mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-02 13:39:41 +02:00
- BLOCKER (privacy): the CJK diagnostic trace logged typed CONTENT — _esc(e.key) per keystroke, up to 24 chars of textarea value on focus/blur/compstart/ compend/input, and the flushed text — mirrored into _crashDiag, which persists to localStorage and beacons to POST /api/crash-diag. Traces are now content-free: key CLASS via _kdesc (any single code point → 'printable', named keys pass through), value lengths + phantom presence via _vdesc (len=N[+ph]), and 'flush send len=N'. _esc removed. - MAJOR: the onData self-heal refocused the CJK field whenever gated data arrived with focus elsewhere — but onData also fires for xterm's SELF-GENERATED query replies (DA/DSR/CPR/OSC during Ink redraws), so it stole focus from rename/search/settings inputs while output streamed. Now requires document.activeElement === this.terminal.textarea (genuine typed input) and bails when shouldSuppressTerminalQueryResponse(data) matches. - MAJOR: the pointerdown blur→setTimeout(focus,0) wedged-IME recovery ran on ALL platforms; on iOS tapping the focused empty field is normal and the async refocus is outside the user-gesture stack. The listener is now only registered when /Android/i.test(navigator.userAgent). - tests: trace-privacy test (no typed character or textarea value ever appears in the trace; lengths/key classes still recorded), iOS harness asserts the pointerdown recovery never cycles, self-heal source guard asserts both new conditions; vm harness gained a ua option (navigator injected, Android UA default so the existing wedged-IME test still exercises the recovery). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>