Brad Groux
f7cff20cd8
test: add v5 dual-storage parity gate
...
## Summary
- adds the v5 dual-storage parity fixture and focused parity test suite
- covers rich task metadata, archive lifecycle, comments/chat history, settings/templates, prompt usage, telemetry/activity/status history, and a workflow run
- adds an explicit CI parity step for file and SQLite storage drift
- preserves newer file-mode task metadata on reload and stabilizes SQLite chat ordering
- hardens workflow parity polling for asynchronous run writes
## Verification
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
- Local focused parity test, server typecheck, lint budget, build, and audit high gate
2026-05-31 05:26:10 -05:00
Brad Groux
522162ae89
test: add v5 permission coverage manifest gate
...
## Summary
- adds a v5 permission coverage manifest with classifications, required permissions, denial reasons, and review justifications across REST, WebSocket, CLI, MCP, workflow, transition hook, command palette, and background job surfaces
- adds a Node-based coverage checker that fails when tracked surfaces are missing from the manifest or when REST route prefixes drift from the shared permission map
- wires the checker into CI and documents the manifest gate in the security guide
Closes #420 .
## Verification
- `node scripts/check-permission-coverage.mjs`
- `./node_modules/.bin/prettier --check package.json .github/workflows/ci.yml scripts/check-permission-coverage.mjs docs/security/permission-coverage.json docs/security.md`
- `git diff --check`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high` (passes high gate; 3 existing moderate findings)
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 05:02:26 -05:00
Brad Groux
3f5c9a03af
feat: enforce CLI and MCP token permissions
...
## Summary
- adds a shared client-side API permission mapper and guarded API client for CLI and MCP calls
- exposes a non-secret /api/auth/context endpoint for scoped token preflight
- routes CLI and MCP task lookup helpers through the guarded client
- preflights direct summary text fetches that bypass the JSON API helper
- adds focused CLI and MCP token authorization coverage and documents the behavior
Refs #336 .
## Verification
- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm --filter @veritas-kanban/server typecheck
- focused CLI and MCP api-permissions tests
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- pnpm build
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:35:10 -05:00
Brad Groux
b615052d4a
feat: filter WebSocket events by permissions
...
## Summary
- adds a shared WebSocket delivery gate for workspace and permission checks
- filters task, chat, squad, telemetry, broadcast, workflow, and agent-status fanout by authenticated capabilities
- gates chat and task-output subscriptions behind task read access
- adds broadcast coverage for workspace and permission filtering
Refs #336 .
## Verification
- ./node_modules/.bin/vitest run server/src/__tests__/broadcast-service.test.ts
- pnpm --filter @veritas-kanban/server typecheck
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- pnpm build
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:23:02 -05:00
Brad Groux
90da5149ec
feat: add REST route permission guards
...
## Summary
- adds method/path-aware permission middleware for explicit REST read, write, and execute requirements
- maps the v1 route registry to permission presets across task, settings, agent, telemetry, report, policy, workflow, backup, and workspace surfaces
- preserves read-like POST behavior for search, workflow execution, report/scoring generation, policy evaluation, and prompt preview/usage routes
- uses v5 auth user IDs for workflow ACL checks when available
- adds focused coverage for permission selection and v1 route preset behavior
Refs #336 .
## Verification
- `./node_modules/.bin/vitest run server/src/__tests__/middleware/auth.test.ts server/src/__tests__/routes/v1-permission-guards.test.ts`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm lint:budget` (708 warnings, budget 714)
- `pnpm audit --prod --audit-level=high` (3 moderate advisories, high gate passes)
- `pnpm build`
- `./node_modules/.bin/prettier --check server/src/middleware/auth.ts server/src/routes/v1/index.ts server/src/routes/v1/permissions.ts server/src/__tests__/middleware/auth.test.ts server/src/__tests__/routes/v1-permission-guards.test.ts server/src/routes/workflows.ts`
- `git diff --check`
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:13:07 -05:00
Brad Groux
e97d01846a
feat: add SQLite provenance queries
...
