Skip to content

(feat)rebrand: NTP - #2923

Merged
borgateo merged 34 commits into
mainfrom
matteo/rebrand/ntp-feature-branch
Aug 7, 2026
Merged

(feat)rebrand: NTP #2923
borgateo merged 34 commits into
mainfrom
matteo/rebrand/ntp-feature-branch

Conversation

@borgateo

@borgateo borgateo commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Feature branch consolidating NTP rebrand PRs for coordinated merge.

Includes

Test environment

https://mborgato.duckduckgo.com/ntp/preview-hub.html


Note

Medium Risk
Broad NTP UI and styling changes across many widgets, but gated on the rebrand flag with extensive integration coverage; no auth or data-handling changes.

Overview
Consolidates the NTP rebrand into one branch: new-tab visuals, icons, and behavior are updated when body[data-rebrand="true"] / useNewTabPageRebranding() is on; legacy UI stays unchanged when the flag is off.

Design system: Bumps @duckduckgo/design-tokens to v0.34.0 and imports NTP desktop token CSS. Adds shared theme vars (--ntp-card-shadow-rest, dismiss/favicon tokens) and macOS accent/secondary button overrides under rebrand.

Widgets (CSS + small JS hooks): Omnibar (radius, shadows, search/Duck.ai tab icons, suggestions accent-alt rows), favorites tiles, customizer drawer/theme sections, Protections (card chrome, sliding pill between Stats/Activity, tab ARIA), privacy stats, activity (favicon chrome; burn uses TrashIcon vs fire/cross), Next Steps / Next Steps List (rebrand illustrations, empty peek shell behind stacked cards), RMF, PIR/winback banners, shared dismiss and show-more pills.

Assets: New 96px step icons, TrashIcon, rebrand omnibar glyphs (AiChat, SearchFind), and icons/rebrand/* paths for messaging banners.

Tests & tooling: Integration tests for rebrand icons (activity burn/remove, dock vs taskbar, empty peek shell); protections_feed query param in mocks/specs; Next Steps List examples; .gitignore for local agent files.

Reviewed by Cursor Bugbot for commit 57dc562. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Build Branch

Branch pr-releases/matteo/rebrand/ntp-feature-branch
Commit 9665eebdf6
Updated August 7, 2026 at 5:18:23 PM UTC

Static preview entry points

QR codes (mobile preview)
Entry point QR code
Docs QR for docs preview
Static pages QR for static pages preview
Integration pages QR for integration pages preview

Integration commands

npm (Android / Extension):

npm i github:duckduckgo/content-scope-scripts#pr-releases/matteo/rebrand/ntp-feature-branch

Swift Package Manager (Apple):

.package(url: "https://github.com/duckduckgo/content-scope-scripts.git", branch: "pr-releases/matteo/rebrand/ntp-feature-branch")

git submodule (Windows):

git -C submodules/content-scope-scripts fetch origin pr-releases/matteo/rebrand/ntp-feature-branch
git -C submodules/content-scope-scripts checkout origin/pr-releases/matteo/rebrand/ntp-feature-branch
Pin to exact commit

npm (Android / Extension):

npm i github:duckduckgo/content-scope-scripts#9665eebdf622365e077a719ab659bb07e07d1aa0

Swift Package Manager (Apple):

.package(url: "https://github.com/duckduckgo/content-scope-scripts.git", revision: "9665eebdf622365e077a719ab659bb07e07d1aa0")

git submodule (Windows):

git -C submodules/content-scope-scripts fetch origin pr-releases/matteo/rebrand/ntp-feature-branch
git -C submodules/content-scope-scripts checkout 9665eebdf622365e077a719ab659bb07e07d1aa0

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

[Beta] Generated file diff

Time updated: Fri, 07 Aug 2026 17:19:02 GMT

Apple
    - apple/pages/errorpage/dist/index.css
  • apple/pages/errorpage/index.html
  • apple/pages/history/dist/index.css
  • apple/pages/new-tab/dist/index.css
  • apple/pages/new-tab/dist/index.js
  • apple/pages/onboarding/dist/index.css
  • apple/pages/release-notes/dist/index.css
  • apple/pages/special-error/dist/index.css
  • apple/pages/special-error/index.html

File has changed

Removed Files
    - apple/pages/new-tab/icons/Subscription-96.svg
  • integration/pages/new-tab/icons/Subscription-96.svg
  • windows/pages/new-tab/icons/Subscription-96.svg

❌ File only exists in old changeset

Integration
    - integration/pages/errorpage/dist/index.css
  • integration/pages/example/dist/index.css
  • integration/pages/history/dist/index.css
  • integration/pages/new-tab/dist/index.css
  • integration/pages/new-tab/dist/index.js
  • integration/pages/onboarding/dist/index.css
  • integration/pages/release-notes/dist/index.css
  • integration/pages/special-error/dist/index.css

