Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a7d398ad6a | ||
|
|
a55a7a9170 | ||
|
|
8ddfe1b3e1 | ||
|
|
cc724f894b |
@@ -30,7 +30,7 @@ jobs:
|
|||||||
|
|
||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: 20
|
node-version-file: .nvmrc
|
||||||
cache: npm
|
cache: npm
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
|
|||||||
@@ -1,3 +1,36 @@
|
|||||||
|
# After action report
|
||||||
|
|
||||||
|
## Done — 10 PRs implemented, merged, and CI-green on both forges
|
||||||
|
I worked through ai_prompts/prompt4.md and shipped PRs 1–10 of the plan's recommended sequence. Each was a focused branch, opened on both GitHub (Twest2/StepForge #5–#14) and Gitea (Tyler/autodoc #21–#30), verified green on GitHub CI (Ubuntu + Windows + dependency audit), merged with the same SHA to both forges, and the Gitea mirror closed with a merge note. Final state: main is byte-identical across local, GitHub, and Gitea (cc724f8), main CI is green, no open PRs, 289 unit tests pass (0 fail).
|
||||||
|
|
||||||
|
## PR What it fixed
|
||||||
|
1 Pinned Node ≥22.12 (.nvmrc/engines); removed all runtime npm self-repair; refuse silent --no-sandbox; CI on pull_request + prod/full audits; made the click E2E stop hiding startup crashes as "SKIPPED"; remediated the form-data/undici advisories
|
||||||
|
2 Closed the renderer privilege boundary: navigation/popup denial, sandboxed windows, per-channel IPC sender+argument validation, deny-by-default permissions (display capture only for the capture worker), intent-specific shell access replacing arbitrary shell:openPath
|
||||||
|
3 Truthful local-first AI/privacy contract: raw keystroke capture off by default, AbortController timeouts + cancellation + concurrency + image-size limits, loopback-only Ollama unless explicitly opted in, honest docs + new docs/PRIVACY.md
|
||||||
|
4 Optimistic revision fields + compare-and-swap (stale AI responses can't clobber edits), autosave keeps dirty state on failed saves, corrupt guides/steps quarantined instead of silently vanishing
|
||||||
|
5 Region-capture nested-result + listener-leak bugs, single-owner power blocker, explicit click-source reporting (evdev fix), strict-mode skips instead of storing post-click shots, pathToFileURL, shutdown drain
|
||||||
|
6 ZIP-bomb limits, transactional archive import, atomic snapshot restore, exclusive locks (O_EXCL + token), search index reconcile at startup, implemented the dead automatic-backup settings
|
||||||
|
7 Platform adapter layer — window-context detection extracted to app/platform/{windows,linux,darwin}/; shared code no longer branches on process.platform; Linux capability diagnostics
|
||||||
|
8 Production .deb (runtime-only staging, no dev tree, detected arch, desktop/MIME/icons, original generated icon set), apt setup scripts, real launcher; retired the old broken packager
|
||||||
|
9 Production .rpm + dnf setup, shared stage-runtime.sh so both formats never drift
|
||||||
|
10 Honest Wayland triggers (never promises per-click coordinates it can't deliver) + a least-privilege mouse-only udev rule replacing the broad input group keylogging surface; .gitattributes so Unix scripts don't break on CRLF
|
||||||
|
I verified real behavior where possible: built and inspected an actual 107 MB .deb, ran the click self-test (markers 3/3, burst 8/8), and confirmed the sandboxed app boots.
|
||||||
|
|
||||||
|
## One blocking item I did not act on — the license (needs your decision)
|
||||||
|
The plan calls this a legal release blocker that an implementation agent must not guess, and I agree. The repo currently contradicts itself:
|
||||||
|
|
||||||
|
package.json → MPL-2.0 and CONTRIBUTING requires MPL-2.0 + DCO sign-off (permits commercial use)
|
||||||
|
docs/LICENSE + README §License → Creative Commons Attribution-NonCommercial (forbids commercial use; also not a software license)
|
||||||
|
there is no root LICENSE file
|
||||||
|
MPL-2.0 and CC-BY-NC are mutually exclusive, and contributors have been signing off under a license the project doesn't actually ship. You need to pick one, then I can reconcile the SPDX field, root LICENSE, README, CONTRIBUTING, package payloads, and the About view in a single follow-up PR.
|
||||||
|
|
||||||
|
## What remains (plan PRs 11–14 — larger, several need your input)
|
||||||
|
Canonical blocks/callout-placement schema-v2 migration; lazy exports + Unicode font vendoring (needs a licensed-font choice); editor modularization + accessibility; and the signed reproducible release pipeline (needs signing keys). Also still open: the click self-test's arm/debounce scenarios fail on Linux — a pre-existing capture defect I surfaced honestly in PR 1 but didn't chase down (it needs on-device Linux capture debugging).
|
||||||
|
|
||||||
|
Tell me your license choice and I'll do the reconciliation PR; tell me which of 11–14 to prioritize and I'll take it next.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
# StepForge comprehensive improvement plan
|
# StepForge comprehensive improvement plan
|
||||||
|
|
||||||
This document is an implementation handoff for another coding agent. It is based on a repository-wide audit of commit `534a28e` on 2026-07-03. It is a plan, not authorization to make all changes in one unreviewable patch.
|
This document is an implementation handoff for another coding agent. It is based on a repository-wide audit of commit `534a28e` on 2026-07-03. It is a plan, not authorization to make all changes in one unreviewable patch.
|
||||||
|
|||||||
@@ -186,6 +186,11 @@ async function promptText({ title, label = 'Value', value = '', placeholder = ''
|
|||||||
});
|
});
|
||||||
|
|
||||||
field.addEventListener('keydown', (e) => {
|
field.addEventListener('keydown', (e) => {
|
||||||
|
if (multiline && e.key === 'Enter') {
|
||||||
|
// Let the textarea keep the Enter key for a new line.
|
||||||
|
e.stopPropagation();
|
||||||
|
return;
|
||||||
|
}
|
||||||
if (!multiline && e.key === 'Enter') {
|
if (!multiline && e.key === 'Enter') {
|
||||||
e.preventDefault();
|
e.preventDefault();
|
||||||
close();
|
close();
|
||||||
|
|||||||
+36
-18
@@ -105,6 +105,19 @@ function isEditableTarget(target) {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const ZOOM_IN_KEYS = new Set(['=', '+', 'Add']);
|
||||||
|
const ZOOM_OUT_KEYS = new Set(['-', '_', 'Subtract']);
|
||||||
|
|
||||||
|
function zoomShortcutFromEvent(e) {
|
||||||
|
if (!(e.ctrlKey || e.metaKey)) return null;
|
||||||
|
|
||||||
|
const { key, code } = e;
|
||||||
|
if (key === '0' || code === 'Digit0' || code === 'Numpad0') return 'fit';
|
||||||
|
if (ZOOM_IN_KEYS.has(key) || code === 'Equal' || code === 'NumpadAdd') return 'in';
|
||||||
|
if (ZOOM_OUT_KEYS.has(key) || code === 'Minus' || code === 'NumpadSubtract') return 'out';
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
class GuideEditor {
|
class GuideEditor {
|
||||||
constructor({ root, onMetaChange = () => {}, onToast = toast, onBack = () => {} } = {}) {
|
constructor({ root, onMetaChange = () => {}, onToast = toast, onBack = () => {} } = {}) {
|
||||||
this.root = root;
|
this.root = root;
|
||||||
@@ -1182,7 +1195,6 @@ class GuideEditor {
|
|||||||
const typeSelect = makeSelect(selected.type, [
|
const typeSelect = makeSelect(selected.type, [
|
||||||
'rect', 'oval', 'line', 'arrow', 'text', 'tooltip', 'number', 'blur', 'highlight', 'magnify', 'cursor',
|
'rect', 'oval', 'line', 'arrow', 'text', 'tooltip', 'number', 'blur', 'highlight', 'magnify', 'cursor',
|
||||||
].map((type) => ({ value: type, label: ANNOTATION_TYPE_LABELS[type] || type })));
|
].map((type) => ({ value: type, label: ANNOTATION_TYPE_LABELS[type] || type })));
|
||||||
const textInput = el('input', { type: 'text', value: selected.text || '', placeholder: 'Annotation text' });
|
|
||||||
const valueInput = el('input', { type: 'number', value: Number.isFinite(selected.value) ? selected.value : '', placeholder: 'Value' });
|
const valueInput = el('input', { type: 'number', value: Number.isFinite(selected.value) ? selected.value : '', placeholder: 'Value' });
|
||||||
const strokeInput = el('input', { type: 'color', value: style.stroke || '#E5484D' });
|
const strokeInput = el('input', { type: 'color', value: style.stroke || '#E5484D' });
|
||||||
const fillInput = el('input', { type: 'color', value: style.fill && style.fill !== 'transparent' ? style.fill : '#ffffff' });
|
const fillInput = el('input', { type: 'color', value: style.fill && style.fill !== 'transparent' ? style.fill : '#ffffff' });
|
||||||
@@ -1218,9 +1230,17 @@ class GuideEditor {
|
|||||||
const fields = new Set(ANNOTATION_FIELDS[selected.type] || []);
|
const fields = new Set(ANNOTATION_FIELDS[selected.type] || []);
|
||||||
const strokeLabel = (selected.type === 'text' || selected.type === 'number') ? 'Color' : 'Stroke';
|
const strokeLabel = (selected.type === 'text' || selected.type === 'number') ? 'Color' : 'Stroke';