## Summary
- adds a SQLite operational provenance repository with bounded task, run, and recent artifact queries
- exposes lightweight provenance metadata for work products, task deliverables, attachments, workflow runs, scheduled run snapshots, notifications, and task chat messages without returning raw JSON payloads
- wires the provenance repository into the SQLite storage provider
- documents the query surface in the SQLite schema guide
Closes #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- Local: `./node_modules/.bin/vitest run server/src/__tests__/storage/sqlite-provenance-repository.test.ts`
- Local: `pnpm --filter @veritas-kanban/server typecheck`
- Local: `pnpm lint:budget`
- Local: `pnpm audit --prod --audit-level=high`
- Local: `pnpm build`
- Local: prettier check for changed files
- Local: `git diff --check`
2026-05-31 03:52:38 -05:00
Brad Groux
452f984e5c
feat: migrate shared primitives to Mantine
...
## Summary
- migrates low-risk shared UI wrappers to Mantine-backed compatibility components
- routes existing toast() calls through Mantine notifications
- adds shared primitive regression coverage and provider/test environment shims
- documents temporary Radix holdouts for compound and focus-heavy APIs
Refs #416 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- Local: `pnpm --filter @veritas-kanban/web typecheck`
- Local: `pnpm --filter @veritas-kanban/web test -- mantine-ui-primitives`
- Local: `pnpm --filter @veritas-kanban/web test`
- Local: `pnpm lint:budget`
- Local: `pnpm audit --prod --audit-level=high`
- Local: `pnpm build`
- Local: prettier check for changed files
- Local: `git diff --check`
- Browser smoke: setup page rendered with Mantine styles, button/input slots, notification root, no overflow, and no new console errors
2026-05-31 03:35:48 -05:00
Brad Groux
2a04b07198
feat: add v5 Mantine foundation
...
## Summary
- adds Mantine core/hooks/form/modals/notifications plus the required PostCSS setup
- wraps the web app and shared test renderer in a Veritas Mantine provider with modals, notifications, and color-scheme bridging
- defines the v5 Mantine theme, status colors, density defaults, breakpoints, and layout shell primitives
- keeps the existing `.dark` class contract active while migrated and unmigrated surfaces coexist
- documents the foundation conventions and bundle impact for the v5 UI migration
Closes #415 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/web test -- mantine-theme`
- `pnpm --filter @veritas-kanban/web typecheck`
- `pnpm --filter @veritas-kanban/web test`
- `pnpm lint:budget`
- `pnpm audit --prod --audit-level=high`
- `pnpm build`
- `./node_modules/.bin/prettier --check docs/UI-MANTINE-MIGRATION.md web/index.html web/postcss.config.cjs web/src/__tests__/mantine-theme.test.tsx web/src/__tests__/test-utils.tsx web/src/components/layout/mantine-shell.tsx web/src/hooks/useTheme.ts web/src/main.tsx web/src/theme/color-scheme.ts web/src/theme/mantine-theme.ts web/src/theme/MantineRoot.tsx web/vite.config.ts web/package.json`
- `git diff --check`
- Browser smoke: `http://127.0.0.1:3000/ ` rendered the setup page with Mantine CSS variables, dark color scheme, no new console errors, and no horizontal overflow at 1280x720 or 390x844
## Notes
- Production audit still reports the existing 3 moderate advisories; the high-severity gate passes.
- Build now emits explicit Mantine vendor assets: `vendor-mantine-CvPmQ6ZW.css` at 214.56 kB / 31.59 kB gzip and `vendor-mantine-JZsLAwaX.js` at 148.11 kB / 45.81 kB gzip.
2026-05-31 03:05:48 -05:00
Brad Groux
4ccac06355
docs: plan v5 Mantine migration
...
## Summary
- adds the v5 Mantine migration plan and current component inventory
- maps current shared UI primitives to Mantine targets or retained custom surfaces
- documents migration order, Tailwind strategy, risk areas, rollback strategy, dependency cleanup, and verification gates
- links the plan from the README documentation map
Closes #414 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `./node_modules/.bin/prettier --check docs/UI-MANTINE-MIGRATION.md README.md`
- `git diff --check`
## Notes
- This is the planning slice for the Mantine migration. It intentionally does not add Mantine packages or change runtime UI behavior.
2026-05-31 02:42:12 -05:00
Brad Groux
c40f378bb9
feat: add v5 auth permission context
...
## Summary
- adds a shared v5 auth context for REST requests and WebSocket connections
- adds role-derived permission sets plus an explicit `authorizePermission` guard for upcoming route migrations
- documents scoped CLI and MCP token expectations for v5 RBAC work
Refs #336 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- middleware/auth`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
## Notes
- This is a compatibility groundwork slice for #336 . It does not complete route-by-route permission enforcement, workspace filtering, or agent token scoping.
2026-05-31 02:35:24 -05:00
Brad Groux
b44efb8ade
feat: add multi-user identity APIs
...
## Summary
- adds the SQLite multi-user identity foundation migration for expanded workspace roles and workspace invitations
- adds SQLite identity repository/service support for local owner setup, workspace/profile reads, invitations, role updates, member removal, audit/activity recording, and invitation acceptance
- adds `/api/identity` and `/api/v1/identity` routes plus unauthenticated `/api/auth/invitations/accept`
- wires SQLite auth setup to ensure the local owner/default workspace exists
- includes identity tables in SQLite portability backups and documents the new identity API surface
Closes #335 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-identity-repository identity-service routes/identity`
- `pnpm --filter @veritas-kanban/server test -- sqlite-portability-service sqlite-storage routes/auth`
- `pnpm --filter @veritas-kanban/server test -- middleware/auth`
- `pnpm --filter @veritas-kanban/server test -- docker-paths`
- `pnpm --filter @veritas-kanban/server typecheck`
- `./node_modules/.bin/prettier --check docs/API-REFERENCE.md docs/SQLITE-SCHEMA.md server/src/routes/auth.ts server/src/routes/identity.ts server/src/routes/v1/index.ts server/src/services/activity-service.ts server/src/services/identity-service.ts server/src/services/sqlite-portability-service.ts server/src/storage/index.ts server/src/storage/sqlite/identity-repository.ts server/src/storage/sqlite/migrations.ts server/src/__tests__/identity-service.test.ts server/src/__tests__/routes/identity.test.ts server/src/__tests__/storage/sqlite-identity-repository.test.ts`
- `git diff --check`
- `pnpm lint:budget`
- `pnpm audit --prod --audit-level=high`
- `pnpm build`
## Notes
- `pnpm lint:budget` currently reports the existing 707 warnings against the 714-warning budget.
- `pnpm audit --prod --audit-level=high` exits cleanly with 3 moderate advisories reported.
- A full `pnpm test:unit` attempt reached 1,625 passing server tests and timed out on `docker-paths.test.ts`; the isolated `docker-paths` rerun passed and hosted Workspace Unit Tests are green.
- This is the management API/data foundation for #335 . Broad route-by-route RBAC enforcement remains in #336 .
2026-05-31 02:25:04 -05:00
Brad Groux
5cf82db881
docs: define v5 identity RBAC model
...
## Summary
- adds the v5 identity, workspace, and RBAC design document
- defines users, workspaces, memberships, invitations, sessions, agent identities, scoped API tokens, roles, route permissions, entity-level rules, and actor attribution
- documents local mode, server mode, localhost bypass behavior, backward-compatible migration, recovery, invitation, device pairing, and agent token UX flows
- links the design from the README docs map, security guide, and SQLite schema strategy
Closes #334 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `./node_modules/.bin/prettier --check docs/IDENTITY-RBAC.md README.md docs/security.md docs/SQLITE-SCHEMA.md`
- `git diff --check`
## Notes
- This is the design slice for #334 . It intentionally does not implement the RBAC tables or middleware.
2026-05-31 02:04:08 -05:00
Brad Groux
90793aeb54
feat: add SQLite migration backup API
...
## Summary
- adds an admin-only SQLite portability API for dry-run file migrations, migration runs, backup bundle export, and bundle import
- imports file-backed tasks, settings, templates, prompt registry data, telemetry, activity/status history, workflows, workflow runs, task chat, and squad messages into SQLite
- exports raw SQLite table snapshots plus human-readable task Markdown, config JSON, and workflow YAML, then rebuilds search indexes on import
- fixes squad transcript parsing so the first message after the file heading is preserved
- documents migration/recovery API usage and adds regression coverage for malformed input and backup round trips
Closes #333 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-portability-service`
- `pnpm --filter @veritas-kanban/server test -- chat-service`
- `pnpm --filter @veritas-kanban/server typecheck`
- `./node_modules/.bin/prettier --check docs/API-REFERENCE.md docs/SQLITE-SCHEMA.md server/src/routes/v1/index.ts server/src/routes/sqlite-portability.ts server/src/services/chat-service.ts server/src/services/sqlite-portability-service.ts server/src/__tests__/sqlite-portability-service.test.ts server/src/__tests__/chat-service.test.ts server/src/storage/index.ts`
- `git diff --check`
- `pnpm lint:budget`
- `pnpm audit --prod --audit-level=high`
- `pnpm build`
## Notes
- `pnpm lint:budget` currently reports 707 existing warnings against the 714-warning budget.
