Commit graph

203 commits

Author SHA1 Message Date
Brad Groux
e4ef471941 fix: status counter accuracy + bulk operation performance (#104, #105)
- New GET /api/tasks/counts endpoint for sidebar totals (independent of board filters)
- New useTaskCounts() hook + BoardSidebar rewired
- New bulk endpoints: POST /api/tasks/bulk-update, bulk-archive-by-ids, /api/backlog/bulk-demote
- BulkActionsBar uses single API calls instead of N sequential requests
- Array size validation (max 100) on all bulk endpoints
- Parallel execution via Promise.allSettled() (~26x faster)
- Updated squad chat model field documentation (#106)
- Version bump to 2.1.4

Closes #104, #105
10/10/10/10 reviewed by TARS (gh-sonnet)
2026-02-09 15:03:59 -06:00
Brad Groux
13a86b15e2 fix(tests): correct vi.mock for node:fs/promises in docker-paths test
- Use importOriginal to spread actual module exports
- Provide default export required by vitest
- Mock mkdir, access, existsSync for CI runner compatibility
2026-02-08 14:37:22 -06:00
Brad Groux
fab0f16ab4 fix(test): add default export to node:fs/promises mock
The mock needs a default export for vitest to properly handle the module import.
2026-02-08 14:32:37 -06:00
Brad Groux
f50c8a594c fix(ci): add shared build step + fix all type errors across server/cli
- Add 'Build shared' step to Lint & Type Check job in CI workflow
- Add explicit type annotations to ~50 parameters across server + CLI
- Fix docker-paths test to properly mock filesystem operations
- Verified: clean install → shared build → lint/typecheck/test/build all passing
2026-02-08 14:29:55 -06:00
Brad Groux
5c17972bfb fix(ci): mock docker paths fs calls + add CLI type annotations
- Mock fs.mkdir in docker-paths test (EACCES on Linux runners)
- Mock fs.existsSync with smart logic for pnpm-workspace.yaml detection
- Add explicit type annotations to all CLI commands (27 implicit any types)
- Verified: pnpm lint, typecheck, test (1252 tests), build all passing
2026-02-08 14:04:33 -06:00
Brad Groux
8310167d4c fix(tests): update 85 server tests for v2.1.0 service refactoring
- Update agent-registry tests for singleton pattern (29 tests)
- Rewrite notification tests for @mention-based API (22 tests)
- Fix auth middleware test fixtures (3 tests)
- Update schema default expectations (1 test)
- Fix docker-paths test to mock fs.mkdir properly
- All 1252 tests passing

Test categories fixed:
1. AgentRegistryService: Changed from constructor to getAgentRegistryService() singleton
2. NotificationService: Complete API rewrite for @mention system
3. Auth middleware: API key format now includes - and _ characters
4. Schema: Metrics period default changed from 24h to 7d

Part of task_20260208_9pK4PX
2026-02-08 13:14:48 -06:00
Brad Groux
44b63455ea fix(docker): standardize path resolution across all services (#102)
Created shared paths.ts utility as single source of truth for all path
resolution. Refactored 7 services to use it:

- server/src/utils/paths.ts: New shared utility with JSDoc docs
- task-service: Uses getTasksActiveDir()/getTasksArchiveDir()
- activity-service: Uses getDataDir()
- chat-service: Uses getChatsDir()
- audit-service: Uses getAuditDir()
- metrics/helpers: Uses getProjectRoot()/getTelemetryDir()
- backlog-repository: Uses getTasksBacklogDir()

Resolution priority: DATA_DIR/VERITAS_DATA_DIR env var > auto-discovery
of monorepo root (walks up looking for pnpm-workspace.yaml) > cwd fallback.
Filesystem root guard prevents silent '/' resolution (the original EACCES bug).

Backwards compatible: existing DATA_DIR configurations unchanged.
Cross-model reviewed: 10/10/10/10 (GPT-5.1 authored, Claude Sonnet 4.5 reviewed).

