80 tests across 7 test suites
|
||||||
|
- New tests for sidebar manager, command palette, print preview, markdown extensions, and utility functions
|
||||||
|
|
||||||
|
### Breaking Changes
|
||||||
|
- Editor is now CodeMirror 6 (replaces textarea)
|
||||||
|
- marked API changed to use marked.use() instead of marked.setOptions()
|
||||||
|
- pdfjs-dist upgraded to v5 with new worker model
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## Version 2.1.0 (December 14, 2025)
|
## Version 2.1.0 (December 14, 2025)
|
||||||
|
|
||||||
### 🎨 UI/UX Improvements
|
### 🎨 UI/UX Improvements
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1,93 @@
|
|||||||
|
Copyright (c) 2014, The Fira Code Project Authors (https://github.com/tonsky/FiraCode)
|
||||||
|
|
||||||
|
This Font Software is licensed under the SIL Open Font License, Version 1.1.
|
||||||
|
This license is copied below, and is also available with a FAQ at:
|
||||||
|
http://scripts.sil.org/OFL
|
||||||
|
|
||||||
|
|
||||||
|
-----------------------------------------------------------
|
||||||
|
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
|
||||||
|
-----------------------------------------------------------
|
||||||
|
|
||||||
|
PREAMBLE
|
||||||
|
The goals of the Open Font License (OFL) are to stimulate worldwide
|
||||||
|
development of collaborative font projects, to support the font creation
|
||||||
|
efforts of academic and linguistic communities, and to provide a free and
|
||||||
|
open framework in which fonts may be shared and improved in partnership
|
||||||
|
with others.
|
||||||
|
|
||||||
|
The OFL allows the licensed fonts to be used, studied, modified and
|
||||||
|
redistributed freely as long as they are not sold by themselves. The
|
||||||
|
fonts, including any derivative works, can be bundled, embedded,
|
||||||
|
redistributed and/or sold with any software provided that any reserved
|
||||||
|
names are not used by derivative works. The fonts and derivatives,
|
||||||
|
however, cannot be released under any other type of license. The
|
||||||
|
requirement for fonts to remain under this license does not apply
|
||||||
|
to any document created using the fonts or their derivatives.
|
||||||
|
|
||||||
|
DEFINITIONS
|
||||||
|
"Font Software" refers to the set of files released by the Copyright
|
||||||
|
Holder(s) under this license and clearly marked as such. This may
|
||||||
|
include source files, build scripts and documentation.
|
||||||
|
|
||||||
|
"Reserved Font Name" refers to any names specified as such after the
|
||||||
|
copyright statement(s).
|
||||||
|
|
||||||
|
"Original Version" refers to the collection of Font Software components as
|
||||||
|
distributed by the Copyright Holder(s).
|
||||||
|
|
||||||
|
"Modified Version" refers to any derivative made by adding to, deleting,
|
||||||
|
or substituting -- in part or in whole -- any of the components of the
|
||||||
|
Original Version, by changing formats or by porting the Font Software to a
|
||||||
|
new environment.
|
||||||
|
|
||||||
|
"Author" refers to any designer, engineer, programmer, technical
|
||||||
|
writer or other person who contributed to the Font Software.
|
||||||
|
|
||||||
|
PERMISSION & CONDITIONS
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining
|
||||||
|
a copy of the Font Software, to use, study, copy, merge, embed, modify,
|
||||||
|
redistribute, and sell modified and unmodified copies of the Font
|
||||||
|
Software, subject to the following conditions:
|
||||||
|
|
||||||
|
1) Neither the Font Software nor any of its individual components,
|
||||||
|
in Original or Modified Versions, may be sold by itself.
|
||||||
|
|
||||||
|
2) Original or Modified Versions of the Font Software may be bundled,
|
||||||
|
redistributed and/or sold with any software, provided that each copy
|
||||||
|
contains the above copyright notice and this license. These can be
|
||||||
|
included either as stand-alone text files, human-readable headers or
|
||||||
|
in the appropriate machine-readable metadata fields within text or
|
||||||
|
binary files as long as those fields can be easily viewed by the user.
|
||||||
|
|
||||||
|
3) No Modified Version of the Font Software may use the Reserved Font
|
||||||
|
Name(s) unless explicit written permission is granted by the corresponding
|
||||||
|
Copyright Holder. This restriction only applies to the primary font name as
|
||||||
|
presented to the users.
|
||||||
|
|
||||||
|
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
|
||||||
|
Software shall not be used to promote, endorse or advertise any
|
||||||
|
Modified Version, except to acknowledge the contribution(s) of the
|
||||||
|
Copyright Holder(s) and the Author(s) or with their explicit written
|
||||||
|
permission.
|
||||||
|
|
||||||
|
5) The Font Software, modified or unmodified, in part or in whole,
|
||||||
|
must be distributed entirely under this license, and must not be
|
||||||
|
distributed under any other license. The requirement for fonts to
|
||||||
|
remain under this license does not apply to any document created
|
||||||
|
using the Font Software.
|
||||||
|
|
||||||
|
TERMINATION
|
||||||
|
This license becomes null and void if any of the above conditions are
|
||||||
|
not met.
|
||||||
|
|
||||||
|
DISCLAIMER
|
||||||
|
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||||||
|
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
|
||||||
|
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
|
||||||
|
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
|
||||||
|
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
|
||||||
|
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
|
||||||
|
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
||||||
|
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
|
||||||
|
OTHER DEALINGS IN THE FONT SOFTWARE.
|
||||||
File diff suppressed because one or more lines are too long
Binary file not shown.
@@ -0,0 +1,93 @@
|
|||||||
|
Copyright 2020 The JetBrains Mono Project Authors (https://github.com/JetBrains/JetBrainsMono)
|
||||||
|
|
||||||
|
This Font Software is licensed under the SIL Open Font License, Version 1.1.
|
||||||
|
This license is copied below, and is also available with a FAQ at:
|
||||||
|
https://scripts.sil.org/OFL
|
||||||
|
|
||||||
|
|
||||||
|
-----------------------------------------------------------
|
||||||
|
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
|
||||||
|
-----------------------------------------------------------
|
||||||
|
|
||||||
|
PREAMBLE
|
||||||
|
The goals of the Open Font License (OFL) are to stimulate worldwide
|
||||||
|
development of collaborative font projects, to support the font creation
|
||||||
|
efforts of academic and linguistic communities, and to provide a free and
|
||||||
|
open framework in which fonts may be shared and improved in partnership
|
||||||
|
with others.
|
||||||
|
|
||||||
|
The OFL allows the licensed fonts to be used, studied, modified and
|
||||||
|
redistributed freely as long as they are not sold by themselves. The
|
||||||
|
fonts, including any derivative works, can be bundled, embedded,
|
||||||
|
redistributed and/or sold with any software provided that any reserved
|
||||||
|
names are not used by derivative works. The fonts and derivatives,
|
||||||
|
however, cannot be released under any other type of license. The
|
||||||
|
requirement for fonts to remain under this license does not apply
|
||||||
|
to any document created using the fonts or their derivatives.
|
||||||
|
|
||||||
|
DEFINITIONS
|
||||||
|
"Font Software" refers to the set of files released by the Copyright
|
||||||
|
Holder(s) under this license and clearly marked as such. This may
|
||||||
|
include source files, build scripts and documentation.
|
||||||
|
|
||||||
|
"Reserved Font Name" refers to any names specified as such after the
|
||||||
|
copyright statement(s).
|
||||||
|
|
||||||
|
"Original Version" refers to the collection of Font Software components as
|
||||||
|
distributed by the Copyright Holder(s).
|
||||||
|
|
||||||
|
"Modified Version" refers to any derivative made by adding to, deleting,
|
||||||
|
or substituting -- in part or in whole -- any of the components of the
|
||||||
|
Original Version, by changing formats or by porting the Font Software to a
|
||||||
|
new environment.
|
||||||
|
|
||||||
|
"Author" refers to any designer, engineer, programmer, technical
|
||||||
|
writer or other person who contributed to the Font Software.
|
||||||
|
|
||||||
|
PERMISSION & CONDITIONS
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining
|
||||||
|
a copy of the Font Software, to use, study, copy, merge, embed, modify,
|
||||||
|
redistribute, and sell modified and unmodified copies of the Font
|
||||||
|
Software, subject to the following conditions:
|
||||||
|
|
||||||
|
1) Neither the Font Software nor any of its individual components,
|
||||||
|
in Original or Modified Versions, may be sold by itself.
|
||||||
|
|
||||||
|
2) Original or Modified Versions of the Font Software may be bundled,
|
||||||
|
redistributed and/or sold with any software, provided that each copy
|
||||||
|
contains the above copyright notice and this license. These can be
|
||||||
|
included either as stand-alone text files, human-readable headers or
|
||||||
|
in the appropriate machine-readable metadata fields within text or
|
||||||
|
binary files as long as those fields can be easily viewed by the user.
|
||||||
|
|
||||||
|
3) No Modified Version of the Font Software may use the Reserved Font
|
||||||
|
Name(s) unless explicit written permission is granted by the corresponding
|
||||||
|
Copyright Holder. This restriction only applies to the primary font name as
|
||||||
|
presented to the users.
|
||||||
|
|
||||||
|
4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
|
||||||
|
Software shall not be used to promote, endorse or advertise any
|
||||||
|
Modified Version, except to acknowledge the contribution(s) of the
|
||||||
|
Copyright Holder(s) and the Author(s) or with their explicit written
|
||||||
|
permission.
|
||||||
|
|
||||||
|
5) The Font Software, modified or unmodified, in part or in whole,
|
||||||
|
must be distributed entirely under this license, and must not be
|
||||||
|
distributed under any other license. The requirement for fonts to
|
||||||
|
remain under this license does not apply to any document created
|
||||||
|
using the Font Software.
|
||||||
|
|
||||||
|
TERMINATION
|
||||||
|
This license becomes null and void if any of the above conditions are
|
||||||
|
not met.
|
||||||
|
|
||||||
|
DISCLAIMER
|
||||||
|
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||||||
|
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
|
||||||
|
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
|
||||||
|
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
|
||||||
|
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
|
||||||
|
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
|
||||||
|
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
||||||
|
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
|
||||||
|
OTHER DEALINGS IN THE FONT SOFTWARE.
|
||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Vendored
+1
File diff suppressed because one or more lines are too long
@@ -0,0 +1,866 @@
|
|||||||
|
# MarkdownConverter - STRIDE Threat Model Analysis
|
||||||
|
|
||||||
|
**Version:** 4.1.0
|
||||||
|
**Date:** 2026-03-15
|
||||||
|
**Methodology:** STRIDE + MITRE ATT&CK Mapping
|
||||||
|
**Analyst:** Security Assessment Team
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Executive Summary
|
||||||
|
|
||||||
|
This threat model analyzes the MarkdownConverter Electron application using the STRIDE methodology. The assessment identified **10 critical vulnerabilities** with CVSS scores ranging from 3.5 to 9.6. The most severe threats involve insecure Electron configuration (CVE-MC-001) and arbitrary code execution via REPL (CVE-MC-002), which could allow complete system compromise.
|
||||||
|
|
||||||
|
**Risk Summary:**
|
||||||
|
| Severity | Count | Total CVSS Impact |
|
||||||
|
|----------|-------|-------------------|
|
||||||
|
| Critical (9.0+) | 2 | 18.9 |
|
||||||
|
| High (7.0-8.9) | 3 | 23.3 |
|
||||||
|
| Medium (5.0-6.9) | 3 | 17.3 |
|
||||||
|
| Low (<5.0) | 2 | 7.9 |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 1. System Architecture Overview
|
||||||
|
|
||||||
|
### 1.1 Application Components
|
||||||
|
|
||||||
|
```
|
||||||
|
+------------------------------------------------------------------+
|
||||||
|
| MarkdownConverter v4.0.0 |
|
||||||
|
+------------------------------------------------------------------+
|
||||||
|
| |
|
||||||
|
| +------------------+ +------------------+ |
|
||||||
|
| | Main Process |<--->| Renderer Process| |
|
||||||
|
| | (Node.js) | | (Chromium) | |
|
||||||
|
| +------------------+ +------------------+ |
|
||||||
|
| | | |
|
||||||
|
| | IPC Channels | |
|
||||||
|
| v v |
|
||||||
|
| +------------------+ +------------------+ |
|
||||||
|
| | preload.js | | renderer.js | |
|
||||||
|
| | (Bridge Layer) | | (UI Logic) | |
|
||||||
|
| +------------------+ +------------------+ |
|
||||||
|
| | | |
|
||||||
|
| v v |
|
||||||
|
| +--------------------------------------------------+ |
|
||||||
|
| | External Tools | |
|
||||||
|
| | Pandoc | FFmpeg | ImageMagick | LibreOffice | |
|
||||||
|
| +--------------------------------------------------+ |
|
||||||
|
| |
|
||||||
|
+------------------------------------------------------------------+
|
||||||
|
|
|
||||||
|
v
|
||||||
|
+------------------------------------------------------------------+
|
||||||
|
| External Services |
|
||||||
|
| - plantuml.com (diagram rendering) |
|
||||||
|
| - cdn.jsdelivr.net (scripts) |
|
||||||
|
| - cdnjs.cloudflare.com (styles) |
|
||||||
|
+------------------------------------------------------------------+
|
||||||
|
```
|
||||||
|
|
||||||
|
### 1.2 Data Flow Diagram (Level 1)
|
||||||
|
|
||||||
|
```
|
||||||
|
TRUST BOUNDARY
|
||||||
|
|
|
||||||
|
+-----------+ | +-----------+
|
||||||
|
| User | | | System |
|
||||||
|
| (Author) |------------------>|------------------>| Files |
|
||||||
|
+-----------+ Markdown | File I/O +-----------+
|
||||||
|
Content |
|
||||||
|
|
|
||||||
|
+---------------+---------------+
|
||||||
|
| |
|
||||||
|
v v
|
||||||
|
+---------------+ +---------------+
|
||||||
|
| Editor | | Preview |
|
||||||
|
| (CodeMirror) | | (Rendered) |
|
||||||
|
+---------------+ +---------------+
|
||||||
|
| ^
|
||||||
|
| Sanitization |
|
||||||
|
| (DOMPurify) |
|
||||||
|
v |
|
||||||
|
+---------------+ |
|
||||||
|
| Renderer |-----------------------+
|
||||||
|
| Process | HTML/SVG
|
||||||
|
+---------------+
|
||||||
|
|
|
||||||
|
| IPC (Whitelisted Channels)
|
||||||
|
v
|
||||||
|
+---------------+ +-----------+
|
||||||
|
| Main |-------------->| Pandoc |
|
||||||
|
| Process | execFile | FFmpeg |
|
||||||
|
| (Node.js) | | etc. |
|
||||||
|
+---------------+ +-----------+
|
||||||
|
|
|
||||||
|
| HTTPS
|
||||||
|
v
|
||||||
|
+---------------+
|
||||||
|
| PlantUML |
|
||||||
|
| Server |
|
||||||
|
| (External) |
|
||||||
|
+---------------+
|
||||||
|
```
|
||||||
|
|
||||||
|
### 1.3 Trust Boundaries
|
||||||
|
|
||||||
|
```
|
||||||
|
+============================================================================+
|
||||||
|
|| TRUST BOUNDARY 1: User <-> Application ||
|
||||||
|
|| - User input (markdown content) is UNTRUSTED ||
|
||||||
|
|| - File paths from dialogs are PARTIALLY TRUSTED ||
|
||||||
|
+============================================================================+
|
||||||
|
|
|
||||||
|
v
|
||||||
|
+============================================================================+
|
||||||
|
|| TRUST BOUNDARY 2: Renderer <-> Main Process ||
|
||||||
|
|| - IPC communication via preload.js ||
|
||||||
|
|| - CRITICAL: nodeIntegration=true bypasses isolation ||
|
||||||
|
+============================================================================+
|
||||||
|
|
|
||||||
|
v
|
||||||
|
+============================================================================+
|
||||||
|
|| TRUST BOUNDARY 3: Application <-> System ||
|
||||||
|
|| - External tool execution (Pandoc, FFmpeg, etc.) ||
|
||||||
|
|| - File system access ||
|
||||||
|
+============================================================================+
|
||||||
|
|
|
||||||
|
v
|
||||||
|
+============================================================================+
|
||||||
|
|| TRUST BOUNDARY 4: Application <-> Internet ||
|
||||||
|
|| - PlantUML server (https://www.plantuml.com) ||
|
||||||
|
|| - CDN resources (jsdelivr, cdnjs) ||
|
||||||
|
+============================================================================+
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 2. STRIDE Analysis
|
||||||
|
|
||||||
|
### 2.1 Spoofing
|
||||||
|
|
||||||
|
| ID | Threat | Description | CVE | CVSS |
|
||||||
|
|----|--------|-------------|-----|------|
|
||||||
|
| S-01 | **PlantUML Server Spoofing** | Application sends diagram content to external PlantUML server. MITM or compromised server could return malicious SVG content. | CVE-MC-007 | 5.3 |
|
||||||
|
| S-02 | **CDN Compromise** | Scripts loaded from cdn.jsdelivr.net and styles from cdnjs.cloudflare.com could be compromised in supply chain attack. | - | 6.5 |
|
||||||
|
|
||||||
|
**Attack Tree - S-01 PlantUML Data Exfiltration:**
|
||||||
|
|
||||||
|
```
|
||||||
|
GOAL: Exfiltrate sensitive data via PlantUML rendering
|
||||||
|
│
|
||||||
|
├── [1] Intercept network traffic (MITM)
|
||||||
|
│ ├── [1.1] Exploit weak TLS implementation
|
||||||
|
│ └── [1.1] DNS hijacking
|
||||||
|
│
|
||||||
|
├── [2] Compromise PlantUML server
|
||||||
|
│ ├── [2.1] Server breach
|
||||||
|
│ └── [2.2] Supply chain compromise
|
||||||
|
│
|
||||||
|
└── [3] Inject malicious SVG response
|
||||||
|
├── [3.1] XSS via SVG onload
|
||||||
|
└── [3.2] Data exfiltration via image src
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.2 Tampering
|
||||||
|
|
||||||
|
| ID | Threat | Description | CVE | CVSS |
|
||||||
|
|----|--------|-------------|-----|------|
|
||||||
|
| T-01 | **Markdown Content Tampering** | XSS in markdown rendering could modify rendered content or inject malicious scripts. | CVE-MC-003 | 8.0 |
|
||||||
|
| T-02 | **File Tampering via Path Traversal** | Missing path validation could allow writing to arbitrary locations. | CVE-MC-004 | 7.8 |
|
||||||
|
| T-03 | **REPL Code Injection** | Arbitrary code execution via REPL feature allows system modification. | CVE-MC-002 | 9.3 |
|
||||||
|
|
||||||
|
**Attack Tree - T-03 REPL Code Injection:**
|
||||||
|
|
||||||
|
```
|
||||||
|
GOAL: Achieve arbitrary code execution via REPL
|
||||||
|
│
|
||||||
|
├── [1] User opens malicious markdown file
|
||||||
|
│ ├── [1.1] Phishing/social engineering
|
||||||
|
│ └── [1.2] Malicious file from untrusted source
|
||||||
|
│
|
||||||
|
├── [2] Malicious code block rendered in preview
|
||||||
|
│ ├── [2.1] JavaScript code block
|
||||||
|
│ ├── [2.2] Python code block
|
||||||
|
│ └── [2.3] Bash/Shell code block
|
||||||
|
│
|
||||||
|
├── [3] User clicks "Run" button
|
||||||
|
│
|
||||||
|
└── [4] Code executed on main process
|
||||||
|
├── [4.1] File system access
|
||||||
|
├── [4.2] Process execution
|
||||||
|
└── [4.3] Network access
|
||||||
|
└── [4.3.1] Data exfiltration
|
||||||
|
└── [4.3.2] C2 communication
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.3 Repudiation
|
||||||
|
|
||||||
|
| ID | Threat | Description | CVE | CVSS |
|
||||||
|
|----|--------|-------------|-----|------|
|
||||||
|
| R-01 | **Missing Audit Logging** | No logging of security-relevant events (file access, code execution, exports). | - | 4.0 |
|
||||||
|
| R-02 | **REPL Execution No Audit Trail** | Code executed via REPL leaves no persistent audit log. | CVE-MC-002 | 5.0 |
|
||||||
|
|
||||||
|
### 2.4 Information Disclosure
|
||||||
|
|
||||||
|
| ID | Threat | Description | CVE | CVSS |
|
||||||
|
|----|--------|-------------|-----|------|
|
||||||
|
| I-01 | **Path Disclosure in Error Messages** | Error messages may expose absolute file paths. Partially mitigated by `sanitizeErrorMessage()`. | - | 4.5 |
|
||||||
|
| I-02 | **PlantUML Data Leakage** | Diagram content sent to external server could contain sensitive information. | CVE-MC-007 | 5.3 |
|
||||||
|
| I-03 | **CSP Allows External Connections** | Weak CSP allows data exfiltration via `connect-src 'self' https://www.plantuml.com`. | CVE-MC-005 | 7.5 |
|
||||||
|
|
||||||
|
**Data Flow - Information Disclosure via PlantUML:**
|
||||||
|
|
||||||
|
```
|
||||||
|
+-------------+ Encoded Diagram +------------------+
|
||||||
|
| Renderer | ----------------------> | www.plantuml.com |
|
||||||
|
| Process | (~h encoded) | (External) |
|
||||||
|
+-------------+ +------------------+
|
||||||
|
| |
|
||||||
|
| Sensitive data in diagram: |
|
||||||
|
| - Architecture details |
|
||||||
|
| - Database schemas |
|
||||||
|
| - API endpoints |
|
||||||
|
| - Class names/relationships |
|
||||||
|
v v
|
||||||
|
+-------------+ +-------------+
|
||||||
|
| Attacker | <--- Network Capture -- | Network |
|
||||||
|
| (MITM) | | Traffic |
|
||||||
|
+-------------+ +-------------+
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.5 Denial of Service
|
||||||
|
|
||||||
|
| ID | Threat | Description | CVE | CVSS |
|
||||||
|
|----|--------|-------------|-----|------|
|
||||||
|
| D-01 | **REPL Resource Exhaustion** | Code execution has 10s timeout but could consume CPU/memory. | CVE-MC-002 | 4.5 |
|
||||||
|
| D-02 | **Large File Processing** | Files up to 50MB allowed, could cause memory exhaustion during conversion. | - | 5.0 |
|
||||||
|
| D-03 | **Infinite Loop in Markdown** | Malicious markdown could cause rendering loops. | - | 4.0 |
|
||||||
|
|
||||||
|
### 2.6 Elevation of Privilege
|
||||||
|
|
||||||
|
| ID | Threat | Description | CVE | CVSS |
|
||||||
|
|----|--------|-------------|-----|------|
|
||||||
|
| E-01 | **Insecure Electron Configuration** | `nodeIntegration: true` + `contextIsolation: false` allows full Node.js access from renderer. | CVE-MC-001 | 9.6 |
|
||||||
|
| E-02 | **XSS to RCE Chain** | XSS vulnerability combined with E-01 enables remote code execution. | CVE-MC-003 + CVE-MC-001 | 9.8 |
|
||||||
|
| E-03 | **External Tool Command Injection** | While using `execFile`, improper input validation could still pose risks. | CVE-MC-009 | 4.4 |
|
||||||
|
| E-04 | **Inconsistent Window Security** | PDF export windows use insecure settings (nodeIntegration: true). | CVE-MC-006 | 6.5 |
|
||||||
|
|
||||||
|
**Attack Tree - E-01/E-02 XSS to RCE Chain:**
|
||||||
|
|
||||||
|
```
|
||||||
|
GOAL: Remote Code Execution via XSS -> RCE Chain
|
||||||
|
│
|
||||||
|
├── [1] Inject malicious script (XSS)
|
||||||
|
│ ├── [1.1] Via malicious markdown file
|
||||||
|
│ │ ├── HTML injection
|
||||||
|
│ │ ├── SVG with script
|
||||||
|
│ │ └── DOMPurify bypass
|
||||||
|
│ │
|
||||||
|
│ └── [1.2] Via PlantUML SVG response
|
||||||
|
│ └── Compromised server returns malicious SVG
|
||||||
|
│
|
||||||
|
├── [2] Execute in renderer context
|
||||||
|
│ └── [2.1] Script runs with nodeIntegration=true
|
||||||
|
│ ├── Direct require() access
|
||||||
|
│ ├── child_process.exec()
|
||||||
|
│ └── fs module access
|
||||||
|
│
|
||||||
|
└── [3] Achieve RCE
|
||||||
|
├── [3.1] Execute system commands
|
||||||
|
├── [3.2] Read/write arbitrary files
|
||||||
|
├── [3.3] Install persistence mechanisms
|
||||||
|
└── [3.4] Lateral movement
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 3. Attack Scenarios
|
||||||
|
|
||||||
|
### 3.1 Scenario: Malicious Markdown Document (Critical)
|
||||||
|
|
||||||
|
**Attack Chain:**
|
||||||
|
|
||||||
|
```
|
||||||
|
1. Attacker creates malicious.md containing:
|
||||||
|
- Embedded JavaScript in markdown
|
||||||
|
- Malicious code blocks (JavaScript/Python/Bash)
|
||||||
|
|
||||||
|
2. Victim opens file in MarkdownConverter
|
||||||
|
|
||||||
|
3. XSS payload executes due to:
|
||||||
|
- CVE-MC-003: Potential XSS in markdown rendering
|
||||||
|
- CVE-MC-001: nodeIntegration=true allows Node.js access
|
||||||
|
|
||||||
|
4. Payload executes system commands:
|
||||||
|
- Exfiltrates sensitive files
|
||||||
|
- Installs backdoor
|
||||||
|
- Establishes persistence
|
||||||
|
|
||||||
|
5. Impact: Complete system compromise
|
||||||
|
```
|
||||||
|
|
||||||
|
**MITRE ATT&CK Mapping:**
|
||||||
|
|
||||||
|
| Tactic | Technique | ID | Description |
|
||||||
|
|--------|-----------|-----|-------------|
|
||||||
|
| Initial Access | Phishing | T1566 | Malicious file via email |
|
||||||
|
| Execution | User Execution | T1204 | Victim opens malicious file |
|
||||||
|
| Execution | Command/Scripting | T1059 | JavaScript/Python execution |
|
||||||
|
| Persistence | Registry Run Keys | T1547 | Establish persistence |
|
||||||
|
| Collection | Data from Local System | T1005 | File exfiltration |
|
||||||
|
| Exfiltration | Exfiltration Over C2 | T1041 | Data sent to attacker |
|
||||||
|
|
||||||
|
### 3.2 Scenario: REPL Code Execution (Critical)
|
||||||
|
|
||||||
|
**Attack Chain:**
|
||||||
|
|
||||||
|
```
|
||||||
|
1. Social engineering: Attacker convinces user to:
|
||||||
|
- Open a "configuration guide" markdown file
|
||||||
|
- Run the code examples to "verify setup"
|
||||||
|
|
||||||
|
2. Markdown contains malicious code blocks:
|
||||||
|
```javascript
|
||||||
|
const fs = require('fs');
|
||||||
|
const https = require('https');
|
||||||
|
// Exfiltrate SSH keys
|
||||||
|
```
|
||||||
|
|
||||||
|
3. User clicks "Run" button on code block
|
||||||
|
|
||||||
|
4. Code executes via 'execute-code' IPC handler:
|
||||||
|
- CVE-MC-002: Arbitrary code execution via REPL
|
||||||
|
- No sandboxing or permission checks
|
||||||
|
|
||||||
|
5. Impact: Credential theft, data exfiltration
|
||||||
|
```
|
||||||
|
|
||||||
|
**MITRE ATT&CK Mapping:**
|
||||||
|
|
||||||
|
| Tactic | Technique | ID | Description |
|
||||||
|
|--------|-----------|-----|-------------|
|
||||||
|
| Initial Access | Phishing | T1566 | Social engineering |
|
||||||
|
| Execution | Command/Scripting | T1059.004 | Bash execution |
|
||||||
|
| Execution | Command/Scripting | T1059.007 | JavaScript/Node execution |
|
||||||
|
| Credential Access | Credentials from Files | T1083 | SSH key theft |
|
||||||
|
| Exfiltration | Exfiltration Over Web Service | T1567 | HTTPS exfiltration |
|
||||||
|
|
||||||
|
### 3.3 Scenario: PlantUML Data Exfiltration (Medium)
|
||||||
|
|
||||||
|
**Attack Chain:**
|
||||||
|
|
||||||
|
```
|
||||||
|
1. User creates architecture diagram in PlantUML:
|
||||||
|
- Contains sensitive system design
|
||||||
|
- Database schemas
|
||||||
|
- API endpoints
|
||||||
|
|
||||||
|
2. Renderer encodes and sends to www.plantuml.com:
|
||||||
|
- CVE-MC-007: Data sent to external server
|
||||||
|
|
||||||
|
3. Attacker (MITM or compromised server):
|
||||||
|
- Captures diagram content
|
||||||
|
- Extracts sensitive information
|
||||||
|
|
||||||
|
4. Impact: Intellectual property theft, reconnaissance
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.4 Scenario: PDF Export Window Exploitation (Medium)
|
||||||
|
|
||||||
|
**Attack Chain:**
|
||||||
|
|
||||||
|
```
|
||||||
|
1. User exports document to PDF
|
||||||
|
|
||||||
|
2. Hidden PDF export window created with:
|
||||||
|
- CVE-MC-006: nodeIntegration: true
|
||||||
|
- CVE-MC-008: contextIsolation: false
|
||||||
|
|
||||||
|
3. If malicious content in document:
|
||||||
|
- Script execution in PDF window
|
||||||
|
- Access to Node.js APIs
|
||||||
|
|
||||||
|
4. Impact: Code execution during export process
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 4. Risk Matrix & Prioritization
|
||||||
|
|
||||||
|
### 4.1 Vulnerability Risk Matrix
|
||||||
|
|
||||||
|
```
|
||||||
|
IMPACT
|
||||||
|
Low Medium High Critical
|
||||||
|
(1-3) (4-6) (7-8) (9-10)
|
||||||
|
+------------+------------+--------------+-------------+
|
||||||
|
High | CVE-MC-010 | CVE-MC-007 | CVE-MC-005 | CVE-MC-001 |
|
||||||
|
(0.7-1.0) | 3.5 | 5.3 | 7.5 | 9.6 |
|
||||||
|
| DEPENDENCY | INFOSEC | CSP | CONFIG |
|
||||||
|
+------------+------------+--------------+-------------+
|
||||||
|
| | CVE-MC-006 | CVE-MC-003 | CVE-MC-002 |
|
||||||
|
LIKELIHOOD | | 6.5 | 8.0 | 9.3 |
|
||||||
|
(0.4-0.6) | | PDF-WIN | XSS | REPL |
|
||||||
|
+------------+------------+--------------+-------------+
|
||||||
|
Medium | | CVE-MC-008 | CVE-MC-004 | |
|
||||||
|
(0.2-0.4) | | 5.5 | 7.8 | |
|
||||||
|
| | INCONSIST | PATH-TRAV | |
|
||||||
|
+------------+------------+--------------+-------------+
|
||||||
|
Low | | | CVE-MC-009 | |
|
||||||
|
(0-0.2) | | | 4.4 | |
|
||||||
|
| | | CMD-EXEC | |
|
||||||
|
+------------+------------+--------------+-------------+
|
||||||
|
```
|
||||||
|
|
||||||
|
### 4.2 Prioritized Remediation List
|
||||||
|
|
||||||
|
| Priority | CVE | Vulnerability | CVSS | Effort | Risk Reduction |
|
||||||
|
|----------|-----|---------------|------|--------|----------------|
|
||||||
|
| P0 | CVE-MC-001 | Insecure Electron Config | 9.6 | Medium | Critical |
|
||||||
|
| P0 | CVE-MC-002 | REPL Code Execution | 9.3 | High | Critical |
|
||||||
|
| P1 | CVE-MC-003 | XSS in Markdown | 8.0 | Medium | High |
|
||||||
|
| P1 | CVE-MC-004 | Path Traversal | 7.8 | Low | High |
|
||||||
|
| P1 | CVE-MC-005 | Weak CSP | 7.5 | Medium | High |
|
||||||
|
| P2 | CVE-MC-006 | PDF Window Config | 6.5 | Low | Medium |
|
||||||
|
| P2 | CVE-MC-008 | Inconsistent Settings | 5.5 | Low | Medium |
|
||||||
|
| P2 | CVE-MC-007 | PlantUML Exfiltration | 5.3 | Medium | Medium |
|
||||||
|
| P3 | CVE-MC-009 | External Tool Execution | 4.4 | Low | Low |
|
||||||
|
| P3 | CVE-MC-010 | Dependency Versioning | 3.5 | Low | Low |
|
||||||
|
|
||||||
|
### 4.3 Risk Score Calculation
|
||||||
|
|
||||||
|
```
|
||||||
|
Overall Application Risk Score: 7.8 (HIGH)
|
||||||
|
|
||||||
|
Calculation:
|
||||||
|
- Weighted by exploitability and impact
|
||||||
|
- P0 issues weighted 3x
|
||||||
|
- P1 issues weighted 2x
|
||||||
|
- P2 issues weighted 1x
|
||||||
|
- P3 issues weighted 0.5x
|
||||||
|
|
||||||
|
Risk = (9.6*3 + 9.3*3 + 8.0*2 + 7.8*2 + 7.5*2 + 6.5 + 5.5 + 5.3 + 4.4*0.5 + 3.5*0.5) / 17
|
||||||
|
= (28.8 + 27.9 + 16.0 + 15.6 + 15.0 + 6.5 + 5.5 + 5.3 + 2.2 + 1.75) / 17
|
||||||
|
= 124.55 / 17
|
||||||
|
= 7.33 (adjusted to 7.8 with environmental factors)
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 5. Business Impact Analysis
|
||||||
|
|
||||||
|
### 5.1 Impact Categories
|
||||||
|
|
||||||
|
| Category | Description | Affected CVEs | Impact Level |
|
||||||
|
|----------|-------------|---------------|--------------|
|
||||||
|
| **Data Confidentiality** | Unauthorized access to sensitive documents | CVE-MC-001,002,003,007 | Critical |
|
||||||
|
| **Data Integrity** | Modification of documents or system files | CVE-MC-001,002,004 | Critical |
|
||||||
|
| **System Availability** | Application or system unavailability | CVE-MC-002,009 | Medium |
|
||||||
|
| **Compliance** | Regulatory violations (GDPR, HIPAA) | CVE-MC-001,002,007 | High |
|
||||||
|
| **Reputation** | Trust damage from security incidents | All CVEs | High |
|
||||||
|
| **Financial** | Direct costs from breaches | CVE-MC-001,002,003 | Critical |
|
||||||
|
|
||||||
|
### 5.2 Business Impact by Attack Type
|
||||||
|
|
||||||
|
#### Complete System Compromise (CVE-MC-001 + CVE-MC-002)
|
||||||
|
```
|
||||||
|
Financial Impact:
|
||||||
|
- Incident response: $50,000 - $200,000
|
||||||
|
- Data breach notification: $100,000+
|
||||||
|
- Regulatory fines: Up to 4% annual revenue (GDPR)
|
||||||
|
- Legal fees: $100,000 - $500,000
|
||||||
|
- Business disruption: $10,000/day
|
||||||
|
|
||||||
|
Reputational Impact:
|
||||||
|
- Customer trust erosion
|
||||||
|
- Market share loss
|
||||||
|
- Brand damage
|
||||||
|
|
||||||
|
Estimated Total: $500,000 - $5,000,000+
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Data Exfiltration via PlantUML (CVE-MC-007)
|
||||||
|
```
|
||||||
|
Financial Impact:
|
||||||
|
- Intellectual property theft
|
||||||
|
- Competitive disadvantage
|
||||||
|
- Remediation costs: $20,000 - $50,000
|
||||||
|
|
||||||
|
Reputational Impact:
|
||||||
|
- Customer concerns about data handling
|
||||||
|
- Potential contract violations
|
||||||
|
|
||||||
|
Estimated Total: $50,000 - $500,000
|
||||||
|
```
|
||||||
|
|
||||||
|
#### XSS Attack (CVE-MC-003)
|
||||||
|
```
|
||||||
|
Financial Impact:
|
||||||
|
- Session hijacking remediation
|
||||||
|
- Credential reset costs
|
||||||
|
- Monitoring enhancement
|
||||||
|
|
||||||
|
Estimated Total: $10,000 - $100,000
|
||||||
|
```
|
||||||
|
|
||||||
|
### 5.3 Risk Tolerance Matrix
|
||||||
|
|
||||||
|
| Asset | Criticality | Current Risk | Tolerance | Gap |
|
||||||
|
|-------|-------------|--------------|-----------|-----|
|
||||||
|
| User Documents | High | Critical | Low | **HIGH** |
|
||||||
|
| System Integrity | Critical | Critical | Very Low | **CRITICAL** |
|
||||||
|
| User Credentials | Critical | High | Very Low | **HIGH** |
|
||||||
|
| Application Availability | Medium | Medium | Medium | Low |
|
||||||
|
| Network Communication | Medium | Medium | Low | Medium |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 6. MITRE ATT&CK Framework Mapping
|
||||||
|
|
||||||
|
### 6.1 Complete Technique Mapping
|
||||||
|
|
||||||
|
| Tactic | Technique | ID | CVE Reference | Detection | Mitigation |
|
||||||
|
|--------|-----------|-----|---------------|-----------|------------|
|
||||||
|
| **Initial Access** |
|
||||||
|
| | Phishing | T1566 | CVE-MC-003 | Email filtering | User training |
|
||||||
|
| | Valid Accounts | T1078 | N/A | Auth logging | MFA |
|
||||||
|
| **Execution** |
|
||||||
|
| | Command/Scripting Interpreter | T1059 | CVE-MC-002 | Process monitoring | Disable REPL |
|
||||||
|
| | JavaScript | T1059.007 | CVE-MC-001,003 | CSP violations | Enable contextIsolation |
|
||||||
|
| | Python | T1059.006 | CVE-MC-002 | Process monitoring | Sandboxing |
|
||||||
|
| | Bash | T1059.004 | CVE-MC-002 | Process monitoring | Input validation |
|
||||||
|
| **Persistence** |
|
||||||
|
| | Registry Run Keys | T1547.001 | Post-CVE-MC-001 | Registry monitoring | Principle of least privilege |
|
||||||
|
| | Scheduled Task | T1053 | Post-CVE-MC-001 | Task monitoring | Application hardening |
|
||||||
|
| **Defense Evasion** |
|
||||||
|
| | Obfuscated Files | T1027 | CVE-MC-003 | Content inspection | Strict CSP |
|
||||||
|
| **Credential Access** |
|
||||||
|
| | Credentials from Files | T1083 | CVE-MC-002 | File access monitoring | Isolate secrets |
|
||||||
|
| **Discovery** |
|
||||||
|
| | File and Directory Discovery | T1083 | CVE-MC-001,002 | File monitoring | Sandbox |
|
||||||
|
| | System Information Discovery | T1082 | CVE-MC-002 | Process monitoring | Disable REPL |
|
||||||
|
| **Collection** |
|
||||||
|
| | Data from Local System | T1005 | CVE-MC-002 | DLP | Access controls |
|
||||||
|
| **Command and Control** |
|
||||||
|
| | Application Layer Protocol | T1071 | CVE-MC-007 | Network monitoring | Disable external services |
|
||||||
|
| **Exfiltration** |
|
||||||
|
| | Exfiltration Over Web Service | T1567 | CVE-MC-007 | Network monitoring | Block external connections |
|
||||||
|
| | Exfiltration Over C2 | T1041 | Post-exploitation | EDR | Network segmentation |
|
||||||
|
|
||||||
|
### 6.2 Attack Flow Diagram
|
||||||
|
|
||||||
|
```
|
||||||
|
+------------------+ +------------------+ +------------------+
|
||||||
|
| INITIAL | | EXECUTION | | PERSISTENCE |
|
||||||
|
| ACCESS | | | | |
|
||||||
|
| | | | | |
|
||||||
|
| T1566 Phishing |---->| T1059.007 JS |---->| T1547.001 Reg |
|
||||||
|
| T1204 User Exec | | T1059.004 Bash | | T1053 Sched Task |
|
||||||
|
| | | T1059.006 Python | | |
|
||||||
|
+------------------+ +------------------+ +------------------+
|
||||||
|
|
|
||||||
|
v
|
||||||
|
+------------------+ +------------------+ +------------------+
|
||||||
|
| COLLECTION |<----| DISCOVERY | | C2 |
|
||||||
|
| | | | | |
|
||||||
|
| T1005 Local Data | | T1083 File Disc | | T1071 HTTPS |
|
||||||
|
| T1083 Creds File | | T1082 Sys Info | | |
|
||||||
|
+------------------+ +------------------+ +------------------+
|
||||||
|
|
|
||||||
|
v
|
||||||
|
+------------------+
|
||||||
|
| EXFILTRATION |
|
||||||
|
| |
|
||||||
|
| T1567 Web Service|
|
||||||
|
| T1041 Over C2 |
|
||||||
|
+------------------+
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 7. Security Requirements & Mitigations
|
||||||
|
|
||||||
|
### 7.1 Critical Mitigations (P0)
|
||||||
|
|
||||||
|
#### CVE-MC-001: Insecure Electron Configuration
|
||||||
|
|
||||||
|
**Current State:**
|
||||||
|
```javascript
|
||||||
|
// main.js:328-331
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: true,
|
||||||
|
contextIsolation: false,
|
||||||
|
spellcheck: true
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Required Changes:**
|
||||||
|
```javascript
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: false, // REQUIRED
|
||||||
|
contextIsolation: true, // REQUIRED
|
||||||
|
sandbox: true, // RECOMMENDED
|
||||||
|
spellcheck: true
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Migration Path:**
|
||||||
|
1. Update preload.js to expose all required APIs
|
||||||
|
2. Update renderer.js to use exposed APIs instead of require()
|
||||||
|
3. Test all functionality
|
||||||
|
4. Deploy in stages
|
||||||
|
|
||||||
|
#### CVE-MC-002: REPL Code Execution
|
||||||
|
|
||||||
|
**Mitigation Options:**
|
||||||
|
|
||||||
|
| Option | Security | Usability | Effort |
|
||||||
|
|--------|----------|-----------|--------|
|
||||||
|
| Disable REPL entirely | Highest | None | Low |
|
||||||
|
| Sandbox with restricted permissions | High | High | High |
|
||||||
|
| Add execution confirmation dialog | Medium | High | Low |
|
||||||
|
| Require admin password | Medium | Medium | Medium |
|
||||||
|
| Log all executions | Low | High | Low |
|
||||||
|
|
||||||
|
**Recommended Approach:**
|
||||||
|
1. Add user confirmation dialog with code preview
|
||||||
|
2. Implement execution sandboxing (Docker/container)
|
||||||
|
3. Add audit logging
|
||||||
|
4. Restrict available modules
|
||||||
|
|
||||||
|
### 7.2 High Priority Mitigations (P1)
|
||||||
|
|
||||||
|
#### CVE-MC-003: XSS in Markdown
|
||||||
|
|
||||||
|
**Current Mitigations:**
|
||||||
|
- DOMPurify sanitization
|
||||||
|
|
||||||
|
**Additional Required:**
|
||||||
|
```javascript
|
||||||
|
// Enhanced DOMPurify configuration
|
||||||
|
const purifyConfig = {
|
||||||
|
ALLOWED_TAGS: [...],
|
||||||
|
ALLOWED_ATTR: [...],
|
||||||
|
FORBID_TAGS: ['script', 'iframe', 'object', 'embed'],
|
||||||
|
FORBID_ATTR: ['onerror', 'onload', 'onclick'],
|
||||||
|
ADD_ATTR: ['target'],
|
||||||
|
FORCE_BODY: true
|
||||||
|
};
|
||||||
|
```
|
||||||
|
|
||||||
|
#### CVE-MC-005: Weak CSP
|
||||||
|
|
||||||
|
**Current CSP:**
|
||||||
|
```
|
||||||
|
default-src 'self';
|
||||||
|
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net;
|
||||||
|
style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com;
|
||||||
|
img-src 'self' data: blob: file:;
|
||||||
|
font-src 'self' data:;
|
||||||
|
connect-src 'self' https://www.plantuml.com;
|
||||||
|
```
|
||||||
|
|
||||||
|
**Recommended CSP:**
|
||||||
|
```
|
||||||
|
default-src 'self';
|
||||||
|
script-src 'self';
|
||||||
|
style-src 'self';
|
||||||
|
img-src 'self' data:;
|
||||||
|
font-src 'self';
|
||||||
|
connect-src 'self';
|
||||||
|
frame-src 'none';
|
||||||
|
object-src 'none';
|
||||||
|
base-uri 'self';
|
||||||
|
form-action 'self';
|
||||||
|
```
|
||||||
|
|
||||||
|
**Note:** This requires:
|
||||||
|
- Bundling all dependencies locally
|
||||||
|
- Removing PlantUML server dependency (use local rendering)
|
||||||
|
- Removing unsafe-inline and unsafe-eval
|
||||||
|
|
||||||
|
### 7.3 Medium Priority Mitigations (P2)
|
||||||
|
|
||||||
|
#### CVE-MC-006/008: Window Security Consistency
|
||||||
|
|
||||||
|
**Affected Windows:**
|
||||||
|
- PDF export window (main.js:2579-2585)
|
||||||
|
- Hidden conversion window (main.js:3263-3268)
|
||||||
|
|
||||||
|
**Fix:**
|
||||||
|
```javascript
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: false,
|
||||||
|
contextIsolation: true,
|
||||||
|
sandbox: true,
|
||||||
|
preload: path.join(__dirname, 'preload-pdf.js')
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
#### CVE-MC-007: PlantUML Data Exfiltration
|
||||||
|
|
||||||
|
**Options:**
|
||||||
|
1. Use local PlantUML JAR file
|
||||||
|
2. Use PlantUML npm package
|
||||||
|
3. Add warning before sending to external server
|
||||||
|
4. Allow configuration of PlantUML server URL
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 8. Attack Tree Summary
|
||||||
|
|
||||||
|
### 8.1 Primary Attack Tree - Full System Compromise
|
||||||
|
|
||||||
|
```
|
||||||
|
GOAL: Full System Compromise via MarkdownConverter
|
||||||
|
│
|
||||||
|
├── [BRANCH A] Exploit CVE-MC-001 (nodeIntegration)
|
||||||
|
│ │
|
||||||
|
│ ├── [A.1] XSS via malicious markdown
|
||||||
|
│ │ ├── [A.1.1] HTML injection
|
||||||
|
│ │ ├── [A.1.2] SVG script injection
|
||||||
|
│ │ └── [A.1.3] DOMPurify bypass
|
||||||
|
│ │
|
||||||
|
│ ├── [A.2] Compromised CDN script
|
||||||
|
│ │ ├── [A.2.1] jsdelivr compromise
|
||||||
|
│ │ └── [A.2.2] cdnjs compromise
|
||||||
|
│ │
|
||||||
|
│ └── [A.3] PlantUML SVG injection
|
||||||
|
│ └── [A.3.1] Compromised plantuml.com
|
||||||
|
│
|
||||||
|
├── [BRANCH B] Exploit CVE-MC-002 (REPL)
|
||||||
|
│ │
|
||||||
|
│ ├── [B.1] Social engineering
|
||||||
|
│ │ ├── [B.1.1] Malicious tutorial document
|
||||||
|
│ │ └── [B.1.2] Phishing with "config file"
|
||||||
|
│ │
|
||||||
|
│ └── [B.2] Code execution
|
||||||
|
│ ├── [B.2.1] JavaScript (Node.js)
|
||||||
|
│ ├── [B.2.2] Python
|
||||||
|
│ └── [B.2.3] Bash/Shell
|
||||||
|
│
|
||||||
|
└── [BRANCH C] Chain Exploits
|
||||||
|
│
|
||||||
|
├── [C.1] XSS -> RCE (CVE-MC-003 + CVE-MC-001)
|
||||||
|
│ └── Impact: CVSS 9.8
|
||||||
|
│
|
||||||
|
├── [C.2] Path Traversal -> Privilege Escalation
|
||||||
|
│ └── Impact: CVSS 8.5
|
||||||
|
│
|
||||||
|
└── [C.3] PlantUML -> XSS -> RCE
|
||||||
|
└── Impact: CVSS 9.1
|
||||||
|
```
|
||||||
|
|
||||||
|
### 8.2 Attack Success Probability
|
||||||
|
|
||||||
|
| Attack Path | Complexity | Privileges Required | User Interaction | Probability |
|
||||||
|
|-------------|------------|---------------------|------------------|-------------|
|
||||||
|
| A.1 XSS->RCE | Low | None | Required | 75% |
|
||||||
|
| A.2 CDN Compromise | High | None | None | 15% |
|
||||||
|
| A.3 PlantUML->RCE | Medium | None | Required | 40% |
|
||||||
|
| B.1 REPL Social Eng | Low | None | Required | 60% |
|
||||||
|
| C.1 Combined XSS-RCE | Low | None | Required | 70% |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 9. Recommendations
|
||||||
|
|
||||||
|
### 9.1 Immediate Actions (0-30 days)
|
||||||
|
|
||||||
|
1. **CVE-MC-001**: Enable `contextIsolation: true` and `nodeIntegration: false` for main window
|
||||||
|
2. **CVE-MC-002**: Add confirmation dialog before REPL execution with code preview
|
||||||
|
3. **CVE-MC-005**: Remove `unsafe-inline` and `unsafe-eval` from CSP
|
||||||
|
4. **CVE-MC-006**: Fix PDF export window security settings
|
||||||
|
|
||||||
|
### 9.2 Short-term Actions (30-90 days)
|
||||||
|
|
||||||
|
1. **CVE-MC-002**: Implement sandboxed code execution environment
|
||||||
|
2. **CVE-MC-003**: Enhance DOMPurify configuration, add CSP reporting
|
||||||
|
3. **CVE-MC-007**: Implement local PlantUML rendering option
|
||||||
|
4. Add comprehensive security audit logging
|
||||||
|
|
||||||
|
### 9.3 Long-term Actions (90+ days)
|
||||||
|
|
||||||
|
1. **CVE-MC-010**: Implement dependency pinning and SCA scanning
|
||||||
|
2. Security awareness training for users
|
||||||
|
3. Implement secure development lifecycle (SDL)
|
||||||
|
4. Regular penetration testing schedule
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 10. Appendix
|
||||||
|
|
||||||
|
### A. Security Configuration Audit
|
||||||
|
|
||||||
|
**Main Window (main.js:323-334)**
|
||||||
|
```javascript
|
||||||
|
// CURRENT (INSECURE)
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: true, // CRITICAL: Allows require() in renderer
|
||||||
|
contextIsolation: false, // CRITICAL: No isolation between contexts
|
||||||
|
spellcheck: true
|
||||||
|
}
|
||||||
|
|
||||||
|
// RECOMMENDED
|
||||||
|
webPreferences: {
|
||||||
|
nodeIntegration: false,
|
||||||
|
contextIsolation: true,
|
||||||
|
sandbox: true,
|
||||||
|
spellcheck: true,
|
||||||
|
webSecurity: true,
|
||||||
|
allowRunningInsecureContent: false
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**CSP Configuration (index.html:5)**
|
||||||
|
```html
|
||||||
|
<!-- CURRENT (WEAK) -->
|
||||||
|
<meta http-equiv="Content-Security-Policy"
|
||||||
|
content="default-src 'self';
|
||||||
|
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net;
|
||||||
|
...">
|
||||||
|
|
||||||
|
<!-- RECOMMENDED -->
|
||||||
|
<meta http-equiv="Content-Security-Policy"
|
||||||
|
content="default-src 'self';
|
||||||
|
script-src 'self';
|
||||||
|
style-src 'self';
|
||||||
|
img-src 'self' data:;
|
||||||
|
connect-src 'self';
|
||||||
|
frame-src 'none';
|
||||||
|
object-src 'none'">
|
||||||
|
```
|
||||||
|
|
||||||
|
### B. IPC Channel Security Review
|
||||||
|
|
||||||
|
**High-Risk Channels:**
|
||||||
|
| Channel | Risk | Recommendation |
|
||||||
|
|---------|------|----------------|
|
||||||
|
| `execute-code` | Critical | Remove or sandbox |
|
||||||
|
| `save-file` | High | Add path validation |
|
||||||
|
| `batch-convert` | Medium | Rate limiting exists |
|
||||||
|
| `git-*` | Medium | Audit git operations |
|
||||||
|
|
||||||
|
### C. Dependency Security
|
||||||
|
|
||||||
|
**Critical Dependencies:**
|
||||||
|
| Package | Version | Known CVEs | Recommendation |
|
||||||
|
|---------|---------|------------|----------------|
|
||||||
|
| electron | 37.4.0 | None | Pin version |
|
||||||
|
| dompurify | 3.3.1 | None | Keep updated |
|
||||||
|
| marked | 17.0.3 | None | Keep updated |
|
||||||
|
| mermaid | 11.12.3 | None | Review CSP impact |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Document Control
|
||||||
|
|
||||||
|
| Version | Date | Author | Changes |
|
||||||
|
|---------|------|--------|---------|
|
||||||
|
| 1.0 | 2026-03-15 | Security Team | Initial threat model |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
*This threat model should be reviewed and updated after any significant architectural changes or at minimum annually.*
|
||||||
@@ -0,0 +1,502 @@
|
|||||||
|
# MarkdownConverter v5.0 - React + Tauri + PWA Architecture Design
|
||||||
|
|
||||||
|
**Date:** 2026-03-15
|
||||||
|
**Status:** Approved
|
||||||
|
**Target Platforms:** Desktop (Tauri), Web (PWA), Mobile (Future)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Executive Summary
|
||||||
|
|
||||||
|
This document outlines the architecture for MarkdownConverter v5.0, a complete rewrite using React, Tauri, and PWA technologies. The new architecture enables:
|
||||||
|
|
||||||
|
- **Multi-platform support**: Single codebase for desktop, web, and future mobile
|
||||||
|
- **Improved security**: Eliminates critical Electron vulnerabilities by design
|
||||||
|
- **Reduced bundle size**: ~5-10MB desktop, ~137KB web (vs 150MB+ Electron)
|
||||||
|
- **Better maintainability**: Component-based architecture with TypeScript
|
||||||
|
- **Offline support**: Full PWA capabilities with IndexedDB storage
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 1. Project Structure
|
||||||
|
|
||||||
|
```
|
||||||
|
markdown-converter-v5/
|
||||||
|
├── src/
|
||||||
|
│ ├── components/
|
||||||
|
│ │ ├── ui/ # Shadcn/ui components (button, dialog, etc.)
|
||||||
|
│ │ ├── editor/ # CodeMirror wrapper, toolbar
|
||||||
|
│ │ ├── preview/ # Markdown preview, theme rendering
|
||||||
|
│ │ ├── sidebar/ # Explorer, Git, Snippets, Templates panels
|
||||||
|
│ │ ├── tabs/ # Tab bar, tab management
|
||||||
|
│ │ ├── dialogs/ # Export, batch converter, settings dialogs
|
||||||
|
│ │ └── layout/ # Main layout, splitter panes
|
||||||
|
│ │
|
||||||
|
│ ├── hooks/
|
||||||
|
│ │ ├── useEditor.ts # Editor state & actions
|
||||||
|
│ │ ├── useTheme.ts # Theme management
|
||||||
|
│ │ ├── useFileSystem.ts # File operations (uses adapter)
|
||||||
|
│ │ ├── useConversion.ts # Conversion operations
|
||||||
|
│ │ └── useKeyboardShortcuts.ts
|
||||||
|
│ │
|
||||||
|
│ ├── stores/
|
||||||
|
│ │ ├── editorStore.ts # Content, tabs, cursor position
|
||||||
|
│ │ ├── settingsStore.ts # User preferences
|
||||||
|
│ │ ├── themeStore.ts # Active theme, custom themes
|
||||||
|
│ │ └── sidebarStore.ts # Sidebar state, active panel
|
||||||
|
│ │
|
||||||
|
│ ├── adapters/
|
||||||
|
│ │ ├── types.ts # Interface definitions
|
||||||
|
│ │ ├── tauri/
|
||||||
|
│ │ │ ├── index.ts # Tauri adapter implementation
|
||||||
|
│ │ │ ├── fs.ts # File system via Tauri
|
||||||
|
│ │ │ ├── convert.ts # Pandoc, FFmpeg via Tauri
|
||||||
|
│ │ │ └── system.ts # System info, paths
|
||||||
|
│ │ ├── web/
|
||||||
|
│ │ │ ├── index.ts # Web adapter implementation
|
||||||
|
│ │ │ ├── fs.ts # IndexedDB + File System Access API
|
||||||
|
│ │ │ ├── convert.ts # WASM converters, cloud fallback
|
||||||
|
│ │ │ └── system.ts # Browser capabilities
|
||||||
|
│ │ └── index.ts # Platform detection & export
|
||||||
|
│ │
|
||||||
|
│ ├── wasm/
|
||||||
|
│ │ ├── pdf.wasm # PDF generation
|
||||||
|
│ │ ├── marked.wasm # Markdown parsing (if available)
|
||||||
|
│ │ └── loader.ts # WASM module loader
|
||||||
|
│ │
|
||||||
|
│ ├── lib/
|
||||||
|
│ │ ├── markdown.ts # Marked + plugins config
|
||||||
|
│ │ ├── syntax.ts # Highlight.js config
|
||||||
|
│ │ ├── mermaid.ts # Diagram rendering
|
||||||
|
│ │ └── utils.ts # Helper functions
|
||||||
|
│ │
|
||||||
|
│ ├── styles/
|
||||||
|
│ │ ├── globals.css # Tailwind imports, CSS variables
|
||||||
|
│ │ ├── themes/ # Theme CSS files
|
||||||
|
│ │ └── editor.css # CodeMirror styling
|
||||||
|
│ │
|
||||||
|
│ ├── types/
|
||||||
|
│ │ ├── editor.ts # Editor-related types
|
||||||
|
│ │ ├── conversion.ts # Conversion options types
|
||||||
|
│ │ └── platform.ts # Platform capability types
|
||||||
|
│ │
|
||||||
|
│ ├── App.tsx # Root component
|
||||||
|
│ ├── main.tsx # Entry point
|
||||||
|
│ └── vite-env.d.ts
|
||||||
|
│
|
||||||
|
├── src-tauri/ # Tauri backend (Rust)
|
||||||
|
│ ├── src/
|
||||||
|
│ │ ├── main.rs # Tauri entry
|
||||||
|
│ │ ├── commands/ # IPC command handlers
|
||||||
|
│ │ │ ├── fs.rs # File system operations
|
||||||
|
│ │ │ ├── convert.rs # Pandoc, FFmpeg wrappers
|
||||||
|
│ │ │ └── system.rs # System utilities
|
||||||
|
│ │ └── lib.rs
|
||||||
|
│ ├── Cargo.toml
|
||||||
|
│ └── tauri.conf.json
|
||||||
|
│
|
||||||
|
├── public/
|
||||||
|
│ ├── manifest.json # PWA manifest
|
||||||
|
│ ├── sw.js # Service worker
|
||||||
|
│ ├── fonts/ # JetBrains Mono, Inter
|
||||||
|
│ └── icons/ # App icons
|
||||||
|
│
|
||||||
|
├── package.json
|
||||||
|
├── vite.config.ts
|
||||||
|
├── tailwind.config.ts
|
||||||
|
├── tsconfig.json
|
||||||
|
└── components.json # Shadcn/ui config
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 2. Component Architecture
|
||||||
|
|
||||||
|
```tsx
|
||||||
|
// Component hierarchy
|
||||||
|
|
||||||
|
<App> // Root layout, theme provider
|
||||||
|
├── <Layout>
|
||||||
|
│ ├── <TitleBar /> // Draggable title bar (desktop only)
|
||||||
|
│ ├── <TabBar /> // Document tabs
|
||||||
|
│ ├── <MainContent>
|
||||||
|
│ │ ├── <Sidebar> // Collapsible sidebar
|
||||||
|
│ │ │ ├── <ExplorerPanel />
|
||||||
|
│ │ │ ├── <GitPanel />
|
||||||
|
│ │ │ ├── <SnippetsPanel />
|
||||||
|
│ │ │ └── <TemplatesPanel />
|
||||||
|
│ │ ├── <EditorPane> // Split view container
|
||||||
|
│ │ │ ├── <CodeMirrorEditor />
|
||||||
|
│ │ │ └── <PreviewPane>
|
||||||
|
│ │ │ └── <MarkdownPreview />
|
||||||
|
│ │ └── <BottomPanel> // REPL, terminal, output
|
||||||
|
│ └── <StatusBar /> // Line count, encoding, status
|
||||||
|
│
|
||||||
|
└── <Dialogs> // Portal-based dialogs
|
||||||
|
├── <ExportDialog />
|
||||||
|
├── <BatchConvertDialog />
|
||||||
|
├── <SettingsDialog />
|
||||||
|
├── <ThemeDialog />
|
||||||
|
└── <PdfEditorDialog />
|
||||||
|
```
|
||||||
|
|
||||||
|
**Key Components:**
|
||||||
|
|
||||||
|
| Component | Props | Responsibility |
|
||||||
|
|-----------|-------|----------------|
|
||||||
|
| `CodeMirrorEditor` | `content`, `onChange`, `theme` | Wrap CodeMirror 6 with React |
|
||||||
|
| `MarkdownPreview` | `content`, `theme` | Render sanitized HTML with themes |
|
||||||
|
| `TabBar` | `tabs`, `activeId`, `onSelect`, `onClose` | Manage document tabs |
|
||||||
|
| `Sidebar` | `activePanel`, `collapsed` | Collapsible sidebar container |
|
||||||
|
| `ExportDialog` | `format`, `options` | Export configuration UI |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 3. State Management (Zustand)
|
||||||
|
|
||||||
|
### Editor Store
|
||||||
|
|
||||||
|
```typescript
|
||||||
|
interface Tab {
|
||||||
|
id: string;
|
||||||
|
title: string;
|
||||||
|
content: string;
|
||||||
|
filePath?: string;
|
||||||
|
isDirty: boolean;
|
||||||
|
cursorPosition: { line: number; column: number };
|
||||||
|
}
|
||||||
|
|
||||||
|
interface EditorState {
|
||||||
|
tabs: Tab[];
|
||||||
|
activeTabId: string | null;
|
||||||
|
|
||||||
|
// Actions
|
||||||
|
createTab: (title?: string) => string;
|
||||||
|
closeTab: (id: string) => void;
|
||||||
|
setActiveTab: (id: string) => void;
|
||||||
|
updateContent: (id: string, content: string) => void;
|
||||||
|
updateCursorPosition: (id: string, pos: { line: number; column: number }) => void;
|
||||||
|
markSaved: (id: string, filePath?: string) => void;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Settings Store
|
||||||
|
|
||||||
|
```typescript
|
||||||
|
interface SettingsState {
|
||||||
|
theme: string;
|
||||||
|
fontSize: number;
|
||||||
|
fontFamily: string;
|
||||||
|
previewMode: 'split' | 'editor' | 'preview';
|
||||||
|
showLineNumbers: boolean;
|
||||||
|
wordWrap: boolean;
|
||||||
|
autoSave: boolean;
|
||||||
|
autoSaveInterval: number;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Stores Summary:**
|
||||||
|
|
||||||
|
| Store | State | Persisted |
|
||||||
|
|-------|-------|-----------|
|
||||||
|
| `editorStore` | Tabs, content, cursor | Tab metadata only |
|
||||||
|
| `settingsStore` | User preferences | Yes |
|
||||||
|
| `themeStore` | Active theme, custom themes | Yes |
|
||||||
|
| `sidebarStore` | Panel state, width | Yes |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 4. Platform Adapters
|
||||||
|
|
||||||
|
### Adapter Interface
|
||||||
|
|
||||||
|
```typescript
|
||||||
|
export interface PlatformAdapter {
|
||||||
|
name: 'tauri' | 'web';
|
||||||
|
|
||||||
|
// File System
|
||||||
|
fs: {
|
||||||
|
readFile: (path: string) => Promise<string>;
|
||||||
|
writeFile: (path: string, content: string) => Promise<void>;
|
||||||
|
deleteFile: (path: string) => Promise<void>;
|
||||||
|
listDirectory: (path: string) => Promise<FileInfo[]>;
|
||||||
|
exists: (path: string) => Promise<boolean>;
|
||||||
|
watchDirectory?: (path: string, callback: WatchCallback) => () => void;
|
||||||
|
};
|
||||||
|
|
||||||
|
// Conversion
|
||||||
|
convert: {
|
||||||
|
toPdf: (content: string, options: PdfOptions) => Promise<Blob>;
|
||||||
|
toDocx: (content: string, options: DocxOptions) => Promise<Blob>;
|
||||||
|
toHtml: (content: string, options: HtmlOptions) => Promise<string>;
|
||||||
|
batchConvert: (files: string[], format: string) => Promise<ConversionResult[]>;
|
||||||
|
};
|
||||||
|
|
||||||
|
// Capabilities
|
||||||
|
capabilities: {
|
||||||
|
hasPandoc: boolean;
|
||||||
|
hasFfmpeg: boolean;
|
||||||
|
hasLibreOffice: boolean;
|
||||||
|
hasDirectFs: boolean;
|
||||||
|
hasSystemNotifications: boolean;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Platform Detection
|
||||||
|
|
||||||
|
```typescript
|
||||||
|
// Auto-detect platform at startup
|
||||||
|
const isTauri = typeof window !== 'undefined' &&
|
||||||
|
'__TAURI__' in window;
|
||||||
|
|
||||||
|
export const adapter: PlatformAdapter = isTauri
|
||||||
|
? tauriAdapter
|
||||||
|
: webAdapter;
|
||||||
|
```
|
||||||
|
|
||||||
|
### Capability Differences
|
||||||
|
|
||||||
|
| Feature | Tauri (Desktop) | Web (PWA) |
|
||||||
|
|---------|-----------------|-----------|
|
||||||
|
| File System | Direct access | IndexedDB + File System Access API |
|
||||||
|
| PDF Export | Pandoc (native) | WASM converter |
|
||||||
|
| DOCX Export | Pandoc (native) | Limited/not available |
|
||||||
|
| Media Conversion | FFmpeg (native) | Cloud API or limited |
|
||||||
|
| File Watching | Native events | Not available |
|
||||||
|
| Offline | Always | Service Worker |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 5. Build Configuration
|
||||||
|
|
||||||
|
### Vite Configuration
|
||||||
|
|
||||||
|
- Target: ESNext
|
||||||
|
- Minifier: esbuild
|
||||||
|
- Code splitting by vendor chunks
|
||||||
|
- Source maps enabled
|
||||||
|
|
||||||
|
### Tailwind Configuration
|
||||||
|
|
||||||
|
- Dark mode: `class` strategy
|
||||||
|
- Custom colors using CSS variables
|
||||||
|
- Custom font families (JetBrains Mono, Inter)
|
||||||
|
- Tailwindcss-animate plugin
|
||||||
|
|
||||||
|
### TypeScript Configuration
|
||||||
|
|
||||||
|
- Target: ES2022
|
||||||
|
- Strict mode enabled
|
||||||
|
- All strict checks enabled
|
||||||
|
- Path aliases (`@/*`)
|
||||||
|
|
||||||
|
### Bundle Sizes (Estimated)
|
||||||
|
|
||||||
|
| Chunk | Size (gzipped) |
|
||||||
|
|-------|----------------|
|
||||||
|
| `vendor-react` | ~12KB |
|
||||||
|
| `vendor-editor` | ~45KB |
|
||||||
|
| `vendor-markdown` | ~35KB |
|
||||||
|
| `vendor-ui` | ~15KB |
|
||||||
|
| `app` (your code) | ~30KB |
|
||||||
|
| **Total PWA** | **~137KB** |
|
||||||
|
| Tauri desktop | ~5-10MB (with WebView) |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 6. Tauri Backend (Rust)
|
||||||
|
|
||||||
|
### IPC Commands
|
||||||
|
|
||||||
|
**File System:**
|
||||||
|
- `read_file` - Read file content
|
||||||
|
- `write_file` - Write file content
|
||||||
|
- `delete_file` - Delete file
|
||||||
|
- `list_directory` - List directory contents
|
||||||
|
- `path_exists` - Check path existence
|
||||||
|
- `watch_directory` - Watch for file changes
|
||||||
|
|
||||||
|
**Conversion:**
|
||||||
|
- `to_pdf` - Convert to PDF via Pandoc
|
||||||
|
- `to_docx` - Convert to DOCX via Pandoc
|
||||||
|
- `to_html` - Convert to HTML via Pandoc
|
||||||
|
- `batch_convert` - Batch conversion
|
||||||
|
|
||||||
|
**System:**
|
||||||
|
- `check_dependencies` - Check for Pandoc, FFmpeg, LibreOffice
|
||||||
|
- `get_config_dir` - Get config directory path
|
||||||
|
|
||||||
|
### Security Comparison
|
||||||
|
|
||||||
|
| Aspect | Electron (Current) | Tauri |
|
||||||
|
|--------|-------------------|-------|
|
||||||
|
| `nodeIntegration` | `true` (CVE) | Not possible |
|
||||||
|
| `contextIsolation` | `false` (CVE) | Always enforced |
|
||||||
|
| Bundle size | ~150MB | ~5-10MB |
|
||||||
|
| Memory usage | Higher | Lower |
|
||||||
|
| IPC security | Manual whitelist | Compile-time verified |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 7. PWA Configuration
|
||||||
|
|
||||||
|
### Web App Manifest
|
||||||
|
|
||||||
|
- Name: Markdown Converter
|
||||||
|
- Display: Standalone
|
||||||
|
- Theme color: #5661b3
|
||||||
|
- File handlers for .md, .markdown, .txt
|
||||||
|
- Share target for receiving shared content
|
||||||
|
|
||||||
|
### Service Worker
|
||||||
|
|
||||||
|
- Cache-first for static assets
|
||||||
|
- Network-first for API calls
|
||||||
|
- Stale-while-revalidate for dynamic content
|
||||||
|
- Automatic update detection
|
||||||
|
|
||||||
|
### IndexedDB Storage
|
||||||
|
|
||||||
|
**Stores:**
|
||||||
|
- `files` - Offline file storage
|
||||||
|
- `settings` - User preferences
|
||||||
|
- `templates` - Custom templates
|
||||||
|
|
||||||
|
### PWA Features
|
||||||
|
|
||||||
|
| Feature | Implementation |
|
||||||
|
|---------|---------------|
|
||||||
|
| Offline support | Service Worker + IndexedDB |
|
||||||
|
| Install prompt | Web App Manifest |
|
||||||
|
| File handling | File System Access API (Chrome) |
|
||||||
|
| Share target | Share Target API |
|
||||||
|
| Background sync | Background Sync API |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 8. Migration Plan
|
||||||
|
|
||||||
|
### Timeline: 8 Weeks
|
||||||
|
|
||||||
|
**Phase 1: Foundation (Week 1-2)**
|
||||||
|
- Initialize new repo
|
||||||
|
- Setup Vite + React + TypeScript
|
||||||
|
- Configure Tailwind + Shadcn/ui
|
||||||
|
- Setup Zustand stores
|
||||||
|
- Create platform adapter interfaces
|
||||||
|
- Setup Tauri project structure
|
||||||
|
|
||||||
|
**Phase 2: Core Editor (Week 3-4)**
|
||||||
|
- CodeMirrorEditor component
|
||||||
|
- MarkdownPreview component
|
||||||
|
- SplitPane layout
|
||||||
|
- Theme system
|
||||||
|
- Tab management
|
||||||
|
- Keyboard shortcuts
|
||||||
|
|
||||||
|
**Phase 3: Sidebar & Panels (Week 5)**
|
||||||
|
- Sidebar container
|
||||||
|
- ExplorerPanel
|
||||||
|
- GitPanel
|
||||||
|
- SnippetsPanel
|
||||||
|
- TemplatesPanel
|
||||||
|
- Bottom panel
|
||||||
|
|
||||||
|
**Phase 4: Platform Adapters (Week 6)**
|
||||||
|
- Web adapter implementation
|
||||||
|
- Tauri adapter implementation
|
||||||
|
- File system operations
|
||||||
|
- PDF conversion
|
||||||
|
- Capability detection
|
||||||
|
|
||||||
|
**Phase 5: Export & Conversion (Week 7)**
|
||||||
|
- ExportDialog
|
||||||
|
- BatchConvertDialog
|
||||||
|
- UniversalConverterDialog
|
||||||
|
- ImageConverterDialog
|
||||||
|
- AudioConverterDialog
|
||||||
|
- VideoConverterDialog
|
||||||
|
- PDF Editor Dialog
|
||||||
|
|
||||||
|
**Phase 6: PWA & Polish (Week 8)**
|
||||||
|
- Service Worker setup
|
||||||
|
- Web App Manifest
|
||||||
|
- IndexedDB storage
|
||||||
|
- Offline mode indicator
|
||||||
|
- Settings persistence
|
||||||
|
- Accessibility audit
|
||||||
|
- Performance optimization
|
||||||
|
|
||||||
|
### Parallel Development Strategy
|
||||||
|
|
||||||
|
```
|
||||||
|
Current Electron App (v4.x) New React+Tauri App (v5.0)
|
||||||
|
│ │
|
||||||
|
│ Bug fixes only │ Active development
|
||||||
|
│ Security patches │ Feature migration
|
||||||
|
▼ ▼
|
||||||
|
Stable release ────────────> Beta release
|
||||||
|
(maintained) (new features)
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 9. Design Decisions Summary
|
||||||
|
|
||||||
|
| Decision | Choice | Rationale |
|
||||||
|
|----------|--------|-----------|
|
||||||
|
| Code Structure | Single repo with platform adapters | Lightest weight, clean separation |
|
||||||
|
| State Management | Zustand | Minimal (~1KB), simple API |
|
||||||
|
| UI Library | Shadcn/ui + Tailwind | Copy-paste ownership, excellent DX |
|
||||||
|
| Build Tool | Vite | Industry standard, fast HMR |
|
||||||
|
| TypeScript | Strict mode | Maximum type safety |
|
||||||
|
| Desktop Features | Hybrid (WASM core, desktop advanced) | Best of both worlds |
|
||||||
|
| Migration | Parallel development | Zero disruption to stable release |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 10. Success Criteria
|
||||||
|
|
||||||
|
- [ ] All core editor features functional on both Tauri and PWA
|
||||||
|
- [ ] Bundle size under 150KB for PWA
|
||||||
|
- [ ] All 13 themes migrated and working
|
||||||
|
- [ ] Export to PDF works on both platforms
|
||||||
|
- [ ] Offline mode fully functional in PWA
|
||||||
|
- [ ] WCAG 2.1 AA accessibility compliance
|
||||||
|
- [ ] TypeScript strict mode with no `any` types
|
||||||
|
- [ ] All IPC channels have TypeScript types
|
||||||
|
- [ ] Security audit passes with no critical issues
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Appendix: Dependencies
|
||||||
|
|
||||||
|
### Production Dependencies
|
||||||
|
|
||||||
|
- `react` - UI library
|
||||||
|
- `react-dom` - React DOM renderer
|
||||||
|
- `zustand` - State management
|
||||||
|
- `@radix-ui/react-*` - Headless UI primitives
|
||||||
|
- `@codemirror/*` - Code editor
|
||||||
|
- `marked` - Markdown parser
|
||||||
|
- `highlight.js` - Syntax highlighting
|
||||||
|
- `mermaid` - Diagram rendering
|
||||||
|
- `dompurify` - HTML sanitization
|
||||||
|
- `class-variance-authority` - Component variants
|
||||||
|
- `clsx` + `tailwind-merge` - Class utilities
|
||||||
|
- `lucide-react` - Icons
|
||||||
|
|
||||||
|
### Development Dependencies
|
||||||
|
|
||||||
|
- `@tauri-apps/cli` - Tauri CLI
|
||||||
|
- `typescript` - TypeScript compiler
|
||||||
|
- `vite` - Build tool
|
||||||
|
- `tailwindcss` - CSS framework
|
||||||
|
- `eslint` - Linting
|
||||||
|
- `prettier` - Formatting
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
*Document generated: 2026-03-15*
|
||||||
|
*Next step: Invoke writing-plans skill to create detailed implementation plan*
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,202 @@
|
|||||||
|
# Modal System Design
|
||||||
|
|
||||||
|
**Date:** 2026-03-24
|
||||||
|
**Version:** 4.0.0
|
||||||
|
**Status:** Approved
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
Replace the existing dialog implementations with a unified modal system that provides:
|
||||||
|
- Glassmorphism backdrop matching app aesthetic
|
||||||
|
- Full accessibility (ARIA, focus trap, keyboard navigation)
|
||||||
|
- Smooth fade + scale animations
|
||||||
|
- Consistent API via `ModalManager` class
|
||||||
|
|
||||||
|
## Decisions Made
|
||||||
|
|
||||||
|
| Decision | Choice | Rationale |
|
||||||
|
|----------|--------|-----------|
|
||||||
|
| Architecture | Unified `ModalManager` class | Cleaner, consistent behavior across all modals |
|
||||||
|
| Backdrop style | Glassmorphism | Matches existing app design language |
|
||||||
|
| Focus management | Focus first interactive element | Standard, predictable behavior |
|
||||||
|
| Animation | Fade + scale (95% → 100%) | Modern, subtle effect |
|
||||||
|
| Implementation | Custom (not native `<dialog>`) | Full control, no polyfill concerns |
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|
### File Structure
|
||||||
|
|
||||||
|
```
|
||||||
|
src/
|
||||||
|
├── utils/
|
||||||
|
│ └── ModalManager.js # Core modal logic (~150 lines)
|
||||||
|
├── styles/
|
||||||
|
│ └── modal.css # Unified modal styles (~200 lines)
|
||||||
|
└── index.html # Updated dialog markup
|
||||||
|
```
|
||||||
|
|
||||||
|
### ModalManager Class
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
class ModalManager {
|
||||||
|
constructor(element, options = {})
|
||||||
|
open() // Show modal with animation
|
||||||
|
close() // Hide modal with animation
|
||||||
|
destroy() // Cleanup event listeners
|
||||||
|
on(event, callback) // Event subscription
|
||||||
|
|
||||||
|
// Internal
|
||||||
|
#createBackdrop() // Create glassmorphism backdrop
|
||||||
|
#trapFocus() // Manage focus within modal
|
||||||
|
#handleKeydown(e) // Escape key handler
|
||||||
|
#getFocusableElements() // Query focusable children
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Events
|
||||||
|
|
||||||
|
- `open` — Fired after open animation completes
|
||||||
|
- `close` — Fired after close animation completes
|
||||||
|
|
||||||
|
## CSS Design
|
||||||
|
|
||||||
|
### Variables (from tokens.css)
|
||||||
|
|
||||||
|
```css
|
||||||
|
--z-modal: 200;
|
||||||
|
--transition-normal: 200ms cubic-bezier(0.4, 0, 0.2, 1);
|
||||||
|
--shadow-xl: 0 20px 25px -5px rgb(0 0 0 / 0.1);
|
||||||
|
--radius-lg: 0.5rem;
|
||||||
|
```
|
||||||
|
|
||||||
|
### Backdrop
|
||||||
|
|
||||||
|
```css
|
||||||
|
.modal-backdrop {
|
||||||
|
position: fixed;
|
||||||
|
inset: 0;
|
||||||
|
background: rgba(0, 0, 0, 0.4);
|
||||||
|
backdrop-filter: blur(4px);
|
||||||
|
-webkit-backdrop-filter: blur(4px);
|
||||||
|
z-index: var(--z-modal);
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Modal Container
|
||||||
|
|
||||||
|
```css
|
||||||
|
.modal {
|
||||||
|
position: fixed;
|
||||||
|
inset: 0;
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
z-index: calc(var(--z-modal) + 1);
|
||||||
|
opacity: 0;
|
||||||
|
visibility: hidden;
|
||||||
|
transition: opacity var(--transition-normal),
|
||||||
|
visibility var(--transition-normal);
|
||||||
|
}
|
||||||
|
|
||||||
|
.modal.open {
|
||||||
|
opacity: 1;
|
||||||
|
visibility: visible;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Modal Content (with animation)
|
||||||
|
|
||||||
|
```css
|
||||||
|
.modal-content {
|
||||||
|
background: hsl(var(--background));
|
||||||
|
border-radius: var(--radius-lg);
|
||||||
|
box-shadow: var(--shadow-xl);
|
||||||
|
max-width: 90vw;
|
||||||
|
max-height: 90vh;
|
||||||
|
overflow: hidden;
|
||||||
|
transform: scale(0.95);
|
||||||
|
transition: transform var(--transition-normal);
|
||||||
|
}
|
||||||
|
|
||||||
|
.modal.open .modal-content {
|
||||||
|
transform: scale(1);
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
## HTML Structure
|
||||||
|
|
||||||
|
All dialogs convert to unified structure:
|
||||||
|
|
||||||
|
```html
|
||||||
|
<div id="export-dialog"
|
||||||
|
class="modal"
|
||||||
|
role="dialog"
|
||||||
|
aria-modal="true"
|
||||||
|
aria-labelledby="export-dialog-title">
|
||||||
|
|
||||||
|
<div class="modal-backdrop" data-close></div>
|
||||||
|
|
||||||
|
<div class="modal-content">
|
||||||
|
<div class="modal-header">
|
||||||
|
<h3 id="export-dialog-title">Export Options</h3>
|
||||||
|
<button class="modal-close" aria-label="Close">×</button>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="modal-body">
|
||||||
|
<!-- Dialog-specific content -->
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="modal-footer">
|
||||||
|
<button class="btn btn-secondary" data-close>Cancel</button>
|
||||||
|
<button class="btn btn-primary">Confirm</button>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
```
|
||||||
|
|
||||||
|
### Key Attributes
|
||||||
|
|
||||||
|
- `role="dialog"` — Screen reader identification
|
||||||
|
- `aria-modal="true"` — Prevents screen reader from accessing background
|
||||||
|
- `aria-labelledby` — References the dialog title
|
||||||
|
- `data-close` — Click handler for closing (backdrop, cancel buttons)
|
||||||
|
|
||||||
|
## Accessibility Features
|
||||||
|
|
||||||
|
1. **Focus trap** — Tab cycles within modal only
|
||||||
|
2. **Focus first element** — Auto-focuses first input/button on open
|
||||||
|
3. **Escape key** — Closes modal
|
||||||
|
4. **Click outside** — Clicking backdrop closes modal
|
||||||
|
5. **Focus restoration** — Returns focus to trigger element on close
|
||||||
|
6. **ARIA attributes** — Proper screen reader support
|
||||||
|
|
||||||
|
## Dialogs to Migrate
|
||||||
|
|
||||||
|
| Dialog ID | Current Class | Complexity |
|
||||||
|
|-----------|--------------|------------|
|
||||||
|
| `find-dialog` | `.find-dialog` | Simple |
|
||||||
|
| `export-dialog` | `.export-dialog` | Complex (many sections) |
|
||||||
|
| `print-preview-overlay` | `.export-dialog` | Medium |
|
||||||
|
| `table-generator-dialog` | `.export-dialog` | Simple |
|
||||||
|
| `ascii-art-dialog` | `.export-dialog` | Medium |
|
||||||
|
| `universal-converter-dialog` | `.export-dialog` | Complex |
|
||||||
|
| `batch-dialog` | `.batch-dialog` | Complex |
|
||||||
|
| `pdf-editor-dialog` | `.export-dialog` | Complex |
|
||||||
|
| `header-footer-dialog` | `.export-dialog` | Medium |
|
||||||
|
| `field-picker-dialog` | `.export-dialog` | Simple |
|
||||||
|
|
||||||
|
## Migration Steps
|
||||||
|
|
||||||
|
1. Create `src/utils/ModalManager.js`
|
||||||
|
2. Create `src/styles/modal.css`
|
||||||
|
3. Update `index.html` to include new stylesheet
|
||||||
|
4. Convert each dialog HTML to new structure
|
||||||
|
5. Initialize `ModalManager` instances in `renderer.js`
|
||||||
|
6. Remove old CSS from `styles.css`
|
||||||
|
7. Test all dialogs
|
||||||
|
|
||||||
|
## Out of Scope
|
||||||
|
|
||||||
|
- Modal nesting (stacked modals) — can be added later if needed
|
||||||
|
- Animated backdrop (currently static blur)
|
||||||
|
- Modal size variants (small/large/fullscreen) — can use inline styles
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,326 @@
|
|||||||
|
# V4 Enhancement + Flutter Exploration Design
|
||||||
|
|
||||||
|
**Date:** 2026-03-24
|
||||||
|
**Status:** Approved
|
||||||
|
**Approach:** Incremental V4 Enhancement + Flutter Spike (70/30 split)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Executive Summary
|
||||||
|
|
||||||
|
This design outlines a two-track approach:
|
||||||
|
1. **V4 Enhancement (70%)**: Fix critical bugs, optimize performance, add platform adapters, improve UI patterns
|
||||||
|
2. **Flutter Exploration (30%)**: Build proof-of-concept for cross-platform evaluation (Windows, Mobile, Web)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Goals & Scope
|
||||||
|
|
||||||
|
### Primary Goals
|
||||||
|
1. **Fix critical bug**: PDF and markdown multitab functionality
|
||||||
|
2. **Performance improvements**: Faster startup, smoother editing, responsive preview
|
||||||
|
3. **Architecture improvements**: Platform adapters, cleaner state management
|
||||||
|
4. **Flutter research**: Proof-of-concept for cross-platform evaluation
|
||||||
|
|
||||||
|
### Out of Scope
|
||||||
|
- Full V5 migration
|
||||||
|
- Complete UI redesign
|
||||||
|
- New features (focus on optimization)
|
||||||
|
|
||||||
|
### Success Criteria
|
||||||
|
|
||||||
|
| Metric | Current | Target |
|
||||||
|
|--------|---------|--------|
|
||||||
|
| Startup time | ~3-5s | <2s |
|
||||||
|
| Editor typing latency | Noticeable lag | <16ms |
|
||||||
|
| Preview render (1MB file) | ~500ms | <200ms |
|
||||||
|
| Memory usage | ~300MB | <200MB |
|
||||||
|
| Bundle size | ~150MB | <100MB |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Section 1: V4 Critical Fixes & Performance Optimizations
|
||||||
|
|
||||||
|
### 1.1 Fix: PDF/Markdown Multitab Bug
|
||||||
|
|
||||||
|
**Location:** `src/renderer.js` (TabManager class)
|
||||||
|
|
||||||
|
**Investigation areas:**
|
||||||
|
- `switchToTab()` - ensure proper state preservation
|
||||||
|
- `closeTab()` - ensure EditorView cleanup
|
||||||
|
- Add tab type tracking (markdown vs pdf)
|
||||||
|
- Isolate PDF viewer state from editor state
|
||||||
|
|
||||||
|
### 1.2 Startup Performance Optimizations
|
||||||
|
|
||||||
|
| Optimization | Implementation | Expected Gain |
|
||||||
|
|--------------|----------------|---------------|
|
||||||
|
| Defer Mermaid | Load only when diagram detected | ~500ms |
|
||||||
|
| Defer PDF.js | Load on first PDF open | ~800ms |
|
||||||
|
| Lazy load themes | Load active theme only | ~200ms |
|
||||||
|
| Lazy sidebar panels | Load panel code when sidebar opens | ~300ms |
|
||||||
|
| Preload optimization | Remove unused IPC channels | ~100ms |
|
||||||
|
|
||||||
|
**Lazy loading pattern:**
|
||||||
|
```javascript
|
||||||
|
// Current (loads everything upfront)
|
||||||
|
const { dialog } = require('@electron/remote');
|
||||||
|
|
||||||
|
// Optimized (load on demand)
|
||||||
|
let _dialog;
|
||||||
|
function getDialog() {
|
||||||
|
if (!_dialog) _dialog = require('@electron/remote').dialog;
|
||||||
|
return _dialog;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 1.3 Editor Performance
|
||||||
|
|
||||||
|
| Issue | Solution |
|
||||||
|
|-------|----------|
|
||||||
|
| Typing lag with large files | Debounce preview updates (300ms) |
|
||||||
|
| Syntax highlight overhead | Use highlight.js lazy mode |
|
||||||
|
| Memory leaks | Clean up EditorView on tab close |
|
||||||
|
| Theme switching lag | Pre-compile theme CSS |
|
||||||
|
|
||||||
|
### 1.4 Preview Rendering
|
||||||
|
|
||||||
|
| Issue | Solution |
|
||||||
|
|-------|----------|
|
||||||
|
| Mermaid slow | Render on-demand, cache results |
|
||||||
|
| Full re-render on keystroke | Debounced incremental updates |
|
||||||
|
| Large documents | Viewport rendering (visible portion only) |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Section 2: Platform Adapter Pattern
|
||||||
|
|
||||||
|
### 2.1 Architecture
|
||||||
|
|
||||||
|
```
|
||||||
|
src/
|
||||||
|
├── adapters/
|
||||||
|
│ ├── index.js # Auto-detects and exports adapter
|
||||||
|
│ ├── types.js # Interface definitions (JSDoc)
|
||||||
|
│ │
|
||||||
|
│ ├── electron/ # Current Electron implementation
|
||||||
|
│ │ ├── index.js # Exports electronAdapter
|
||||||
|
│ │ ├── fs.js # File system operations
|
||||||
|
│ │ ├── convert.js # Pandoc, FFmpeg conversions
|
||||||
|
│ │ ├── pdf.js # PDF operations
|
||||||
|
│ │ └── system.js # System info, dialogs, notifications
|
||||||
|
│ │
|
||||||
|
│ └── mock/ # For testing
|
||||||
|
│ └── index.js # Mock adapter for unit tests
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.2 Adapter Interface
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
/**
|
||||||
|
* @typedef {Object} PlatformAdapter
|
||||||
|
* @property {'electron'} name
|
||||||
|
* @property {FileSystemAdapter} fs
|
||||||
|
* @property {ConversionAdapter} convert
|
||||||
|
* @property {PdfAdapter} pdf
|
||||||
|
* @property {SystemAdapter} system
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @typedef {Object} FileSystemAdapter
|
||||||
|
* @property {(path: string) => Promise<string>} readFile
|
||||||
|
* @property {(path: string, content: string) => Promise<void>} writeFile
|
||||||
|
* @property {(path: string) => Promise<void>} deleteFile
|
||||||
|
* @property {(path: string) => Promise<FileInfo[]>} listDirectory
|
||||||
|
* @property {(path: string) => Promise<boolean>} exists
|
||||||
|
*/
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2.3 Migration Strategy
|
||||||
|
|
||||||
|
| Phase | What | Files Affected |
|
||||||
|
|-------|------|----------------|
|
||||||
|
| 1 | Create adapter structure | New files only |
|
||||||
|
| 2 | Migrate file operations | `renderer.js`, `sidebar/*.js` |
|
||||||
|
| 3 | Migrate conversions | Export dialogs |
|
||||||
|
| 4 | Migrate PDF operations | PDF viewer |
|
||||||
|
| 5 | Remove old IPC calls | `preload.js` cleanup |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Section 3: UI Improvements (Shadcn/ui Patterns)
|
||||||
|
|
||||||
|
### 3.1 Design Token System
|
||||||
|
|
||||||
|
```css
|
||||||
|
/* src/styles/tokens.css */
|
||||||
|
|
||||||
|
:root {
|
||||||
|
/* Colors - Light mode */
|
||||||
|
--background: 0 0% 100%;
|
||||||
|
--foreground: 222.2 84% 4.9%;
|
||||||
|
--primary: 227 44% 52%;
|
||||||
|
--primary-foreground: 210 40% 98%;
|
||||||
|
--secondary: 210 40% 96.1%;
|
||||||
|
--secondary-foreground: 222.2 47.4% 11.2%;
|
||||||
|
--muted: 210 40% 96.1%;
|
||||||
|
--muted-foreground: 215.4 16.3% 46.9%;
|
||||||
|
--destructive: 0 84.2% 60.2%;
|
||||||
|
--border: 214.3 31.8% 91.4%;
|
||||||
|
--ring: 227 44% 52%;
|
||||||
|
|
||||||
|
/* Spacing & Radii */
|
||||||
|
--radius: 0.5rem;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.2 Component Improvements
|
||||||
|
|
||||||
|
| Component | Current Issue | Fix |
|
||||||
|
|-----------|---------------|-----|
|
||||||
|
| Buttons | Inconsistent hover/focus | Use `.btn` with variants |
|
||||||
|
| Dialogs | Missing focus trap | Add focus trap, Escape key, aria-modal |
|
||||||
|
| Tabs | No keyboard navigation | Add arrow key nav, aria-selected |
|
||||||
|
| Sidebar | No collapse animation | CSS transitions |
|
||||||
|
| Dropdowns | Missing click-outside | Add proper event handling |
|
||||||
|
|
||||||
|
### 3.3 Accessibility Improvements
|
||||||
|
|
||||||
|
- Focus states with `:focus-visible`
|
||||||
|
- Skip to content link
|
||||||
|
- ARIA labels on interactive elements
|
||||||
|
- Keyboard navigation for all components
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Section 4: Flutter Exploration (30% Effort)
|
||||||
|
|
||||||
|
### 4.1 Flutter Project Structure
|
||||||
|
|
||||||
|
```
|
||||||
|
markdown-converter-flutter/
|
||||||
|
├── lib/
|
||||||
|
│ ├── main.dart
|
||||||
|
│ ├── app.dart
|
||||||
|
│ ├── core/
|
||||||
|
│ │ ├── theme/
|
||||||
|
│ │ └── constants.dart
|
||||||
|
│ ├── features/
|
||||||
|
│ │ ├── editor/
|
||||||
|
│ │ ├── preview/
|
||||||
|
│ │ └── tabs/
|
||||||
|
│ ├── services/
|
||||||
|
│ │ ├── file_service.dart
|
||||||
|
│ │ ├── export_service.dart
|
||||||
|
│ │ └── platform_service.dart
|
||||||
|
│ └── adapters/
|
||||||
|
│ ├── file_adapter.dart
|
||||||
|
│ ├── file_adapter_mobile.dart
|
||||||
|
│ ├── file_adapter_web.dart
|
||||||
|
│ └── file_adapter_desktop.dart
|
||||||
|
├── pubspec.yaml
|
||||||
|
├── windows/
|
||||||
|
├── web/
|
||||||
|
└── lib/
|
||||||
|
```
|
||||||
|
|
||||||
|
### 4.2 Key Dependencies
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
dependencies:
|
||||||
|
flutter_markdown: ^0.7.0
|
||||||
|
flutter_code_editor: ^0.3.0
|
||||||
|
provider: ^6.1.0
|
||||||
|
file_picker: ^8.0.0
|
||||||
|
path_provider: ^2.1.0
|
||||||
|
pdf: ^3.10.0
|
||||||
|
printing: ^5.12.0
|
||||||
|
```
|
||||||
|
|
||||||
|
### 4.3 Prototype Features
|
||||||
|
|
||||||
|
| Feature | Priority |
|
||||||
|
|---------|----------|
|
||||||
|
| Basic markdown editor | Must have |
|
||||||
|
| Live preview | Must have |
|
||||||
|
| Light/dark theme | Must have |
|
||||||
|
| Tab management | Should have |
|
||||||
|
| File open/save | Should have |
|
||||||
|
| PDF export | Nice to have |
|
||||||
|
| Windows exe build | Must have |
|
||||||
|
| Web build | Must have |
|
||||||
|
| Mobile build | Should have |
|
||||||
|
|
||||||
|
### 4.4 Evaluation Criteria
|
||||||
|
|
||||||
|
| Metric | Target |
|
||||||
|
|--------|--------|
|
||||||
|
| Windows exe size | <50MB |
|
||||||
|
| Web initial load | <500KB |
|
||||||
|
| Cold start time | <2s |
|
||||||
|
| Editor typing latency | <16ms |
|
||||||
|
|
||||||
|
### 4.5 Flutter vs Tauri Comparison
|
||||||
|
|
||||||
|
| Aspect | Flutter | Tauri + React |
|
||||||
|
|--------|---------|---------------|
|
||||||
|
| Mobile support | ✅ Excellent | ❌ Requires separate app |
|
||||||
|
| Web performance | ⚠️ Good, larger | ✅ Excellent, small |
|
||||||
|
| Desktop bundle | ⚠️ ~30-50MB | ✅ ~5-10MB |
|
||||||
|
| Native feel | ⚠️ Custom rendering | ✅ System WebView |
|
||||||
|
| Code reuse | ✅ 100% shared | ⚠️ Some platform-specific |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Implementation Timeline
|
||||||
|
|
||||||
|
### Phase 1: V4 Critical Fixes (Week 1)
|
||||||
|
- Fix PDF/markdown multitab bug
|
||||||
|
- Implement startup optimizations
|
||||||
|
- Add debounced preview rendering
|
||||||
|
|
||||||
|
### Phase 2: Platform Adapters (Week 2)
|
||||||
|
- Create adapter structure
|
||||||
|
- Migrate file operations
|
||||||
|
- Migrate conversions
|
||||||
|
|
||||||
|
### Phase 3: UI Improvements (Week 3)
|
||||||
|
- Add design tokens
|
||||||
|
- Improve component accessibility
|
||||||
|
- Add keyboard navigation
|
||||||
|
|
||||||
|
### Phase 4: Flutter Prototype (Weeks 2-4, parallel)
|
||||||
|
- Set up Flutter project
|
||||||
|
- Implement basic editor
|
||||||
|
- Build Windows and Web versions
|
||||||
|
- Document findings
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Risk Mitigation
|
||||||
|
|
||||||
|
| Risk | Mitigation |
|
||||||
|
|------|------------|
|
||||||
|
| Multitab fix causes regressions | Comprehensive test suite before changes |
|
||||||
|
| Performance optimizations break features | Incremental changes with benchmarks |
|
||||||
|
| Flutter proves unsuitable | 30% effort limit, V4 remains primary |
|
||||||
|
| Platform adapter migration too slow | Phased approach, each phase independent |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Success Metrics
|
||||||
|
|
||||||
|
- [ ] Multitab functionality working correctly
|
||||||
|
- [ ] Startup time < 2 seconds
|
||||||
|
- [ ] No perceived editor lag with files < 1MB
|
||||||
|
- [ ] Preview renders in < 200ms
|
||||||
|
- [ ] Bundle size reduced by 30%+
|
||||||
|
- [ ] Platform adapters for fs, convert, pdf implemented
|
||||||
|
- [ ] Design tokens applied to all components
|
||||||
|
- [ ] Flutter prototype running on Windows + Web
|
||||||
|
- [ ] Flutter evaluation documented with recommendation
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
*Document generated: 2026-03-24*
|
||||||
|
*Next step: Create detailed implementation plan*
|
||||||
@@ -0,0 +1,335 @@
|
|||||||
|
# Writer's Studio Feature Pack — Design Document
|
||||||
|
|
||||||
|
**Date**: 2026-04-06
|
||||||
|
**Version**: 4.2.0 target
|
||||||
|
**Status**: Approved
|
||||||
|
**Scope**: Three cohesive features to transform MarkdownConverter into a writing environment
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
The Writer's Studio Feature Pack adds three interconnected features to MarkdownConverter:
|
||||||
|
|
||||||
|
1. **Zen Mode** — Distraction-free writing environment with typewriter scrolling
|
||||||
|
2. **Document Outline** — Heading hierarchy sidebar panel for navigation
|
||||||
|
3. **Writing Analytics** — Real-time readability and vocabulary analysis dashboard
|
||||||
|
|
||||||
|
These features work together: Zen Mode creates the environment, Outline provides navigation, Analytics gives insight.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Feature 1: Zen Mode
|
||||||
|
|
||||||
|
### Purpose
|
||||||
|
|
||||||
|
Transform the app from a multi-tool into a focused writing environment. Inspired by iA Writer, Typora, and Bear.
|
||||||
|
|
||||||
|
### New Files
|
||||||
|
|
||||||
|
- `src/zen-mode.js` — ZenMode class (~150 lines)
|
||||||
|
- `src/styles-zen.css` — Zen mode specific styles (~120 lines)
|
||||||
|
|
||||||
|
### Integration Points
|
||||||
|
|
||||||
|
- `src/renderer.js` — Initialize ZenMode, register F11 shortcut, add View > Zen Mode menu
|
||||||
|
- `src/editor/codemirror-setup.js` — Export typewriter + dimming extensions
|
||||||
|
|
||||||
|
### Behavior
|
||||||
|
|
||||||
|
**Toggle**: F11, View > Zen Mode, command palette "Toggle Zen Mode"
|
||||||
|
**Exit**: Escape key, F11 again
|
||||||
|
|
||||||
|
**What hides**:
|
||||||
|
- Tab bar
|
||||||
|
- Toolbar
|
||||||
|
- Sidebar (collapsed)
|
||||||
|
- Status bar
|
||||||
|
- App header
|
||||||
|
|
||||||
|
**What shows**:
|
||||||
|
- Editor (full viewport)
|
||||||
|
- Floating HUD (bottom-center, semi-transparent)
|
||||||
|
|
||||||
|
### Floating HUD
|
||||||
|
|
||||||
|
```
|
||||||
|
┌─────────────────────────────────────────┐
|
||||||
|
│ 847 words • ~4 min • 23:45 session │
|
||||||
|
│ ████████████████░░░░ 85% of 1000 │
|
||||||
|
└─────────────────────────────────────────┘
|
||||||
|
```
|
||||||
|
|
||||||
|
- Word count (from existing status bar logic)
|
||||||
|
- Estimated reading time (~200 wpm)
|
||||||
|
- Session timer (starts when zen mode activates)
|
||||||
|
- Optional progress bar toward word goal
|
||||||
|
|
||||||
|
### CodeMirror Extensions
|
||||||
|
|
||||||
|
**Typewriter Scroll** (`ViewPlugin`):
|
||||||
|
- Listens to `EditorView.update` for selection changes
|
||||||
|
- Calls `editor.dispatch({ effects: EditorView.scrollIntoView(pos, { y: 'center' }) })`
|
||||||
|
- Smooth scrolling with `scrollBehavior: 'smooth'` in CSS
|
||||||
|
|
||||||
|
**Line Dimming** (`ViewPlugin` + `Decoration`):
|
||||||
|
- Builds a `DecorationSet` mapping each line to an opacity value
|
||||||
|
- Active line: opacity 1.0
|
||||||
|
- 1-2 lines away: 0.7
|
||||||
|
- 3-4 lines away: 0.5
|
||||||
|
- 5+ lines away: 0.3
|
||||||
|
- Uses `Decoration.line({ attributes: { style: 'opacity: X' } })`
|
||||||
|
|
||||||
|
### Centered Column
|
||||||
|
|
||||||
|
CSS applied to `.zen-mode .cm-content`:
|
||||||
|
```css
|
||||||
|
.zen-mode .cm-content {
|
||||||
|
max-width: 700px;
|
||||||
|
margin: 0 auto;
|
||||||
|
font-size: 18px;
|
||||||
|
line-height: 1.8;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### State Management
|
||||||
|
|
||||||
|
- `this.previousState` stores which UI elements were visible before zen mode
|
||||||
|
- On exit, restores all elements to their previous visibility
|
||||||
|
- Editor content, cursor position, and scroll state are never modified
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Feature 2: Document Outline Panel
|
||||||
|
|
||||||
|
### Purpose
|
||||||
|
|
||||||
|
Provide always-visible heading navigation for documents of any length. The single most-requested navigation feature for multi-section documents.
|
||||||
|
|
||||||
|
### New Files
|
||||||
|
|
||||||
|
- `src/sidebar/outline-panel.js` — `renderOutlinePanel` function (~100 lines)
|
||||||
|
|
||||||
|
### Modified Files
|
||||||
|
|
||||||
|
- `src/index.html` — Add outline icon button in sidebar icons strip
|
||||||
|
- `src/renderer.js` — Register 'outline' panel, provide editor reference
|
||||||
|
|
||||||
|
### Sidebar Integration
|
||||||
|
|
||||||
|
Uses existing `SidebarManager.registerPanel()` API:
|
||||||
|
```javascript
|
||||||
|
sidebarManager.registerPanel('outline', {
|
||||||
|
title: 'Outline',
|
||||||
|
render: (container) => renderOutlinePanel(container, editor, editorContent)
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
New icon button in sidebar strip (after templates icon):
|
||||||
|
```html
|
||||||
|
<button class="sidebar-icon" data-panel="outline" title="Outline (Ctrl+Shift+O)">
|
||||||
|
<!-- hierarchy/list icon SVG -->
|
||||||
|
</button>
|
||||||
|
```
|
||||||
|
|
||||||
|
### Parsing Logic
|
||||||
|
|
||||||
|
Parse headings from raw markdown content using regex:
|
||||||
|
```javascript
|
||||||
|
const headingRegex = /^(#{1,6})\s+(.+)$/gm;
|
||||||
|
```
|
||||||
|
|
||||||
|
Returns array of:
|
||||||
|
```javascript
|
||||||
|
{ level: 1-6, text: "Heading Text", line: 42 }
|
||||||
|
```
|
||||||
|
|
||||||
|
Debounced at 300ms to avoid re-parsing on every keystroke.
|
||||||
|
|
||||||
|
### UI Structure
|
||||||
|
|
||||||
|
```
|
||||||
|
┌──────────────────────────────────────────┐
|
||||||
|
│ OUTLINE ☰ │
|
||||||
|
├──────────────────────────────────────────┤
|
||||||
|
│ ▸ Introduction (H1) │
|
||||||
|
│ ▸ Getting Started (H2) │
|
||||||
|
│ ▸ Prerequisites (H2) │
|
||||||
|
│ ▸ Node.js (H3) ◄ │
|
||||||
|
│ ▸ Installation (H2) │
|
||||||
|
│ ▸ Features (H1) │
|
||||||
|
│ ▸ Editor (H2) │
|
||||||
|
│ ▸ Export (H2) │
|
||||||
|
├──────────────────────────────────────────┤
|
||||||
|
│ 9 headings • 2 H1 • 4 H2 • 3 H3 │
|
||||||
|
└──────────────────────────────────────────┘
|
||||||
|
```
|
||||||
|
|
||||||
|
- Indentation based on heading level (H1 = 0px, H2 = 16px, H3 = 32px, etc.)
|
||||||
|
- Current heading highlighted with accent color (◄ indicator)
|
||||||
|
- Hover shows full heading text if truncated
|
||||||
|
|
||||||
|
### Click-to-Navigate
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
editor.dispatch({
|
||||||
|
effects: EditorView.scrollIntoView(linePos, { y: 'center' })
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
Brief highlight animation on the target line (fades out over 500ms).
|
||||||
|
|
||||||
|
### Current Heading Sync
|
||||||
|
|
||||||
|
On editor update (debounced 100ms):
|
||||||
|
1. Get cursor line number
|
||||||
|
2. Find the last heading whose line number <= cursor line
|
||||||
|
3. Set that heading as active in the outline
|
||||||
|
|
||||||
|
### Empty State
|
||||||
|
|
||||||
|
When no headings found:
|
||||||
|
```
|
||||||
|
No headings found
|
||||||
|
|
||||||
|
Use # to create headings:
|
||||||
|
# Heading 1
|
||||||
|
## Heading 2
|
||||||
|
### Heading 3
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Feature 3: Writing Analytics
|
||||||
|
|
||||||
|
### Purpose
|
||||||
|
|
||||||
|
Give writers real-time insight into their document's readability, structure, and vocabulary. This is the "surprise" feature most Markdown editors lack.
|
||||||
|
|
||||||
|
### New Files
|
||||||
|
|
||||||
|
- `src/analytics/writing-analytics.js` — `WritingAnalytics` class (~180 lines)
|
||||||
|
- `src/analytics/analytics-panel.js` — `renderAnalyticsPanel` function (~120 lines)
|
||||||
|
|
||||||
|
### Integration Points
|
||||||
|
|
||||||
|
- `src/renderer.js` — Register Ctrl+Shift+A shortcut, command palette entry, View menu item
|
||||||
|
|
||||||
|
### Trigger
|
||||||
|
|
||||||
|
- Keyboard: `Ctrl+Shift+A`
|
||||||
|
- Command Palette: "Show Writing Analytics"
|
||||||
|
- Menu: View > Writing Analytics
|
||||||
|
|
||||||
|
### Presentation
|
||||||
|
|
||||||
|
Uses existing `ModalManager` to show a modal overlay with analytics dashboard.
|
||||||
|
|
||||||
|
```
|
||||||
|
┌─────────────────────────────────────────────────────┐
|
||||||
|
│ Writing Analytics ✕ │
|
||||||
|
├─────────────────────────────────────────────────────┤
|
||||||
|
│ │
|
||||||
|
│ ┌─ Readability ──────────────────────────────────┐ │
|
||||||
|
│ │ Flesch Reading Ease: 67.3 (Standard) ○ │ │
|
||||||
|
│ │ Grade Level: 8.2 ○○○●○ │ │
|
||||||
|
│ └─────────────────────────────────────────────────┘ │
|
||||||
|
│ │
|
||||||
|
│ ┌─ Timing ───────────────────────────────────────┐ │
|
||||||
|
│ │ Reading Time: ~4 min │ │
|
||||||
|
│ │ Speaking Time: ~6 min │ │
|
||||||
|
│ └─────────────────────────────────────────────────┘ │
|
||||||
|
│ │
|
||||||
|
│ ┌─ Structure ────────────────────────────────────┐ │
|
||||||
|
│ │ Sentences: 42 • Paragraphs: 8 │ │
|
||||||
|
│ │ Avg Sentence: 14.2 words │ │
|
||||||
|
│ │ Longest: 38 words ("The quick brown fox...") │ │
|
||||||
|
│ └─────────────────────────────────────────────────┘ │
|
||||||
|
│ │
|
||||||
|
│ ┌─ Vocabulary ───────────────────────────────────┐ │
|
||||||
|
│ │ Unique: 312 / 847 words (36.8%) │ │
|
||||||
|
│ │ Top: the(42) and(31) markdown(28) ... │ │
|
||||||
|
│ └─────────────────────────────────────────────────┘ │
|
||||||
|
│ │
|
||||||
|
│ ┌─ Word Goal ────────────────────────────────────┐ │
|
||||||
|
│ │ Target: [1000] words │ │
|
||||||
|
│ │ ████████████████░░░░ 847/1000 (85%) │ │
|
||||||
|
│ └─────────────────────────────────────────────────┘ │
|
||||||
|
│ │
|
||||||
|
└─────────────────────────────────────────────────────┘
|
||||||
|
```
|
||||||
|
|
||||||
|
### Metrics Implementation
|
||||||
|
|
||||||
|
**Readability (Flesch-Kincaid):**
|
||||||
|
```javascript
|
||||||
|
// Flesch Reading Ease
|
||||||
|
ease = 206.835 - 1.015 * (words / sentences) - 84.6 * (syllables / words);
|
||||||
|
|
||||||
|
// Flesch-Kincaid Grade Level
|
||||||
|
grade = 0.39 * (words / sentences) + 11.8 * (syllables / words) - 15.59;
|
||||||
|
```
|
||||||
|
|
||||||
|
**Syllable Estimation:**
|
||||||
|
```javascript
|
||||||
|
function countSyllables(word) {
|
||||||
|
word = word.toLowerCase().replace(/(?:[^laeiouy]es|ed|[^laeiouy]e)$/, '');
|
||||||
|
word = word.replace(/^y/, '');
|
||||||
|
return word.match(/[aeiouy]{1,2}/g)?.length || 1;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Reading/Speaking Time:**
|
||||||
|
- Reading: 200 words/minute
|
||||||
|
- Speaking: 130 words/minute
|
||||||
|
|
||||||
|
**Lexical Diversity:**
|
||||||
|
- Ratio of unique words to total words (excluding stop words)
|
||||||
|
|
||||||
|
**Top Words:**
|
||||||
|
- Frequency map, sorted descending, top 10
|
||||||
|
- Excludes common stop words (the, a, an, is, are, etc.)
|
||||||
|
|
||||||
|
### Word Goal
|
||||||
|
|
||||||
|
- Persisted in `electron-store` per document (or global default)
|
||||||
|
- Progress bar with percentage
|
||||||
|
- Celebration effect when goal is reached (brief confetti animation or green flash)
|
||||||
|
|
||||||
|
### Update Cadence
|
||||||
|
|
||||||
|
- Re-analyzes on editor content change (debounced at 1000ms)
|
||||||
|
- If modal is open, updates live
|
||||||
|
- If modal is closed, no computation (zero overhead)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## File Summary
|
||||||
|
|
||||||
|
| File | Action | Purpose |
|
||||||
|
|------|--------|---------|
|
||||||
|
| `src/zen-mode.js` | Create | ZenMode class with CM6 extensions |
|
||||||
|
| `src/styles-zen.css` | Create | Zen mode styling |
|
||||||
|
| `src/sidebar/outline-panel.js` | Create | Outline sidebar panel |
|
||||||
|
| `src/analytics/writing-analytics.js` | Create | Analytics computation engine |
|
||||||
|
| `src/analytics/analytics-panel.js` | Create | Analytics modal UI |
|
||||||
|
| `src/index.html` | Modify | Add outline icon, zen mode button |
|
||||||
|
| `src/renderer.js` | Modify | Initialize all three features |
|
||||||
|
| `src/editor/codemirror-setup.js` | Modify | Export typewriter + dimming extensions |
|
||||||
|
|
||||||
|
## Keyboard Shortcuts
|
||||||
|
|
||||||
|
| Shortcut | Feature | Action |
|
||||||
|
|----------|---------|--------|
|
||||||
|
| F11 | Zen Mode | Toggle on/off |
|
||||||
|
| Escape | Zen Mode | Exit (when active) |
|
||||||
|
| Ctrl+Shift+O | Outline | Open outline sidebar panel |
|
||||||
|
| Ctrl+Shift+A | Analytics | Open analytics modal |
|
||||||
|
|
||||||
|
## Dependencies
|
||||||
|
|
||||||
|
No new npm dependencies required. All features use:
|
||||||
|
- Existing CodeMirror 6 APIs (ViewPlugin, Decoration, scrollIntoView)
|
||||||
|
- Existing SidebarManager API
|
||||||
|
- Existing ModalManager API
|
||||||
|
- Pure JavaScript math for analytics
|
||||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,759 @@
|
|||||||
|
# Feature Audit, Bug Fixes, New Features & Security Hardening Implementation Plan
|
||||||
|
|
||||||
|
> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking.
|
||||||
|
|
||||||
|
**Goal:** Fix every verified non-working feature in MarkdownConverter, build out the orphaned image/audio/video converter subsystem, add 9 new features extending existing architecture, remediate a critical Pandoc argument-injection vulnerability plus other security findings, then produce a clean local release build.
|
||||||
|
|
||||||
|
**Architecture:** Vanilla JS Electron app (`contextIsolation: false`, `nodeIntegration: true`). Main process (`src/main.js`, ~5000 lines) owns all IPC handlers, dialogs, and external-tool invocation (Pandoc, ffmpeg, ImageMagick, LibreOffice) via `execFile`. Renderer (`src/renderer.js`, ~6150 lines) is vanilla DOM manipulation; it uses `ipcRenderer` both directly (legacy) and via the whitelisted `window.electronAPI` bridge (`src/preload.js`). Feature modules live under `src/main/*.js` (PDF, Git, font embedding) and `src/plugins/*.js` (plugin system). Follow this existing pattern for all new code — do not introduce a bundler, framework, or TypeScript.
|
||||||
|
|
||||||
|
**Tech Stack:** Electron 41, Node 20, Pandoc (external binary via `getPandocPath()`), ffmpeg-static (bundled, via `getFFmpegPath()`), `sharp` (image ops, currently a devDependency — must move to `dependencies`), `pdf-lib` (`src/main/PDFOperations.js`), `simple-git` (`src/main/GitOperations.js`), Jest for tests, ESLint flat config + Prettier.
|
||||||
|
|
||||||
|
**Spec:** This plan is self-originated from a live codebase audit (two parallel research passes + manual verification of every finding against `src/main.js`, `src/preload.js`, `src/renderer.js`, `src/main/GitOperations.js`, `src/main/PDFOperations.js`, `src/plugins/plugin-context.js`). No separate spec doc exists; each task below states the verified current behavior and the required end behavior.
|
||||||
|
|
||||||
|
## Global Constraints
|
||||||
|
|
||||||
|
- `contextIsolation: false` / `nodeIntegration: true` is the existing (weak) security model for this branch — do not attempt to flip it as part of this plan; that is a separate, much larger migration tracked elsewhere. Do not make the security posture worse than it already is.
|
||||||
|
- All new external-process invocation MUST use `execFile` with an explicit argument array — **never** build a shell-style command string and re-tokenize it. This is the root cause of Finding SEC-1 below; do not repeat the pattern anywhere new.
|
||||||
|
- All new/changed IPC channels must be added to the correct whitelist array in `src/preload.js` (`ALLOWED_SEND_CHANNELS` for renderer→main, `ALLOWED_RECEIVE_CHANNELS` for main→renderer) — an unlisted channel is silently blocked (see `preload.js:261-282`).
|
||||||
|
- 2-space indent, single quotes, semicolons, 100-char width (Prettier). Run `npm run lint` and `npm run format:check` before every commit; both must pass.
|
||||||
|
- `npm test` (Jest, jsdom) must stay green (247 tests / 32 suites passing at plan start) after every task.
|
||||||
|
- File size limit for user-opened files is `MAX_FILE_SIZE_MB = 50` (`main.js:57-58`) — reuse this constant for any new file-accepting handler, don't invent a new limit.
|
||||||
|
- Error messages shown to the user must go through `sanitizeErrorMessage()` (`main.js:61-70`) if they might contain absolute paths.
|
||||||
|
- No forbidden markers (`TODO`, `FIXME`, `stub`, `placeholder`, `coming soon`, etc.) in any changed file.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase A — Fix Verified Non-Working Features
|
||||||
|
|
||||||
|
### Task 1: Fix "Open PDF File..." menu item (wrong IPC channel)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main.js:1666-1684` (`openPDFFile()`)
|
||||||
|
|
||||||
|
**Verified current behavior:** `openPDFFile()` sends `mainWindow.webContents.send('open-pdf-viewer', files[0])` (line 1682). No listener for `'open-pdf-viewer'` exists anywhere in the repo. The working PDF-editor open path is `show-pdf-editor-dialog`, whose renderer listener is `ipcRenderer.on('show-pdf-editor-dialog', (event, operation, openedFilePath) => {...})` (`renderer.js:3685`).
|
||||||
|
|
||||||
|
- [ ] **Step 1:** In `openPDFFile()`, replace the send call:
|
||||||
|
```javascript
|
||||||
|
mainWindow.webContents.send('show-pdf-editor-dialog', null, files[0]);
|
||||||
|
```
|
||||||
|
- [ ] **Step 2:** Manually verify: `npm start`, open a PDF via File → Open PDF File (or the equivalent menu entry), confirm the PDF editor dialog opens with the file loaded (same result as opening it via the PDF toolbar button).
|
||||||
|
- [ ] **Step 3:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 4:** Commit: `git add src/main.js && git commit -m "fix(pdf): route Open PDF File menu item to the working editor dialog channel"`
|
||||||
|
|
||||||
|
### Task 2: Fix "Clear Recent Files" silent no-op
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main.js:731-736` (menu click handler), `src/main.js:4480-4491` (`ipcMain.on('clear-recent-files', ...)`)
|
||||||
|
|
||||||
|
**Verified current behavior:** The menu click handler does `mainWindow.webContents.send('clear-recent-files')` (main→renderer), but nothing in the renderer listens for that channel. The actual deletion logic lives in `ipcMain.on('clear-recent-files', (event) => {...})`, which only fires on a renderer→main `.send`/`.invoke` that never happens from this menu path. `preload.js:342` exposes a separate `clearRecent: () => ipcRenderer.send('clear-recent-files')` helper that IS the correct renderer→main direction, but the menu item bypasses it entirely by sending the same channel name in the wrong direction.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Extract the deletion logic into a standalone function above the `ipcMain.on` registration:
|
||||||
|
```javascript
|
||||||
|
function clearRecentFilesOnDisk() {
|
||||||
|
const userDataPath = app.getPath('userData');
|
||||||
|
const recentFilesPath = path.join(userDataPath, 'recent-files.json');
|
||||||
|
fs.writeFileSync(recentFilesPath, JSON.stringify([], null, 2));
|
||||||
|
createMenu();
|
||||||
|
}
|
||||||
|
```
|
||||||
|
- [ ] **Step 2:** Update the `ipcMain.on` handler to use it:
|
||||||
|
```javascript
|
||||||
|
ipcMain.on('clear-recent-files', (event) => {
|
||||||
|
try {
|
||||||
|
clearRecentFilesOnDisk();
|
||||||
|
event.reply('recent-files-cleared');
|
||||||
|
} catch (error) {
|
||||||
|
console.error('Error clearing recent files:', error);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
```
|
||||||
|
- [ ] **Step 3:** Update the menu click handler (`main.js:731-736`) to call the main-process function directly and notify the renderer the same way the working path does:
|
||||||
|
```javascript
|
||||||
|
{
|
||||||
|
label: 'Clear Recent Files',
|
||||||
|
click: () => {
|
||||||
|
try {
|
||||||
|
clearRecentFilesOnDisk();
|
||||||
|
mainWindow.webContents.send('recent-files-cleared');
|
||||||
|
} catch (error) {
|
||||||
|
console.error('Error clearing recent files:', error);
|
||||||
|
}
|
||||||
|
},
|
||||||
|
},
|
||||||
|
```
|
||||||
|
- [ ] **Step 4:** Manually verify: open a few recent files, use File menu → Clear Recent Files, confirm the Recent Files submenu is empty afterward.
|
||||||
|
- [ ] **Step 5:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 6:** Commit: `git add src/main.js && git commit -m "fix(menu): make Clear Recent Files actually clear the list"`
|
||||||
|
|
||||||
|
### Task 3: Wire "Insert Template" submenu (content already exists, just needs a listener)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/renderer.js` (near the existing `templates` sidebar-panel registration, ~line 1744-1758)
|
||||||
|
|
||||||
|
**Verified current behavior:** `main.js:811-847` sends `mainWindow.webContents.send('load-template-menu', '<file>.md')` for 10 menu items. `'load-template-menu'` IS already in `ALLOWED_RECEIVE_CHANNELS` (`preload.js:241`) but nothing in the renderer listens for it — **however** the underlying feature is fully implemented already: `src/templates/*.md` contains real content for all 10 templates, `ipcMain.handle('load-template', ...)` (`main.js:4641-4649`) reads them, and the sidebar Templates panel (`renderer.js:1744-1758`) already does exactly the load-into-new-tab flow needed. Do not author new template content — reuse the existing flow.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Extract the existing inline callback at `renderer.js:1746-1757` into a shared named function so both the sidebar panel and the new menu listener use it:
|
||||||
|
```javascript
|
||||||
|
async function loadTemplateIntoNewTab(file) {
|
||||||
|
const templateContent = await ipcRenderer.invoke('load-template', file);
|
||||||
|
if (templateContent) {
|
||||||
|
const content = templateContent.replace(/\{\{DATE\}\}/g, new Date().toISOString().split('T')[0]);
|
||||||
|
tabManager.createNewTab();
|
||||||
|
const tab = tabManager.tabs.get(tabManager.activeTabId);
|
||||||
|
tabManager.setEditorContent(tab.id, content);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
Place this near the top of the sidebar-initialization block (wherever `tabManager` is already in scope at that point), then replace the sidebar panel's inline callback with `render: (container) => getRenderTemplatesPanel()(container, loadTemplateIntoNewTab)`.
|
||||||
|
- [ ] **Step 2:** Add a listener for the menu channel, near the other `ipcRenderer.on(...)` registrations in the same initialization area:
|
||||||
|
```javascript
|
||||||
|
ipcRenderer.on('load-template-menu', (event, file) => {
|
||||||
|
loadTemplateIntoNewTab(file);
|
||||||
|
});
|
||||||
|
```
|
||||||
|
- [ ] **Step 3:** Manually verify: File → New from Template → Blog Post (and 2-3 others), confirm a new tab opens with the real template content, `{{DATE}}` replaced with today's date.
|
||||||
|
- [ ] **Step 4:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 5:** Commit: `git add src/renderer.js && git commit -m "fix(templates): wire New from Template menu to existing template-loading flow"`
|
||||||
|
|
||||||
|
### Task 4: Wire Command Palette / Sidebar / Bottom Panel menu toggles
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/renderer.js` (near command palette init ~line 2045, sidebar manager init ~line 1703, bottom/REPL panel init ~line 1007)
|
||||||
|
|
||||||
|
**Verified current behavior:** `main.js:1047,1057-1069,1075` send `toggle-command-palette`, `toggle-sidebar-panel` (with a panel-id arg: `explorer`/`git`/`snippets`/`templates`), and `toggle-bottom-panel`. All three channels are already whitelisted in `ALLOWED_RECEIVE_CHANNELS` (`preload.js:242-244`). None have a renderer listener — the Command Palette currently only opens via its own `Ctrl+Shift+P` keydown handler (`renderer.js:2045-2049`), sidebar panels only toggle via their own buttons, and the bottom/REPL panel only auto-shows when a code block runs (`renderer.js:1007`).
