Files
KoalaSync/scripts/README.md
T
MacBook f7829bbebb security: harden server relay + documentation audit
Server Security (S-1 through S-8):
- S-1: Type-check and clamp peerId, protocolVersion, password
- S-2: Validate numeric/boolean/enum fields in relay peerData
- S-3: Construct explicit relay payload (stop spreading raw data)
- S-4: Type-check targetId and actionTimestamp in EVENT_ACK
- S-5: Restrict room IDs to [a-zA-Z0-9-] only
- S-7: Add eventCounts periodic cleanup alongside connectionCounts
- S-8: Guard version parsing against NaN bypass

Documentation (P-1, R-1 through R-6):
- P-1: Fix PRIVACY.md typo, document all in-memory data maps
- R-1/R-5: Fix stale sync-constants.bat references in shared/
- R-2: Fix stale lastTargetState ref in ARCHITECTURE.md
- R-3: Extension README title reflects cross-browser support
- R-6: Document content injection markers in scripts/README.md
2026-05-04 05:19:18 +02:00

1.8 KiB

Development Scripts

This directory contains utility scripts for the KoalaSync development workflow.

build-extension.js

The primary build tool for KoalaSync. This Node.js script automates two critical tasks:

  1. Protocol Synchronization: Copies the "Single Source of Truth" constants (shared/constants.js) and the domain blacklist (shared/blacklist.js) from the root /shared directory into the extension/shared/ directory.
  2. Content Script Injection: Injects protocol constants directly into content.js using marker-based replacement. This is necessary because content.js executes synchronously and cannot use ES module imports.
  3. Artifact Generation: Compiles the extension into browser-specific bundles for Chrome and Firefox, located in the dist/ directory.

Usage

From the repository root, run:

node scripts/build-extension.js

Why this script exists

KoalaSync uses Vanilla JS in the extension to maintain zero runtime dependencies and maximum privacy. Since we don't use a bundler (like Webpack or Vite) inside the extension, this script serves as our lightweight "pre-build" step to ensure that the protocol constants remain synchronized between the extension and the relay server.

Content Injection Markers

The build script uses marker comments in content.js to locate and replace constant blocks:

Marker Pair Injected Value Source
SHARED_EVENTS_INJECT_START / END The full EVENTS object shared/constants.js
SHARED_HEARTBEAT_INJECT_START / END HEARTBEAT_INTERVAL value shared/constants.js

⚠️ Do NOT remove or modify these marker comments in content.js. They are required for the build script to function. If the markers are missing, the build will fail with a clear error message.