Call hotkeys: rebind has no denylist, modifiers ignored, Space swallowed on buttons, duplicate bindings allowed #23
Closed
opened 2026-09-12 01:50:56 -04:00 by jared
·
0 comments
No Branch/Tag Specified
lotus
update-packages
sw-fix
read-me-update
image-path-changes
dm-calls
fix-2469
renovate/element-hq-element-call-embedded-0.x
renovate/npm-i18next-http-backend-vulnerability
renovate/npm-vite-vulnerability
dev
docs-update
more-theme
fix-257
imporve-thread-reply
revert-2402-improve-menu-congestion
mxidColor-toggle
update-sw-main-msg
v4.11.1
v4.10.5
v4.10.4
v4.10.3
v4.10.2
v4.10.1
v4.10.0
v4.9.1
v4.9.0
v4.8.1
v4.8.0
v4.7.1
v4.7.0
v4.6.0
v4.5.1
v4.5.0
v4.4.0
v4.3.2
v4.3.0
v4.2.3
v4.2.2
v4.2.1
v4.2.0
v4.1.0
v4.0.3
v4.0.0
v3.2.0
v3.1.0
v3.0.0
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.8.2
v1.8.1
v1.8.0
v1.7.0
v1.6.1
v1.6.0
v1.5.1
v1.5.0
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Labels
Clear labels
a11y
area: appearance
area: auth-session
area: build-ci
area: calls
area: desktop
area: media
area: messaging
area: mobile
area: moderation
area: navigation
area: notifications
area: settings
area: threads
bug
dependencies
docs
duplicate
enhancement
help wanted
invalid
needs-human-review
performance
planning
priority: critical
priority: high
priority: low
priority: medium
qa
question
research
security
tech-debt
ux
wontfix
Accessibility: keyboard, screen reader, contrast, motion
Client area: appearance
Client area: auth-session
Client area: build-ci
Client area: calls
Client area: desktop
Client area: media
Client area: messaging
Client area: mobile
Client area: moderation
Client area: navigation
Client area: notifications
Client area: settings
Client area: threads
Something is not working
Third-party package versions and advisories
README / LOTUS_* docs wrong or missing
This issue or pull request already exists
New feature
Need some help
Something is wrong
Re-render storms, leaks, heavy work on hot paths
Data loss, security hole, or crash on a main path
Broken feature or serious usability problem
Minor issue or polish
Wrong behaviour in an edge case or notable degradation
Manual QA: shipped, needs a human in a real environment
More information is needed
XSS, unsafe URLs, data leaks, auth/session
Code health, dead code, fragile patterns
Usability or visual inconsistency
This won't be fixed
Milestone
No items
No Milestone
Audit 2026-09 · High
Projects
Clear projects
No projects
Notifications
Due Date
Dependencies
No dependencies set.
Reference: LotusGuild/cinny#23
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: high · Type: a11y · Confidence: high
Location:
src/app/features/settings/general/General.tsx:1477-1500(useKeyBind— only excludesEscape); runtime consumersrc/app/features/call/CallControls.tsx:172-188(onKeyDowncallse.preventDefault()unconditionally whenevere.code === pttKeyand the focus target isn't editable)src/app/features/call/CallControls.tsx:172-195,256-262,src/app/features/settings/general/General.tsx:1477-1500Problem
useKeyBindcaptures literally anyKeyboardEvent.codefrom Settings → General → Calls and stores it verbatim aspttKey/deafenKey, denylisting onlyEscape. The runtime PTT listener inCallControls.tsxthen callspreventDefault()on every matching keydown outside an editable field. If a keyboard-only user (deliberately, or by mis-click while trying to rebind) sets the PTT or deafen key toTab,ArrowUp/Down/Left/Right,Spaceoutside a field, orEnter, that key stops moving focus / activating controls anywhere in the app for the duration of the call — a full keyboard trap that can only be escaped by ending the call or reloading. There is also no check thatpttKey !== deafenKey, so a user can silently bind both actions to the same key.Second mechanism (related finding): both key handlers match on
e.codeonly — no check ofctrlKey/metaKey/altKey/shiftKey. With the defaultdeafenKey: 'KeyM',Ctrl+M,Alt+Mand macOSCmd+M(minimise window) all toggle deafen and getpreventDefault()ed. With the defaultpttKey: 'Space', PTTpreventDefault()s every Space press outside an input — which is how keyboard users activate<button>s, so during a call in PTT mode Space no longer activates the mic/deafen/hangup buttons or scrolls the page.useKeyBindalso accepts any key without validation or conflict detection, so PTT and deafen can be bound to the same key.How to trigger
Settings → General → Calls → click the Push-to-talk key field → press
Tab. Join/start a call; pressing Tab anywhere non-editable in the app now toggles the mic and is swallowed instead of moving focus.Also: join a call with PTT on, Tab to the End button, press Space — nothing happens. Or press Cmd+M / Ctrl+M during any call.
Suggested fix
Denylist
Tab,ShiftLeft/Right(already a modifier concern), arrow keys, and other navigation-critical codes inuseKeyBind, and warn/reject when the new binding equals the other call-shortcut key.Also: ignore events with any modifier held in both handlers; only
preventDefault()the PTT key when the event target is not an interactive control; reject duplicate/reserved bindings inuseKeyBind.Filed from the September 2026 client audit (branch
lotus@4bea4895).