Commit graph

28 commits

Author SHA1 Message Date
Brad Groux
4aba9229c9
feat: gate agent launches on workspace trust (#1031) 2026-07-25 00:48:28 -05:00
Brad Groux
4ccec233ca
feat: enforce run-scoped filesystem sandboxes (#1028)
* feat: enforce run-scoped filesystem sandboxes

* test: complete config service mock
2026-07-25 00:05:14 -05:00
Brad Groux
1bd43f9279
release: Veritas Kanban 6.0.0 (#985)
* build: prepare 6.0.0 release

* docs: link the 6.0.0 release pull request
2026-07-24 11:26:25 -05:00
Brad Groux
0fbd9ee428
feat: add run-scoped tool control plane (#959)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Changed Tests (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
Desktop Artifacts / Unsigned macOS Artifact (push) Waiting to run
Desktop Artifacts / Unsigned Linux Artifacts (push) Waiting to run
Desktop Artifacts / Unsigned Windows Artifacts (push) Waiting to run
* feat: add run-scoped tool control plane (#857)

* test: align provider capability fixtures
2026-07-24 05:10:20 -05:00
Brad Groux
c1be9f7322 feat: add durable run supervisor 2026-07-24 03:02:36 -05:00
Brad Groux
81730a451a
feat: import Buzz persona and team definitions (#948) 2026-07-23 23:31:16 -05:00
Brad Groux
f5333fd271
feat: add bidirectional Buzz Squad Chat adapter (#947)
Closes #906
2026-07-23 22:58:20 -05:00
Brad Groux
54417357f9
feat: add secure Buzz connection diagnostics (#946) 2026-07-23 22:07:25 -05:00
Brad Groux
32517e4df6
feat: make worktree lifecycle transactional (#934)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
Closes #858.
2026-07-23 19:44:42 -05:00
Brad Groux
0f8506b4ce
feat: add run-bound credential lease engine (#933) 2026-07-23 18:43:21 -05:00
Brad Groux
566ec0f7fe
feat: enforce provider runtime manifests (#887) (#890)
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-16 11:00:44 -05:00
Brad Groux
8686803350
Implement agent run budget enforcement
Adds enforceable agent and workflow run budgets with governance traces, UI controls, completion evidence, docs, and regression coverage.
2026-06-18 15:22:45 -05:00
Brad Groux
398d6024af
Add sandbox policy presets (#727) 2026-06-18 14:44:27 -05:00
Brad Groux
1c96a326aa
Enforce v5 password-session boundary
Limit password-session cookies to local-owner loopback clients and document device/session-token requirements for remote and multi-user v5 GA access.
2026-06-05 14:53:17 -05:00
Brad Groux
72715f229f
Add v5 release readiness docs (#546) 2026-06-03 07:49:26 -07:00
Brad Groux
fd96f73408
Harden v5 security review surfaces (#531) 2026-06-03 03:55:22 -07:00
Brad Groux
847c9d1287
Document v5 remote server security posture
Adds the v5 remote/server-mode security posture ADR and links it from deployment, self-hosting, security, API reference, and GA checklist docs.
2026-06-03 01:25:02 -07:00
Brad Groux
cb70bc42f9
fix: tighten agent approval RBAC guards
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
## Summary

- splits agent register, permission, and routing route guards so read-like POSTs stay available without treating all agent self-service POSTs as read-only safe
- requires task:write for agent approval requests, telemetry:write for agent registration writes, and admin:manage for approval review/routing configuration/permission elevation
- mirrors the route guard changes in the shared CLI/MCP permission preflight map
- expands REST, CLI, and MCP authorization tests for read-only mutation denial and scoped agent approval requests

Closes #336.

## Verification

- VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts
- node scripts/check-permission-coverage.mjs
- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/server typecheck
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm build
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- node_modules/.bin/prettier --check server/src/routes/v1/permissions.ts server/src/routes/v1/index.ts shared/src/utils/api-permissions.ts server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts docs/security.md
- git diff --check

## Notes

- pnpm audit --prod --audit-level=high passes the high-severity gate and still reports 3 moderate existing vulnerabilities.
- pnpm lint:budget passed with 705 warnings under the 714 warning budget.
- pnpm --filter @veritas-kanban/mcp typecheck is not available because the package has no typecheck script; pnpm --filter @veritas-kanban/mcp build covers TypeScript compilation.
2026-05-31 05:53:32 -05:00
Brad Groux
522162ae89
test: add v5 permission coverage manifest gate
## Summary

- adds a v5 permission coverage manifest with classifications, required permissions, denial reasons, and review justifications across REST, WebSocket, CLI, MCP, workflow, transition hook, command palette, and background job surfaces
- adds a Node-based coverage checker that fails when tracked surfaces are missing from the manifest or when REST route prefixes drift from the shared permission map
- wires the checker into CI and documents the manifest gate in the security guide

Closes #420.

