Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9ab0a350ec |
@@ -1,4 +0,0 @@
|
|||||||
## 2024-06-25 - Excalidraw Memoization
|
|
||||||
|
|
||||||
**Learning:** The `@excalidraw/excalidraw` package's `Excalidraw` component is exceptionally expensive to re-render. Even though `EditorCanvas` was wrapped in `React.memo`, passing an inline arrow function to `onExcalidrawAPI` in the parent `App` broke memoization, causing severe input lag when typing in completely independent UI elements like the codeblock editor sidebar due to the entire canvas re-rendering.
|
|
||||||
**Action:** When passing callbacks to heavy third-party components like Excalidraw, always wrap them in `useCallback` hook to preserve their prop stability and maintain `React.memo` benefits, preventing disastrous performance regressions on typing/input.
|
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
## 2024-06-06 - Missing HTTP Security Headers
|
||||||
|
**Vulnerability:** The Caddyfile configuration was missing standard HTTP security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy), leaving the application susceptible to clickjacking, MIME-type sniffing, and sensitive data leakage via referrers.
|
||||||
|
**Learning:** The application relies on Caddy as a reverse proxy, and by default, Caddy doesn't automatically add these specific security headers unless explicitly configured.
|
||||||
|
**Prevention:** Ensure that reverse proxy configurations in new projects or updates to existing ones explicitly include essential HTTP security headers in a global scope to protect all served content.
|
||||||
@@ -6,6 +6,12 @@
|
|||||||
:80 {
|
:80 {
|
||||||
encode zstd gzip
|
encode zstd gzip
|
||||||
|
|
||||||
|
header {
|
||||||
|
X-Frame-Options "SAMEORIGIN"
|
||||||
|
X-Content-Type-Options "nosniff"
|
||||||
|
Referrer-Policy "strict-origin-when-cross-origin"
|
||||||
|
}
|
||||||
|
|
||||||
handle /mcp {
|
handle /mcp {
|
||||||
reverse_proxy 127.0.0.1:3001
|
reverse_proxy 127.0.0.1:3001
|
||||||
}
|
}
|
||||||
|
|||||||
+7
-9
@@ -307,10 +307,6 @@ function PrivateApp() {
|
|||||||
[],
|
[],
|
||||||
);
|
);
|
||||||
|
|
||||||
const handleExcalidrawAPI = useCallback((api: ExcalidrawImperativeAPI) => {
|
|
||||||
excalidrawApiRef.current = api;
|
|
||||||
}, []);
|
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="app-shell" ref={appShellRef}>
|
<div className="app-shell" ref={appShellRef}>
|
||||||
{toastMessage && (
|
{toastMessage && (
|
||||||
@@ -336,7 +332,9 @@ function PrivateApp() {
|
|||||||
onSceneChange={handleSceneChange}
|
onSceneChange={handleSceneChange}
|
||||||
onSelectionStateChange={handleCodeBlockSelectionChange}
|
onSelectionStateChange={handleCodeBlockSelectionChange}
|
||||||
onEditorActivity={scheduleThemeTokenSync}
|
onEditorActivity={scheduleThemeTokenSync}
|
||||||
onExcalidrawAPI={handleExcalidrawAPI}
|
onExcalidrawAPI={(api) => {
|
||||||
|
excalidrawApiRef.current = api;
|
||||||
|
}}
|
||||||
renderEmbeddable={renderCodeBlockEmbeddable}
|
renderEmbeddable={renderCodeBlockEmbeddable}
|
||||||
/>
|
/>
|
||||||
<CodeBlockSidebar
|
<CodeBlockSidebar
|
||||||
@@ -359,12 +357,12 @@ function PrivateApp() {
|
|||||||
onClose={closeSidebar}
|
onClose={closeSidebar}
|
||||||
onCreate={handleCreateDrawing}
|
onCreate={handleCreateDrawing}
|
||||||
onSelect={handleSelectDrawing}
|
onSelect={handleSelectDrawing}
|
||||||
onDelete={deleteDrawing}
|
onDelete={(drawingId) => void deleteDrawing(drawingId)}
|
||||||
onTitleChange={setActiveTitle}
|
onTitleChange={setActiveTitle}
|
||||||
onTitleSubmit={submitTitle}
|
onTitleSubmit={() => void submitTitle()}
|
||||||
onPublicationSlugChange={setPublicationSlug}
|
onPublicationSlugChange={setPublicationSlug}
|
||||||
onPublish={publishPublication}
|
onPublish={() => void publishPublication()}
|
||||||
onDisablePublication={disablePublication}
|
onDisablePublication={() => void disablePublication()}
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
import { memo } from "react";
|
|
||||||
import { type DrawingMeta, type DrawingPublication } from "../../core/shared";
|
import { type DrawingMeta, type DrawingPublication } from "../../core/shared";
|
||||||
|
|
||||||
type DrawingSidebarProps = {
|
type DrawingSidebarProps = {
|
||||||
@@ -10,14 +9,14 @@ type DrawingSidebarProps = {
|
|||||||
publicationSlug: string;
