Commit graph

69 commits

Author SHA1 Message Date
Brad Groux
44b63455ea fix(docker): standardize path resolution across all services (#102)
Created shared paths.ts utility as single source of truth for all path
resolution. Refactored 7 services to use it:

- server/src/utils/paths.ts: New shared utility with JSDoc docs
- task-service: Uses getTasksActiveDir()/getTasksArchiveDir()
- activity-service: Uses getDataDir()
- chat-service: Uses getChatsDir()
- audit-service: Uses getAuditDir()
- metrics/helpers: Uses getProjectRoot()/getTelemetryDir()
- backlog-repository: Uses getTasksBacklogDir()

Resolution priority: DATA_DIR/VERITAS_DATA_DIR env var > auto-discovery
of monorepo root (walks up looking for pnpm-workspace.yaml) > cwd fallback.
Filesystem root guard prevents silent '/' resolution (the original EACCES bug).

Backwards compatible: existing DATA_DIR configurations unchanged.
Cross-model reviewed: 10/10/10/10 (GPT-5.1 authored, Claude Sonnet 4.5 reviewed).

Closes #102

[author: gpt-5.1]
[reviewed-by: claude-sonnet-4.5]
Version: 2.1.3
2026-02-07 22:02:05 -06:00
Brad Groux
d9b946b215 chore: bump version to 2.1.2 — Docker path resolution fix
- Version bumped in all package.json files (root, server, web, shared)
- CHANGELOG: v2.1.2 entry documenting WORKDIR fix and root cause
- README: version badge updated to 2.1.2
- DEPLOYMENT.md: path resolution note added
- TROUBLESHOOTING.md: EACCES fix guide added
- docker-compose.yml: WORKDIR comment added

Reviewed: 10/10/10/10
Related: #102
2026-02-07 16:57:37 -06:00
Brad Groux
8cce9f24c4 feat: Squad chat protocol scripts, system events, model attribution
- Add squad-post.sh for regular agent messages
- Add squad-event.sh for lifecycle events (spawned/completed/failed/status)
- Add model field to squad messages (types, server, UI, scripts)
- System events render as divider lines in squad chat panel
- Model attribution displays next to agent names in UI
- Full protocol documented in SQUAD-CHAT-PROTOCOL.md
- Updated CONTRIBUTING.md, README.md, and all SOPs
- Added VK_HOST/VK_PORT env vars to .env.example

4-check cross-model review: 10/10 (Code/GPT-5.1, Func/Grok, Perf/Grok, Sec/GPT-5.1)
Agents: R2-D2 (feature), TARS/CASE/Ava/K-2SO (reviews)
2026-02-07 13:04:17 -06:00
Brad Groux
e79b7c3f5b v2.1.0: Documentation, security hardening, performance optimizations
Documentation:
- Updated README with all new features (squad chat, broadcasts, deliverables, polling, delegation, OpenClaw integration)
- Added Pre-Commit Review Protocol to CONTRIBUTING.md (mandatory 4 checks: code, functionality, performance, security)
- Added One Agent Per File development rule
- Created 5 comprehensive feature docs (docs/features/)
- Consolidated and cleaned up 8 scattered implementation docs
- Updated lessons learned with 6 additional insights from today

Security:
- Stripped gateway token from all API responses (write-only field)
- Added file locking to notification-service and config-service

Performance:
- Removed double cache invalidation in squad chat
- Added React.memo to message bubble components

Version bump: 2.0.0 → 2.1.0

All reviews passed 10/10 (code, functionality, performance, security)
Contributors: TARS, CASE, Ava, K-2SO, R2-D2, VERITAS
2026-02-07 11:51:24 -06:00
Brad Groux
a249dee1fb Merge: Squad chat, webhooks, delegation, polling + critical security fixes
Feature branches merged:
- Agent squad chat with real-time WebSocket updates
- Broadcast notifications (priority levels, read receipts)
- Task deliverables as first-class objects
- Efficient polling endpoint with change tracking
- Approval delegation / vacation mode