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Find the existing function/method that the `Ctrl+Shift+P` keydown handler calls to open the command palette (read `renderer.js:2040-2060` to get its exact name), then add:
|
||||||
|
```javascript
|
||||||
|
ipcRenderer.on('toggle-command-palette', () => {
|
||||||
|
/* call the same open/toggle function the Ctrl+Shift+P handler uses */
|
||||||
|
});
|
||||||
|
```
|
||||||
|
- [ ] **Step 2:** Find the existing method on `sidebarManager` used to show/activate a panel by id (read the `SidebarManager` class, likely in `src/sidebar/` — grep `class SidebarManager`), then add:
|
||||||
|
```javascript
|
||||||
|
ipcRenderer.on('toggle-sidebar-panel', (event, panelId) => {
|
||||||
|
/* call sidebarManager's existing toggle/show method with panelId */
|
||||||
|
});
|
||||||
|
```
|
||||||
|
- [ ] **Step 3:** Find the existing function that shows/hides the bottom REPL panel (read `renderer.js` around line 997-1012), then add:
|
||||||
|
```javascript
|
||||||
|
ipcRenderer.on('toggle-bottom-panel', () => {
|
||||||
|
/* call the same show/hide function used when a code block runs, but toggle rather than force-show */
|
||||||
|
});
|
||||||
|
```
|
||||||
|
- [ ] **Step 4:** Manually verify each of the three View-menu items now actually opens/toggles its target.
|
||||||
|
- [ ] **Step 5:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 6:** Commit: `git add src/renderer.js && git commit -m "fix(menu): wire Command Palette / Sidebar / Bottom Panel View-menu toggles"`
|
||||||
|
|
||||||
|
### Task 5: Fix broken `git-diff` IPC call (renderer invokes a channel main never handles)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main/GitOperations.js`, `src/main.js` (near the other `git-*` handlers, ~line 4889-4904)
|
||||||
|
- Modify: `src/sidebar/git-panel.js`, `src/renderer.js:1714-1731`
|
||||||
|
|
||||||
|
**Verified current behavior:** `renderer.js:1718-1721` passes `gitDiff: (file) => ipcRenderer.invoke('git-diff', { file })` into the Git sidebar panel, but `src/main.js` has **no** `ipcMain.handle('git-diff', ...)` registered anywhere (only `git-status`, `git-stage`, `git-commit`, `git-log` exist at lines 4889-4904), and `GitOperations.js` exports no `diff` function. Additionally, `src/sidebar/git-panel.js:1` receives this callback as a parameter literally named `_gitDiff` (underscore-prefixed = intentionally unused) — the panel never even calls it. This is dead on both ends. Fold the real fix into Task 14 (Phase C, new git features) rather than doing a throwaway partial fix here.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** No action in this task — cross-reference only. Mark this task done once Task 14 lands, since it fully supersedes it.
|
||||||
|
|
||||||
|
### Task 6: Whitelist and wire "Document Compare" menu item
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/preload.js` (`ALLOWED_RECEIVE_CHANNELS`)
|
||||||
|
|
||||||
|
**Verified current behavior:** `main.js:1411-1413` sends `mainWindow.webContents.send('show-document-compare')`, but `'show-document-compare'` is **not** in `ALLOWED_RECEIVE_CHANNELS` at all (unlike the other dead channels, which were at least whitelisted) — per `preload.js:288-...` the `on()` wrapper drops unlisted channels. Building the actual compare UI is Task 20 (Phase C) — this task only covers the whitelist fix; C8 covers the working listener + UI.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Add `'show-document-compare'` to `ALLOWED_RECEIVE_CHANNELS` in `src/preload.js` (alongside the other `show-*-dialog`/`show-*-converter` entries for consistency).
|
||||||
|
- [ ] **Step 2:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 3:** Commit: `git add src/preload.js && git commit -m "fix(preload): whitelist show-document-compare channel"`
|
||||||
|
- Do not close this task's manual-verification step until Task 20 lands (there is nothing to see until the listener exists).
|
||||||
|
|
||||||
|
### Task 7: Reachable UI control for monospace font settings
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/renderer.js` (Settings panel/dialog — locate existing settings UI, e.g. grep `showSettingsDialog` or similar)
|
||||||
|
|
||||||
|
**Verified current behavior:** `ipcMain.handle('set-monospace-settings', ...)` exists and works (`main.js:375` area) and the getter is used at `renderer.js:1857`, but no UI control anywhere calls the setter — a user cannot actually change the monospace font/ligature preference.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Read `main.js` around the `get-monospace-settings`/`set-monospace-settings` handlers to learn the exact settings shape (property names, e.g. `{ enabled, fontFamily, ligatures }` — use whatever the real shape is, do not invent fields).
|
||||||
|
- [ ] **Step 2:** Locate the app's existing Settings panel/dialog in `renderer.js` (grep for where `get-monospace-settings` is already invoked at line ~1857 to find the surrounding UI section) and add a toggle + font-family control there, following the existing settings-control markup/CSS pattern already used for other settings in that same dialog.
|
||||||
|
- [ ] **Step 3:** Wire the control's change handler to `ipcRenderer.invoke('set-monospace-settings', {...})` and apply the returned/echoed setting immediately (toggle the body class the same way the existing `renderer.js:1857`-area code does on load).
|
||||||
|
- [ ] **Step 4:** Manually verify: toggle monospace font in Settings, confirm the editor/preview font changes live, and confirm the preference persists across an app restart.
|
||||||
|
- [ ] **Step 5:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 6:** Commit: `git add src/renderer.js && git commit -m "feat(settings): expose monospace font toggle in Settings UI"`
|
||||||
|
|
||||||
|
### Task 8: Dependency hygiene — `jszip` and `sharp`
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `package.json`
|
||||||
|
|
||||||
|
**Verified current behavior:** `src/main/DocxFontEmbedder.js` and `src/main/EpubFontEmbedder.js` `require('jszip')` directly, but `jszip` is declared only under `overrides`, not `dependencies` — it currently resolves only via hoisting from a transitive dependency. `sharp` is declared under `devDependencies` (used today only by `scripts/generate-icons.js` at build time) but Phase B (media converter) will require it at **runtime** in the packaged app, where devDependencies are not installed/bundled.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** In `package.json`, add `"jszip": "^3.10.1"` to `dependencies` (matching the version already pinned in `overrides`; keep the `overrides` entry too — it still forces the version for transitive consumers).
|
||||||
|
- [ ] **Step 2:** Move `"sharp": "^0.34.3"` from `devDependencies` to `dependencies`.
|
||||||
|
- [ ] **Step 3:** Add `"node_modules/sharp/**"` to the `build.asarUnpack` array in `package.json` (alongside the existing `ffmpeg-static` and `assets/fonts` entries) — `sharp` ships native `.node` bindings that must not be packed into `app.asar`.
|
||||||
|
- [ ] **Step 4:** Run `npm install` to regenerate the lockfile, then `npm test` to confirm nothing broke.
|
||||||
|
- [ ] **Step 5:** Commit: `git add package.json package-lock.json && git commit -m "fix(deps): move jszip and sharp to runtime dependencies, unpack sharp from asar"`
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase B — Build Out Image/Audio/Video Converter (currently orphaned dead API)
|
||||||
|
|
||||||
|
**Context:** `preload.js` whitelists 16 channels (`image-convert`, `image-batch-convert`, `image-resize`, `image-compress`, `image-rotate`, `audio-convert`, `audio-batch-convert`, `audio-extract`, `audio-trim`, `audio-merge`, `video-convert`, `video-batch-convert`, `video-compress`, `video-trim`, `video-frames`, `video-gif`) and 3 receive channels (`show-image-converter`, `show-audio-converter`, `show-video-converter`), but **zero** `ipcMain` handlers exist for any of them and no menu/UI ever triggers them. This is distinct from the already-working generic "Universal Converter" (`universal-convert`/`universal-convert-batch`, `main.js:2377-2622`) which does plain format-to-format conversion via bare `convertWithImageMagick`/`convertWithFFmpeg` calls with no operation-specific options. Phase B builds the **operation-specific** toolkit (resize/compress/rotate for images; trim/merge/extract for audio; compress/trim/frames/gif for video) as a new `src/main/MediaOperations.js` module, modeled directly on the existing `src/main/PDFOperations.js` pattern (single `executeOperation(operation, data)` dispatcher).
|
||||||
|
|
||||||
|
### Task 9: Image operations backend (`sharp`-based)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Create: `src/main/ImageOperations.js`
|
||||||
|
- Create: `tests/main/ImageOperations.test.js`
|
||||||
|
- Modify: `src/main.js` (register handlers near the PDF operation handlers, ~line 4535)
|
||||||
|
|
||||||
|
**Interfaces:**
|
||||||
|
- Produces: `module.exports = { executeOperation, imageConvert, imageResize, imageCompress, imageRotate }` — `executeOperation(operation, data)` where `operation` is one of `'convert' | 'resize' | 'compress' | 'rotate'` and `data` always includes `{ inputPath, outputPath }` plus operation-specific fields below.
|
||||||
|
- `imageConvert(data)`: `data = { inputPath, outputPath, format }` (`format` is one of sharp's supported output formats: `jpeg|png|webp|avif|tiff|gif`) → uses `sharp(inputPath).toFormat(format).toFile(outputPath)`.
|
||||||
|
- `imageResize(data)`: `data = { inputPath, outputPath, width, height, fit }` (`fit` one of `'cover'|'contain'|'fill'|'inside'|'outside'`, default `'inside'`) → `sharp(inputPath).resize({ width, height, fit }).toFile(outputPath)`. `width`/`height` may be `null` (sharp allows omitting one dimension to preserve aspect ratio) but not both.
|
||||||
|
- `imageCompress(data)`: `data = { inputPath, outputPath, quality }` (`quality` integer 1-100, default 80) → route by output extension: jpeg/webp/avif use `{ quality }`, png uses `{ quality, compressionLevel: 9 }`.
|
||||||
|
- `imageRotate(data)`: `data = { inputPath, outputPath, angle }` (`angle` integer degrees, any value — sharp's `.rotate(angle)` handles non-90 multiples by expanding canvas) → `sharp(inputPath).rotate(angle).toFile(outputPath)`.
|
||||||
|
- All four validate `inputPath` exists and is ≤ `MAX_FILE_SIZE` (import the same 50MB constant convention used in `main.js` — pass it in as a parameter from `main.js`, do not redefine a second limit).
|
||||||
|
- All four return `{ success: true, outputPath }` on success or throw an `Error` with a sanitized (no absolute-path leakage beyond what's already the app's convention) message on failure — `main.js` wraps calls in try/catch per the PDFOperations pattern.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Write `tests/main/ImageOperations.test.js` covering all four operations against small fixture images (generate fixtures at test time with `sharp` itself — e.g. a 100x100 red PNG buffer — do not commit binary fixtures):
|
||||||
|
```javascript
|
||||||
|
const sharp = require('sharp');
|
||||||
|
const fs = require('fs');
|
||||||
|
const os = require('os');
|
||||||
|
const path = require('path');
|
||||||
|
const ImageOperations = require('../../src/main/ImageOperations');
|
||||||
|
|
||||||
|
describe('ImageOperations', () => {
|
||||||
|
let tmpDir, inputPath;
|
||||||
|
beforeEach(async () => {
|
||||||
|
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'imgops_'));
|
||||||
|
inputPath = path.join(tmpDir, 'in.png');
|
||||||
|
await sharp({ create: { width: 100, height: 100, channels: 3, background: { r: 255, g: 0, b: 0 } } })
|
||||||
|
.png()
|
||||||
|
.toFile(inputPath);
|
||||||
|
});
|
||||||
|
afterEach(() => fs.rmSync(tmpDir, { recursive: true, force: true }));
|
||||||
|
|
||||||
|
test('imageConvert converts PNG to JPEG', async () => {
|
||||||
|
const outputPath = path.join(tmpDir, 'out.jpg');
|
||||||
|
const result = await ImageOperations.imageConvert({ inputPath, outputPath, format: 'jpeg' });
|
||||||
|
expect(result.success).toBe(true);
|
||||||
|
expect(fs.existsSync(outputPath)).toBe(true);
|
||||||
|
const meta = await sharp(outputPath).metadata();
|
||||||
|
expect(meta.format).toBe('jpeg');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('imageResize resizes to given width preserving aspect', async () => {
|
||||||
|
const outputPath = path.join(tmpDir, 'out.png');
|
||||||
|
await ImageOperations.imageResize({ inputPath, outputPath, width: 50, height: null, fit: 'inside' });
|
||||||
|
const meta = await sharp(outputPath).metadata();
|
||||||
|
expect(meta.width).toBe(50);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('imageRotate rotates by given angle', async () => {
|
||||||
|
const outputPath = path.join(tmpDir, 'out.png');
|
||||||
|
await ImageOperations.imageRotate({ inputPath, outputPath, angle: 90 });
|
||||||
|
const meta = await sharp(outputPath).metadata();
|
||||||
|
expect(meta.width).toBe(100); // 90deg on square stays square
|
||||||
|
});
|
||||||
|
|
||||||
|
test('imageCompress produces a smaller or equal-size JPEG at low quality', async () => {
|
||||||
|
const jpegPath = path.join(tmpDir, 'in.jpg');
|
||||||
|
await sharp(inputPath).jpeg({ quality: 100 }).toFile(jpegPath);
|
||||||
|
const outputPath = path.join(tmpDir, 'compressed.jpg');
|
||||||
|
await ImageOperations.imageCompress({ inputPath: jpegPath, outputPath, quality: 10 });
|
||||||
|
expect(fs.statSync(outputPath).size).toBeLessThanOrEqual(fs.statSync(jpegPath).size);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('executeOperation dispatches to the correct function', async () => {
|
||||||
|
const outputPath = path.join(tmpDir, 'out.png');
|
||||||
|
const result = await ImageOperations.executeOperation('rotate', { inputPath, outputPath, angle: 180 });
|
||||||
|
expect(result.success).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('unknown operation throws', async () => {
|
||||||
|
await expect(ImageOperations.executeOperation('bogus', {})).rejects.toThrow();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
```
|
||||||
|
- [ ] **Step 2:** Run `npx jest tests/main/ImageOperations.test.js` — expect FAIL (module doesn't exist).
|
||||||
|
- [ ] **Step 3:** Implement `src/main/ImageOperations.js` per the interfaces above, using `sharp`. Model the file's shape (JSDoc header, `executeOperation` switch, `module.exports`) on `src/main/PDFOperations.js:404-436`.
|
||||||
|
- [ ] **Step 4:** Run `npx jest tests/main/ImageOperations.test.js` — expect PASS.
|
||||||
|
- [ ] **Step 5:** In `src/main.js`, add a single dispatcher handler near the PDF operation handler (`process-pdf-operation`, ~line 4535):
|
||||||
|
```javascript
|
||||||
|
const ImageOperations = require('./main/ImageOperations');
|
||||||
|
// ...
|
||||||
|
ipcMain.handle('process-image-operation', async (event, { operation, data }) => {
|
||||||
|
try {
|
||||||
|
return await ImageOperations.executeOperation(operation, data);
|
||||||
|
} catch (error) {
|
||||||
|
return { success: false, error: sanitizeErrorMessage(error.message) };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
```
|
||||||
|
Note: this collapses the originally-whitelisted 5 separate channel names (`image-convert`, `image-batch-convert`, `image-resize`, `image-compress`, `image-rotate`) into one operation-dispatch channel, matching the existing `process-pdf-operation` pattern — remove the 5 stale names from `ALLOWED_SEND_CHANNELS` in `src/preload.js` and add `'process-image-operation'` in their place (also add `'select-image-folder'` if batch needs folder selection — mirror `select-pdf-folder`). Batch (`image-batch-convert`) is handled in Task 12.
|
||||||
|
- [ ] **Step 6:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 7:** Commit: `git add src/main/ImageOperations.js tests/main/ImageOperations.test.js src/main.js src/preload.js && git commit -m "feat(image): implement sharp-based image operations backend"`
|
||||||
|
|
||||||
|
### Task 10: Audio operations backend (`ffmpeg`-based)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Create: `src/main/AudioOperations.js`
|
||||||
|
- Create: `tests/main/AudioOperations.test.js`
|
||||||
|
- Modify: `src/main.js`
|
||||||
|
|
||||||
|
**Interfaces:**
|
||||||
|
- `module.exports = { executeOperation, buildConvertArgs, buildTrimArgs, buildExtractArgs, buildMergeArgs }`. Because ffmpeg is an external binary, this module exposes **pure argument-builder functions** (easily unit-testable without invoking a real binary) plus `executeOperation`, which is the only piece that actually spawns ffmpeg via `execFile` — inject the ffmpeg path and an `execFileFn` (defaulting to Node's real `execFile`) as parameters so tests can stub it.
|
||||||
|
- `buildConvertArgs({ inputPath, outputPath, format })` → returns `string[]` args, e.g. `['-i', inputPath, '-y', outputPath]` (format is implied by `outputPath`'s extension — ffmpeg infers it; do not pass a separate `-f` unless `format` is explicitly given and differs from the extension, in which case append `['-f', format]` before `outputPath`).
|
||||||
|
- `buildTrimArgs({ inputPath, outputPath, startTime, duration })` → `['-i', inputPath, '-ss', String(startTime), '-t', String(duration), '-y', outputPath]`. `startTime`/`duration` are seconds (numbers), validate they are finite non-negative numbers before building args (throw `Error('Invalid trim range')` otherwise — this is the injection guard, since these become argv elements passed straight to execFile with no shell involved, but malformed values should still fail fast rather than reach ffmpeg).
|
||||||
|
- `buildExtractArgs({ inputPath, outputPath })` → extracts the audio track from a video/audio file: `['-i', inputPath, '-vn', '-acodec', 'copy', '-y', outputPath]` (fallback if codec copy fails: caller retries without `-acodec copy`, letting ffmpeg transcode — implement this retry inside `executeOperation`'s `'extract'` case, not in the pure builder).
|
||||||
|
- `buildMergeArgs({ inputPaths, outputPath })` → `inputPaths` is `string[]` (2+ files) → build a temp concat-list file is the safe approach; but since this module must stay pure/testable, `buildMergeArgs` returns `{ args, concatListContent }` where `concatListContent` is the `file '<path>'` lines the caller writes to a temp file, and `args = ['-f', 'concat', '-safe', '0', '-i', tempListPath, '-c', 'copy', '-y', outputPath]` (caller supplies `tempListPath` after writing the file — see `executeOperation`'s `'merge'` case).
|
||||||
|
- `executeOperation(operation, data, { ffmpegPath, execFileFn } = {})` where `operation` is `'convert'|'trim'|'extract'|'merge'`, defaults `ffmpegPath` to the real `getFFmpegPath()`-resolved path (passed in from `main.js`, not re-implemented here) and `execFileFn` to `require('child_process').execFile`. Returns a Promise resolving `{ success: true, outputPath }`.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Write `tests/main/AudioOperations.test.js` testing the pure builders directly (no real ffmpeg spawn needed for these) plus one `executeOperation` test with a stubbed `execFileFn`:
|
||||||
|
```javascript
|
||||||
|
const AudioOperations = require('../../src/main/AudioOperations');
|
||||||
|
|
||||||
|
describe('AudioOperations argument builders', () => {
|
||||||
|
test('buildConvertArgs builds correct ffmpeg args', () => {
|
||||||
|
const args = AudioOperations.buildConvertArgs({ inputPath: '/a.wav', outputPath: '/b.mp3' });
|
||||||
|
expect(args).toEqual(['-i', '/a.wav', '-y', '/b.mp3']);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('buildTrimArgs builds correct trim args', () => {
|
||||||
|
const args = AudioOperations.buildTrimArgs({ inputPath: '/a.mp3', outputPath: '/b.mp3', startTime: 5, duration: 10 });
|
||||||
|
expect(args).toEqual(['-i', '/a.mp3', '-ss', '5', '-t', '10', '-y', '/b.mp3']);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('buildTrimArgs rejects non-finite startTime', () => {
|
||||||
|
expect(() =>
|
||||||
|
AudioOperations.buildTrimArgs({ inputPath: '/a.mp3', outputPath: '/b.mp3', startTime: NaN, duration: 10 })
|
||||||
|
).toThrow('Invalid trim range');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('buildMergeArgs builds concat-demuxer args and list content', () => {
|
||||||
|
const { args, concatListContent } = AudioOperations.buildMergeArgs({
|
||||||
|
inputPaths: ['/a.mp3', '/b.mp3'],
|
||||||
|
outputPath: '/out.mp3',
|
||||||
|
});
|
||||||
|
expect(concatListContent).toContain("file '/a.mp3'");
|
||||||
|
expect(concatListContent).toContain("file '/b.mp3'");
|
||||||
|
expect(args).toContain('-f');
|
||||||
|
expect(args).toContain('concat');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('AudioOperations.executeOperation', () => {
|
||||||
|
test('convert calls execFileFn with ffmpeg path and args, resolves success', async () => {
|
||||||
|
const execFileFn = (cmd, args, opts, cb) => cb(null, '', '');
|
||||||
|
const result = await AudioOperations.executeOperation(
|
||||||
|
'convert',
|
||||||
|
{ inputPath: '/a.wav', outputPath: '/b.mp3' },
|
||||||
|
{ ffmpegPath: '/usr/bin/ffmpeg', execFileFn }
|
||||||
|
);
|
||||||
|
expect(result.success).toBe(true);
|
||||||
|
expect(result.outputPath).toBe('/b.mp3');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('unknown operation rejects', async () => {
|
||||||
|
await expect(
|
||||||
|
AudioOperations.executeOperation('bogus', {}, { ffmpegPath: '/usr/bin/ffmpeg', execFileFn: () => {} })
|
||||||
|
).rejects.toThrow();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
```
|
||||||
|
- [ ] **Step 2:** Run `npx jest tests/main/AudioOperations.test.js` — expect FAIL.
|
||||||
|
- [ ] **Step 3:** Implement `src/main/AudioOperations.js` per the interfaces above. Use `fs.writeFileSync`/`fs.mkdtempSync` (Node `os.tmpdir()`) inside `executeOperation`'s `'merge'` case to materialize the concat list file before invoking `execFileFn`.
|
||||||
|
- [ ] **Step 4:** Run `npx jest tests/main/AudioOperations.test.js` — expect PASS.
|
||||||
|
- [ ] **Step 5:** In `src/main.js`, add the dispatcher handler (mirrors Task 9 Step 5):
|
||||||
|
```javascript
|
||||||
|
const AudioOperations = require('./main/AudioOperations');
|
||||||
|
// ...
|
||||||
|
ipcMain.handle('process-audio-operation', async (event, { operation, data }) => {
|
||||||
|
try {
|
||||||
|
return await AudioOperations.executeOperation(operation, data, { ffmpegPath: getFFmpegPath() });
|
||||||
|
} catch (error) {
|
||||||
|
return { success: false, error: sanitizeErrorMessage(error.message) };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
```
|
||||||
|
Replace the 5 stale audio channel names in `ALLOWED_SEND_CHANNELS` (`preload.js`) with `'process-audio-operation'` (batch handled in Task 12).
|
||||||
|
- [ ] **Step 6:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 7:** Commit: `git add src/main/AudioOperations.js tests/main/AudioOperations.test.js src/main.js src/preload.js && git commit -m "feat(audio): implement ffmpeg-based audio operations backend"`
|
||||||
|
|
||||||
|
### Task 11: Video operations backend (`ffmpeg`-based)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Create: `src/main/VideoOperations.js`
|
||||||
|
- Create: `tests/main/VideoOperations.test.js`
|
||||||
|
- Modify: `src/main.js`
|
||||||
|
|
||||||
|
**Interfaces:** Same shape as Task 10 (`executeOperation(operation, data, { ffmpegPath, execFileFn })`, pure arg builders for testability).
|
||||||
|
- `buildConvertArgs({ inputPath, outputPath })` → `['-i', inputPath, '-y', outputPath]`.
|
||||||
|
- `buildCompressArgs({ inputPath, outputPath, crf })` (`crf` 0-51, default 28 — lower is higher quality/larger file, matching libx264 convention) → `['-i', inputPath, '-vcodec', 'libx264', '-crf', String(crf), '-y', outputPath]`. Validate `crf` is an integer 0-51 (throw otherwise).
|
||||||
|
- `buildTrimArgs({ inputPath, outputPath, startTime, duration })` → identical shape/validation to `AudioOperations.buildTrimArgs`.
|
||||||
|
- `buildFramesArgs({ inputPath, outputDir, fps })` (`fps` frames-per-second to extract, default 1) → `['-i', inputPath, '-vf', `fps=${fps}`, path.join(outputDir, 'frame-%04d.png')]`. Validate `fps` is a positive finite number.
|
||||||
|
- `buildGifArgs({ inputPath, outputPath, fps, width })` (`fps` default 10, `width` default 480, height auto via `-1`) → `['-i', inputPath, '-vf', `fps=${fps},scale=${width}:-1:flags=lanczos`, '-y', outputPath]`.
|
||||||
|
- `operation` is `'convert'|'compress'|'trim'|'frames'|'gif'`.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Write `tests/main/VideoOperations.test.js` mirroring Task 10's test structure — one test per builder function checking exact `args` array output plus validation-rejection tests for `compress` (bad `crf`) and `frames` (bad `fps`), plus one `executeOperation` test with a stubbed `execFileFn` for `'convert'` and one for `'frames'` that also verifies the output directory is created (`fs.mkdirSync(outputDir, { recursive: true })` inside `executeOperation`'s `'frames'` case before spawning ffmpeg).
|
||||||
|
- [ ] **Step 2:** Run `npx jest tests/main/VideoOperations.test.js` — expect FAIL.
|
||||||
|
- [ ] **Step 3:** Implement `src/main/VideoOperations.js` per the interfaces above.
|
||||||
|
- [ ] **Step 4:** Run `npx jest tests/main/VideoOperations.test.js` — expect PASS.
|
||||||
|
- [ ] **Step 5:** In `src/main.js`, add the dispatcher handler (mirrors B1/B2):
|
||||||
|
```javascript
|
||||||
|
const VideoOperations = require('./main/VideoOperations');
|
||||||
|
// ...
|
||||||
|
ipcMain.handle('process-video-operation', async (event, { operation, data }) => {
|
||||||
|
try {
|
||||||
|
return await VideoOperations.executeOperation(operation, data, { ffmpegPath: getFFmpegPath() });
|
||||||
|
} catch (error) {
|
||||||
|
return { success: false, error: sanitizeErrorMessage(error.message) };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
```
|
||||||
|
Replace the 6 stale video channel names in `ALLOWED_SEND_CHANNELS` with `'process-video-operation'`.
|
||||||
|
- [ ] **Step 6:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 7:** Commit: `git add src/main/VideoOperations.js tests/main/VideoOperations.test.js src/main.js src/preload.js && git commit -m "feat(video): implement ffmpeg-based video operations backend"`
|
||||||
|
|
||||||
|
### Task 12: Media Operations UI (menu entries + dialog + batch)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Create: `src/renderer/media-operations-dialog.js` (follow whatever module pattern `src/renderer.js` already uses for the PDF editor dialog — read `renderer.js:3685` onward to find that dialog's implementation file/pattern before creating this one)
|
||||||
|
- Modify: `src/main.js` (menu — add "Image/Audio/Video Tools..." entries under the existing `Tools` submenu, next to Table Generator/ASCII Art Generator at `main.js:1395-1414`; also extend `universal-convert-batch`'s existing batch-folder flow OR add three new `process-*-operation` batch loops mirroring the pattern at `main.js:2454-2563`, whichever requires less duplication once B1-B3 exist — prefer reusing `executeOperation` in a loop over `fs.readdirSync` results, matching the existing batch style)
|
||||||
|
- Modify: `src/preload.js` (add `'show-image-converter'`... already present; add `'process-image-operation'`/`'process-audio-operation'`/`'process-video-operation'` to `ALLOWED_SEND_CHANNELS` if not already added by B1-B3)
|
||||||
|
|
||||||
|
**Verified current behavior:** `show-image-converter`/`show-audio-converter`/`show-video-converter` are whitelisted receive channels with no sender and no listener — Batch Image/Audio/Video Conversion menu items already exist and work via the generic Universal Converter (`main.js:1283-1291`, `2454-2563`) for plain format conversion; this task adds the **operation-specific** single-file dialogs (resize/compress/rotate/trim/merge/extract/frames/gif) that B1-B3 implemented.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Add three menu items under `Tools` (`main.js`, after the "Document Compare" item added conceptually in Task 6/C8):
|
||||||
|
```javascript
|
||||||
|
{ label: 'Image Tools...', click: () => mainWindow.webContents.send('show-image-converter') },
|
||||||
|
{ label: 'Audio Tools...', click: () => mainWindow.webContents.send('show-audio-converter') },
|
||||||
|
{ label: 'Video Tools...', click: () => mainWindow.webContents.send('show-video-converter') },
|
||||||
|
```
|
||||||
|
- [ ] **Step 2:** Build the renderer-side dialog module. Read how the existing PDF Editor dialog (triggered by `show-pdf-editor-dialog`) is structured/rendered in `renderer.js` (search for its listener at line 3685 and follow into whatever function/file builds its DOM) and replicate that construction pattern for a single dialog that: (a) lets the user pick an operation from a dropdown scoped to the current media kind (image/audio/video), (b) shows the relevant operation-specific fields (e.g. width/height for resize, quality for compress, angle for rotate, startTime/duration for trim, fps/width for gif), (c) has an input-file picker (reuse the existing `dialog.showOpenDialogSync` pattern via a new small `ipcMain.handle('select-media-file', ...)` if no generic file-picker IPC already exists — check first; `select-pdf-folder` is folder-only, so a new single-file-picker handler is likely needed), (d) calls `ipcRenderer.invoke('process-image-operation', { operation, data })` (or audio/video) and shows success/error the same way `pdf-operation-complete`/`pdf-operation-error` are surfaced elsewhere.
|
||||||
|
- [ ] **Step 3:** Wire the three `ipcRenderer.on('show-image-converter'|'show-audio-converter'|'show-video-converter', ...)` listeners in `renderer.js` to open the new dialog scoped to the right media kind.
|
||||||
|
- [ ] **Step 4:** Manually verify with `npm start`: Tools → Image Tools → Resize a test PNG, confirm the output file is created at the chosen size; repeat once each for one audio op (trim) and one video op (compress) using any small local test media file.
|
||||||
|
- [ ] **Step 5:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 6:** Commit: `git add -A && git commit -m "feat(media): add Image/Audio/Video Tools dialogs wired to new operation backends"`
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase C — New Features (extending existing systems)
|
||||||
|
|
||||||
|
### Task 13: Expose more Pandoc export/import formats already supported by the bundled Pandoc
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main.js` (export submenu ~`main.js:864-959`; `exportFile()` at `main.js:1766`; the format switch inside `performExportWithOptions`/`buildPandocExportArgs` — see Task 23, which replaces string-building with an args-array builder; add cases there, not to the old string-concat code)
|
||||||
|
|
||||||
|
**New formats to add** (all already importable per the existing import switch at `main.js:3507` — Pandoc supports both directions for each):
|
||||||
|
- Export: AsciiDoc (`asciidoc`), reStructuredText (`rst`), MediaWiki (`mediawiki`), Org-mode (`org`), Textile (`textile`), man page (`man`), Jupyter Notebook (`ipynb`).
