curo1305
a6e8a597e7
docs(12.1-01): complete Plan 01 summary and state updates
2026-06-22 08:20:06 +02:00
curo1305
62128730e8
fix(12.1-01): restore asyncio import, bump version to 0.2.3, update docs
...
- Restore asyncio import removed when legacy list_folder was deleted (health_check
still uses asyncio.to_thread); fixes test_nextcloud_connect_persists regression
- Bump backend/main.py and frontend/package.json version to 0.2.3
- Update CLAUDE.md: note Phase 12.1 Plan 01 complete, add normalize_nextcloud_url
to shared module map, add NextcloudBackend no-override rule
- Update README.md: version 0.2.3, note canonical Nextcloud URL normalization and
OneDrive nextLink origin guard
- Full backend suite: 585 passed, 1 pre-existing failure (missing python-docx module)
2026-06-22 08:18:23 +02:00
curo1305
805fe44bfb
feat(12.1-01): add cross-origin nextLink guard and Drive/OneDrive contract tests
...
- Validate @odata.nextLink hostname against graph.microsoft.com before following
(T-12.1-03); cross-origin nextLink returns complete=False with prior items retained
- Add TestOneDriveCrossOriginNextLink: cross-origin rejection, same-origin follows,
page failure retains prior items
- Add TestGoogleDriveAuthFailureControl: 401 returns complete=False, page1+page2
error retains page1 items
- All 163 four-provider contract tests pass
2026-06-22 08:12:39 +02:00
curo1305
2b46f74329
feat(12.1-01): repair Nextcloud adapter contract and add URL normalization
...
- Remove incompatible NextcloudBackend.list_folder(folder_path="") override
so Nextcloud inherits canonical WebDAVBackend.list_folder(connection_id,
user_id, parent_ref=None, page_token=None) -> CloudListing
- Add normalize_nextcloud_url() to cloud_utils.py: idempotent canonical DAV
root derivation, username percent-encoding, https-only, rejects userinfo/
query/fragment, validates via SSRF guard before return
- Use normalize_nextcloud_url in cloud_backend_factory for nextcloud provider
- Add TestNextcloudBackendNoListFolderOverride and TestNextcloudUrlNormalization
to test_webdav_backend.py
- All 9 Nextcloud contract failures now pass; full focused suite: 158 passed
2026-06-22 08:11:06 +02:00
curo1305
eb68facd6c
test(12.1-01): add failing four-provider contract suite and fixtures
...
- Create test_cloud_provider_contract.py with parametrized suite for
Nextcloud, WebDAV, Google Drive, OneDrive
- Assert canonical (connection_id, user_id, parent_ref=None, page_token=None)
signature, CloudListing return type, trusted caller identity propagation,
metadata normalization, pagination completeness, and forbidden-operation spies
- Add synthetic credential-free fixtures: nextcloud_root.xml, webdav_root.xml,
google_drive_pages.json, onedrive_pages.json
- 9 tests fail for nextcloud (expected RED state — incompatible list_folder override)
- All webdav, google_drive, onedrive contract tests pass
2026-06-22 08:09:00 +02:00
curo1305
692600c755
test(12): close Nyquist validation gap
2026-06-22 06:44:33 +02:00
curo1305
e64980af5f
docs(phase-12): add security threat verification — 26/26 closed
2026-06-22 01:39:24 +02:00
curo1305 and Claude Sonnet 4.6
c283623903
docs(phase-12): resolve UAT gaps and close phase after 12-06 gap closure
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-21 22:38:23 +02:00
curo1305
bd5e8f4192
docs(12): add code review report for phase 12-06 gap closure
2026-06-21 22:35:01 +02:00
curo1305
4a910549ac
docs(12-06): add plan 06 SUMMARY — UUID-only navigation, multi-account, credential-update
2026-06-21 22:30:51 +02:00
curo1305
c85e4abd91
chore(12-06): bump version 0.2.1 → 0.2.2
2026-06-21 22:30:11 +02:00
curo1305
057b4999fd
feat(12-06): UUID-only cloud navigation, breadcrumb hierarchy, route-aware sidebar
...