Security & stability fixes:
- Fix: path traversal vulnerability in broadcast storage
- Fix: TOCTTOU race condition in broadcast.markRead()
- Fix: double cache invalidation in squad chat
- Fix: file locking consistency for concurrent writes
- Add: default agent display name handling

Improvements:
- React.memo for message bubbles (perf)
- Save-on-blur for display name input
- Auto-scroll to latest in squad chat
- OpenClaw gateway wake integration
- One-agent-per-file development rule (CONTRIBUTING.md)

All reviews passed (code, functionality, performance, security)
27 files changed, comprehensive test coverage added

v2.0.0 ready for production
2026-02-07 11:30:52 -06:00
Brad Groux
c3f67da1f9 merge: integrate broadcast endpoint into main 2026-02-07 08:20:34 -06:00
Brad Groux
181939739f merge: resolve conflicts integrating polling + broadcast endpoints 2026-02-07 08:20:21 -06:00
Brad Groux
1eb93b1dd0 Merge branch 'feat/agent-squad-chat' 2026-02-07 08:20:06 -06:00
Brad Groux
c67173a7e0 feat: deliverables as first-class task objects (#95)
- Add Deliverable interface with type, status, path, agent fields
- Add deliverables field to Task, UpdateTaskInput, TaskSummary
- Create API endpoints: POST/GET/PATCH/DELETE /api/tasks/:id/deliverables
- Add requireDeliverableForDone setting (default: false)
- Validate done transition requires deliverable when setting enabled
- Add DeliverablesSection component to task detail panel
- Add deliverable count badge to board cards
- Add settings toggle in Tasks tab
- Log deliverable_added/updated/deleted activity events
- Add useDeliverables hooks for CRUD operations
2026-02-07 08:18:18 -06:00
Brad Groux
5225658e3a feat: agent squad chat channel (#97) 2026-02-07 08:14:54 -06:00
Brad Groux
f00bba7010 feat: broadcast endpoint for agent notifications (#98) 2026-02-07 08:09:53 -06:00
Brad Groux
4f513017f9 feat: add efficient agent polling endpoint (changes since) (#96) 2026-02-07 08:05:38 -06:00
UC-VR
f17568cd21
feat: configurable auto-save delay for task editor (#94)
- Add autoSaveDelayMs to TaskBehaviorSettings (default: 500ms)
- Update useDebouncedSave hook to use config setting instead of hardcoded value
- Add UI control in Tasks settings tab (slider: 200-5000ms, step 100)
- Add validation schema (min: 200ms, max: 5000ms)

The default 500ms delay was too aggressive for comfortable text editing,
causing interruptions mid-sentence. This makes the delay user-configurable
to accommodate different typing speeds and preferences.

Co-authored-by: OpenClaw Agent <agent@openclaw.ai>
2026-02-07 07:36:59 -06:00
Brad Groux
69cf3c334c chore: v2.0.0 release prep
Version:
- Bump all packages to 2.0.0 (root, server, web, shared, mcp)

Security:
- Patch MCP SDK from ^1.25.3 to ^1.26.0 (GHSA-345p-7cg4-v4c7)
- Add rate limiting warning to README security section

Documentation:
- CHANGELOG: comprehensive v2.0.0 entry (18 features, fixes, credits)
- README: updated roadmap with v2.0 shipped features
- README: added v2.0 feature highlights (multi-agent, dashboard, lifecycle)
- README: version badge updated to 2.0.0
- AGENT-REGISTRY.md: VERITAS naming consistency (all caps)

