Commit Graph
28 Commits
Author SHA1 Message Date
google-labs-jules[bot]andAEmotionStudio 85a0a6fa33 perf: optimize node rendering by caching visible nodes
Reduced redundant iterations over `app.graph._nodes` in `OffscreenRenderer`.
Implemented `getVisibleNodes` to calculate visible nodes once per frame (O(N)) and reused this list for text, title, and image preview rendering passes (O(M)).
This improves performance for large graphs by replacing multiple O(N) traversals with a single O(N) traversal followed by O(M) traversals where M << N.

Added unit tests in `tests/unit/OffscreenRenderer.test.ts` to verify node visibility culling logic.
Updated `.jules/bolt.md` with performance learnings.

Co-authored-by: AEmotionStudio <163354043+AEmotionStudio@users.noreply.github.com>
2026-02-09 16:18:12 +00:00
google-labs-jules[bot] f6a9e5faa7 security(ui): eliminate XSS vector by replacing isHtml bypass with strict specialType
Removed the `isHtml` flag support in `UIManager`, which allowed bypassing HTML escaping.
Replaced it with a `specialType` mechanism (specifically 'focus-node') to render trusted
HTML structures internally while ensuring dynamic values are always escaped.
Updated `Security.test.ts` to verify the fix and prevent regression.

Fixes: Potential XSS vulnerability via unchecked HTML injection.
2026-01-19 05:05:28 +00:00
AEmotionStudio 8bdfbedf46 feat: add new themes and enhance popout viewer interaction
- Added 'Obsidian', 'Obsidian Dark', and 'Milk White' themes to Info Panel and PopOut viewer.
- Improved theme detection in 'StateManager' to support new themes.
- Implemented button widget support in PopOut viewer with 'button-click' event handling.
- Enhanced widget options handling in 'PopOutManager' for combo widgets.
- Updated dropdown accessibility tests.
2026-01-18 11:02:06 -08:00
google-labs-jules[bot] dd4e34df6f fix(security): prevent XSS in WebGL error toast by using DOM API
- Refactor `showWebGLError` to use `document.createElement` instead of `innerHTML`
- Replace inline `onclick` handler with `addEventListener` for CSP compliance
- Add unit test to verify XSS prevention and button functionality
2026-01-18 04:50:44 +00:00
google-labs-jules[bot] 717b823d20 fix(ui): prevent race conditions and focus hijacking in dropdown 2026-01-17 07:42:29 +00:00
google-labs-jules[bot] 3ab3e4a02e fix(ui): fix event listener leak on dropdown re-open 2026-01-17 06:31:06 +00:00
google-labs-jules[bot] 2786436e4a fix(ui): restrict keyboard handler to focused dropdown 2026-01-17 05:56:45 +00:00
google-labs-jules[bot] d8ee89ca02 fix(ui): prevent event listener leak in dropdown selection 2026-01-17 05:25:38 +00:00
google-labs-jules[bot] 55c7114fa0 feat(ui): add keyboard navigation and ARIA to node selector dropdown 2026-01-17 04:43:13 +00:00
Æmotion Studio 40c70bdba4 Merge pull request #21 from AEmotionStudio/bolt/optimize-render-overlays-1998194206652878890
⚡ Bolt: Optimize rendering loop by hoisting getBoundingClientRect
2026-01-15 22:28:43 -08:00
Æmotion Studio 9092cfd0ac Merge pull request #20 from AEmotionStudio/sentinel-validation-fix-2381716828487744723
🛡️ Sentinel: [MEDIUM] Add input validation for info panel settings
2026-01-15 22:28:27 -08:00
google-labs-jules[bot] 6d5791eb3c perf: hoist getBoundingClientRect out of render loop
- Moves `litegraphCanvas.getBoundingClientRect()` call outside the widget loop in `renderHtmlOverlays`.
- Reuses the `dpr` calculated at the top level.
- Adds regression test `tests/unit/MagnifyGlassRenderOptim.test.ts`.

Improves rendering performance by reducing forced reflows during magnification.
2026-01-16 04:57:01 +00:00
google-labs-jules[bot] fe771ef87e feat(security): implement strict input validation for InfoPanel settings
Add validation for all InfoPanel settings loaded in StateManager to prevent
injection of invalid values (e.g. out-of-bounds numbers, invalid colors).
This mitigates risks of degraded stability or potential injection via
manipulated settings storage.

