Phase 2 of the improvement plan (PR 5 of the sequence). Several confirmed
capture defects from the audit.
Region capture:
- regionCapture returned { ok, step } wrapping storeFrameAsStep's own
{ ok, step }, so the real step was at result.step.step — region selection
and region auto-doc (which read result.step.stepId) broke. Return the
storeFrameAsStep result directly.
- pickRegion leaked the region:picked IPC listener (and the overlay/image
refs) whenever the overlay was cancelled/closed rather than picked: cleanup
only ran on a pick. Cleanup is now idempotent and runs on pick, close, load
failure, and settle. The received rectangle is validated and clamped to the
image (new overlayRectToImageRect handles negative-size drags and
out-of-bounds selections) so image.crop can never read out of bounds.
Power blocker ownership:
- New single owner: CaptureService.syncPower() holds the blocker iff a session
is actively recording, called on start/pause/resume/finish. A new session
starts paused and no longer holds the blocker while idle; tray and
second-instance pauses that previously bypassed main.js's stop closure now
release it correctly. main.js provides the power policy (blocker + EcoQoS
opt-out) via dependency injection.
Explicit click-trigger source:
- startEvdevWatcher never set clickWatcher, so state().clickCapture read false
while evdev was actively capturing clicks. Replaced the boolean with an
explicit clickSource (windows-hook | x11 | evdev-x11 | evdev-wayland |
unavailable); clickCapture is now derived from it. evdev device-stream
errors/closes now fall back via handleClickWatcherLoss instead of being
swallowed.
Strict click timing:
- When no pre-click frame qualifies, strict mode previously fell through to a
fresh (post-click) shot and stored it — contradicting the strict promise.
It now skips with a capture:diagnostic instead. Non-strict (balanced) mode
keeps the fresh-shot fallback. Existing tests that exercised the fallback
now run in balanced mode; the strict test asserts the skip.
Other:
- pathToFileURL replaces file://${p} concatenation for step image URLs and
export previews (correct for spaces, #, %, drive letters).
- Best-effort click-queue drain on app shutdown (before-quit) so a burst just
before quit is not lost; bounded so quit never hangs.
Tests: region rect clamping/normalization, power-held-only-while-recording
(incl. finish releases), click-source reporting incl. evdev, drain deadline.
230 unit tests pass. Click self-test: markers 3/3 (strict) and burst 8/8
deterministic across runs; the burst scenario runs in balanced mode because
it tests the drain, not strict timing. (arm/debounce remain the pre-existing
Linux capture failures untouched by this PR.)
Co-Authored-By: Claude Fable 5 <[email protected]>
StepForge
StepForge is a local-first, open-source desktop app for Windows, with Linux (WIP) builds. It captures step-by-step workflows as screenshots, lets you annotate and describe each step in a focused three-pane editor, and exports the result to Markdown, DOCX, PPTX, PDF, HTML (WIP), GIF (WIP), confluence (WIP), Wiki.js (WIP), and image bundles (WIP). The current reconmendations for exporting is Markdown and PDF.
It is an independent desktop guide-capture tool inspired by publicly documented workflow patterns of commercial documentation tools like Folge. It contains no third-party branding, assets, or code from those tools.
Network and privacy contract. StepForge has no telemetry, no update checks, no license checks, and no cloud. Guides never leave your machine on their own. The only outbound network feature is the optional AI integration: when you enable it and configure an Ollama endpoint, StepForge sends step screenshots and text to that endpoint to generate titles and descriptions. By default that endpoint must be local (loopback); sending data to a remote host requires the explicit "Allow remote AI host" opt-in. See docs/PRIVACY.md for exactly what is collected and sent. Note that OCR (Tesseract) and its English language data are bundled production dependencies — Electron is not the only one.
Overview
The core workflow:
- Capture — take full-screen, active-window, or region screenshots with configurable delay, pause/resume, and global hotkeys; or import images and paste from the clipboard.
- Annotate — rectangles, ovals, lines, arrows, text, tooltips, numbered markers, blur, highlight, magnify, and crop on a resolution-independent annotation scene graph.
