Skip to content

docs: 2026-08-18 frontend audit (Electron / Next.js) - #7

Closed
wu1w wants to merge 1 commit into
mainfrom
cursor/frontend-audit-2026-08-18-ca60
Closed

docs: 2026-08-18 frontend audit (Electron / Next.js)#7
wu1w wants to merge 1 commit into
mainfrom
cursor/frontend-audit-2026-08-18-ca60

Conversation

@wu1w

@wu1w wu1w commented Aug 18, 2026

Copy link
Copy Markdown
Owner

Read-only audit of the Electron / Next.js frontend at main SHA cfccbbb9ed3a8a489097aa3a6e42ee0049a66e43.

This PR contains only docs/audit-frontend-2026-08-18.md. No product, CI, or ESLint files were changed.

What’s in the report

  • Findings ranked critical / high / medium / low with file paths and suggested fixes
  • Preload / IPC: contextIsolation, sandbox, renderer-invokable channels
  • Chat stop/end vs mainstream agents (partial replies, in-flight tools, composer overflow)
  • Session delete + draft restore: UI/backend desync cases
  • XSS / open redirect / untrusted markdown and tool HTML
  • frontend-ci red on cfccbbb and 698ebe5: ESLint react-hooks/refs error in frontend/hooks/useColResize.ts:23 (widthRef.current = width during render). Last green main run was 4133b5f.
  • Knowledge list still silently capped at 500; ModelSettingsPanel props look consistent on this SHA
  • “What looks solid” section

This PR does not implement the suggested fixes.

Open in Web Open in Cursor 

Read-only review of preload/IPC, chat stop UX, session delete/drafts,
XSS surfaces, knowledge paging, and the frontend-ci red on cfccbbb.

Co-authored-by: wu1w <wu1w@users.noreply.github.com>
@wu1w wu1w closed this Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants