Skip to content
This repository was archived by the owner on Jun 17, 2026. It is now read-only.
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 43 additions & 0 deletions .github/workflows/frontend-pages.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# https://github.com/actions/deploy-pages#usage
name: Deploy to GitHub Pages
on:
workflow_dispatch:
push:
branches:
- master
- rewrite/vue
jobs:
build:
if: "!contains(github.event.head_commit.message, '[SKIP CI]')"
runs-on: ubuntu-latest
steps:
Comment on lines +10 to +13

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Restrict permissions in build job.

The build job uses default permissions which are overly broad. Apply the principle of least privilege by explicitly setting minimal permissions.

🔒 Proposed fix
   build:
     if: contains(github.event.head_commit.message, '[CI]')
     runs-on: ubuntu-latest
+    permissions:
+      contents: read
     steps:
🧰 Tools
🪛 zizmor (1.25.2)

[warning] 9-25: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block

(excessive-permissions)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/frontend-pages.yml around lines 9 - 12, The build job
currently relies on default (broad) permissions; add an explicit permissions
block under the build job to apply least-privilege. Update the "build" job
definition (the job named "build" that contains the existing if:
contains(github.event.head_commit.message, '[CI]') and runs-on: ubuntu-latest)
to include a permissions section that limits scopes to only what the workflow
needs (for example: contents: read and pages: write if publishing to Pages,
optionally id-token: write if using OIDC, and any other specific minimal
scopes), ensuring no broad permissions are inherited.

- uses: actions/checkout@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Add persist-credentials: false to checkout action.

The checkout action should set persist-credentials: false to prevent the GITHUB_TOKEN from persisting in the workspace, reducing the risk of credential leakage through artifacts.

🔒 Proposed fix
       - uses: actions/checkout@v4
+        with:
+          persist-credentials: false
       - run: corepack enable
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- uses: actions/checkout@v4
- uses: actions/checkout@v4
with:
persist-credentials: false
- run: corepack enable
🧰 Tools
🪛 zizmor (1.25.2)

[warning] 13-13: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 13-13: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/frontend-pages.yml at line 13, The checkout step using
actions/checkout@v4 currently lacks the persist-credentials setting; update the
checkout step (the actions/checkout@v4 usage) to include persist-credentials:
false so the GITHUB_TOKEN is not left in the workspace and cannot be leaked via
artifacts or other files.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Get commit SHAs for the action versions used in the workflow

echo "actions/checkout@v4:"
gh api repos/actions/checkout/git/ref/tags/v4 --jq '.object.sha'

echo "actions/setup-node@v4:"
gh api repos/actions/setup-node/git/ref/tags/v4 --jq '.object.sha'

echo "actions/upload-pages-artifact@v3:"
gh api repos/actions/upload-pages-artifact/git/ref/tags/v3 --jq '.object.sha'

echo "actions/deploy-pages@v4:"
gh api repos/actions/deploy-pages/git/ref/tags/v4 --jq '.object.sha'

Repository: vtf6259/ChatWS

Length of output: 325


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/frontend-pages.yml"
echo "== File: $FILE =="
nl -ba "$FILE" | sed -n '1,120p'

Repository: vtf6259/ChatWS

Length of output: 168


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/frontend-pages.yml"

echo "== File: $FILE =="
# cat -n is usually available; limit output to keep it readable
cat -n "$FILE" | sed -n '1,140p'

Repository: vtf6259/ChatWS

Length of output: 1709


🏁 Script executed:

#!/bin/bash
set -euo pipefail
FILE=".github/workflows/frontend-pages.yml"

echo "== Tail: $FILE =="
tail -n 40 "$FILE" | cat -n

Repository: vtf6259/ChatWS

Length of output: 1607


Pin GitHub Actions to commit SHAs for supply chain security.

The workflow uses mutable tag refs:

  • actions/checkout@v4 (line 13) → actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
  • actions/setup-node@v4 (line 15) → actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
  • actions/upload-pages-artifact@v3 (line 22) → actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa
  • actions/deploy-pages@v4 (line 43) → actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e

Update each uses: to the commit SHA (keep a comment with the original tag, e.g. # v4/# v3).

