curo1305 and Claude Sonnet 4.6
b8b0840729
docs(phase-7): update tracking after wave 3 — plan 07-03 complete
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-04 19:19:03 +02:00
curo1305 and Claude Sonnet 4.6
420fecdacd
docs(phase-6): update tracking after wave 3 — plan 06-06 complete, Phase 6 done
...
All 6 Phase 6 plans complete. Phase 6 status updated to Complete in STATE.md
and ROADMAP.md (plans 06-04, 06-05, 06-06 checked). UAT passed (06-UAT.md),
D-10 CVE gate passed (trivy exit 0), D-14 RUNBOOK.md in place.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-04 19:14:22 +02:00
curo1305 and Claude Sonnet 4.6
ea8df02491
docs(phase-7): update tracking after wave 2 — plan 07-02 complete
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-04 19:06:07 +02:00
curo1305 and Claude Sonnet 4.6
651713fa7a
docs(phase-7): update tracking after wave 1 — plan 07-01 complete
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-04 18:53:25 +02:00
curo1305
6d1ecbd9e2
docs(phase-06): update tracking after wave 1 — 06-02 and 06-03 complete
2026-06-03 18:54:06 +02:00
curo1305
c11984c66c
docs(phase-06): update tracking after wave 0 — 06-01 complete
2026-06-03 18:41:46 +02:00
curo1305 and Claude Sonnet 4.6
3df62506c9
docs(07): create phase plan — 5 plans, verification passed
...
5 waves: system_settings DB + HKDF encryption (01), ProviderConfig +
GenericOpenAIProvider + singleton client fix (02), Anthropic output_config +
classifier wiring (03), Celery retry 30/90/270s + re-queue endpoint (04),
admin AI panel + DocumentCard badge + human checkpoint (05).
All 18 decisions D-01..D-18 covered. Plan checker passed after 1 revision
round (4 blockers fixed: D-02/D-14 coverage, D-11 Vitest tests, Plan 05
files_modified).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-03 18:25:00 +02:00
curo1305 and Claude Sonnet 4.6
70c09f6cd4
docs(06): create phase 6 plan — performance & production hardening
...
6 plans across 4 waves covering structlog/Loki observability, Locust
load testing, multi-stage Dockerfile hardening, trusted-proxy rate
limiting, and RUNBOOK.md. Verification passed (0 blockers).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-02 20:35:03 +02:00
curo1305 and Claude Sonnet 4.6
bd17b4b22f
docs(06.2): mark phase 6.2 complete — all gates passed
...
UAT complete (7/7 re-tests passed or skipped with reason), security gate
passed (threats_open: 0), 344 backend tests passing.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-01 21:09:04 +02:00
curo1305
5093aa5630
docs(phase-02): update tracking after plan 06 gap closure — 6/6 plans complete
2026-06-01 14:24:46 +02:00
curo1305
c3c7030e91
docs(phase-06.2): update tracking after wave 3 — all 5 plans complete
2026-05-31 20:16:08 +02:00
curo1305
abb964531f
docs(phase-06.2): update tracking after wave 2 — plan 06.2-04 complete
2026-05-31 15:24:44 +02:00
curo1305 and Claude Sonnet 4.6
708fd7fad0
docs(phase-6.2): record planning complete — 4 plans verified, state updated
...
- ROADMAP.md: progress table → Planned; wave annotations already added by planner
- STATE.md: phase 6.2 row → Planned (4 plans, 3 waves); session note added
- 06.2-03-PLAN.md: remove incorrect SHARE-03/SHARE-05 from requirements field
- 06.2-RESEARCH.md: mark Open Questions section as RESOLVED
- 06.2-UI-SPEC.md: add to version control (was untracked)
Verification: 0 blockers, 2 cosmetic warnings fixed.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-31 11:41:32 +02:00
curo1305 and Claude Sonnet 4.6
4adc77d8cc
docs(06.2): create 4-plan phase covering SHARE-03, SHARE-05, cloud-delete, ADMIN-06
...
Wave 0: 11 xfail stubs across test_shares/test_documents/test_audit
Wave 1 (parallel): SHARE-05 badge + SHARE-03 permission control; cloud-delete propagation
Wave 2: audit handle enrichment, user_handle filter, CSV fetch+Blob, daily-export UI
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-31 11:36:33 +02:00
curo1305 and Claude Sonnet 4.6
7be48266ae
docs(06.2): capture phase context + fix admin user creation 500
...
