Commit graph

43 commits

Author SHA1 Message Date
Brad Groux
37d256a3a6
feat: add harness compatibility matrix (#976) 2026-07-24 09:01:43 -05:00
Brad Groux
9a9db9b5b6
feat: add ACP server view (#960) (#967) 2026-07-24 07:23:45 -05:00
Brad Groux
0fbd9ee428
feat: add run-scoped tool control plane (#959)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Changed Tests (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
Desktop Artifacts / Unsigned macOS Artifact (push) Waiting to run
Desktop Artifacts / Unsigned Linux Artifacts (push) Waiting to run
Desktop Artifacts / Unsigned Windows Artifacts (push) Waiting to run
* feat: add run-scoped tool control plane (#857)

* test: align provider capability fixtures
2026-07-24 05:10:20 -05:00
Brad Groux
6b9510c58f
feat: add provider-neutral conversation lifecycle (#856) (#958) 2026-07-24 04:07:40 -05:00
Brad Groux
54417357f9
feat: add secure Buzz connection diagnostics (#946) 2026-07-23 22:07:25 -05:00
Brad Groux
9f51d78c50
feat: add immutable run launch manifests (#926)
Closes #854.
2026-07-23 16:00:23 -05:00
Brad Groux
e6f21a849d
feat: add first-class harness support profiles (#925)
Closes #919. Adds versioned support evidence, fail-closed dispatch, redacted diagnostics, and shared API, CLI, and Settings status.
2026-07-23 14:52:07 -05:00
Brad Groux
b704ab92d0
feat: add provider-neutral task envelope contracts (#891) (#894)
Some checks failed
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-16 12:48:48 -05:00
Brad Groux
566ec0f7fe
feat: enforce provider runtime manifests (#887) (#890)
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-16 11:00:44 -05:00
Brad Groux
44d1611741
feat: add governed SQLite journal maintenance (#884)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
* feat: add governed SQLite journal maintenance

* fix: update permission coverage for SQLite maintenance

---------

Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-15 20:00:58 -05:00
Brad Groux
9abd06dd0e
Add policy-gated queue intake monitors
Add GitHub-backed queue monitor service, APIs, CLI commands, Settings queue dashboard, scheduler integration, operations digest activity, tests, and documentation.
2026-06-26 11:40:11 -05:00
Brad Groux
5b363303c4
Add unified recurring work scheduler
Add scheduler APIs, CLI commands, settings UI, retry/event state, telemetry hooks, and documentation over scheduled deliverables and workflow schedules.
2026-06-26 11:06:45 -05:00
Brad Groux
fbff5b5c40
Add workspace capability discovery and intake
Add config-backed workspace capability discovery, trusted intake APIs, CLI commands, settings UI, and delegated work status links.
2026-06-26 10:45:47 -05:00
Brad Groux
4a0c66d331
Add reusable agent profile packages (#729)
* Add reusable agent profile packages

* Add profile CLI permission coverage
2026-06-18 15:53:47 -05:00
dependabot[bot]
31359ebebf
build(deps): bump @eslint/js to 10.0.1
* build(deps-dev): bump @eslint/js from 9.38.0 to 10.0.1

Bumps [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js) from 9.38.0 to 10.0.1.
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/commits/v10.0.1/packages/js)

---
updated-dependencies:
- dependency-name: "@eslint/js"
  dependency-version: 10.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* Resolve eslint js 10 lint failures

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Brad Groux <3053586+BradGroux@users.noreply.github.com>
2026-06-09 06:16:16 -05:00
Brad Groux
446def7e8d
Add configurable board columns
Adds configurable board columns and dynamic task statuses across the board, server validation, summaries, CLI, MCP, and docs.

Closes #640.
2026-06-05 11:44:10 -05:00
Brad Groux
2cd7fe2ad2 Add prompt template import command 2026-06-04 01:01:14 -07:00
Brad Groux
eb7085a34a Add redacted runtime snapshot command 2026-06-04 00:45:31 -07:00
Brad Groux
5c6ca0651d Add vk doctor setup health command 2026-06-04 00:29:32 -07:00
Brad Groux
a42988a3e2 Ratcheting lint warning budget 2026-06-04 00:16:42 -07:00
Brad Groux
cb70bc42f9
fix: tighten agent approval RBAC guards
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
## Summary

- splits agent register, permission, and routing route guards so read-like POSTs stay available without treating all agent self-service POSTs as read-only safe
- requires task:write for agent approval requests, telemetry:write for agent registration writes, and admin:manage for approval review/routing configuration/permission elevation
- mirrors the route guard changes in the shared CLI/MCP permission preflight map
- expands REST, CLI, and MCP authorization tests for read-only mutation denial and scoped agent approval requests

Closes #336.