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Add 7 new menu entries to the Export submenu (`main.js:864-959`), grouped in a new labeled section, each calling `exportFile('<format>')` with the format id above.
|
||||||
|
- [ ] **Step 2:** Add each format to the extension-mapping table used by the export path (the `formatExtMap` object at `main.js:2624-2629` — add `asciidoc: 'adoc', mediawiki: 'wiki'`; the rest already match their format id as extension).
|
||||||
|
- [ ] **Step 3:** RULING (pre-flight scan, execution order is Phase A→B→C→D, so Task 23 has NOT run yet when this task executes): add each format as an additional `-t <format>` case to the **current** string-concatenation `pandocCmd` logic in `performExportWithOptions` (the same pattern already used for `'json'`, `'beamer'`, `'jira'` etc. around `main.js:2825-2965` — a simple `pandocCmd = \`${getPandocPath()} "${currentFile}" -t <format> -o "${outputFile}"\`; exportWithPandoc(pandocCmd, outputFile, format);` branch per new format is sufficient; do not introduce any new string-interpolated user-controlled fields — these 7 formats take no extra options beyond the standard ones already handled generically above the format switch). When Task 23 runs later (Phase D) it will read the current state of this function, per its own Step 3 instruction to "read every one of the sites... in full," and MUST carry these 7 new cases into its args-array rewrite — that responsibility already belongs to SEC-1's own scope and needs no separate action here.
|
||||||
|
- [ ] **Step 4:** Manually verify: export the currently-open sample markdown file to each of the 7 new formats, confirm each produces a non-empty output file Pandoc itself can round-trip (`pandoc out.rst -o roundtrip.md` succeeds).
|
||||||
|
- [ ] **Step 5:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 6:** Commit: `git add src/main.js && git commit -m "feat(export): expose AsciiDoc, RST, MediaWiki, Org, Textile, man, ipynb export formats"`
|
||||||
|
|
||||||
|
### Task 14: Git branch / diff / push / pull
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main/GitOperations.js`
|
||||||
|
- Modify: `tests/` (find and extend the existing GitOperations test file — grep `tests/**/GitOperations*`; if none exists, create `tests/main/GitOperations.test.js`)
|
||||||
|
- Modify: `src/main.js` (register 4 new `ipcMain.handle` calls near the existing git handlers, `main.js:4889-4904`)
|
||||||
|
- Modify: `src/preload.js` (add `'git-branch'`, `'git-diff'` is already listed but unhandled — see below, `'git-push'`, `'git-pull'` to `ALLOWED_SEND_CHANNELS`)
|
||||||
|
- Modify: `src/sidebar/git-panel.js`, `src/renderer.js:1714-1731`
|
||||||
|
|
||||||
|
**Interfaces (add to `GitOperations.js`, matching the existing `try { ... } catch (err) { return { error: err.message } }` pattern used by every existing function there):**
|
||||||
|
```javascript
|
||||||
|
async function diff(dir, file) { /* git.diff([file]) if file given, else git.diff() for full working-tree diff */ }
|
||||||
|
async function branches(dir) { /* git.branchLocal() — returns { all, current, branches } */ }
|
||||||
|
async function checkoutBranch(dir, name, isNew) { /* isNew=true: git.checkoutLocalBranch(name); else git.checkout(name) */ }
|
||||||
|
async function push(dir) { /* git.push() */ }
|
||||||
|
async function pull(dir) { /* git.pull() */ }
|
||||||
|
module.exports = { getStatus, stage, commit, log, diff, branches, checkoutBranch, push, pull };
|
||||||
|
```
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Write/extend the Jest test file covering `diff`, `branches`, `checkoutBranch`, `push`, `pull` against a real temp git repo (follow whatever fixture pattern the existing Git-related tests use — if this is the first GitOperations test file, initialize a repo with `simple-git` itself inside `beforeEach` using `fs.mkdtempSync` + `simpleGit(tmpDir).init()`, matching how `simple-git` is already used in the module under test).
|
||||||
|
- [ ] **Step 2:** Run the new tests — expect FAIL (functions don't exist).
|
||||||
|
- [ ] **Step 3:** Implement the 5 new functions in `GitOperations.js` per the interfaces above.
|
||||||
|
- [ ] **Step 4:** Run the tests — expect PASS.
|
||||||
|
- [ ] **Step 5:** In `main.js`, register handlers next to the existing 4:
|
||||||
|
```javascript
|
||||||
|
ipcMain.handle('git-diff', async (event, { file }) => {
|
||||||
|
const dir = path.dirname(currentFile || app.getPath('documents'));
|
||||||
|
return GitOperations.diff(dir, file);
|
||||||
|
});
|
||||||
|
ipcMain.handle('git-branches', async () => GitOperations.branches(path.dirname(currentFile || app.getPath('documents'))));
|
||||||
|
ipcMain.handle('git-checkout', async (event, { name, isNew }) => GitOperations.checkoutBranch(path.dirname(currentFile || app.getPath('documents')), name, isNew));
|
||||||
|
ipcMain.handle('git-push', async () => GitOperations.push(path.dirname(currentFile || app.getPath('documents'))));
|
||||||
|
ipcMain.handle('git-pull', async () => GitOperations.pull(path.dirname(currentFile || app.getPath('documents'))));
|
||||||
|
```
|
||||||
|
(Match whatever `dir` resolution the existing `git-status` handler at `main.js:4889-4891` actually uses — read those 3 lines first and reuse the identical expression rather than inventing a new one.)
|
||||||
|
- [ ] **Step 6:** Add `'git-branches'`, `'git-checkout'`, `'git-push'`, `'git-pull'` to `ALLOWED_SEND_CHANNELS` in `preload.js` (`'git-diff'` is already present).
|
||||||
|
- [ ] **Step 7:** In `src/sidebar/git-panel.js`, rename the unused `_gitDiff` parameter to `gitDiff` and add UI to actually call it (a "diff" button/icon per changed file in the status list, rendering the returned diff text in a `<pre>` block or similar — follow the panel's existing rendering style for the status list). Add branch/push/pull UI following the same panel's existing button/section style.
|
||||||
|
- [ ] **Step 8:** In `renderer.js:1714-1731`, pass the 4 new callbacks (`gitBranches`, `gitCheckout`, `gitPush`, `gitPull`) into `getRenderGitPanel()` alongside the existing ones.
|
||||||
|
- [ ] **Step 9:** Manually verify in a real git-tracked test folder: view a file diff, list branches, create+checkout a new branch, (push/pull only if a real remote is available — otherwise verify the IPC round-trip returns a sane `{error: ...}` for a repo with no remote, not a crash).
|
||||||
|
- [ ] **Step 10:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 11:** Commit: `git add -A && git commit -m "feat(git): add diff, branch, checkout, push, pull to Git sidebar panel"`
|
||||||
|
|
||||||
|
### Task 15: More PDF operations — extract text, page numbers, crop, extract images
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main/PDFOperations.js`, its test file (grep `tests/**/PDFOperations*`)
|
||||||
|
- Modify: `src/main.js` (`process-pdf-operation` already dispatches via `executeOperation` — no new handler needed, just new `case`s in `PDFOperations.js`'s existing switch at line 404)
|
||||||
|
- Modify: renderer PDF editor dialog UI (wherever the existing operation list/buttons are — find via the `show-pdf-editor-dialog` listener at `renderer.js:3685`)
|
||||||
|
|
||||||
|
**Interfaces (add to the existing `executeOperation` switch, `PDFOperations.js:404-430`):**
|
||||||
|
```javascript
|
||||||
|
async function pdfExtractText(data) { /* data: {inputPath}. Use pdf-lib's page.getTextContent() is NOT available in pdf-lib — pdf-lib has no text extraction. Use pdfjs-dist (already a dependency) instead: load with pdfjs-dist, iterate pages, getTextContent(), join strings. Return { success: true, text } */ }
|
||||||
|
async function pdfAddPageNumbers(data) { /* data: {inputPath, outputPath, position, startNumber}. For each page, drawText via pdf-lib at the given corner (reuse the position-mapping switch already present in pdfWatermark, PDFOperations.js:258-287, for corner math). */ }
|
||||||
|
async function pdfCrop(data) { /* data: {inputPath, outputPath, margins: {top,bottom,left,right}} in points. Use page.setCropBox(x, y, width, height) computed from the page's existing MediaBox minus margins. */ }
|
||||||
|
async function pdfExtractImages(data) { /* data: {inputPath, outputDir}. pdf-lib doesn't expose embedded image extraction either — use pdfjs-dist's page.getOperatorList() + page.objs to pull OPS.paintImageXObject image data, write each as PNG via sharp (already a dependency after Task 8). Return { success: true, count, files: string[] } */ }
|
||||||
|
```
|
||||||
|
Add 4 new `case` branches to `executeOperation` (`'extractText'`, `'pageNumbers'`, `'crop'`, `'extractImages'`) and add all 4 to `module.exports`.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Read `PDFOperations.js:233-317` (`pdfWatermark`) in full to reuse its exact position-to-coordinate mapping logic for `pdfAddPageNumbers` rather than re-deriving it.
|
||||||
|
- [ ] **Step 2:** Write tests for all 4 new functions in the existing PDFOperations test file, generating a minimal test PDF at test time via `pdf-lib`'s `PDFDocument.create()` (mirror however the existing test file already builds its fixture PDFs — check its `beforeEach`).
|
||||||
|
- [ ] **Step 3:** Run new tests — expect FAIL.
|
||||||
|
- [ ] **Step 4:** Implement the 4 functions.
|
||||||
|
- [ ] **Step 5:** Run new tests — expect PASS.
|
||||||
|
- [ ] **Step 6:** Add 4 corresponding buttons/menu entries to the PDF editor dialog UI, following its existing per-operation button pattern exactly (find where 'Watermark' or 'Rotate' is wired in the renderer PDF dialog and copy that structure).
|
||||||
|
- [ ] **Step 7:** Manually verify each of the 4 operations against a real PDF via the app UI.
|
||||||
|
- [ ] **Step 8:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 9:** Commit: `git add -A && git commit -m "feat(pdf): add extract text, page numbers, crop, extract images operations"`
|
||||||
|
|
||||||
|
### Task 16: PDF form field fill/flatten
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main/PDFOperations.js` (+ test file), PDF editor dialog UI
|
||||||
|
|
||||||
|
**Interfaces:**
|
||||||
|
```javascript
|
||||||
|
async function pdfGetFormFields(data) { /* data: {inputPath}. PDFDocument.load(bytes) -> pdfDoc.getForm().getFields() -> map each to {name, type, value}. Return { success: true, fields } */ }
|
||||||
|
async function pdfFillForm(data) { /* data: {inputPath, outputPath, values: Record<string,string>, flatten}. Load, getForm(), for each key in values call form.getTextField(key).setText(value) (wrap per-field in try/catch to skip fields that don't exist or aren't text fields — this app's convention per pdfWatermark is to fail loudly on real errors but this is a batch-of-independent-fields case, so log+skip per-field failures and continue). If flatten, call form.flatten() before saving. */ }
|
||||||
|
```
|
||||||
|
Add `'formFields'` (get) and `'fillForm'` cases to `executeOperation`, add both to exports.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Write tests building a test PDF with an AcroForm text field via `pdf-lib`'s `form.createTextField()` API (check pdf-lib's docs/existing usage in the codebase for the exact field-creation calls — `PDFOperations.js` already imports `pdf-lib`, follow its existing import style).
|
||||||
|
- [ ] **Step 2:** Run tests — expect FAIL.
|
||||||
|
- [ ] **Step 3:** Implement both functions.
|
||||||
|
- [ ] **Step 4:** Run tests — expect PASS.
|
||||||
|
- [ ] **Step 5:** Add a "Fill Form" UI entry to the PDF editor dialog: on open, call `formFields` to list detected fields, render a text input per field, a "Flatten after fill" checkbox, then call `fillForm` on submit.
|
||||||
|
- [ ] **Step 6:** Manually verify against a real fillable PDF (search for one under `tests/fixtures/` or create one with `pdf-lib` in a scratch script — do not commit the scratch script).
|
||||||
|
- [ ] **Step 7:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 8:** Commit: `git add -A && git commit -m "feat(pdf): add form field detection, fill, and flatten"`
|
||||||
|
|
||||||
|
### Task 17: Plugin API — export-format and file-reader registration hooks
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/plugins/plugin-context.js`, `src/plugins/plugin-loader.js` (or wherever plugin manifests are validated/loaded — grep `plugin-loader.js`), `src/main.js` (export format switch — needs to consult plugin-registered formats)
|
||||||
|
|
||||||
|
**Interfaces (extend `PluginContext`, `plugin-context.js:64-71`, alongside the existing `this.exports` block):**
|
||||||
|
```javascript
|
||||||
|
this.formats = {
|
||||||
|
registerExportFormat: (id, opts) => {
|
||||||
|
// opts: { label, extension, handler: async (markdownContent, outputPath, options) => void }
|
||||||
|
if (formatRegistry) formatRegistry.register(`${pluginId}:${id}`, opts);
|
||||||
|
},
|
||||||
|
};
|
||||||
|
```
|
||||||
|
This requires a new small `FormatRegistry` (mirror the existing `plugin-registry.js` pattern — read it first to match its exact API shape, e.g. `register(id, opts)` / `getAll()` / `get(id)`) injected into `PluginContext`'s constructor `deps` alongside `sidebar`/`commands`/`statusBar`.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Read `src/plugins/plugin-registry.js` in full to learn its exact class/function shape before adding a sibling `FormatRegistry` (or extending the existing registry with a new namespace if it's already generic enough — prefer extending over duplicating if the existing registry is namespace-agnostic).
|
||||||
|
- [ ] **Step 2:** Add `registerExportFormat` to `PluginContext` per the interface above, wired to whatever registry mechanism Step 1 determined is the right fit.
|
||||||
|
- [ ] **Step 3:** In `src/main.js`'s export dispatch path (wherever the Export submenu's dynamic entries would need to merge in plugin formats — likely requires the Export submenu to be rebuilt after plugin load, similar to how `createMenu()` is already called after recent-files change in Task 2; check if `createMenu()` is idempotent/safe to call after plugin loading completes), add plugin-registered formats as additional Export submenu entries whose `click` handler calls the plugin's registered `handler` function instead of Pandoc.
|
||||||
|
- [ ] **Step 4:** Update the built-in `writing-studio` plugin's manifest/index (`src/plugins/built-in/`) with a trivial example usage of `registerExportFormat` (e.g. exporting sprint data as a `.txt` summary) — this both documents the new API and gives Step 5's manual test something concrete to click.
|
||||||
|
- [ ] **Step 5:** Write a unit test in `tests/plugins/` (find the existing plugin test directory/pattern) verifying a plugin calling `context.formats.registerExportFormat(...)` results in the registry containing the namespaced entry.
|
||||||
|
- [ ] **Step 6:** Manually verify: `npm start`, confirm the writing-studio example format appears in the Export menu and produces the expected output file when clicked.
|
||||||
|
- [ ] **Step 7:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 8:** Commit: `git add -A && git commit -m "feat(plugins): add export-format registration hook to plugin API"`
|
||||||
|
|
||||||
|
### Task 18: DOCX/EPUB template gallery UI
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/renderer.js` (export dialog for DOCX/EPUB — find via `exportWordWithTemplate()` at `main.js:881` and follow into whatever renderer dialog it opens)
|
||||||
|
- Modify: `src/main.js` (wherever the existing Word-template list is sourced from — grep `WordTemplateExporter` and `listTemplates`/`getTemplates`-style function)
|
||||||
|
|
||||||
|
**Verified context:** `main.js` already has `exportWordWithTemplate()` and `WordTemplateExporter` (`src/wordTemplateExporter.js`) — a template mechanism for DOCX exists but per the feature-inventory research pass has "no discoverable UI" for browsing available templates; the user has to already know a template exists. Read `src/wordTemplateExporter.js` in full first to learn how templates are currently listed/selected (is there a folder of `.dotx`/`.docx` template files? A hardcoded list?) before designing the gallery.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Read `src/wordTemplateExporter.js` and the renderer dialog `exportWordWithTemplate()` opens, to learn the exact current template-selection mechanism (function names, data shape).
|
||||||
|
- [ ] **Step 2:** Add a visual gallery (grid of template name + thumbnail-if-available, or name + short description if no thumbnails exist) to that same dialog, replacing or augmenting whatever minimal selector currently exists, following the dialog's existing CSS/markup conventions (check `src/styles.css` for the dialog's existing classes before inventing new ones).
|
||||||
|
- [ ] **Step 3:** Do the same for EPUB export if `main.js` has an equivalent EPUB-template mechanism (grep for `epub` + `template`); if none exists, skip EPUB (do not invent a template system that doesn't exist — note this explicitly as out of scope in the commit message rather than silently dropping it).
|
||||||
|
- [ ] **Step 4:** Manually verify: open the DOCX export dialog, see the template gallery, pick one, confirm the exported DOCX uses it.
|
||||||
|
- [ ] **Step 5:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 6:** Commit: `git add -A && git commit -m "feat(export): add visual template gallery to DOCX export dialog"`
|
||||||
|
|
||||||
|
### Task 19: CSV-to-markdown-table toolbar converter
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/renderer.js` (editor toolbar — find the existing toolbar button registration pattern, e.g. near table generator/ASCII generator toolbar buttons)
|
||||||
|
|
||||||
|
**Verified context:** Pandoc already imports CSV (`main.js:3507` import switch includes `csv`). This task adds a quick in-editor action: paste/select CSV-like text, convert to a markdown table without leaving the editor (distinct from the full file-import path).
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Add a toolbar button "CSV → Table" (or a Command Palette entry, matching whichever pattern is more consistent with similar single-action editor tools already in the toolbar — check what's already there before choosing).
|
||||||
|
- [ ] **Step 2:** Implement a pure client-side CSV→Markdown-table converter function in `renderer.js` (no need to round-trip through Pandoc for this simple case — parse the current selection's lines by comma, respecting basic double-quote-wrapped fields containing commas; build a `| a | b |` / `|---|---|` markdown table). Keep this function small and testable — extract it to `src/lib/csv-to-markdown-table.js` if `src/renderer.js` doesn't already have a `src/lib/`-style extraction pattern for similar pure functions (check first).
|
||||||
|
- [ ] **Step 3:** Write a Jest unit test for the converter function covering: simple CSV, quoted fields containing commas, ragged rows (fewer columns in some rows — pad with empty cells), empty input.
|
||||||
|
- [ ] **Step 4:** Wire the toolbar button to: read the editor selection, run the converter, replace the selection with the resulting markdown table.
|
||||||
|
- [ ] **Step 5:** Manually verify: select a few lines of comma-separated text in the editor, click the button, confirm it becomes a proper markdown table.
|
||||||
|
- [ ] **Step 6:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 7:** Commit: `git add -A && git commit -m "feat(editor): add CSV-to-markdown-table toolbar converter"`
|
||||||
|
|
||||||
|
### Task 20: Document Compare / diff view (completes Task 6)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/renderer.js` (new listener for `show-document-compare`, whitelisted in Task 6)
|
||||||
|
- Create: `src/renderer/document-compare-dialog.js` (or inline in `renderer.js` if that's the dominant pattern for similar dialogs — match Task 12's finding on dialog-module conventions)
|
||||||
|
|
||||||
|
**Verified context:** `main.js:1411-1413` sends `show-document-compare`; Task 6 whitelisted the channel; nothing renders it yet. This task adds an actual two-pane diff: either two arbitrary local files, or (leveraging Task 14's new `GitOperations.diff`) the current file against its last-committed git revision.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Build a simple two-file diff dialog: two "choose file" buttons (or one defaulting to the currently-open tab + one file picker for the comparison target), a line-by-line diff render. Do not add a new diff-algorithm dependency — write a minimal LCS-based line diff in a small pure function (`src/lib/line-diff.js`) since the app has no existing diff library; keep it under ~60 lines (standard textbook LCS-diff, not a full Myers-diff library port).
|
||||||
|
- [ ] **Step 2:** Write a Jest unit test for the line-diff function: identical files (no diffs), pure additions, pure deletions, mixed changes.
|
||||||
|
- [ ] **Step 3:** Add a "Compare with Git HEAD" option in the same dialog when the current file is inside a git repo, using `GitOperations.diff` from Task 14 (raw git diff text render, separate code path from the line-diff function — git's own diff output is already a diff, don't re-diff it).
|
||||||
|
- [ ] **Step 4:** Wire `ipcRenderer.on('show-document-compare', () => { /* open the dialog */ })` in `renderer.js`.
|
||||||
|
- [ ] **Step 5:** Manually verify: Tools → Document Compare, compare two local markdown files, confirm additions/deletions are visually distinguished (e.g. green/red line backgrounds, matching the app's existing theme CSS variables rather than hardcoded colors).
|
||||||
|
- [ ] **Step 6:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 7:** Commit: `git add -A && git commit -m "feat(compare): implement Document Compare dialog with local-diff and git-HEAD-diff modes"`
|
||||||
|
|
||||||
|
### Task 21: Export presets/profiles
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main.js` (near `get-header-footer-settings`/`save-header-footer-settings` handlers, `main.js:1857-1886`)
|
||||||
|
- Modify: renderer export-options dialog (wherever `export-with-options` is invoked from — grep `export-with-options` in `renderer.js`)
|
||||||
|
|
||||||
|
**Interfaces:**
|
||||||
|
```javascript
|
||||||
|
// main.js — new handlers, settings persisted the same way header/footer settings already are
|
||||||
|
// (read main.js:1857-1886 first to copy its exact settings-file read/write pattern, e.g. settings.json path + key)
|
||||||
|
ipcMain.handle('get-export-presets', async () => { /* returns array of {id, name, format, options} */ });
|
||||||
|
ipcMain.handle('save-export-preset', async (event, preset) => { /* upsert by id, persist, return updated list */ });
|
||||||
|
ipcMain.handle('delete-export-preset', async (event, presetId) => { /* remove by id, persist, return updated list */ });
|
||||||
|
```
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Read `main.js:1857-1886` in full to learn the exact settings-persistence pattern already used (this app uses a custom JSON file store per `CLAUDE.md`, not `electron-store` — confirm the exact file/key convention and reuse it verbatim for presets, e.g. a new top-level `exportPresets` array in the same `settings.json`).
|
||||||
|
- [ ] **Step 2:** Implement the 3 handlers per the interfaces above, add all 3 channel names to `ALLOWED_SEND_CHANNELS` in `preload.js`.
|
||||||
|
- [ ] **Step 3:** In the renderer's export-options dialog, add a "Save as preset" button (captures the current dialog's option values, prompts for a name, calls `save-export-preset`) and a preset dropdown at the top of the dialog (populated via `get-export-presets` on open; selecting one pre-fills the dialog's fields) plus a delete icon per preset row.
|
||||||
|
- [ ] **Step 4:** Manually verify: configure export options, save as a preset, close and reopen the dialog, confirm the preset is selectable and correctly restores all fields; delete it, confirm it's gone.
|
||||||
|
- [ ] **Step 5:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 6:** Commit: `git add -A && git commit -m "feat(export): add save/select/delete export presets"`
|
||||||
|
|
||||||
|
### Task 22: Batch PDF operations UI (beyond format conversion)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/renderer.js` (Batch menu handling — find the `show-batch-converter` listener with `'pdf'` type)
|
||||||
|
- Modify: `src/main.js` (extend the batch loop to support PDFOperations, not just format conversion)
|
||||||
|
|
||||||
|
**Verified context:** `main.js:1293-1296` already has a "Batch PDF Conversion..." menu item sending `show-batch-converter` with type `'pdf'`, but (per the existing batch conversion handlers at `main.js:2454-2563`) batch only does format conversion via `convertWithLibreOffice`/pandoc — it never calls into `PDFOperations.executeOperation` for bulk watermark/compress/rotate across many files.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** In the renderer's batch dialog (wherever the `'pdf'`-typed batch dialog renders), add an operation-type selector when the batch type is `'pdf'`: "Convert format" (existing behavior, keep as default) vs. "Bulk PDF Operation" (new: pick one of merge/split/compress/rotate/watermark/etc. plus that operation's fields, same fields as the single-file PDF editor dialog).
|
||||||
|
- [ ] **Step 2:** Add a new `ipcMain.on('batch-pdf-operation', async (event, { operation, data, inputFolder, includeSubfolders }) => {...})` handler in `main.js` that collects matching `.pdf` files (reuse the exact `collectFiles` recursive helper already defined inside `universal-convert-batch`, `main.js:2472-2484` — extract it to a shared top-level function if it isn't already, since Task 22 needs the identical logic) and calls `PDFOperations.executeOperation(operation, {...data, inputPath: filePath, outputPath: ...})` per file in a loop, reporting progress via `mainWindow.webContents.send('batch-progress', ...)` matching the existing batch progress-reporting convention.
|
||||||
|
- [ ] **Step 3:** Add `'batch-pdf-operation'` to `ALLOWED_SEND_CHANNELS`.
|
||||||
|
- [ ] **Step 4:** Manually verify: batch-watermark a folder of 2-3 test PDFs, confirm each output file has the watermark applied.
|
||||||
|
- [ ] **Step 5:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 6:** Commit: `git add -A && git commit -m "feat(pdf): add bulk PDF operations (watermark/compress/rotate/etc.) to batch converter"`
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase D — Security Remediation
|
||||||
|
|
||||||
|
### Task 23: Fix Pandoc argument-injection vulnerability (CRITICAL)
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main.js` (every `pandocCmd` string-concatenation site: `performExportWithOptions` ~`2623-2965`, `exportPDFViaWordTemplate`-adjacent function ~`2980-3050`, `runPandocCmd`/`parseCommand` at `231-282`, the import-side builder at `~3501`, and the enhanced-export builder at `~3997-4097`)
|
||||||
|
- Modify: `tests/` (new regression test)
|
||||||
|
|
||||||
|
**Verified root cause:** `performExportWithOptions` and its siblings build a shell-style command **string** by concatenating user-influenced values (export dialog fields: `options.template`, `options.metadata` key/values, `options.variables` key/values, `options.bibliography` path, `options.csl` path, `options.geometry`, footer text, CSS file path) wrapped in double quotes, e.g. `` pandocCmd += ` --bibliography="${options.bibliography}"` ``. This string is later tokenized by `parseCommand()` (`main.js:253-282`) — a hand-rolled parser that toggles an `inQuotes` flag on any `"` or `'` character and has **no backslash-escape handling at all**. The `.replace(/"/g, '\\"')` escaping applied to `metadata`/`variables` values therefore does nothing protective: `parseCommand` sees the literal backslash as an ordinary character and the following `"` still toggles quote state exactly as an unescaped quote would. Any field that reaches `parseCommand` un-sanitized (which is most of them — `template`, `bibliography`, `csl`, `geometry`, footer text are never escaped at all) lets an attacker-controlled value containing a `"` character break out of its intended single argument and inject additional argv elements into the `execFile(pandocPath, args, ...)` call at the end of `runPandocCmd`. Because `execFile` (not `exec`) is used, this is **not** a shell-injection (no `;`, `|`, backticks interpreted) — it is **argument injection into pandoc itself**, which is still exploitable: Pandoc supports `--lua-filter=<path>` and `--filter=<path>` (arbitrary Lua/executable code execution), `-o <path>` (arbitrary file overwrite by injecting a second `-o`), and `--resource-path`/`--extract-media` (arbitrary-path writes). A malicious value in any of the un-escaped fields above is enough to reach that severity — no shell metacharacters are even needed, just a `"` followed by a new flag.
|
||||||
|
|
||||||
|
**Fix approach:** Stop building command strings entirely for every one of these call sites. Replace with direct `execFile(pandocPath, argsArray, ...)` calls where `argsArray` is built as a real JS array (`push`, never string interpolation) — this is exactly what `PDFOperations.js`/`GitOperations.js` already do correctly, and what `AudioOperations.js`/`VideoOperations.js`/`ImageOperations.js` do from Phase B. `parseCommand`/`runPandocCmd`'s string-based indirection should be deleted once all call sites are converted — do not leave it in place as unused dead code (would violate the "no forbidden markers/half-finished" standard); if any call site turns out to be legitimately hard to convert in this task, that is a signal that call site needs its own careful sub-step, not a reason to keep the vulnerable helper around "just in case."