- Phase 6.2 CONTEXT.md: cloud-delete propagation, SHARE-03/05, audit
log CSV export fix, daily export UI, user handle display
- Fix: admin create_user missing session.flush() before write_audit_log
caused FK violation on PostgreSQL (silent on SQLite)
- Regression test: test_create_user_writes_audit_log in test_admin_api.py
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-31 11:00:45 +02:00
curo1305 and Claude Sonnet 4.6
1e4654aad5
docs(phase-6.1): update tracking after wave 1 — both plans complete
...
11 tests passing (7 shares + 4 audit), 309 total, 0 failures.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-30 23:18:04 +02:00
curo1305 and Claude Sonnet 4.6
12dd692f00
docs(05): mark phase 5 complete — 12/12 plans done, all UAT gaps resolved
...
Update STATE.md and ROADMAP.md to reflect plan 05-12 completion and Phase 5
as fully complete. All UAT gaps (OneDrive 500 → 400, cloud stream 500 → 502,
upload hint) resolved. 293 tests passing.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-30 17:56:18 +02:00
curo1305 and Claude Sonnet 4.6
f006c00d49
docs(05): create UAT gap closure plans 09-11
...
Three new plans address all 6 diagnosed gaps from 05-UAT.md:
- 05-09: cloud document open (fetch+Blob URL), re-analyze (cloud-aware
Celery task), and edit (PATCH /api/documents/{id})
- 05-10: OAuth initiate JSON response fix, Nextcloud custom endpoint
edit round-trip, Edit button on ERROR rows, confirmation text overflow
- 05-11: admin hard-delete with admin-password confirmation (backend
UserDeleteConfirm model + frontend inline panel)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-30 10:39:47 +02:00
curo1305
7691477c6d
docs(05): mark Phase 5 complete — all 8 plans executed, security gates passed, human checkpoint approved
...
- ROADMAP.md: all 05-01..05-08 plans marked [x], phase gates [x], Progress Table row updated to Complete 2026-05-29
- STATE.md: status→complete, completed_phases→5, percent→100, session continuity entry added
2026-05-29 09:16:45 +02:00
curo1305
c44e861271
docs(05-06): complete cloud upload/test integration plan — SUMMARY and STATE
...
- Create 05-06-SUMMARY.md: documents.py cloud extension + 20 passing cloud tests
- Update STATE.md: plan 5→6 of 8, session notes, next action → 05-07
- Update ROADMAP.md: mark 05-06 as complete [x]
2026-05-29 07:58:03 +02:00
curo1305
be6ff5a71f
docs(05-05): complete cloud API endpoints plan — SUMMARY and STATE
...
- Created 05-05-SUMMARY.md: cloud.py (7 endpoints), main.py (router registration), admin.py (SEC-09 cleanup)
- Updated STATE.md: plan advanced to 5/8, session log updated, decisions recorded
- Updated ROADMAP.md: 05-03, 05-04, 05-05 marked complete
- Updated REQUIREMENTS.md: SEC-09 marked complete (cloud credential purge on account deletion)
2026-05-29 07:34:22 +02:00
curo1305
3b84626da9
docs(05-02): complete shared cloud utilities plan
...
- 05-02-SUMMARY.md: full plan summary with TDD gate compliance, deviation docs, threat surface scan
- STATE.md: advanced to plan 26/32 (81%), updated session log, added 4 key decisions
- ROADMAP.md: marked 05-02 complete (2/8 Phase 5 plans done)
2026-05-28 21:04:03 +02:00
curo1305
664451b8e6
docs(05-01): complete Wave 0 Nyquist scaffold plan
...
- Create 05-01-SUMMARY.md documenting all 3 tasks and 5 files modified
- Update STATE.md: session record, progress 78% (25/32 plans), resume file → 05-02
- Update ROADMAP.md: Phase 5 progress (1/8 summaries, In Progress)
- Update REQUIREMENTS.md: mark CLOUD-01..07 complete (Wave 0 scaffold)
2026-05-28 20:54:51 +02:00
curo1305 and Claude Sonnet 4.6
d13801538d
fix(05): revise Phase 5 plans based on checker feedback — B1-B4, W1-W4
...