|
||||||
const typeLabel = ANNOTATION_TYPE_LABELS[selected.type] || selected.type;
|
const typeLabel = ANNOTATION_TYPE_LABELS[selected.type] || selected.type;
|
||||||
|
const textInput = fields.has('text')
|
||||||
|
? el('textarea', {
|
||||||
|
rows: Math.max(3, Math.min(8, String(selected.text || '').split('\n').length)),
|
||||||
|
placeholder: 'Annotation text',
|
||||||
|
spellcheck: true,
|
||||||
|
})
|
||||||
|
: el('input', { type: 'text', value: selected.text || '', placeholder: 'Annotation text' });
|
||||||
|
if (fields.has('text')) textInput.value = selected.text || '';
|
||||||
|
|
||||||
const rows = [labeledRow('Type', typeSelect)];
|
const rows = [labeledRow('Type', typeSelect)];
|
||||||
if (fields.has('text')) rows.push(labeledRow('Text', textInput));
|
if (fields.has('text')) rows.push(labeledRow('Text', textInput, { stacked: true }));
|
||||||
if (fields.has('value')) rows.push(labeledRow('Value', valueInput));
|
if (fields.has('value')) rows.push(labeledRow('Value', valueInput));
|
||||||
if (fields.has('stroke')) rows.push(labeledRow(strokeLabel, strokeInput));
|
if (fields.has('stroke')) rows.push(labeledRow(strokeLabel, strokeInput));
|
||||||
if (fields.has('fill')) rows.push(labeledRow('Fill', fillInput));
|
if (fields.has('fill')) rows.push(labeledRow('Fill', fillInput));
|
||||||
@@ -2178,9 +2198,10 @@ class GuideEditor {
|
|||||||
ann.text = value;
|
ann.text = value;
|
||||||
step.annotations = clone(step.annotations || []);
|
step.annotations = clone(step.annotations || []);
|
||||||
this.pendingSave = true;
|
this.pendingSave = true;
|
||||||
await this.flushStep(step);
|
this.canvas.setAnnotations(step.annotations || []);
|
||||||
this.renderAnnotationPanel();
|
this.renderAnnotationPanel();
|
||||||
this.emitMeta();
|
this.emitMeta();
|
||||||
|
await this.flushStep(step);
|
||||||
}
|
}
|
||||||
|
|
||||||
formatDescription(command, block = null) {
|
formatDescription(command, block = null) {
|
||||||
@@ -2227,6 +2248,18 @@ class GuideEditor {
|
|||||||
|
|
||||||
onDocumentKeyDown(e) {
|
onDocumentKeyDown(e) {
|
||||||
if (!this.active || !this.guide) return;
|
if (!this.active || !this.guide) return;
|
||||||
|
const zoomShortcut = zoomShortcutFromEvent(e);
|
||||||
|
if (zoomShortcut) {
|
||||||
|
e.preventDefault();
|
||||||
|
if (zoomShortcut === 'in') {
|
||||||
|
this.setZoom(Math.min(3, (Number(this.currentZoom) || 1) + 0.25));
|
||||||
|
} else if (zoomShortcut === 'out') {
|
||||||
|
this.setZoom(Math.max(0.25, (Number(this.currentZoom) || 1) - 0.25));
|
||||||
|
} else {
|
||||||
|
this.setZoom('fit');
|
||||||
|
}
|
||||||
|
return;
|
||||||
|
}
|
||||||
if ((e.ctrlKey || e.metaKey) && e.key === '/' && !e.shiftKey) {
|
if ((e.ctrlKey || e.metaKey) && e.key === '/' && !e.shiftKey) {
|
||||||
e.preventDefault();
|
e.preventDefault();
|
||||||
this.openQuickActions();
|
this.openQuickActions();
|
||||||
@@ -2270,21 +2303,6 @@ class GuideEditor {
|
|||||||
if (next) this.selectStep(next.stepId);
|
if (next) this.selectStep(next.stepId);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if ((e.ctrlKey || e.metaKey) && (e.key === '=' || e.key === '+')) {
|
|
||||||
e.preventDefault();
|
|
||||||
this.setZoom(Math.min(3, (Number(this.currentZoom) || 1) + 0.25));
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if ((e.ctrlKey || e.metaKey) && e.key === '-') {
|
|
||||||
e.preventDefault();
|
|
||||||
this.setZoom(Math.max(0.25, (Number(this.currentZoom) || 1) - 0.25));
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if ((e.ctrlKey || e.metaKey) && e.key === '0') {
|
|
||||||
e.preventDefault();
|
|
||||||
this.setZoom('fit');
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
// Copy / paste the selected annotation.
|
// Copy / paste the selected annotation.
|
||||||
if ((e.ctrlKey || e.metaKey) && e.key.toLowerCase() === 'c' && this.selectedAnnotationId) {
|
if ((e.ctrlKey || e.metaKey) && e.key.toLowerCase() === 'c' && this.selectedAnnotationId) {
|
||||||
e.preventDefault();
|
e.preventDefault();
|
||||||
|
|||||||
Reference in New Issue
Block a user