File has changed

Windows
    - windows/pages/history/dist/index.css
  • windows/pages/new-tab/dist/index.css
  • windows/pages/new-tab/dist/index.js
  • windows/pages/onboarding/dist/index.css
  • windows/pages/release-notes/dist/index.css
  • windows/pages/special-error/dist/index.css
  • windows/pages/special-error/index.html

File has changed

New Files
    - apple/pages/new-tab/icons/Browser-Redesign-96.svg
  • apple/pages/new-tab/icons/Default-App-96.svg
  • apple/pages/new-tab/icons/Desktop-Mobile-Subscription-96.svg
  • apple/pages/new-tab/icons/Dock-Add-Mac-96.svg
  • apple/pages/new-tab/icons/Dock-Add-Windows-96.svg
  • apple/pages/new-tab/icons/Email-Protection-96.svg
  • apple/pages/new-tab/icons/Passwords-Import-96.svg
  • apple/pages/new-tab/icons/Shield-Color-16.svg
  • apple/pages/new-tab/icons/Sync-96.svg
  • apple/pages/new-tab/icons/YouTube-Clean-96.svg
  • apple/pages/new-tab/icons/rebrand/Announce-96.svg
  • apple/pages/new-tab/icons/rebrand/AppUpdate-96.svg
  • apple/pages/new-tab/icons/rebrand/CriticalUpdate-96.svg
  • apple/pages/new-tab/icons/rebrand/DDGAnnounce-96.svg
  • apple/pages/new-tab/icons/rebrand/DuckAi-96.svg
  • apple/pages/new-tab/icons/rebrand/PIR-96.svg
  • apple/pages/new-tab/icons/rebrand/Preview-96.svg
  • apple/pages/new-tab/icons/rebrand/PrivacyPro-96.svg
  • apple/pages/new-tab/icons/rebrand/Radar-96.svg
  • apple/pages/new-tab/icons/rebrand/RadarCheckGreen-96.svg
  • apple/pages/new-tab/icons/rebrand/RadarCheckPurple-96.svg
  • apple/pages/new-tab/icons/rebrand/Subscription-96.svg
  • apple/pages/new-tab/icons/rebrand/Subscription-Clock-96.svg
  • apple/pages/new-tab/icons/rebrand/VeryCriticalUpdate-96.svg
  • apple/pages/new-tab/icons/rebrand/YoutubeNew-96.svg
  • integration/pages/new-tab/icons/Browser-Redesign-96.svg
  • integration/pages/new-tab/icons/Default-App-96.svg
  • integration/pages/new-tab/icons/Desktop-Mobile-Subscription-96.svg
  • integration/pages/new-tab/icons/Dock-Add-Mac-96.svg
  • integration/pages/new-tab/icons/Dock-Add-Windows-96.svg
  • integration/pages/new-tab/icons/Email-Protection-96.svg
  • integration/pages/new-tab/icons/Passwords-Import-96.svg
  • integration/pages/new-tab/icons/Shield-Color-16.svg
  • integration/pages/new-tab/icons/Sync-96.svg
  • integration/pages/new-tab/icons/YouTube-Clean-96.svg
  • integration/pages/new-tab/icons/rebrand/Announce-96.svg
  • integration/pages/new-tab/icons/rebrand/AppUpdate-96.svg
  • integration/pages/new-tab/icons/rebrand/CriticalUpdate-96.svg
  • integration/pages/new-tab/icons/rebrand/DDGAnnounce-96.svg
  • integration/pages/new-tab/icons/rebrand/DuckAi-96.svg
  • integration/pages/new-tab/icons/rebrand/PIR-96.svg
  • integration/pages/new-tab/icons/rebrand/Preview-96.svg
  • integration/pages/new-tab/icons/rebrand/PrivacyPro-96.svg
  • integration/pages/new-tab/icons/rebrand/Radar-96.svg
  • integration/pages/new-tab/icons/rebrand/RadarCheckGreen-96.svg
  • integration/pages/new-tab/icons/rebrand/RadarCheckPurple-96.svg
  • integration/pages/new-tab/icons/rebrand/Subscription-96.svg
  • integration/pages/new-tab/icons/rebrand/Subscription-Clock-96.svg
  • integration/pages/new-tab/icons/rebrand/VeryCriticalUpdate-96.svg
  • integration/pages/new-tab/icons/rebrand/YoutubeNew-96.svg
  • windows/pages/new-tab/icons/Browser-Redesign-96.svg
  • windows/pages/new-tab/icons/Default-App-96.svg
  • windows/pages/new-tab/icons/Desktop-Mobile-Subscription-96.svg
  • windows/pages/new-tab/icons/Dock-Add-Mac-96.svg
  • windows/pages/new-tab/icons/Dock-Add-Windows-96.svg
  • windows/pages/new-tab/icons/Email-Protection-96.svg
  • windows/pages/new-tab/icons/Passwords-Import-96.svg
  • windows/pages/new-tab/icons/Shield-Color-16.svg
  • windows/pages/new-tab/icons/Sync-96.svg
  • windows/pages/new-tab/icons/YouTube-Clean-96.svg
  • windows/pages/new-tab/icons/rebrand/Announce-96.svg
  • windows/pages/new-tab/icons/rebrand/AppUpdate-96.svg
  • windows/pages/new-tab/icons/rebrand/CriticalUpdate-96.svg
  • windows/pages/new-tab/icons/rebrand/DDGAnnounce-96.svg
  • windows/pages/new-tab/icons/rebrand/DuckAi-96.svg
  • windows/pages/new-tab/icons/rebrand/PIR-96.svg
  • windows/pages/new-tab/icons/rebrand/Preview-96.svg
  • windows/pages/new-tab/icons/rebrand/PrivacyPro-96.svg
  • windows/pages/new-tab/icons/rebrand/Radar-96.svg
  • windows/pages/new-tab/icons/rebrand/RadarCheckGreen-96.svg
  • windows/pages/new-tab/icons/rebrand/RadarCheckPurple-96.svg
  • windows/pages/new-tab/icons/rebrand/Subscription-96.svg
  • windows/pages/new-tab/icons/rebrand/Subscription-Clock-96.svg
  • windows/pages/new-tab/icons/rebrand/VeryCriticalUpdate-96.svg
  • windows/pages/new-tab/icons/rebrand/YoutubeNew-96.svg

