Commit graph

418 commits

Author SHA1 Message Date
Brad Groux
a249dee1fb Merge: Squad chat, webhooks, delegation, polling + critical security fixes
Feature branches merged:
- Agent squad chat with real-time WebSocket updates
- Broadcast notifications (priority levels, read receipts)
- Task deliverables as first-class objects
- Efficient polling endpoint with change tracking
- Approval delegation / vacation mode

Security & stability fixes:
- Fix: path traversal vulnerability in broadcast storage
- Fix: TOCTTOU race condition in broadcast.markRead()
- Fix: double cache invalidation in squad chat
- Fix: file locking consistency for concurrent writes
- Add: default agent display name handling

Improvements:
- React.memo for message bubbles (perf)
- Save-on-blur for display name input
- Auto-scroll to latest in squad chat
- OpenClaw gateway wake integration
- One-agent-per-file development rule (CONTRIBUTING.md)

All reviews passed (code, functionality, performance, security)
27 files changed, comprehensive test coverage added

v2.0.0 ready for production
2026-02-07 11:30:52 -06:00
Brad Groux
ce429dd1b3 fix: allow WebSocket connectSrc in production CSP 2026-02-07 08:50:54 -06:00
Brad Groux
1183a4b02a feat: wire DelegationTab into settings dialog + merge all feature branches 2026-02-07 08:24:45 -06:00
Brad Groux
c3f67da1f9 merge: integrate broadcast endpoint into main 2026-02-07 08:20:34 -06:00
Brad Groux
181939739f merge: resolve conflicts integrating polling + broadcast endpoints 2026-02-07 08:20:21 -06:00
Brad Groux
1eb93b1dd0 Merge branch 'feat/agent-squad-chat' 2026-02-07 08:20:06 -06:00
Brad Groux
c67173a7e0 feat: deliverables as first-class task objects (#95)
- Add Deliverable interface with type, status, path, agent fields
- Add deliverables field to Task, UpdateTaskInput, TaskSummary
- Create API endpoints: POST/GET/PATCH/DELETE /api/tasks/:id/deliverables
- Add requireDeliverableForDone setting (default: false)
- Validate done transition requires deliverable when setting enabled
- Add DeliverablesSection component to task detail panel
- Add deliverable count badge to board cards
- Add settings toggle in Tasks tab
- Log deliverable_added/updated/deleted activity events
- Add useDeliverables hooks for CRUD operations
2026-02-07 08:18:18 -06:00
Brad Groux
5225658e3a feat: agent squad chat channel (#97) 2026-02-07 08:14:54 -06:00
Brad Groux
f00bba7010 feat: broadcast endpoint for agent notifications (#98) 2026-02-07 08:09:53 -06:00
Brad Groux
2309e1e09d fix: remove stray broadcast route reference 2026-02-07 08:06:28 -06:00
Brad Groux
4f513017f9 feat: add efficient agent polling endpoint (changes since) (#96) 2026-02-07 08:05:38 -06:00
UC-VR
f17568cd21
feat: configurable auto-save delay for task editor (#94)
- Add autoSaveDelayMs to TaskBehaviorSettings (default: 500ms)
- Update useDebouncedSave hook to use config setting instead of hardcoded value
- Add UI control in Tasks settings tab (slider: 200-5000ms, step 100)
- Add validation schema (min: 200ms, max: 5000ms)

The default 500ms delay was too aggressive for comfortable text editing,
causing interruptions mid-sentence. This makes the delay user-configurable
to accommodate different typing speeds and preferences.

