Commit graph

358 commits

Author SHA1 Message Date
Brad Groux
e00a72bb3d perf: Stream telemetry reads, push pagination to service, optimize lookups
PERF-001: Replace gunzipSync with streaming readline + createGunzip
         Apply filters during streaming for early rejection

PERF-002: Add offset parameter to activity service getActivities()
         Route uses offset instead of fetching page*limit and slicing

PERF-003: BacklogRepository findById() uses file prefix lookup O(n) → O(1)
         task-metrics velocity uses Set for archived IDs (O(n²) → O(n))
         audit-service verifyAuditLog() uses readline streaming

Ref: RF-002a audit findings (Medium/Low severity)
2026-02-04 09:56:19 -06:00
Brad Groux
ac1386ac12 fix(QA): Replace Math.random with crypto.randomUUID, align types, fix React issues
QA-001: Use crypto.randomUUID() for entity IDs (comments, subtasks, verification)
QA-002: Add 'critical' to TaskPriority, 'cancelled' to TaskStatus; guard process.env
QA-003: Fix GitSelectionForm useEffect deps, AgentStatusIndicator useMemo tick,
        ArchivePage Set mutation
Bonus: Add variant to Toast type (pre-existing build error)

Ref: RF-002a/b/c audit findings
2026-02-04 09:52:54 -06:00
Brad Groux
f176592259 feat(US-1611): Complete orchestrator-inspired features
- #73 Prompts registry: prompt-registry/ with 10 starter templates ✓
- #74 Doc freshness: CLAUDE.md template + SOP-documentation-freshness.md ✓
- #75 Setup wizard: vk setup command ✓
- #76 Lifecycle hooks: hook-service.ts + SOP-lifecycle-hooks.md ✓
- #77 Shared resources: SOP-shared-resources.md ✓

Credit: Inspired by Monika Voutov's BoardKit Orchestrator
https://github.com/BoardKit/orchestrator

Closes #73, closes #74, closes #75, closes #76, closes #77
2026-02-04 09:47:38 -06:00
Brad Groux
4a1cf7d36d docs: US-1611 SOP-shared-resources — multi-repo resource sharing patterns
Added docs/SOP-shared-resources.md covering:
- Single repo vs multi-repo directory structures
- Mounting strategies (copy, symlinks, git submodules, npm packages)
- What to share vs what to keep project-specific
- Referencing shared resources in tasks and prompts
- Versioning and update protocols
- Migration checklist

Updated GETTING-STARTED.md to reference the new prompt-registry templates.

Credit: BoardKit Orchestrator (Monika Voutov) for the shared resources pattern.

Closes #77
2026-02-04 09:36:02 -06:00
Brad Groux
43c01ec8e8 feat: US-1611 prompt-registry — 10 copy/paste prompt templates
Created prompt-registry/ folder with starter templates:
- sprint-planning.md — Break epics into sprints
- worker-handoff.md — PM → Worker assignment
- cross-model-review.md — Claude ↔ GPT review gate
- feature-development.md — E2E feature implementation
- bug-triage.md — Investigation and fix workflow
- research-report.md — Deep research deliverable
- task-completion.md — Pre-completion checklist
- blocked-escalation.md — Blocker reporting
- pm-orchestration.md — PM agent managing workers
- standup-summary.md — Daily status report

Updated docs to reference prompt-registry/ instead of shared/prompt-registry/.

Credit: BoardKit Orchestrator (Monika Voutov) for the registry pattern.

Closes #69
2026-02-04 09:34:36 -06:00
Brad Groux
bf04c95421 docs: update CHANGELOG, README, TIPS-AND-TRICKS for v1.5.0 features
- CHANGELOG.md: Added CLI section for vk setup, Fixed section for archive/metrics/backlog bugs, Security section for SEC-001 extensions
- README.md: Added Setup & Onboarding section with vk setup examples
- TIPS-AND-TRICKS.md: Added vk setup to CLI shortcuts table
- GETTING-STARTED.md: Updated to reference vk setup as available (not roadmap)
2026-02-04 09:29:44 -06:00
Brad Groux
89d6efbe6e feat(cli): US-1611 vk setup — guided onboarding wizard
New CLI command that validates environment and helps new users get started:

- Checks Node version (requires >=18)
- Verifies server is running and accessible
- Tests API authentication
- Optionally creates a welcome task with next steps
- Supports --json output for automation
- Supports --skip-task to skip sample task creation

Updated docs/GETTING-STARTED.md to reference the new command.

Credit: BoardKit Orchestrator (Monika Voutov) for the wizard pattern inspiration.

Closes #71
2026-02-04 09:14:01 -06:00
Brad Groux
30e18393f4 fix(security): SEC-001 path traversal — add validation to trace + template services
Extended path traversal protection to two services missed in initial audit:

- trace-service.ts: validate attemptId, taskId, traceId before path.join
- template-service.ts: validate templateId in templatePath()

Both now use validatePathSegment() + ensureWithinBase() from utils/sanitize.ts.

Ref: RF-002a Batch 3a Findings (High+Medium severity)
2026-02-04 09:08:35 -06:00
Brad Groux
ed1fbb3fb4 fix: sidebar task counts now show current state, not time-filtered
Bug 1: /api/metrics/all was passing the period filter to task counts,
showing only tasks touched within the time window (e.g., 33 todo in 24h)
instead of current board state (124 todo total).

Fix: computeAllMetrics now passes null to computeTaskMetrics so task
status counts always reflect current state. Period filter still applies
to telemetry metrics (runs, tokens, duration).

Bug 2: /api/backlog/count was double-wrapping response (route wrapped
with success/data, then middleware wrapped again).

Fix: Route now returns { count } and lets responseEnvelopeMiddleware
handle wrapping.
2026-02-04 09:02:16 -06:00
Brad Groux
f508c00593 fix: archive/delete/restore now find actual file on disk
Bug: taskToFilename() generates filename from current title, but the
actual file on disk may have a different slug if the title changed after
creation. This caused INTERNAL_ERROR on archive/delete/restore.

Fix: Added findTaskFile() helper that searches by task ID prefix instead
of computing the expected filename. Applied to archiveTask, deleteTask,
and restoreTask.

Also: archiveSprint now throws ValidationError instead of generic Error
for better API error responses.
2026-02-04 08:54:27 -06:00
Brad Groux
9291ba1cb3 fix: Update version to 1.5.0 in all package.json files
- Root package.json: 1.4.1 → 1.5.0
- server/package.json: 1.4.1 → 1.5.0
- web/package.json: 1.4.1 → 1.5.0
- shared/package.json: 1.4.1 → 1.5.0

Health endpoint now reflects correct version.
2026-02-04 08:40:24 -06:00
Brad Groux
995eabe93a chore: Bump version to 1.5.0 + update CHANGELOG
Version 1.5.0 release includes:
- Complete SOP documentation suite (8 new guides in docs/)
- GH-86 fix: Bulk archive error handling + toasts
- GH-87 fix: Sidebar metrics cache sync
- Script improvements for launchd reliability

See CHANGELOG for full details.
2026-02-04 08:33:48 -06:00
Brad Groux
eeb11ba219 feat(US-1600): Complete SOP Sprint + fix GH-86 & GH-87
Documentation (8 new files in docs/):
- GETTING-STARTED.md: 5-min quickstart, BoardKit insights, sanity checks
- SOP-agent-task-workflow.md: Full lifecycle (claim → work → complete)
- SOP-sprint-planning.md: Epic → sprint → task hierarchy + estimation
- SOP-multi-agent-orchestration.md: PM + worker roles, handoff patterns
- SOP-cross-model-code-review.md: Claude ↔ GPT gate, checklist, RF-002 ref
- BEST-PRACTICES.md: 10 DOs + 10 DON'Ts based on real usage
- EXAMPLES-agent-workflows.md: 6 copy/pasteable recipes (feature, bug fix, docs, audit, content, research)
- TIPS-AND-TRICKS.md: CLI shortcuts, keyboard shortcuts, integrations (MCP, git worktrees, Obsidian)
- README.md: Added 'Documentation Map' linking all new docs

