-
Notifications
You must be signed in to change notification settings - Fork 0
Frontend #9
base: master
Are you sure you want to change the base?
Frontend #9
Changes from all commits
09e2aa8
9555fe2
938c963
fd355ac
aeddef0
0852a39
3cd2acf
1700480
094db8e
ee4f74f
2164f68
2509390
7007f0a
512f0c5
4bc4465
8387ac3
eb3711b
b495300
96d040d
83bcc87
e283f35
885cb3b
97dbca5
8753a19
28019c9
742ee94
266a2c7
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,43 @@ | ||||||||||||
| # https://github.com/actions/deploy-pages#usage | ||||||||||||
| name: Deploy to GitHub Pages | ||||||||||||
| on: | ||||||||||||
| workflow_dispatch: | ||||||||||||
| push: | ||||||||||||
| branches: | ||||||||||||
| - master | ||||||||||||
| - rewrite/vue | ||||||||||||
| jobs: | ||||||||||||
| build: | ||||||||||||
| if: "!contains(github.event.head_commit.message, '[SKIP CI]')" | ||||||||||||
| runs-on: ubuntu-latest | ||||||||||||
| steps: | ||||||||||||
| - uses: actions/checkout@v4 | ||||||||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Add persist-credentials: false to checkout action. The checkout action should set 🔒 Proposed fix - uses: actions/checkout@v4
+ with:
+ persist-credentials: false
- run: corepack enable📝 Committable suggestion
Suggested change
🧰 Tools🪛 zizmor (1.25.2)[warning] 13-13: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [error] 13-13: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI Agents🧩 Analysis chain🏁 Script executed: #!/bin/bash
# Get commit SHAs for the action versions used in the workflow
echo "actions/checkout@v4:"
gh api repos/actions/checkout/git/ref/tags/v4 --jq '.object.sha'
echo "actions/setup-node@v4:"
gh api repos/actions/setup-node/git/ref/tags/v4 --jq '.object.sha'
echo "actions/upload-pages-artifact@v3:"
gh api repos/actions/upload-pages-artifact/git/ref/tags/v3 --jq '.object.sha'
echo "actions/deploy-pages@v4:"
gh api repos/actions/deploy-pages/git/ref/tags/v4 --jq '.object.sha'Repository: vtf6259/ChatWS Length of output: 325 🏁 Script executed: #!/bin/bash
set -euo pipefail
FILE=".github/workflows/frontend-pages.yml"
echo "== File: $FILE =="
nl -ba "$FILE" | sed -n '1,120p'Repository: vtf6259/ChatWS Length of output: 168 🏁 Script executed: #!/bin/bash
set -euo pipefail
FILE=".github/workflows/frontend-pages.yml"
echo "== File: $FILE =="
# cat -n is usually available; limit output to keep it readable
cat -n "$FILE" | sed -n '1,140p'Repository: vtf6259/ChatWS Length of output: 1709 🏁 Script executed: #!/bin/bash
set -euo pipefail
FILE=".github/workflows/frontend-pages.yml"
echo "== Tail: $FILE =="
tail -n 40 "$FILE" | cat -nRepository: vtf6259/ChatWS Length of output: 1607 Pin GitHub Actions to commit SHAs for supply chain security. The workflow uses mutable tag refs:
Update each 🧰 Tools🪛 zizmor (1.25.2)[warning] 13-13: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [error] 13-13: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI Agents |
||||||||||||
| - run: corepack enable | ||||||||||||
| - uses: actions/setup-node@v4 | ||||||||||||
| with: | ||||||||||||
| node-version: "20" | ||||||||||||
| # Pick your own package manager and build script | ||||||||||||
| - run: make frontend | ||||||||||||
| - name: Upload artifact | ||||||||||||
| uses: actions/upload-pages-artifact@v3 | ||||||||||||
| with: | ||||||||||||
| path: ./frontend/dist | ||||||||||||
| # Deployment job | ||||||||||||
| deploy: | ||||||||||||
| if: "!contains(github.event.head_commit.message, '[SKIP CI]')" | ||||||||||||
| # Add a dependency to the build job | ||||||||||||
| needs: build | ||||||||||||
| # Grant GITHUB_TOKEN the permissions required to make a Pages deployment | ||||||||||||
| permissions: | ||||||||||||
| pages: write # to deploy to Pages | ||||||||||||
| id-token: write # to verify the deployment originates from an appropriate source | ||||||||||||
| # Deploy to the github_pages environment | ||||||||||||
| environment: | ||||||||||||
| name: github-pages | ||||||||||||
| url: ${{ steps.deployment.outputs.page_url }} | ||||||||||||
| # Specify runner + deployment step | ||||||||||||
| runs-on: ubuntu-latest | ||||||||||||
| steps: | ||||||||||||
| - name: Deploy to GitHub Pages | ||||||||||||
| id: deployment | ||||||||||||
| uses: actions/deploy-pages@v4 | ||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| # Users | ||
| This section is for users of ChatWS | ||
| 1. Your private key is your second password TREAT IT LIKE A PASSWORD! DO NOT SEND IT TO ANYONE! | ||
| 2. Your public key is for the server and users to send messages to you. | ||
| - Your public key __needs__ to be shared for users to send messages. | ||
| - You can get it from your private key if you lose it. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,2 +1,3 @@ | ||
| * | ||
| !.gitignore | ||
| !.gitignore | ||
| !README.md |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| # Build output(s) | ||
| The ChatWS file is the server here is a example command to run it | ||
|
vtf6259 marked this conversation as resolved.
|
||
| ```bash | ||
| ./ChatWS --port 8098 --pgppubkey dev.pub.pgp --pgpprivkey dev.priv.pgp | ||
| ``` | ||
| The dist folder is what you put on a web server for the frontend KEEP THE ChatWS FOLDER VITE CONFIGURES FOR THAT IF YOU WANT TO CHANGE IT EDIT vite.config.ts IN THE FRONTEND FOLDER AND REBUILD | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -2,4 +2,5 @@ | |
| cd frontend | ||
| npm i | ||
| npm run build | ||
| cp -R dist ../build | ||
| mkdir -p ../build/dist | ||
| cp -R dist ../build/dist/ChatWS | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,5 +1,5 @@ | ||
| < MOTD <the motd> (if there is no motd it will be *NOMOTD*) | ||
| > USER <username> | ||
| < MOTD <the motd> (if there is no motd it will be *NOMOTD*) | ||
|
Comment on lines
1
to
+2
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
# Description: Verify that App.vue sends USER before receiving MOTD
# Search for WebSocket message handling in the frontend
rg -n -C5 'USER|MOTD' frontend/src/App.vue
# Also check for any protocol documentation or comments
rg -n 'protocol|handshake' frontend/src/Repository: vtf6259/ChatWS Length of output: 525 🏁 Script executed: #!/bin/bash
set -euo pipefail
# 1) Find all frontend references to USER/MOTD (beyond App.vue snippet) and locate onmessage handlers.
rg -n --hidden --no-ignore -S 'MOTD' frontend/src
rg -n --hidden --no-ignore -S 'USER\s' frontend/src
rg -n -S 'onmessage|addEventListener\("message"|message\)' frontend/src
# 2) Check for protocol/handshake mentions in frontend again but include other files.
rg -n -S 'protocol|handshake|connectStandard|MOTD|USER\s' frontend/src
# 3) Backend verification: locate MOTD/USER handling/sending.
# Try common backend directories first by searching entire repo for these literals.
rg -n --hidden --no-ignore -S '"MOTD' .
rg -n --hidden --no-ignore -S 'MOTD\s' .
rg -n --hidden --no-ignore -S '"USER ' .
rg -n --hidden --no-ignore -S 'USER\s' .
# 4) Locate connectStandard file and show its first couple lines for exact wording.
# (If the file is named exactly connectStandard without extension, search by filename.)
fd -a -H 'connectStandard*' . | head -n 20Repository: vtf6259/ChatWS Length of output: 40 🏁 Script executed: #!/bin/bash
set -euo pipefail
# After locating connectStandard candidates, print the likely one.
# This script is tolerant: it prints contents only for paths that match connectStandard*.
paths=$(fd -a -H 'connectStandard*' . | head -n 20)
echo "$paths"
echo "----"
# Print first 30 lines of each candidate (to keep output small).
for p in $paths; do
echo "## $p"
sed -n '1,30p' "$p" | cat -n
echo
doneRepository: vtf6259/ChatWS Length of output: 570 🏁 Script executed: #!/bin/bash
set -euo pipefail
# Frontend: find where incoming messages are parsed/handled
rg -n -S '\bMOTD\b' frontend/src || true
rg -n -S 'addEventListener\("message"|onmessage|message\s*\(' frontend/src || true
rg -n -S 'split\(|startsWith\(|includes\(|switch\s*\(|case\s+"' frontend/src/App.vue frontend/src || true
echo "---- FRONTEND: likely message parsing around "MOTD" ----"
# Try to grab nearby context for any MOTD mention
rg -n -S -C5 '\bMOTD\b' frontend/src || true
# Backend: find handshake state machine / message handlers for these protocol tokens
rg -n -S '\bMOTD\b' . || true
rg -n -S '"USER ' . || true
rg -n -S '\bUSER\b' . || true
echo "---- BACKEND: likely websocket message handler code ----"
rg -n -S 'websocket|ws|upgrade|onmessage|message\s*\(|addEventListener\("message"|wss' . || trueRepository: vtf6259/ChatWS Length of output: 10111 🏁 Script executed: #!/bin/bash
set -euo pipefail
# Show backend getAuth and handshake ordering.
sed -n '1,170p' backend/server.go | cat -n
echo "---- frontend App.vue ----"
sed -n '1,120p' frontend/src/App.vue | cat -n
echo "---- message parsing helper (if exists) ----"
ls -la | sed -n '1,200p'
ls -la frontend/src | sed -n '1,200p'
if [ -f messageTypes ]; then
echo "---- messageTypes ----"
