Commit graph

264 commits

Author SHA1 Message Date
yun-zhi-ztl
cc11f2f023 fix(search): unify prefix vector search behavior 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
c9b49ad5b0 fix(auth): harden mock auth and rate limit auth flows 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
605634290a fix(publish): allow long skill descriptions 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
6e3582b4bc fix(admin): avoid runtime role helper dependency 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
984c25d104 fix(publish): reject oversized skill summaries 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
6a53a6f6c7 fix(admin): resolve user ids for role updates 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
149f811b43 fix(auth): localize password change feedback 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
1d983233de fix(auth): default new users to USER role 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
bace5f0b1b fix(my-skills): show pending skills after upload 2026-03-15 14:20:07 +08:00
yun-zhi-ztl
bf62b340ab fix: change api/v1/cli to api/v1 2026-03-14 20:35:50 +08:00
yun-zhi-ztl
9040b8ef3a chore(api): add concise logs for failed core requests 2026-03-14 20:01:45 +08:00
yun-zhi-ztl
a1083412e1 fix(stars): keep favorites data in sync 2026-03-14 19:51:06 +08:00
yun-zhi-ztl
05c4842ac5 fix(auth): validate email format on register 2026-03-14 19:47:02 +08:00
yun-zhi-ztl
bf319332c5 feat(token): paginate token list 2026-03-14 19:44:11 +08:00
yun-zhi-ztl
fc9bdffc7d fix(token): validate name length and uniqueness 2026-03-14 19:38:18 +08:00
yun-zhi-ztl
df850d1f63 fix(search): support short skill queries 2026-03-14 19:30:15 +08:00
yun-zhi-ztl
a5d6b6246b fix(auth): localize login errors and align API error handling 2026-03-14 19:05:20 +08:00
yun-zhi-ztl
188f6108d1 feat(auth): improve extensible login method metadata 2026-03-14 18:52:35 +08:00
yun-zhi-ztl
142685610a fix(test): update ReviewPermissionCheckerTest for stricter self-review policy
After merge, HEAD's ReviewPermissionChecker prohibits all self-review
(including SKILL_ADMIN/SUPER_ADMIN). Updated tests to reflect this
stricter security model from A2.
2026-03-14 17:52:56 +08:00
yun-zhi-ztl
a6cf862e8e merge(main): sync latest origin/main into feature/project-review
Resolved 9 conflicts according to documented strategy:
- .gitignore: kept both entries (docs/review/ + CLAUDE.md)
- ClawHubCompatController.java: manual merge (use @AuthenticationPrincipal + platformRoles)
- ClawHubCompatControllerTest.java: kept ours (HEAD security tests)
- CliControllerTest.java: kept ours (HEAD platform roles tests)
- ReviewPermissionChecker.java: kept ours (stricter permission model)
- SkillPublishService.java: kept theirs (main SUPER_ADMIN bypass + events)
- SkillPublishServiceTest.java: kept theirs (main complete test suite)
- router.tsx: manual merge (HEAD's createLazyRouteComponent + main's privacy/terms)
- markdown-renderer.tsx: kept ours (HEAD frontmatter stripping + styles)

All A1-A9 security fixes preserved. No new logic introduced.
2026-03-14 17:50:38 +08:00
wowo
b96126a267 Merge pull request #20 from iflytek/bugfix/require-auth-for-download
fix: require authentication for downloads and fix download count increment
2026-03-14 17:22:38 +08:00
yun-zhi-ztl
3a5e03fd63 Merge pull request #5 from iflytek/feature/projcet-clawhub
feat: add ClawHub registry compatibility layer for public skill installation
2026-03-14 02:21:06 -07:00
wowo-zZ
871278d43a fix(infra): add @Transactional to incrementDownloadCount
The @Modifying query requires a transaction context to execute.
Adding @Transactional at the repository method level ensures the
update query runs within a transaction, even when called from
async event listeners.

This fixes the issue where download counts were not being incremented
after skill downloads due to TransactionRequiredException.
2026-03-14 17:03:58 +08:00
wowo-zZ
56e7baed15 fix(auth): require authentication for skill downloads
- Remove download endpoints from permitAll list in SecurityConfig
- Add authentication checks to download tests
- Add login redirect for unauthenticated download attempts in frontend

This prevents unauthorized access to skill package downloads while
maintaining public access to skill metadata and file listings.
2026-03-14 16:54:10 +08:00
wowo-zZ
e97752735c fix(auth): improve logout flow to always redirect to home
- Use window.location.href for full page refresh
- Move redirect to finally block to ensure it always executes
- Fix V7 migration to be a no-op since column is already jsonb
2026-03-14 15:40:53 +08:00
wowo
bd87e701cf Merge pull request #14 from iflytek/feat/optimize-staging-build
feat: optimize development workflow with fast local dev and staging environments
2026-03-14 14:27:48 +08:00
wowo-zZ
5581bd6f06 feat(staging): optimize staging build with local Maven packaging
- Add server/Dockerfile.dev for fast local builds (JRE-only, ~70MB)
- Modify staging target to build JAR locally before Docker image
- Update .dockerignore to allow target/ directory for Dockerfile.dev
- Build time reduced from 17+ minutes to ~4 seconds
- Reuses local Maven cache (~/.m2/repository) instead of downloading in Docker
2026-03-14 14:21:06 +08:00
wowo-zZ
5254cd155e update 2026-03-14 13:54:39 +08:00
wowo-zZ
797cfc5272 feat(dev): add Spring Boot DevTools for fast restart in local dev 2026-03-14 13:23:50 +08:00
wowo-zZ
d631b0e20a fix(ops): resolve storage permission and audit log JSONB type issues
Fixes two critical issues when deploying with runtime.sh:

