Block a user
Manual pin resolves by userId only, so multi-device users pin an arbitrary device
Decoration URLs derive from an unvalidated arbitrary profile field
Pinning during a screenshare removes the PiP even when the pin is a third party
Denoise external-module contracts are untyped
any and break silently on an asset bump
Audio-output sink is never restored when the selected device becomes undefined again
Denoise worklet node ignores its
channelCount: 1 (no channelCountMode: "explicit")
Dry/wet floor sums an undelayed dry copy with the delayed denoised path (comb filtering)
Published npm version consumed by cinny has no corresponding git tag
Upstream fork is 6 minor releases behind with no cherry-picks; hotspot files have heavy upstream churn
lotusTransparent/lotusTheme provide no contrast guard for an arbitrary host background
In-call avatar decoration (animated APNG) ignores prefers-reduced-motion, unlike the host renderer
call_state can emit up to 8 messages/second; dedupe runs after the throttle
Decoration roster and spotlight pin are lost on an EC handler remount and never re-pushed
Torn-down lotus actions pile up in the LazyEventEmitter backlog and replay stale
Spotlight pin can never be cleared once set
Each soundboard clip creates a new AudioContext, against a per-document limit of ~6
Incoming
io.lotus.* toWidget actions are accepted from any origin
Screenshare bitrate cap is applied per simulcast layer, so the aggregate can be N× the cap
Soundboard clips are published to peers even while the local mic is muted
Sending
null does not clear a quality cap, contrary to the host contract