Bug Fixes:
- fix(GH-86): BulkActionsBar now handles archive errors gracefully
  * Per-task error tracking (replaces Promise.all)
  * Toast notifications on success/partial/failure
  * Logs individual failures to console

- fix(GH-87): Sidebar metrics now stay in sync with board state
  * Invalidate metrics cache when task status changes
  * Prevents up-to-30s lag in sidebar counts
  * Preserves timer state during mutations

Scripts:
- scripts/dev-clean.sh: Added explicit pnpm path resolution for launchd
- scripts/dev-watchdog.sh: Fixed restart storm prevention + pnpm path

BREAKING: None
TESTING:
- Manual: Bulk archive Done column tasks, verify toasts appear
- Manual: Move tasks between columns, verify sidebar counts update <2s
- Unit: Consider regression tests for metrics invalidation
2026-02-04 08:18:01 -06:00
Brad Groux
4936a64b12 docs(readme): link history rewrite notice 2026-02-04 01:22:35 -06:00
Brad Groux
2192ca6beb docs: note planning is not a status (agent-facing) 2026-02-04 00:35:50 -06:00
Brad Groux
895b3b1e3a Merge pull request #83 from BradGroux/feat/dev-reliability-82-v2
Dev reliability: /api/health + dev:clean + watchdog
2026-02-04 00:22:15 -06:00
Brad Groux
d98c8c6615 Dev reliability: add /api/health, dev:clean, and dev watchdog 2026-02-03 23:41:10 -06:00
Brad Groux
855dbfc850 Revert "Dev reliability: add /api/health, dev:clean, and dev watchdog"
This reverts commit a1c19d5772.
2026-02-03 23:40:53 -06:00
Brad Groux
a1c19d5772 Dev reliability: add /api/health, dev:clean, and dev watchdog 2026-02-03 23:37:15 -06:00
Brad Groux
4e11a4e584 Fix docker startup when cwd is / (issue #62) (#78)
Co-authored-by: Brad Groux <bradgroux@Brads-Mac-mini.local>
2026-02-03 04:56:06 -06:00
Brad Groux
a87c28decf docs: align versioning to v1.4.1 (packages, README, changelog) 2026-02-03 01:51:21 -06:00
Brad Groux
8d2f624670 fix: restore example tasks to tracking (intentional repo content) 2026-02-02 20:03:24 -06:00
Brad Groux
57f637fe9d fix: remove tracked task files and update .gitignore
tasks/backlog/*.md and tasks/examples/*.md were not covered by
.gitignore — only active/ and archive/ were. Added both patterns
and removed 56 tracked task files from the index.

Files remain on disk (only removed from git tracking).
2026-02-02 20:03:00 -06:00
Brad Groux
774673b80a fix(security): RF-002 — path traversal, admin authz, agent status WebSocket
SEC-001: Path traversal prevention
- Add validatePathSegment() and ensureWithinBase() to server/src/utils/sanitize.ts
- Apply to chat-service (sessionId/taskId in file paths)
- Apply to conflict-service (filePath in path.join)
- Apply to clawdbot-agent-service (taskId/attemptId in log/request paths)

SEC-007: Admin authorization on mutating endpoints
- settings.ts: PATCH /features requires authorize('admin')
- config.ts: POST/PATCH/DELETE repos, PUT agents, PUT default-agent
- activity.ts: DELETE / requires authorize('admin')
- notifications.ts: POST/mark-sent/check require authorize('admin','agent'), DELETE requires admin
- status-history.ts: DELETE / requires authorize('admin')
- Updated test harnesses with admin auth injection

Agent Status Indicator: WebSocket fix
- BoardSidebar now uses useRealtimeAgentStatus (WebSocket) instead of useGlobalAgentStatus (polling)
- Fixed field name mismatch: server broadcasts 'activeAgents' but hook expected 'subAgents'
- Hook now correctly reads activeAgents from both WebSocket messages and REST fallback
- Added connection status indicator and stale detection to sidebar
- Fixed agent-status.ts spread order for persisted status restore

Pre-existing fixes included (from earlier RF-002 sub-agent diffs):
- auth.ts: X-Forwarded-For only trusted when trust proxy configured
- rate-limit.ts: isLocalhost returns false in production
- telemetry-service: CSV formula injection prefix sanitization
- Frontend: window.open noopener/noreferrer on all instances
2026-02-02 09:09:15 -06:00
Brad Groux
dc826961ba fix: reset subAgentCount on idle + agent status reporting SOP
The agent status indicator on the VK board was not updating during
sub-agent workloads because OpenClaw sub-agents (spawned via
sessions_spawn) run outside VK's clawdbot-agent-service — nothing
was POSTing to /api/agent/status.

Server fix:
- Reset subAgentCount to 0 when status transitions to idle
  (previously only cleared activeTask, errorMessage, and activeAgents)

Workflow fix (in clawd workspace):
- Created vk-status.sh script to wrap the agent status API
- Added mandatory SOP to AGENTS.md: orchestrator calls vk-status.sh
  before/after every spawn, and every sub-agent task prompt includes
  a curl POST to /api/agent/status as its first action
- Works regardless of which model runs the sub-agent (Codex, Sonnet,
  GPT, etc.) — both the orchestrator and the agent itself report in
2026-02-02 06:41:59 -06:00
Brad Groux
238433b2ad feat: RF-002 cross-model code audit — full codebase
Complete cross-model audit of Veritas Kanban codebase:
- Auditor: GPT-5.2 Codex (8 parallel batches)
- Reviewer: Claude Opus 4.5

Results: 331 files, 55,300 lines audited
- 39 confirmed findings (91% Codex accuracy)
- 4 High, 16 Medium, 19 Low, 0 Critical
- Top patterns: path traversal (4), race conditions (8), state bugs (12)
- Estimated remediation: 16 hours across 4 sprints

Reports: 9 batch reports + executive summary + HTML presentation
All mirrored to Brain (dm-bg/refactoring/)
2026-02-02 05:39:01 -06:00
Brad Groux
59b0a8fd73 Merge feat/backlog-board-65: backlog board, dashboard overhaul, UI/UX refinements (#65, #66) 2026-02-02 04:56:51 -06:00
Brad Groux
6356a5e15e feat: backlog board, dashboard overhaul, UI/UX refinements (#65, #66)
Backlog Board (#65):
- BacklogRepository, BacklogService, API routes (/api/backlog/*)
- BacklogPage with inline expand/collapse, promote/demote actions
- CLI commands: vk backlog list|promote|demote|delete
- Activity events for demote/promote operations
- 47 tasks moved to backlog (sales, DM-Web, HubSpot, Customer.io)

Dashboard Overhaul:
- Recovered DashboardFilterBar from crashed branch (preset pills, custom date range, project filter)
- New metrics: Cost per Task, Agent Utilization (status-history-based)
- Fixed success rate calculation (backward-compat for status vs success field)
- Backfilled 23 estimated run.tokens events
- Task Activity per Day replaces Runs per Day chart
- Removed Sprint Velocity, Blocked Breakdown, period dropdowns
- Fixed ErrorsDrillDown empty state

Board & Sidebar:
- 5th column sidebar: Agent Status Panel (always visible), Recent Status Changes, Budget
- Clickable task names/IDs in agent status
- Removed planning column entirely (status, type, schemas, UI, CLI, MCP)
- Archive button in task detail panel (next to Delete)
- Select button moved to FilterBar row

Activity Page (#66):
- Removed tabs, side-by-side layout: Activity Feed (2/3) + Status History (1/3)
- Daily summary spans top

