Code Monkey home page Code Monkey logo

devbook-palette's People

Contributors

mlejva avatar valentatomas avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar

devbook-palette's Issues

RCE/XSS vulnerability with Mozilla 'interactive-examples' iFrames.

Hello, I was able to execute code that would interact with the electron instance via the Mozilla interactive examples iFrames. You can watch an example of this vulnerability on YouTube. This is a common vulnerability involved with Electrons "nodeIntegration" property being set to true. You can read more about the vulnerability on Doyensec's Blog.

How to reproduce

The Mozilla interactive examples run inside an iFrame and allows you to modify and execute JavaScript. I was able to execute code inside the iFrame that would set the parent page of iFrame to a website of my choice. On the website of my choice I wrote JavaScript that would interact with the NodeJS process and execute programs require('child_process').exec().

Possible ways to fix the vulnerability.

  1. Try running iFrames with the sandbox attribute

Configurable shortcuts

Hello,
it would be nice to have option to configure more shortcuts than just shortcut to display search window. I'm using i3 and I use Ctrl, win key and alt to switch between workspaces on different monitors, so alt + 1 or alt + 2, does not work for me to switch between docs and Stack Overflow. Cpprefernce in docs would be nice to have too.

MDN codeblock takes over the keyboard navigation

Hello there and congratulations for this app ๐ŸŽ‰ I really find it useful and let me speed up my searches, something that as developers we do hundreds of time per day ๐Ÿ˜‚

Just wanted to let you know about an issue that I am facing, didn't find a better way than write here.

Basically, if you use the 'documentation' part of the app and you look for something on MDN, the example that most of the time is put on the top of the reference takes control over the keyboard navigation that is in place. This is a bit annoying because then I have to take my mouse to scroll ๐Ÿ˜Š

mdn-takes-over

I see that the app is built with React and Electron, I do have experience with the first and always wanted to get some for the latter. So I'll try to have a look at it in my spare time, that is not that much tbh.

Thank you once more for this!

Why deprecated?

This was such a good docs app. I was using it as an alternative to Dash on windows.

May I ask why did you make the decision to kill the project?

Is this project dead?

I really loved the simplicity and design of this app. Are you deciding on killing it or is it still going to receive updates and new doc additions?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.