Closes #102

[author: gpt-5.1]
[reviewed-by: claude-sonnet-4.5]
Version: 2.1.3
2026-02-07 22:02:05 -06:00
Brad Groux
e0bd0102cb fix: add TRUST_PROXY env var for reverse proxy deployments (#100)
Resolves #100. Adds configurable trust proxy setting via TRUST_PROXY
environment variable. Supports numeric hop counts, subnet strings, and
named values (loopback, linklocal, uniquelocal). TRUST_PROXY=true is
intentionally blocked (unsafe for production — logs warning and falls
back to default). Disabled by default (no behavior change).

Includes documentation updates for nginx, Caddy, and Docker deployments.
2026-02-07 14:53:02 -06:00
Brad Groux
8cce9f24c4 feat: Squad chat protocol scripts, system events, model attribution
- Add squad-post.sh for regular agent messages
- Add squad-event.sh for lifecycle events (spawned/completed/failed/status)
- Add model field to squad messages (types, server, UI, scripts)
- System events render as divider lines in squad chat panel
- Model attribution displays next to agent names in UI
- Full protocol documented in SQUAD-CHAT-PROTOCOL.md
- Updated CONTRIBUTING.md, README.md, and all SOPs
- Added VK_HOST/VK_PORT env vars to .env.example

4-check cross-model review: 10/10 (Code/GPT-5.1, Func/Grok, Perf/Grok, Sec/GPT-5.1)
Agents: R2-D2 (feature), TARS/CASE/Ava/K-2SO (reviews)
2026-02-07 13:04:17 -06:00
Brad Groux
e79b7c3f5b v2.1.0: Documentation, security hardening, performance optimizations
Documentation:
- Updated README with all new features (squad chat, broadcasts, deliverables, polling, delegation, OpenClaw integration)
- Added Pre-Commit Review Protocol to CONTRIBUTING.md (mandatory 4 checks: code, functionality, performance, security)
- Added One Agent Per File development rule
- Created 5 comprehensive feature docs (docs/features/)
- Consolidated and cleaned up 8 scattered implementation docs
- Updated lessons learned with 6 additional insights from today

Security:
- Stripped gateway token from all API responses (write-only field)
- Added file locking to notification-service and config-service

Performance:
- Removed double cache invalidation in squad chat
- Added React.memo to message bubble components

Version bump: 2.0.0 → 2.1.0

All reviews passed 10/10 (code, functionality, performance, security)
Contributors: TARS, CASE, Ava, K-2SO, R2-D2, VERITAS
2026-02-07 11:51:24 -06:00
Brad Groux
a249dee1fb Merge: Squad chat, webhooks, delegation, polling + critical security fixes
Feature branches merged:
- Agent squad chat with real-time WebSocket updates
- Broadcast notifications (priority levels, read receipts)
- Task deliverables as first-class objects
- Efficient polling endpoint with change tracking
- Approval delegation / vacation mode

Security & stability fixes:
- Fix: path traversal vulnerability in broadcast storage
- Fix: TOCTTOU race condition in broadcast.markRead()
- Fix: double cache invalidation in squad chat
- Fix: file locking consistency for concurrent writes
- Add: default agent display name handling

Improvements:
- React.memo for message bubbles (perf)
- Save-on-blur for display name input
- Auto-scroll to latest in squad chat
- OpenClaw gateway wake integration
- One-agent-per-file development rule (CONTRIBUTING.md)

All reviews passed (code, functionality, performance, security)
27 files changed, comprehensive test coverage added

v2.0.0 ready for production
2026-02-07 11:30:52 -06:00
Brad Groux
ce429dd1b3 fix: allow WebSocket connectSrc in production CSP 2026-02-07 08:50:54 -06:00
Brad Groux
c3f67da1f9 merge: integrate broadcast endpoint into main 2026-02-07 08:20:34 -06:00
Brad Groux
181939739f merge: resolve conflicts integrating polling + broadcast endpoints 2026-02-07 08:20:21 -06:00
Brad Groux
1eb93b1dd0 Merge branch 'feat/agent-squad-chat' 2026-02-07 08:20:06 -06:00
Brad Groux
c67173a7e0 feat: deliverables as first-class task objects (#95)
- Add Deliverable interface with type, status, path, agent fields
- Add deliverables field to Task, UpdateTaskInput, TaskSummary
- Create API endpoints: POST/GET/PATCH/DELETE /api/tasks/:id/deliverables
- Add requireDeliverableForDone setting (default: false)
- Validate done transition requires deliverable when setting enabled
- Add DeliverablesSection component to task detail panel
- Add deliverable count badge to board cards
- Add settings toggle in Tasks tab
- Log deliverable_added/updated/deleted activity events
- Add useDeliverables hooks for CRUD operations
2026-02-07 08:18:18 -06:00
Brad Groux
5225658e3a feat: agent squad chat channel (#97) 2026-02-07 08:14:54 -06:00
Brad Groux
f00bba7010 feat: broadcast endpoint for agent notifications (#98) 2026-02-07 08:09:53 -06:00
Brad Groux
2309e1e09d fix: remove stray broadcast route reference 2026-02-07 08:06:28 -06:00
Brad Groux
4f513017f9 feat: add efficient agent polling endpoint (changes since) (#96) 2026-02-07 08:05:38 -06:00
UC-VR
f17568cd21
feat: configurable auto-save delay for task editor (#94)
- Add autoSaveDelayMs to TaskBehaviorSettings (default: 500ms)
- Update useDebouncedSave hook to use config setting instead of hardcoded value
- Add UI control in Tasks settings tab (slider: 200-5000ms, step 100)
- Add validation schema (min: 200ms, max: 5000ms)

The default 500ms delay was too aggressive for comfortable text editing,
causing interruptions mid-sentence. This makes the delay user-configurable
to accommodate different typing speeds and preferences.

Co-authored-by: OpenClaw Agent <agent@openclaw.ai>
2026-02-07 07:36:59 -06:00
Brad Groux
ed8606fb74 feat: per-widget dashboard visibility toggles
Add individual on/off toggles for each dashboard widget in
Settings > Board & Display. When 'Show Dashboard' is enabled,
a nested list of 12 widget toggles appears:

- Token Usage, Run Duration, Agent Comparison, Status Timeline
- Cost per Task, Agent Utilization, Wall Time, Session Metrics
- Activity Clock, Where Time Went, Hourly Activity, Trends Charts

All default to ON. Server-side Zod schema updated to accept
the new dashboardWidgets object. Shared types already had the
DashboardWidgetSettings interface from a prior commit.
2026-02-05 20:48:35 -06:00
Brad Groux
6d0bca3ed9 feat: register all 10 named agents + fix route ordering
Agent Roster:
- Veritas (orchestrator, Opus 4.6)
- TARS, CASE (leads, Opus 4.6)
- Ava, R2-D2, K-2SO, MAX, Bishop (specialists, Sonnet 4.5)
- Johnny 5, Marvin (interns, Haiku 4.5)

Fix: mount /agents/register and /agents/permissions BEFORE
/agents catch-all routes to prevent /:taskId param matching
2026-02-05 19:58:06 -06:00
Brad Groux
ddd5049d45 fix: comprehensive dashboard plumbing overhaul
Data fixes:
- Backfill agent='veritas' on 987 telemetry events (were 'unknown')
- Backfill run.tokens events for Feb 3-5 (46 events, estimated from durations)
- Reset stuck agent status to idle

Utilization:
- Switch from status-history (1 entry!) to telemetry-based computation
- Timezone-aware date bucketing via tz query param
- Current day uses elapsed time, not full 24h

Dashboard layout:
- Remove Success Rate chart (redundant with Session Metrics)
- Task Activity Per Day now full width
- Fix tooltip info icons (delayDuration=0, asChild, button wrapper)
- Default period changed from 3d to 7d (token data starts Jan 31)
2026-02-05 19:43:08 -06:00
Brad Groux
2952c4b3f1 feat: timezone-aware metrics via tz query param
- Add ?tz=<offset> to metrics endpoints (e.g. ?tz=-6 for CST, ?tz=9 for JST)
- Server defaults to system time when tz is omitted
- Client auto-sends browser timezone offset on utilization requests
- Shared helpers: toLocalDateStr(), getTodayStr(), getElapsedTodayMs()
- Date bucketing and 'today' detection respect the requested timezone
- Works for any timezone — not hardcoded to any region
2026-02-05 19:30:18 -06:00
Brad Groux
23a96d3ea7 feat: add timezone offset to all API response meta
Every API response now includes:
  meta.timezone: 'UTC-06:00' (human-readable)
  meta.utcOffset: -6 (numeric, for client-side math)

Uses system time — no config needed.
2026-02-05 19:24:22 -06:00
Brad Groux
db6d741b3f fix: use system local timezone for utilization date bucketing
- 'Today' detection uses local time (getHours) not UTC (getUTCHours)
- Event timestamps converted to local dates for daily bucketing
- Fixes Feb 5 CST events being bucketed into Feb 6 UTC
- Server uses system timezone (America/Chicago = CST/CDT)
2026-02-05 19:22:05 -06:00
Brad Groux
b9cf2f4a29 fix: dashboard plumbing audit — utilization, activity sources, data integrity
- Fix daily utilization: use elapsed time for current day (was 100% because
  active time ÷ 0 hours elapsed = infinity, capped to 100%)
- Activity Clock + Hourly Activity: switch from broken activity.json (1 record)
  to status-history endpoint (has actual agent state transitions)
- Task-cost API: add project + totalDurationMs fields for Where Time Went
- Where Time Went: pull real project data from task-cost telemetry
- Wall Time toggle: rewrite with clear labels + info tooltips
- Normalize Feb 3 telemetry outlier (66min → 19min)

GH #92 created: Dashboard widget toggles with descriptions
2026-02-05 19:09:50 -06:00
Brad Groux
63eea30aad fix: dashboard overhaul per Brad's review feedback
- Remove Success/Errors card (Sessions widget covers it)
- Activity Over Time: add Y-axis 'Events' label
- Where Time Went: pull real data from telemetry by project (was blank)
- Wall Time: rewrite as Total Agent Time + Avg Run Duration with tooltips
- Activity Clock: add info tooltip explaining the visualization
- Agent Comparison: lower minRuns to 1 so all agents show
- Task-cost API: add project + totalDurationMs fields for widgets
- Normalize Feb 3 time outlier (66min → 19min, capped at p95)
- TrendsCharts (Task Activity per Day): full width layout
2026-02-05 19:01:17 -06:00
Brad Groux
21d3fed50b fix: resolve build errors — storage paths, type casts, import ordering, backward compat
- Replace non-existent getStorageBase with DATA_DIR inline constant
- Fix import ordering (path must be imported before DATA_DIR declaration)
- Fix req.params/req.query type casts for Express strict mode
- Add createNotification() to NotificationService for failure-alert backward compat
- Export NotificationService class for type imports
- Cast telemetry events properly in cost-prediction service
- Server builds clean and starts successfully
2026-02-05 18:49:39 -06:00
Brad Groux
5ea3e58964 feat: add branded PDF report generation with templates and brand config (closes #90)
Inspired by @nateherk's Klouse branded PDF reports.

- 5 report templates: audit, summary, analysis, standup, custom
- Brand config: company name, logo, colors, font, tagline
- Markdown → HTML conversion with print-optimized CSS
- Template-specific styles (audit findings, metrics cards, status colors)
- HTML served directly or printable to PDF via browser
- Reports stored in docs/reports/ and accessible via docs tab
- REST API: generate, list, get, brand CRUD, templates, HTML serve
2026-02-05 18:38:45 -06:00
Brad Groux
0ade973d7d feat: add scheduled deliverables view — recurring workflows and outputs (closes #89)
Inspired by @nateherk's Klouse scheduled deliverables view.

- Deliverables: daily/weekly/biweekly/monthly/custom schedules
- Run tracking: success/failed/skipped with output files and summaries
- Next run calculation, enable/disable toggle
- REST API: CRUD deliverables, record runs, run history
- Tags, agent assignment, output path configuration
- Persistent storage with 500-run history cap
2026-02-05 18:37:04 -06:00
Brad Groux
6c47b8801c feat: add docs tab with markdown viewer, editor, and file browser (closes #88)
Inspired by @nateherk's Klouse dashboard docs section.

- DocsService: CRUD for markdown files, search by name/content, directory listing
- Path traversal protection: resolved paths validated against docs root
- REST API: list, get, save, delete, search, directories, stats
- DocsViewer component: file browser sidebar + markdown preview/editor
- Directory navigation, file search, inline editing with save
- Create new docs, delete existing, file size + modified timestamps
- Configurable docs root via VK_DOCS_DIR env var
2026-02-05 18:35:46 -06:00
Brad Groux
8963293e38 feat: add task lifecycle hooks — configurable automation on state transitions (closes #72)
Inspired by Monika Voutov's BoardKit Orchestrator (https://github.com/BoardKit/orchestrator)

- 7 built-in hooks: log, time start/stop, verify checklist, request context, notify, telemetry
- 8 lifecycle events: created, started, blocked, done, cancelled, assigned, commented, reviewed
- Custom hooks: create your own with filters (task type, project, priority)
- Execution log: track hook runs with timing and success/failure
- Extensible: registerHandler() for custom action types
- REST API: CRUD hooks, manual fire, execution history
- Fixed duplicate notification import in v1/index.ts
2026-02-05 18:29:30 -06:00
Brad Groux
5af107d0a1 feat: add agent permission levels — intern/specialist/lead with approval workflow (closes #31)
- Three levels: intern (needs approval), specialist (independent), lead (full autonomy)
- Permission checks: canCreateTasks, canDelegate, canApprove, autoComplete
- Approval queue: interns request approval, leads review
- Trusted domains: scope specialist agents to specific capabilities
- Custom restrictions: block specific endpoint patterns per agent
- REST API: GET/PUT/PATCH permissions, POST check, approval CRUD
- Persistent storage: agent-permissions.json, approval-requests.json
2026-02-05 18:27:41 -06:00
Brad Groux
2620e9a79c feat: add @mention notification system with thread subscriptions (closes #30)
- Notification Service: @mention parsing, delivery tracking, thread subscriptions
- Mention parser: extracts @agent-name from text, supports @all broadcast
- Thread subscriptions: auto-subscribe on comment, mention, or assignment
- Delivery tracking: mark individual or bulk-deliver notifications
- REST API: GET notifications, POST process, POST delivered, GET stats
- Notification types: mention, assignment, status_change, reply
- Persistent storage: notifications.json + thread-subscriptions.json
2026-02-05 18:18:47 -06:00
Brad Groux
35277d5c10 feat: add error learning workflow — structured failure analysis and knowledge capture (closes #91)
Inspired by @nateherk's Klouse dashboard approach:
'Spin up agents to analyze what broke, why, and how to prevent it'

- Error Learning Service: submit errors, structured analysis, pattern detection
- Auto-tags, severity estimation, repeat detection
- Links analyses to task lessonsLearned field
- Similarity search for 'have we seen this before?'
- Aggregate stats: by type, severity, repeat rate, top prevention steps
- REST API: POST /submit, PATCH /:id, GET /, GET /stats, GET /search
2026-02-05 18:06:25 -06:00
Brad Groux
c13ee08fbf feat: add task cost prediction at creation with accuracy tracking (closes #54)
- Cost Prediction Service: predicts task cost based on type, priority, complexity, history
- Prediction factors: type multiplier, priority multiplier, description complexity, project adjustment
- Historical base cost: calculated from telemetry data for similar tasks
- Confidence levels: low/medium/high based on sample size
- Accuracy tracking: predicted vs actual cost comparison for completed tasks
- Accuracy stats: MAE, mean/median accuracy, within-20%/50% metrics, per-type breakdown
- Task schema: added costPrediction and actualCost fields
- REST API: POST /predict, GET /accuracy, GET /accuracy/stats
2026-02-05 18:02:39 -06:00
Brad Groux
fcf1756b79 feat: add agent self-reporting protocol with registry, heartbeat, and discovery (closes #52)
- Agent Registry Service: registration, heartbeat, capability discovery, stale detection
- REST API: POST /register, POST /:id/heartbeat, DELETE /:id, GET /stats, GET /capabilities/:cap
- Persistent storage: .veritas-kanban/agent-registry.json
- Auto-offline: agents without heartbeat for 5min marked offline
- AGENTS.md template: docs/AGENTS-TEMPLATE.md with full integration guide
2026-02-05 17:56:04 -06:00
Brad Groux
d6518f66db fix(activity): Status history click opens task + capture task info
1. KanbanBoard now consumes pendingTaskId from ViewContext
   - Clicking status history entry navigates to board AND opens task detail
   - Fetches task from API if not in current filtered list

2. Status history now captures taskId/taskTitle from activeAgents
   - When status changes via activeAgents (not activeTask), derive task info
   - Falls back to first activeAgent's taskId/taskTitle
   - Fixes missing titles in ~90% of status history entries
2026-02-04 20:55:28 -06:00
Brad Groux
51bd4da251 docs(#43): Add Analytics API documentation and Swagger schemas
- Add comprehensive ANALYTICS.md documenting all endpoints
- Document data models, metrics, and usage examples
- Add TESTING_ANALYTICS.md with test scenarios
- Update swagger.ts with analytics schemas and endpoints
- Include performance benchmarks and troubleshooting guide
2026-02-04 20:40:49 -06:00
Brad Groux
dd9f8eee1e feat(#39): Task Templates UI - management page + create from template 2026-02-04 20:39:28 -06:00
Brad Groux
64998b0757 feat: Multiple bug fixes and enhancements
- fix(REL-001): Add withFileLock to 5 unguarded services
- fix(REL-002): Replace plain objects with useRef in useFeatureSettings
- fix(REL-003): Only clear dirty state on mutation success in useDebouncedSave
- fix(REL-004): Fix ActivityFeed knownIdsRef stale reference
- fix(REL-005): Fix ArchiveSidebar useMemo used as useEffect
- fix(REL-006): Fix ConflictResolver render-time setState
- fix(REL-007): Fix useSortableList stale rollback + array mutation
- feat(A11Y-001): Add aria-labels to icon-only buttons
- feat(A11Y-002): Add keyboard support to clickable divs
- feat(#41): Lessons Learned Field - UI component + API endpoint

Co-authored-by: Veritas <veritas@digitalmeld.io>
2026-02-04 20:37:18 -06:00
Brad Groux
6fcab43803 feat: Status Transition Hooks (Quality Gates)
Add pre-transition gates that must pass before status change is allowed:
- require-agent: Task must have agent assigned
- require-plan: Description must contain Plan section
- require-verification-complete: All verification steps checked
- require-time-tracked: Time tracking must have entries
- require-closing-comment: Task must have at least one comment
- require-subtasks-complete: All subtasks completed
- require-blocker-reason: blockedReason must be set

Add post-transition actions that fire after status change:
- auto-start-timer: Start time tracking
- auto-stop-timer: Stop time tracking
- send-webhook: POST to URL
- send-notification: Send to channel
- prompt-lessons-learned: Flag for capture
- log-activity: Log to activity feed

API:
- GET/PUT/PATCH /api/settings/transition-hooks
- POST /api/settings/transition-hooks/validate
- CRUD for individual rules at /api/settings/transition-hooks/rules

Config stored in .veritas-kanban/transition-hooks.json

Also adds 'cancelled' status and 'critical' priority to shared types.

Ref: task_20260201_04iPHh
2026-02-04 19:50:57 -06:00
Brad Groux
e00a72bb3d perf: Stream telemetry reads, push pagination to service, optimize lookups
PERF-001: Replace gunzipSync with streaming readline + createGunzip
         Apply filters during streaming for early rejection

PERF-002: Add offset parameter to activity service getActivities()
         Route uses offset instead of fetching page*limit and slicing

PERF-003: BacklogRepository findById() uses file prefix lookup O(n) → O(1)
         task-metrics velocity uses Set for archived IDs (O(n²) → O(n))
         audit-service verifyAuditLog() uses readline streaming

Ref: RF-002a audit findings (Medium/Low severity)
2026-02-04 09:56:19 -06:00
Brad Groux
ac1386ac12 fix(QA): Replace Math.random with crypto.randomUUID, align types, fix React issues
QA-001: Use crypto.randomUUID() for entity IDs (comments, subtasks, verification)
QA-002: Add 'critical' to TaskPriority, 'cancelled' to TaskStatus; guard process.env
QA-003: Fix GitSelectionForm useEffect deps, AgentStatusIndicator useMemo tick,
        ArchivePage Set mutation
Bonus: Add variant to Toast type (pre-existing build error)

Ref: RF-002a/b/c audit findings
2026-02-04 09:52:54 -06:00
Brad Groux
f176592259 feat(US-1611): Complete orchestrator-inspired features
- #73 Prompts registry: prompt-registry/ with 10 starter templates ✓
- #74 Doc freshness: CLAUDE.md template + SOP-documentation-freshness.md ✓
- #75 Setup wizard: vk setup command ✓
- #76 Lifecycle hooks: hook-service.ts + SOP-lifecycle-hooks.md ✓
- #77 Shared resources: SOP-shared-resources.md ✓

Credit: Inspired by Monika Voutov's BoardKit Orchestrator
https://github.com/BoardKit/orchestrator

Closes #73, closes #74, closes #75, closes #76, closes #77
2026-02-04 09:47:38 -06:00
Brad Groux
30e18393f4 fix(security): SEC-001 path traversal — add validation to trace + template services
Extended path traversal protection to two services missed in initial audit:

- trace-service.ts: validate attemptId, taskId, traceId before path.join
- template-service.ts: validate templateId in templatePath()

Both now use validatePathSegment() + ensureWithinBase() from utils/sanitize.ts.

Ref: RF-002a Batch 3a Findings (High+Medium severity)
2026-02-04 09:08:35 -06:00
Brad Groux
ed1fbb3fb4 fix: sidebar task counts now show current state, not time-filtered
Bug 1: /api/metrics/all was passing the period filter to task counts,
showing only tasks touched within the time window (e.g., 33 todo in 24h)
instead of current board state (124 todo total).

Fix: computeAllMetrics now passes null to computeTaskMetrics so task
status counts always reflect current state. Period filter still applies
to telemetry metrics (runs, tokens, duration).

Bug 2: /api/backlog/count was double-wrapping response (route wrapped
with success/data, then middleware wrapped again).

Fix: Route now returns { count } and lets responseEnvelopeMiddleware
handle wrapping.
2026-02-04 09:02:16 -06:00
Brad Groux
f508c00593 fix: archive/delete/restore now find actual file on disk
Bug: taskToFilename() generates filename from current title, but the
actual file on disk may have a different slug if the title changed after
creation. This caused INTERNAL_ERROR on archive/delete/restore.

Fix: Added findTaskFile() helper that searches by task ID prefix instead
of computing the expected filename. Applied to archiveTask, deleteTask,
and restoreTask.

Also: archiveSprint now throws ValidationError instead of generic Error
for better API error responses.
2026-02-04 08:54:27 -06:00