- CloudProviderTreeItem: getCloudFoldersByConnectionId(connection.id) + /cloud/{uuid}/root
- CloudFolderTreeItem: connectionId prop replaces provider slug in browse + route
- AppSidebar: Cloud Storage active only on exact /cloud; connection nodes use per-connection isActive
- New tests: CloudProviderTreeItem, CloudFolderTreeItem, AppSidebar cloud active-state
2026-06-21 22:30:05 +02:00
curo1305
731b65ecdd
feat(12-06): connection-ID native lifecycle — always INSERT, PUT credentials, connectionsFor multi-account
...
- Replace _upsert_cloud_connection with _insert_cloud_connection (always inserts new UUID row)
- Add PUT /connections/{id}/credentials endpoint (owner-scoped, SSRF + health-check, password-preserve)
- SettingsCloudTab: connectionsFor() renders all same-provider connections with Add account row
- CloudCredentialModal.submit: calls updateWebDavCredentials on edit, connectWebDav on create
- utils.js: FastAPI validation arrays normalised to concise field messages (Rule 2)
- Backend tests: same-provider independence + IDOR negative test for credential update
2026-06-21 22:29:59 +02:00
curo1305
97c30c3a15
docs(12): plan cloud UAT gap fixes
2026-06-21 22:21:05 +02:00
curo1305
70ed1219a9
test(12): pause UAT - 1 passed, 2 issues, 3 blocked
2026-06-21 22:18:14 +02:00
curo1305
8c80607df9
fix(dev-env): complete local startup configuration
2026-06-21 20:43:45 +02:00
curo1305
461b56892c
docs(12-05): mark VERIFICATION.md passed — all 5 truths verified
2026-06-21 20:33:37 +02:00
curo1305 and Claude Sonnet 4.6
206f564248
test(12-05): fix test_nextcloud_connect_persists + compose migration test path
...
- test_nextcloud_connect_persists: provider=nextcloud routes to NextcloudBackend
(not WebDAVBackend) — add storage.nextcloud_backend.validate_cloud_url patch
and use AsyncMock for asyncio.to_thread (plain return_value=True is not
awaitable, swallowed by except → False). Test now passes HTTP 201.
- test_compose_migrations: skip module when docker-compose.yml is not found at
the expected repo-root path (file is not mounted inside the backend container).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-20 12:35:35 +02:00
curo1305 and Claude Sonnet 4.6
043a7817e2
fix(12-uat): add display_name_override schema regression + Compose hardening
...
- test_list_connections_reads_display_name_override_column: proves GET /api/cloud/connections
does not raise UndefinedColumn (direct Phase 12 UAT blocker regression)
- docker-compose: promtail socket :ro, Grafana password fail-fast (:?)
- test_migration_0006: DDL privilege test fails not skips when role absent
- README: version 0.2.1
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-20 11:07:30 +02:00
curo1305 and Claude Sonnet 4.6
760a8d4bcd
fix(12-uat): resolve critical code review findings in gap closure (CR-01 through CR-03, IN-01)
...
- CR-01: promtail Docker socket mounted :ro (was read-write)
- CR-02: Grafana admin password uses :? fail-fast (was :-changeme default)
- CR-03: DDL privilege test fails not skips when docuvault_app role absent
- IN-01: README version synced to 0.2.1
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-20 10:55:23 +02:00
curo1305
b6526e46f1
docs(12): add gap closure code review report
2026-06-20 10:54:22 +02:00
curo1305
bb818e0621
docs(phase-12): resolve UAT gaps and debug sessions after 12-05 gap closure
2026-06-20 10:51:44 +02:00
curo1305
34be364ca7
docs(phase-12): update tracking after gap closure wave
2026-06-20 10:50:38 +02:00
curo1305
824d271a42
chore: merge executor worktree (worktree-agent-a724010d4b729caf8)
2026-06-20 10:50:22 +02:00
curo1305
67d3e4bcac
docs(12-05): complete gap closure plan SUMMARY
2026-06-20 10:49:59 +02:00
curo1305
3ca57dcd0c
fix(12-05): bump version to 0.2.1 and update docs for migration-gated startup
...