Co-authored-by: OpenClaw Agent <agent@openclaw.ai>
2026-02-07 07:36:59 -06:00
Brad Groux
9cd0eb2858 docs: add favicon to v2.0.0 changelog 2026-02-05 20:57:59 -06:00
Brad Groux
4fc8f29be6 feat: add purple scales of justice favicon
Replaces default Vite logo with a custom SVG favicon —
purple circle with white scales of justice cutout.
2026-02-05 20:56:24 -06:00
Brad Groux
8cfe28326d docs: comprehensive v2.0.0 documentation update
- FEATURES.md: Added Multi-Agent System section (registry, dashboard,
  assignment, mentions, permissions, error learning, doc freshness)
- FEATURES.md: Added Dashboard Widgets section (activity clock, hourly
  activity, where time went, wall time, session metrics, widget toggles,
  lifecycle hooks, cost prediction, timezone-aware metrics)
- FEATURES.md: Added v2.0 API endpoints to route table
- FEATURES.md: Updated response envelope with timezone meta fields
- CHANGELOG.md: Added #92 Dashboard Widget Toggles to v2.0.0
- README.md: Moved #92 from backlog to shipped in v2.0.0
- README.md: Cleaned stale 'NEW — v1.x' tags from pre-v2.0 features
- CLAUDE.md: Updated to v2.0.0 — added mcp/ package, multi-agent
  lessons, registry/telemetry file locations
- security.md: Added v2.0.0 changelog entry (permissions, MCP patch)
- All docs verified: no broken links, no stale version refs, no secrets
2026-02-05 20:54:37 -06:00
Brad Groux
ed8606fb74 feat: per-widget dashboard visibility toggles
Add individual on/off toggles for each dashboard widget in
Settings > Board & Display. When 'Show Dashboard' is enabled,
a nested list of 12 widget toggles appears:

- Token Usage, Run Duration, Agent Comparison, Status Timeline
- Cost per Task, Agent Utilization, Wall Time, Session Metrics
- Activity Clock, Where Time Went, Hourly Activity, Trends Charts

All default to ON. Server-side Zod schema updated to accept
the new dashboardWidgets object. Shared types already had the
DashboardWidgetSettings interface from a prior commit.
2026-02-05 20:48:35 -06:00
Brad Groux
69cf3c334c chore: v2.0.0 release prep
Version:
- Bump all packages to 2.0.0 (root, server, web, shared, mcp)

Security:
- Patch MCP SDK from ^1.25.3 to ^1.26.0 (GHSA-345p-7cg4-v4c7)
- Add rate limiting warning to README security section

Documentation:
- CHANGELOG: comprehensive v2.0.0 entry (18 features, fixes, credits)
- README: updated roadmap with v2.0 shipped features
- README: added v2.0 feature highlights (multi-agent, dashboard, lifecycle)
- README: version badge updated to 2.0.0
- AGENT-REGISTRY.md: VERITAS naming consistency (all caps)

Maintenance:
- Cleaned 21 stale feature branches (down to main only)
- Dashboard widget toggles scaffolding (#92)
- Pre-commit secret scan: clean
2026-02-05 20:45:36 -06:00
Brad Groux
c7ade9d32c VERITAS — all caps (it's an acronym) 2026-02-05 20:20:10 -06:00
Brad Groux
c1d8f975f2 fix: archive optimistic update, registry stats, cost-per-task UX, outlier cap
Archive:
- Optimistic removal from cache on archive (instant UI update)
- Rollback on error, refetch on settle

Agent Registry:
- Fix RegistryStats interface to match server (total/online/busy/idle/offline)
- Add 'idle' status style (blue) to MultiAgentPanel
- Panel already dynamic — no hardcoded agent limit

Cost Per Task:
- Enhanced clickable styling (border, hover highlight, arrow indicator)
- Tasks already wired to open-task event

Telemetry:
- Capped 3 Feb 2 outliers from 15-19min to 10min
- Token events verified present for Feb 3-5 (backfilled earlier)
2026-02-05 20:08:15 -06:00
Brad Groux
7c272963f5 docs: comprehensive Agent Registry documentation
- Full API reference (register, heartbeat, list, stats, capabilities, deregister)
- Agent lifecycle diagram (online → busy → idle → offline)
- Current 10-agent roster with roles, models, capabilities
- Sub-agent spawn template with registration block
- Name assignment order (TARS through Marvin)
- Dashboard integration notes
- Configuration reference
- File format spec
- Troubleshooting guide
2026-02-05 20:04:54 -06:00
Brad Groux
6d0bca3ed9 feat: register all 10 named agents + fix route ordering
Agent Roster:
- Veritas (orchestrator, Opus 4.6)
- TARS, CASE (leads, Opus 4.6)
- Ava, R2-D2, K-2SO, MAX, Bishop (specialists, Sonnet 4.5)
- Johnny 5, Marvin (interns, Haiku 4.5)