## Verification

- `node scripts/check-permission-coverage.mjs`
- `./node_modules/.bin/prettier --check package.json .github/workflows/ci.yml scripts/check-permission-coverage.mjs docs/security/permission-coverage.json docs/security.md`
- `git diff --check`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high` (passes high gate; 3 existing moderate findings)
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 05:02:26 -05:00
Brad Groux
c40f378bb9
feat: add v5 auth permission context
## Summary

- adds a shared v5 auth context for REST requests and WebSocket connections
- adds role-derived permission sets plus an explicit `authorizePermission` guard for upcoming route migrations
- documents scoped CLI and MCP token expectations for v5 RBAC work

Refs #336.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- middleware/auth`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`

## Notes

- This is a compatibility groundwork slice for #336. It does not complete route-by-route permission enforcement, workspace filtering, or agent token scoping.
2026-05-31 02:35:24 -05:00
Brad Groux
5cf82db881
docs: define v5 identity RBAC model
## Summary

- adds the v5 identity, workspace, and RBAC design document
- defines users, workspaces, memberships, invitations, sessions, agent identities, scoped API tokens, roles, route permissions, entity-level rules, and actor attribution
- documents local mode, server mode, localhost bypass behavior, backward-compatible migration, recovery, invitation, device pairing, and agent token UX flows
- links the design from the README docs map, security guide, and SQLite schema strategy

Closes #334.

## Verification

- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `./node_modules/.bin/prettier --check docs/IDENTITY-RBAC.md README.md docs/security.md docs/SQLITE-SCHEMA.md`
- `git diff --check`

## Notes

- This is the design slice for #334. It intentionally does not implement the RBAC tables or middleware.
2026-05-31 02:04:08 -05:00
V.K. Watson
50dfff84ef revert: restore port 3001 across codebase, keep Express 5 path fix
Reverts port change from 1b7a9fe. OpenClaw gateway will move off 3001 instead.
2026-02-20 21:12:49 -06:00
V.K. Watson
1b7a9feb03 fix: update default API port from 3001 to 3002 across codebase
Avoids conflict with OpenClaw gateway on port 3001.
Updated: server config, docs, README, WebSocket hook.
2026-02-20 21:11:40 -06:00
V.K. Watson
9657e731b6
fix: guard updatedTask null check in task routes
also clean up observations section build warning
2026-02-20 01:51:45 -06:00
Brad Groux
8cfe28326d docs: comprehensive v2.0.0 documentation update
- FEATURES.md: Added Multi-Agent System section (registry, dashboard,
  assignment, mentions, permissions, error learning, doc freshness)
- FEATURES.md: Added Dashboard Widgets section (activity clock, hourly
  activity, where time went, wall time, session metrics, widget toggles,
  lifecycle hooks, cost prediction, timezone-aware metrics)
- FEATURES.md: Added v2.0 API endpoints to route table
- FEATURES.md: Updated response envelope with timezone meta fields
- CHANGELOG.md: Added #92 Dashboard Widget Toggles to v2.0.0
- README.md: Moved #92 from backlog to shipped in v2.0.0
- README.md: Cleaned stale 'NEW — v1.x' tags from pre-v2.0 features
- CLAUDE.md: Updated to v2.0.0 — added mcp/ package, multi-agent
  lessons, registry/telemetry file locations
- security.md: Added v2.0.0 changelog entry (permissions, MCP patch)
- All docs verified: no broken links, no stale version refs, no secrets
2026-02-05 20:54:37 -06:00
Brad Groux
793192e6b3 docs: rename Moltbot references to OpenClaw (formerly Clawdbot/Moltbot) 2026-01-29 23:39:11 -06:00
Brad Groux
c250a5a60f docs: final documentation pass for public release
- CONTRIBUTING: fix Node.js prerequisite (20 → 22), fix .env path, add seed docs, expand project structure
- CHANGELOG: move 1.1.0 to Unreleased (matches package.json 1.0.0), add seed data entry, fix link refs
- README: add examples/ and gitignored annotations to architecture tree
- docs/security.md: update Clawdbot reference to Moltbot, fix release date
2026-01-29 15:51:41 -06:00
Brad Groux
3efa474eb0 feat(server): Add authentication & authorization system
- Add auth middleware (server/src/middleware/auth.ts)
  - API key authentication via Bearer token, X-API-Key header, or query param
  - Role-based authorization (admin, agent, read-only)
  - Localhost bypass option for development
  - WebSocket connection authentication

- Update index.ts to integrate auth middleware
  - Apply authenticate middleware to all /api routes
  - Add /api/auth/status endpoint for diagnostics
  - Protect WebSocket connections with token validation
  - Display auth status in startup banner

- Add configuration via environment variables
  - VERITAS_AUTH_ENABLED (default: true)
  - VERITAS_AUTH_LOCALHOST_BYPASS (default: false)
  - VERITAS_ADMIN_KEY for admin access
  - VERITAS_API_KEYS for named keys with roles

- Add comprehensive security documentation (docs/security.md)
- Add .env.example with all auth configuration options

Closes RF-01
2026-01-28 07:37:44 -06:00