Brad Groux
a7877e57b5
v1.2.0: Foundation Hardening ( #2 , #6 , #32 )
...
- Standardize API response envelope and error format (#2 )
- Add UnauthorizedError, ForbiddenError, BadRequestError, InternalError classes
- Add pagination support with sendPaginated() helper
- Standardize all 11 route files to use error classes (zero ad-hoc patterns)
- Standardize auth middleware error responses
- Abstract file storage behind repository interface (#6 )
- Extend storage interfaces: Activity, Template, StatusHistory, ManagedList, Telemetry
- Implement file-based adapters in FileStorageProvider
- Add fs-helpers.ts as centralized filesystem access layer
- Remove direct fs imports from all 10 service/route files
- Complete blocked task status implementation (#32 )
- Fix MCP tools Zod/JSON schema definitions
- Fix MCP active tasks filter
- Fix CLI help text and status color formatting
Closes #2 , closes #6 , closes #32
2026-01-31 23:03:10 -06:00
Brad Groux
0c0f5b344d
security+quality: final codebase review fixes
...
Security (critical):
- Remove shell:true from preview-service spawn (command injection fix)
- Replace exec() with execFile() in github-service (no shell interpolation)
- Add SIGKILL fallback after SIGTERM timeout in worktree-service
Stability:
- Add process cleanup handlers (SIGTERM/SIGINT) for preview servers
- Add MAX_PREVIEW_SERVERS=5 limit to prevent resource exhaustion
- Memoize WebSocket context value to prevent unnecessary re-renders
Code quality:
- Remove hardcoded 'Brad' author → 'User' (3 files)
- Replace hardcoded localhost:3001 URLs with API_BASE (AttachmentsSection)
- Fix SECURITY-AUDIT.md date (2025 → 2026)
- Add license/repository/author to all 6 package.json files
Data hygiene:
- Untrack all runtime data files (.veritas-kanban/*.json, telemetry, activity)
- Simplify .gitignore: .veritas-kanban/* except .gitkeep
- Removed ~15,700 lines of runtime data from git history
2026-01-29 06:13:10 -06:00
Brad Groux
3edffec98c
chore: bump version to 1.0.0, add CHANGELOG
...
- Bump all 6 package.json files from 0.1.0 to 1.0.0
- Add CHANGELOG.md with full feature summary
- Git history scrubbed of security.json (JWT secret)
2026-01-29 01:42:04 -06:00
Brad Groux
39eccf3556
feat: Sprint US-1200 Refactoring batch — 13 tasks complete
...
Completed refactors:
- RF-02: Fix dependency vulnerabilities (xlsx → exceljs, Hono updates)
- RF-05: Add React error boundaries (FeatureErrorBoundary wrapper)
- RF-06: Server error handling middleware (AppError classes, asyncHandler)
- RF-10: Split shared types.ts into domain modules (6 files)
- RF-11: Consolidate frontend API layer (hooks now use api.ts)
- RF-13: TaskConfigContext — eliminate prop drilling
- RF-14: Split god components (GitSection, TaskDetailPanel, CreateTaskDialog, DiffViewer)
- RF-16: Frontend accessibility (ARIA labels, sr-only text)
- RF-17: Modularize CLI (899 → commands/ structure)
- RF-18: Modularize MCP (843 → tools/ structure)
- RF-19: Create shared API client library
- RF-21: Server performance (batch loading, memory limits, timeouts, graceful shutdown)
- RF-23: Extract shared utilities (path, format, constants)
Stats: ~59 files changed, significant code reduction through modularization
2026-01-28 06:08:59 -06:00
Brad Groux
575035d69b
refactor: Replace direct spawn with Clawdbot sessions API integration
...
- Created ClawdbotAgentService that delegates to Veritas main session
- Agent requests written to .veritas-kanban/agent-requests/ as JSON
- Added /api/agents/pending endpoint for Veritas to poll
- Added /api/agents/:taskId/complete callback endpoint
- CLI commands: agents:pending, agents:complete, agents:status
- Removed PTY process management - Clawdbot handles it
Flow:
1. Kanban UI → POST /api/agents/:taskId/start
2. Server writes request to agent-requests/{taskId}.json
3. Veritas polls agents:pending or checks manually
4. Veritas calls sessions_spawn with task prompt
5. Sub-agent works in worktree, commits changes
6. Veritas calls /api/agents/:taskId/complete
7. Task updated, notifications sent
2026-01-26 11:20:28 -06:00
Brad Groux
809bf4d94e
feat(US-505): Teams notification integration
...
- New /api/notifications endpoints (create, list, pending, mark-sent, check, clear)
- Notification types: agent_complete, agent_failed, needs_review, task_done, high_priority, error, milestone, info
- CLI commands: notify, notify:check, notify:pending, notify:list, notify:clear
- MCP tools: create_notification, get_pending_notifications, check_notifications
- Notifications stored in .veritas-kanban/notifications.json
- Teams-formatted output with icons and task links
2026-01-26 04:34:41 -06:00
Brad Groux
7d7e92e2ce
feat(US-504): Memory system sync
...
- New /api/summary endpoint (status counts, projects, high-priority)
- New /api/summary/recent endpoint (recently completed tasks)
- New /api/summary/memory endpoint (markdown formatted for memory files)
- CLI: vk summary - show kanban overview
- CLI: vk memory - get memory-formatted summary
- CLI: vk memory -o <file> - append to memory file
- MCP: get_summary, get_memory_summary tools
2026-01-26 04:29:03 -06:00
Brad Groux
6112517ee7
feat(US-503): Veritas sub-agent integration
...
- Added 'veritas' agent type for automation tasks
- New automation field on tasks (sessionKey, spawnedAt, completedAt, result)
- New API endpoints:
- POST /api/automation/:id/start - start automation task
- POST /api/automation/:id/complete - complete automation task
- GET /api/automation/pending - list pending automation tasks
- GET /api/automation/running - list running automation tasks
- CLI commands: automation:pending, automation:start, automation:complete, automation:running
- MCP tools: list_pending_automation, list_running_automation, start_automation, complete_automation
2026-01-26 04:26:28 -06:00
Brad Groux
bec40a05de
feat(US-501): CLI for task management
...
- vk list: list tasks with filters (status, type, project)
- vk show: display task details
- vk create: create new tasks
- vk update: modify task fields
- vk start: start agent on task
- vk stop: stop running agent
- vk archive: archive completed task
- vk delete: delete task
- JSON output option for all commands
- Partial ID matching support
2026-01-26 04:17:52 -06:00