Repository navigation
feature: vscode debug config support - #446
Conversation
| "request": "attach", | ||
| "port": 8315, | ||
| "webRoot": "${workspaceFolder}/src", | ||
| "timeout": 100000, |
There was a problem hiding this comment.
15s (15000) or 30s (30000) is a good timeout.
| "type": "node", | ||
| "request": "launch", | ||
| "name": "Marktext: Main", | ||
| "program": "${workspaceFolder}/.electron-vue/dev-runner.js" |
There was a problem hiding this comment.
I did not tested this on Windows, but do we not have to set the windows runtime executable?
"program": "${workspaceFolder}/.electron-vue/dev-runner.js",
"windows": {
"runtimeExecutable": "${workspaceRoot}/node_modules/.bin/electron.cmd"
}
There was a problem hiding this comment.
I don't think we need windows runtimeExecutable config, because we don't run electron directly, we run electro-vue that wrap this.
There was a problem hiding this comment.
@enyaxu I tested it on Windows and you don't need the windows attribute. It didn't work with the attribute at all.
| } | ||
|
|
||
| // Enable vscode chrome extension debugger connection | ||
| if (process.env.NODE_ENV !== 'production' || process.env.NODE_ENV === 'development') { |
There was a problem hiding this comment.
Personally I would check for process.env.NODE_ENV === 'development' only. First of all because of security reasons and it's redundant.
|
@joc OK, I’ll fixed later.
|
|
@Jocs Why |
@Jocs @enyaxu I think it's the same problem as electron-userland/electron-builder#3204. |
|
Is there any error message ouputed by vscode?
|
No. I guess the problem is that we don't run electron directly as you already said. If you remove the |
|
thank you all! |
* chore(deps): bump dompurify to ^3.4.9 across desktop/muya/muyajs Updates the HTML sanitizer from ^3.4.3/^3.4.5 to ^3.4.9 (resolves to 3.4.11), deduping the two installed versions (3.4.3 + 3.4.7) into one. Clears Dependabot alerts #443/#451/#452/#453/#454/#455/#456. MarkText calls DOMPurify.sanitize() only with string input and RETURN_TRUSTED_TYPE: false (no IN_PLACE/RETURN_DOM/addHook/ SAFE_FOR_TEMPLATES), so none of these CVEs were reachable; the bump is defense-in-depth for the editor's HTML sanitization path. DOMPurify 3.4.8+ hardened cross-realm namespace validation, which the happy-dom test environment does not satisfy: under happy-dom it strips every element, even default-allowed tags like <p>/<h1>. Real Chromium/Electron is unaffected (verified: jsdom, which matches production DOM behavior, sanitizes correctly). Move the five DOMPurify-dependent muya specs to the jsdom environment and declare jsdom as a muya devDependency. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * chore(deps): bump happy-dom to ^20.8.9 in muya Updates muya's vitest DOM test environment from ^15.11.7 to ^20.8.9 (resolves to 20.10.6). Clears Dependabot alerts #426/#427/#428/#434/#437/#438 (2 critical "VM context escape / RCE", 4 high). happy-dom is a devDependency used only as the unit-test DOM; it is never bundled into the shipped app, and the muya suites run trusted fixtures, so these CVEs were not reachable. The bump keeps the test toolchain current and clears the critical badges. The full muya unit suite (143 files) passes on 20.x — the DOMPurify-dependent specs already moved to jsdom in the previous commit. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * chore(deps): update vite to patched 7.3.5 / 8.0.16 Bumps vite to the patched releases across the workspace (desktop ^7.3.5, muya + muya-e2e ^8.0.16), updating the declared floors so installs can't regress below the fix. Clears Dependabot alerts #441/#442/#447/#448 (server.fs.deny bypass + launch-editor NTLMv2 disclosure — both Windows dev-server only; vite is build tooling, never shipped to users). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * chore(deps): pin transitive deps to patched versions via pnpm overrides Adds range-scoped pnpm.overrides to force patched releases of the transitive dependencies Dependabot flagged, while leaving unaffected older majors in place (undici 6.x, esbuild 0.25.x, js-yaml 3.x): form-data 4.0.5 -> 4.0.6 (#450 CRLF injection) tmp 0.2.5 -> 0.2.6 (#411 path traversal) tar 7.5.15 -> 7.5.16 (#449 PAX file smuggling) ws 8.20.1 -> 8.21.0 (#444 memory-exhaustion DoS) undici 7.24/7.25 -> 7.28.0 (#457 SOCKS5 TLS bypass; keeps 6.25.0) esbuild 0.27/0.28.0-> 0.28.1 (#439 dev-server file read; keeps 0.25.x) @babel/core 7.29.0 -> 7.29.6 (#445 sourceMappingURL file read) js-yaml 4.1.1 -> 4.2.0 (#446 merge-key DoS; keeps 3.14.2) All are build/test/website tooling reachable only on developer/CI machines, never bundled into the shipped app. js-yaml 3.14.2 remains via the website's gray-matter (no 3.x patch exists); it parses only trusted first-party content, so #446 is not exploitable there and will be dismissed on GitHub. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
* feature: vscode debug config support * improment vscode debug settings
Description
Add vscode debugger config, you need install Debugger for chrome