Skip to content

fix: neutralize presentation and secure document message boundaries - #245

Open
chaxus wants to merge 5 commits into
mainfrom
fix/neutral-presentation-and-message-boundaries
Open

chaxus wants to merge 5 commits into
mainfrom
fix/neutral-presentation-and-message-boundaries

Conversation

@chaxus

@chaxus chaxus commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Product marks previously appeared in the site chrome, editor shells and PWA assets. Replace these with neutral document icons and generic interface labels while retaining upstream copyright, license, version and source information. Update all README translations and NOTICE to explain the modifications and distinguish the FSF interpretation from a court judgment.

Light and dark modes now keep favicons, browser theme colors and editor presentation consistent, including manual overrides and offline cache availability. The PWA launcher keeps a stable icon; ordinary icons have transparent corners and the maskable icon is fully opaque.

The review also found document-message trust issues: reject export streams outside the current same-origin editor, accept embed commands only from the direct parent with a fixed origin, and stop forwarding raw file bytes to the top-level window. Fix Service Worker cleanup promises, language-button accessible names and outdated image fixtures. Unify data handling and offline prerequisites across all seven site languages, including landing-page metadata, visible FAQs and their JSON-LD. Mark the built-in AI assistant as unfinished rather than advertise the experimental modules as a released feature. Explain embedding-host and external browser-agent data sharing separately from core local editing; README notes describe cloud-provider data flows only for development tests. Document seven-day recovery copies, deletion controls and storage limitations. Refresh stale sitemap dates from Git history and correct crawler guidance.

Validation

  • 60 unit-test files / 3462 tests passed.
  • TypeScript, oxlint, Prettier, production build and git diff whitespace checks passed.
  • 63 related Chromium E2E tests passed, covering themes, branding/legal notices, embed commands, real document exports, images, disk saves, language menus and mobile layout.
  • Built LICENSE and NOTICE match the repository originals.
  • Follow-up copy validation: 2431 page-generation, SEO and copyright tests passed; 20 language-menu and all-page mobile-layout E2E tests passed. Recovery-window assertions now cover all seven languages and use the actual retention configuration.

The broader corpus/API sweep and other browsers were not run locally; repository CI will perform its configured checks. Existing optional SDK externalization and WebLLM chunk-size build warnings remain.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Deploying document with  Cloudflare Pages  Cloudflare Pages

Latest commit: 61c5df1
Status: ✅  Deploy successful!
Preview URL: https://c46a7d60.document-7hm.pages.dev
Branch Preview URL: https://fix-neutral-presentation-and.document-7hm.pages.dev

View logs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant