Commit graph

340 commits

Author SHA1 Message Date
Brad Groux
a1c19d5772 Dev reliability: add /api/health, dev:clean, and dev watchdog 2026-02-03 23:37:15 -06:00
Brad Groux
4e11a4e584 Fix docker startup when cwd is / (issue #62) (#78)
Co-authored-by: Brad Groux <bradgroux@Brads-Mac-mini.local>
2026-02-03 04:56:06 -06:00
Brad Groux
a87c28decf docs: align versioning to v1.4.1 (packages, README, changelog) 2026-02-03 01:51:21 -06:00
Brad Groux
8d2f624670 fix: restore example tasks to tracking (intentional repo content) 2026-02-02 20:03:24 -06:00
Brad Groux
57f637fe9d fix: remove tracked task files and update .gitignore
tasks/backlog/*.md and tasks/examples/*.md were not covered by
.gitignore — only active/ and archive/ were. Added both patterns
and removed 56 tracked task files from the index.

Files remain on disk (only removed from git tracking).
2026-02-02 20:03:00 -06:00
Brad Groux
774673b80a fix(security): RF-002 — path traversal, admin authz, agent status WebSocket
SEC-001: Path traversal prevention
- Add validatePathSegment() and ensureWithinBase() to server/src/utils/sanitize.ts
- Apply to chat-service (sessionId/taskId in file paths)
- Apply to conflict-service (filePath in path.join)
- Apply to clawdbot-agent-service (taskId/attemptId in log/request paths)

SEC-007: Admin authorization on mutating endpoints
- settings.ts: PATCH /features requires authorize('admin')
- config.ts: POST/PATCH/DELETE repos, PUT agents, PUT default-agent
- activity.ts: DELETE / requires authorize('admin')
- notifications.ts: POST/mark-sent/check require authorize('admin','agent'), DELETE requires admin
- status-history.ts: DELETE / requires authorize('admin')
- Updated test harnesses with admin auth injection

Agent Status Indicator: WebSocket fix
- BoardSidebar now uses useRealtimeAgentStatus (WebSocket) instead of useGlobalAgentStatus (polling)
- Fixed field name mismatch: server broadcasts 'activeAgents' but hook expected 'subAgents'
- Hook now correctly reads activeAgents from both WebSocket messages and REST fallback
- Added connection status indicator and stale detection to sidebar
- Fixed agent-status.ts spread order for persisted status restore

Pre-existing fixes included (from earlier RF-002 sub-agent diffs):
- auth.ts: X-Forwarded-For only trusted when trust proxy configured
- rate-limit.ts: isLocalhost returns false in production
- telemetry-service: CSV formula injection prefix sanitization
- Frontend: window.open noopener/noreferrer on all instances
2026-02-02 09:09:15 -06:00
Brad Groux
dc826961ba fix: reset subAgentCount on idle + agent status reporting SOP
The agent status indicator on the VK board was not updating during
sub-agent workloads because OpenClaw sub-agents (spawned via
sessions_spawn) run outside VK's clawdbot-agent-service — nothing
was POSTing to /api/agent/status.

Server fix:
- Reset subAgentCount to 0 when status transitions to idle
  (previously only cleared activeTask, errorMessage, and activeAgents)

Workflow fix (in clawd workspace):
- Created vk-status.sh script to wrap the agent status API
- Added mandatory SOP to AGENTS.md: orchestrator calls vk-status.sh
  before/after every spawn, and every sub-agent task prompt includes
  a curl POST to /api/agent/status as its first action
- Works regardless of which model runs the sub-agent (Codex, Sonnet,
  GPT, etc.) — both the orchestrator and the agent itself report in
2026-02-02 06:41:59 -06:00
Brad Groux
238433b2ad feat: RF-002 cross-model code audit — full codebase
Complete cross-model audit of Veritas Kanban codebase:
- Auditor: GPT-5.2 Codex (8 parallel batches)
- Reviewer: Claude Opus 4.5

Results: 331 files, 55,300 lines audited
- 39 confirmed findings (91% Codex accuracy)
- 4 High, 16 Medium, 19 Low, 0 Critical
- Top patterns: path traversal (4), race conditions (8), state bugs (12)
- Estimated remediation: 16 hours across 4 sprints

Reports: 9 batch reports + executive summary + HTML presentation
All mirrored to Brain (dm-bg/refactoring/)
2026-02-02 05:39:01 -06:00
Brad Groux
59b0a8fd73 Merge feat/backlog-board-65: backlog board, dashboard overhaul, UI/UX refinements (#65, #66) 2026-02-02 04:56:51 -06:00
Brad Groux
6356a5e15e feat: backlog board, dashboard overhaul, UI/UX refinements (#65, #66)
Backlog Board (#65):
- BacklogRepository, BacklogService, API routes (/api/backlog/*)
- BacklogPage with inline expand/collapse, promote/demote actions
- CLI commands: vk backlog list|promote|demote|delete
- Activity events for demote/promote operations
- 47 tasks moved to backlog (sales, DM-Web, HubSpot, Customer.io)

Dashboard Overhaul:
- Recovered DashboardFilterBar from crashed branch (preset pills, custom date range, project filter)
- New metrics: Cost per Task, Agent Utilization (status-history-based)
- Fixed success rate calculation (backward-compat for status vs success field)
- Backfilled 23 estimated run.tokens events
- Task Activity per Day replaces Runs per Day chart
- Removed Sprint Velocity, Blocked Breakdown, period dropdowns
- Fixed ErrorsDrillDown empty state

Board & Sidebar:
- 5th column sidebar: Agent Status Panel (always visible), Recent Status Changes, Budget
- Clickable task names/IDs in agent status
- Removed planning column entirely (status, type, schemas, UI, CLI, MCP)
- Archive button in task detail panel (next to Delete)
- Select button moved to FilterBar row

Activity Page (#66):
- Removed tabs, side-by-side layout: Activity Feed (2/3) + Status History (1/3)
- Daily summary spans top

UI/UX:
- Command palette (Cmd+K)
- Theme toggle (Moon/Sun) in header
- Main padding increased, removed chat icon
- Cleaned up dead code (VelocityChart, MetricCard, unused imports)
- Fixed conditional hooks in CommandPalette
2026-02-02 04:56:47 -06:00
Brad Groux
de546c6e52 feat: full-width layout + archive page (unified design)
- Remove container max-width from main layout — all views now full-width
- Convert Archive from sidebar to full page with search, filters, bulk restore
- Add Archive nav button in header (replaces sidebar icon)
- Archive page matches Backlog/Activity design: expand-in-place, checkboxes, badges
- Sprint filter on archive page
- Consistent UX across Board, Activity, Backlog, and Archive views
2026-02-02 02:45:26 -06:00
Brad Groux
2f69af3fe6 fix: remove max-w-4xl from Activity feed to match Backlog width 2026-02-02 02:39:58 -06:00
Brad Groux
71afc9d539 feat: move Daily Summary above tabs, always visible on Activity page 2026-02-02 02:39:02 -06:00
Brad Groux
9083f7d2ab feat: merge Activity Sidebar into Activity Feed (GH-66)
- Add Status History tab with day-grouped status transitions
- Add Daily Summary tab with active/idle/utilization metrics
- Remove Activity Sidebar component and its header icon
- Single 'Activity' nav button now opens the unified feed page
- Agent status indicator links to activity feed instead of sidebar
- Closes #66
2026-02-02 02:37:13 -06:00
Brad Groux
a07f7489fa fix: clicking backlog task now expands inline instead of navigating away
Previously clicking a task in the backlog called navigateToTask which
switched back to the board view. Now tasks expand/collapse inline with
full description, dates, agent, and recent comments.
2026-02-02 02:31:13 -06:00
Brad Groux
fcf2ccaab0 fix: strip undefined values in backlog YAML serialization
Fixes YAMLException when creating backlog tasks - undefined frontmatter
fields were being passed to gray-matter stringify which can't serialize
them. Now filters out undefined values before serialization.
2026-02-02 02:23:58 -06:00
Brad Groux
8302375051 feat: Add backlog board feature (Issue #65)
- Add BacklogRepository for file-based storage in tasks/backlog/
- Add BacklogService with promote/demote logic
- Add backlog API routes (list, create, update, delete, promote, demote)
- Add BacklogPage component with search, filtering, and bulk actions
- Add backlog navigation with task count badge in header
- Add 'Move to Backlog' action to bulk actions bar
- Add CLI commands: backlog list/add/promote/demote/delete/count
- Add activity types for task_promoted and task_demoted events
- Backlog tasks are stored separately and not loaded by main task service
- Tasks can be promoted from backlog to active board (status -> todo)
- Tasks can be demoted from active board to backlog
2026-02-02 02:20:14 -06:00
Brad Groux
a5d1be9276 feat: clicking emoji/title refreshes the page 2026-02-01 15:29:08 -06:00
Brad Groux
0491729800 style: add ArrowRight icon to Move button, match Archive/Delete sizing 2026-02-01 15:27:39 -06:00
Brad Groux
dfa81b0405 fix: add Move confirm button to bulk actions (two-step flow)
Previously the 'Move to...' dropdown fired immediately on selection with
no confirm step. Now it's a two-step flow: pick target status from dropdown,
then click 'Move' button to confirm — consistent with Archive and Delete.

Fixes task_20260201_NqmOuf
2026-02-01 15:25:19 -06:00
Brad Groux
dc6bd85405 fix: replace all remaining 'Review' references with 'Blocked'
- BulkActionsBar: dropdown option 'Review' → 'Blocked'
- NotificationsTab: 'Review Needed' → 'Blocked' label/description
- constants.ts: remove obsolete 'review' status label
- summary CLI: 'Review' → 'Blocked' in standup output
- notification-service: fix misleading comment
- summary-service: fix misleading comment

Closes task_20260201_wOFjfL
2026-02-01 15:18:34 -06:00
Brad Groux
872e01a50f chore: add landing page to docs/ for GitHub Pages + configure Pages from /docs 2026-02-01 02:55:26 -06:00
Brad Groux
68839ccf04 feat: add 'Why Veritas Kanban' landing page for GitHub Pages (site/) 2026-02-01 02:54:55 -06:00
Brad Groux
583d74b38d feat(v1.4): planning status + verification checklists (#40 #38) 2026-02-01 02:45:57 -06:00
Brad Groux
b19a275ad0 docs: comprehensive v1.4 CLI workflow documentation — README, FEATURES, CHANGELOG, new CLI-GUIDE.md (#44) 2026-02-01 02:24:34 -06:00
Brad Groux
cf413bbd64 feat(cli): add workflow commands - vk begin/done/block/unblock, time tracking, comments, agent status, projects (#44) 2026-02-01 02:05:40 -06:00
Brad Groux
bbc8d948b4 docs: update roadmap with current milestones and completed items 2026-01-31 23:48:09 -06:00
Brad Groux
9369ca8bcf docs: update all documentation for v1.2.0 + v1.3.0
- Bump all package versions to 1.3.0
- README: version badge, blocked column, new feature highlights
- CHANGELOG: full v1.2.0 and v1.3.0 entries
- FEATURES.md: GitHub sync, activity feed, standup summary sections
- FEATURES.md: storage architecture, API envelope docs, new CLI commands
- FEATURES.md: updated API endpoints table and response format docs
2026-01-31 23:33:37 -06:00
Brad Groux
879b095096 v1.3.0: Visibility & Automation (#21, #33, #34)
- Bidirectional GitHub Issues sync (#21)
  - GitHubSyncService with polling, label-based field mapping, circuit breaker
  - Inbound: import issues with 'kanban' label as tasks
  - Outbound: push status changes and comments back to GitHub
  - Config/state persistence, 5 new API endpoints
  - CLI: vk github sync/status/config/mappings
  - TaskGitHub interface added to shared types

- Activity feed view (#33)
  - Full-page chronological feed with day grouping
  - Filter bar: agent, type, date range (combinable)
  - Compact vs detailed view toggle
  - Infinite scroll via IntersectionObserver
  - Real-time WebSocket updates with animation
  - Agent field added to Activity, MAX_ACTIVITIES 1000→5000
  - New ViewContext for board/activity navigation

- Daily standup summary generation (#34)
  - GET /api/summary/standup with date, format params
  - JSON, markdown, and plain text output formats
  - Sections: completed, in-progress, blocked, upcoming, stats
  - CLI: vk summary standup with --yesterday, --date, --json flags
  - 12 new tests for standup logic

Closes #21, closes #33, closes #34
2026-01-31 23:15:08 -06:00
Brad Groux
a7877e57b5 v1.2.0: Foundation Hardening (#2, #6, #32)
- Standardize API response envelope and error format (#2)
  - Add UnauthorizedError, ForbiddenError, BadRequestError, InternalError classes
  - Add pagination support with sendPaginated() helper
  - Standardize all 11 route files to use error classes (zero ad-hoc patterns)
  - Standardize auth middleware error responses

- Abstract file storage behind repository interface (#6)
  - Extend storage interfaces: Activity, Template, StatusHistory, ManagedList, Telemetry
  - Implement file-based adapters in FileStorageProvider
  - Add fs-helpers.ts as centralized filesystem access layer
  - Remove direct fs imports from all 10 service/route files

- Complete blocked task status implementation (#32)
  - Fix MCP tools Zod/JSON schema definitions
  - Fix MCP active tasks filter
  - Fix CLI help text and status color formatting

Closes #2, closes #6, closes #32
2026-01-31 23:03:10 -06:00
Brad Groux
3430b265c3 feat: Add webhook notifications for Clawdbot Gateway integration (#36)
feat: Add webhook notifications for Clawdbot Gateway integration
2026-01-31 22:37:00 -06:00
Brad Groux
a421fada46 fix(docker): resolve build failures from lockfile mismatch and permissions
Fixes #35

- Copy real web/package.json instead of creating a minimal stub, which
  caused pnpm-lock.yaml specifier mismatch with --frozen-lockfile
- Add --ignore-scripts to skip husky prepare hook in container builds
- Remove web/node_modules after install (frontend is pre-built static)
- Create .veritas-kanban directory with correct ownership for non-root user

Closes #35
2026-01-31 22:31:07 -06:00
Scout Murphy
4189af29cb feat: Add webhook notifications for Clawdbot Gateway integration
- Add webhookUrl to NotificationSettingsSchema
- Create clawdbot-webhook-service with fire-and-forget delivery + 1 retry
- Hook into broadcastTaskChange and broadcastChatMessage in broadcast-service
- Support VERITAS_WEBHOOK_URL and VERITAS_WEBHOOK_SECRET env vars
- HMAC-SHA256 payload signing via X-Webhook-Signature header
- Add 16 tests covering config, signing, delivery, retry, and payload formatting
- Update .env.example with new env var documentation
2026-01-31 21:30:02 -07:00
Brad Groux
14fbf33609 fix: unwrap API envelope in shared client (fixes #27) 2026-01-31 12:09:58 -06:00
Brad Groux
28eeb58133 docs: add agent quickstart prompt to README 2026-01-31 11:41:22 -06:00
Brad Groux
f3e4ab2375 Merge pull request #26 from BradGroux/fix/timer-stop-cache-race-7
Fixes the timer stop race condition (Issue #7). Debounced field saves no longer overwrite timer state.
2026-01-31 07:28:55 -06:00
Brad Groux
d8dab5a612 chore: bump version to v1.1.0 + changelog 2026-01-31 07:09:18 -06:00
Brad Groux
a81b4ea1f7 Merge feat/v1.1-agent-routing-16-17-18: agent routing, chat interface (#16, #17, #18) 2026-01-31 07:08:06 -06:00
Brad Groux
cb3d3cdc04 fix: chat delete + export + input focus
- Fix delete not clearing UI (React Query kept stale data on 404 refetch)
- Fix post-delete send breaking (server recreates task sessions instead of 404)
- Add chat export as markdown (download icon next to trash)
- Auto-focus input on panel open and after each send
- Defensive delete on server (handle already-deleted sessions)
2026-01-31 07:06:00 -06:00
Brad Groux
321071b2b8 feat: chat clear history + title updates
- Board Chat / Task Chat dynamic title
- Trash icon in header to clear chat history
- Confirmation dialog before deleting
- Re-initializes task session after clear
- Floating chat bubble from previous commit
2026-01-31 06:49:35 -06:00
Brad Groux
974255bff3 feat: floating chat bubble with pulse indicator
- Floating chat icon in bottom-right corner
- Opens board-level chat (not tied to any task)
- Pulsing green dot when new response arrives while closed
- Hides bubble when chat panel is open
- Clears unread indicator on open
2026-01-31 06:46:26 -06:00
Brad Groux
89a5fd8b20 feat: wire up chat AI responses via Clawdbot gateway, fix UI bugs
- Chat now generates actual AI responses via Clawdbot gateway WebSocket
- Gateway chat client handles auth, streaming deltas, and final response
- Chat responses broadcast to UI via kanban WebSocket (shared connection)
- Fix double X close button on chat panel (SheetContent built-in + manual)
- Move Chat/Template buttons above tab row to reduce cramping
- Chat/Template buttons now 50/50 full width
- Fix subtask add button height mismatch
- Fix chat send crash (API response type mismatch)
- Remove non-functional agent/model dropdowns from chat panel
- Add model picker (sonnet/opus/haiku) to Agent panel in task detail
- Replace tooltip with inline mode hint text in chat
- Load chat history on panel open (deterministic task session ID)
- Chat stream uses shared WebSocket instead of opening duplicate connection
2026-01-31 06:44:42 -06:00
Brad Groux
643b62d90d feat: add agent filter to board FilterBar
- Agent dropdown in same row as search, project, type filters
- Options: All Agents, Auto (routing), Unassigned, + each configured agent
- URL sync support (?agent=claude-code)
- Filter logic handles auto, unassigned, and specific agent matching
2026-01-31 06:07:03 -06:00
Brad Groux
878ea8d088 fix: sticky header + match indicator dot sizes
- Header: sticky top-0 z-50 so it stays visible on scroll
- Agent status dot: w-2.5 → w-2 to match WebSocket indicator size
2026-01-31 06:04:02 -06:00
Brad Groux
c198f1c2c7 feat: chat interface frontend — panel, streaming, keyboard shortcuts (#18)
- ChatPanel: right-side slide-out panel with agent/model selectors
- Markdown rendering, tool call collapsible blocks, streaming indicator
- Ask/Build mode toggle for read-only vs mutation-capable conversations
- Task-scoped chat (from task detail) and board-level chat
- Cmd+Shift+C keyboard shortcut to toggle chat panel
- Chat button in header toolbar
- Chat tab in task detail panel
- API hooks (useChatSession, useSendChatMessage, useChatStream)
- WebSocket streaming placeholder (ready to wire up)
2026-01-31 06:02:17 -06:00
Brad Groux
fe721fd96b feat: chat interface frontend — panel, streaming, keyboard shortcuts (#18) 2026-01-31 06:01:21 -06:00
Brad Groux
e8e153d037 feat: chat interface backend — storage, API, WebSocket (#18) 2026-01-31 05:58:43 -06:00
Brad Groux
d12dcd6278 fix: align Sprint and Agent labels in task forms 2026-01-31 05:57:38 -06:00
Brad Groux
782f36c85b feat: agent selection on task creation (#17)
- Add agent field to CreateTaskForm state with 'auto' default
- Agent dropdown in CreateTaskDialog (Auto + all enabled agents)
- Agent field in TaskMetadataSection (task detail panel) — editable inline
- Pass agent through useTemplateForm to task creation API
- Server: accept agent field in create/update task schemas
- TaskService: persist agent field on task creation
- AgentPanel: pre-select task's assigned agent (priority: manual > pre-assigned > routed > default)
- Sprint and Agent dropdowns now share a row for compact layout
2026-01-31 05:53:33 -06:00
Brad Groux
fa7ac0fe1a feat: task-aware agent routing engine (#16)
- Add AgentRoutingConfig types with RoutingRule, RoutingMatchCriteria, RoutingResult
- Add DEFAULT_ROUTING_CONFIG with sensible defaults (code/bug/docs/review rules)
- Create AgentRoutingService with resolveAgent() and getFallback() methods
- First-match-wins rule evaluation with type, priority, project, minSubtasks criteria
- Array support for match criteria (e.g., type: ['code', 'bug'])
- Routing API: POST /agents/route, GET/PUT /agents/routing
- Integrate routing into ClawdbotAgentService.startAgent() for 'auto' agent selection
- Add agent field to Task, CreateTaskInput, UpdateTaskInput, TaskSummary schemas
- Settings UI: routing rules section in Agents tab with add/edit/remove/reorder
- Agent Panel: show routing recommendation when starting agent
- 17 unit tests for routing service (all passing)
- Full typecheck clean across shared, server, and web packages
2026-01-31 05:18:44 -06:00