- Describe — rich-text titles and descriptions, informational text blocks, code blocks, tables, step links, and placeholders.
- Export — every exporter renders from the same normalized Render AST, so output is deterministic across formats.
What's Included
- Guide library with folders, favorites, title search, full-text search,
duplicate/move/delete, and a quick-actions palette (
Ctrl+/). - Capture engine — the editor's Capture ▾ button offers full screen, active window, and region capture (the app hides itself during the shot), plus continuous capture sessions that grab a step on every click where the OS allows it, or on a 3/5/10 s auto-interval everywhere else. The REC bar shows the live count and the start/pause control. Delay, global hotkeys, click markers, clipboard paste, and PNG/JPEG/GIF import included. The full keyboard shortcut list lives under More ▾ → Keyboard shortcuts in the editor.
- Three-pane editor — step tree with substeps, statuses (todo/in-progress/done), hidden/skipped steps, focused view (zoom/pan that never mutates the original image), autosave, and command-stack undo/redo.
- Annotation canvas — normalized JSON scene graph with resolution-independent coordinates; annotations render identically in the editor and in every exporter.
- Sharing & backups — single-file
.sfgzarchives (zip-based, path- traversal validated), linked guides with.lock-sfgzlock files and explicit save, plus automated snapshot backups and restore. - Exports — JSON, Markdown, Simple HTML, Rich HTML (checkboxes + floating
TOC), PDF, animated GIF, image bundle, DOCX, and PPTX, with per-format
export templates shareable as
.sfgltfiles. - Settings & theming — system/light/dark themes, capture options, keyboard shortcuts, preview step count.
Everything except the Electron shell is dependency-free Node.js: the ZIP, PNG, GIF, PDF, DOCX, and PPTX writers are all implemented in this repository using only Node built-ins.
Getting Started
For a Windows installation, see docs/windows_installation or for a developer/more in depth walkthrough, see docs/GETTING_STARTED.md.
On Linux (⚠️ work in progress — X11 vs Wayland, enabling per-click capture, the screen-share prompt), see docs/GETTING_STARTED_WITH_LINUX.md.
Requirements: Node.js 22.12+ and npm (pinned in .nvmrc; installs are
refused on older Nodes because the packaging toolchain needs 22.12+).
npm ci # one-time, installs the locked dependency tree
npm start # launch StepForge
Dependencies are only ever installed by you, via npm ci — the app never
downloads or repairs packages at runtime.
First run creates the local data directory (~/.local/share/stepforge on
Linux (WIP), %APPDATA%/stepforge on Windows; override with
STEPFORGE_DATA_DIR).
Testing
Please create your tests so that when the following is ran it automatically tests your test.
bash tests/run_test.sh
The runner executes every tests/checks/test_*.sh script; those scripts run
the workflow test suites under tests/unit/ with node --test. The tests
exercise real workflows like creating guides, round-tripping archives, exporting
documents, and validating the bytes of the output, not string matching.
Building & Packaging
bash scripts/bootstrap-offline.sh # verify toolchain availability
bash scripts/verify.sh # full test suite + smoke checks
bash scripts/build-release.sh # assemble runnable app directory
bash scripts/package-linux.sh # local Linux packaging (WIP; not part of release)
npm run package:windows # Windows installer .exe in releases/
pwsh scripts/package-windows.ps1 # same Windows installer build via PowerShell
See build/build_report.md for what was produced on this machine and which packaging tools were unavailable.
Offline Guarantee
The shipping app makes zero network calls. There is no telemetry, no update check, no license validation, no cloud sync, no account system, and no remote AI. Exports embed no remote fonts or CDN references. See docs/SECURITY.md for the threat model.
Contributing
See docs/CONTRIBUTING.md for the full contribution flow, including the issue-number requirement for every pull request and the clean-room rules.
Repository Layout
Project docs live in docs/ and prompt handoffs live in ai_prompts/.
See docs/ARCHITECTURE.md for the repo layout.
License
Creative Commons Attribution-NonCommercial
Basically, do whatever you want with it just don't make money off it or sell it.