❌ File only exists in new changeset

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected PR Evaluation: Web Compatibility & Security

SHA: 37876f4d5 · Scope: 81 files, all special-pages/ (NTP rebrand feature branch combining #2877, #2882, #2887). No injected/ or messaging/ changes.


Web Compatibility Assessment

File Lines Sev Finding
special-pages/pages/new-tab/app/protections/components/Protections.module.css 29–40 info Base .switcher rules (DS raised-backdrop token + backdrop-filter: blur(48px) on non-default backgrounds) are not gated behind body[data-rebrand="true"]. Pre-rebrand users on custom backgrounds will see the new blurred switcher chrome. Cosmetic only, but worth confirming intent.
special-pages/pages/new-tab/app/protections/components/Protections.js 103–125 info role="tablist" / role="tab" / aria-selected added, but the tab pattern is incomplete: no aria-controls linking tabs to panels, no role="tabpanel" on feed content, no roving tabindex. Keyboard/AT users may not get full tab semantics.
special-pages/pages/new-tab/app/favorites/components/Tile.module.css 59–71, 137–184 info Comment acknowledges pre-existing dark+userImage border/hover fallthrough (dead compound selector removed). Rebrand block correctly switches .draggable to --ntp-surface-background-color, fixing .plus icon legibility on dark+custom backgrounds.
special-pages/pages/new-tab/app/styles/ntp-theme.css 44–52, 67–77 info --ntp-card-shadow-rest correctly scoped under [data-theme] (shadow tokens only resolve there). Dark veil for custom backgrounds correctly gated behind body[data-rebrand="true"] with compounded attribute selectors.
special-pages/pages/new-tab/app/next-steps-list/components/NextStepsListCard.js 172–186 info Rebrand empty peek shell correctly gated via useNewTabPageRebranding(); integration test guards against leaking to non-rebrand users.
(entire PR) info No browser API overrides, prototype patches, or DOM timing changes. Out of scope for injected compat categories.

Security Assessment

File Lines Sev Finding
special-pages/pages/new-tab/app/remote-messaging-framework/components/RemoteMessagingFramework.js 61–62 info Icon src interpolates message.icon, but the value is typed as RMFIcon (closed enum in generated types). No path-traversal risk from page scripts — data is native-supplied and schema-validated.
special-pages/pages/new-tab/app/freemium-pir-banner/components/FreemiumPIRBanner.js 20 info Pre-existing convertMarkdownToHTMLForStrongTagsdangerouslySetInnerHTML for native message copy. Unchanged in this PR; trusted-boundary content only.
special-pages/package.json 31 info @duckduckgo/design-tokens bumped v0.30.0 → v0.34.0. Collateral: onboarding ComparisonTable.module.css still references removed --ds-color-palette-red-50 (see #2902/#2904). Not an injected risk, but verify onboarding build.
(entire PR) info No changes to captured-globals.js, message bridge, origin validation, postMessage, or nativeData handling.

Risk Level

Low Risk — Special-pages NTP UI/CSS rebrand only; all visual changes are gated behind useNewTabPageRebranding() / body[data-rebrand="true"] (with the noted exception of base Protections switcher chrome). No injected script surface area touched.


Recommendations

  1. (info) Confirm whether the ungated Protections switcher backdrop/blur change is intentional for pre-rebrand users; if not, move lines 33–40 under :global(body[data-rebrand="true"]).
  2. (info) Complete the tablist ARIA pattern (aria-controls, role="tabpanel", roving tabindex) before shipping the rebrand tab switcher broadly.
  3. (info) Verify onboarding ComparisonTable against design-tokens v0.34.0 (companion fix #2904) since this branch bumps the shared dependency.
  4. (info) Follow up on dark+userImage favorites tile border/hover fallthrough noted in Tile.module.css comments.
  5. (positive) Good integration-test coverage added for rebrand icon gating, peek-shell behavior, and activity burn/remove icon swaps.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

⚠️ Cursor review was not successful.

This PR requires a manual review and approval from a member of one of the following teams:

  • @duckduckgo/content-scope-scripts-owners
  • @duckduckgo/apple-devs
  • @duckduckgo/android-devs
  • @duckduckgo/team-windows-development
  • @duckduckgo/extension-owners
  • @duckduckgo/config-aor
  • @duckduckgo/breakage-aor
  • @duckduckgo/breakage

Comment thread special-pages/pages/new-tab/app/omnibar/components/useKeyboardFocusWithin.js Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected PR Evaluation: Web Compatibility & Security

Re-assessed on synchronize (8331bda44, 2026-08-04). Delta since 4ee53d575: merges Customize drawer rebrand (#2890) — 7 files, CSS-only.

Scope note: 97 files total, all special-pages/ (NTP rebrand feature branch combining #2877, #2882, #2887, #2890, #2912). No injected/, messaging/, wrapper-utils.js, or captured-globals.js changes.


Web Compatibility Assessment

File Severity Finding
(none in injected/) No browser API overrides, prototype patches, or content-script messaging in this PR.
customizer/components/Customizer.module.css:46-47 info Rebrand customize button drops backdrop-filter in favor of solid control-fill tokens — reduces GPU/compositing cost; correctly scoped to [data-rebrand="true"].
customizer/components/CustomizerDrawerInner.module.css:265+ info Drawer typography, background-panel selection rings, and close-button styling are all under [data-rebrand="true"] — no legacy-path impact.
customizer/components/ThemeSection.module.css:87+ info --theme-swatch-outer-radius: 10px is a hardcoded Figma value (no matching DS token); rebrand-gated. macOS segmented-control inset shadow scoped to [data-rebrand][data-platform-name="macos"].
styles/ntp-theme.css:44-47, 79-84 info Rebrand drawer width (264px) and darker dark-mode veil (black-at-50) are compound-gated on body[data-rebrand] + background-kind — correct selector pattern (no descendant combinator on body attrs).
shared/components/Switch/Switch.module.css:100+ info Windows medium switch sizing overrides gated on :global([data-rebrand="true"]).
onboarding/.../ComparisonTable.module.css:119 info Hardcoded #de5833 replaces removed --ds-color-palette-red-50 token — onboarding collateral from design-tokens bump, not NTP runtime.
protections/components/Protections.js:102-127 info Tablist adds role="tab" / aria-selected (improvement) but still lacks aria-controls + role="tabpanel" wiring — incomplete ARIA tab pattern.
protections/components/Protections.module.css:1-3, 38-40 info .root and non-default-background .switcher retain ungated backdrop-filter: blur(48px) — pre-existing; rebrand blob indicator is gated in JS.
favorites/components/Tile.module.css:59-60, 173-174 info Dark+userImage tile border/hover still falls through to light rules when rebrand is off — acknowledged pre-existing.
omnibar/components/useKeyboardFocusWithin.js info Tab-only keyboard-focus detection; listeners skipped when enabled: false (rebrand off). Correctly lifted to Omnibar.js with enabled: rebrand.

Security Assessment

File Severity Finding
(entire PR) No injected script surface. NTP is a privileged embedded page, not arbitrary third-party DOM.
remote-messaging-framework/.../RemoteMessagingFramework.js info Icon paths use ./icons/rebrand/${message.icon}-96.svgmessage.icon comes from native RMF config (trusted), not page-controlled input.
(none) No nativeData forwarding, message-bridge changes, postMessage, eval/Function, uncaptured globals, or origin-validation relaxations.

Risk Level

Low Risk — CSS/visual rebrand work and NTP component styling gated behind body[data-rebrand="true"] / useNewTabPageRebranding(); zero changes to injected privacy features or messaging security boundaries.

Recommendations

  1. (info) Complete Protections tablist ARIA: add aria-controls on tabs and role="tabpanel" on the feed container.
  2. (info) Manual QA: rebrand customize drawer on macOS + Windows (theme swatches, background panels, visibility toggles, drawer width).
  3. (info) Optional: integration test with rebrand: 'enabled' for customize drawer open/close and theme selection.
  4. (info) Track dark+userImage favorites tile border fallthrough for a follow-up when rebrand ships broadly.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@borgateo
borgateo requested a review from vkraucunas August 4, 2026 02:19
@borgateo borgateo self-assigned this Aug 4, 2026
@borgateo
borgateo marked this pull request as ready for review August 5, 2026 01:30
@borgateo
borgateo requested review from a team and daxtheduck as code owners August 5, 2026 01:30

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected PR Evaluation: Web Compatibility & Security

Ready-for-review sign-off at 380dc6f66 (2026-08-05).