Fix: mount /agents/register and /agents/permissions BEFORE
/agents catch-all routes to prevent /:taskId param matching
2026-02-05 19:58:06 -06:00
Brad Groux
ddd5049d45 fix: comprehensive dashboard plumbing overhaul
Data fixes:
- Backfill agent='veritas' on 987 telemetry events (were 'unknown')
- Backfill run.tokens events for Feb 3-5 (46 events, estimated from durations)
- Reset stuck agent status to idle

Utilization:
- Switch from status-history (1 entry!) to telemetry-based computation
- Timezone-aware date bucketing via tz query param
- Current day uses elapsed time, not full 24h

Dashboard layout:
- Remove Success Rate chart (redundant with Session Metrics)
- Task Activity Per Day now full width
- Fix tooltip info icons (delayDuration=0, asChild, button wrapper)
- Default period changed from 3d to 7d (token data starts Jan 31)
2026-02-05 19:43:08 -06:00
Brad Groux
2952c4b3f1 feat: timezone-aware metrics via tz query param
- Add ?tz=<offset> to metrics endpoints (e.g. ?tz=-6 for CST, ?tz=9 for JST)
- Server defaults to system time when tz is omitted
- Client auto-sends browser timezone offset on utilization requests
- Shared helpers: toLocalDateStr(), getTodayStr(), getElapsedTodayMs()
- Date bucketing and 'today' detection respect the requested timezone
- Works for any timezone — not hardcoded to any region
2026-02-05 19:30:18 -06:00
Brad Groux
23a96d3ea7 feat: add timezone offset to all API response meta
Every API response now includes:
  meta.timezone: 'UTC-06:00' (human-readable)
  meta.utcOffset: -6 (numeric, for client-side math)

Uses system time — no config needed.
2026-02-05 19:24:22 -06:00
Brad Groux
db6d741b3f fix: use system local timezone for utilization date bucketing
- 'Today' detection uses local time (getHours) not UTC (getUTCHours)
- Event timestamps converted to local dates for daily bucketing
- Fixes Feb 5 CST events being bucketed into Feb 6 UTC
- Server uses system timezone (America/Chicago = CST/CDT)
2026-02-05 19:22:05 -06:00
Brad Groux
b9cf2f4a29 fix: dashboard plumbing audit — utilization, activity sources, data integrity
- Fix daily utilization: use elapsed time for current day (was 100% because
  active time ÷ 0 hours elapsed = infinity, capped to 100%)
- Activity Clock + Hourly Activity: switch from broken activity.json (1 record)
  to status-history endpoint (has actual agent state transitions)
- Task-cost API: add project + totalDurationMs fields for Where Time Went
- Where Time Went: pull real project data from task-cost telemetry
- Wall Time toggle: rewrite with clear labels + info tooltips
- Normalize Feb 3 telemetry outlier (66min → 19min)

GH #92 created: Dashboard widget toggles with descriptions
2026-02-05 19:09:50 -06:00
Brad Groux
63eea30aad fix: dashboard overhaul per Brad's review feedback
- Remove Success/Errors card (Sessions widget covers it)
- Activity Over Time: add Y-axis 'Events' label
- Where Time Went: pull real data from telemetry by project (was blank)
- Wall Time: rewrite as Total Agent Time + Avg Run Duration with tooltips
- Activity Clock: add info tooltip explaining the visualization
- Agent Comparison: lower minRuns to 1 so all agents show
- Task-cost API: add project + totalDurationMs fields for widgets
- Normalize Feb 3 time outlier (66min → 19min, capped at p95)
- TrendsCharts (Task Activity per Day): full width layout
2026-02-05 19:01:17 -06:00
Brad Groux
2ddc8aacc3 fix: resolve web TypeScript errors — unused imports, API references, type corrections
- Remove unused imports (Eye, useMemo, MODE_ICONS, Briefcase)
- Fix SessionMetrics to use useMetrics hook instead of non-existent api.telemetry
- Update dashboard widgets to use correct DurationMetrics properties (avgMs, runs)
- Simplify SessionMetrics estimation logic to work with existing metrics interface
2026-02-05 18:52:42 -06:00
Brad Groux
21d3fed50b fix: resolve build errors — storage paths, type casts, import ordering, backward compat
- Replace non-existent getStorageBase with DATA_DIR inline constant
- Fix import ordering (path must be imported before DATA_DIR declaration)
- Fix req.params/req.query type casts for Express strict mode
- Add createNotification() to NotificationService for failure-alert backward compat
- Export NotificationService class for type imports
- Cast telemetry events properly in cost-prediction service
- Server builds clean and starts successfully
2026-02-05 18:49:39 -06:00
Brad Groux
5ea3e58964 feat: add branded PDF report generation with templates and brand config (closes #90)
Inspired by @nateherk's Klouse branded PDF reports.

- 5 report templates: audit, summary, analysis, standup, custom
- Brand config: company name, logo, colors, font, tagline
- Markdown → HTML conversion with print-optimized CSS
- Template-specific styles (audit findings, metrics cards, status colors)
- HTML served directly or printable to PDF via browser
- Reports stored in docs/reports/ and accessible via docs tab
- REST API: generate, list, get, brand CRUD, templates, HTML serve
2026-02-05 18:38:45 -06:00
Brad Groux
0ade973d7d feat: add scheduled deliverables view — recurring workflows and outputs (closes #89)
Inspired by @nateherk's Klouse scheduled deliverables view.

- Deliverables: daily/weekly/biweekly/monthly/custom schedules
- Run tracking: success/failed/skipped with output files and summaries
- Next run calculation, enable/disable toggle
- REST API: CRUD deliverables, record runs, run history
- Tags, agent assignment, output path configuration
- Persistent storage with 500-run history cap
2026-02-05 18:37:04 -06:00
Brad Groux
6c47b8801c feat: add docs tab with markdown viewer, editor, and file browser (closes #88)
Inspired by @nateherk's Klouse dashboard docs section.

- DocsService: CRUD for markdown files, search by name/content, directory listing
- Path traversal protection: resolved paths validated against docs root
- REST API: list, get, save, delete, search, directories, stats
- DocsViewer component: file browser sidebar + markdown preview/editor
- Directory navigation, file search, inline editing with save
- Create new docs, delete existing, file size + modified timestamps
- Configurable docs root via VK_DOCS_DIR env var
2026-02-05 18:35:46 -06:00
Brad Groux
0aedd8c969 feat: add 5 dashboard widgets — time breakdown, activity clock, hourly chart, wall time toggle, sessions (closes #57, #58, #59, #60, #61)
- WhereTimeWent (#57): Time breakdown by workstream with progress bars
- ActivityClock (#58): 24-hour donut chart showing activity distribution
- HourlyActivityChart (#59): Bar chart of hourly activity over time
- WallTimeToggle (#60): Toggle between wall time and active time with efficiency %
- SessionMetrics (#61): Session count, success rate, avg duration, completed/failed/abandoned
- All widgets responsive, using existing useMetrics + activity API
- Integrated into Dashboard in new grid layout sections
2026-02-05 18:32:30 -06:00
Brad Groux
ec364c1695 docs: add documentation freshness guide with steward workflow (closes #74)
Inspired by Monika Voutov's BoardKit Orchestrator — 'stale docs = hallucinating AI'