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Write a regression test proving the vulnerability exists in the *current* code, in a new file `tests/main/pandoc-arg-safety.test.js`, calling `parseCommand` directly (it will need to be exported from `main.js` for testing, or extracted first — see Step 2) with a crafted value and asserting it does NOT produce an injected extra argument:
|
||||||
|
```javascript
|
||||||
|
// This test is written to FAIL against the current parseCommand implementation,
|
||||||
|
// proving the vulnerability, then PASS once Step 3+ removes the vulnerable path.
|
||||||
|
const { buildPandocArgs } = require('../../src/main/PandocArgs'); // new module created in Step 3
|
||||||
|
|
||||||
|
test('a bibliography path containing a double quote cannot inject extra pandoc flags', () => {
|
||||||
|
const malicious = '/tmp/x.bib" --lua-filter=/tmp/evil.lua -o "/tmp/x.bib';
|
||||||
|
const args = buildPandocArgs({
|
||||||
|
inputFile: '/in.md',
|
||||||
|
outputFile: '/out.pdf',
|
||||||
|
format: 'pdf',
|
||||||
|
options: { bibliography: malicious },
|
||||||
|
});
|
||||||
|
// The malicious string must appear as exactly ONE argv element (whatever
|
||||||
|
// value it ends up as), never split into multiple args, and
|
||||||
|
// '--lua-filter=/tmp/evil.lua' must not appear as its own array element.
|
||||||
|
expect(args).not.toContain('--lua-filter=/tmp/evil.lua');
|
||||||
|
expect(args.filter((a) => a.includes(malicious) || a === malicious).length).toBeLessThanOrEqual(1);
|
||||||
|
});
|
||||||
|
```
|
||||||
|
- [ ] **Step 2:** Run the test — confirm it fails to even import (module doesn't exist yet) — this is expected; proceed to build the real module.
|
||||||
|
- [ ] **Step 3:** Create `src/main/PandocArgs.js` — a pure module exporting `buildPandocArgs({ inputFile, outputFile, format, options })` that returns a plain `string[]` args array (no string concatenation of the whole command — only individual argv elements are ever created via `.push(...)`), reimplementing every option currently handled across the string-building sites (`toc`, `tocDepth`, `numberSections`, `citeproc`, `bibliography`, `csl`, `template`, `metadata` (loop → `push('-M', `${key}=${value}`)` — no manual quote-escaping needed at all, since array elements are passed to `execFile` as literal argv, never re-parsed), `variables` (same pattern with `-V`), `pdfEngine`, `geometry`, monospace font header include, footer text). Read every one of the sites listed in "Files" above in full before writing this, to ensure no option is silently dropped.
|
||||||
|
- [ ] **Step 4:** Run the Step 1 test — expect PASS now.
|
||||||
|
- [ ] **Step 5:** Replace every call site that currently builds a `pandocCmd` string and calls `runPandocCmd(pandocCmd, ...)` with: build args via `PandocArgs.buildPandocArgs(...)`, then `execFile(getPandocPath(), args, { maxBuffer: 10 * 1024 * 1024 }, callback)` directly — inline this or add a tiny `runPandocArgs(args, callback)` helper next to the deleted `runPandocCmd` to avoid repeating the `execFile` options object at every site.
|
||||||
|
- [ ] **Step 6:** Delete `parseCommand` and the old `runPandocCmd` (`main.js:231-282`) once no call site references them (grep to confirm zero remaining references before deleting).
|
||||||
|
- [ ] **Step 7:** Manually re-run every export format the app supports (or at minimum: PDF, DOCX, HTML, EPUB, LaTeX — the ones with the most option surface) via the UI, confirming exports still succeed with the new args-array path, including with TOC/metadata/bibliography options actually filled in (not just defaults) to catch any option silently dropped in Step 3.
|
||||||
|
- [ ] **Step 8:** `npm run lint && npm test`
|
||||||
|
- [ ] **Step 9:** Commit: `git add -A && git commit -m "fix(security): eliminate pandoc argument-injection vector by building execFile args arrays directly"`
|
||||||
|
|
||||||
|
### Task 24: Formal security-review pass
|
||||||
|
|
||||||
|
**Files:** N/A — process task.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** Invoke the `security-review` skill against the full working tree (post Phase A/B/C/SEC-1 changes) to catch anything beyond what this plan's manual audit already found — particularly re-check the new `AudioOperations`/`VideoOperations`/`ImageOperations` modules and the new file-picker/batch handlers added in Phase B/C for the same class of injection risk (all must use `execFile` with array args — verify none of them slipped into string-building), and check the new plugin `registerExportFormat` hook (Task 17) for arbitrary-code-execution risk if a malicious/compromised plugin could abuse it beyond what a plugin can already do.
|
||||||
|
- [ ] **Step 2:** For every finding the skill reports, triage severity and either fix inline (Critical/High) or explicitly log as an accepted/deferred risk with reasoning (Medium/Low) — do not silently drop findings.
|
||||||
|
- [ ] **Step 3:** Produce a short written security summary (what was found across both the manual audit and the formal pass, what was fixed, what if anything was deferred and why) and save it to `docs/superpowers/plans/2026-08-23-security-assessment-summary.md`.
|
||||||
|
- [ ] **Step 4:** Commit any additional fixes with individual, scoped commit messages (do not batch unrelated security fixes into one commit).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase E — Rebuild Local Release
|
||||||
|
|
||||||
|
### Task 25: Full verification + local build
|
||||||
|
|
||||||
|
**Files:** N/A — build/verification task.
|
||||||
|
|
||||||
|
- [ ] **Step 1:** `npm run lint` — must pass clean.
|
||||||
|
- [ ] **Step 2:** `npm run format:check` — must pass clean (run `npm run format` first if not).
|
||||||
|
- [ ] **Step 3:** `npm test` — all suites must pass; confirm the total test count has grown from the 247-test baseline (new tests from Phase B/C tasks should be present).
|
||||||
|
- [ ] **Step 4:** `npm run download-tools` (ensures bundled Pandoc/tool binaries are current for the build).
|
||||||
|
- [ ] **Step 5:** `npm run build:local` (per `package.json` script — builds Linux + Windows targets; this matches "local release" for this dev machine's platform(s)). If this machine is Linux-only and Windows cross-build tooling (wine, etc.) isn't available, fall back to `npm run build:linux-ci` and note the Windows build was skipped and why.
|
||||||
|
- [ ] **Step 6:** Verify the `dist/` output contains the expected artifacts (`.deb`, `.AppImage` at minimum) and that the packaged app launches (`./dist/*.AppImage` or the unpacked `dist/linux-unpacked/markdown-converter` binary) without immediate crash — smoke-test opening a markdown file and exporting to PDF from the packaged build specifically (not `npm start`), since `asarUnpack` behavior for `sharp`/`ffmpeg-static`/fonts only manifests in a packaged build.
|
||||||
|
- [ ] **Step 7:** Report the final `dist/` artifact list and versions to the user; do not bump `package.json`'s version number as part of this task unless the user asks — that is a separate release-management decision.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Task 26: Migrate `File.path` → `webUtils.getPathForFile` (Electron 41 fix) — appended by controller ruling 2026-08-23
|
||||||
|
|
||||||
|
**Origin:** Task 20 review. `File.path` was removed in Electron 32; this app pins `electron ^41.1.1` and has no `webUtils` usage — every renderer file-picker reading `file.path` gets `undefined` at runtime (~15 sites: universal converter, PDF editor pickers, bibliography/CSL pickers, custom template, media merge lists, document-compare File B).
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/preload.js` (expose a `getFilePath(file)` helper via `webUtils.getPathForFile`)
|
||||||
|
- Modify: `src/renderer.js`, `src/renderer/media-operations-dialog.js`, `src/renderer/document-compare-dialog.js` (migrate all `file.path` reads to the helper)
|
||||||
|
|
||||||
|
**Steps:**
|
||||||
|
1. In `src/preload.js`, expose `getFilePath: (file) => webUtils.getPathForFile(file)` on the existing `electronAPI` surface (webUtils is available in the preload/renderer context; it exists precisely to replace File.path). No new IPC channel needed — this is a synchronous in-process call.
|
||||||
|
2. Grep-migrate every `file.path` / `files[i].path` read in the three renderer files to `window.electronAPI.getFilePath(file)` (falling back to `file.path` if the helper is absent, to keep jsdom tests runnable — verify which tests mock this surface and update them to mock the helper).
|
||||||
|
3. Add a preload test asserting `getFilePath` is exposed (follow tests/preload.test.js conventions).
|
||||||
|
4. `npm run lint && npm test`.
|
||||||
|
5. Commit: `fix(renderer): migrate File.path reads to webUtils.getPathForFile for Electron 41`
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Task 27: PDF encrypt/decrypt/permissions — replace silent no-op with honest failure — appended by controller ruling 2026-08-23
|
||||||
|
|
||||||
|
**Origin:** Task 22 review (empirically verified). pdf-lib 1.17.1 cannot encrypt: `save({userPassword, ownerPassword, permissions})` silently ignores these options, `PDFDocument.load({password})` is not a LoadOptions field. Current behavior: `pdfEncrypt`/`pdfSetPermissions` write unprotected files and report success; `pdfDecrypt` reports success on non-encrypted inputs (copy no-op) and always fails on genuinely encrypted ones.
|
||||||
|
|
||||||
|
**Files:**
|
||||||
|
- Modify: `src/main/PDFOperations.js` (pdfEncrypt, pdfDecrypt, pdfSetPermissions), their renderer call sites if messages surface there, and `src/main/PDFBatchOperations.js` exclusion register comment (already excludes these ops — keep excluded, update the comment to reference this task).
|
||||||
|
|
||||||
|
**Steps:**
|
||||||
|
1. Capability-detect once at module load (probe whether the installed pdf-lib honors encryption — e.g. build a tiny in-memory PDFDocument, save with a userPassword, check raw bytes for `/Encrypt`; or simply pin the known limitation with a constant + comment referencing pdf-lib 1.17.1) — prefer the empirical probe so a future library swap re-enables the ops automatically.
|
||||||
|
2. When encryption is unsupported: pdfEncrypt/pdfSetPermissions return `{success: false, message: 'Password protection is not available in this build (pdf-lib lacks encryption support).'}`; pdfDecrypt returns an equivalent honest failure. Never write a file. Never report success.
|
||||||
|
3. Update the PDF editor dialog so these three controls are disabled with explanatory hint text when unavailable (grep renderer call sites for the encrypt/permissions handlers).
|
||||||
|
4. Update tests: existing encrypt/decrypt/permissions tests (they currently pin the broken behavior — rewrite to assert honest failure); keep any genuinely-passing load-with-password tests only if the probe says the library supports them.
|
||||||
|
5. `npm run lint && npm test`.
|
||||||
|
6. Commit: `fix(pdf): make encrypt/decrypt/permissions fail honestly instead of silent no-op`
|
||||||
|
|
||||||
|
**Out of scope (user decision pending):** swapping pdf-lib for an encryption-capable fork (e.g. @cantoo/pdf-lib) to restore the feature for real — new dependency, needs sign-off.
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
# Security Assessment Summary — MarkdownConverter (master branch)
|
||||||
|
|
||||||
|
**Date:** 2026-08-23 · **Scope:** full branch `6db54a5..HEAD` (feature-audit-and-hardening plan, 27 tasks) · **Method:** manual feature/security audit at plan time + formal review pass (Task 24: three-stage vulnerability scan — identify → false-positive filter at confidence ≥ 8 → inline fix of confirmed High findings)
|
||||||
|
|
||||||
|
## 1. What the manual audit found (plan Phases A–D)
|
||||||
|
|
||||||
|
| # | Finding | Severity | Resolution |
|
||||||
|
|---|---------|----------|------------|
|
||||||
|
| SEC-1 | Pandoc invocation built as shell-style string and re-tokenized — argument injection via crafted filenames/options/bibliography paths | **Critical** | Fixed — Task 23 (`d41b7df`): every invocation now `execFile(path, args[])` via pure builder `src/main/PandocArgs.js`; string tokenizer deleted; 21 injection-vector tests + differential exploit-split proof + 23 real-pandoc e2e checks |
|
||||||
|
| UX-1..7 | Seven non-working features: PDF menu IPC misrouting, media converter with 16 IPC channels and 0 handlers, dead New-from-Template menu, dead View-menu toggles, Clear-Recent-Files no-op, unreachable font settings, jszip/sharp misplaced in devDependencies | High (functional) | Fixed — Tasks 1–14; media backends (sharp/ffmpeg) implemented execFile-array-first |
|
||||||
|
| LAT-1 | `File.path` reads dead on Electron 41 (removed in v32; app pins ^41.1.1) — every renderer file-picker returned `undefined` | High (functional) | Found during Task 20 review; fixed — Task 26 (`32a5755`): `webUtils.getPathForFile` exposed in preload + main-window shim; all ~15 picker sites migrated |
|
||||||
|
| LAT-2 | pdf-lib 1.17.1 silently ignores `userPassword`/`ownerPassword`/`permissions` — PDF encrypt/permissions wrote **unprotected** files while reporting success; decrypt was a copy no-op | High (integrity) | Found during Task 22 review; fixed — Task 27 (`78afccc`): empirical capability probe (fail-closed), honest unavailability errors, UI controls disabled with hint. Real encryption requires a library swap (see deferred #D1) |
|
||||||
|
|
||||||
|
## 2. What the formal pass (Task 24) found
|
||||||
|
|
||||||
|
**Confirmed (confidence 8/10, HIGH) — fixed inline:**
|
||||||
|
|
||||||
|
- **Git sidebar XSS → code execution** (`src/sidebar/git-panel.js`): repo-derived branch names, git-status file names, commit messages/author names, and git stderr rendered into `innerHTML` unescaped in the `nodeIntegration:true` main window, whose CSP permits `'unsafe-inline'` handlers. A malicious repo (attacker-authored commit message or crafted branch name) cloned by the victim executes script with full Node access when the Git panel loads. Fixed — `eafaf6e`: `escapeHtml` (& < > " ') across all 13 sink sites; jsdom tests assert structural inertness (no `img`/`script` elements, no attribute breakout) and that `dataset` reads still return raw names for git operations.
|
||||||
|
|
||||||
|
**Candidate assessed and dropped (with evidence):**
|
||||||
|
|
||||||
|
- PowerShell BurntToast interpolation (`main.js` ~4344): pre-existing at origin/master in identical `execFile`-array form. The dialog path interpolates a `format` chosen from a hardcoded 12-entry list; the `--convert-to <format>` CLI path feeds raw argv into the same string — but argv is trusted local-user input (precedent: CLI flags are trusted), and no shell is involved. Not exploitable. (Evidence note: the "hardcoded list" rationale covers the dialog path only; the drop stands on the argv-trust precedent for the CLI path.)
|
||||||
|
|
||||||
|
**Verified clean (14 areas):** media operation backends and all batch handlers (execFile arrays throughout, no string re-tokenization); plugin system (no escalation beyond the renderer's existing privileges; format metadata reaches main only as native menu labels and save-dialog filters); all new dialog renderers (`textContent`-only for dynamic content); PDFOperations new ops (pdfjs/sharp in-process, no shell); wordTemplateExporter (all `<w:t>` insertions escaped, no zip extraction → no zip-slip); GitOperations (simple-git array args); settings/presets stores (no deep merge → no prototype pollution); PandocArgs completeness (tree-wide grep: zero surviving string-built pandoc invocations); font embedders (fixed family→filename maps); generator windows (no untrusted prefill); print-preview (DOMPurify flow); no `eval`/`new Function`; no variable-URL `shell.openExternal`; no secrets in the diff.
|
||||||
|
|
||||||
|
## 3. Deferred / accepted risks
|
||||||
|
|
||||||
|
| ID | Risk | Disposition |
|
||||||
|
|----|------|-------------|
|
||||||
|
| D1 | **Real PDF encryption unavailable** (pdf-lib limitation) — feature now fails honestly rather than lying | Accepted for this release. Restoring it means swapping pdf-lib for an encryption-capable fork (e.g. `@cantoo/pdf-lib`, API-compatible) — **needs explicit sign-off on a new dependency** |
|
||||||
|
| D2 | `nodeIntegration:true` + `contextIsolation:false` on mainWindow, pdfWindow, hiddenWindow; main window does not load `preload.js` (inline shim instead) — the IPC whitelist is a live control only on the two generator windows | Accepted legacy risk for this branch; owned by the react-electron migration (contextIsolation + preload-everywhere), tracked separately |
|
||||||
|
| D3 | Generator-window preload whitelist is broad (`execute-code`, `read-file`, `write-file`, `delete-file` reachable from isolated windows) | No current content vector into those windows; flag for the migration to narrow per-window APIs |
|
||||||
|
| D4 | CSP allows `'unsafe-inline'` / `'unsafe-eval'` (required by marked + Mermaid rendering model) | Accepted; revisit under the migration with a nonce-based CSP |
|
||||||
|
| D5 | `outline-panel.js` / `repl-panel.js` / `analytics-panel.js` have local `escapeHtml` helpers that do not escape quotes | Deferred hardening: unsafe only if reused in attribute contexts; no such current use found |
|
||||||
|
| D6 | `scripts/download-tools.js` downloads Pandoc/fonts without checksum pinning | Build-time supply-chain hardening; recommended follow-up (pin + verify SHA-256) |
|
||||||
|
| D7 | Misc functional edge cases (batch same-folder overwrite, `pdfSplit` non-positive interval loop, rate-limiter dialog stall) | Deferred minors, logged in the plan ledger; none security-relevant |
|
||||||
|
|
||||||
|
## 4. Verification state
|
||||||
|
|
||||||
|
- Test suite: **49 suites / 512 tests passing**; ESLint and Prettier clean at every task boundary (enforced per-task during execution).
|
||||||
|
- All new external-process code paths verified `execFile`-array by independent tree-wide grep (Task 23 review) and re-verified in the formal pass.
|
||||||
|
- **Release blocker (human step):** this environment cannot launch the Electron GUI. A human pass in the running app — light + dark themes, file picking in the main dialogs (File B in Document Compare, bibliography/CSL, universal converter, PDF editor), Git sidebar on a real repo — is required before shipping.
|
||||||
|
|
||||||
|
**Bottom line:** the one Critical (argument injection) and one confirmed High (Git panel XSS) are closed with tests; two latent silent-failure bugs (File.path, fake encryption) are fixed; the remaining exposure is the documented legacy trust model (D2–D4) owned by the planned Electron security migration plus one dependency decision (D1).
|
||||||
@@ -0,0 +1,426 @@
|
|||||||
|
# MarkdownConverter v5.0 — Platform Design
|
||||||
|
|
||||||
|
**Date:** 2026-04-14
|
||||||
|
**Status:** Approved
|
||||||
|
**Author:** Amit Haridas
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
Transform MarkdownConverter from a monolithic editor into an extensible platform with a plugin system and three feature packs, shipped together as v5.0.
|
||||||
|
|
||||||
|
## Subsystems
|
||||||
|
|
||||||
|
1. **Plugin System** — Lightweight plugin registry with extension points (sidebar, commands, settings, status bar, export hooks, event bus)
|
||||||
|
2. **Writing Studio Plugin** — Manuscript manager, goal tracking, writing sprints, snapshots, smart proofreading
|
||||||
|
3. **AI Assistant Plugin** — Multi-provider AI writing assistant (Ollama, LMStudio, GGUF direct with GPU, Anthropic, OpenAI)
|
||||||
|
4. **Collaboration Plugin** — Git-based async collaboration, comments/annotations, review requests
|
||||||
|
|
||||||
|
## Core Principle
|
||||||
|
|
||||||
|
**Existing functionality is never replaced or broken.** The plugin system is additive. All existing keyboard shortcuts, features, and UI remain untouched. Plugin shortcuts use `Ctrl+Alt+` namespace.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 1. Plugin System
|
||||||
|
|
||||||
|
### File Structure
|
||||||
|
|
||||||
|
```
|
||||||
|
src/
|
||||||
|
plugins/
|
||||||
|
plugin-registry.js # Load, register, lifecycle
|
||||||
|
plugin-api.js # Base class plugins extend
|
||||||
|
plugin-loader.js # Discovers and validates manifests
|
||||||
|
built-in/
|
||||||
|
writing-studio/
|
||||||
|
manifest.json
|
||||||
|
index.js
|
||||||
|
panels/
|
||||||
|
components/
|
||||||
|
ai-assistant/
|
||||||
|
manifest.json
|
||||||
|
index.js
|
||||||
|
providers/
|
||||||
|
collaboration/
|
||||||
|
manifest.json
|
||||||
|
index.js
|
||||||
|
```
|
||||||
|
|
||||||
|
### Manifest Schema
|
||||||
|
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"id": "writing-studio",
|
||||||
|
"name": "Writing Studio",
|
||||||
|
"version": "1.0.0",
|
||||||
|
"description": "Manuscript management, goal tracking, writing sprints",
|
||||||
|
"icon": "pen-tool",
|
||||||
|
"extensionPoints": {
|
||||||
|
"sidebar": { "panel": "panels/manuscript-panel.js", "order": 30 },
|
||||||
|
"settings": { "section": "settings/index.js" },
|
||||||
|
"statusBar": { "indicators": ["sprint-timer", "word-goal"] },
|
||||||
|
"commands": [
|
||||||
|
{ "id": "start-sprint", "label": "Start Writing Sprint", "shortcut": "Ctrl+Alt+S" },
|
||||||
|
{ "id": "take-snapshot", "label": "Take Snapshot", "shortcut": "Ctrl+Alt+N" }
|
||||||
|
],
|
||||||
|
"exportHooks": {
|
||||||
|
"preExport": "hooks/pre-export.js",
|
||||||
|
"postExport": "hooks/post-export.js"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"settings": [
|
||||||
|
{ "key": "dailyGoal", "type": "number", "default": 1000, "label": "Daily word goal" },
|
||||||
|
{ "key": "sprintDuration", "type": "number", "default": 25, "label": "Sprint duration (min)" }
|
||||||
|
]
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Plugin Lifecycle
|
||||||
|
|
||||||
|
1. PluginLoader discovers manifests in `built-in/` + user plugins directory
|
||||||
|
2. PluginRegistry validates manifests
|
||||||
|
3. Each plugin calls `Plugin.init(context)` receiving scoped API context
|
||||||
|
4. Extension points registered (sidebar panels, commands, status bar items)
|
||||||
|
5. Plugins activate lazily — sidebar panel loads JS when user clicks tab
|
||||||
|
|
||||||
|
### Plugin Context API
|
||||||
|
|
||||||
|
Each plugin's `init()` receives:
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
{
|
||||||
|
sidebar: {
|
||||||
|
registerPanel(id, { icon, title, component })
|
||||||
|
},
|
||||||
|
commands: {
|
||||||
|
register(id, label, handler, shortcut?)
|
||||||
|
},
|
||||||
|
statusBar: {
|
||||||
|
registerIndicator(id, { position, render })
|
||||||
|
},
|
||||||
|
settings: {
|
||||||
|
get(key), // plugin-scoped
|
||||||
|
set(key, value), // auto-persisted via electron-store
|
||||||
|
onChanged(key, callback)
|
||||||
|
},
|
||||||
|
editor: {
|
||||||
|
getContent(), // current document
|
||||||
|
getSelection(), // selected text
|
||||||
|
insertAtCursor(text), // requires opt-in
|
||||||
|
onContentChanged(callback)
|
||||||
|
},
|
||||||
|
events: {
|
||||||
|
on(event, handler),
|
||||||
|
emit(event, data)
|
||||||
|
},
|
||||||
|
exports: {
|
||||||
|
registerPreHook(handler),
|
||||||
|
registerPostHook(handler)
|
||||||
|
},
|
||||||
|
ipc: {
|
||||||
|
invoke(channel, ...args),
|
||||||
|
on(channel, handler)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Event Bus Events
|
||||||
|
|
||||||
|
Each event has a versioned payload schema. Breaking changes increment the version suffix.
|
||||||
|
|
||||||
|
```
|
||||||
|
document:opened → { filePath: string, tabId: string }
|
||||||
|
document:saved → { filePath: string, tabId: string }
|
||||||
|
document:changed → { tabId: string, content: string, wordCount: number }
|
||||||
|
editor:selection-changed → { tabId: string, text: string, from: {line,ch}, to: {line,ch} }
|
||||||
|
tab:switched → { tabId: string, filePath: string }
|
||||||
|
tab:closed → { tabId: string, filePath: string }
|
||||||
|
export:started → { format: string, filePath: string }
|
||||||
|
export:completed → { format: string, filePath: string, outputPath: string }
|
||||||
|
export:failed → { format: string, error: string }
|
||||||
|
plugin:loaded → { pluginId: string, version: string }
|
||||||
|
plugin:activated → { pluginId: string }
|
||||||
|
plugin:deactivated → { pluginId: string }
|
||||||
|
app:ready → {}
|
||||||
|
app:before-quit → {}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Design Rules
|
||||||
|
|
||||||
|
- Built-in plugins use the same API as future third-party plugins
|
||||||
|
- Lazy activation — sidebar panels don't load until clicked
|
||||||
|
- Scoped settings: `plugins.<id>.<key>` in electron-store
|
||||||
|
- Plugin commands globally unique — registry rejects duplicate command IDs at load time
|
||||||
|
- **Plugin sandboxing**: each plugin handler is wrapped in try/catch. For CPU-intensive operations (AI inference, diff computation), plugins must delegate to main process via IPC. Handlers that block the renderer for >5s trigger a warning notification. Memory-hungry operations (GGUF inference) run in isolated child processes.
|
||||||
|
- **Cross-plugin graceful degradation**: plugins check `context.events.hasHandler('ai:analyze')` before emitting cross-plugin requests. If no handler (AI plugin disabled), show a "this feature requires the AI plugin" prompt instead of failing silently. All cross-plugin calls have a 30s timeout with default fallback behavior.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 2. Writing Studio Plugin
|
||||||
|
|
||||||
|
### 2A. Manuscript / Project Manager
|
||||||
|
|
||||||
|
Folder-based project structure:
|
||||||
|
|
||||||
|
```
|
||||||
|
~/Manuscripts/
|
||||||
|
my-novel/
|
||||||
|
.project.json # { title, targets, metadata }
|
||||||
|
01-chapter-one.md
|
||||||
|
02-chapter-two.md
|
||||||
|
characters/
|
||||||
|
protagonist.md
|
||||||
|
research/
|
||||||
|
world-building.md
|
||||||
|
.snapshots/
|
||||||
|
2026-04-14T10-30.json
|
||||||
|
```
|
||||||
|
|
||||||
|
`.project.json`:
|
||||||
|
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"title": "My Novel",
|
||||||
|
"type": "manuscript",
|
||||||
|
"target": { "words": 80000, "deadline": "2026-09-01" },
|
||||||
|
"chapters": [
|
||||||
|
{ "file": "01-chapter-one.md", "title": "The Beginning", "status": "draft" }
|
||||||
|
],
|
||||||
|
"metadata": { "author": "", "genre": "", "synopsis": "" }
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Sidebar panel shows project tree with drag-to-reorder, word counts per chapter, target progress bar. "Compile manuscript" exports all chapters as a single document.
|
||||||
|
|
||||||
|
### 2B. Goal Tracking & Writing Sprints
|
||||||
|
|
||||||
|
- **Status bar**: daily progress bar + sprint timer
|
||||||
|
- **Writing sprint**: configurable duration (15/25/30/45/60 min), word count delta, WPM at end
|
||||||
|
- **Goal tracking**: daily/weekly word goals, streak tracking, 30-day bar chart
|
||||||
|
- **Enhanced analytics**: session tracking, readability scores, productive time-of-day heatmap
|
||||||
|
- Data stored in `plugins.writing-studio.history` as date-keyed map
|
||||||
|
|
||||||
|
### 2C. Snapshot & Versioning
|
||||||
|
|
||||||
|
- `Ctrl+Alt+N` or toolbar button saves snapshot
|
||||||
|
- Stored as JSON: `{ timestamp, content, wordCount, cursorPos, label }`
|
||||||
|
- Snapshot panel in sidebar: Restore, Diff (side-by-side), auto-snapshot interval
|
||||||
|
- Snapshots in `.snapshots/` inside project folder, or app data if no project
|
||||||
|
|
||||||
|
### 2D. Smart Proofreading
|
||||||
|
|
||||||
|
Delegates to AI plugin via event bus. Writing Studio provides:
|
||||||
|
- Right-click context menu: "Check grammar", "Suggest alternatives", "Analyze readability"
|
||||||
|
- Inline wavy underline decorations for issues
|
||||||
|
- Proofread panel: issues categorized by type with Accept/Dismiss
|
||||||
|
|
||||||
|
### Commands
|
||||||
|
|
||||||
|
| Command | Shortcut | Action |
|
||||||
|
|---------|----------|--------|
|
||||||
|
| `start-sprint` | `Ctrl+Alt+S` | Start writing sprint |
|
||||||
|
| `stop-sprint` | `Ctrl+Alt+Shift+S` | Stop sprint |
|
||||||
|
| `take-snapshot` | `Ctrl+Alt+N` | Save snapshot |
|
||||||
|
| `restore-last-snapshot` | `Ctrl+Alt+Z` | Restore latest snapshot |
|
||||||
|
| `new-project` | — | Create manuscript project |
|
||||||
|
| `compile-manuscript` | `Ctrl+Alt+E` | Export all chapters |
|
||||||
|
| `proofread-document` | `Ctrl+Alt+G` | AI proofread |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 3. AI Assistant Plugin
|
||||||
|
|
||||||
|
### Provider Architecture
|
||||||
|
|
||||||
|
```
|
||||||
|
AI Plugin
|
||||||
|
├── Provider Interface
|
||||||
|
│ ├── complete(prompt, options) → string
|
||||||
|
│ ├── stream(prompt, options) → AsyncIterable
|
||||||
|
│ └── analyze(text, type) → AnalysisResult
|
||||||
|
│
|
||||||
|
├── Providers
|
||||||
|
│ ├── OllamaProvider — localhost:11434
|
||||||
|
│ ├── LMStudioProvider — localhost:1234/v1
|
||||||
|
│ ├── GGUFProvider — direct llama.cpp with GPU support
|
||||||
|
│ ├── AnthropicProvider — Claude API
|
||||||
|
│ └── OpenAIProvider — GPT API
|
||||||
|
│
|
||||||
|
└── Features
|
||||||
|
├── Grammar/style check
|
||||||
|
├── Inline auto-complete
|
||||||
|
├── AI chat panel (sidebar)
|
||||||
|
├── Document analysis
|
||||||
|
└── Smart commands (command palette)
|
||||||
|
```
|
||||||
|
|
||||||
|
### Provider Details
|
||||||
|
|
||||||
|
**Ollama:** `GET /api/tags` for models, `POST /api/generate` and `POST /api/chat` for inference.
|
||||||
|
|
||||||
|
**LMStudio:** OpenAI-compatible API at `localhost:1234/v1`. `GET /v1/models`, standard chat completion format, SSE streaming.
|
||||||
|
|
||||||
|
**GGUF Direct (with GPU):**
|
||||||
|
- Ships bundled llama.cpp binaries per platform (CUDA, Vulkan, Metal, CPU variants)
|
||||||
|
- Auto-detects GPU: CUDA (nvidia-smi), Vulkan driver, Metal (macOS)
|
||||||
|
- GPU layer offloading: configurable, auto-suggests based on VRAM vs model size
|
||||||
|
- Settings: GPU backend selection, layer count, context length, thread count
|
||||||
|
- "Keep model loaded" option for faster repeated requests
|
||||||
|
- WASM fallback for sandboxed environments (CPU-only)
|
||||||
|
- External binary path for advanced users with custom builds
|
||||||
|
- **Process isolation**: llama.cpp runs as a spawned child process (not in main process). If it crashes, detected via exit handler, auto-restarted with notification. GPU memory freed on crash. App remains stable.
|
||||||
|
- Process management: spawn in server mode on localhost ephemeral port, clean up on app quit or model unload
|
||||||
|
|
||||||
|
**Cloud (Anthropic/OpenAI):**
|
||||||
|
- API key stored encrypted via electron safeStorage
|
||||||
|
- Token usage tracking with estimated cost
|
||||||
|
- Rate limit awareness with request queueing and backoff
|
||||||
|
|
||||||
|
### IPC Design
|
||||||
|
|
||||||
|
All provider HTTP requests go through main process:
|
||||||
|
- No CORS issues
|
||||||
|
- API keys never in renderer
|
||||||
|
- Main process enforces rate limiting
|
||||||
|
- GGUF inference in isolated child process
|
||||||
|
|
||||||
|
**Request/response lifecycle:**
|
||||||
|
```
|
||||||
|
Renderer → ipc.invoke('ai:complete') → Main → HTTP to provider → result → Renderer
|
||||||
|
```
|
||||||
|
|
||||||
|
**Streaming lifecycle with error handling:**
|
||||||
|
```
|
||||||
|
Renderer → ipc.invoke('ai:stream', { requestId, prompt })
|
||||||
|
← Main assigns requestId, returns { requestId }
|
||||||
|
← ipc.on('ai:chunk', { requestId, text }) — repeated
|
||||||
|
← ipc.on('ai:done', { requestId }) — success
|
||||||
|
← ipc.on('ai:error', { requestId, error }) — failure
|
||||||
|
|
||||||
|
// Cancellation
|
||||||
|
Renderer → ipc.invoke('ai:cancel', { requestId })
|
||||||
|
← Main aborts HTTP request, emits 'ai:done'
|
||||||
|
|
||||||
|
// Orphan cleanup: if renderer disconnects (crash/close),
|
||||||
|
// main process detects via 'render-view-deleted' and aborts all active streams.
|
||||||
|
// Heartbeat: if no chunk received in 30s, main emits 'ai:error' with timeout.
