Files
KoalaSync/docs
KoalaDev cb84709358 fix(popup): render lobby peer names as text, not markup
Peer usernames are remote-controlled and were interpolated into an
innerHTML string in updateLobbyUI. The server only truncates them to 30
chars, so a peer could inject markup into everyone else's popup: enough
to load a remote image (leaking viewer IPs) or spoof readiness badges.
Inline handlers were already blocked by the MV3 default CSP.

Build the peer items with the DOM API, matching the pattern the sibling
peer list already uses.

Add the two checks that would have caught this before upload:
- eslint no-unsanitized, which reproduces the AMO warning at lint time
- addons-linter on the built XPI in verify-release, with
  --warnings-as-errors since it exits 0 on warnings and AMO rejects them

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 05:57:38 +02:00
..
2026-07-15 04:45:45 +02:00
2026-07-02 10:20:25 +02:00

Technical Documentation

This directory contains deep-dives into the KoalaSync protocol, architecture, roadmap, and operational guidelines.

Start Here by Role

🏗️ Core Architecture & Design

  • ARCHITECTURE.md: Overview of the communication flows, Dual Heartbeat architecture, and synchronization logic.
  • HOW_IT_WORKS.md: Step-by-step walkthrough of every user flow, from room creation to synchronized playback. Ideal for store reviewers and manual testers.
  • host-control-mode.md: Design, requirements, and edge cases of the Host Control feature.
  • AI_INIT.md: Maintainer and AI-agent onboarding: non-negotiables, workflow order, and safety checks.

📡 Protocol & Synchronization

  • PROTOCOL.md: Low-level message format and payload descriptions for the KoalaSync sync protocol.
  • SYNC_GUIDE.md: Guide on keeping protocol constants synchronized across the workspace.

📋 Compatibility, Roadmap & Contribution

  • TESTED_SERVICES.md: Status of compatibility with major streaming services and contribution guidelines for testing new platforms.
  • KNOWN_LIMITATIONS.md: Threat model and accepted design limitations (NOFIX entries) for security audits.
  • PRIVACY.md: Privacy model and data-handling policy for users, reviewers, and contributors.
  • ROADMAP.md: Planned features, backlog items, and rejected proposals.
  • TRANSLATION.md: Guide for native speakers to contribute and audit dynamic extension/website translations.

🚀 DevOps & Releases

  • devops.md: Guide on the automated tag-based release pipeline.
  • CHANGELOG.md: Detailed history of releases and changes.

For high-level project information and developer setup instructions, refer to the root README.md.