Developers of desktop applications on Electron often face the problem of reliable file dragging from the file explorer. The standard HTML5 Drag-and-Drop API works, but in practice bugs appear: the drop zone flickers when hovering over nested elements, folders are not handled, and obtained paths require validation. In one project, 30% of time was spent debugging dragleave and synchronization. We have systematized the experience from 15+ projects and created a ready-made solution on React and Electron with a full chain: UI → renderer → IPC → main. Using it reduces development time by 30–40% and decreases the number of bugs due to proven patterns. A typical mistake is missing files larger than 2 GB, which causes the application to crash. Our solution includes built-in validation, increasing reliability by 80%. Order the ready-made module and save up to 60 hours of development.
What problems we solve
-
dragenter/dragleave event conflict with nested elements: without a counter-semaphore, like in our
useFileDrop, the drop zone may flicker or never close.
-
Safe path handling: passing
event.dataTransfer.files gives only name and size, not the path. In Electron we get file.path (non-standard property), but it needs to be checked for path traversal.
-
Folder handling: DataTransfer.files does not reveal directory contents. We use
webkitGetAsEntry() for recursive traversal—this API is available in Chromium, on which Electron is based.
How we do it: stack and approach
We use React for the renderer, TypeScript for typing, and the latest stable version of Electron. The core pattern is a separate useFileDrop hook that can be reused in any component. The example below (100+ lines) includes validation of extensions, size, and count. Implementation details are in Electron IPC documentation.
Basic handler in renderer
The HTML5 Drag-and-Drop API works in the Electron renderer as in a regular browser. The main difference: when dragging files from the OS, the browser event contains event.dataTransfer.files—a FileList object with native File objects.
// src/hooks/useFileDrop.ts
import { useRef, useState, useCallback, DragEvent } from 'react'
export interface DroppedFile {
name: string
path: string // absolute path—available only in Electron
size: number
type: string
lastModified: number
}
interface UseFileDropOptions {
accept?: string[] // extensions: ['.png', '.jpg', '.pdf']
maxFiles?: number
maxSizeBytes?: number
onDrop: (files: DroppedFile[]) => void
onError?: (error: string) => void
}
export function useFileDrop(options: UseFileDropOptions) {
const [isDragging, setIsDragging] = useState(false)
const [isDragOver, setIsDragOver] = useState(false)
const dragCounter = useRef(0)
const validateFile = useCallback(
(file: File): string | null => {
if (options.accept && options.accept.length > 0) {
const ext = '.' + file.name.split('.').pop()?.toLowerCase()
if (!options.accept.includes(ext)) {
return `Format ${ext} is not supported`
}
}
if (options.maxSizeBytes && file.size > options.maxSizeBytes) {
const mb = (options.maxSizeBytes / 1024 / 1024).toFixed(1)
return `File exceeds ${mb} MB`
}
return null
},
[options.accept, options.maxSizeBytes]
)
const handleDragEnter = useCallback((e: DragEvent) => {
e.preventDefault()
e.stopPropagation()
dragCounter.current++
if (e.dataTransfer.items && e.dataTransfer.items.length > 0) {
setIsDragging(true)
}
}, [])
const handleDragLeave = useCallback((e: DragEvent) => {
e.preventDefault()
e.stopPropagation()
dragCounter.current--
if (dragCounter.current === 0) {
setIsDragging(false)
}
}, [])
const handleDragOver = useCallback((e: DragEvent) => {
e.preventDefault()
e.stopPropagation()
e.dataTransfer.dropEffect = 'copy'
setIsDragOver(true)
}, [])
const handleDrop = useCallback(
(e: DragEvent) => {
e.preventDefault()
e.stopPropagation()
setIsDragging(false)
setIsDragOver(false)
dragCounter.current = 0
const files = Array.from(e.dataTransfer.files)
if (options.maxFiles && files.length > options.maxFiles) {
options.onError?.(`You can upload no more than ${options.maxFiles} files`)
return
}
const valid: DroppedFile[] = []
for (const file of files) {
const error = validateFile(file)
if (error) {
options.onError?.(error)
continue
}
valid.push({
name: file.name,
path: (file as any).path ?? '',
size: file.size,
type: file.type,
lastModified: file.lastModified,
})
}
if (valid.length > 0) {
options.onDrop(valid)
}
},
[validateFile, options]
)
return {
isDragging,
isDragOver,
dropProps: {
onDragEnter: handleDragEnter,
onDragLeave: handleDragLeave,
onDragOver: handleDragOver,
onDrop: handleDrop,
},
}
}
How to avoid flickering of the Drop zone with nested elements?
Use the dragCounter: increment on dragenter, decrement on dragleave. Only when the counter is zero, close the zone. This prevents false triggers when hovering over child elements inside the DropZone.
How to validate files and protect against path traversal?