- Doc update checklist for every task completion
- Freshness headers format: date | version | updater
- Three-phase automation plan: manual → hook-based → AI doc steward
- Repo rules (CLAUDE.md equivalent) for agents
- Trigger matrix: when to update what
- Credit: @mvoutov
2026-02-05 18:30:24 -06:00
Brad Groux
8963293e38 feat: add task lifecycle hooks — configurable automation on state transitions (closes #72)
Inspired by Monika Voutov's BoardKit Orchestrator (https://github.com/BoardKit/orchestrator)

- 7 built-in hooks: log, time start/stop, verify checklist, request context, notify, telemetry
- 8 lifecycle events: created, started, blocked, done, cancelled, assigned, commented, reviewed
- Custom hooks: create your own with filters (task type, project, priority)
- Execution log: track hook runs with timing and success/failure
- Extensible: registerHandler() for custom action types
- REST API: CRUD hooks, manual fire, execution history
- Fixed duplicate notification import in v1/index.ts
2026-02-05 18:29:30 -06:00
Brad Groux
5af107d0a1 feat: add agent permission levels — intern/specialist/lead with approval workflow (closes #31)
- Three levels: intern (needs approval), specialist (independent), lead (full autonomy)
- Permission checks: canCreateTasks, canDelegate, canApprove, autoComplete
- Approval queue: interns request approval, leads review
- Trusted domains: scope specialist agents to specific capabilities
- Custom restrictions: block specific endpoint patterns per agent
- REST API: GET/PUT/PATCH permissions, POST check, approval CRUD
- Persistent storage: agent-permissions.json, approval-requests.json
2026-02-05 18:27:41 -06:00
Brad Groux
c57e368a25 docs: add mandatory telemetry emission steps to agent docs
The dashboard's Success Rate, Token Usage, and Average Run Duration
graphs are powered by run.* telemetry events that agents must emit
manually — they are NOT auto-captured like task.* events.

This has broken multiple times when agents lost their AGENTS.md
instructions. Now documented in:
- AGENTS-TEMPLATE.md (copy-paste for new agents)
- SOP-agent-task-workflow.md (full API flow with telemetry steps)

Both docs now include the exact curl commands for run.started,
run.completed, and run.tokens events, plus a table clarifying
what's auto-captured vs. manual.
2026-02-05 18:26:34 -06:00
Brad Groux
2620e9a79c feat: add @mention notification system with thread subscriptions (closes #30)
- Notification Service: @mention parsing, delivery tracking, thread subscriptions
- Mention parser: extracts @agent-name from text, supports @all broadcast
- Thread subscriptions: auto-subscribe on comment, mention, or assignment
- Delivery tracking: mark individual or bulk-deliver notifications
- REST API: GET notifications, POST process, POST delivered, GET stats
- Notification types: mention, assignment, status_change, reply
- Persistent storage: notifications.json + thread-subscriptions.json
2026-02-05 18:18:47 -06:00
Brad Groux
dead22ba40 feat: add multi-agent task assignment with backward-compatible agent/agents fields (closes #29)
- Task schema: added agents[] field alongside existing agent field
- Agent helpers: getAssignedAgents(), isAgentAssigned(), normalizeAgentFields()
- MultiAgentSelector component: chips with colors, add/remove, primary star
- Registry integration: dropdown shows registered agents + custom input
- Backward compat: single agent auto-wrapped in array, agents[0] synced to agent
- Exported from shared package for CLI/server/web consumption
2026-02-05 18:17:25 -06:00
Brad Groux
65b766d504 feat: add multi-agent dashboard sidebar with registry integration (closes #28)
- MultiAgentPanel component: shows all registered agents with live status
- Agent cards: status dot, model, capabilities, current task, heartbeat
- Merges registry data with real-time WebSocket status
- Registry API client: list, stats, get agent
- Integrated into BoardSidebar below existing AgentStatusPanel
- Color scheme: green=online, purple=busy, gray=offline, red=error
- Expandable cards show capabilities, provider, version, heartbeat
2026-02-05 18:15:41 -06:00
Brad Groux
35277d5c10 feat: add error learning workflow — structured failure analysis and knowledge capture (closes #91)
Inspired by @nateherk's Klouse dashboard approach:
'Spin up agents to analyze what broke, why, and how to prevent it'