B1: Mark RESEARCH.md Open Questions as (RESOLVED) with decision text for all 3
B2: Backends now stateless — raise CloudConnectionError(reason=) only; API layer
in cloud.py owns token refresh + DB update via _call_cloud_op helper
B3: Add Task 3 to Plan 05 — cloud connection + object cleanup on account deletion (SEC-09)
B4: Add frontend_url setting to Plan 01 Task 1; Plan 05 uses settings.frontend_url
for OAuth callback redirects
W1: ROADMAP.md Phase 5 now correctly labels Plans 03+04 as Wave 3 (not Wave 2)
W2: Plan 06 invalid_grant test now asserts both 503 HTTP response AND DB REQUIRES_REAUTH
W3: Plan 06 Task 2 split into unit tests (4, cloud_utils.py) and integration tests (11, HTTP)
W4: Plan 07 adds Vitest tests for cloudConnections store (4 tests) and SettingsCloudTab
mount test (2 tests) per CLAUDE.md testing protocol
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-28 19:55:28 +02:00
curo1305 and Claude Sonnet 4.6
baa5bed7e2
docs(05): create phase 5 plan — cloud storage backends (8 plans, 7 waves)
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-28 19:43:12 +02:00
curo1305 and Claude Sonnet 4.6
d6f742a3c1
chore(phase-4): UAT complete — Phase 4 marked done, sidebar collapse, duplicate-folder fix
...
UAT: 14/15 passed. Bug fixed: folders/rootFolders array alias in fetchFolders caused
duplicate folder row on creation (rootFolders = [...list] breaks the shared reference).
Sidebar: Folders section now has a collapse/expand chevron, collapsed by default.
State: Phase 4 complete, Phase 5 (Cloud Storage Backends) is next.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-28 17:34:07 +02:00
curo1305
c6feb5faf2
docs(phase-4): complete 04-03-PLAN.md — Folders API + audit helper
...
- Create 04-03-SUMMARY.md with full frontmatter, decisions, threat surface scan
- Update STATE.md: plan 3/9, new decisions, session continuity
- Update ROADMAP.md: mark 04-01, 04-02, 04-03 plans complete (3/9)
- Update REQUIREMENTS.md: mark FOLD-01..FOLD-05 complete
2026-05-25 18:40:33 +02:00
curo1305 and Claude Sonnet 4.6
747303246a
docs(04): create phase 4 plan (9 plans, 7 waves)
...
Folders, Sharing, Quotas & Document UX — plans verified (0 blockers,
2 non-blocking warnings). Covers FOLD-01..05, SHARE-01..05, SEC-08/09,
ADMIN-06, DOC-01/02.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-25 18:20:16 +02:00
curo1305
6bd57629ce
docs(03-04): complete flat-file settings retirement and per-user AI classification plan
...
- 03-04-SUMMARY.md: Plan complete — classifier signature, env var defaults, security
mitigations T-03-17/18/19/21 all resolved; DOC-03, DOC-05 requirements completed
- STATE.md: Advance to Plan 4/5 complete, add 5 key decisions from this plan
- ROADMAP.md: Mark 03-04-PLAN.md complete (Wave 4)
- REQUIREMENTS.md: Mark DOC-03 and DOC-05 as complete
2026-05-23 20:39:33 +02:00
curo1305
aadc69fea0
docs(03-03): complete per-user document and topic isolation plan
...
- 03-03-SUMMARY.md: documents all endpoint auth guards, ownership assertions, namespace isolation pattern, and SQLite compat deviations
- STATE.md: advance to Plan 3/5 complete, add 6 key decisions (get_regular_user, 404-not-403, CASE WHEN, or_/is_(None), AI user namespace)
- ROADMAP.md: mark 03-03-PLAN.md complete
- REQUIREMENTS.md: mark SEC-04 and DOC-04 complete
2026-05-23 20:22:12 +02:00
curo1305
4e9b586ec4
docs(03-01): complete Wave 0 scaffolding plan — migration 0003 + xfail stubs
...
- Create 03-01-SUMMARY.md with all 19 new test IDs, task commits, and decisions
- Update STATE.md: phase 3 in progress, plan 1/5 complete, 3 new key decisions
- Update ROADMAP.md: mark 03-01-PLAN.md as complete (2026-05-23)
2026-05-23 13:48:07 +02:00
curo1305 and Claude Sonnet 4.6
fdc32d431d
docs(03): create Phase 3 execution plan — document migration & multi-user isolation
...
5 plans across 5 sequential waves covering: Alembic migration 0003 (null-user
cleanup, NOT NULL constraint, quota reconciliation), presigned MinIO PUT upload
flow with atomic quota enforcement, auth guards on all document/topic endpoints,
flat-file settings retirement + per-user AI classification, and frontend quota bar
with 3-step XHR upload progress.
