Brad Groux
1c96a326aa
Enforce v5 password-session boundary
...
Limit password-session cookies to local-owner loopback clients and document device/session-token requirements for remote and multi-user v5 GA access.
2026-06-05 14:53:17 -05:00
Brad Groux
438301dd1e
Add watcher continuation policy gates ( #591 )
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-04 16:01:16 -07:00
Brad Groux
fbfd9eb572
Detect duplicate task identities
2026-06-03 08:14:38 -07:00
Brad Groux
7fac1b8977
Add skill risk gates
2026-06-03 07:02:44 -07:00
Brad Groux
a9217784b3
Add skill security scanner ( #538 )
2026-06-03 06:33:05 -07:00
Brad Groux
4274171a8a
Add skill capability profiles
2026-06-03 06:09:29 -07:00
Brad Groux
abfac7c446
Add governance decision traces
2026-06-03 05:45:59 -07:00
Brad Groux
62f258052c
Add v5 maintenance center ( #535 )
2026-06-03 05:02:57 -07:00
Brad Groux
398ac2f606
Add v5 data lifecycle controls ( #533 )
2026-06-03 04:31:07 -07:00
Brad Groux
58f39ea2b5
Implement secure device pairing sessions
...
Add signed pairing-code exchange, hashed device session secrets, identity device session management, desktop pairing onboarding, docs, and regression coverage.
2026-06-03 02:02:22 -07:00
Brad Groux
847c9d1287
Document v5 remote server security posture
...
Adds the v5 remote/server-mode security posture ADR and links it from deployment, self-hosting, security, API reference, and GA checklist docs.
2026-06-03 01:25:02 -07:00
Brad Groux
28aee90b82
feat: add actor attribution and optimistic concurrency
...
## Summary
- adds task/comment/workflow revision metadata, ETag headers, and stale-write 409 conflict responses
- records actors on task, comment, activity, audit, and workflow API mutations
- sends cached revisions from web task/comment mutations and reloads the current task on conflicts
- documents the conflict contract and adds route/API regression coverage
## Verification
- `VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/tasks-coverage.test.ts server/src/__tests__/routes/optimistic-concurrency.test.ts`
- `node_modules/.bin/prettier --check server/src/__tests__/routes/tasks-coverage.test.ts`
- `pnpm --filter @veritas-kanban/server typecheck`
- `git diff --check`
- PR checks: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 10:54:53 -05:00
Brad Groux
022889bf26
feat: add SQLite migration recovery drills
...
## Summary
- adds migration journals, recovery-state reporting, and restore-from-pre-migration-backup service support
- exposes admin recovery and restore endpoints for SQLite migration rollback drills
- documents the v5 recovery contract, downgrade policy, and support bundle contents
- expands portability tests for completed journals, corrupt target failure recovery, rerun, restore, duplicate IDs, and missing attachment files
Closes #419 .
## Verification
- VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/sqlite-portability-service.test.ts
- pnpm --filter @veritas-kanban/server typecheck
- pnpm build
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- node_modules/.bin/prettier --check server/src/services/sqlite-portability-service.ts server/src/routes/sqlite-portability.ts server/src/__tests__/sqlite-portability-service.test.ts docs/API-REFERENCE.md docs/SQLITE-SCHEMA.md docs/MIGRATION-RECOVERY.md README.md
- git diff --check
## Notes
- pnpm audit --prod --audit-level=high passes the high-severity gate and still reports 3 moderate existing vulnerabilities.
- pnpm lint:budget passed with 705 warnings under the 714 warning budget.
2026-05-31 05:43:25 -05:00
Brad Groux
c40f378bb9
feat: add v5 auth permission context
...
## Summary
- adds a shared v5 auth context for REST requests and WebSocket connections
- adds role-derived permission sets plus an explicit `authorizePermission` guard for upcoming route migrations
- documents scoped CLI and MCP token expectations for v5 RBAC work
Refs #336 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- middleware/auth`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
## Notes
- This is a compatibility groundwork slice for #336 . It does not complete route-by-route permission enforcement, workspace filtering, or agent token scoping.
2026-05-31 02:35:24 -05:00
Brad Groux
b44efb8ade
feat: add multi-user identity APIs
...