- `pnpm audit --prod --audit-level=high` exits cleanly with 3 moderate advisories reported.
2026-05-31 01:56:05 -05:00
Brad Groux
b502872b49
feat: add durable work product foundation
...
Summary:
- adds typed durable work product render contracts
- adds SQLite work_products, work_product_versions, and work_product_search storage
- adds create, list, refine, archive, restore, preview, and export APIs
- wires work products into task-scoped APIs and keyword search
- adds redacted preview/export behavior and SQLite regression coverage
- documents the work product API and SQLite schema
Verification:
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- ./node_modules/.bin/prettier --check README.md docs/SQLITE-SCHEMA.md docs/features/work-products.md shared/src/types/work-product.types.ts shared/src/types/index.ts server/src/schemas/work-product-schemas.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/work-product-repository.ts server/src/services/work-product-service.ts server/src/routes/work-products.ts server/src/routes/v1/index.ts server/src/routes/search.ts server/src/services/search-service.ts server/src/__tests__/storage/sqlite-work-products.test.ts
- pnpm --filter @veritas-kanban/server test -- sqlite-work-products
- pnpm typecheck
- pnpm lint:budget
- pnpm --filter @veritas-kanban/server test
- pnpm build
- pnpm audit --prod --audit-level=high
- git diff --check
Part of #403 .
Part of #332 .
2026-05-31 01:31:00 -05:00
Brad Groux
277dc6608e
feat: load dashboard metrics from sqlite telemetry
...
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
Summary:
- read dashboard telemetry from SQLite telemetry_events in SQLite mode
- route dashboard metrics, trends, agent comparison, task cost, and utilization through the shared active-backend reader
- add SQLite regression coverage for metrics and trends without telemetry files
- document the SQLite dashboard aggregation path
Verification:
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- ./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/services/metrics/telemetry-reader.ts server/src/services/metrics/dashboard-metrics.ts server/src/__tests__/storage/sqlite-dashboard-metrics.test.ts
- pnpm --filter @veritas-kanban/server test -- sqlite-dashboard-metrics
- pnpm typecheck
- pnpm lint:budget
- pnpm --filter @veritas-kanban/server test
- pnpm build
- pnpm audit --prod --audit-level=high
- git diff --check
Part of #332 .
2026-05-31 01:05:55 -05:00
Brad Groux
39d9b907d3
feat: add SQLite task artifact metadata
...
## Summary
- adds SQLite migration 0012 for normalized task attachment and task deliverable metadata
- mirrors attachment validation, hash/path, retention, owner/session, and cleanup fields from task JSON into queryable SQLite rows
- adds deliverable provenance fields for model/source run/redaction/version metadata and stores them in SQLite
- updates task artifact schema docs and adds repository coverage for child row sync
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-task-repository`
- `pnpm typecheck`
- `pnpm lint:budget`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/__tests__/storage/sqlite-task-repository.test.ts server/src/routes/task-deliverables.ts server/src/schemas/deliverable-schemas.ts server/src/services/attachment-service.ts server/src/services/clawdbot-agent-service.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/task-repository.ts shared/src/types/task.types.ts shared/src/types/task.types.d.ts`
- `git diff --check`
## Notes
- Attachment binary blobs remain on disk; this slice persists metadata in SQLite for query, migration, backup/import, and cleanup workflows.
2026-05-31 00:47:56 -05:00
Brad Groux
5b45fa1788
feat: add SQLite scheduled deliverable repositories
...
## Summary
- adds SQLite tables and repository storage for scheduled deliverables and recurring run history
- wires ScheduledDeliverablesService into SQLite mode while preserving JSON file mode and configurable file paths
- captures stable scheduled-run snapshots with source workflow/run IDs, output metadata, summary, duration, and audit-safe snapshot metadata
- adds restart-style SQLite coverage for schedules, filters, run history, snapshots, and no JSON-file writes
- documents the scheduled deliverable repository schema mapping
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-scheduled-deliverables-repository.test.ts`
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
- `git diff --cached --check`
## Notes
- The production audit currently reports only moderate vulnerabilities.