🧰 Tools
🪛 zizmor (1.25.2)

[warning] 13-13: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 13-13: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/frontend-pages.yml at line 13, Update the GitHub Actions
steps that currently use mutable tags to pinned commit SHAs: replace
actions/checkout@v4 with
actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 (keep a trailing
comment "# v4"), replace actions/setup-node@v4 with
actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 ("# v4"), replace
actions/upload-pages-artifact@v3 with
actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa ("# v3"),
and replace actions/deploy-pages@v4 with
actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e ("# v4"); ensure
each uses: line is updated accordingly in the workflow so the actions are pinned
to the provided SHAs and each retains a comment with the original tag for
clarity.

- run: corepack enable
- uses: actions/setup-node@v4
with:
node-version: "20"
# Pick your own package manager and build script
- run: make frontend
- name: Upload artifact
uses: actions/upload-pages-artifact@v3
with:
path: ./frontend/dist
# Deployment job
deploy:
if: "!contains(github.event.head_commit.message, '[SKIP CI]')"
# Add a dependency to the build job
needs: build
# Grant GITHUB_TOKEN the permissions required to make a Pages deployment
permissions:
pages: write # to deploy to Pages
id-token: write # to verify the deployment originates from an appropriate source
# Deploy to the github_pages environment
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
# Specify runner + deployment step
runs-on: ubuntu-latest
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v4
6 changes: 3 additions & 3 deletions .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
name: Makefile CI

on:
workflow_dispatch:
push:
branches: [ "master" ]
pull_request:
branches: [ "master" ]

jobs:
build:
if: contains(github.event.head_commit.message, '[CI]')
if: "!contains(github.event.head_commit.message, '[SKIP CI]')"
if: "!contains(github.event.head_commit.message, '[SKIP BACKEND BUILD]')"
runs-on: ubuntu-latest

steps:
Expand Down
8 changes: 4 additions & 4 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ frontend:
backend:
./buildBackend.sh
clean:
rm backend/ChatWS
rm -r build/ChatWS
rm -r frontend/dist
rm -r build/dist
rm -f backend/ChatWS
rm -f build/ChatWS
rm -rf frontend/dist
rm -rf build/dist
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# Users
This section is for users of ChatWS
1. Your private key is your second password TREAT IT LIKE A PASSWORD! DO NOT SEND IT TO ANYONE!
2. Your public key is for the server and users to send messages to you.
- Your public key __needs__ to be shared for users to send messages.
- You can get it from your private key if you lose it.
3 changes: 2 additions & 1 deletion build/.gitignore
Original file line number Diff line number Diff line change
@@ -1,2 +1,3 @@
*
!.gitignore
!.gitignore
!README.md
6 changes: 6 additions & 0 deletions build/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# Build output(s)
The ChatWS file is the server here is a example command to run it
Comment thread
vtf6259 marked this conversation as resolved.
```bash
./ChatWS --port 8098 --pgppubkey dev.pub.pgp --pgpprivkey dev.priv.pgp
```
The dist folder is what you put on a web server for the frontend KEEP THE ChatWS FOLDER VITE CONFIGURES FOR THAT IF YOU WANT TO CHANGE IT EDIT vite.config.ts IN THE FRONTEND FOLDER AND REBUILD
3 changes: 2 additions & 1 deletion buildFrontend.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,5 @@
cd frontend
npm i
npm run build
cp -R dist ../build
mkdir -p ../build/dist
cp -R dist ../build/dist/ChatWS
2 changes: 1 addition & 1 deletion connectStandard
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
< MOTD <the motd> (if there is no motd it will be *NOMOTD*)
> USER <username>
< MOTD <the motd> (if there is no motd it will be *NOMOTD*)
Comment on lines 1 to +2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Description: Verify that App.vue sends USER before receiving MOTD

# Search for WebSocket message handling in the frontend
rg -n -C5 'USER|MOTD' frontend/src/App.vue

# Also check for any protocol documentation or comments
rg -n 'protocol|handshake' frontend/src/

Repository: vtf6259/ChatWS

Length of output: 525


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# 1) Find all frontend references to USER/MOTD (beyond App.vue snippet) and locate onmessage handlers.
rg -n --hidden --no-ignore -S 'MOTD' frontend/src
rg -n --hidden --no-ignore -S 'USER\s' frontend/src
rg -n -S 'onmessage|addEventListener\("message"|message\)' frontend/src

# 2) Check for protocol/handshake mentions in frontend again but include other files.
rg -n -S 'protocol|handshake|connectStandard|MOTD|USER\s' frontend/src

# 3) Backend verification: locate MOTD/USER handling/sending.
# Try common backend directories first by searching entire repo for these literals.
rg -n --hidden --no-ignore -S '"MOTD' .
rg -n --hidden --no-ignore -S 'MOTD\s' .
rg -n --hidden --no-ignore -S '"USER ' .
rg -n --hidden --no-ignore -S 'USER\s' .

