refactor: complete compatibility-preserving frontend v2 - #10
Merged
Conversation
Rework client, daemon, desktop, privacy, storage, routing, accessibility, native packaging, CI, and public documentation while retaining the supported operation API and project data model. Retire only the insecure browser-exposed bearer-token path and preserve trusted compatibility adapters.
Accept ordinary Windows path aliases without relaxing junction defenses, replace uncontrolled regex parsing with linear scans, and make HTML escaping single-pass so the full Windows and CodeQL gates can run cleanly.
Preserve component-level junction rejection while accepting canonical path aliases, and generate documentation heading IDs with an ASCII-only linear parser.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ZharwingMemoryClient/AimemClientfacade, trusted AIMEM environment aliases, and legacy personal-preview CLI behaviorVITE_*bearer-token pathValidation
Compatibility and release notes
This is a codebase refactor, not a project-data or operation-API migration. Trusted compatibility adapters remain available. The browser-side bearer-token fallback is intentionally unavailable because embedding a reusable secret in frontend bytes is unsafe.
The website should be deployed only after all PR checks pass and this PR is merged to a clean
main.