2026-05-31 00:33:29 -05:00
Brad Groux
d168ac6e4c
feat: add SQLite notification repositories
...
## Summary
- adds SQLite tables and repository storage for notification inbox records and thread subscriptions
- wires NotificationService into SQLite mode while preserving JSON file mode and existing file-path test options
- preserves direct notification metadata including type, title, task title, project, target URL, dedupe key, and source metadata
- adds restart-style SQLite coverage for mentions, assignments, direct notifications, delivered state, stats, and subscriptions
- documents the notification repository schema mapping
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-notification-repositories.test.ts src/__tests__/notification-service.test.ts src/__tests__/failure-alert-service.test.ts src/__tests__/routes/notifications-coverage.test.ts`
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
- `git diff --cached --check`
## Notes
- The production audit currently reports only moderate vulnerabilities.
2026-05-31 00:22:30 -05:00
Brad Groux
a59f1d42d1
feat: add SQLite chat repositories
...
## Summary
- adds SQLite tables and repositories for board chat sessions, task chat messages, and squad chat messages
- wires ChatService into SQLite mode while leaving Markdown file mode as the default
- adds restart-style SQLite coverage proving board chat, task chat, and squad chat persist without markdown files
- documents the chat repository schema mapping
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-chat-repositories.test.ts src/__tests__/chat-service.test.ts src/__tests__/routes/chat.test.ts`
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 23:51:15 -05:00
Brad Groux
ea1e69dadc
feat: add SQLite workflow repositories
...
## Summary
- adds SQLite tables and repositories for workflow definitions, ACLs, audit events, run state, and workflow snapshots
- wires workflow definition and run services into SQLite mode while keeping file mode as the default
- adds SQLite repository tests plus an execution-path test for start, retry, block, resume, and complete behavior
- documents the workflow repository schema mapping
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-workflow-repositories.test.ts src/__tests__/storage/sqlite-workflow-run-execution.test.ts src/__tests__/workflow-service.test.ts src/__tests__/workflow-run-service.test.ts`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 22:56:20 -05:00
Brad Groux
e24c7abfd6
feat: add SQLite audit and policy repositories
...
## Summary
- adds v7 SQLite tables and repositories for audit entries, agent policies, and tool policies
- routes audit logging, policy service, and tool policy service to SQLite when configured while preserving file-backed defaults
- keeps audit hash-chain verification and recent-entry reads working in SQLite mode
- adds SQLite coverage for audit persistence, agent policy CRUD/evaluation, tool policy CRUD/access filters, and no file writes
- documents the audit/policy tables in the SQLite schema notes
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-audit-policy-repositories.test.ts`
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-audit-policy-repositories.test.ts src/__tests__/services/audit-service.test.ts src/__tests__/services/policy-service.test.ts`
- `./node_modules/.bin/eslint server/src/__tests__/storage/sqlite-audit-policy-repositories.test.ts server/src/services/audit-service.ts server/src/services/policy-service.ts server/src/services/tool-policy-service.ts server/src/storage/index.ts server/src/storage/sqlite/audit-policy-repositories.ts server/src/storage/sqlite/migrations.ts --quiet`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm typecheck`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 22:25:14 -05:00
Brad Groux
1bcb4087eb
feat: add SQLite governance repositories
...
## Summary
- adds v6 SQLite governance tables and repository implementations for decisions, feedback, scoring, and drift data
- routes DecisionService, FeedbackService, ScoringService, and DriftService to SQLite when configured while preserving file-backed defaults
- adds SQLite coverage for decision chains, feedback analytics, scoring history, drift alerts and baselines, and no file writes
- documents the governance repository tables in the SQLite schema notes
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-governance-repositories.test.ts`
- `pnpm typecheck`
- `./node_modules/.bin/eslint server/src/__tests__/storage/sqlite-governance-repositories.test.ts server/src/services/decision-service.ts server/src/services/feedback-service.ts server/src/services/scoring-service.ts server/src/services/drift-service.ts server/src/storage/index.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/governance-repositories.ts --quiet`
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-governance-repositories.test.ts src/__tests__/decision-service.test.ts src/__tests__/feedback-service.test.ts src/__tests__/scoring-service.test.ts src/__tests__/drift-service.test.ts`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 22:10:57 -05:00
Brad Groux
df54a42de7
feat: add SQLite operational history repositories
...
## Summary
- adds SQLite migration/table support for activity events, status history, and telemetry events
- wires ActivityService, StatusHistoryService, TelemetryService, and SqliteStorageProvider to use SQLite repositories in sqlite mode
- keeps file storage explicitly file-backed and adds regression coverage that sqlite mode does not create JSON/NDJSON operational files
- documents the operational repository slice in the v5 SQLite schema plan
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- --run src/__tests__/storage/sqlite-operational-repositories.test.ts src/__tests__/storage/sqlite-storage.test.ts`
- `pnpm typecheck`
- `./node_modules/.bin/eslint server/src/__tests__/storage/sqlite-storage.test.ts server/src/__tests__/storage/sqlite-operational-repositories.test.ts server/src/services/activity-service.ts server/src/services/status-history-service.ts server/src/services/telemetry-service.ts server/src/storage/file-storage.ts server/src/storage/index.ts server/src/storage/interfaces.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/activity-repository.ts server/src/storage/sqlite/status-history-repository.ts server/src/storage/sqlite/telemetry-repository.ts --quiet`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
2026-05-30 21:50:48 -05:00
Brad Groux
bcf7110b96
feat: add SQLite configuration repositories
...
## Summary
- adds SQLite migration/table support for app config, managed lists, task templates, prompt templates, prompt versions, and prompt usage
- wires ConfigService, ManagedListService, TemplateService, and PromptRegistryService into SQLite mode while preserving file-backed behavior
- exposes repository/provider implementations and documents the runtime schema
- adds SQLite configuration repository coverage and removes file-backed template constructor directory races
Closes #331 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/services/config-service.ts server/src/services/managed-list-service.ts server/src/services/prompt-registry-service.ts server/src/services/template-service.ts server/src/storage/file-storage.ts server/src/storage/index.ts server/src/storage/interfaces.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/managed-list-repository.ts server/src/storage/sqlite/prompt-registry-repository.ts server/src/storage/sqlite/settings-repository.ts server/src/storage/sqlite/template-repository.ts server/src/__tests__/storage/sqlite-config-repositories.test.ts`
- `./node_modules/.bin/eslint server/src/services/config-service.ts server/src/services/managed-list-service.ts server/src/services/prompt-registry-service.ts server/src/services/template-service.ts server/src/storage/file-storage.ts server/src/storage/index.ts server/src/storage/interfaces.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/managed-list-repository.ts server/src/storage/sqlite/prompt-registry-repository.ts server/src/storage/sqlite/settings-repository.ts server/src/storage/sqlite/template-repository.ts server/src/__tests__/storage/sqlite-config-repositories.test.ts --quiet`
- `pnpm --filter @veritas-kanban/server test -- src/__tests__/prompt-registry-service.test.ts src/__tests__/template-service.test.ts src/__tests__/storage/sqlite-config-repositories.test.ts`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm typecheck`
- `pnpm lint:budget`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- Live SQLite API smoke for `/api/settings/features`, `/api/projects`, `/api/templates`, `/api/prompt-registry`, prompt versions, prompt usage, prompt stats, and schema row counts
2026-05-30 20:49:35 -05:00
Brad Groux
df9c29cf05
feat: add SQLite task repository parity
...
## Summary
- adds the v5 SQLite task table, indexed task columns, and FTS5 task_search migration
- adds SqliteTaskRepository for full task JSON persistence plus active/archive/backlog state helpers
- wires TaskService SQLite mode for create/list/read/update/delete/archive/restore/reorder without task markdown writes
- preserves serialized task mutations in SQLite mode and adds repository, service, and route-shape coverage
- documents the task repository storage strategy in the SQLite schema guide
Closes #330 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/services/task-service.ts server/src/storage/index.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/task-repository.ts server/src/__tests__/storage/sqlite-task-repository.test.ts server/src/__tests__/task-service-sqlite.test.ts server/src/__tests__/routes/tasks-sqlite.test.ts`
- `./node_modules/.bin/eslint server/src/services/task-service.ts server/src/storage/index.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/task-repository.ts server/src/__tests__/storage/sqlite-task-repository.test.ts server/src/__tests__/task-service-sqlite.test.ts server/src/__tests__/routes/tasks-sqlite.test.ts --quiet`
- `pnpm lint`
- `pnpm lint:budget`
- `pnpm typecheck`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm --filter @veritas-kanban/server test -- src/__tests__/storage/sqlite-task-repository.test.ts src/__tests__/task-service-sqlite.test.ts src/__tests__/routes/tasks-sqlite.test.ts`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- live SQLite API smoke: POST/GET `/api/tasks` with `VERITAS_STORAGE=sqlite`, verified only `veritas.db` was created under the data dir
## Notes
- The production audit gate reports 3 moderate vulnerabilities and no high/critical failures.
2026-05-30 20:01:43 -05:00
Brad Groux
ec6bc83fd2
feat: add SQLite storage foundation
...
## Summary
- adds a dependency-free Node `node:sqlite` database foundation with safe PRAGMAs, schema_migrations tracking, checksum validation, and transactional migration rollback
- adds the SQLite storage provider shell, lifecycle shutdown, and isolated SQLite test helpers while file repositories remain the default behavior
- wires `VERITAS_STORAGE=file|sqlite` plus `VERITAS_SQLITE_PATH` through env validation, docs, and server startup/shutdown
Closes #329 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Workspace Unit Tests
- CI: Security Audit
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/config/env.ts server/src/index.ts server/src/storage/index.ts server/src/storage/sqlite/database.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/sqlite-storage.ts server/src/storage/sqlite/test-helpers.ts server/src/__tests__/config/env.test.ts server/src/__tests__/storage/sqlite-database.test.ts server/src/__tests__/storage/sqlite-storage.test.ts`
- `./node_modules/.bin/eslint server/src --ext .ts --quiet`
- `pnpm --filter @veritas-kanban/server test -- src/__tests__/storage/sqlite-database.test.ts src/__tests__/storage/sqlite-storage.test.ts src/__tests__/config/env.test.ts`
- `pnpm --filter @veritas-kanban/server typecheck`
- `pnpm --filter @veritas-kanban/server build`
- `pnpm audit --prod --audit-level=high`
- `git diff --check`
- SQLite startup smoke with `VERITAS_STORAGE=sqlite` against a fresh temp data dir and `/api/health` returning ok
## Notes
- File storage remains the default until the provider parity and migration/import issues land. SQLite mode currently owns database lifecycle and migrations, then delegates existing repositories to file storage.
2026-05-30 17:39:23 -05:00
Brad Groux
d78af4053e
docs: define v5 SQLite schema strategy
...
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
## Summary
- adds the v5 SQLite schema and migration strategy document
- maps current file-backed objects to SQLite destinations
- documents migration numbering, rollback policy, FTS5 tables, multi-user-ready columns, and sensitive field handling
- links the design doc from the README roadmap section
- pins transitive tmp to a patched version for the security audit gate
Closes #328 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Workspace Unit Tests
- CI: Security Audit
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md README.md`
- `git diff --check HEAD~2..HEAD`
- `pnpm audit --prod --audit-level=high`
2026-05-30 14:43:38 -05:00
Brad Groux
92b573ab18
chore: bump version to 4.3.2
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
2026-05-16 19:10:53 -05:00
Brad Groux
d3976f1d74
chore: harden audit findings and release QA
...
Add release validation and scheduled QA workflows.
Harden webhook URL handling, API helper edge cases, and runtime version reporting.
Split heavy web bundles, centralize view metadata, and stabilize full-suite tests.
2026-05-16 18:59:40 -05:00
Brad Groux
55ba8b8f4d
Add CLI and MCP setup smoke checks
...
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
Add CLI and MCP read/write smoke checks, simplify README onboarding, and remove stale shipped-roadmap noise.
2026-05-13 15:21:16 -05:00
Brad Groux
578269963a
Clarify setup paths and integration auth
...
Clarify setup paths, integration auth behavior, and communication docs.
2026-05-13 14:21:30 -05:00
dependabot[bot]
e36074e922
Bump sanitize-html, ws, and DOMPurify
...
Summary:
- Update sanitize-html to 2.17.4.
- Update ws to 8.20.1.
- Update DOMPurify to 3.4.3.
Verification:
- pnpm install --frozen-lockfile
- pnpm typecheck
- pnpm build
- CI: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-13 13:59:30 -05:00
dependabot[bot]
811489057b
Bump lint-staged to 17.0.4
...
Summary:
- Update lint-staged to 17.0.4.
- Raise Node engine floor to 22.22.1 to match lint-staged's supported runtime.
Verification:
- pnpm install --frozen-lockfile
- pnpm typecheck
- pnpm build
- CI: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-13 13:51:47 -05:00
dependabot[bot]
c16b32f194
Bump production dependencies
...