sed -n '1,80p' messageTypes | cat -n
fi
# Show js-client handshake order for additional context.
sed -n '1,120p' js-client/index.js | cat -nRepository: vtf6259/ChatWS Length of output: 13616 connectStandard handshake order conflicts with backend implementation
🤖 Prompt for AI Agents |
||
| < CHALLENGE <random text> <server public pgp key> | ||
| > AUTH <random text encrypted with server public key> | ||
| (if failed) | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| { | ||
| "recommendations": ["Vue.volar"] | ||
| } |
| Original file line number | Diff line number | Diff line change | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,42 @@ | ||||||||||||
| # ChatWS Frontend | ||||||||||||
| This is the vue frontend for ChatWS. | ||||||||||||
| Also ignore the error in tsconfig.node.json the error is false. | ||||||||||||
| The rest is from the template readme. | ||||||||||||
|
Comment on lines
+3
to
+4
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Remove blanket “ignore the error” guidance on Line 3. As written, this can normalize ignoring real TypeScript/configuration failures. Replace it with the exact diagnostic (or a tracked issue link) and a concrete workaround. Proposed doc fix-Also ignore the error in tsconfig.node.json the error is false.
-The rest is from the template readme.
+If you see a `tsconfig.node.json` diagnostic, do not ignore it by default.
+Document the exact error message and apply the corresponding fix (or link a tracked issue with context).
+The rest of this file is based on the Vue template README.📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||||||||
| ## Recommended IDE Setup | ||||||||||||
|
|
||||||||||||
| [VS Code](https://code.visualstudio.com/) + [Vue (Official)](https://marketplace.visualstudio.com/items?itemName=Vue.volar) (and disable Vetur). | ||||||||||||
|
|
||||||||||||
| ## Recommended Browser Setup | ||||||||||||
|
|
||||||||||||
| - Chromium-based browsers (Chrome, Edge, Brave, etc.): | ||||||||||||
| - [Vue.js devtools](https://chromewebstore.google.com/detail/vuejs-devtools/nhdogjmejiglipccpnnnanhbledajbpd) | ||||||||||||
| - [Turn on Custom Object Formatter in Chrome DevTools](http://bit.ly/object-formatters) | ||||||||||||
| - Firefox: | ||||||||||||
| - [Vue.js devtools](https://addons.mozilla.org/en-US/firefox/addon/vue-js-devtools/) | ||||||||||||
| - [Turn on Custom Object Formatter in Firefox DevTools](https://fxdx.dev/firefox-devtools-custom-object-formatters/) | ||||||||||||
|
|
||||||||||||
| ## Type Support for `.vue` Imports in TS | ||||||||||||
|
|
||||||||||||
| TypeScript cannot handle type information for `.vue` imports by default, so we replace the `tsc` CLI with `vue-tsc` for type checking. In editors, we need [Volar](https://marketplace.visualstudio.com/items?itemName=Vue.volar) to make the TypeScript language service aware of `.vue` types. | ||||||||||||
|
|
||||||||||||
| ## Customize configuration | ||||||||||||
|
|
||||||||||||
| See [Vite Configuration Reference](https://vite.dev/config/). | ||||||||||||
|
|
||||||||||||
| ## Project Setup | ||||||||||||
|
|
||||||||||||
| ```sh | ||||||||||||
| npm install | ||||||||||||
| ``` | ||||||||||||
|
|
||||||||||||
| ### Compile and Hot-Reload for Development | ||||||||||||
|
|
||||||||||||
| ```sh | ||||||||||||
| npm run dev | ||||||||||||
| ``` | ||||||||||||
|
|
||||||||||||
| ### Type-Check, Compile and Minify for Production | ||||||||||||
|
|
||||||||||||
| ```sh | ||||||||||||
| npm run build | ||||||||||||
| ``` | ||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| /// <reference types="vite/client" /> |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,12 +1,13 @@ | ||
| <!doctype html> | ||
| <html lang="en"> | ||
| <!DOCTYPE html> | ||
| <html lang=""> | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Set a valid document language instead of empty Line 2 uses 🤖 Prompt for AI Agents |
||
| <head> | ||
| <meta charset="UTF-8" /> | ||
| <meta name="viewport" content="width=device-width, initial-scale=1.0" /> | ||
| <title>FolderChat</title> | ||
| <meta charset="UTF-8"> | ||
| <link rel="icon" href="/favicon.ico"> | ||
| <meta name="viewport" content="width=device-width, initial-scale=1.0"> | ||
| <title>ChatWS</title> | ||
| </head> | ||
| <body> | ||
| <div id="reactDOM"></div> | ||
| <script type="module" src="/src/main.tsx"></script> | ||
| <div id="app"></div> | ||
| <script type="module" src="/src/main.ts"></script> | ||
| </body> | ||
| </html> | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Restrict permissions in build job.
The build job uses default permissions which are overly broad. Apply the principle of least privilege by explicitly setting minimal permissions.
🔒 Proposed fix
build: if: contains(github.event.head_commit.message, '[CI]') runs-on: ubuntu-latest + permissions: + contents: read steps:🧰 Tools
🪛 zizmor (1.25.2)
[warning] 9-25: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
🤖 Prompt for AI Agents