fix: 修复代码审计发现的全部 37 个问题

严重 Bug(8 个):
- B-01: isClosing 永不重置 — WINDOW_CANCEL_CLOSE 现在正确重置状态并清除超时
- B-02: replaceAll 算法完全错误 — 改为从后向前逐个替换(SearchBar + useFileWatch)
- B-03: Preview 用 setInterval 轮询 — 改为响应式订阅 activeTab.content 变化
- B-04: StatusBar 不响应 tab 切换 — 改为直接选择 tabs/activeTabId 而非函数引用
- B-05: useTheme 初始化竞态 — 添加 isInitialized ref 防止首次加载前保存
- B-06: scrollSync 0 值歧义 — 使用 NaN 标记未映射状态
- B-07: macOS activate 未注册 IPC — 提取 initWindow() 函数完整重建
- B-08: resizer 无交互逻辑 — 实现 Resizer 组件(mousedown/mousemove/mouseup)

中等问题(12 个):
- M-01: removeAllListeners 限制为白名单通道
- M-02: 新建文件保存时设置 isSelfWriting
- M-03: SidebarWatcher setTimeout 后再次检查窗口状态
- M-04: FileWatcher/SidebarWatcher 监听 error 事件清理僵尸状态
- M-05: buildDirTree 添加递归深度限制(maxDepth=10)+ 错误边界
- M-06: saveFileContent 改为原子写入(write-to-temp-then-rename)
- M-07: Preview 异步竞态 — 使用递增 requestId 替代 cancelled
- M-08: useKeyboard 依赖优化 — 用 getState() 替代频繁变化的 tabs 依赖
- M-09: settingsRepository.save() 改为 Dexie put 直接合并
- M-10: useSettings 返回函数用 useCallback 稳定引用
- M-11: App.tsx 事件注册添加 cleanup 清理 + ref 保持最新回调
- M-12: ipc-channels.ts 类型签名统一

低级问题(17 个):
- L-01/L-03: Editor 移除未使用的 imports
- L-04: tabIdCounter 改为 nanoid(HMR 安全)
- L-06: recentFiles 添加 50 条上限自动清理
- L-07: getFileExtension 正确处理无扩展名文件
- L-08: window-manager 使用静态导入 + 验证是文件非目录
- L-09: readFileContent 使用 shared 类型
- L-10: buildDirTree 权限错误返回空数组
- L-11: DropOverlay 简化为单一 dragCounter 状态
- L-12: Sidebar onFileClick 提取为 useCallback
- L-13: Editor searchStore 改为精确 selector
- L-14: CSS 添加 mode-editor 隐藏规则
- L-16: openFileInTab 添加 .catch() 异常处理

TypeScript 检查零错误,构建成功。
This commit is contained in:
thzxx
2026-05-27 20:52:49 +08:00
parent 5e1c89d280
commit 959fde70e3
23 changed files with 279 additions and 239 deletions
+24 -19
View File
@@ -19,12 +19,14 @@ const sidebarWatcher = new SidebarWatcher(() => mainWindow)
function openFileInTab(filePath: string): void {
if (!mainWindow || mainWindow.isDestroyed()) return
readFileContent(filePath).then(result => {
if (result.success) {
if (result.success && mainWindow && !mainWindow.isDestroyed()) {
state.activeFilePath = filePath
fileWatcher.start(filePath)
mainWindow!.setTitle(`MarkLite - ${filePath.split(/[/\\]/).pop()}`)
mainWindow!.webContents.send('file:openInTab', { filePath, content: result.content })
mainWindow.setTitle(`MarkLite - ${filePath.split(/[/\\]/).pop()}`)
mainWindow.webContents.send('file:openInTab', { filePath, content: result.content })
}
}).catch((err) => {
console.error('openFileInTab failed:', err)
})
}
@@ -70,24 +72,12 @@ if (!lockOk) {
})
}
app.whenReady().then(() => {
app.on('open-file', (event, filePath) => {
event.preventDefault()
if (mainWindow && !mainWindow.isDestroyed() && mainWindow.webContents.isLoading()) {
state.pendingFilePath = filePath
} else if (mainWindow && !mainWindow.isDestroyed()) {
openFileInTab(filePath)
} else {
state.pendingFilePath = filePath
}
})
// B-07: 完整的窗口初始化逻辑(activate 复用)
function initWindow(): void {
mainWindow = createWindow()
// 注册 IPC 处理器
registerIpcHandlers(() => mainWindow, fileWatcher, sidebarWatcher, state)
// 加载渲染进程页面
if (process.env.ELECTRON_RENDERER_URL) {
mainWindow.loadURL(process.env.ELECTRON_RENDERER_URL)
} else {
@@ -108,6 +98,21 @@ if (!lockOk) {
sidebarWatcher.stop()
mainWindow = null
})
}
app.whenReady().then(() => {
app.on('open-file', (event, filePath) => {
event.preventDefault()
if (mainWindow && !mainWindow.isDestroyed() && mainWindow.webContents.isLoading()) {
state.pendingFilePath = filePath
} else if (mainWindow && !mainWindow.isDestroyed()) {
openFileInTab(filePath)
} else {
state.pendingFilePath = filePath
}
})
initWindow()
// 命令行文件
const cmdFile = getFilePathFromArgs(process.argv)
@@ -120,10 +125,10 @@ if (!lockOk) {
if (process.platform !== 'darwin') app.quit()
})
// B-07: macOS activate 完整重建窗口
app.on('activate', () => {
if (BrowserWindow.getAllWindows().length === 0) {
mainWindow = createWindow()
setupCloseHandler()
initWindow()
}
})
}