## Verification

- VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts
- node scripts/check-permission-coverage.mjs
- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/server typecheck
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm build
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- node_modules/.bin/prettier --check server/src/routes/v1/permissions.ts server/src/routes/v1/index.ts shared/src/utils/api-permissions.ts server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts docs/security.md
- git diff --check

## Notes

- pnpm audit --prod --audit-level=high passes the high-severity gate and still reports 3 moderate existing vulnerabilities.
- pnpm lint:budget passed with 705 warnings under the 714 warning budget.
- pnpm --filter @veritas-kanban/mcp typecheck is not available because the package has no typecheck script; pnpm --filter @veritas-kanban/mcp build covers TypeScript compilation.
2026-05-31 05:53:32 -05:00
Brad Groux
3f5c9a03af
feat: enforce CLI and MCP token permissions
## Summary

- adds a shared client-side API permission mapper and guarded API client for CLI and MCP calls
- exposes a non-secret /api/auth/context endpoint for scoped token preflight
- routes CLI and MCP task lookup helpers through the guarded client
- preflights direct summary text fetches that bypass the JSON API helper
- adds focused CLI and MCP token authorization coverage and documents the behavior

Refs #336.

## Verification

- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm --filter @veritas-kanban/server typecheck
- focused CLI and MCP api-permissions tests
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- pnpm build
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:35:10 -05:00
Brad Groux
d3976f1d74 chore: harden audit findings and release QA
Add release validation and scheduled QA workflows.

Harden webhook URL handling, API helper edge cases, and runtime version reporting.

Split heavy web bundles, centralize view metadata, and stabilize full-suite tests.
2026-05-16 18:59:40 -05:00
Brad Groux
578269963a
Clarify setup paths and integration auth
Clarify setup paths, integration auth behavior, and communication docs.
2026-05-13 14:21:30 -05:00
Brad Groux
f7d2dcd099 fix: restore ci typecheck for cli 2026-05-04 01:53:21 -05:00
Brad Groux
ea9217c9fd
feat(cli+mcp): add sprint management commands and task --sprint flags (#161)
Add CLI sprint subcommands (list, create, update, delete, close, suggestions)
and MCP sprint tools for AI agent integration.

- New: cli/src/commands/sprints.ts - full sprint CRUD + archive workflow
- New: mcp/src/tools/sprints.ts - MCP tools for sprint management
- Add -S/--sprint flag to vk list, vk create, vk update
- Add sprint field to MCP list_tasks, create_task, update_task tools
- Wire sprint commands into CLI and MCP entry points

Based on sprint features from #80 by @mariozig, scoped to CLI/MCP surfaces only.

Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-01 13:07:14 -06:00
Brad Groux
f50c8a594c fix(ci): add shared build step + fix all type errors across server/cli
- Add 'Build shared' step to Lint & Type Check job in CI workflow
- Add explicit type annotations to ~50 parameters across server + CLI
- Fix docker-paths test to properly mock filesystem operations
- Verified: clean install → shared build → lint/typecheck/test/build all passing
2026-02-08 14:29:55 -06:00
Brad Groux
5c17972bfb fix(ci): mock docker paths fs calls + add CLI type annotations
- Mock fs.mkdir in docker-paths test (EACCES on Linux runners)
- Mock fs.existsSync with smart logic for pnpm-workspace.yaml detection
- Add explicit type annotations to all CLI commands (27 implicit any types)
- Verified: pnpm lint, typecheck, test (1252 tests), build all passing
2026-02-08 14:04:33 -06:00
Brad Groux
8e8e928380 feat: add CLI usage reporting commands (closes #50) 2026-02-05 17:53:52 -06:00
Brad Groux
89d6efbe6e feat(cli): US-1611 vk setup — guided onboarding wizard
New CLI command that validates environment and helps new users get started:

- Checks Node version (requires >=18)
- Verifies server is running and accessible
- Tests API authentication
- Optionally creates a welcome task with next steps
- Supports --json output for automation
- Supports --skip-task to skip sample task creation

Updated docs/GETTING-STARTED.md to reference the new command.

Credit: BoardKit Orchestrator (Monika Voutov) for the wizard pattern inspiration.

