feat: cap peer device names at 64 chars on every inbound seam (v4.8.8) Local names were already bounded (setDeviceName); peer-supplied names had no bound, letting a hostile peer grow chrome.storage and blow out fixed-width UI. Add MAX_DEVICE_NAME_CHARS/capDeviceName in shared/sync-limits.ts and apply at device-manifest normaliseEntry, paired-devices upsertPairedDevice, pending-vouched addPendingVouchedDevice, and sync-alerts recordSyncAlerts. Cap rather than reject so old peers with long-but-honest names keep syncing. Tests: +7 (paired-devices, device-manifest, new pending-vouched-devices and sync-alerts specs). Also tighten SA01 to assert zero horizontal overflow on the steady-state popup (the earlier ~7px reading was a mid-open tab artifact).

dev · 2 weeks ago · 2026-08-07 · 5.8 MB

$ koh steal kepr.uk/peach-browser@847806bd2188
·
← c387e8a41f26 2a311f0d3062 →
⇓ download .face