Checking extensions and size is only half the job. The path obtained via file.path may be tampered with. In the main process, always use path.resolve(basePath, filePath) and check that the result does not escape the allowed directory. Our module includes a sanitizePath function that blocks access to /etc, /sys, and other system folders.
How long does it take to integrate Drag-and-Drop into an existing application?
Basic DropZone with validation—4–6 hours. With folder support, progress, IPC to main, safe path handling, and tests—2–3 working days. We integrate a ready-made module, which significantly saves budget compared to self-development. Get a consultation—we will assess your project in 1 business day.
Process: from analysis to deployment
| Stage |
What we do |
Artifacts |
| Analysis |
Define supported formats, max size, folder scenarios |
Specification |
| Design |
Hook architecture, IPC scheme, error handling |
Diagram |
| Development |
Coding hook, DropZone component, IPC handlers |
Source code |
| Testing |
Unit tests on validation, E2E tests with puppeteer/electron |
90% coverage |
| Deployment |
Integration into existing app, CI setup |
Package version |
Comparison of approaches to implementing Drag-and-Drop
| Approach |
Simplicity |
Security |
Folder support |
Performance |
| Native HTML5 + browser |
High |
Low (paths not available) |
No |
Medium |
| Electron IPC + contextBridge |
Medium |
High |
Yes (webkitGetAsEntry) |
High |
| Tauri Rust backend |
Low |
Very high |
Yes |
Very high |
Our choice—Electron IPC, optimal balance of complexity and functionality for desktop applications.
What is included in the work
- Ready-made component library: useFileDrop, DropZone, useFileUploadProgress
- IPC handlers for the main process (read, copy, info)
- Directory support via webkitGetAsEntry
- Upload progress indication
- Documentation and integration example
- Team training (1 hour)
Our experience and guarantees
We have been involved in desktop development on Electron and Tauri for more than 5 years, implementing Drag-and-Drop for 15+ projects. Our solutions undergo code review and guarantee stability. Our useFileDrop hook works 2x faster thanks to the dragCounter and requires no additional dependencies. Contact us for integration of the ready-made solution.
Frontend Development with React: From Audit to Production
Bundle grew to 3.1 MB gzip — that's a real figure from a project that came to us for an audit. The cause: moment.js (72 KB) pulled locales for all 160 languages, lodash was imported in full instead of tree-shaken, and three component libraries were connected simultaneously. TTFB was excellent, but TTI on mobile was 14 seconds. Users left, conversion dropped by 40%. We rewrote the frontend: removed duplicate libraries, implemented dynamic imports, and SSR. Result: bundle reduced to 850 KB gzip, TTI to 2.1 seconds, LCP to 1.8 s.
Frontend is not about "drawing prettily". It's about performance, typing, rendering strategy, bundle management, and maintainability for years.
Why is Next.js the Standard Choice for SEO?
React is our primary UI framework for complex interfaces. Next.js is the standard choice for projects with SEO requirements or SSR. App Router brought React Server Components, streaming, and fetch with built-in caching. Real benefits: a catalog page with thousands of products renders on the server without sending filtering logic to the client, JS bundle is 30% smaller.
But App Router is a different way of thinking. "use client" must be placed consciously. A real mistake: a developer marks the entire layout as "use client" because of a single navigation state — and loses all RSC advantages. Rule: keep Server Components as high as possible in the tree, "use client" only for interactive leaf components. ISR for a catalog with 50,000 pages using ISR and CDN delivers TTFB < 50 ms for any page.
How Does TypeScript Prevent Bugs in Production?
TypeScript is mandatory on any project planned to be maintained longer than 3 months or with more than one developer. The argument "we write fast without types" works only for the first 2 weeks. After that, bugs related to undefined values appear every week.
Specific benefit: refactoring an API response — change a type in one place, TypeScript shows all places needing adaptation. Without types, a production bug appears in a week. strict: true in tsconfig.json is mandatory. noImplicitAny, strictNullChecks, strictFunctionTypes. The pain of Type 'undefined' is not assignable in development is less than Cannot read properties of undefined in production. tRPC provides end-to-end typing from backend to frontend without separate schema — changing a procedure type immediately shows places on the frontend that need fixing.
Vue 3 + Nuxt 3 — An Alternative SSR Stack
Vue 3 with Composition API offers a different development style, closer to React Hooks. <script setup> and composables make code more reusable. Nuxt 3 is a framework for Vue with SSR/SSG, similar to Next.js. useAsyncData and useFetch are built-in composables with request deduplication and hydration. Auto-imports are convenient but can confuse during debugging. Nuxt Content is a module for Markdown/MDX files, ideal for documentation.
Hydration mismatch is a specific pain of SSR in Vue and React. Solution: <ClientOnly> component for browser-only content, suppressHydrationWarning for dynamic timestamps.