Summary:\n- Update the production-dependencies group.\n- Rebase the lockfile on top of the current dependency state.\n\nVerification:\n- pnpm typecheck\n- pnpm build\n- CI: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-13 13:44:07 -05:00
dependabot[bot]
c98536c124
Bump content-disposition to 2.0.0
...
Summary:\n- Update content-disposition to 2.0.0.\n- Use the named create export and remove stale external types.\n- Preserve basename-style filename handling for attachment download headers.\n\nVerification:\n- pnpm --filter @veritas-kanban/server typecheck\n- pnpm --filter @veritas-kanban/server build\n- CI: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-13 13:39:32 -05:00
Cob-AI
030e5ec27a
Fix notification CLI routes and Squad Chat senders
...
Summary:\n- Add notification CLI compatibility routes and configured Squad Chat sender selection.\n- Restrict global notification operations to admins.\n- Guard Squad Chat storage access in restricted environments.\n\nVerification:\n- pnpm --filter @veritas-kanban/server test -- notifications-coverage\n- pnpm --filter @veritas-kanban/server typecheck\n- pnpm --filter @veritas-kanban/web test -- SquadChatPanel\n- pnpm --filter @veritas-kanban/web typecheck
2026-05-13 13:34:04 -05:00
Brad Groux
175de95717
fix: restrict governance routes to admins
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
2026-05-10 23:14:50 -05:00
Brad Groux
612599c58d
chore: resolve VK cutover and zod update ( #324 )
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
2026-05-09 02:11:52 -05:00
dependabot[bot]
bd5256c927
chore: bump the production-dependencies group with 4 updates ( #296 )
...
Bumps the production-dependencies group with 4 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ), [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit ) and [postcss](https://github.com/postcss/postcss ).
Updates `@typescript-eslint/eslint-plugin` from 8.59.1 to 8.59.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.59.2/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.59.1 to 8.59.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.59.2/packages/parser )
Updates `express-rate-limit` from 8.4.1 to 8.5.0
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases )
- [Commits](https://github.com/express-rate-limit/express-rate-limit/compare/v8.4.1...v8.5.0 )
Updates `postcss` from 8.5.13 to 8.5.14
- [Release notes](https://github.com/postcss/postcss/releases )
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/postcss/compare/8.5.13...8.5.14 )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.59.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.59.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: express-rate-limit
dependency-version: 8.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: postcss
dependency-version: 8.5.14
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-09 01:48:02 -05:00
Brad Groux
04e02f0c3e
feat: add codex settings health checks ( #318 )
CI / Security Audit (push) Has been cancelled
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
2026-05-05 22:13:25 -05:00
Brad Groux
e4519b5eef
feat: add codex review actions ( #317 )
2026-05-05 22:07:59 -05:00
Brad Groux
11e94aef4e
feat: run codex workflow steps ( #316 )
2026-05-05 22:01:05 -05:00
Brad Groux
7bf8df6666
feat: add codex cloud delegation ( #315 )
2026-05-05 21:53:47 -05:00
Brad Groux
42fb759cca
feat: add codex sdk sessions ( #314 )
2026-05-05 21:44:29 -05:00
Brad Groux
bd6c1744e1
feat: add codex cli agent execution
...
Adds built-in Codex agent configuration and local codex exec support through the Veritas agent lifecycle.
2026-05-05 21:20:27 -05:00
Brad Groux
7b3b2e0743
docs: add v4.2.0 changelog
...
Adds release notes for the v4.2.0 Codex integration planning and documentation release.
2026-05-05 21:07:19 -05:00
Brad Groux
0df2b02781
chore: bump release version to 4.2.0
...
Aligns workspace package versions and README badge with the v4.2 release track.
2026-05-05 21:03:50 -05:00
Brad Groux
6066e8dd36
docs: plan v4.2 codex integration
...
Adds the v4.2 OpenAI Codex integration roadmap, SOP, examples, MCP setup notes, AGENTS.md guidance, and planned feature documentation.
2026-05-05 20:56:41 -05:00
Brad Groux
f2845d2cda
Merge pull request #295 from BradGroux/release/v4.1.0-version-bump
...
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
chore: bump version to 4.1.0
2026-05-04 03:21:04 -05:00
Brad Groux
3f45965fd9
chore: bump version to 4.1.0
2026-05-04 03:19:18 -05:00