Skip to content

Fix/investigate caching deployment#6

Merged
BandiAkarsh merged 3 commits intomainfrom
fix/investigate-caching-deployment
Mar 1, 2026
Merged

Fix/investigate caching deployment#6
BandiAkarsh merged 3 commits intomainfrom
fix/investigate-caching-deployment

Conversation

@BandiAkarsh
Copy link
Copy Markdown
Owner

No description provided.

CRITICAL FIXES:
- Remove debug console logs from Editor.svelte, providers.ts, service-worker.js
- Implement proper PBKDF2 key derivation in crypto/e2e.ts (100k iterations, SHA-256)
- Remove non-functional passkey button from landing page
- Fix XSS vulnerability in export (sanitize HTML before export)

HIGH PRIORITY FIXES:
- Add proper form labels with aria-label for accessibility
- Add sr-only class for screen readers
- Remove unused imports (Button, Card) from dashboard

Security improvements:
- Proper key derivation prevents brute force attacks
- Removed debug logs prevent info leaks in production

Note: Some callers of deriveKeyFromPassword still need to be updated to use await
since the function is now async.
- Properly remove all debug console.log statements from Editor.svelte
- Fix multiline console.log removal that was breaking syntax
- Update deriveKeyFromPassword callers to use await:
  - note/[id]/+page.svelte: handlePasswordSubmit
  - notes.svelte.ts: protectNote function
- Remove passkey button from landing page
- Add accessibility labels to form inputs

Build now passes successfully with 0 errors.
XSS Protection:
- Add sanitizeHTML function to escape HTML special characters
- Use sanitized title in export (prevents XSS in exported files)

Editor Menu Fixes:
- Replace CSS hover-based dropdowns with click-to-toggle menus
- Add openMenu state to track which menu is open
- Click outside or select menu item now closes dropdown
- Menus now work properly on mobile and desktop

Both fixes improve security and usability.
@BandiAkarsh BandiAkarsh merged commit aaeca10 into main Mar 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant