Commit graph

439 commits

Author SHA1 Message Date
Brad Groux
fbfd9eb572 Detect duplicate task identities 2026-06-03 08:14:38 -07:00
Brad Groux
ea352fcac9
Add orchestrator pipelines and product modes
Add first-class orchestrator pipeline metadata, OpenClaw audit recipe support, persisted product modes, and the related UI, docs, and regression coverage.
2026-06-03 07:34:51 -07:00
Brad Groux
7fac1b8977
Add skill risk gates 2026-06-03 07:02:44 -07:00
Brad Groux
a9217784b3
Add skill security scanner (#538) 2026-06-03 06:33:05 -07:00
Brad Groux
4274171a8a Add skill capability profiles 2026-06-03 06:09:29 -07:00
Brad Groux
abfac7c446 Add governance decision traces 2026-06-03 05:45:59 -07:00
Brad Groux
62f258052c
Add v5 maintenance center (#535) 2026-06-03 05:02:57 -07:00
Brad Groux
398ac2f606
Add v5 data lifecycle controls (#533) 2026-06-03 04:31:07 -07:00
Brad Groux
7d386659fb
Add v5 performance load coverage (#532) 2026-06-03 04:14:07 -07:00
Brad Groux
fd96f73408
Harden v5 security review surfaces (#531) 2026-06-03 03:55:22 -07:00
Brad Groux
0676970825
Harden realtime sync delivery
Harden realtime sync delivery for v5 remote multi-client use.
2026-06-03 03:31:29 -07:00
Brad Groux
58f39ea2b5
Implement secure device pairing sessions
Add signed pairing-code exchange, hashed device session secrets, identity device session management, desktop pairing onboarding, docs, and regression coverage.
2026-06-03 02:02:22 -07:00
Brad Groux
17799f3f72
Add workflow recipe authoring and dry-run linting
Adds workflow recipe authoring, visual/YAML dry-run linting, and output/schedule metadata for v5 workflows.
2026-06-03 01:12:57 -07:00
Brad Groux
07c8f85658
Add universal search command center (#524) 2026-06-03 00:38:41 -07:00
Brad Groux
de5183ed0e
Capture agent stream and retry trace events (#523)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-03 00:12:15 -07:00
Brad Groux
7b64a5388b
Add work product maintenance preview (#522) 2026-06-02 23:59:05 -07:00
Brad Groux
4d5243d980
Add task completion packets (#519) 2026-06-02 23:24:07 -07:00
Brad Groux
9a878242e5
Complete agent run timeline replay (#518) 2026-06-02 23:09:53 -07:00
Brad Groux
8d854a1786
Add task readiness start gate (#517) 2026-06-02 22:54:42 -07:00
Brad Groux
f4146b9b1f
Add agent timeline links and entry points
Enrich agent run timeline navigation and linked evidence from dashboard, workflow, notification, approval, and work-product surfaces.
2026-06-02 22:22:26 -07:00
Brad Groux
af7e68c541 Add agent run timeline replay view 2026-06-02 14:22:27 -07:00
Brad Groux
6c0a24c232
Migrate manage settings tab to Mantine (#486) 2026-06-01 00:09:24 -05:00
Brad Groux
f0dceac22f
Add macOS desktop release pipeline (#473) 2026-05-31 17:48:50 -05:00
Brad Groux
b8bd5b26ec Scaffold v5 desktop shell 2026-05-31 15:04:12 -05:00
Brad Groux
8ca08f316c Add scoped API token management 2026-05-31 12:49:46 -05:00
Brad Groux
28aee90b82
feat: add actor attribution and optimistic concurrency
## Summary

- adds task/comment/workflow revision metadata, ETag headers, and stale-write 409 conflict responses
- records actors on task, comment, activity, audit, and workflow API mutations
- sends cached revisions from web task/comment mutations and reloads the current task on conflicts
- documents the conflict contract and adds route/API regression coverage

## Verification

- `VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/tasks-coverage.test.ts server/src/__tests__/routes/optimistic-concurrency.test.ts`
- `node_modules/.bin/prettier --check server/src/__tests__/routes/tasks-coverage.test.ts`
- `pnpm --filter @veritas-kanban/server typecheck`
- `git diff --check`
- PR checks: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 10:54:53 -05:00
Brad Groux
cb70bc42f9
fix: tighten agent approval RBAC guards
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
## Summary

- splits agent register, permission, and routing route guards so read-like POSTs stay available without treating all agent self-service POSTs as read-only safe
- requires task:write for agent approval requests, telemetry:write for agent registration writes, and admin:manage for approval review/routing configuration/permission elevation
- mirrors the route guard changes in the shared CLI/MCP permission preflight map
- expands REST, CLI, and MCP authorization tests for read-only mutation denial and scoped agent approval requests

Closes #336.

## Verification

- VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts
- node scripts/check-permission-coverage.mjs
- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/server typecheck
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm build
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- node_modules/.bin/prettier --check server/src/routes/v1/permissions.ts server/src/routes/v1/index.ts shared/src/utils/api-permissions.ts server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts docs/security.md
- git diff --check

## Notes

- pnpm audit --prod --audit-level=high passes the high-severity gate and still reports 3 moderate existing vulnerabilities.
- pnpm lint:budget passed with 705 warnings under the 714 warning budget.
- pnpm --filter @veritas-kanban/mcp typecheck is not available because the package has no typecheck script; pnpm --filter @veritas-kanban/mcp build covers TypeScript compilation.
2026-05-31 05:53:32 -05:00
Brad Groux
022889bf26
feat: add SQLite migration recovery drills
## Summary

- adds migration journals, recovery-state reporting, and restore-from-pre-migration-backup service support
- exposes admin recovery and restore endpoints for SQLite migration rollback drills
- documents the v5 recovery contract, downgrade policy, and support bundle contents
- expands portability tests for completed journals, corrupt target failure recovery, rerun, restore, duplicate IDs, and missing attachment files

Closes #419.

## Verification

- VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/sqlite-portability-service.test.ts
- pnpm --filter @veritas-kanban/server typecheck
- pnpm build
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- node_modules/.bin/prettier --check server/src/services/sqlite-portability-service.ts server/src/routes/sqlite-portability.ts server/src/__tests__/sqlite-portability-service.test.ts docs/API-REFERENCE.md docs/SQLITE-SCHEMA.md docs/MIGRATION-RECOVERY.md README.md
- git diff --check

## Notes

- pnpm audit --prod --audit-level=high passes the high-severity gate and still reports 3 moderate existing vulnerabilities.
- pnpm lint:budget passed with 705 warnings under the 714 warning budget.
2026-05-31 05:43:25 -05:00
Brad Groux
f7cff20cd8
test: add v5 dual-storage parity gate
## Summary

- adds the v5 dual-storage parity fixture and focused parity test suite
- covers rich task metadata, archive lifecycle, comments/chat history, settings/templates, prompt usage, telemetry/activity/status history, and a workflow run
- adds an explicit CI parity step for file and SQLite storage drift
- preserves newer file-mode task metadata on reload and stabilizes SQLite chat ordering
- hardens workflow parity polling for asynchronous run writes

## Verification

- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
- Local focused parity test, server typecheck, lint budget, build, and audit high gate
2026-05-31 05:26:10 -05:00
Brad Groux
3f5c9a03af
feat: enforce CLI and MCP token permissions
## Summary

- adds a shared client-side API permission mapper and guarded API client for CLI and MCP calls
- exposes a non-secret /api/auth/context endpoint for scoped token preflight
- routes CLI and MCP task lookup helpers through the guarded client
- preflights direct summary text fetches that bypass the JSON API helper
- adds focused CLI and MCP token authorization coverage and documents the behavior

Refs #336.

## Verification

- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm --filter @veritas-kanban/server typecheck
- focused CLI and MCP api-permissions tests
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- pnpm build
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:35:10 -05:00
Brad Groux
b615052d4a
feat: filter WebSocket events by permissions
## Summary

- adds a shared WebSocket delivery gate for workspace and permission checks
- filters task, chat, squad, telemetry, broadcast, workflow, and agent-status fanout by authenticated capabilities
- gates chat and task-output subscriptions behind task read access
- adds broadcast coverage for workspace and permission filtering

Refs #336.

## Verification

- ./node_modules/.bin/vitest run server/src/__tests__/broadcast-service.test.ts
- pnpm --filter @veritas-kanban/server typecheck
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- pnpm build
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:23:02 -05:00
Brad Groux
90da5149ec
feat: add REST route permission guards
## Summary

- adds method/path-aware permission middleware for explicit REST read, write, and execute requirements
- maps the v1 route registry to permission presets across task, settings, agent, telemetry, report, policy, workflow, backup, and workspace surfaces
- preserves read-like POST behavior for search, workflow execution, report/scoring generation, policy evaluation, and prompt preview/usage routes
- uses v5 auth user IDs for workflow ACL checks when available
- adds focused coverage for permission selection and v1 route preset behavior

Refs #336.

## Verification

- `./node_modules/.bin/vitest run server/src/__tests__/middleware/auth.test.ts server/src/__tests__/routes/v1-permission-guards.test.ts`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm lint:budget` (708 warnings, budget 714)
- `pnpm audit --prod --audit-level=high` (3 moderate advisories, high gate passes)
- `pnpm build`
- `./node_modules/.bin/prettier --check server/src/middleware/auth.ts server/src/routes/v1/index.ts server/src/routes/v1/permissions.ts server/src/__tests__/middleware/auth.test.ts server/src/__tests__/routes/v1-permission-guards.test.ts server/src/routes/workflows.ts`
- `git diff --check`
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:13:07 -05:00
Brad Groux
e97d01846a
feat: add SQLite provenance queries
## Summary

- adds a SQLite operational provenance repository with bounded task, run, and recent artifact queries
- exposes lightweight provenance metadata for work products, task deliverables, attachments, workflow runs, scheduled run snapshots, notifications, and task chat messages without returning raw JSON payloads
- wires the provenance repository into the SQLite storage provider
- documents the query surface in the SQLite schema guide

Closes #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- Local: `./node_modules/.bin/vitest run server/src/__tests__/storage/sqlite-provenance-repository.test.ts`
- Local: `pnpm --filter @veritas-kanban/server typecheck`
- Local: `pnpm lint:budget`
- Local: `pnpm audit --prod --audit-level=high`
- Local: `pnpm build`
- Local: prettier check for changed files
- Local: `git diff --check`
2026-05-31 03:52:38 -05:00
Brad Groux
c40f378bb9
feat: add v5 auth permission context
## Summary

- adds a shared v5 auth context for REST requests and WebSocket connections
- adds role-derived permission sets plus an explicit `authorizePermission` guard for upcoming route migrations
- documents scoped CLI and MCP token expectations for v5 RBAC work

Refs #336.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- middleware/auth`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`

## Notes

- This is a compatibility groundwork slice for #336. It does not complete route-by-route permission enforcement, workspace filtering, or agent token scoping.
2026-05-31 02:35:24 -05:00
Brad Groux
b44efb8ade
feat: add multi-user identity APIs
## Summary

- adds the SQLite multi-user identity foundation migration for expanded workspace roles and workspace invitations
- adds SQLite identity repository/service support for local owner setup, workspace/profile reads, invitations, role updates, member removal, audit/activity recording, and invitation acceptance
- adds `/api/identity` and `/api/v1/identity` routes plus unauthenticated `/api/auth/invitations/accept`
- wires SQLite auth setup to ensure the local owner/default workspace exists
- includes identity tables in SQLite portability backups and documents the new identity API surface

Closes #335.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-identity-repository identity-service routes/identity`
- `pnpm --filter @veritas-kanban/server test -- sqlite-portability-service sqlite-storage routes/auth`
- `pnpm --filter @veritas-kanban/server test -- middleware/auth`
- `pnpm --filter @veritas-kanban/server test -- docker-paths`
- `pnpm --filter @veritas-kanban/server typecheck`
- `./node_modules/.bin/prettier --check docs/API-REFERENCE.md docs/SQLITE-SCHEMA.md server/src/routes/auth.ts server/src/routes/identity.ts server/src/routes/v1/index.ts server/src/services/activity-service.ts server/src/services/identity-service.ts server/src/services/sqlite-portability-service.ts server/src/storage/index.ts server/src/storage/sqlite/identity-repository.ts server/src/storage/sqlite/migrations.ts server/src/__tests__/identity-service.test.ts server/src/__tests__/routes/identity.test.ts server/src/__tests__/storage/sqlite-identity-repository.test.ts`
- `git diff --check`
- `pnpm lint:budget`
- `pnpm audit --prod --audit-level=high`
- `pnpm build`

## Notes

- `pnpm lint:budget` currently reports the existing 707 warnings against the 714-warning budget.
- `pnpm audit --prod --audit-level=high` exits cleanly with 3 moderate advisories reported.
- A full `pnpm test:unit` attempt reached 1,625 passing server tests and timed out on `docker-paths.test.ts`; the isolated `docker-paths` rerun passed and hosted Workspace Unit Tests are green.
- This is the management API/data foundation for #335. Broad route-by-route RBAC enforcement remains in #336.
2026-05-31 02:25:04 -05:00
Brad Groux
90793aeb54
feat: add SQLite migration backup API
## Summary

- adds an admin-only SQLite portability API for dry-run file migrations, migration runs, backup bundle export, and bundle import
- imports file-backed tasks, settings, templates, prompt registry data, telemetry, activity/status history, workflows, workflow runs, task chat, and squad messages into SQLite
- exports raw SQLite table snapshots plus human-readable task Markdown, config JSON, and workflow YAML, then rebuilds search indexes on import
- fixes squad transcript parsing so the first message after the file heading is preserved
- documents migration/recovery API usage and adds regression coverage for malformed input and backup round trips

Closes #333.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-portability-service`
- `pnpm --filter @veritas-kanban/server test -- chat-service`
- `pnpm --filter @veritas-kanban/server typecheck`
- `./node_modules/.bin/prettier --check docs/API-REFERENCE.md docs/SQLITE-SCHEMA.md server/src/routes/v1/index.ts server/src/routes/sqlite-portability.ts server/src/services/chat-service.ts server/src/services/sqlite-portability-service.ts server/src/__tests__/sqlite-portability-service.test.ts server/src/__tests__/chat-service.test.ts server/src/storage/index.ts`
- `git diff --check`
- `pnpm lint:budget`
- `pnpm audit --prod --audit-level=high`
- `pnpm build`

## Notes

- `pnpm lint:budget` currently reports 707 existing warnings against the 714-warning budget.
- `pnpm audit --prod --audit-level=high` exits cleanly with 3 moderate advisories reported.
2026-05-31 01:56:05 -05:00
Brad Groux
b502872b49
feat: add durable work product foundation
Summary:
- adds typed durable work product render contracts
- adds SQLite work_products, work_product_versions, and work_product_search storage
- adds create, list, refine, archive, restore, preview, and export APIs
- wires work products into task-scoped APIs and keyword search
- adds redacted preview/export behavior and SQLite regression coverage
- documents the work product API and SQLite schema

Verification:
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- ./node_modules/.bin/prettier --check README.md docs/SQLITE-SCHEMA.md docs/features/work-products.md shared/src/types/work-product.types.ts shared/src/types/index.ts server/src/schemas/work-product-schemas.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/work-product-repository.ts server/src/services/work-product-service.ts server/src/routes/work-products.ts server/src/routes/v1/index.ts server/src/routes/search.ts server/src/services/search-service.ts server/src/__tests__/storage/sqlite-work-products.test.ts
- pnpm --filter @veritas-kanban/server test -- sqlite-work-products
- pnpm typecheck
- pnpm lint:budget
- pnpm --filter @veritas-kanban/server test
- pnpm build
- pnpm audit --prod --audit-level=high
- git diff --check

Part of #403.
Part of #332.
2026-05-31 01:31:00 -05:00
Brad Groux
277dc6608e
feat: load dashboard metrics from sqlite telemetry
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
Summary:
- read dashboard telemetry from SQLite telemetry_events in SQLite mode
- route dashboard metrics, trends, agent comparison, task cost, and utilization through the shared active-backend reader
- add SQLite regression coverage for metrics and trends without telemetry files
- document the SQLite dashboard aggregation path

Verification:
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- ./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/services/metrics/telemetry-reader.ts server/src/services/metrics/dashboard-metrics.ts server/src/__tests__/storage/sqlite-dashboard-metrics.test.ts
- pnpm --filter @veritas-kanban/server test -- sqlite-dashboard-metrics
- pnpm typecheck
- pnpm lint:budget
- pnpm --filter @veritas-kanban/server test
- pnpm build
- pnpm audit --prod --audit-level=high
- git diff --check

Part of #332.
2026-05-31 01:05:55 -05:00
Brad Groux
39d9b907d3
feat: add SQLite task artifact metadata
## Summary

- adds SQLite migration 0012 for normalized task attachment and task deliverable metadata
- mirrors attachment validation, hash/path, retention, owner/session, and cleanup fields from task JSON into queryable SQLite rows
- adds deliverable provenance fields for model/source run/redaction/version metadata and stores them in SQLite
- updates task artifact schema docs and adds repository coverage for child row sync

Part of #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-task-repository`
- `pnpm typecheck`
- `pnpm lint:budget`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/__tests__/storage/sqlite-task-repository.test.ts server/src/routes/task-deliverables.ts server/src/schemas/deliverable-schemas.ts server/src/services/attachment-service.ts server/src/services/clawdbot-agent-service.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/task-repository.ts shared/src/types/task.types.ts shared/src/types/task.types.d.ts`
- `git diff --check`

## Notes

- Attachment binary blobs remain on disk; this slice persists metadata in SQLite for query, migration, backup/import, and cleanup workflows.
2026-05-31 00:47:56 -05:00
Brad Groux
5b45fa1788
feat: add SQLite scheduled deliverable repositories
## Summary

- adds SQLite tables and repository storage for scheduled deliverables and recurring run history
- wires ScheduledDeliverablesService into SQLite mode while preserving JSON file mode and configurable file paths
- captures stable scheduled-run snapshots with source workflow/run IDs, output metadata, summary, duration, and audit-safe snapshot metadata
- adds restart-style SQLite coverage for schedules, filters, run history, snapshots, and no JSON-file writes
- documents the scheduled deliverable repository schema mapping

Part of #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-scheduled-deliverables-repository.test.ts`
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
- `git diff --cached --check`

## Notes

- The production audit currently reports only moderate vulnerabilities.
2026-05-31 00:33:29 -05:00
Brad Groux
d168ac6e4c
feat: add SQLite notification repositories
## Summary

- adds SQLite tables and repository storage for notification inbox records and thread subscriptions
- wires NotificationService into SQLite mode while preserving JSON file mode and existing file-path test options
- preserves direct notification metadata including type, title, task title, project, target URL, dedupe key, and source metadata
- adds restart-style SQLite coverage for mentions, assignments, direct notifications, delivered state, stats, and subscriptions
- documents the notification repository schema mapping

Part of #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-notification-repositories.test.ts src/__tests__/notification-service.test.ts src/__tests__/failure-alert-service.test.ts src/__tests__/routes/notifications-coverage.test.ts`
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
- `git diff --cached --check`

## Notes

- The production audit currently reports only moderate vulnerabilities.
2026-05-31 00:22:30 -05:00
Brad Groux
a59f1d42d1
feat: add SQLite chat repositories
## Summary

- adds SQLite tables and repositories for board chat sessions, task chat messages, and squad chat messages
- wires ChatService into SQLite mode while leaving Markdown file mode as the default
- adds restart-style SQLite coverage proving board chat, task chat, and squad chat persist without markdown files
- documents the chat repository schema mapping

Part of #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-chat-repositories.test.ts src/__tests__/chat-service.test.ts src/__tests__/routes/chat.test.ts`
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 23:51:15 -05:00
Brad Groux
ea1e69dadc
feat: add SQLite workflow repositories
## Summary

- adds SQLite tables and repositories for workflow definitions, ACLs, audit events, run state, and workflow snapshots
- wires workflow definition and run services into SQLite mode while keeping file mode as the default
- adds SQLite repository tests plus an execution-path test for start, retry, block, resume, and complete behavior
- documents the workflow repository schema mapping

Part of #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-workflow-repositories.test.ts src/__tests__/storage/sqlite-workflow-run-execution.test.ts src/__tests__/workflow-service.test.ts src/__tests__/workflow-run-service.test.ts`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 22:56:20 -05:00
Brad Groux
e24c7abfd6
feat: add SQLite audit and policy repositories
## Summary

- adds v7 SQLite tables and repositories for audit entries, agent policies, and tool policies
- routes audit logging, policy service, and tool policy service to SQLite when configured while preserving file-backed defaults
- keeps audit hash-chain verification and recent-entry reads working in SQLite mode
- adds SQLite coverage for audit persistence, agent policy CRUD/evaluation, tool policy CRUD/access filters, and no file writes
- documents the audit/policy tables in the SQLite schema notes

Part of #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-audit-policy-repositories.test.ts`
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-audit-policy-repositories.test.ts src/__tests__/services/audit-service.test.ts src/__tests__/services/policy-service.test.ts`
- `./node_modules/.bin/eslint server/src/__tests__/storage/sqlite-audit-policy-repositories.test.ts server/src/services/audit-service.ts server/src/services/policy-service.ts server/src/services/tool-policy-service.ts server/src/storage/index.ts server/src/storage/sqlite/audit-policy-repositories.ts server/src/storage/sqlite/migrations.ts --quiet`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm typecheck`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 22:25:14 -05:00
Brad Groux
1bcb4087eb
feat: add SQLite governance repositories
## Summary

- adds v6 SQLite governance tables and repository implementations for decisions, feedback, scoring, and drift data
- routes DecisionService, FeedbackService, ScoringService, and DriftService to SQLite when configured while preserving file-backed defaults
- adds SQLite coverage for decision chains, feedback analytics, scoring history, drift alerts and baselines, and no file writes
- documents the governance repository tables in the SQLite schema notes

Part of #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-governance-repositories.test.ts`
- `pnpm typecheck`
- `./node_modules/.bin/eslint server/src/__tests__/storage/sqlite-governance-repositories.test.ts server/src/services/decision-service.ts server/src/services/feedback-service.ts server/src/services/scoring-service.ts server/src/services/drift-service.ts server/src/storage/index.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/governance-repositories.ts --quiet`
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-governance-repositories.test.ts src/__tests__/decision-service.test.ts src/__tests__/feedback-service.test.ts src/__tests__/scoring-service.test.ts src/__tests__/drift-service.test.ts`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 22:10:57 -05:00
Brad Groux
df54a42de7
feat: add SQLite operational history repositories
## Summary

- adds SQLite migration/table support for activity events, status history, and telemetry events
- wires ActivityService, StatusHistoryService, TelemetryService, and SqliteStorageProvider to use SQLite repositories in sqlite mode
- keeps file storage explicitly file-backed and adds regression coverage that sqlite mode does not create JSON/NDJSON operational files
- documents the operational repository slice in the v5 SQLite schema plan

Part of #332.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-operational-repositories.test.ts src/__tests__/storage/sqlite-storage.test.ts`
- `pnpm typecheck`
- `./node_modules/.bin/eslint server/src/__tests__/storage/sqlite-storage.test.ts server/src/__tests__/storage/sqlite-operational-repositories.test.ts server/src/services/activity-service.ts server/src/services/status-history-service.ts server/src/services/telemetry-service.ts server/src/storage/file-storage.ts server/src/storage/index.ts server/src/storage/interfaces.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/activity-repository.ts server/src/storage/sqlite/status-history-repository.ts server/src/storage/sqlite/telemetry-repository.ts --quiet`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 21:50:48 -05:00
Brad Groux
bcf7110b96
feat: add SQLite configuration repositories
## Summary

- adds SQLite migration/table support for app config, managed lists, task templates, prompt templates, prompt versions, and prompt usage
- wires ConfigService, ManagedListService, TemplateService, and PromptRegistryService into SQLite mode while preserving file-backed behavior
- exposes repository/provider implementations and documents the runtime schema
- adds SQLite configuration repository coverage and removes file-backed template constructor directory races

Closes #331.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/services/config-service.ts server/src/services/managed-list-service.ts server/src/services/prompt-registry-service.ts server/src/services/template-service.ts server/src/storage/file-storage.ts server/src/storage/index.ts server/src/storage/interfaces.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/managed-list-repository.ts server/src/storage/sqlite/prompt-registry-repository.ts server/src/storage/sqlite/settings-repository.ts server/src/storage/sqlite/template-repository.ts server/src/__tests__/storage/sqlite-config-repositories.test.ts`
- `./node_modules/.bin/eslint server/src/services/config-service.ts server/src/services/managed-list-service.ts server/src/services/prompt-registry-service.ts server/src/services/template-service.ts server/src/storage/file-storage.ts server/src/storage/index.ts server/src/storage/interfaces.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/managed-list-repository.ts server/src/storage/sqlite/prompt-registry-repository.ts server/src/storage/sqlite/settings-repository.ts server/src/storage/sqlite/template-repository.ts server/src/__tests__/storage/sqlite-config-repositories.test.ts --quiet`
- `pnpm --filter @veritas-kanban/server test -- src/__tests__/prompt-registry-service.test.ts src/__tests__/template-service.test.ts src/__tests__/storage/sqlite-config-repositories.test.ts`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm typecheck`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- Live SQLite API smoke for `/api/settings/features`, `/api/projects`, `/api/templates`, `/api/prompt-registry`, prompt versions, prompt usage, prompt stats, and schema row counts
2026-05-30 20:49:35 -05:00
Brad Groux
df9c29cf05
feat: add SQLite task repository parity
## Summary

- adds the v5 SQLite task table, indexed task columns, and FTS5 task_search migration
- adds SqliteTaskRepository for full task JSON persistence plus active/archive/backlog state helpers
- wires TaskService SQLite mode for create/list/read/update/delete/archive/restore/reorder without task markdown writes
- preserves serialized task mutations in SQLite mode and adds repository, service, and route-shape coverage
- documents the task repository storage strategy in the SQLite schema guide

Closes #330.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/services/task-service.ts server/src/storage/index.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/task-repository.ts server/src/__tests__/storage/sqlite-task-repository.test.ts server/src/__tests__/task-service-sqlite.test.ts server/src/__tests__/routes/tasks-sqlite.test.ts`
- `./node_modules/.bin/eslint server/src/services/task-service.ts server/src/storage/index.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/task-repository.ts server/src/__tests__/storage/sqlite-task-repository.test.ts server/src/__tests__/task-service-sqlite.test.ts server/src/__tests__/routes/tasks-sqlite.test.ts --quiet`
- `pnpm lint`
- `pnpm lint:budget`
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm --filter @veritas-kanban/server test -- src/__tests__/storage/sqlite-task-repository.test.ts src/__tests__/task-service-sqlite.test.ts src/__tests__/routes/tasks-sqlite.test.ts`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- live SQLite API smoke: POST/GET `/api/tasks` with `VERITAS_STORAGE=sqlite`, verified only `veritas.db` was created under the data dir

## Notes

- The production audit gate reports 3 moderate vulnerabilities and no high/critical failures.
2026-05-30 20:01:43 -05:00
Brad Groux
ec6bc83fd2
feat: add SQLite storage foundation
## Summary

- adds a dependency-free Node `node:sqlite` database foundation with safe PRAGMAs, schema_migrations tracking, checksum validation, and transactional migration rollback
- adds the SQLite storage provider shell, lifecycle shutdown, and isolated SQLite test helpers while file repositories remain the default behavior
- wires `VERITAS_STORAGE=file|sqlite` plus `VERITAS_SQLITE_PATH` through env validation, docs, and server startup/shutdown

Closes #329.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Workspace Unit Tests
- CI: Security Audit
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/config/env.ts server/src/index.ts server/src/storage/index.ts server/src/storage/sqlite/database.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/test-helpers.ts server/src/__tests__/config/env.test.ts server/src/__tests__/storage/sqlite-database.test.ts server/src/__tests__/storage/sqlite-storage.test.ts`
- `./node_modules/.bin/eslint server/src --ext .ts --quiet`
- `pnpm --filter @veritas-kanban/server test -- src/__tests__/storage/sqlite-database.test.ts src/__tests__/storage/sqlite-storage.test.ts src/__tests__/config/env.test.ts`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm --filter @veritas-kanban/server build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
- SQLite startup smoke with `VERITAS_STORAGE=sqlite` against a fresh temp data dir and `/api/health` returning ok

## Notes

- File storage remains the default until the provider parity and migration/import issues land. SQLite mode currently owns database lifecycle and migrations, then delegates existing repositories to file storage.
2026-05-30 17:39:23 -05:00
Brad Groux
92b573ab18 chore: bump version to 4.3.2
Some checks failed
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
2026-05-16 19:10:53 -05:00