Maintenance:
- Cleaned 21 stale feature branches (down to main only)
- Dashboard widget toggles scaffolding (#92)
- Pre-commit secret scan: clean
2026-02-05 20:45:36 -06:00
Brad Groux
21d3fed50b fix: resolve build errors — storage paths, type casts, import ordering, backward compat
- Replace non-existent getStorageBase with DATA_DIR inline constant
- Fix import ordering (path must be imported before DATA_DIR declaration)
- Fix req.params/req.query type casts for Express strict mode
- Add createNotification() to NotificationService for failure-alert backward compat
- Export NotificationService class for type imports
- Cast telemetry events properly in cost-prediction service
- Server builds clean and starts successfully
2026-02-05 18:49:39 -06:00
Brad Groux
dead22ba40 feat: add multi-agent task assignment with backward-compatible agent/agents fields (closes #29)
- Task schema: added agents[] field alongside existing agent field
- Agent helpers: getAssignedAgents(), isAgentAssigned(), normalizeAgentFields()
- MultiAgentSelector component: chips with colors, add/remove, primary star
- Registry integration: dropdown shows registered agents + custom input
- Backward compat: single agent auto-wrapped in array, agents[0] synced to agent
- Exported from shared package for CLI/server/web consumption
2026-02-05 18:17:25 -06:00
Brad Groux
c13ee08fbf feat: add task cost prediction at creation with accuracy tracking (closes #54)
- Cost Prediction Service: predicts task cost based on type, priority, complexity, history
- Prediction factors: type multiplier, priority multiplier, description complexity, project adjustment
- Historical base cost: calculated from telemetry data for similar tasks
- Confidence levels: low/medium/high based on sample size
- Accuracy tracking: predicted vs actual cost comparison for completed tasks
- Accuracy stats: MAE, mean/median accuracy, within-20%/50% metrics, per-type breakdown
- Task schema: added costPrediction and actualCost fields
- REST API: POST /predict, GET /accuracy, GET /accuracy/stats
2026-02-05 18:02:39 -06:00
Brad Groux
931d437b67 chore: Release v1.6.0
## Highlights
- Activity Page Redesign — Full-width status history, clickable navigation, color-coded badges
- Task Templates UI (#39) — Full management interface for templates
- Analytics API (#43) — Timeline and aggregate metrics endpoints
- Status Transition Hooks — Quality gates for task status changes
- 7 GitHub Issues Closed (#47, #48, #49, #51, #53, #56, #82)

## Changes
- Bump all packages to 1.6.0
- Update CHANGELOG.md with comprehensive release notes
- Update README.md version badge and roadmap
- Update FEATURES.md with new sections:
  - Task Templates (v1.6.0)
  - Analytics API (v1.6.0)
  - Dashboard Filter Bar (v1.6.0)
  - Redesigned Activity Feed section
- Activity page: purple for sub-agent, amber for in-progress, blue for done
- Status badges: uniform width, color-coded by status type
2026-02-04 22:11:13 -06:00
Brad Groux
64998b0757 feat: Multiple bug fixes and enhancements
- fix(REL-001): Add withFileLock to 5 unguarded services
- fix(REL-002): Replace plain objects with useRef in useFeatureSettings
- fix(REL-003): Only clear dirty state on mutation success in useDebouncedSave
- fix(REL-004): Fix ActivityFeed knownIdsRef stale reference
- fix(REL-005): Fix ArchiveSidebar useMemo used as useEffect
- fix(REL-006): Fix ConflictResolver render-time setState
- fix(REL-007): Fix useSortableList stale rollback + array mutation
- feat(A11Y-001): Add aria-labels to icon-only buttons
- feat(A11Y-002): Add keyboard support to clickable divs
- feat(#41): Lessons Learned Field - UI component + API endpoint

Co-authored-by: Veritas <veritas@digitalmeld.io>
2026-02-04 20:37:18 -06:00
Brad Groux
6fcab43803 feat: Status Transition Hooks (Quality Gates)
Add pre-transition gates that must pass before status change is allowed:
- require-agent: Task must have agent assigned
- require-plan: Description must contain Plan section
- require-verification-complete: All verification steps checked
- require-time-tracked: Time tracking must have entries
- require-closing-comment: Task must have at least one comment
- require-subtasks-complete: All subtasks completed
- require-blocker-reason: blockedReason must be set

Add post-transition actions that fire after status change:
- auto-start-timer: Start time tracking
- auto-stop-timer: Stop time tracking
- send-webhook: POST to URL
- send-notification: Send to channel
- prompt-lessons-learned: Flag for capture
- log-activity: Log to activity feed

API:
- GET/PUT/PATCH /api/settings/transition-hooks
- POST /api/settings/transition-hooks/validate
- CRUD for individual rules at /api/settings/transition-hooks/rules

Config stored in .veritas-kanban/transition-hooks.json

Also adds 'cancelled' status and 'critical' priority to shared types.

Ref: task_20260201_04iPHh
2026-02-04 19:50:57 -06:00
Brad Groux
ac1386ac12 fix(QA): Replace Math.random with crypto.randomUUID, align types, fix React issues
QA-001: Use crypto.randomUUID() for entity IDs (comments, subtasks, verification)
QA-002: Add 'critical' to TaskPriority, 'cancelled' to TaskStatus; guard process.env
QA-003: Fix GitSelectionForm useEffect deps, AgentStatusIndicator useMemo tick,
        ArchivePage Set mutation
Bonus: Add variant to Toast type (pre-existing build error)

Ref: RF-002a/b/c audit findings
2026-02-04 09:52:54 -06:00
Brad Groux
f176592259 feat(US-1611): Complete orchestrator-inspired features
- #73 Prompts registry: prompt-registry/ with 10 starter templates ✓
- #74 Doc freshness: CLAUDE.md template + SOP-documentation-freshness.md ✓
- #75 Setup wizard: vk setup command ✓
- #76 Lifecycle hooks: hook-service.ts + SOP-lifecycle-hooks.md ✓
- #77 Shared resources: SOP-shared-resources.md ✓

Credit: Inspired by Monika Voutov's BoardKit Orchestrator
https://github.com/BoardKit/orchestrator

Closes #73, closes #74, closes #75, closes #76, closes #77
2026-02-04 09:47:38 -06:00
Brad Groux
9291ba1cb3 fix: Update version to 1.5.0 in all package.json files
- Root package.json: 1.4.1 → 1.5.0
- server/package.json: 1.4.1 → 1.5.0
- web/package.json: 1.4.1 → 1.5.0
- shared/package.json: 1.4.1 → 1.5.0

Health endpoint now reflects correct version.
2026-02-04 08:40:24 -06:00
Brad Groux
a87c28decf docs: align versioning to v1.4.1 (packages, README, changelog) 2026-02-03 01:51:21 -06:00
Brad Groux
6356a5e15e feat: backlog board, dashboard overhaul, UI/UX refinements (#65, #66)
Backlog Board (#65):
- BacklogRepository, BacklogService, API routes (/api/backlog/*)
- BacklogPage with inline expand/collapse, promote/demote actions
- CLI commands: vk backlog list|promote|demote|delete
- Activity events for demote/promote operations
- 47 tasks moved to backlog (sales, DM-Web, HubSpot, Customer.io)

Dashboard Overhaul:
- Recovered DashboardFilterBar from crashed branch (preset pills, custom date range, project filter)
- New metrics: Cost per Task, Agent Utilization (status-history-based)
- Fixed success rate calculation (backward-compat for status vs success field)
- Backfilled 23 estimated run.tokens events
- Task Activity per Day replaces Runs per Day chart
- Removed Sprint Velocity, Blocked Breakdown, period dropdowns
- Fixed ErrorsDrillDown empty state

Board & Sidebar:
- 5th column sidebar: Agent Status Panel (always visible), Recent Status Changes, Budget
- Clickable task names/IDs in agent status
- Removed planning column entirely (status, type, schemas, UI, CLI, MCP)
- Archive button in task detail panel (next to Delete)
- Select button moved to FilterBar row

Activity Page (#66):
- Removed tabs, side-by-side layout: Activity Feed (2/3) + Status History (1/3)
- Daily summary spans top

UI/UX:
- Command palette (Cmd+K)
- Theme toggle (Moon/Sun) in header
- Main padding increased, removed chat icon
- Cleaned up dead code (VelocityChart, MetricCard, unused imports)
- Fixed conditional hooks in CommandPalette
2026-02-02 04:56:47 -06:00
Brad Groux
dc6bd85405 fix: replace all remaining 'Review' references with 'Blocked'
- BulkActionsBar: dropdown option 'Review' → 'Blocked'
- NotificationsTab: 'Review Needed' → 'Blocked' label/description
- constants.ts: remove obsolete 'review' status label
- summary CLI: 'Review' → 'Blocked' in standup output
- notification-service: fix misleading comment
- summary-service: fix misleading comment