# 4) Locate connectStandard file and show its first couple lines for exact wording.
# (If the file is named exactly connectStandard without extension, search by filename.)
fd -a -H 'connectStandard*' . | head -n 20

Repository: vtf6259/ChatWS

Length of output: 40


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# After locating connectStandard candidates, print the likely one.
# This script is tolerant: it prints contents only for paths that match connectStandard*.
paths=$(fd -a -H 'connectStandard*' . | head -n 20)
echo "$paths"
echo "----"
# Print first 30 lines of each candidate (to keep output small).
for p in $paths; do
  echo "## $p"
  sed -n '1,30p' "$p" | cat -n
  echo
done

Repository: vtf6259/ChatWS

Length of output: 570


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Frontend: find where incoming messages are parsed/handled
rg -n -S '\bMOTD\b' frontend/src || true
rg -n -S 'addEventListener\("message"|onmessage|message\s*\(' frontend/src || true
rg -n -S 'split\(|startsWith\(|includes\(|switch\s*\(|case\s+"' frontend/src/App.vue frontend/src || true

echo "---- FRONTEND: likely message parsing around "MOTD" ----"
# Try to grab nearby context for any MOTD mention
rg -n -S -C5 '\bMOTD\b' frontend/src || true

# Backend: find handshake state machine / message handlers for these protocol tokens
rg -n -S '\bMOTD\b' . || true
rg -n -S '"USER ' . || true
rg -n -S '\bUSER\b' . || true

echo "---- BACKEND: likely websocket message handler code ----"
rg -n -S 'websocket|ws|upgrade|onmessage|message\s*\(|addEventListener\("message"|wss' . || true

Repository: vtf6259/ChatWS

Length of output: 10111


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Show backend getAuth and handshake ordering.
sed -n '1,170p' backend/server.go | cat -n

echo "---- frontend App.vue ----"
sed -n '1,120p' frontend/src/App.vue | cat -n

echo "---- message parsing helper (if exists) ----"
ls -la | sed -n '1,200p'
ls -la frontend/src | sed -n '1,200p'

if [ -f messageTypes ]; then
  echo "---- messageTypes ----"
  sed -n '1,80p' messageTypes | cat -n
fi

# Show js-client handshake order for additional context.
sed -n '1,120p' js-client/index.js | cat -n

Repository: vtf6259/ChatWS

Length of output: 13616


connectStandard handshake order conflicts with backend implementation

connectStandard states > USER occurs before < MOTD, but backend/server.go sends MOTD immediately after the websocket upgrade and only then enters getAuth() which reads the client’s first message expecting USER. The current frontend sends USER on socket open and doesn’t assume strict ordering, but the documented protocol contract is inconsistent with the server and may break other clients.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@connectStandard` around lines 1 - 2, The protocol doc in connectStandard is
out of order compared to the server: backend/server.go sends MOTD immediately
after websocket upgrade and then calls getAuth() to read the client's first
message (USER), so update connectStandard to reflect the actual handshake order
by showing the server-to-client MOTD ("< MOTD" or "*NOMOTD*") before the
client-to-server USER ("> USER"); reference connectStandard, backend/server.go
and getAuth when making the change so the documented contract matches the
implementation.

< CHALLENGE <random text> <server public pgp key>
> AUTH <random text encrypted with server public key>
(if failed)
Expand Down
21 changes: 16 additions & 5 deletions frontend/.gitignore
Original file line number Diff line number Diff line change
@@ -1,7 +1,3 @@
# nuxt rewrite stuff even though it is on a diffrent branch git goes crazy since it is not tracked on rewrite/nuxt
.nuxt
.output

# Logs
logs
*.log
Expand All @@ -12,17 +8,32 @@ pnpm-debug.log*
lerna-debug.log*

node_modules
.DS_Store
dist
dist-ssr
coverage
*.local

# Editor directories and files
.vscode/*
!.vscode/extensions.json
.idea
.DS_Store
*.suo
*.ntvs*
*.njsproj
*.sln
*.sw?

*.tsbuildinfo

.eslintcache

# Cypress
/cypress/videos/
/cypress/screenshots/

# Vitest
__screenshots__/

# Vite
*.timestamp-*-*.mjs
3 changes: 3 additions & 0 deletions frontend/.vscode/extensions.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"recommendations": ["Vue.volar"]
}
42 changes: 42 additions & 0 deletions frontend/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
# ChatWS Frontend
This is the vue frontend for ChatWS.
Also ignore the error in tsconfig.node.json the error is false.
The rest is from the template readme.
Comment on lines +3 to +4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Remove blanket “ignore the error” guidance on Line 3.

