JERMChart 发布:面向信托架构图表的离线开源应用
Introducing JERMChart
JERMChart v1.0.0 已发布,这是一款用于绘制信托组织、子公司及董事结构的图表应用,支持导出 PPTX、Excel、PDF 和高分辨率图片。应用完全离线运行,仅白名单 Google API,Vision OCR 采用 BYOK 模式,用户自备密钥,项目已开源。
A backstory
A few weeks ago, my wife discovered that I was working on random projects of my own. These days, other than working on SDPFuzz2 (a rework of my NUS capstone project), I am building random stuffs such as Travel Planner (a web app that helps budgeting travel plans) and Librarian (a RAG pipeline for knowledge management). So she asked me if I could build a charting application for her work. Of course, I gladly oblige (if not the crouch would be happy to see me....).
The Design
The charting software is a straightforward project. It is to map out the structure of a Trust, which includes the Trust organisation, its subsidiary organisations, and the directors. The chart should be exported into PPTX, Excel, PDF or high resolution images depending on the user's need.
I looked at the UX requirements, and eventually decided to add in a few more features:
- Chart import through Excel
- Chart creation through Vision OCR of hand drawn diagrams.
The major issue
If it is not already obvious, this app may be used by people who managed high net worth clients. This means that the application, other future features and enhancements will need to be designed with security as top priority.
Most application design should already factor in security. Incidents like the Panama Paper leak make security even more important for applications like this, where a single leak, regardless of sources, would bring upon reputation damages to the organization managing the trusts.
Thankfully, my security training can finally be put into practice, though not all. For the initial setup, I was merely following standard security practice. Some of my setups include:
- Full test coverages with edge cases. Standard TDD stuffs, not really security related. But I do have network isolation tests to ensure no third party dependencies are sending any traffic out. Not very easy though, as I am still working on this.
- Fully offline application. The application will be fully offline where the only whitelisted traffic is Google API for Gen-AI services. This is essential since I will be using Gemini for my Vision OCR.
- Isolated sandbox build to ensure that the application runs on sandbox mode. Honestly, I do not know how legit is this as this is my first time trying out Electron. Hopefully with future testings, it can be established that this achieves what it intends to do.
- For the only network traffic going out of the app, the Vision OCR will be something that is risky as public models do have the tendency to train on their users’ data. For that, I decided to NOT to provide any Gemini service in-app. Instead, the Vision OCR works on a BYOK mode. User supplies his own key, which hopefully is from an enterprise plan.
- Make the project open source. By opening the source code, I am hoping that there will be folks who can point out any security issues with the application and help make it more secure. Can people steal my idea and make it their own? Maybe. There are potentials in this project and to be honest, it is easy to monetize the project. I am banking on the fact such applications has to be developed with security as top priority, not an after-thought.
So…
Originally, I wanted to discuss my tech stack. However, since I decided to make the project open-source, such discussions can easily be reviewed in my README file.
As of now, I have already released v1.0.0. The chart is modeled based on my wife’s requirement. I am looking to expand further on the project to include more chart style. In any case, the project is available in: JERMChart
来源:Google AI:DEV 作者专属(RSS) · dev.to