curo1305
3b24058e15
test(12-04): add dedicated cloud security-negative integration suite
...
- test_foreign_user_cannot_browse_cloud_item (IDOR T-12-01, CONN-04)
- test_admin_cannot_browse_cloud_connection (admin block T-12-01, D-03)
- test_browse_response_excludes_credentials_and_raw_fields (T-12-03, D-06)
- test_ssrf_url_validation_invariants (T-12-04, D-14)
- test_browse_no_quota_mutation (T-12-09, D-07)
- test_browse_no_minio_calls (T-12-09, D-08)
- test_disabled_connection_browse_blocked (D-17)
- test_same_provider_items_scoped_to_connection (D-01, D-05 PostgreSQL)
- test_no_byte_download_during_browse (D-18)
- 16 tests pass; full suite 509 passed
2026-06-19 01:51:13 +02:00
curo1305
8a99230048
docs(phase-12): update tracking after wave 3
2026-06-18 23:33:03 +02:00
curo1305
84c2549c36
chore: merge executor worktree (worktree-agent-a280818c01e94acd2)
2026-06-18 23:32:56 +02:00
curo1305
5287efd34c
docs(12-03): add plan 03 execution summary
2026-06-18 23:32:41 +02:00
curo1305
c6c0742267
feat(12-03): breadcrumb freshness, formatRelativeTime, v0.1.6, docs
...
- BreadcrumbBar: refreshing spinner, fresh checkmark (fades 3s), stale warning banner
- Accessible labels and role=status for all freshness states
- formatters.js: add formatRelativeTime (shared, no duplication)
- Version bump 0.1.5 → 0.1.6 in backend/main.py and frontend/package.json
- AGENTS.md: update state, shared module map (formatRelativeTime)
- README.md: unified connection-root browsing and capability explanations feature text
- 17 BreadcrumbBar tests pass; 323 total; production build clean
2026-06-18 23:31:50 +02:00
curo1305
44244335a1
feat(12-03): capability-aware action rendering in StorageBrowser
...
- Add capabilities, connectionRoot, folderFreshness, lastRefreshedAt, byteAvailability props
- CapabilityButton inline component: aria-disabled, click/Enter/Space/touch suppression
- Gray for unsupported, amber for temporarily_unavailable — no native disabled
- Local defaults preserve all pre-Phase-12 drag/share/move/delete behavior
- Cached-byte marker (clock icon) on size column when byteAvailability='cached'
- No marker for cloud_only
- AppIcon: add info, clock icons
- 50 StorageBrowser tests pass
2026-06-18 23:29:10 +02:00
curo1305
bf9af11274
feat(12-03): connection-ID routing, rename, session folder memory, thin views
...
- Route /cloud/:connectionId/:folderId replaces /cloud/:provider/:folderId
- api/cloud.js: getCloudFoldersByConnectionId + renameCloudConnection
- cloudConnections store: rename, selectConnection, setBrowseState, defaultDisplayName, session storage helpers
- CloudStorageView: thin — passes connectionRoots to StorageBrowser
- CloudFolderView: thin — uses connectionId param, never provider slug
- SettingsCloudTab: inline rename input for each active connection
- 27 tests pass: store, view, settings
2026-06-18 23:25:29 +02:00
curo1305
6f0ecfa39b
docs(phase-12): update tracking after wave 2
2026-06-18 23:19:55 +02:00
curo1305
81c4d52041
chore: merge executor worktree (worktree-agent-ac074b0ec7fc0dbc3)
2026-06-18 23:19:27 +02:00
curo1305
f61736621e
chore: track AGENTS.md (untracked file blocking wave-2 merge)
2026-06-18 23:19:05 +02:00
curo1305
e5d6b9ea53
docs(12-02): execution summary — CloudResourceAdapter, browse endpoint, Celery refresh task
2026-06-18 23:18:30 +02:00
curo1305
c6237ca57f
feat(12-02): add refresh_cloud_folder Celery task, staleness trigger, version 0.1.5
...
- Add tasks/cloud_tasks.py: durable refresh_cloud_folder task with 3-retry
bounded backoff (30s/90s/270s +jitter), credential decryption in worker only
- Register tasks.cloud_tasks.* on documents queue in celery_app.py
- Add stale-while-revalidate staleness trigger in browse.py (5-min threshold)
- Add 4 Task 3 tests: idempotency, cached-row retention on failure, task structure,
no-byte-download contract; add background-refresh scheduling integration test
- Bump backend version 0.1.4 → 0.1.5, frontend package.json 0.1.4 → 0.1.5
- Update AGENTS.md with Phase 12 Plan 02 state and new shared module map entries
- Update README with connection-ID browse API table and v0.1.5
2026-06-18 23:17:34 +02:00
curo1305
e186019066
feat(12-02): decompose api/cloud.py into package with connection-ID browse endpoint
...
- Add api/cloud/ package: connections.py, browse.py, schemas.py, __init__.py
- Add GET /api/cloud/connections/{connection_id}/items (T-12-01 IDOR, T-12-03 cred-free)
- Add PATCH /api/cloud/connections/{id} for display_name_override rename
- Add display_name_override ORM field to CloudConnection model
- Add CloudResourceAdapter service layer with str/UUID coercion
- Fix UUID type compatibility: test_cloud_items.py now uses UUID(as_uuid=True)
matching conftest — removes String(36) patch that caused type incompatibility
- Add 11 Phase 12 integration tests (IDOR, admin block, credential exclusion,
duplicate providers, rename, malformed UUID)
- Remove deleted api/cloud.py (replaced by api/cloud/ package)
2026-06-18 23:10:30 +02:00
curo1305
ff33439f0a
feat(12-02): normalize all four providers into CloudResourceAdapter contract
...
- GoogleDriveBackend: list_folder with full pagination, native doc size=None, get_capabilities
- OneDriveBackend: list_folder with @odata.nextLink pagination, get_capabilities
- WebDAVBackend: list_folder via PROPFIND with SSRF re-validation, get_capabilities
- NextcloudBackend: inherits CloudResourceAdapter from WebDAVBackend
- build_cloud_resource_adapter() added to factory
- 22 new contract/behavior/pagination/no-byte-download tests (51 total pass)
2026-06-18 22:45:09 +02:00
curo1305
71ba0293a5
docs(phase-12): update tracking after wave 1
2026-06-18 22:39:35 +02:00
curo1305
312a96d2bf
chore: merge executor worktree (worktree-agent-a032d981c3b3ec11b)
2026-06-18 22:39:06 +02:00
curo1305
3127853c1e
docs(12-01): complete cloud-resource-foundation plan 01 summary
2026-06-18 22:38:46 +02:00
curo1305
718fb2c2b5
feat(12-01): durable owner-scoped cloud metadata schema (migration 0006 + models)
...
- Migration 0006: cloud_items, cloud_item_topics, cloud_folder_states tables
- cloud_connections: add display_name_override column for same-provider disambiguation
- CloudItem, CloudItemTopic, CloudFolderState ORM models with owner/connection indexes
- Unique (connection_id, provider_item_id) boundary; no MinIO object_key field
- Root folder state representable as parent_ref='' without CloudItem parent row
- services/cloud_items.py: resolve_owned_connection, upsert, list, reconcile, folder state
- 17 unit/integration tests covering model fields, isolation, quota invariant, idempotency
2026-06-18 22:37:28 +02:00
curo1305
0a7273b9fe
feat(12-01): normalized cloud resource capability contract and unit tests
...
- Define 9 action keys, 3 capability states, 6 reason codes in cloud_base.py
- Immutable CloudCapability, CloudResource, CloudListing frozen dataclasses
- Abstract CloudResourceAdapter with list_folder, get_capabilities, merge_item_capabilities
- No mutation methods in Phase 12 interface (Phase 13 boundary enforced)
- 29 unit tests covering vocabulary, validation, merge behavior, fake adapter
2026-06-18 22:34:23 +02:00
curo1305
11b91775b6
docs(12): create phase plan
2026-06-18 22:30:07 +02:00
curo1305 and Claude Sonnet 4.6
fe54a855b3
docs(phase-12): fix UI-SPEC typography and spacing blocking issues
...
- Collapse font weights from 3 to 2: drop font-medium (500), use font-semibold (600) for row primary names, labels, column headers; font-normal (400) for body
- Fix sm spacing token usage: replace p-1.5 (6px) with p-2 (8px) to match declared 8px value
- Update health badge in connection root list from font-medium to font-semibold
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-18 22:19:25 +02:00
curo1305 and Claude Sonnet 4.6
ea682fdecd
docs(phase-12): add UI design contract for cloud-resource-foundation
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-18 22:16:22 +02:00
curo1305
52b110acef
docs(phase-12): add research and validation strategy
2026-06-18 22:13:23 +02:00
curo1305
09814c28a9
docs(12): capture phase context
2026-06-18 22:07:26 +02:00
curo1305
a323276e37
docs: create milestone v0.3 roadmap (5 phases)
2026-06-17 23:27:21 +02:00
curo1305
608acedaf6
docs: define milestone v0.3 requirements
2026-06-17 23:24:54 +02:00
curo1305
9150d28fe1
docs: research milestone v0.3 cloud storage integration
2026-06-17 23:19:01 +02:00
curo1305
0e56c85349
docs: start milestone v0.3 Reimagining Cloud Storage integration
2026-06-17 23:16:21 +02:00
curo1305 and Claude Sonnet 4.6
123ae5b29b
chore: archive v0.2 phase directories to milestones/v0.2-phases/
...
Moves phases 08–11 execution artifacts from .planning/phases/ to
.planning/milestones/v0.2-phases/ to keep .planning/phases/ clean
for the next milestone.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-17 14:34:52 +02:00
curo1305 and Claude Sonnet 4.6
e008bf7dae
chore: remove REQUIREMENTS.md for v0.2 milestone
...
Requirements archived to .planning/milestones/v0.2-REQUIREMENTS.md.
Fresh REQUIREMENTS.md will be created by /gsd:new-milestone for v0.3.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
v0.2
2026-06-17 14:26:51 +02:00
curo1305 and Claude Sonnet 4.6
475e519158
chore: archive v0.2 milestone files
...
Archive v0.2 (UI Overhaul and Optimization) to milestones/:
- milestones/v0.2-ROADMAP.md — full phase archive (Phases 8–11, 33 plans)
- milestones/v0.2-REQUIREMENTS.md — all 40 requirements marked complete
- milestones/v0.2-MILESTONE-AUDIT.md — audit artifact (passed, 40/40)
- MILESTONES.md — new living milestone index
- RETROSPECTIVE.md — new living retrospective with v0.2 section
- PROJECT.md — full evolution review: v0.2 requirements moved to Validated, 5 new Key Decisions added
- STATE.md — updated to milestone-complete status
- ROADMAP.md — v0.2 phases collapsed into <details> with progress table updated
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-17 14:26:19 +02:00
curo1305
2280b6f987
docs(milestone): mark v0.2 audit passed
2026-06-17 13:13:30 +02:00
curo1305
aaf57eae80
fix(milestone): close v0.2 audit gaps
2026-06-17 12:42:20 +02:00
curo1305
b9e2fc1803
docs(milestone): audit v0.2 closeout gaps
2026-06-17 11:51:27 +02:00
curo1305
595b33a68c
fix(phase-11): close mobile storage UAT gaps
2026-06-17 10:48:35 +02:00
curo1305
c48ebf152c
test(phase-11): record mobile UAT gaps
2026-06-17 10:37:21 +02:00
curo1305
64aa960d20
test(phase-11): add Nyquist validation coverage
2026-06-17 09:58:59 +02:00
curo1305 and Claude Sonnet 4.6
f5fc8d111b
docs(phase-11): add security threat verification — 13/13 threats CLOSED
...
Retroactive-STRIDE audit for Phase 11 (visual-design-responsive-layout-cleanup).
No plan-time threat model existed; register built from implementation files.
All 13 threats closed: 7 mitigated, 6 accepted with documented rationale.
threats_open: 0 — phase 11 security gate passes.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-17 09:51:47 +02:00
curo1305
1c0b231002
docs(11): update VERIFICATION.md — all 12 requirements satisfied after TreeItem gap fix
2026-06-17 09:37:36 +02:00
curo1305
28e75e971d
fix(11): TreeItem.vue — focus-visible ring on all interactive elements; skeleton width → static Tailwind
...
- Expand/collapse button, router-link label, and button label all get focus-visible:ring-2 focus-visible:ring-indigo-500 focus-visible:ring-offset-1
- :style skeleton width replaced with :class w-12/w-16/w-20 (same fix applied to AppSidebar in 11-05)
- Closes VISUAL-01 and VISUAL-03 gaps found by verifier
2026-06-17 09:35:06 +02:00
curo1305
8ac5b15f51
docs(11): add code review report
2026-06-17 09:26:45 +02:00
curo1305
f667a3bbc8
docs(phase-11): update tracking after wave 5 — all plans complete
2026-06-17 08:03:50 +02:00
curo1305
73f409dd2f
chore: merge executor worktree (worktree-agent-a39e918c6d4ac337a)
2026-06-17 08:03:27 +02:00
curo1305
b121bc2a86
docs(11-06): complete Plan 11-06 — dead-code cleanup and final verification SUMMARY
...
Summary covers all 8 tasks:
- Task 1 (prior): AccountView.vue deleted (a8e0a19 )
- Tasks 2-5: admin test classification (3 retained), FolderRow.vue deleted,
stale FolderRow tests removed; 268/268 tests pass (a928b54 )
- Task 6 (prior): final bundle analysis committed (888d376 )
- Task 7: phase11-final-summary.md — -81 kB / -30.6% main bundle (df981fb )
- Task 8: 11-VERIFICATION.md — all 12 Phase 11 requirements SATISFIED (9ad88ab )
2026-06-17 08:02:16 +02:00
curo1305
9ad88abe88
docs(11-06): add 11-VERIFICATION.md — all 12 Phase 11 requirements mapped to evidence
...
Maps VISUAL-01..04, RESP-01..05, CODE-07, PERF-02, PERF-03 to concrete
code locations, test describe/it strings, and build output evidence.
All 12 requirements verified as SATISFIED:
- VISUAL-01: skeleton Tailwind classes; AppSidebar.visual.test.js
- VISUAL-02: @tailwindcss/forms active; ShareModal form tests
- VISUAL-03: typography normalized; typography.visual.test.js
- VISUAL-04: 62 focus-visible occurrences; AppSidebar.visual.test.js
- RESP-01: App.vue hamburger drawer with Teleport backdrop
- RESP-02: StorageBrowser hidden md/sm columns; skeleton test
- RESP-03: 36px touch targets; StorageBrowser.skeleton.test.js
- RESP-04: max-h-[90vh] overflow-y-auto on all 4 modals; mobile tests
- RESP-05: AdminLayout.vue hamburger drawer pattern
- CODE-07: FolderRow.vue + AccountView.vue deleted; 3 admin tests retained
- PERF-02: 4 perf artifacts in .planning/perf/
- PERF-03: 21 JS chunks vs 15 baseline; all non-initial routes lazy
2026-06-17 08:01:00 +02:00
curo1305
df981fbced
docs(11-06): write Phase 11 bundle final summary — baseline vs final comparison
...
Baseline: 264.63 kB main / 89.34 kB gzip / 15 JS chunks
Final: 183.62 kB main / 64.83 kB gzip / 21 JS chunks
Delta: -81.01 kB raw (-30.6%), -24.51 kB gzip (-27.4%), +6 new lazy chunks
Documents the 5 new lazy route chunks from Plan 11-02 (SettingsView,
TopicsView, DocumentView, CloudStorageView, CloudFolderView), CSS growth
from new responsive Tailwind classes, and the intentional synchronous
FileManagerView decision (D-10, critical first authenticated surface).
2026-06-17 07:58:14 +02:00
curo1305
a928b54781
chore(11-06): dead-code cleanup — delete FolderRow.vue, retain admin tab tests
...
Task 2 — admin test classification:
- AdminAiConfigTab.test.js: RETAINED (tests AdminAiView.vue, a live component)
- AdminQuotasTab.test.js: RETAINED (tests AdminQuotasView.vue, a live component)
- AdminUsersTab.test.js: RETAINED (tests AdminUsersView.vue, a live component)
Task 3 — confirmed absent: HomeView.vue, FolderView.vue, AdminView.vue all absent
Task 4 — dead-code scan:
- FolderRow.vue: DELETED — no import in any live component; StorageBrowser renders
folder rows inline; FolderRow had no active route or active import (CLAUDE.md rule)
Task 5 — stale test removal:
- dropdown.test.js: removed 2 FolderRow tests (tested dead component);
kept 2 DocumentCard Teleport tests (protect live surface)
- No unused named imports found in live components
268/268 tests pass.
2026-06-17 07:56:00 +02:00
curo1305
6e3d1f866a
chore: merge executor worktree (worktree-agent-a3ed83649498e1792)
2026-06-17 05:43:53 +02:00
curo1305
888d3761d5
chore(11-06): capture final Phase 11 bundle analysis report
...
- Run ANALYZE=true npm run build after all Phase 11 optimizations
- Main bundle: 183.62 kB raw / 64.84 kB gzip (was 264.63 kB / 89.34 kB)
- SettingsView, TopicsView, DocumentView all now in separate lazy chunks
- 25 chunks total vs 15 at baseline
2026-06-17 03:55:12 +02:00
curo1305
a8e0a199f2
chore(11-06): delete orphaned AccountView.vue
...
- AccountView.vue had no active route component reference
- /account path uses redirect: '/settings' with no component import
- No imports found across the entire codebase
- Satisfies CODE-07: no unreferenced route views remain
2026-06-17 00:39:05 +02:00