|
||||||
|
```
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
1. **Inline suggestions**: ghost text after configurable delay, Tab to accept, Esc to dismiss
|
||||||
|
2. **AI chat panel**: sidebar conversation, "Insert" / "Replace selection" buttons
|
||||||
|
3. **Document analysis**: grammar, style, tone, with accept/reject per suggestion
|
||||||
|
4. **Smart commands**: summarize, generate outline, find inconsistencies, translate, explain code
|
||||||
|
|
||||||
|
### Privacy
|
||||||
|
|
||||||
|
- Local-first: default provider is Ollama
|
||||||
|
- No telemetry: requests go direct to provider
|
||||||
|
- Content gating: exclude file types from AI
|
||||||
|
- Status bar shows "AI: processing..." with cancel option
|
||||||
|
- Cloud usage stats in settings (tokens, cost)
|
||||||
|
|
||||||
|
### Cross-Plugin Integration
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
// Writing Studio calls AI Plugin
|
||||||
|
context.events.emit('ai:analyze', { text, type: 'grammar', callback });
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 4. Collaboration Plugin
|
||||||
|
|
||||||
|
### 4A. Enhanced Git Panel
|
||||||
|
|
||||||
|
Upgrades to existing git panel:
|
||||||
|
- Remote management (add/remove remotes, push/pull)
|
||||||
|
- Branch list and switching
|
||||||
|
- Commit history with diff viewer (side-by-side or unified)
|
||||||
|
- Conflict resolution UI (accept-ours/accept-theirs/per-edit)
|
||||||
|
|
||||||
|
### 4B. Shared Repository Workflow
|
||||||
|
|
||||||
|
1. Writer A creates project + initializes git + pushes to shared repo
|
||||||
|
2. Writer B clones repo from within MarkdownConverter
|
||||||
|
3. Both write on their own branches
|
||||||
|
4. Writer A creates review request (simplified PR)
|
||||||
|
|
||||||
|
Review request: changed files, word count diff, commit messages. Reviewer can approve, request changes, leave inline comments. Reviews are git branches + comments as git notes.
|
||||||
|
|
||||||
|
### 4C. Comments & Annotations
|
||||||
|
|
||||||
|
Inline comments stored as JSON in `.comments/` directory (git-tracked):
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"id": "uuid",
|
||||||
|
"file": "03-chapter-three.md",
|
||||||
|
"anchor": {
|
||||||
|
"contextBefore": "The hero looked at the horizon and said,",
|
||||||
|
"selectedText": "I will not go quietly into that dark night",
|
||||||
|
"contextAfter": "He turned to face the army alone."
|
||||||
|
},
|
||||||
|
"line": 142,
|
||||||
|
"text": "This dialogue feels unnatural",
|
||||||
|
"author": "amit",
|
||||||
|
"timestamp": "2026-04-14T14:30:00Z",
|
||||||
|
"replies": [],
|
||||||
|
"resolved": false
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
- **Anchor-based positioning**: comments store `contextBefore`, `selectedText`, and `contextAfter` (not absolute byte offsets). On file change, re-anchor by searching for the context text. If context no longer matches, mark comment as "detached" and show a warning. Falls back to `line` number as rough position.
|
||||||
|
- Highlighted text in editor with tooltip on hover
|
||||||
|
- Comment panel in sidebar: all unresolved comments across files
|
||||||
|
- Resolution workflow: add → address → reply → resolve
|
||||||
|
- Resolved comments dim but stay visible
|
||||||
|
|
||||||
|
### 4D. Change Notifications
|
||||||
|
|
||||||
|
- Status bar indicator: `↓ 3 new commits`
|
||||||
|
- Click to see changes, one-click pull
|
||||||
|
- Conflicts trigger resolution UI
|
||||||
|
- Push button only when local commits ahead of remote
|
||||||
|
|
||||||
|
### 4E. Offline-First
|
||||||
|
|
||||||
|
All writing happens locally. Git is the sync mechanism. No internet required for writing, commenting, snapshots, or sprints. Push/pull on user action or auto-sync setting.
|
||||||
|
|
||||||
|
### Commands
|
||||||
|
|
||||||
|
| Command | Shortcut | Action |
|
||||||
|
|---------|----------|--------|
|
||||||
|
| `collab:commit` | `Ctrl+Shift+G` | Commit with message |
|
||||||
|
| `collab:push` | — | Push current branch |
|
||||||
|
| `collab:pull` | — | Pull from remote |
|
||||||
|
| `collab:add-comment` | `Ctrl+Alt+C` | Comment on selection |
|
||||||
|
| `collab:next-comment` | `F8` | Next unresolved comment |
|
||||||
|
| `collab:prev-comment` | `Shift+F8` | Previous comment |
|
||||||
|
| `collab:create-review` | — | Create review request |
|
||||||
|
|
||||||
|
### Cross-Plugin Integration
|
||||||
|
|
||||||
|
```javascript
|
||||||
|
context.events.emit('snapshot:created', { file, snapshotId });
|
||||||
|
context.events.on('project:chapter-opened', (chapter) => { /* load comments */ });
|
||||||
|
context.events.on('comment:added', (comment) => { /* AI could suggest fix */ });
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Bundle Size Impact
|
||||||
|
|
||||||
|
- llama.cpp binaries: ~15MB per GPU variant. Only target platform shipped. GPU variants (CUDA/Vulkan/Metal) downloaded on demand if user enables GGUF direct loading — not bundled by default. Only CPU fallback bundled (~15MB).
|
||||||
|
- Plugin system core: ~30KB
|
||||||
|
- Each built-in plugin: ~50-100KB
|
||||||
|
- Diff library (jsdiff): ~15KB
|
||||||
|
- Total estimated increase: ~20-30MB (core), additional ~30-50MB per GPU variant (lazy download)
|
||||||
|
|
||||||
|
## Testing Strategy
|
||||||
|
|
||||||
|
- Plugin system: unit tests for registry, loader, context API mocking
|
||||||
|
- Each plugin: isolated unit tests, integration tests via plugin context
|
||||||
|
- AI provider tests: mock HTTP responses, test streaming parsing
|
||||||
|
- Git tests: use test repository fixture
|
||||||
|
- E2E: verify plugin loading doesn't break existing features
|
||||||
@@ -0,0 +1,216 @@
|
|||||||
|
# MarkdownConverter — Monospace Font Embedding Design
|
||||||
|
|
||||||
|
**Date:** 2026-06-30
|
||||||
|
**Status:** Approved
|
||||||
|
**Author:** Amit Haridas
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
Guarantee proper ASCII character alignment in MarkdownConverter's preview and every supported export format (PDF, DOCX, HTML, plus ODT/RTF/EPUB/LaTeX), with no OS-level font dependency. The user can pick between **JetBrains Mono** (default) and **Fira Code**, and toggle ligatures (default off). Both font families are bundled inside the app, so alignment holds on every supported platform (Windows/macOS/Linux) without an internet connection, without system-wide font installation, and without the user touching anything system-level.
|
||||||
|
|
||||||
|
## Goals
|
||||||
|
|
||||||
|
1. ASCII art and code-block tables (e.g. `+----+----+` column delimiters) render at identical advance widths in the live preview **and** in every exported file.
|
||||||
|
2. No OS font dependency — TTFs ship inside the app.
|
||||||
|
3. Per-user choice of monospace family + ligature behaviour.
|
||||||
|
4. Self-contained exports: the exported PDF/DOCX/HTML file is portable to another machine and stays aligned.
|
||||||
|
|
||||||
|
## Non-Goals (v1)
|
||||||
|
|
||||||
|
- No font subsetting of TTFs (we ship the full file; xelatex subsets it into the PDF automatically; DOCX carriers get the full TTF in `word/fonts/`).
|
||||||
|
- No support for the user adding a third bundled font family.
|
||||||
|
- No PPTX or revealjs/Beamer ligature-toggle (PPTX is a slide format that rarely carries ASCII tables; revealjs/Beamer inherit HTML/LaTeX defaults).
|
||||||
|
- No licensed/commercial fonts (Fira Code and JetBrains Mono are both SIL OFL — confirmed in `assets/fonts/JetBrainsMono-LICENSE.txt`).
|
||||||
|
|
||||||
|
## Decisions Locked
|
||||||
|
|
||||||
|
| Decision | Choice | Reason |
|
||||||
|
|---|---|---|
|
||||||
|
| Scope | All export formats | All-surfaces alignment |
|
||||||
|
| DOCX strategy | Embed TTF into the DOCX zip | Truly portable; alignment holds even when the recipient lacks the font |
|
||||||
|
| PDF strategy | Pass TTF path to xelatex via `fontspec` (`\setmonofont[Path=...]`) | xelatex subsets the font into the PDF; reproducible across machines |
|
||||||
|
| Font choice | Both bundled; user-pickable in settings | Cover both preferences; default JetBrains Mono |
|
||||||
|
| Ligatures | Off by default; user toggle | Ligatures change advance widths and break ASCII grid alignment |
|
||||||
|
| License | SIL OFL (both families) | Embedding/bundling explicitly permitted when license travels with the binary (already present at `assets/fonts/JetBrainsMono-LICENSE.txt`) |
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|
```
|
||||||
|
settings.json
|
||||||
|
│
|
||||||
|
│ (renderer + main read on init)
|
||||||
|
▼
|
||||||
|
CSS body classes: .mono-jetbrains / .mono-fira
|
||||||
|
.mono-ligatures-on / .mono-ligatures-off
|
||||||
|
--font-mono-active token
|
||||||
|
▲ ▲
|
||||||
|
│ IPC │ IPC
|
||||||
|
│ │
|
||||||
|
Preview pane ┌───────────┴──────────┐
|
||||||
|
ASCII Generator window │ Export pipeline │
|
||||||
|
Print-preview iframe │ (main process) │
|
||||||
|
│ uses MonospaceFontConfig
|
||||||
|
└──────────────────────┘
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
Bundle: assets/fonts/
|
||||||
|
├─ JetBrainsMono-Regular.ttf
|
||||||
|
├─ JetBrainsMono-Bold.ttf
|
||||||
|
├─ FiraCode-Regular.ttf
|
||||||
|
├─ FiraCode-Bold.ttf
|
||||||
|
└─ (existing woff2 for renderer)
|
||||||
|
```
|
||||||
|
|
||||||
|
## New Modules
|
||||||
|
|
||||||
|
| File | Role |
|
||||||
|
|---|---|
|
||||||
|
| `src/main/MonospaceFontConfig.js` | Single source of truth. Resolves the active monospace family + weight → absolute TTF path, with awareness of dev vs packaged (asar.unpacked) layout. Returns `null` + warns when a file is missing. |
|
||||||
|
| `src/main/PdfFontHeader.js` | Builds the xelatex `header.tex` snippet with `\usepackage{fontspec}\setmonofont{...ttf}[Path=...,UprightFont=*-Regular,BoldFont=*-Bold,Ligatures=NoCommon/TeX]`. Also returns the lualatex equivalent. |
|
||||||
|
| `src/main/DocxFontEmbedder.js` | Unzips a pandoc-produced DOCX with `jszip`, writes TTFs into `word/fonts/`, patches `[Content_Types].xml`, `_rels/document.xml.rels`, creates `word/fontTable.xml` with `<w:embedRegular/>` referencing the TTF, patches `word/styles.xml` so the `SourceCode`/`VerbatimChar` styles bind to the embedded font name, then rezips. Idempotent. |
|
||||||
|
| `src/main/EpubFontEmbedder.js` | Wrapper around pandoc `--epub-embed-font` — verifies the chosen TTF is referenced in `OEBPS/content.opf`; patches the manifest if missing. |
|
||||||
|
| `src/main/ExportCss.js` | Returns a self-contained CSS string with `@font-face { src: url(data:font/woff2;base64,...) }` for the chosen family. Used by HTML export `--css` and by print-preview iframe. |
|
||||||
|
| `src/main/settings/SettingsUI.Monospace.js` | Two new controls in the in-app settings dialog: monospace font select + ligatures checkbox. Persists to `<userData>/settings.json`. |
|
||||||
|
|
||||||
|
## Modified Modules
|
||||||
|
|
||||||
|
| File | Change |
|
||||||
|
|---|---|
|
||||||
|
| `src/fonts.css` | Add `@font-face` entries for Fira Code Regular (400) and Bold (700), pointing to `assets/fonts/FiraCode-*.woff2` (downloaded via the extended `download-tools.js`). |
|
||||||
|
| `src/styles/tokens.css` + `src/styles-concreteinfo.css` | Define new tokens `--font-mono-active` (resolves to `"JetBrains Mono"` or `"Fira Code"`) and `--font-mono-feature` (`"liga" 0, "calt" 0, "dlig" 0` for ligatures-off, else `normal`). Body classes flip these. |
|
||||||
|
| `src/styles-modern.css` | `.editor-textarea`, `.preview-content code`, `.preview-content pre`, `.codemirror-container .cm-editor` reference `var(--font-mono-active)` and apply `font-feature-settings: var(--font-mono-feature)`. |
|
||||||
|
| `src/ascii-generator.html` | Replace `<link href="https://fonts.googleapis.com/...">` with `<link rel="stylesheet" href="../styles/fonts.css">` plus inline `body` class defaulting. The window is plain HTML; the renderer script that opens it sets `body.classList` from settings. |
|
||||||
|
| `src/print-preview.js` | Inject `<style>` with embedded woff2 base64 from `ExportCss.js` into the srcdoc iframe HTML; set `pre`/`code` font-family to `var(--font-mono-active)`. |
|
||||||
|
| `src/main.js` | Five `--css/-V monofont=Consolas` lines and the export pipelines need surgery (table below). On successful DOCX export, pipeline the output through `DocxFontEmbedder`. On HTML export, pass `--css` referencing a temp file emitted by `ExportCss.js`. On EPUB, pass `--epub-embed-font` for both Regular and Bold. On LaTeX/PDF, pass `--include-in-header` referencing a temp `header.tex` emitted by `PdfFontHeader.js`. The Electron `printToPDF` fallback also consumes `ExportCss.js`. |
|
||||||
|
| `src/renderer.js` | On `settings-changed`, toggle `document.body.classList` between `mono-jetbrains` / `mono-fira` and `mono-ligatures-on` / `mono-ligatures-off`. The active class is also written by the bit that initializes Monaco/CodeMirror when the editor is mounted. |
|
||||||
|
| `scripts/download-tools.js` | Add `fira-code` task: downloads `FiraCode-Regular.ttf`, `FiraCode-Bold.ttf`, `FiraCode-LICENSE.txt` from the official `tonsky/FiraCode` GitHub release (version-pinned, mirrors how Pandoc is downloaded). |
|
||||||
|
| `package.json` | `build.asarUnpack` extended to `"assets/fonts/**"` so xelatex/Pandoc can read TTFs at runtime in packaged builds. No new NPM dependencies — `jszip ^3.10.1` is already present. |
|
||||||
|
|
||||||
|
## Per-Export Behaviour
|
||||||
|
|
||||||
|
| Format | What changes | Post-processing | Resulting file shape |
|
||||||
|
|---|---|---|---|
|
||||||
|
| **PDF** (xelatex) | Replace `-V monofont="Consolas"` with `--include-in-header=<tmp>.tex` from `PdfFontHeader` (`\setmonofont{JetBrainsMono-Regular.ttf}[Path=…,Extension=.ttf,UprightFont=*-Regular,BoldFont=*-Bold,Ligatures=NoCommon]`). | none — xelatex subsets the font into the PDF. | Self-contained PDF; code-block columns align across pages. |
|
||||||
|
| **PDF** (lualatex fallback) | Same header uses lualatex-compatible fontspec syntax (identical to xelatex in modern LuaTeX). | none | Same as above. |
|
||||||
|
| **PDF** (pdflatex final fallback) | Revert to `-V monofont="Consolas"` + warn (Consolas not on all systems; document limitation). | none | Best-effort — relies on pdftex default monospace. |
|
||||||
|
| **DOCX** | Existing pandoc invocation. After pandoc writes, hand to `DocxFontEmbedder`. | Embed Regular + Bold TTF into `word/fonts/`; patch `[Content_Types].xml` Default+Override; add `word/_rels` entry for `fontTable.xml.rels`; create `word/fontTable.xml` with `<w:embedRegular/>` for each font weight; patch `word/styles.xml` so `SourceCode` (or whatever style Pandoc wrote under) sets `w:rFonts ascii="JetBrains Mono" hAnsi="JetBrains Mono"`. | ~550 KB larger DOCX; fully portable. |
|
||||||
|
| **HTML** (standalone) | Add `--css=<tmp>.css` (built by `ExportCss` with base64 woff2). | none | One self-contained `.html`; aligned anywhere, offline. |
|
||||||
|
| **EPUB** | Add `--epub-embed-font=<bundleAbs>/<Family>-Regular.ttf` and same for Bold (Pandoc 2.11+ supports this natively). | `EpubFontEmbedder` patches `OEBPS/content.opf` if the font reference is missing. | Embedded font travels in the EPUB. |
|
||||||
|
| **ODT** | `--variable=mainfont="JetBrains Mono"` (or Fira). | Before final write, show a non-blocking confirmation: "ODT embeds the font *name* — recipients must also have it installed to keep alignment. Continue?". | Light; portability caveat explicit to user. |
|
||||||
|
| **RTF** | `\fonttbl` directive already injected by pandoc when `mainfont=` is set. | Same ODT confirmation. | Same caveat as ODT. |
|
||||||
|
| **LaTeX (`.tex`)** | `--include-in-header=<tmp>.tex` identical to the PDF header. | none | Self-contained `.tex` for downstream compile. |
|
||||||
|
| **PPTX** | unchanged | n/a | v1: don't try to enforce. |
|
||||||
|
| **RevealJS** | behaves like HTML (uses `ExportCss`). | n/a | self-contained. |
|
||||||
|
| **Beamer** | behaves like LaTeX (uses `PdfFontHeader` snippet). | n/a | downstream PDF compile respects font. |
|
||||||
|
| **Print preview** | n/a | `ExportCss` injected into srcdoc iframe HTML. | Inside-app preview aligned. |
|
||||||
|
| **ASCII Generator window** | Replace Google Fonts CDN link with local `fonts.css`. | n/a | Offline, aligned. |
|
||||||
|
|
||||||
|
## Path Resolution
|
||||||
|
|
||||||
|
`MonospaceFontConfig` exposes:
|
||||||
|
|
||||||
|
```js
|
||||||
|
exports.getActiveMonoFontPath = function getActiveMonoFontPath(weight = 400)
|
||||||
|
exports.getActiveMonoFamily = function getActiveMonoFamily()
|
||||||
|
exports.ligaturesEnabled = function ligaturesEnabled()
|
||||||
|
```
|
||||||
|
|
||||||
|
- Dev: `<repoRoot>/assets/fonts/<Family>-<Weight>.ttf`
|
||||||
|
- Packaged: `<process.resourcesPath>/app.asar.unpacked/assets/fonts/<Family>-<Weight>.ttf`
|
||||||
|
- If the file is missing, returns `null` and emits a `console.warn` + a single non-blocking toast: "Using system monospace — bundled font missing".
|
||||||
|
|
||||||
|
## Settings Schema
|
||||||
|
|
||||||
|
Extended `<userData>/settings.json`:
|
||||||
|
|
||||||
|
```jsonc
|
||||||
|
{
|
||||||
|
// ... existing keys ...
|
||||||
|
"monospaceFont": "jetbrains-mono", // "jetbrains-mono" | "fira-code"
|
||||||
|
"monospaceLigatures": false // bool
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Defaults: `monospaceFont: "jetbrains-mono"`, `monospaceLigatures: false`. Migration: if a settings file exists without these keys, fill with defaults silently on read.
|
||||||
|
|
||||||
|
## Testing
|
||||||
|
|
||||||
|
**New test files:**
|
||||||
|
|
||||||
|
| File | Asserts |
|
||||||
|
|---|---|
|
||||||
|
| `tests/monospace-font-config.test.js` | Dev vs packaged path semantics; null-and-warn on missing TTF; settings-driven family selection. |
|
||||||
|
| `tests/docx-font-embedder.test.js` | Produces a valid DOCX; `unzip -l` lists `word/fonts/JetBrainsMono-{Regular,Bold}.ttf`; `word/fontTable.xml` contains `<w:embedRegular r:id="…"/>` entries with correct names; `styles.xml` binds the monospace style to `"JetBrains Mono"`; idempotent (running twice doesn't double-embed). |
|
||||||
|
| `tests/pdf-font-header.test.js` | Output contains `\setmonofont{JetBrainsMono-Regular.ttf}` with `Path=` matching the resolved absolute path; `Ligatures=NoCommon` when settings say off. |
|
||||||
|
| `tests/export-css.test.js` | Output contains a `@font-face` block with `src: url('data:font/woff2;base64,<…>')`; the base64 string decodes to > 50 000 bytes; `pre`/`code`/`kbd` use `var(--font-mono-active)`. |
|
||||||
|
| `tests/epub-font-embedder.test.js` | After embedding, `OEBPS/content.opf` references both Regular and Bold TTFs in `<manifest>`. |
|
||||||
|
|
||||||
|
**Integration test (manual, repeatable):**
|
||||||
|
|
||||||
|
1. Create a fixture markdown file with three ASCII grids (boxes, columns, arrows).
|
||||||
|
2. Open the file in MarkdownConverter.
|
||||||
|
3. Set monospace font = JetBrains Mono, ligatures off.
|
||||||
|
4. Export to PDF / DOCX / HTML.
|
||||||
|
5. Open each result; confirm the `+---+` column delimiters sit at identical X-positions across all three formats and across pages.
|
||||||
|
6. Switch to Fira Code with ligatures on; export again; confirm round-trip works (no crashes) and ligature toggle affects preview.
|
||||||
|
|
||||||
|
## Error Handling
|
||||||
|
|
||||||
|
| Failure | Behaviour |
|
||||||
|
|---|---|
|
||||||
|
| Bundled TTF missing | `MonospaceFontConfig` returns `null`; renderer/main falls back to system monospace; non-blocking toast; never a silent drop. |
|
||||||
|
| `DocxFontEmbedder` fails (zip corruption, insufficient permissions, missing required OOXML element) | Keep the un-embedded DOCX; show a dialog with the exact failure message and a "Report issue" link. Do **not** claim success. |
|
||||||
|
| `PdfFontHeader` can't write temp tex (filesystem permission) | Show an error dialog naming the permission issue; abort the export. |
|
||||||
|
| Pandoc `--epub-embed-font` not supported (Pandoc < 2.11) | Detect via `pandoc --version` at startup (cache `pandocAvailable` already exists). Skip embedding; warn user that the EPUB will degrade if their reader lacks the font. |
|
||||||
|
| Pandoc `--css` flag missing (Pandoc < 2.0) | Detect via the same version check. Skip the `--css` injection; warn user that the exported HTML is not self-contained for the chosen font. |
|
||||||
|
| xelatex fails after fontspec injection | Existing `tryPdfFallback` chain reorders to `lualatex → pdflatex` (Consolas). Already implemented; the reorder is a one-liner. |
|
||||||
|
|
||||||
|
## Acceptance Criteria
|
||||||
|
|
||||||
|
- [ ] All five rows of `Per-Export Behaviour` produce files where ASCII alignment is identical to the editor.
|
||||||
|
- [ ] No new NPM dependencies added (use existing `jszip`, `fontkit`).
|
||||||
|
- [ ] `asarUnpack` covers `assets/fonts/**`.
|
||||||
|
- [ ] Bundle size increase ≤ 1.5 MB (TTFs + Fira TTF + extra metadata).
|
||||||
|
- [ ] No `TODO`/`FIXME`/`HACK` markers in newly touched code.
|
||||||
|
- [ ] Preview, ASCII Generator window, print-preview iframe, PDF, DOCX, HTML, EPUB, ODT all use the same active font + ligature setting (single source of truth).
|
||||||
|
- [ ] On a clean machine with no JetBrains Mono / Fira Code installed system-wide, every export still produces correct alignment.
|
||||||
|
- [ ] Switching between fonts in settings updates preview immediately and is honoured by all subsequent exports in the same session.
|
||||||
|
- [ ] Both font files travel with the binary (`LICENSE.txt` present for both families).
|
||||||
|
|
||||||
|
## File Inventory
|
||||||
|
|
||||||
|
**New (10 files):**
|
||||||
|
|
||||||
|
```
|
||||||
|
src/main/MonospaceFontConfig.js
|
||||||
|
src/main/PdfFontHeader.js
|
||||||
|
src/main/DocxFontEmbedder.js
|
||||||
|
src/main/EpubFontEmbedder.js
|
||||||
|
src/main/ExportCss.js
|
||||||
|
src/main/settings/SettingsUI.Monospace.js
|
||||||
|
tests/monospace-font-config.test.js
|
||||||
|
tests/docx-font-embedder.test.js
|
||||||
|
tests/pdf-font-header.test.js
|
||||||
|
tests/export-css.test.js
|
||||||
|
tests/epub-font-embedder.test.js
|
||||||
|
assets/fonts/FiraCode-Regular.ttf
|
||||||
|
assets/fonts/FiraCode-Bold.ttf
|
||||||
|
assets/fonts/FiraCode-LICENSE.txt
|
||||||
|
```
|
||||||
|
|
||||||
|
**Modified:**
|
||||||
|
|
||||||
|
```
|
||||||
|
src/fonts.css
|
||||||
|
src/styles/tokens.css
|
||||||
|
src/styles-concreteinfo.css
|
||||||
|
src/styles-modern.css
|
||||||
|
src/ascii-generator.html
|
||||||
|
src/print-preview.js
|
||||||
|
src/main.js
|
||||||
|
src/renderer.js
|
||||||
|
scripts/download-tools.js
|
||||||
|
package.json
|
||||||
|
```
|
||||||
|
|
||||||
|
(3 added TTF files counted under "New"; OFL `LICENSE.txt` only required when bundling Fira Code.)
|
||||||
@@ -38,10 +38,30 @@ module.exports = [
|
|||||||
document: 'readonly',
|
document: 'readonly',
|
||||||
localStorage: 'readonly',
|
localStorage: 'readonly',
|
||||||
alert: 'readonly',
|
alert: 'readonly',
|
||||||
|
prompt: 'readonly',
|
||||||
|
confirm: 'readonly',
|
||||||
Event: 'readonly',
|
Event: 'readonly',
|
||||||
CustomEvent: 'readonly',
|
CustomEvent: 'readonly',
|
||||||
HTMLElement: 'readonly',
|
HTMLElement: 'readonly',
|
||||||
MutationObserver: 'readonly',
|
MutationObserver: 'readonly',
|
||||||
|
TextEncoder: 'readonly',
|
||||||
|
FileReader: 'readonly',
|
||||||
|
requestAnimationFrame: 'readonly',
|
||||||
|
cancelAnimationFrame: 'readonly',
|
||||||
|
navigator: 'readonly',
|
||||||
|
location: 'readonly',
|
||||||
|
fetch: 'readonly',
|
||||||
|
URL: 'readonly',
|
||||||
|
Blob: 'readonly',
|
||||||
|
Image: 'readonly',
|
||||||
|
DragEvent: 'readonly',
|
||||||
|
ClipboardEvent: 'readonly',
|
||||||
|
KeyboardEvent: 'readonly',
|
||||||
|
MouseEvent: 'readonly',
|
||||||
|
NodeList: 'readonly',
|
||||||
|
HTMLInputElement: 'readonly',
|
||||||
|
HTMLTextAreaElement: 'readonly',
|
||||||
|
getComputedStyle: 'readonly',
|
||||||
// Electron
|
// Electron
|
||||||
electronAPI: 'readonly',
|
electronAPI: 'readonly',
|
||||||
// Libraries
|
// Libraries
|
||||||
@@ -49,10 +69,13 @@ module.exports = [
|
|||||||
DOMPurify: 'readonly',
|
DOMPurify: 'readonly',
|
||||||
hljs: 'readonly',
|
hljs: 'readonly',
|
||||||
mermaid: 'readonly',
|
mermaid: 'readonly',
|
||||||
|
// Node.js global object
|
||||||
|
global: 'writable',
|
||||||
// Jest
|
// Jest
|
||||||
jest: 'readonly',
|
jest: 'readonly',
|
||||||
describe: 'readonly',
|
describe: 'readonly',
|
||||||
test: 'readonly',
|
test: 'readonly',
|
||||||
|
it: 'readonly',
|
||||||
expect: 'readonly',
|
expect: 'readonly',
|
||||||
beforeEach: 'readonly',
|
beforeEach: 'readonly',
|
||||||
afterEach: 'readonly',
|
afterEach: 'readonly',
|
||||||
|
|||||||
+15
-15
@@ -11,26 +11,25 @@ module.exports = {
|
|||||||
rootDir: '.',
|
rootDir: '.',
|
||||||
|
|
||||||
// Test file patterns
|
// Test file patterns
|
||||||
testMatch: [
|
testMatch: ['**/tests/**/*.test.js', '**/tests/**/*.spec.js'],
|
||||||
'**/tests/**/*.test.js',
|
|
||||||
'**/tests/**/*.spec.js'
|
|
||||||
],
|
|
||||||
|
|
||||||
// Coverage configuration
|
// Coverage configuration
|
||||||
collectCoverageFrom: [
|
collectCoverageFrom: [
|
||||||
'src/**/*.js',
|
'src/**/*.js',
|
||||||
'!src/main.js', // Main process needs electron-mock
|
'!src/main.js', // Main process needs electron-mock
|
||||||
'!**/node_modules/**'
|
'!src/renderer.js', // Large renderer file with duplicate declarations
|
||||||
|
'!src/preload.js', // Electron preload requires contextBridge
|
||||||
|
'!**/node_modules/**',
|
||||||
],
|
],
|
||||||
|
|
||||||
// Coverage thresholds (start low, increase over time)
|
// Coverage thresholds (raised with expanded test suite)
|
||||||
coverageThreshold: {
|
coverageThreshold: {
|
||||||
global: {
|
global: {
|
||||||
branches: 10,
|
branches: 10,
|
||||||
functions: 10,
|
functions: 15,
|
||||||
lines: 10,
|
lines: 15,
|
||||||
statements: 10
|
statements: 15,
|
||||||
}
|
},
|
||||||
},
|
},
|
||||||
|
|
||||||
// Transform settings (no transpilation needed for vanilla JS)
|
// Transform settings (no transpilation needed for vanilla JS)
|
||||||
@@ -43,10 +42,11 @@ module.exports = {
|
|||||||
setupFilesAfterEnv: ['<rootDir>/tests/setup.js'],
|
setupFilesAfterEnv: ['<rootDir>/tests/setup.js'],
|
||||||
|
|
||||||
// Ignore patterns
|
// Ignore patterns
|
||||||
testPathIgnorePatterns: [
|
testPathIgnorePatterns: ['/node_modules/', '/dist/'],
|
||||||
'/node_modules/',
|
|
||||||
'/dist/'
|
// Keep the haste map / snapshot scanner out of build output — electron-builder's
|
||||||
],
|
// .snap (Squashfs) artifacts otherwise register as obsolete Jest snapshots.
|
||||||
|
modulePathIgnorePatterns: ['/dist/'],
|
||||||
|
|
||||||
// Verbose output
|
// Verbose output
|
||||||
verbose: true,
|
verbose: true,
|
||||||
@@ -55,5 +55,5 @@ module.exports = {
|
|||||||
clearMocks: true,
|
clearMocks: true,
|
||||||
|
|
||||||
// Reset modules between tests
|
// Reset modules between tests
|
||||||
resetModules: true
|
resetModules: true,
|
||||||
};
|
};
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 8.6 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 17 KiB |
Generated
+12455
File diff suppressed because it is too large
Load Diff
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user