Closes #71
2026-02-04 09:14:01 -06:00
Brad Groux
6356a5e15e feat: backlog board, dashboard overhaul, UI/UX refinements (#65, #66)
Backlog Board (#65):
- BacklogRepository, BacklogService, API routes (/api/backlog/*)
- BacklogPage with inline expand/collapse, promote/demote actions
- CLI commands: vk backlog list|promote|demote|delete
- Activity events for demote/promote operations
- 47 tasks moved to backlog (sales, DM-Web, HubSpot, Customer.io)

Dashboard Overhaul:
- Recovered DashboardFilterBar from crashed branch (preset pills, custom date range, project filter)
- New metrics: Cost per Task, Agent Utilization (status-history-based)
- Fixed success rate calculation (backward-compat for status vs success field)
- Backfilled 23 estimated run.tokens events
- Task Activity per Day replaces Runs per Day chart
- Removed Sprint Velocity, Blocked Breakdown, period dropdowns
- Fixed ErrorsDrillDown empty state

Board & Sidebar:
- 5th column sidebar: Agent Status Panel (always visible), Recent Status Changes, Budget
- Clickable task names/IDs in agent status
- Removed planning column entirely (status, type, schemas, UI, CLI, MCP)
- Archive button in task detail panel (next to Delete)
- Select button moved to FilterBar row

Activity Page (#66):
- Removed tabs, side-by-side layout: Activity Feed (2/3) + Status History (1/3)
- Daily summary spans top

UI/UX:
- Command palette (Cmd+K)
- Theme toggle (Moon/Sun) in header
- Main padding increased, removed chat icon
- Cleaned up dead code (VelocityChart, MetricCard, unused imports)
- Fixed conditional hooks in CommandPalette
2026-02-02 04:56:47 -06:00
Brad Groux
8302375051 feat: Add backlog board feature (Issue #65)
- Add BacklogRepository for file-based storage in tasks/backlog/
- Add BacklogService with promote/demote logic
- Add backlog API routes (list, create, update, delete, promote, demote)
- Add BacklogPage component with search, filtering, and bulk actions
- Add backlog navigation with task count badge in header
- Add 'Move to Backlog' action to bulk actions bar
- Add CLI commands: backlog list/add/promote/demote/delete/count
- Add activity types for task_promoted and task_demoted events
- Backlog tasks are stored separately and not loaded by main task service
- Tasks can be promoted from backlog to active board (status -> todo)
- Tasks can be demoted from active board to backlog
2026-02-02 02:20:14 -06:00
Brad Groux
dc6bd85405 fix: replace all remaining 'Review' references with 'Blocked'
- BulkActionsBar: dropdown option 'Review' → 'Blocked'
- NotificationsTab: 'Review Needed' → 'Blocked' label/description
- constants.ts: remove obsolete 'review' status label
- summary CLI: 'Review' → 'Blocked' in standup output
- notification-service: fix misleading comment
- summary-service: fix misleading comment

Closes task_20260201_wOFjfL
2026-02-01 15:18:34 -06:00
Brad Groux
583d74b38d feat(v1.4): planning status + verification checklists (#40 #38) 2026-02-01 02:45:57 -06:00
Brad Groux
cf413bbd64 feat(cli): add workflow commands - vk begin/done/block/unblock, time tracking, comments, agent status, projects (#44) 2026-02-01 02:05:40 -06:00
Brad Groux
879b095096 v1.3.0: Visibility & Automation (#21, #33, #34)
- Bidirectional GitHub Issues sync (#21)
  - GitHubSyncService with polling, label-based field mapping, circuit breaker
  - Inbound: import issues with 'kanban' label as tasks
  - Outbound: push status changes and comments back to GitHub
  - Config/state persistence, 5 new API endpoints
  - CLI: vk github sync/status/config/mappings
  - TaskGitHub interface added to shared types

- Activity feed view (#33)
  - Full-page chronological feed with day grouping
  - Filter bar: agent, type, date range (combinable)
  - Compact vs detailed view toggle
  - Infinite scroll via IntersectionObserver
  - Real-time WebSocket updates with animation
  - Agent field added to Activity, MAX_ACTIVITIES 1000→5000
  - New ViewContext for board/activity navigation

- Daily standup summary generation (#34)
  - GET /api/summary/standup with date, format params
  - JSON, markdown, and plain text output formats
  - Sections: completed, in-progress, blocked, upcoming, stats
  - CLI: vk summary standup with --yesterday, --date, --json flags
  - 12 new tests for standup logic

Closes #21, closes #33, closes #34
2026-01-31 23:15:08 -06:00
Brad Groux
a7877e57b5 v1.2.0: Foundation Hardening (#2, #6, #32)
- Standardize API response envelope and error format (#2)
  - Add UnauthorizedError, ForbiddenError, BadRequestError, InternalError classes
  - Add pagination support with sendPaginated() helper
  - Standardize all 11 route files to use error classes (zero ad-hoc patterns)
  - Standardize auth middleware error responses

- Abstract file storage behind repository interface (#6)
  - Extend storage interfaces: Activity, Template, StatusHistory, ManagedList, Telemetry
  - Implement file-based adapters in FileStorageProvider
  - Add fs-helpers.ts as centralized filesystem access layer
  - Remove direct fs imports from all 10 service/route files

- Complete blocked task status implementation (#32)
  - Fix MCP tools Zod/JSON schema definitions
  - Fix MCP active tasks filter
  - Fix CLI help text and status color formatting

Closes #2, closes #6, closes #32
2026-01-31 23:03:10 -06:00
Brad Groux
39eccf3556 feat: Sprint US-1200 Refactoring batch — 13 tasks complete
Completed refactors:
- RF-02: Fix dependency vulnerabilities (xlsx → exceljs, Hono updates)
- RF-05: Add React error boundaries (FeatureErrorBoundary wrapper)
- RF-06: Server error handling middleware (AppError classes, asyncHandler)
- RF-10: Split shared types.ts into domain modules (6 files)
- RF-11: Consolidate frontend API layer (hooks now use api.ts)
- RF-13: TaskConfigContext — eliminate prop drilling
- RF-14: Split god components (GitSection, TaskDetailPanel, CreateTaskDialog, DiffViewer)
- RF-16: Frontend accessibility (ARIA labels, sr-only text)
- RF-17: Modularize CLI (899 → commands/ structure)
- RF-18: Modularize MCP (843 → tools/ structure)
- RF-19: Create shared API client library
- RF-21: Server performance (batch loading, memory limits, timeouts, graceful shutdown)
- RF-23: Extract shared utilities (path, format, constants)

Stats: ~59 files changed, significant code reduction through modularization
2026-01-28 06:08:59 -06:00
Brad Groux
575035d69b refactor: Replace direct spawn with Clawdbot sessions API integration
- Created ClawdbotAgentService that delegates to Veritas main session
- Agent requests written to .veritas-kanban/agent-requests/ as JSON
- Added /api/agents/pending endpoint for Veritas to poll
- Added /api/agents/:taskId/complete callback endpoint
- CLI commands: agents:pending, agents:complete, agents:status
- Removed PTY process management - Clawdbot handles it

Flow:
1. Kanban UI → POST /api/agents/:taskId/start
2. Server writes request to agent-requests/{taskId}.json
3. Veritas polls agents:pending or checks manually
4. Veritas calls sessions_spawn with task prompt
5. Sub-agent works in worktree, commits changes
6. Veritas calls /api/agents/:taskId/complete
7. Task updated, notifications sent
2026-01-26 11:20:28 -06:00
Brad Groux
809bf4d94e feat(US-505): Teams notification integration
- New /api/notifications endpoints (create, list, pending, mark-sent, check, clear)
- Notification types: agent_complete, agent_failed, needs_review, task_done, high_priority, error, milestone, info
- CLI commands: notify, notify:check, notify:pending, notify:list, notify:clear
- MCP tools: create_notification, get_pending_notifications, check_notifications
- Notifications stored in .veritas-kanban/notifications.json
- Teams-formatted output with icons and task links
2026-01-26 04:34:41 -06:00
Brad Groux
7d7e92e2ce feat(US-504): Memory system sync
- New /api/summary endpoint (status counts, projects, high-priority)
- New /api/summary/recent endpoint (recently completed tasks)
- New /api/summary/memory endpoint (markdown formatted for memory files)
- CLI: vk summary - show kanban overview
- CLI: vk memory - get memory-formatted summary
- CLI: vk memory -o <file> - append to memory file
- MCP: get_summary, get_memory_summary tools
2026-01-26 04:29:03 -06:00
Brad Groux
6112517ee7 feat(US-503): Veritas sub-agent integration
- Added 'veritas' agent type for automation tasks
- New automation field on tasks (sessionKey, spawnedAt, completedAt, result)
- New API endpoints:
  - POST /api/automation/:id/start - start automation task
  - POST /api/automation/:id/complete - complete automation task
  - GET /api/automation/pending - list pending automation tasks
  - GET /api/automation/running - list running automation tasks
- CLI commands: automation:pending, automation:start, automation:complete, automation:running
- MCP tools: list_pending_automation, list_running_automation, start_automation, complete_automation
2026-01-26 04:26:28 -06:00
Brad Groux
bec40a05de feat(US-501): CLI for task management
- vk list: list tasks with filters (status, type, project)
- vk show: display task details
- vk create: create new tasks
- vk update: modify task fields
- vk start: start agent on task
- vk stop: stop running agent
- vk archive: archive completed task
- vk delete: delete task
- JSON output option for all commands
- Partial ID matching support
2026-01-26 04:17:52 -06:00