1. Storage Permission Error
   - Problem: AccessDeniedException when publishing skills
   - Root cause: /var/lib/skillhub/storage owned by root, but app runs as 'app' user
   - Solution: Pre-create storage directory with correct permissions in Dockerfile

2. Audit Log JSONB Type Error
   - Problem: PostgreSQL JSONB type mismatch when recording audit logs
   - Root cause: Missing type mapping annotation in AuditLog entity
   - Solution: Add @JdbcTypeCode(SqlTypes.JSON) annotation and V7 migration

Changes:
- server/Dockerfile: Add storage directory creation and permission setup
- server/skillhub-domain/.../AuditLog.java: Add @JdbcTypeCode annotation
- server/skillhub-app/.../V7__fix_audit_log_jsonb_type.sql: Migration for existing data

Impact:
- New deployments: Issues resolved automatically
- Existing deployments: Flyway auto-applies V7 migration on upgrade
2026-03-14 11:23:19 +08:00
vsxd
ac352314f7 Add extensible auth compatibility layer for private SSO 2026-03-13 18:00:22 +08:00
vsxd
9ae9b93ca7 Refine production compose runtime config 2026-03-13 17:00:47 +08:00
vsxd
14d86c290a chore(release): v0.1.0-beta.7 2026-03-13 16:05:08 +08:00
yun-zhi-ztl
f96fa74413 feat(compat): add clawhub registry adapter 2026-03-13 16:04:33 +08:00
vsxd
3682a4646b Auto-publish skills submitted by super admins 2026-03-13 15:36:56 +08:00
vsxd
d82665baba feat(review): allow admins to review their own submissions 2026-03-13 14:23:20 +08:00
yun-zhi-ztl
cab3bc3f8c Merge branch 'main' into feature/project-review 2026-03-13 13:21:51 +08:00
vsxd
763c908f74 Revert "fix(api): 统一所有分页接口为1-based page"
This reverts commit 3706e920df.
2026-03-13 12:56:29 +08:00
vsxd
3706e920df fix(api): 统一所有分页接口为1-based page
前端传 page=1 表示第一页,后端原来是 0-based 导致首页数据丢失。
涉及: SkillSearch, SkillController, ReviewController,
PromotionController, UserManagement, AuditLog
2026-03-13 12:56:23 +08:00
yun-zhi-ztl
447a34a1d1 merge(main): sync latest origin/main into feature/project-review 2026-03-13 12:49:12 +08:00
vsxd
a85a9c3177 fix(publish): 放宽技能包上传校验
- application.yml 补齐缺失的文件扩展名白名单(.js,.ts,.png,.jpg,.svg)
- version 为空时自动生成时间戳版本号,不再强制报错
2026-03-13 12:47:34 +08:00
vsxd
ac32fce08f fix(auth): preserve return target across oauth login 2026-03-13 11:59:17 +08:00
yun-zhi-ztl
556d556724 fix(token): align revoke endpoint with 204 contract
Change DELETE /api/v1/tokens/{id} to return HTTP 204 No Content so the backend matches the existing OpenAPI contract and the frontend delete flow no longer rejects successful revocations.

Add a controller regression test that verifies the endpoint returns 204 with an empty body and still delegates the revoke call to ApiTokenService. Verified with the targeted TokenControllerTest plus full server mvn test.
2026-03-13 11:49:57 +08:00
yun-zhi-ztl
383bc1edae fix(admin): replace compat and admin placeholders with real queries
Implement compat search through SkillSearchAppService instead of returning an empty placeholder list, and map search results back to canonical slugs for the compatibility API.

Replace hard-coded admin user and audit-log payloads with repository-backed application services. User management now supports paged search and status filters, validates managed statuses and role codes, prevents USER_ADMIN from assigning SUPER_ADMIN, and persists role/status changes against the real repositories. Audit logs now read from the audit_log table through a dedicated query repository/service with filterable pagination.

Align admin response DTOs with the frontend contract, add domain not-found handling for localized 404 responses, and cover the new behavior with controller and service regression tests. Verified with targeted skillhub-app tests plus full server mvn test.
2026-03-13 11:46:21 +08:00
vsxd
84dd08503d merge: bring feature/project-init into main for beta3
# Conflicts:
#	scripts/smoke-test.sh
2026-03-13 11:45:56 +08:00
vsxd
6a9e0845d4 Complete phase 3 and 4 backend workflows 2026-03-13 11:36:34 +08:00
vsxd
76808ca794 test(auth): align auth module tests with current flows 2026-03-13 11:32:50 +08:00
vsxd
5bb2eb0d98 fix(auth): grant global membership to new users 2026-03-13 11:29:01 +08:00
vsxd
0c5e4200cb fix(dev): provide explicit skill repository bean 2026-03-13 11:21:32 +08:00
yun-zhi-ztl
ad8bb9c6fd fix(security): whitelist only public skill GET routes
- require authentication for skill star and rating GET endpoints before the public skill-read rules

- keep documented public skill detail, version, download, resolve, and tag listing endpoints readable anonymously

- add regression coverage for anonymous star and rating access denial plus public tag listing
2026-03-13 11:12:18 +08:00