- Add validateNumber, validateColor, validateStringOption helpers
- Update StateManager.loadSettings to validate all keys
- Add unit tests for validation logic
2026-01-16 04:45:01 +00:00
google-labs-jules[bot] d7f6b99051 feat(a11y): associate labels with form controls in sidebar
- Export form creation helpers for testing
- Add unique ID generation for sliders, selects, and color pickers
- Associate labels with inputs using `htmlFor`
- Add unit tests to verify accessibility attributes
2026-01-16 04:37:17 +00:00
Æmotion Studio 6ce27c62a3 Merge pull request #17 from AEmotionStudio/palette/accessible-toggles-10339516210084959098
feat: make sidebar toggle switches accessible
2026-01-14 21:41:39 -08:00
google-labs-jules[bot] bc872f58f6 fix: ensure keyboard events stop propagation in toggles
- Pass event object to handleToggle from keydown listener
- Ensure stopPropagation() is called for keyboard events
- Maintain consistency between mouse and keyboard interaction behavior
2026-01-15 05:33:39 +00:00
google-labs-jules[bot] b73705a106 fix: synchronize aria-checked state in settings panel
- Update Require Alt Key toggle sync to include aria-checked attribute
- Update Reset Position button to clear aria-checked on Follow Cursor toggle
- Add regression tests for sidebar interaction state synchronization
2026-01-15 05:19:31 +00:00
google-labs-jules[bot] 1109ca9f06 feat: make sidebar toggle switches accessible
- Add `role="switch"` and `aria-checked` to toggle elements
- Add `tabIndex="0"` for keyboard focus
- Add keyboard event listeners for Enter and Space keys
- Add `aria-labelledby` to associate toggles with their labels
- Enable toggling by clicking the label text
- Export `createToggle` for testing
- Add unit tests for accessibility and interaction logic
2026-01-15 04:59:19 +00:00
google-labs-jules[bot] f928f848e5 feat(security): add input validation for configuration settings
- Implement `validateNumber` and `validateColor` in `ConfigManager`.
- Clamp numeric settings (zoom, size, borders) to safe ranges.
- Validate color settings against hex regex.
- Update `ConfigManager` unit tests to cover validation logic.

This enhancement prevents invalid configuration states and potential stability issues caused by malformed or extreme setting values.
2026-01-15 04:56:22 +00:00
google-labs-jules[bot] 5e5c49a99c fix(security): handle non-string inputs in escapeHtml to prevent crashes
- Update `escapeHtml` to explicitly coerce input to string
- Handle null/undefined values safely
- Add unit tests for non-string input types (numbers, booleans, objects)
2026-01-14 05:56:33 +00:00
google-labs-jules[bot] 4cf3e9f50b fix(security): allow trusted html in info panel while sanitizing user input
- Add `isHtml` flag to `Focus Node` button to bypass escaping
- Update `UIManager` to check for `isHtml` flag before formatting/escaping
- Add regression tests for trusted HTML rendering logic
2026-01-14 04:56:25 +00:00
google-labs-jules[bot] 416090376e feat(security): sanitize user input in info panel to prevent XSS
- Add `escapeHtml` utility to `src/shared/utils.ts`
- Sanitize rendered values in `src/info-panel/ValueFormatter.ts`
- Sanitize node titles, types, and labels in `src/info-panel/UIManager.ts`
- Add unit tests verifying XSS prevention in `tests/unit/Security.test.ts`
2026-01-14 04:38:38 +00:00
AEmotionStudio ac8bda31ac feat: Introduce NodeSelector for fetching, sorting, and searching ComfyUI nodes. 2026-01-05 15:50:52 -08:00
AEmotionStudio 3804d41ef1 feat: Add ability to hide magnify glass preview and refine info panel visibility based on glass state. 2026-01-05 12:19:46 -08:00
AEmotionStudio 69926fca2b feat: Implement offscreen rendering and remove debug mode setting from defaults. 2026-01-03 17:33:55 -08:00
AEmotionStudio 638fa44442 feat: Introduce shared logger and unit tests, and update magnify glass and info panel components. 2026-01-01 14:46:56 -08:00
AEmotionStudio 9e8b981bdc refactor: Overhaul testing setup with Vitest, add new unit tests for state and config managers, and update WebGLRenderer. 2025-12-31 20:32:02 -08:00
AEmotionStudio 0b49471ad8 refactor: migrate magnify glass and info panel to TypeScript with Vite and Vue 2025-12-31 17:53:29 -08:00