- Error Learning Service: submit errors, structured analysis, pattern detection
- Auto-tags, severity estimation, repeat detection
- Links analyses to task lessonsLearned field
- Similarity search for 'have we seen this before?'
- Aggregate stats: by type, severity, repeat rate, top prevention steps
- REST API: POST /submit, PATCH /:id, GET /, GET /stats, GET /search
2026-02-05 18:06:25 -06:00
Brad Groux
76c40f2d67 docs: add multi-agent git workflow guide — lessons from v2.0 sprint
- Branch collision problem and real-world example
- Three solutions: sequential, git worktree, orchestrator pattern
- Sub-agent task template with git rules
- Pre-commit hook handling for multi-agent
- Secret scanning SOP
- Orchestrator checklist
2026-02-05 18:04:51 -06:00
Brad Groux
c13ee08fbf feat: add task cost prediction at creation with accuracy tracking (closes #54)
- Cost Prediction Service: predicts task cost based on type, priority, complexity, history
- Prediction factors: type multiplier, priority multiplier, description complexity, project adjustment
- Historical base cost: calculated from telemetry data for similar tasks
- Confidence levels: low/medium/high based on sample size
- Accuracy tracking: predicted vs actual cost comparison for completed tasks
- Accuracy stats: MAE, mean/median accuracy, within-20%/50% metrics, per-type breakdown
- Task schema: added costPrediction and actualCost fields
- REST API: POST /predict, GET /accuracy, GET /accuracy/stats
2026-02-05 18:02:39 -06:00
Brad Groux
2a7ed97682 Merge branch 'feat/markdown-rendering-63-clean' 2026-02-05 17:56:09 -06:00
Brad Groux
d52ec5b7de Merge branch 'feat/cli-usage-reporting-50' 2026-02-05 17:56:09 -06:00
Brad Groux
fcf1756b79 feat: add agent self-reporting protocol with registry, heartbeat, and discovery (closes #52)
- Agent Registry Service: registration, heartbeat, capability discovery, stale detection
- REST API: POST /register, POST /:id/heartbeat, DELETE /:id, GET /stats, GET /capabilities/:cap
- Persistent storage: .veritas-kanban/agent-registry.json
- Auto-offline: agents without heartbeat for 5min marked offline
- AGENTS.md template: docs/AGENTS-TEMPLATE.md with full integration guide
2026-02-05 17:56:04 -06:00
Brad Groux
9c2f193658 feat: add markdown rendering for task descriptions and comments (closes #63) 2026-02-05 17:55:44 -06:00
Brad Groux
8e8e928380 feat: add CLI usage reporting commands (closes #50) 2026-02-05 17:53:52 -06:00
Brad Groux
931d437b67 chore: Release v1.6.0
## Highlights
- Activity Page Redesign — Full-width status history, clickable navigation, color-coded badges
- Task Templates UI (#39) — Full management interface for templates
- Analytics API (#43) — Timeline and aggregate metrics endpoints
- Status Transition Hooks — Quality gates for task status changes
- 7 GitHub Issues Closed (#47, #48, #49, #51, #53, #56, #82)

## Changes
- Bump all packages to 1.6.0
- Update CHANGELOG.md with comprehensive release notes
- Update README.md version badge and roadmap
- Update FEATURES.md with new sections:
  - Task Templates (v1.6.0)
  - Analytics API (v1.6.0)
  - Dashboard Filter Bar (v1.6.0)
  - Redesigned Activity Feed section
- Activity page: purple for sub-agent, amber for in-progress, blue for done
- Status badges: uniform width, color-coded by status type
2026-02-04 22:11:13 -06:00
Brad Groux
886504c91d feat(activity): Add task status changes with kanban column colors
- Merged agent status and task status changes into unified view
- Task status badges use kanban column colors:
  - todo → slate
  - in-progress → blue
  - blocked → amber
  - done → green
- Both types sorted by timestamp, grouped by day
- Task ID + title clickable to open task
2026-02-04 21:22:39 -06:00