Scope note: This PR touches 97 files, all under special-pages/pages/new-tab/ and shared components. No injected/ or messaging/ changes. The injected-script threat model (API overrides, captured globals, message-bridge trust boundaries) does not apply.

Delta since last assessment (d1e150351): 380dc6f66 — rebrand-only omnibar TabSwitcher CSS polish (disable hover pseudo on unselected tabs, label padding tweak, remove dark blob shadow). No new compat/security findings.


Web Compatibility Assessment

File Lines Severity Finding
(entire PR) info No injected-script changes. NTP is a privileged embedded page, not page-world injection.
special-pages/.../useKeyboardFocusWithin.js 42–45 info Keyboard-focus tracking is Tab-only; Shift+Tab and arrow-key navigation are not tracked. Acceptable for pill-ring affordance but differs from full :focus-visible semantics. Gated via enabled: false when rebrand is off.
special-pages/.../Protections.js 102–127 info Stats/Activity switcher uses role="tablist" + aria-selected, but tabs lack aria-controls pointing to tabpanels and feed content lacks role="tabpanel". Pre-existing pattern extended with rebrand blob indicator.
special-pages/.../Protections.module.css 1–3, 39 info Legacy .root / .switcher retain backdrop-filter: blur(48px) outside [data-rebrand]. Rebrand path removes blur on switcher; base rules unchanged for flag-off users.
special-pages/.../Tile.module.css 59–67 info Dark + userImage background tile border/hover still falls through to light rule (acknowledged in comment). Pre-existing, not introduced by rebrand.
special-pages/.../onboarding/.../ComparisonTable.module.css info Collateral from design-tokens v0.30→v0.34 bump: --ds-color-palette-red-50 removed. Tracked separately in #2904.

Security Assessment

File Lines Severity Finding
(entire PR) info No changes to captured globals, API shims, messaging transports, or message-bridge trust boundaries.
special-pages/.../RemoteMessagingFramework.js 72–73 info Title/description rendered as text nodes (not innerHTML) — good. Icon paths switch between ./icons/ and ./icons/rebrand/ based on rebrand flag; both are static bundled assets.
special-pages/.../FreemiumPIRBanner.js, SubscriptionWinBackBanner.js info Pre-existing dangerouslySetInnerHTML via convertMarkdownToHTMLForStrongTags() unchanged; PR only adds rebrand icon path switching. Native message content trust boundary unchanged.
special-pages/.../useKeyboardFocusWithin.js 52–61 info Document-level capture listeners (keydown, pointerdown, etc.) are properly cleaned up on unmount and skipped when enabled: false. No leak when rebrand is off.

Risk Level

Low Risk — Special-pages NTP UI/CSS rebrand gated behind useNewTabPageRebranding() / body[data-rebrand="true"], with no injected-script, messaging, or browser API override changes.


Recommendations

  1. (info) Before rebrand GA: add aria-controls / role="tabpanel" to the Protections stats/activity switcher for full tablist semantics.
  2. (info) Coordinate native rollout so newTabPageRebranding flag and body[data-rebrand] stay in sync.
  3. (info) Land #2904 (ComparisonTable palette token) before or with the design-tokens bump if onboarding builds are in scope.
  4. (info) Consider rebrand screenshot baselines for omnibar TabSwitcher dark-mode blob shadow removal (380dc6f66).

No blocking injected compat/security issues found. ✅

Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

Comment thread special-pages/pages/new-tab/app/activity/components/Activity.module.css Outdated
Comment thread special-pages/pages/new-tab/app/components/ShowHide.module.css

@vkraucunas vkraucunas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Found a few things to update / and a few questions. Happy to come back n approve if that makes your life easier.

Comment thread special-pages/pages/new-tab/app/activity/components/Activity.module.css Outdated
Comment thread special-pages/pages/new-tab/app/components/ShowHide.module.css
Comment thread special-pages/pages/new-tab/public/icons/PrivacyPro.svg
Comment thread special-pages/pages/new-tab/public/icons/Subscription-96.svg Outdated
Comment thread special-pages/pages/new-tab/app/omnibar/components/useKeyboardFocusWithin.js Outdated
Comment thread special-pages/pages/new-tab/app/omnibar/components/SearchForm.module.css Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected Web Compatibility & Security Review

Re-assessed on synchronize (cb372d9b8, 2026-08-05). Delta since e68f94550: subscription icon path correction (SubscriptionWinBackBanner now uses rebrand/Subscription-Clock-96.svg; new asset added). No other logic changes.