- backend/main.py, frontend/package.json: version 0.2.0 → 0.2.1
- CLAUDE.md, AGENTS.md: current state updated to reflect gap-closure
- README.md: startup instructions note migrate runs automatically; update migration commands
- RUNBOOK.md: startup diagram includes migrate service; migration gate explanation
- SECURITY.md: Phase 12 gap-closure threat register and security gate evidence
2026-06-20 10:49:21 +02:00
curo1305
de2efd1664
test(12-05): add migration 0005→0006 integration regression and RUNBOOK migration ops
...
- test_migration_0006.py: proves display_name_override, cloud_items, cloud_item_topics,
cloud_folder_states, unique constraints, indexes, and DDL privilege boundary
- Tests skip cleanly without INTEGRATION=1/INTEGRATION_DATABASE_URL (no dev DB mutation)
- RUNBOOK: add Database Migrations section with revision check, upgrade, recovery, and
emergency schema-drift remediation commands
2026-06-20 10:47:11 +02:00
curo1305
1b3084ddfa
feat(12-05): add migration-gated Compose startup path
...
- Add one-shot migrate service using DATABASE_MIGRATE_URL and alembic upgrade head
- Add migrate dependency (service_completed_successfully) to backend, celery-worker, celery-beat
- migrate service has same read_only/cap_drop/no-new-privileges hardening as other services
- Add test_compose_migrations.py: 7 static assertions on Compose configuration
2026-06-20 10:45:22 +02:00
curo1305
66d8634b17
docs(12): plan UAT migration gap closure
2026-06-20 10:40:37 +02:00
curo1305
a7e17d69b4
docs(12): add root causes from diagnosis
2026-06-19 23:44:04 +02:00
curo1305
802afebafe
test(12): complete UAT - 0 passed, 2 issues
2026-06-19 23:39:22 +02:00
curo1305
13b9d83401
docs(phase-12): update validation strategy
2026-06-19 06:10:55 +02:00
curo1305
33264862c1
docs(phase-12): evolve PROJECT.md and CLAUDE.md after phase completion
2026-06-19 06:06:01 +02:00
curo1305
8e5d7a1900
docs(phase-12): complete phase execution
2026-06-19 06:05:03 +02:00
curo1305 and Claude Sonnet 4.6
b6911fb4ed
fix(12): resolve critical code review findings (CR-01 through CR-04)
...
- CR-01: fix browse URL from /folders/{id} to /items?parent_ref= (broken feature)
- CR-02: remove raw provider exception text from _TerminalProviderError messages
- CR-03: add user_id predicate to get_or_create_folder_state query (ownership boundary)
- CR-04: add max_length=255 to ConnectionRenameRequest.display_name
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-19 02:00:05 +02:00
curo1305
de63e2a3a4
docs(12): add code review report
2026-06-19 01:59:17 +02:00
curo1305
b7ae44b3f8
docs(phase-12): update tracking after wave 4
2026-06-19 01:55:47 +02:00
curo1305
06ccc865b9
chore: merge executor worktree (worktree-agent-aa3d7c2b49ba82638)
2026-06-19 01:55:35 +02:00
curo1305
7b1fc6e5cf
docs(12-04): create Phase 12 Plan 04 SUMMARY.md
...
Records security-negative suite completion, threat register closure, gate
evidence, version bump to 0.2.0, and D-01..D-18 decision coverage map.
2026-06-19 01:55:15 +02:00
curo1305
c441fc63e5
chore(12-04): bump version to 0.2.0 and finalize Phase 12 documentation
...
- backend/main.py, frontend/package.json: 0.1.6 → 0.2.0 (phase-complete minor bump)
- AGENTS.md: current state updated to Phase 12 complete; cloud-resource-foundation
summary with browse contract, security suite, and Phase 13/14 boundary note
- README.md: version updated to 0.2.0
- All existing shared module map rules and frontend architecture constraints unchanged
2026-06-19 01:54:24 +02:00
curo1305
fccb9c6394
security(12-04): add Phase 12 security gate evidence and cloud ops runbook
...