As written, this can normalize ignoring real TypeScript/configuration failures. Replace it with the exact diagnostic (or a tracked issue link) and a concrete workaround.

Proposed doc fix
-Also ignore the error in tsconfig.node.json the error is false.   
-The rest is from the template readme.  
+If you see a `tsconfig.node.json` diagnostic, do not ignore it by default.
+Document the exact error message and apply the corresponding fix (or link a tracked issue with context).
+The rest of this file is based on the Vue template README.
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Also ignore the error in tsconfig.node.json the error is false.
The rest is from the template readme.
If you see a `tsconfig.node.json` diagnostic, do not ignore it by default.
Document the exact error message and apply the corresponding fix (or link a tracked issue with context).
The rest of this file is based on the Vue template README.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@frontend/README.md` around lines 3 - 4, Remove the blanket "Also ignore the
error in tsconfig.node.json the error is false." statement from README.md and
replace it with the exact TypeScript diagnostic message or a link to a tracked
issue, plus a concrete workaround; reference the tsconfig.node.json file and
specify the diagnostic code or error text and one clear remediation step (e.g.,
add a specific compilerOptions override, update a package version, or run a
provided CLI command) so readers know how to reproduce and resolve the issue
rather than blanket-ignore it.

## Recommended IDE Setup

[VS Code](https://code.visualstudio.com/) + [Vue (Official)](https://marketplace.visualstudio.com/items?itemName=Vue.volar) (and disable Vetur).

## Recommended Browser Setup

- Chromium-based browsers (Chrome, Edge, Brave, etc.):
- [Vue.js devtools](https://chromewebstore.google.com/detail/vuejs-devtools/nhdogjmejiglipccpnnnanhbledajbpd)
- [Turn on Custom Object Formatter in Chrome DevTools](http://bit.ly/object-formatters)
- Firefox:
- [Vue.js devtools](https://addons.mozilla.org/en-US/firefox/addon/vue-js-devtools/)
- [Turn on Custom Object Formatter in Firefox DevTools](https://fxdx.dev/firefox-devtools-custom-object-formatters/)

## Type Support for `.vue` Imports in TS

TypeScript cannot handle type information for `.vue` imports by default, so we replace the `tsc` CLI with `vue-tsc` for type checking. In editors, we need [Volar](https://marketplace.visualstudio.com/items?itemName=Vue.volar) to make the TypeScript language service aware of `.vue` types.

## Customize configuration

See [Vite Configuration Reference](https://vite.dev/config/).

## Project Setup

```sh
npm install
```

### Compile and Hot-Reload for Development

```sh
npm run dev
```

### Type-Check, Compile and Minify for Production

```sh
npm run build
```
1 change: 1 addition & 0 deletions frontend/env.d.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
/// <reference types="vite/client" />
15 changes: 8 additions & 7 deletions frontend/index.html
Original file line number Diff line number Diff line change
@@ -1,12 +1,13 @@
<!doctype html>
<html lang="en">
<!DOCTYPE html>
<html lang="">

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Set a valid document language instead of empty lang.

Line 2 uses lang="", which hurts accessibility and language detection. Set a concrete locale (for example en).

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@frontend/index.html` at line 2, The document root <html> element currently
has an empty lang attribute (lang=""); update the <html> tag in
frontend/index.html to use a concrete locale (e.g., set lang="en" or the
appropriate BCP 47 locale) so screen readers and language detection work
correctly.

<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>FolderChat</title>
<meta charset="UTF-8">
<link rel="icon" href="/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>ChatWS</title>
</head>
<body>
<div id="reactDOM"></div>
<script type="module" src="/src/main.tsx"></script>
<div id="app"></div>
<script type="module" src="/src/main.ts"></script>
</body>
</html>
Loading
Loading