Block a user
CI: ESLint runs without
--max-warnings, so new react-hooks/exhaustive-deps warnings never surface
CI: built output is never loaded — add a
vite preview boot check after npm run build
CI: bundle size is reported but has no budget — regressions pass green
Room Activity Log can misclassify membership transitions for back-paginated (older) events
Room Insights ("stats") panel freezes at open-time data and never reflects new activity
Package.json engines version misalignment with README and CI
CI:
npm audit is informational — high-severity advisories should fail pull requests
Cross-tab session sync is absent on the auth pages
"Deny" on a pending knock request has no error handling and can be shown to users who lack kick power
Room-history export shows outdated content and a garbled duplicate line for edited messages
Room-history export gives no indication that a message was media/an attachment
Room invite link / QR code always uses the local homeserver as the only via-server, ignoring the shared via-server resolver
Quick Reply's failure is swallowed with no user-visible feedback
LotusToastContainer toast auto-dismiss timer is not reset in a fixed slot, so a fast burst can hide a toast before it's read
getNotificationType/main-timeline gate re-derives push rules on every event without memoization
notificationclick always focuses the first matching window client, not the one most relevant to the notification
useTauriCallPower never releases the native keep-awake state on unmount