## Summary
- adds the SQLite multi-user identity foundation migration for expanded workspace roles and workspace invitations
- adds SQLite identity repository/service support for local owner setup, workspace/profile reads, invitations, role updates, member removal, audit/activity recording, and invitation acceptance
- adds `/api/identity` and `/api/v1/identity` routes plus unauthenticated `/api/auth/invitations/accept`
- wires SQLite auth setup to ensure the local owner/default workspace exists
- includes identity tables in SQLite portability backups and documents the new identity API surface
Closes #335 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-identity-repository identity-service routes/identity`
- `pnpm --filter @veritas-kanban/server test -- sqlite-portability-service sqlite-storage routes/auth`
- `pnpm --filter @veritas-kanban/server test -- middleware/auth`
- `pnpm --filter @veritas-kanban/server test -- docker-paths`
- `pnpm --filter @veritas-kanban/server typecheck`
- `./node_modules/.bin/prettier --check docs/API-REFERENCE.md docs/SQLITE-SCHEMA.md server/src/routes/auth.ts server/src/routes/identity.ts server/src/routes/v1/index.ts server/src/services/activity-service.ts server/src/services/identity-service.ts server/src/services/sqlite-portability-service.ts server/src/storage/index.ts server/src/storage/sqlite/identity-repository.ts server/src/storage/sqlite/migrations.ts server/src/__tests__/identity-service.test.ts server/src/__tests__/routes/identity.test.ts server/src/__tests__/storage/sqlite-identity-repository.test.ts`
- `git diff --check`
- `pnpm lint:budget`
- `pnpm audit --prod --audit-level=high`
- `pnpm build`
## Notes
- `pnpm lint:budget` currently reports the existing 707 warnings against the 714-warning budget.
- `pnpm audit --prod --audit-level=high` exits cleanly with 3 moderate advisories reported.
- A full `pnpm test:unit` attempt reached 1,625 passing server tests and timed out on `docker-paths.test.ts`; the isolated `docker-paths` rerun passed and hosted Workspace Unit Tests are green.
- This is the management API/data foundation for #335 . Broad route-by-route RBAC enforcement remains in #336 .
2026-05-31 02:25:04 -05:00
Brad Groux
90793aeb54
feat: add SQLite migration backup API
...
## Summary
- adds an admin-only SQLite portability API for dry-run file migrations, migration runs, backup bundle export, and bundle import
- imports file-backed tasks, settings, templates, prompt registry data, telemetry, activity/status history, workflows, workflow runs, task chat, and squad messages into SQLite
- exports raw SQLite table snapshots plus human-readable task Markdown, config JSON, and workflow YAML, then rebuilds search indexes on import
- fixes squad transcript parsing so the first message after the file heading is preserved
- documents migration/recovery API usage and adds regression coverage for malformed input and backup round trips
Closes #333 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-portability-service`
- `pnpm --filter @veritas-kanban/server test -- chat-service`
- `pnpm --filter @veritas-kanban/server typecheck`
- `./node_modules/.bin/prettier --check docs/API-REFERENCE.md docs/SQLITE-SCHEMA.md server/src/routes/v1/index.ts server/src/routes/sqlite-portability.ts server/src/services/chat-service.ts server/src/services/sqlite-portability-service.ts server/src/__tests__/sqlite-portability-service.test.ts server/src/__tests__/chat-service.test.ts server/src/storage/index.ts`
- `git diff --check`
- `pnpm lint:budget`
- `pnpm audit --prod --audit-level=high`
- `pnpm build`
## Notes
- `pnpm lint:budget` currently reports 707 existing warnings against the 714-warning budget.
- `pnpm audit --prod --audit-level=high` exits cleanly with 3 moderate advisories reported.
2026-05-31 01:56:05 -05:00
Brad Groux
ef9e88ca1d
feat: add qmd index maintenance
2026-05-04 03:10:16 -05:00
Brad Groux
f0f7d7b03e
feat: add qmd search foundation
2026-05-04 02:35:00 -05:00
Brad Groux
70c8c06e56
docs: v4.0 documentation update and cleanup ( closes #229 ) ( #230 )
...
v4.0 docs update: CHANGELOG, README, FEATURES, API-REFERENCE, 11 new SOPs, MCP docs, version bumps to 4.0.0, docs cleanup. Closes #229 .
2026-03-21 12:20:16 -05:00
Brad Groux
d32f418c24
docs: comprehensive API-REFERENCE.md — add 15+ missing endpoint groups
...
- Add Task Verification, Task Comments, Task Subtasks, Task Deliverables,
Task Archive, Attachments, Agent Permissions, Agent Routing, Shared Resources,
Doc Freshness, Cost Prediction, Error Learning, Tool Policies, Traces,
Audit endpoint documentation
- Full request/response examples for each endpoint group
- Endpoint tables with Method/Path/Description for quick scanning
- Auth requirements noted (Audit = admin only)
- Update Table of Contents from 20 to 35 entries
- Version bump to 3.4.0, updated date to 2026-03-08
- Now covers all route files in server/src/routes/
2026-03-08 01:51:12 -06:00
BradGroux
0ed0064d85
docs: add canonical API Reference (docs/API-REFERENCE.md)
...
- Comprehensive endpoint catalog: tasks, time tracking, observations,
analytics, config, settings, hooks, chat/squad, agent status, auth,
telemetry, health, WebSocket
- Auth methods (Bearer, X-API-Key, WS query param), roles, permissions
- Error model and status codes
- Common workflows: agent task lifecycle, polling, blockers, webhooks
- Versioning/deprecation guidance and rate limits
- Linked from README docs map and GETTING-STARTED What's Next section
2026-03-02 01:25:25 -06:00