Closes task_20260201_wOFjfL
2026-02-01 15:18:34 -06:00
Brad Groux
583d74b38d feat(v1.4): planning status + verification checklists (#40 #38) 2026-02-01 02:45:57 -06:00
Brad Groux
9369ca8bcf docs: update all documentation for v1.2.0 + v1.3.0
- Bump all package versions to 1.3.0
- README: version badge, blocked column, new feature highlights
- CHANGELOG: full v1.2.0 and v1.3.0 entries
- FEATURES.md: GitHub sync, activity feed, standup summary sections
- FEATURES.md: storage architecture, API envelope docs, new CLI commands
- FEATURES.md: updated API endpoints table and response format docs
2026-01-31 23:33:37 -06:00
Brad Groux
879b095096 v1.3.0: Visibility & Automation (#21, #33, #34)
- Bidirectional GitHub Issues sync (#21)
  - GitHubSyncService with polling, label-based field mapping, circuit breaker
  - Inbound: import issues with 'kanban' label as tasks
  - Outbound: push status changes and comments back to GitHub
  - Config/state persistence, 5 new API endpoints
  - CLI: vk github sync/status/config/mappings
  - TaskGitHub interface added to shared types

- Activity feed view (#33)
  - Full-page chronological feed with day grouping
  - Filter bar: agent, type, date range (combinable)
  - Compact vs detailed view toggle
  - Infinite scroll via IntersectionObserver
  - Real-time WebSocket updates with animation
  - Agent field added to Activity, MAX_ACTIVITIES 1000→5000
  - New ViewContext for board/activity navigation

- Daily standup summary generation (#34)
  - GET /api/summary/standup with date, format params
  - JSON, markdown, and plain text output formats
  - Sections: completed, in-progress, blocked, upcoming, stats
  - CLI: vk summary standup with --yesterday, --date, --json flags
  - 12 new tests for standup logic

Closes #21, closes #33, closes #34
2026-01-31 23:15:08 -06:00
Brad Groux
14fbf33609 fix: unwrap API envelope in shared client (fixes #27) 2026-01-31 12:09:58 -06:00
Brad Groux
d8dab5a612 chore: bump version to v1.1.0 + changelog 2026-01-31 07:09:18 -06:00
Brad Groux
e8e153d037 feat: chat interface backend — storage, API, WebSocket (#18) 2026-01-31 05:58:43 -06:00
Brad Groux
fa7ac0fe1a feat: task-aware agent routing engine (#16)
- Add AgentRoutingConfig types with RoutingRule, RoutingMatchCriteria, RoutingResult
- Add DEFAULT_ROUTING_CONFIG with sensible defaults (code/bug/docs/review rules)
- Create AgentRoutingService with resolveAgent() and getFallback() methods
- First-match-wins rule evaluation with type, priority, project, minSubtasks criteria
- Array support for match criteria (e.g., type: ['code', 'bug'])
- Routing API: POST /agents/route, GET/PUT /agents/routing
- Integrate routing into ClawdbotAgentService.startAgent() for 'auto' agent selection
- Add agent field to Task, CreateTaskInput, UpdateTaskInput, TaskSummary schemas
- Settings UI: routing rules section in Agents tab with add/edit/remove/reorder
- Agent Panel: show routing recommendation when starting agent
- 17 unit tests for routing service (all passing)
- Full typecheck clean across shared, server, and web packages
2026-01-31 05:18:44 -06:00
Brad Groux
adc14a49e7 feat: agent CRUD — add, edit, remove agents from Settings UI 2026-01-29 07:19:54 -06:00
Brad Groux
0c0f5b344d security+quality: final codebase review fixes
Security (critical):
- Remove shell:true from preview-service spawn (command injection fix)
- Replace exec() with execFile() in github-service (no shell interpolation)
- Add SIGKILL fallback after SIGTERM timeout in worktree-service

Stability:
- Add process cleanup handlers (SIGTERM/SIGINT) for preview servers
- Add MAX_PREVIEW_SERVERS=5 limit to prevent resource exhaustion
- Memoize WebSocket context value to prevent unnecessary re-renders