Scope note: This PR touches 98 files, all under special-pages/ — there are zero changes to injected/, messaging/, wrapper-utils.js, captured-globals.js, or message-bridge code. The injected compat/security threat model (API overrides on hostile third-party pages, captured globals, messaging trust boundaries) does not apply.


Web Compatibility Assessment

File Severity Finding
(none in injected/) No browser API overrides, prototype patches, or DOM injection into arbitrary web pages.
special-pages/.../useKeyboardFocusWithin.js info Document-level keydown/pointerdown listeners gated via enabled: rebrand; cleaned up on unmount. Tab-only modality (arrow keys won't trigger keyboard-focus ring) — matches static-pages pattern, acceptable for launch.
special-pages/.../Protections.js info role="tablist" / role="tab" / aria-selected added; missing aria-controls / tabindex for full ARIA tabs pattern. NTP embedded surface only.
special-pages/.../Protections.module.css info backdrop-filter: blur(20px) on legacy .blockLegacy path — potential perf cost on low-end devices when rebrand off.
special-pages/.../Tile.module.css info Non-rebrand dark + userImage border/hover may fall through to rebrand rules (acknowledged in #2887).

Security Assessment

File Severity Finding
(none in injected/) No captured-global bypass, messaging bridge, or postMessage changes.
special-pages/.../RemoteMessagingFramework.js info Icon path ./icons/rebrand/${message.icon}-96.svgmessage.icon from native RMF config (trusted source), same interpolation pattern as pre-PR legacy path.
special-pages/.../SubscriptionWinBackBanner.js, FreemiumPIRBanner.js info dangerouslySetInnerHTML with convertMarkdownToHTMLForStrongTags() (escapes HTML before **<strong>). Pre-existing pattern, not introduced here.
special-pages/.../settings.provider.js info Rebrand gated via settings.newTabPageRebranding.state === 'enabled' — remotely controllable by native, allows rollback without deploy.

No warning, error, or critical security findings.


Risk Level

Low Risk — special-pages NTP UI/CSS rebrand behind a native feature flag; no injected script changes, no API shims, no messaging transport modifications.


Recommendations

  1. Resolved (cb372d9b8): Subscription win-back banner now uses rebrand/Subscription-Clock-96.svg per design feedback.
  2. Resolved (ac99d7c27): Legacy ProtectionsBodyLegacy blob pill when rebrand on.
  3. Info (open): Complete ARIA tabs pattern (aria-controls, tabindex) if keyboard nav between Stats/Activity tabs is prioritized.
  4. Info (open): Consider rebrand screenshot baselines for omnibar, RMF, and customizer surfaces.
  5. Info (open): Bugbot-flagged ungated CSS changes in Activity/Protections base rules are visual-scope concerns outside injected compat/security — track separately if legacy NTP parity is required.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

Comment thread special-pages/pages/new-tab/app/components/ShowHide.module.css Outdated
Comment thread special-pages/pages/new-tab/app/components/ShowHide.module.css Outdated
Comment thread special-pages/pages/new-tab/app/components/ShowHide.module.css
@borgateo

borgateo commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

@BugBot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Web Compatibility Assessment

Scope note: 98 files changed, all under special-pages/pages/new-tab/ (plus collateral onboarding screenshot rebaselines). No injected/ changes — third-party web-page API fidelity categories do not apply.

File Severity Finding
omnibar/components/useKeyboardFocusWithin.js info Keyboard focus ring is Tab-only (event.key === 'Tab'); Shift+Tab and arrow-key navigation won't set data-keyboard-focus-within. Matches static-pages pattern; hook is gated via enabled: rebrand.
protections/components/Protections.js info Rebrand adds role="tablist" / role="tab" / aria-selected but omits aria-controls and roving-tabindex arrow-key handling. Buttons still work via click; incomplete WAI-ARIA tabs pattern.
favorites/components/Favorites.js info ShowHideButtonPill does not pass variant="rebrand" while Privacy Stats does — minor visual inconsistency when rebrand is on.
favorites/components/Tile.module.css info Dark + userImage background still falls through to light border/hover rule (acknowledged in-file comment; pre-existing).
next-steps-list/components/NextStepsListCard.module.css info Resolved in e2ccdb4c0: Windows button longhand overrides now scoped to body[data-rebrand="true"] — no longer leaks to legacy NTP on Windows.
components/ShowHide.module.css info Resolved in 43986f98e: Dark rebrand icon background uses nested [data-theme="dark"] under body[data-rebrand] (dead compound selector fixed).

Security Assessment

File Severity Finding
remote-messaging-framework/components/RemoteMessagingFramework.js info Icon path ./icons/rebrand/${message.icon}-96.svg interpolates native RMF config; bounded to bundled static assets under known prefix.
freemium-pir-banner/, subscription-winback-banner/ info Pre-existing dangerouslySetInnerHTML; content sanitized via convertMarkdownToHTMLForStrongTags (HTML escaped before **<strong> conversion).
settings.provider.js info All rebrand UI gated via useNewTabPageRebranding() reading native newTabPageRebranding setting — remotely toggleable without code deploy.
No changes to captured globals, message bridge, origin validation, postMessage, or load()-time injection.