UI/UX:
- Command palette (Cmd+K)
- Theme toggle (Moon/Sun) in header
- Main padding increased, removed chat icon
- Cleaned up dead code (VelocityChart, MetricCard, unused imports)
- Fixed conditional hooks in CommandPalette
2026-02-02 04:56:47 -06:00
Brad Groux
de546c6e52 feat: full-width layout + archive page (unified design)
- Remove container max-width from main layout — all views now full-width
- Convert Archive from sidebar to full page with search, filters, bulk restore
- Add Archive nav button in header (replaces sidebar icon)
- Archive page matches Backlog/Activity design: expand-in-place, checkboxes, badges
- Sprint filter on archive page
- Consistent UX across Board, Activity, Backlog, and Archive views
2026-02-02 02:45:26 -06:00
Brad Groux
2f69af3fe6 fix: remove max-w-4xl from Activity feed to match Backlog width 2026-02-02 02:39:58 -06:00
Brad Groux
71afc9d539 feat: move Daily Summary above tabs, always visible on Activity page 2026-02-02 02:39:02 -06:00
Brad Groux
9083f7d2ab feat: merge Activity Sidebar into Activity Feed (GH-66)
- Add Status History tab with day-grouped status transitions
- Add Daily Summary tab with active/idle/utilization metrics
- Remove Activity Sidebar component and its header icon
- Single 'Activity' nav button now opens the unified feed page
- Agent status indicator links to activity feed instead of sidebar
- Closes #66
2026-02-02 02:37:13 -06:00
Brad Groux
a07f7489fa fix: clicking backlog task now expands inline instead of navigating away
Previously clicking a task in the backlog called navigateToTask which
switched back to the board view. Now tasks expand/collapse inline with
full description, dates, agent, and recent comments.
2026-02-02 02:31:13 -06:00
Brad Groux
fcf2ccaab0 fix: strip undefined values in backlog YAML serialization
Fixes YAMLException when creating backlog tasks - undefined frontmatter
fields were being passed to gray-matter stringify which can't serialize
them. Now filters out undefined values before serialization.
2026-02-02 02:23:58 -06:00
Brad Groux
8302375051 feat: Add backlog board feature (Issue #65)
- Add BacklogRepository for file-based storage in tasks/backlog/
- Add BacklogService with promote/demote logic
- Add backlog API routes (list, create, update, delete, promote, demote)
- Add BacklogPage component with search, filtering, and bulk actions
- Add backlog navigation with task count badge in header
- Add 'Move to Backlog' action to bulk actions bar
- Add CLI commands: backlog list/add/promote/demote/delete/count
- Add activity types for task_promoted and task_demoted events
- Backlog tasks are stored separately and not loaded by main task service
- Tasks can be promoted from backlog to active board (status -> todo)
- Tasks can be demoted from active board to backlog
2026-02-02 02:20:14 -06:00
Brad Groux
a5d1be9276 feat: clicking emoji/title refreshes the page 2026-02-01 15:29:08 -06:00
Brad Groux
0491729800 style: add ArrowRight icon to Move button, match Archive/Delete sizing 2026-02-01 15:27:39 -06:00
Brad Groux
dfa81b0405 fix: add Move confirm button to bulk actions (two-step flow)
Previously the 'Move to...' dropdown fired immediately on selection with
no confirm step. Now it's a two-step flow: pick target status from dropdown,
then click 'Move' button to confirm — consistent with Archive and Delete.

Fixes task_20260201_NqmOuf
2026-02-01 15:25:19 -06:00
Brad Groux
dc6bd85405 fix: replace all remaining 'Review' references with 'Blocked'
- BulkActionsBar: dropdown option 'Review' → 'Blocked'
- NotificationsTab: 'Review Needed' → 'Blocked' label/description
- constants.ts: remove obsolete 'review' status label
- summary CLI: 'Review' → 'Blocked' in standup output
- notification-service: fix misleading comment
- summary-service: fix misleading comment

