Commit graph

202 commits

Author SHA1 Message Date
Brad Groux
5f2b77b0c9 security: untrack security.json from git (contains JWT secret) 2026-01-29 01:36:43 -06:00
Brad Groux
1f52ab9dd2 docs: add open source governance files 2026-01-29 01:35:55 -06:00
Brad Groux
f0616589e6 docs: add LICENSE, SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md 2026-01-29 01:35:51 -06:00
Brad Groux
14e69b9204 docs: add GitHub issue templates, PR template, and config 2026-01-29 00:53:43 -06:00
Brad Groux
de388dc377 feat: complete test coverage sprint - backend 53.5% + E2E 19/19 passing
Backend tests (9 new files):
- summary-service, metrics-helpers, template-service
- status-history-service, trace-service, diff-service
- conflict-service, preview-service, digest-service
- Coverage: 44.27% → 53.52% (897 tests passing)

E2E tests (fixed + hardened):
- Removed debug spec left by sub-agent
- API seed calls now hit backend directly (port 3001)
  to avoid IPv6/Vite proxy issues on macOS
- task-status tests use unique names (prevent strict mode)
- Added waitForResponse for status change assertions
- Enabled webServer auto-start in playwright.config.ts
- All 19 E2E tests passing
2026-01-28 22:42:16 -06:00
Brad Groux
63e961f8d6 refactor: split god files into focused modules
- metrics-service.ts (1727 lines) → 9 files in server/src/services/metrics/
  - types.ts (270), helpers.ts (96), telemetry-reader.ts (99)
  - task-metrics.ts (232), run-metrics.ts (236), token-metrics.ts (225)
  - dashboard-metrics.ts (683), metrics-service.ts facade (108), index.ts (32)
- api.ts (1038 lines) → 9 files in web/src/lib/api/
  - helpers.ts (17), tasks.ts (166), config.ts (100), agent.ts (181)
  - diff.ts (181), entities.ts (245), time.ts (114)
  - managed-list.ts (64), index.ts (77)
- All imports updated, barrel exports maintain backwards compatibility
- TypeScript compiles cleanly for both server and web
- All 740 tests pass (42 test files)
2026-01-28 17:57:45 -06:00
Brad Groux
125430544a docs: add OpenAPI/Swagger API documentation 2026-01-28 17:51:04 -06:00
Brad Groux
2ec4aa5ac2 fix(security): tighten CSP directives, remove unsafe-eval in dev 2026-01-28 17:47:13 -06:00
Brad Groux
86e03f7b00 fix(security): configure persistent JWT secret and add startup warnings 2026-01-28 17:44:26 -06:00
Brad Groux
d756889a1f fix(security): replace weak dev admin key with strong random key 2026-01-28 17:42:20 -06:00
Brad Groux
5d3f75bda6 perf: add pagination and summary mode to reduce API payload 2026-01-28 17:38:04 -06:00
Brad Groux
4531e3799f fix(security): require auth for diagnostics endpoint 2026-01-28 17:36:10 -06:00
Brad Groux
da1532feec fix: adjust rate limit thresholds for local dev tool 2026-01-28 17:32:32 -06:00
Brad Groux
dcbc03f0e5 perf: add telemetry retention and automatic cleanup 2026-01-28 17:32:04 -06:00
Brad Groux
f3ffad2a9f fix: return 403 for CORS rejections instead of 500 2026-01-28 17:30:57 -06:00
Brad Groux
4b4b1197ee fix(types): replace as-any casts with proper type narrowing 2026-01-28 17:29:10 -06:00
Brad Groux
ec5cc7a0e2 fix: audit and fix silent catch blocks 2026-01-28 17:26:30 -06:00
Brad Groux
94f77f7d1d fix(test): fix broken test files with proper mocking and vi.hoisted() for TDZ issues 2026-01-28 17:19:01 -06:00
Brad Groux
3ebfa2c8b7 chore: add pre-commit hooks with husky + lint-staged 2026-01-28 17:17:40 -06:00
Brad Groux
6754302d73 fix: add unhandledRejection and uncaughtException handlers 2026-01-28 17:16:07 -06:00
Brad Groux
f5bb469f9a feat: add structured logging with pino 2026-01-28 17:14:20 -06:00
Brad Groux
1e0842ce4e fix: add service disposal to graceful shutdown 2026-01-28 17:13:49 -06:00
Brad Groux
279221ee38 ci: add GitHub Actions CI pipeline 2026-01-28 17:12:18 -06:00
Brad Groux
190942b154 feat: add request ID middleware for request tracing 2026-01-28 17:11:15 -06:00
Brad Groux
14d60d28eb perf: lazy-load dashboard and split vendor chunks to reduce main bundle by 69% 2026-01-28 17:10:40 -06:00
Brad Groux
ccff6e78c8 fix(security): sanitize Content-Disposition header for attachments 2026-01-28 17:09:38 -06:00
Brad Groux
c8970f0631 fix(security): use timing-safe comparison for recovery keys 2026-01-28 17:08:26 -06:00
Brad Groux
1a9d406e5f fix(security): redact plaintext credentials from task data and audit doc 2026-01-28 17:06:59 -06:00
Brad Groux
b6fadfaa4c docs: add security, performance, and quality audit reports 2026-01-28 16:59:09 -06:00
Brad Groux
615b9b03b4 feat(security): replace custom rate limiter with express-rate-limit
- Swap hand-rolled Map-based rate limiter for battle-tested express-rate-limit
- Built-in MemoryStore handles TTL cleanup automatically (no memory leaks)
- Uses sliding window counter algorithm instead of fixed window
- Emits both IETF draft-7 (RateLimit-*) and legacy (X-RateLimit-*) headers
- Remove duplicate inline rate limiter from settings.ts, use shared strictRateLimit middleware
- Redis not warranted for single-instance local dev tool
2026-01-28 12:22:34 -06:00
Brad Groux
62b26a6f3a fix: add missing route imports in server index.ts (server crash fix) 2026-01-28 12:20:06 -06:00
Brad Groux
99cd20c5a4 perf: add in-memory task caching with file watchers 2026-01-28 12:18:41 -06:00
Brad Groux
7d3a9c404c perf: cache config in memory with write invalidation 2026-01-28 12:14:41 -06:00
Brad Groux
db74b427ef fix(security): add server-side MIME type validation for uploads 2026-01-28 12:14:22 -06:00
Brad Groux
8ec03eb3c9 fix(security): sanitize Markdown to prevent stored XSS 2026-01-28 12:14:12 -06:00
Brad Groux
6793b23310 perf: reduce polling when WebSocket connected 2026-01-28 12:13:48 -06:00
Brad Groux
06df2e2050 fix(security): validate Origin header for WebSocket connections 2026-01-28 12:11:53 -06:00
Brad Groux
d77f5dfa17 feat(security): implement JWT secret rotation mechanism 2026-01-28 12:09:20 -06:00
Brad Groux
9d0f5cae47 feat(perf): add gzip response compression middleware 2026-01-28 12:09:05 -06:00
Brad Groux
12c9f4ed65 feat(deploy): add production Dockerfile with multi-stage build 2026-01-28 12:08:14 -06:00
Brad Groux
5e4f3ec6b9 fix(security): move JWT secret to env var, update .env.example 2026-01-28 12:07:11 -06:00
Brad Groux
9fcb39d0ca feat(security): add CSP headers with Helmet 2026-01-28 12:05:43 -06:00
Brad Groux
5aa31115ae fix(security): remove .env from git, add .env.example 2026-01-28 12:05:17 -06:00
Brad Groux
0c42d0b125 Populate token telemetry for all 192 closed/archived tasks
- Added run.started, run.tokens, run.completed events for every completed task
- Token estimates based on time tracked and task complexity
- Metrics tab now displays agent run data for all historical tasks
- Added create-review-tasks.sh script
- Updated activity and status history
2026-01-28 11:49:14 -06:00
Brad Groux
7dcc78a325 docs: add comprehensive code review findings
Full review covering security, performance, architecture, standards,
testing, and deployment readiness. Created sprint tasks for all findings.
2026-01-28 11:24:47 -06:00
Brad Groux
3f10c45ab2 feat: add task-level metrics to Metrics tab
Shows time tracked, task age, time to close, subtask progress, and other
always-available metrics computed client-side from the Task object.
Agent run telemetry section remains below for tasks with run data.
2026-01-28 11:19:28 -06:00
Brad Groux
ec0466b2dc fix: prevent server refetch from overwriting active typing in task panel
The sync useEffect in useDebouncedSave blindly reset localTask to the
server value on every refetch, wiping out in-flight user input. Now uses
a ref-tracked dirty field set to merge server data while preserving
locally modified fields. Also stabilizes the mutate ref to prevent
debounce timer resets on re-renders.
2026-01-28 11:12:41 -06:00
Brad Groux
228fe0b6f8 fix: add dotenv to load .env file at server startup
- Added dotenv package to server dependencies
- Import dotenv/config at top of server/src/index.ts
- Fixes AUTH_REQUIRED errors when using API keys and localhost bypass

Resolves issue where VERITAS_AUTH_LOCALHOST_BYPASS and VERITAS_ADMIN_KEY
environment variables were not being loaded from .env file.
2026-01-28 10:31:07 -06:00
Brad Groux
887cfc9a7e feat(auth): Complete authentication sprint
- UserMenu: Session indicator with lock icon, expiry display, logout (Cmd+Shift+L)
- SecurityTab: Change password form with strength indicator, danger zone
- Header: Integrated UserMenu with security settings link
- SettingsDialog: Added Security tab with lazy loading, defaultTab prop
- useAuth: Fixed setup() to not refresh status before showing recovery key

Completes: US-d-eQbD, US-fCAsJx
2026-01-28 09:44:31 -06:00
Brad Groux
858669defb feat(US-1006,US-1012): Add metrics export and sprint velocity tracking
US-1006: Add metrics export functionality
- Export button on dashboard with JSON/CSV formats
- Export telemetry service endpoint
- Filter by time period and project

US-1012: Add sprint velocity tracking
- GET /api/metrics/velocity endpoint
- Bar chart with tasks completed per sprint
- Rolling 3-sprint average line overlay
- Velocity trend indicator (accelerating/steady/slowing)
- Task type breakdown on hover
- Current sprint progress vs average
2026-01-28 08:24:32 -06:00