Risk Level

Low Risk — Entirely special-pages NTP styling/components; zero injected/ diff; no browser API overrides, messaging boundary changes, or security-sensitive infrastructure touched.

Recommendations

  1. (info) Consider passing variant="rebrand" to Favorites' ShowHideButtonPill for visual parity with Privacy Stats.
  2. (info) Complete Protections tablist ARIA (aria-controls + keyboard nav) or document as intentional button-group.
  3. (info) Add rebrand-specific Playwright screenshot baselines before ship (onboarding collateral rebaselines are unrelated).
  4. (info) Manual QA: omnibar keyboard focus ring (Tab vs click), Windows Next Steps buttons under rebrand, dark theme ShowHide pills.

Re-assessed at e2ccdb4c0. Delta since 43986f98e: Windows Next Steps button overrides scoped to rebrand; Protections spacing token (--ds-space-x06).

Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

Comment thread special-pages/pages/new-tab/app/omnibar/components/Omnibar.module.css Outdated
Comment thread special-pages/pages/new-tab/app/omnibar/components/Omnibar.js Outdated
Comment thread special-pages/pages/new-tab/app/omnibar/components/Omnibar.js Outdated
Comment thread special-pages/pages/new-tab/app/favorites/components/Favorites.js

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected PR Evaluation: Web Compatibility & Security

Re-assessed on synchronize (18fc384d3, 2026-08-05). Delta since 443151f37: removes useKeyboardFocusWithin hook and its document-level listeners.

Scope: 99 files changed; no injected/ changes. NTP rebrand CSS/JS in special-pages/ only, gated via useNewTabPageRebranding() / body[data-rebrand="true"].


Web Compatibility Assessment

File Lines Severity Finding
special-pages/pages/new-tab/app/omnibar/components/Omnibar.js 154 info Resolved: useKeyboardFocusWithin removed. Focus chrome now relies on :has(input:focus:placeholder-shown) / :focus-visible CSS in Omnibar.module.css — no document-level capture listeners.
special-pages/pages/new-tab/app/protections/components/Protections.js 102–123 info Tab buttons use role="tab" / aria-selected but lack aria-controls linking to tabpanels. Pre-existing pattern; consider role="tabpanel" + aria-labelledby for screen-reader navigation.
special-pages/pages/new-tab/app/omnibar/components/TabSwitcher.js 31–45 info Same tablist ARIA gap as Protections switcher.
special-pages/pages/new-tab/app/omnibar/components/Omnibar.module.css 78–91, 164–201 info Rebrand focus ring uses :has() pseudo-class. Supported in current DDG WebViews; no API-surface fidelity concerns.
special-pages/pages/new-tab/app/favorites/components/Tile.module.css info Non-rebrand dark + userImage background may fall through to legacy border/hover (acknowledged in prior reviews).
special-pages/pages/new-tab/ (screenshots) info No rebrand-specific screenshot baselines added; onboarding rebaselines are collateral from design-tokens bump.

Security Assessment

File Lines Severity Finding
special-pages/pages/new-tab/app/remote-messaging-framework/components/RemoteMessagingFramework.js 62 info Icon path interpolates native message.icon into ./icons/rebrand/${message.icon}-96.svg. Pre-existing pattern; native should whitelist icon names (no XSS via <img>, but unexpected asset load if unvalidated).
special-pages/pages/new-tab/app/freemium-pir-banner/components/FreemiumPIRBanner.js 30 info dangerouslySetInnerHTML for description via convertMarkdownToHTMLForStrongTags — pre-existing, strong-tags only.
No changes to messaging transports, nativeData handling, postMessage, or captured-globals. No injected/ code touched.
special-pages/pages/new-tab/app/settings.provider.js 42–44 info Rebrand styles correctly gated behind settings.newTabPageRebranding.state === 'enabled' — remotely disableable.

Risk Level

Low Risk — special-pages NTP UI/CSS rebrand with feature-flag gating; no injected script changes, API overrides, or messaging security surface touched.


Recommendations

  1. (info) Manual keyboard QA on rebrand omnibar: verify focus ring appearance for Tab vs click on search input and Duck.ai textarea (now CSS-only).
  2. (info) Add aria-controls / role="tabpanel" to Protections and TabSwitcher tablists when convenient.
  3. (info) Consider rebrand screenshot baselines before wide rollout.
  4. (info) Confirm native RMF icon name allowlist covers new rebrand/ asset set.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

Comment thread special-pages/pages/new-tab/app/omnibar/components/TabSwitcher.js
@borgateo
borgateo requested a review from vkraucunas August 5, 2026 23:33
borgateo added 11 commits August 6, 2026 13:19
Removing the rebrand background/backdrop-filter override lets the legacy
custom-bg rules (rgba glass fills) apply on color/gradient/userImage
backgrounds, matching the pre-rebrand behaviour in main.
Revert omnibar focus state to production behaviour: border + outline glow
via --ds-color-theme-accent-primary / accent-glow-primary, removing the
custom box-shadow focused override and keyboard-focus-ring mechanism.