Closes task_20260201_wOFjfL
2026-02-01 15:18:34 -06:00
Brad Groux
872e01a50f chore: add landing page to docs/ for GitHub Pages + configure Pages from /docs 2026-02-01 02:55:26 -06:00
Brad Groux
68839ccf04 feat: add 'Why Veritas Kanban' landing page for GitHub Pages (site/) 2026-02-01 02:54:55 -06:00
Brad Groux
583d74b38d feat(v1.4): planning status + verification checklists (#40 #38) 2026-02-01 02:45:57 -06:00
Brad Groux
b19a275ad0 docs: comprehensive v1.4 CLI workflow documentation — README, FEATURES, CHANGELOG, new CLI-GUIDE.md (#44) 2026-02-01 02:24:34 -06:00
Brad Groux
cf413bbd64 feat(cli): add workflow commands - vk begin/done/block/unblock, time tracking, comments, agent status, projects (#44) 2026-02-01 02:05:40 -06:00
Brad Groux
bbc8d948b4 docs: update roadmap with current milestones and completed items 2026-01-31 23:48:09 -06:00
Brad Groux
9369ca8bcf docs: update all documentation for v1.2.0 + v1.3.0
- Bump all package versions to 1.3.0
- README: version badge, blocked column, new feature highlights
- CHANGELOG: full v1.2.0 and v1.3.0 entries
- FEATURES.md: GitHub sync, activity feed, standup summary sections
- FEATURES.md: storage architecture, API envelope docs, new CLI commands
- FEATURES.md: updated API endpoints table and response format docs
2026-01-31 23:33:37 -06:00
Brad Groux
879b095096 v1.3.0: Visibility & Automation (#21, #33, #34)
- Bidirectional GitHub Issues sync (#21)
  - GitHubSyncService with polling, label-based field mapping, circuit breaker
  - Inbound: import issues with 'kanban' label as tasks
  - Outbound: push status changes and comments back to GitHub
  - Config/state persistence, 5 new API endpoints
  - CLI: vk github sync/status/config/mappings
  - TaskGitHub interface added to shared types

- Activity feed view (#33)
  - Full-page chronological feed with day grouping
  - Filter bar: agent, type, date range (combinable)
  - Compact vs detailed view toggle
  - Infinite scroll via IntersectionObserver
  - Real-time WebSocket updates with animation
  - Agent field added to Activity, MAX_ACTIVITIES 1000→5000
  - New ViewContext for board/activity navigation

- Daily standup summary generation (#34)
  - GET /api/summary/standup with date, format params
  - JSON, markdown, and plain text output formats
  - Sections: completed, in-progress, blocked, upcoming, stats
  - CLI: vk summary standup with --yesterday, --date, --json flags
  - 12 new tests for standup logic

Closes #21, closes #33, closes #34
2026-01-31 23:15:08 -06:00
Brad Groux
a7877e57b5 v1.2.0: Foundation Hardening (#2, #6, #32)
- Standardize API response envelope and error format (#2)
  - Add UnauthorizedError, ForbiddenError, BadRequestError, InternalError classes
  - Add pagination support with sendPaginated() helper
  - Standardize all 11 route files to use error classes (zero ad-hoc patterns)
  - Standardize auth middleware error responses

- Abstract file storage behind repository interface (#6)
  - Extend storage interfaces: Activity, Template, StatusHistory, ManagedList, Telemetry
  - Implement file-based adapters in FileStorageProvider
  - Add fs-helpers.ts as centralized filesystem access layer
  - Remove direct fs imports from all 10 service/route files

- Complete blocked task status implementation (#32)
  - Fix MCP tools Zod/JSON schema definitions
  - Fix MCP active tasks filter
  - Fix CLI help text and status color formatting

Closes #2, closes #6, closes #32
2026-01-31 23:03:10 -06:00
Brad Groux
3430b265c3 feat: Add webhook notifications for Clawdbot Gateway integration (#36)
feat: Add webhook notifications for Clawdbot Gateway integration
2026-01-31 22:37:00 -06:00
Brad Groux
a421fada46 fix(docker): resolve build failures from lockfile mismatch and permissions
Fixes #35

- Copy real web/package.json instead of creating a minimal stub, which
  caused pnpm-lock.yaml specifier mismatch with --frozen-lockfile
- Add --ignore-scripts to skip husky prepare hook in container builds
- Remove web/node_modules after install (frontend is pre-built static)
- Create .veritas-kanban directory with correct ownership for non-root user

Closes #35
2026-01-31 22:31:07 -06:00