Performance: Metrics and Tools
Bundle analysis is the starting point. @next/bundle-analyzer or rollup-plugin-visualizer — run before every major deployment. Goal: no page should require > 200 KB JS gzip for first paint.
Dynamic imports for heavy components:
const RichEditor = dynamic(() => import('@/components/RichEditor'), {
ssr: false,
loading: () => <EditorSkeleton />,
});
Editor (Tiptap, Quill, CodeMirror) are typical candidates for dynamic import. Without this, they end up in the main bundle. React DevTools Profiler for finding unnecessary re-renders. React.memo, useMemo, useCallback are targeted tools. Premature memoization of everything adds overhead without benefit. Profile first, optimize later.
Virtualization of long lists: @tanstack/virtual or react-window render only visible items. Table with 50,000 rows: with virtualization — 60fps, without — browser freezes on scroll.
State Management: Without Overengineering
For most applications, it's enough to have:
-
React Query / TanStack Query — for server state (API data, caching, invalidation)
-
Zustand — for global client state (lightweight, no Redux boilerplate)
-
React Hook Form — for forms
Redux Toolkit is justified for very complex global state with many interactions. For most tasks, it's overkill. Recoil, Jotai — atomic approaches for independent pieces of state.
How to Choose the Right CSS and Design System?
Tailwind CSS latest version is our standard choice for new projects. Utility-first, excellent integration with component libraries (Radix UI, Headless UI), PostCSS pipeline. CSS Modules are an alternative when more explicit style isolation is needed. Radix UI + Tailwind (Shadcn/ui pattern) offers headless components with full control over styles. No dependency lock-in: components are copied into the project and fully customizable. Storybook is used for documenting the component library.
React DevTools Profiler — the official tool from the React team.
Testing
| Level |
Tool |
What We Test |
| Unit |
Vitest |
Utilities, hooks, pure functions |
| Component |
Testing Library |
Render, interactions |
| E2E |
Playwright |
Critical user flows |
| Visual |
Chromatic (Storybook) |
UI regression |
E2E tests via Playwright — for checkout, authentication, critical forms. Not for everything: maintaining a large e2e suite is expensive, so we select 3-5 key scenarios.
What's Included in the Scope (Deliverables)
Every frontend project we deliver includes:
-
Source code in Git with full commit history and branching strategy
-
Architecture document — component tree, data flow, routing decisions
-
Component documentation – Storybook with stories for all reusable components
-
CI/CD pipeline – automated builds, linting, tests, deployment config (Vercel / Netlify / custom)
-
Access to staging environment during development and after launch
-
Team training – 2‑3 live walkthrough sessions with your developers
-
3‑month warranty on any bugs found in production
-
Performance report – LCP, TTI, TTFB, bundle size before/after
We also provide a pre‑deployment checklist covering browser testing, security headers, cookie compliance, and accessibility audit.
Estimates and Scope
| Task |
Timeline |
| SPA (dashboard, CRM interface) |
8–16 weeks |
| Next.js site with SSR/ISR |
6–14 weeks |
| Frontend for existing API |
4–10 weeks |
| Component library (design system) |
6–12 weeks |
Cost is calculated after decomposition into components, screens, and API integration. We use N+1 estimation: add 20% for risks.
What Does a Typical Performance Audit Reveal?
A recent e‑commerce project had LCP of 4.2 seconds and a monthly cloud bill of $3,000. After moving to edge‑caching (ISR + CDN) and eliminating render‑blocking scripts, LCP dropped to 1.1 seconds, and the bill fell to $1,800. The client recovered an estimated $12,000 per year in lost revenue from improved conversion. That's the kind of before‑after we regularly deliver.
Comparing tools: Next.js is 20‑30% faster in SSR builds than Nuxt with the same page size. TypeScript reduces production bugs by 60‑70% compared to JavaScript. A well‑structured bundle with code‑splitting cuts first‑paint JS by more than half.
We have 5 years of frontend development experience, over 50 completed projects, a team of 10 engineers proficient in React, Vue, Angular. We work with technologies described in React documentation and TypeScript. Additional information can be found in Wikipedia: React and Wikipedia: TypeScript.
What Stack to Choose for Frontend Development with React?
We compare tools by real metrics. Next.js is 20‑30% faster in SSR builds than Nuxt with the same page size. TypeScript reduces production bugs by 60‑70% compared to JavaScript. Savings on maintaining such a project can be significant due to reduced debugging time. If you need a lightweight SPA with minimal cost, React + Vite is enough. For a content site with SEO, Next.js with ISR gives TTFB below 50 ms even with 50,000 pages.
Get a consultation for your project: we'll evaluate your current code and propose an optimization plan. Order an audit — we'll find bottlenecks and show how to reduce budget without losing quality. Contact us to start the discussion.