Verification passed across all 12 dimensions. All 8 phase requirements covered
(STORE-03/04/05/06, SEC-04, DOC-03/04/05).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-23 13:36:28 +02:00
curo1305 and Claude Sonnet 4.6
f261c1a53b
docs(02): defer SC5 admin-JWT/document-403 to Phase 3 per D-07; clean STATE.md
...
SC5 admin JWT on /api/documents/* returning 403 is explicitly deferred to
Phase 3 SC4 (D-07: existing doc endpoints stay public until Phase 3 auth
enforcement). ROADMAP updated. Duplicate Open Questions removed from STATE.md.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-22 20:28:55 +02:00
curo1305
858be6260e
docs(02-05): execution summary and state update
...
- 02-05-SUMMARY.md: admin panel frontend complete — AdminView, three tab components, AppSidebar update
- STATE.md: Phase 2 complete (5/5 plans), progress 40%, decisions added
- ROADMAP.md: Phase 2 marked complete, all 5 plans checked
- REQUIREMENTS.md: ADMIN-01 through ADMIN-05 and ADMIN-07 marked complete
2026-05-22 20:12:05 +02:00
curo1305 and Claude Sonnet 4.6
3d487b82ef
docs(02-02): execution summary — auth API endpoints + frontend auth wall complete
...
Requirements completed: AUTH-01, AUTH-02, AUTH-04, SEC-01, SEC-02, SEC-03, SEC-05
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-22 19:48:33 +02:00
curo1305 and Claude Sonnet 4.6
16584ade00
docs(02): create phase 2 plan — Users & Authentication
...
5 plans across 5 waves covering AUTH-01..08, SEC-01..03/05..07,
ADMIN-01..05/07. Includes security hardening (Origin validation,
per-account rate limiting, TOTP replay prevention, refresh token
family revocation with security alert), TOTP + backup code login,
and admin panel frontend.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-22 19:13:44 +02:00
curo1305 and Claude Sonnet 4.6
16bb31eb6d
docs(01-05): complete walking-skeleton plan — SUMMARY, STATE, ROADMAP
...
Phase 1 complete: all 5/5 plans executed, walking-skeleton e2e verified
live against Docker stack (postgres + minio + redis + backend + celery-worker).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-22 14:19:41 +02:00
curo1305
5d21c6f588
docs(01-04): complete StorageBackend + MinIO + async storage plan — SUMMARY, STATE, ROADMAP
2026-05-22 09:41:43 +02:00
curo1305
e822a8f4b1
docs(01-03): complete SQLAlchemy ORM + Alembic plan — SUMMARY, STATE, ROADMAP
...
- SUMMARY.md: all 11 tables documented, privilege grants, verification results, deviations
- STATE.md: plan counter advanced to 3/5, decisions added, session continuity updated
- ROADMAP.md: 01-03-PLAN.md marked complete, progress table updated to 3/5
2026-05-22 09:33:24 +02:00
curo1305
213afec6b3
docs(01-02): complete Wave 0 test scaffolds plan — SUMMARY, STATE, ROADMAP
...
- Create 01-02-SUMMARY.md: 19 total xfail tests across 5 files, 3 task
commits documented, no deviations
- STATE.md: advance to plan 3/5, update progress to 40%, record decisions
for async_client naming and xfail(strict=False) pattern
- ROADMAP.md: mark 01-02-PLAN.md complete, update progress table to 2/5
2026-05-22 09:10:27 +02:00
curo1305
f9b8a0d1ca
docs(01-01): complete Compose + Config Foundation plan — SUMMARY, STATE, ROADMAP
...
- Create 01-01-SUMMARY.md with full execution record (3 tasks, 6 files)
- Update STATE.md: advance to plan 2 of 5, record key decisions, update session
- Update ROADMAP.md: mark 01-01 complete, update progress table (1/5 plans)
2026-05-22 09:01:16 +02:00
curo1305 and Claude Sonnet 4.6
6fed5ba531
docs(01): create phase 1 plan — 5 plans in 4 waves
...
Research, pattern mapping, and verification complete.
Walking Skeleton mode active (MVP Phase 1).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-22 08:49:36 +02:00
curo1305
3353387312
docs: create roadmap (5 phases)
2026-05-21 20:53:28 +02:00