|
publicationSlug: string;
|
||||||
publicationBusy: boolean;
|
publicationBusy: boolean;
|
||||||
onClose: () => void;
|
onClose: () => void;
|
||||||
onCreate: () => void | Promise<void>;
|
onCreate: () => void;
|
||||||
onSelect: (drawingId: string) => void | Promise<void>;
|
onSelect: (drawingId: string) => void;
|
||||||
onDelete: (drawingId: string) => void | Promise<void>;
|
onDelete: (drawingId: string) => void;
|
||||||
onTitleChange: (title: string) => void;
|
onTitleChange: (title: string) => void;
|
||||||
onTitleSubmit: () => void | Promise<void>;
|
onTitleSubmit: () => void;
|
||||||
onPublicationSlugChange: (slug: string) => void;
|
onPublicationSlugChange: (slug: string) => void;
|
||||||
onPublish: () => void | Promise<void>;
|
onPublish: () => void;
|
||||||
onDisablePublication: () => void | Promise<void>;
|
onDisablePublication: () => void;
|
||||||
};
|
};
|
||||||
|
|
||||||
function DrawerIcon() {
|
function DrawerIcon() {
|
||||||
@@ -65,7 +64,7 @@ export function DrawingsToggle({ onClick }: { onClick: () => void }) {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
export const DrawingSidebar = memo(function DrawingSidebar({
|
export function DrawingSidebar({
|
||||||
open,
|
open,
|
||||||
drawings,
|
drawings,
|
||||||
activeId,
|
activeId,
|
||||||
@@ -134,7 +133,7 @@ export const DrawingSidebar = memo(function DrawingSidebar({
|
|||||||
className="title-input"
|
className="title-input"
|
||||||
value={activeTitle}
|
value={activeTitle}
|
||||||
onChange={(event) => onTitleChange(event.target.value)}
|
onChange={(event) => onTitleChange(event.target.value)}
|
||||||
onBlur={() => void onTitleSubmit()}
|
onBlur={onTitleSubmit}
|
||||||
onKeyDown={(event) => {
|
onKeyDown={(event) => {
|
||||||
if (event.key === "Enter") {
|
if (event.key === "Enter") {
|
||||||
event.currentTarget.blur();
|
event.currentTarget.blur();
|
||||||
@@ -144,7 +143,7 @@ export const DrawingSidebar = memo(function DrawingSidebar({
|
|||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
className="icon-button drawing-delete-button"
|
className="icon-button drawing-delete-button"
|
||||||
onClick={() => void onDelete(drawing.id)}
|
onClick={() => onDelete(drawing.id)}
|
||||||
aria-label={`Delete ${drawing.title}`}
|
aria-label={`Delete ${drawing.title}`}
|
||||||
>
|
>
|
||||||
×
|
×
|
||||||
@@ -172,7 +171,7 @@ export const DrawingSidebar = memo(function DrawingSidebar({
|
|||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
className="secondary-button"
|
className="secondary-button"
|
||||||
onClick={() => void onPublish()}
|
onClick={onPublish}
|
||||||
disabled={publicationBusy}
|
disabled={publicationBusy}
|
||||||
>
|
>
|
||||||
{publication.enabled ? "Update link" : "Publish"}
|
{publication.enabled ? "Update link" : "Publish"}
|
||||||
@@ -180,7 +179,7 @@ export const DrawingSidebar = memo(function DrawingSidebar({
|
|||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
className="secondary-button"
|
className="secondary-button"
|
||||||
onClick={() => void onDisablePublication()}
|
onClick={onDisablePublication}
|
||||||
disabled={!publication.enabled || publicationBusy}
|
disabled={!publication.enabled || publicationBusy}
|
||||||
>
|
>
|
||||||
Unpublish
|
Unpublish
|
||||||
@@ -206,7 +205,7 @@ export const DrawingSidebar = memo(function DrawingSidebar({
|
|||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
className="drawing-link"
|
className="drawing-link"
|
||||||
onClick={() => void onSelect(drawing.id)}
|
onClick={() => onSelect(drawing.id)}
|
||||||
>
|
>
|
||||||
<span className="drawing-title">{drawing.title}</span>
|
<span className="drawing-title">{drawing.title}</span>
|
||||||
</button>
|
</button>
|
||||||
@@ -215,7 +214,7 @@ export const DrawingSidebar = memo(function DrawingSidebar({
|
|||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
className="icon-button"
|
className="icon-button"
|
||||||
onClick={() => void onDelete(drawing.id)}
|
onClick={() => onDelete(drawing.id)}
|
||||||
aria-label={`Delete ${drawing.title}`}
|
aria-label={`Delete ${drawing.title}`}
|
||||||
>
|
>
|
||||||
×
|
×
|
||||||
@@ -227,4 +226,4 @@ export const DrawingSidebar = memo(function DrawingSidebar({
|
|||||||
</aside>
|
</aside>
|
||||||
</>
|
</>
|
||||||
);
|
);
|
||||||
});
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user