- SECURITY.md: Phase 12 threat register (T-12-01 through T-12-SC) with
evidence for all 8 threat IDs; bandit/npm audit gate results;
accepted risks for pip-audit tooling gap and DISABLED connection behavior
- RUNBOOK.md: Phase 12 cloud operations section covering connection
management, browse refresh lifecycle, item metadata queries,
stuck-refresh recovery, and security operation notes
2026-06-19 01:52:49 +02:00
curo1305
3b24058e15
test(12-04): add dedicated cloud security-negative integration suite
...
- test_foreign_user_cannot_browse_cloud_item (IDOR T-12-01, CONN-04)
- test_admin_cannot_browse_cloud_connection (admin block T-12-01, D-03)
- test_browse_response_excludes_credentials_and_raw_fields (T-12-03, D-06)
- test_ssrf_url_validation_invariants (T-12-04, D-14)
- test_browse_no_quota_mutation (T-12-09, D-07)
- test_browse_no_minio_calls (T-12-09, D-08)
- test_disabled_connection_browse_blocked (D-17)
- test_same_provider_items_scoped_to_connection (D-01, D-05 PostgreSQL)
- test_no_byte_download_during_browse (D-18)
- 16 tests pass; full suite 509 passed
2026-06-19 01:51:13 +02:00
curo1305
8a99230048
docs(phase-12): update tracking after wave 3
2026-06-18 23:33:03 +02:00
curo1305
84c2549c36
chore: merge executor worktree (worktree-agent-a280818c01e94acd2)
2026-06-18 23:32:56 +02:00
curo1305
5287efd34c
docs(12-03): add plan 03 execution summary
2026-06-18 23:32:41 +02:00
curo1305
c6c0742267
feat(12-03): breadcrumb freshness, formatRelativeTime, v0.1.6, docs
...
- BreadcrumbBar: refreshing spinner, fresh checkmark (fades 3s), stale warning banner
- Accessible labels and role=status for all freshness states
- formatters.js: add formatRelativeTime (shared, no duplication)
- Version bump 0.1.5 → 0.1.6 in backend/main.py and frontend/package.json
- AGENTS.md: update state, shared module map (formatRelativeTime)
- README.md: unified connection-root browsing and capability explanations feature text
- 17 BreadcrumbBar tests pass; 323 total; production build clean
2026-06-18 23:31:50 +02:00
curo1305
44244335a1
feat(12-03): capability-aware action rendering in StorageBrowser
...
- Add capabilities, connectionRoot, folderFreshness, lastRefreshedAt, byteAvailability props
- CapabilityButton inline component: aria-disabled, click/Enter/Space/touch suppression
- Gray for unsupported, amber for temporarily_unavailable — no native disabled
- Local defaults preserve all pre-Phase-12 drag/share/move/delete behavior
- Cached-byte marker (clock icon) on size column when byteAvailability='cached'
- No marker for cloud_only
- AppIcon: add info, clock icons
- 50 StorageBrowser tests pass
2026-06-18 23:29:10 +02:00
curo1305
bf9af11274
feat(12-03): connection-ID routing, rename, session folder memory, thin views
...
- Route /cloud/:connectionId/:folderId replaces /cloud/:provider/:folderId
- api/cloud.js: getCloudFoldersByConnectionId + renameCloudConnection
- cloudConnections store: rename, selectConnection, setBrowseState, defaultDisplayName, session storage helpers
- CloudStorageView: thin — passes connectionRoots to StorageBrowser
- CloudFolderView: thin — uses connectionId param, never provider slug
- SettingsCloudTab: inline rename input for each active connection
- 27 tests pass: store, view, settings
2026-06-18 23:25:29 +02:00
curo1305
6f0ecfa39b
docs(phase-12): update tracking after wave 2
2026-06-18 23:19:55 +02:00
curo1305
81c4d52041
chore: merge executor worktree (worktree-agent-ac074b0ec7fc0dbc3)
2026-06-18 23:19:27 +02:00