Brad Groux
d8dab5a612
chore: bump version to v1.1.0 + changelog
2026-01-31 07:09:18 -06:00
Brad Groux
0c0f5b344d
security+quality: final codebase review fixes
...
Security (critical):
- Remove shell:true from preview-service spawn (command injection fix)
- Replace exec() with execFile() in github-service (no shell interpolation)
- Add SIGKILL fallback after SIGTERM timeout in worktree-service
Stability:
- Add process cleanup handlers (SIGTERM/SIGINT) for preview servers
- Add MAX_PREVIEW_SERVERS=5 limit to prevent resource exhaustion
- Memoize WebSocket context value to prevent unnecessary re-renders
Code quality:
- Remove hardcoded 'Brad' author → 'User' (3 files)
- Replace hardcoded localhost:3001 URLs with API_BASE (AttachmentsSection)
- Fix SECURITY-AUDIT.md date (2025 → 2026)
- Add license/repository/author to all 6 package.json files
Data hygiene:
- Untrack all runtime data files (.veritas-kanban/*.json, telemetry, activity)
- Simplify .gitignore: .veritas-kanban/* except .gitkeep
- Removed ~15,700 lines of runtime data from git history
2026-01-29 06:13:10 -06:00
Brad Groux
3edffec98c
chore: bump version to 1.0.0, add CHANGELOG
...
- Bump all 6 package.json files from 0.1.0 to 1.0.0
- Add CHANGELOG.md with full feature summary
- Git history scrubbed of security.json (JWT secret)
2026-01-29 01:42:04 -06:00
Brad Groux
2ec4aa5ac2
fix(security): tighten CSP directives, remove unsafe-eval in dev
2026-01-28 17:47:13 -06:00
Brad Groux
d756889a1f
fix(security): replace weak dev admin key with strong random key
2026-01-28 17:42:20 -06:00
Brad Groux
279221ee38
ci: add GitHub Actions CI pipeline
2026-01-28 17:12:18 -06:00
Brad Groux
ccff6e78c8
fix(security): sanitize Content-Disposition header for attachments
2026-01-28 17:09:38 -06:00
Brad Groux
615b9b03b4
feat(security): replace custom rate limiter with express-rate-limit
...
- Swap hand-rolled Map-based rate limiter for battle-tested express-rate-limit
- Built-in MemoryStore handles TTL cleanup automatically (no memory leaks)
- Uses sliding window counter algorithm instead of fixed window
- Emits both IETF draft-7 (RateLimit-*) and legacy (X-RateLimit-*) headers
- Remove duplicate inline rate limiter from settings.ts, use shared strictRateLimit middleware
- Redis not warranted for single-instance local dev tool
2026-01-28 12:22:34 -06:00
Brad Groux
06df2e2050
fix(security): validate Origin header for WebSocket connections
2026-01-28 12:11:53 -06:00
Brad Groux
9d0f5cae47
feat(perf): add gzip response compression middleware
2026-01-28 12:09:05 -06:00
Brad Groux
5aa31115ae
fix(security): remove .env from git, add .env.example
2026-01-28 12:05:17 -06:00
Brad Groux
228fe0b6f8
fix: add dotenv to load .env file at server startup
...
- Added dotenv package to server dependencies
- Import dotenv/config at top of server/src/index.ts
- Fixes AUTH_REQUIRED errors when using API keys and localhost bypass
Resolves issue where VERITAS_AUTH_LOCALHOST_BYPASS and VERITAS_ADMIN_KEY
environment variables were not being loaded from .env file.
2026-01-28 10:31:07 -06:00
Brad Groux
887cfc9a7e
feat(auth): Complete authentication sprint
...
- UserMenu: Session indicator with lock icon, expiry display, logout (Cmd+Shift+L)
- SecurityTab: Change password form with strength indicator, danger zone
- Header: Integrated UserMenu with security settings link
- SettingsDialog: Added Security tab with lazy loading, defaultTab prop
- useAuth: Fixed setup() to not refresh status before showing recovery key
Completes: US-d-eQbD, US-fCAsJx
2026-01-28 09:44:31 -06:00
Brad Groux
65e0c8b278
feat(US-1303): Add real-time WebSocket agent status hook
...
- Create useRealtimeAgentStatus hook with WebSocket subscription
- Subscribe to agent:status events as primary transport
- Fall back to polling every 10s when WebSocket disconnects
- Auto-reconnect on WebSocket disconnect (via useWebSocket)
- Stale detection marks agent as idle after 5+ min without updates
- Memoized return value to prevent unnecessary re-renders
- Full TypeScript types for AgentStatusData, SubAgent, AgentStatusState
- Maintain backwards compatibility with useGlobalAgentStatus (polling-only)
2026-01-28 07:42:00 -06:00
Brad Groux
39eccf3556
feat: Sprint US-1200 Refactoring batch — 13 tasks complete
...
Completed refactors:
- RF-02: Fix dependency vulnerabilities (xlsx → exceljs, Hono updates)
- RF-05: Add React error boundaries (FeatureErrorBoundary wrapper)
- RF-06: Server error handling middleware (AppError classes, asyncHandler)
- RF-10: Split shared types.ts into domain modules (6 files)
- RF-11: Consolidate frontend API layer (hooks now use api.ts)
- RF-13: TaskConfigContext — eliminate prop drilling
- RF-14: Split god components (GitSection, TaskDetailPanel, CreateTaskDialog, DiffViewer)
- RF-16: Frontend accessibility (ARIA labels, sr-only text)
- RF-17: Modularize CLI (899 → commands/ structure)
- RF-18: Modularize MCP (843 → tools/ structure)
- RF-19: Create shared API client library
- RF-21: Server performance (batch loading, memory limits, timeouts, graceful shutdown)
- RF-23: Extract shared utilities (path, format, constants)
Stats: ~59 files changed, significant code reduction through modularization
2026-01-28 06:08:59 -06:00
Brad Groux
76f71d2e0d
feat(US-912): Implement task attachments with text extraction pipeline
...
Backend:
- Add Attachment types, limits config, and MIME type allowlist to shared types
- Create AttachmentService for file storage, upload/delete, archive lifecycle
- Create TextExtractionService supporting PDF, DOCX, XLSX, HTML, JSON, plain text
- Add attachment routes with multer upload middleware
- Add /api/tasks/:id/context endpoint for agent consumption
- Update task-service to handle attachments in frontmatter and lifecycle
- Install dependencies: multer, unpdf, mammoth, xlsx, mime-types
Frontend:
- Build AttachmentsSection component with drag-drop upload zone
- Add inline image thumbnails and expandable text previews
- Implement token cost warning banner (amber alert when ≥2 attachments)
- Add Attachments tab to TaskDetailPanel
- Add paperclip badge with count to TaskCard
- Create React hooks: useUploadAttachment, useDeleteAttachment, useTaskContext
Tests:
- Comprehensive test suites for attachment-service and text-extraction-service
- Cover upload, delete, archive, extraction for all file types
All 13 subtasks completed. Project compiles cleanly.
2026-01-27 21:49:00 -06:00
Brad Groux
45a5c37612
feat: complete US-102 (task parser) and US-103 (REST API)
...
- Task schema with full types in shared package
- TaskService with injectable paths for testing
- gray-matter for markdown frontmatter parsing
- 15 unit tests for parser/service
- Full CRUD API with zod validation
- Fixed undefined value handling in frontmatter
- Updated sprint tracking
2026-01-26 02:49:09 -06:00
Brad Groux
95e758337f
fix: TypeScript errors in server and web packages
...
- Remove slugify dependency, use custom makeSlug function
- Add explicit Router type annotation
- Remove unused ChevronUp import
- Build shared package for type exports
2026-01-26 02:37:17 -06:00
Brad Groux
a489c5358f
feat: initial project scaffolding
...
- Dev container with Node.js 22
- pnpm workspace monorepo structure
- Express + WebSocket server
- React + Vite + shadcn/ui frontend
- Shared TypeScript types package
- Kanban board with drag-and-drop
- Task CRUD with file-based persistence
- Dark mode styling
Sprint 1 - US-101: Project scaffolding with dev container
2026-01-26 02:34:54 -06:00