Fix dynamicPickerIconColor in rebrand dark mode: use --color-black-at-96 /
--color-white-at-96 so the icon always contrasts against the swatch color,
independent of the app theme.
Mirrors the same pattern used in PrivacyStats: pass variant='rebrand'
when the rebrand flag is on, 'default' otherwise.
CSS consumers (--keyboard-focus-ring, popup[data-keyboard-focus-within])
were removed when reverting to the production focus ring. The hook is now
dead code — removing to avoid pointless document listeners on every rebrand
NTP load. Will be reintroduced in the follow-up omnibar project.
- TickPill: gate DS token color behind data-rebrand; fix light-mode icon
  color by setting it on .iconWrapper (not path fill) so currentColor works
- Customizer CSS: align [data-rebrand] selectors to :global(body[data-rebrand])
  for consistency and safe retirement-time grep
- FreemiumPIRBanner: use var(--ntp-card-shadow-rest) instead of inline copy
- ActivityItem: hoist useNewTabPageRebranding to memo'd parents, pass isRebrand
  as prop to Controls (removes N context subscriptions for a boot-time constant)
- NextStepsGroup: add missing variant prop to ShowHideButtonPill (latent bug)
- Omnibar: scope --omnibar-radius to .root; inline border token per theme
  directly on .popup instead of global custom properties on body
…-feed

Aligns with the kebab-case convention used by all other multi-word params
(next-steps, rmf-delay, update-notification, etc.).
…_feed

Aligns with underscore convention as agreed with Valerie.
@borgateo
borgateo force-pushed the matteo/rebrand/ntp-feature-branch branch from 9720c6b to 9c237fd Compare August 6, 2026 16:20
@github-actions github-actions Bot added the semver-minor New feature — triggers minor version bump label Aug 6, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit a085878. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Injected PR Evaluation — Web Compatibility & Security

SHA: 4cf387c6d | Delta since last assessment: 1 commit (fix(privacy-stats): use body-md line-height token for rebrand count)

Web Compatibility Assessment

File Lines Severity Finding
(full PR) info No injected/ or messaging/ changes. All 91 files are special-pages/ UI, CSS, icons, tests, and design-token bumps. No browser API overrides, prototype patches, or DOM timing risks.
PrivacyStats.module.css 317 info Resolved: Rebrand .count line-height now uses var(--ds-font-body-md-line-height) instead of hardcoded 13px. Aligns with design-system typography after font-feature-settings removal.
TabSwitcher.js 31–45 info Tablist uses role="tablist" / role="tab" / aria-selected but lacks aria-controls and associated role="tabpanel" panels. Visual-only switcher; minor SR gap.
Protections.js 102–125 info Same tablist pattern for stats/activity feed switcher — no aria-controls/tabpanel pairing.
Tile.module.css 59–67 info Pre-existing: dark+userImage background falls through to light border/hover rule (documented in comment). Cosmetic only.
RemoteMessagingFramework.js 62 info Icon path ./icons/rebrand/${message.icon}-96.svgmessage.icon is typed as RMFIcon union from native messaging; not page-controlled.

Security Assessment

File Lines Severity Finding
(full PR) info No changes to captured-globals.js, message bridge, API shims, shouldExemptMethod(), or postMessage transports.
RemoteMessagingFramework.js 62 info Icon filename from native-controlled RMFIcon typed union — no path traversal from page scripts.
Rebrand gating info All rebrand styles gated via useNewTabPageRebranding() / body[data-rebrand="true"]. Remote-config rollback path preserved.

Risk Level

Low Risk — Special-pages NTP rebrand UI/CSS only; zero injected-script surface. New commit is a single design-token substitution with no compat or security impact.

Recommendations

  1. (info) Consider adding aria-controls + role="tabpanel" to TabSwitcher and Protections feed switchers for full ARIA tab pattern compliance.
  2. (info) Add rebrand screenshot baselines for omnibar, favorites, protections, and RMF before ship.
  3. (info) Optional: address Tile dark+userImage border/hover fallthrough in a follow-up.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@borgateo
borgateo enabled auto-merge August 7, 2026 17:53
@borgateo
borgateo added this pull request to the merge queue Aug 7, 2026
Merged via the queue into main with commit 944266d Aug 7, 2026
37 of 39 checks passed
@borgateo
borgateo deleted the matteo/rebrand/ntp-feature-branch branch August 7, 2026 18:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver-minor New feature — triggers minor version bump

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants