🎁 Get the FREE AI Skills Starter Guide β€” Subscribe β†’
BytesAgainBytesAgain
πŸ¦€ ClawHub

Electron

by @ivangdavila

Build Electron desktop apps with secure architecture and common pitfall avoidance.

Versionv1.0.0
Downloads1,966
Stars⭐ 3
TERMINAL
clawhub install electron

πŸ“– About This Skill


name: Electron description: Build Electron desktop apps with secure architecture and common pitfall avoidance. metadata: {"clawdbot":{"emoji":"⚑","requires":{"bins":["npm"]},"os":["linux","darwin","win32"]}}

Security Non-Negotiables

  • nodeIntegration: false is mandatory β€” renderer with Node.js access means XSS = full system compromise
  • contextIsolation: true is mandatory β€” separates preload context from renderer
  • Whitelist IPC channels explicitly β€” never forward arbitrary channel names from renderer
  • Validate all IPC message content β€” renderer is untrusted, treat like external API input
  • Never use eval() or new Function() in renderer β€” defeats all security boundaries
  • Preload Script Rules

  • contextBridge.exposeInMainWorld() is the only safe bridge β€” raw ipcRenderer exposure is vulnerable
  • Clone data before passing across bridge β€” prevents prototype pollution attacks
  • Minimal API surface β€” expose specific functions, not generic send/receive
  • Architecture Traps

  • webPreferences locked after window creation β€” can't enable nodeIntegration later
  • Blocking main process freezes ALL windows β€” async everything, no sync file operations
  • Each BrowserWindow is separate renderer process β€” can't share JS variables directly
  • show: false then ready-to-show β€” prevents white flash, looks more native
  • Native Module Pain

  • Pre-built native modules won't work β€” must rebuild for Electron's specific Node version
  • electron-rebuild after every Electron upgrade β€” version mismatch = runtime crash
  • N-API modules more stable β€” survive Electron upgrades better than nan-based
  • Packaging Pitfalls

  • Dev dependencies included by default β€” production builds bloat without explicit exclusion
  • Code signing required for macOS auto-update β€” unsigned apps can't use Squirrel
  • Windows notifications require app.setAppUserModelId() β€” silent failure without it
  • ASAR isn't encryption β€” source readable with simple tools, don't rely on it for secrets
  • Platform-Specific Issues

  • CORS blocks file:// protocol β€” use custom protocol (app://) or local server
  • Windows needs NSIS or Squirrel for auto-update β€” installer format matters
  • macOS universal binary needs --universal flag β€” ships both Intel and ARM
  • Memory and Performance

  • Unclosed windows leak memory β€” call win.destroy() explicitly when done
  • Lazy load heavy modules β€” startup time directly affects perceived quality
  • backgroundThrottling: false if timers matter when minimized
  • Debugging

  • Main process: --inspect flag, connect via chrome://inspect
  • Renderer: webContents.openDevTools() or keyboard shortcut
  • electron-log for persistent logs β€” console.log vanishes on restart