Code quality:
- Remove hardcoded 'Brad' author → 'User' (3 files)
- Replace hardcoded localhost:3001 URLs with API_BASE (AttachmentsSection)
- Fix SECURITY-AUDIT.md date (2025 → 2026)
- Add license/repository/author to all 6 package.json files

Data hygiene:
- Untrack all runtime data files (.veritas-kanban/*.json, telemetry, activity)
- Simplify .gitignore: .veritas-kanban/* except .gitkeep
- Removed ~15,700 lines of runtime data from git history
2026-01-29 06:13:10 -06:00
Brad Groux
3edffec98c chore: bump version to 1.0.0, add CHANGELOG
- Bump all 6 package.json files from 0.1.0 to 1.0.0
- Add CHANGELOG.md with full feature summary
- Git history scrubbed of security.json (JWT secret)
2026-01-29 01:42:04 -06:00
Brad Groux
5d3f75bda6 perf: add pagination and summary mode to reduce API payload 2026-01-28 17:38:04 -06:00
Brad Groux
6793b23310 perf: reduce polling when WebSocket connected 2026-01-28 12:13:48 -06:00
Brad Groux
71200bca36 feat(US-1010): Add daily digest feature
- Add digest service for 24h activity aggregation
- Add GET /api/digest/daily endpoint (JSON and Teams format)
- Add GET /api/digest/daily/preview for testing
- Add scripts/daily-digest.sh for cron scheduling
- Skip empty digests when no activity

Content includes:
- Tasks completed/created/in-progress counts
- Agent runs with success rate by agent
- Token usage by agent
- Top accomplishments (recently done tasks)
- Failed runs and blocked items
2026-01-28 08:08:06 -06:00
Brad Groux
a424d0a7c5 refactor(RF-15): split Board and Settings god components
- Extract useBoardDragDrop hook from KanbanBoard (drag-drop logic)
- Extract BoardLoadingSkeleton component from KanbanBoard
- Extract useSortableList hook from ManagedListManager
- Extract SortableListItem component from ManagedListManager

Line count improvements:
- KanbanBoard.tsx: 329 → 210 lines (-36%)
- ManagedListManager.tsx: 372 → 128 lines (-66%)

All extracted components follow single-responsibility principle.
2026-01-28 07:59:17 -06:00
Brad Groux
22509f1808 feat(web): add Task Metrics Panel (US-1002)
- Created useTaskMetrics hook to fetch and aggregate telemetry events for a task
- Built TaskMetricsPanel component with:
  - Summary cards for total runs, success rate, duration, tokens, cost
  - Last run status display
  - Expandable per-attempt breakdown with full details
- Integrated as new 'Metrics' tab in TaskDetailPanel
- Fetches via GET /api/telemetry/events/task/:taskId endpoint
2026-01-28 07:55:48 -06:00
Brad Groux
38ec9a99ce feat(telemetry): Add POST /api/telemetry/events endpoint (US-1401)
- Add POST endpoint for ingesting run telemetry events
  - Accepts: run.started, run.completed, run.error, run.tokens
  - Zod validation with discriminated union schema
  - Stores events in date-partitioned NDJSON files
  - Returns 201 with generated id and timestamp

- Add WebSocket broadcast for telemetry events
  - New broadcastTelemetryEvent() in broadcast-service
  - Emits 'telemetry:event' messages to connected clients

- Update shared telemetry types for flexibility
  - RunStartedEvent, RunCompletedEvent, RunErrorEvent types
  - TokenTelemetryEvent with optional cacheTokens and cost fields
  - Change agent field from AgentType to string for external sources

- Update metrics-service to handle optional totalTokens
  - Calculate totalTokens from input+output when not provided
2026-01-28 07:40:35 -06:00
Brad Groux
cb87b2df52 feat(sprint-1500): status refactor review→blocked + blocked reason tracking
- Rename TaskStatus.review to TaskStatus.blocked across codebase
- Add migration service (auto-converts on startup, idempotent)
- Add blocked reason tracking (category + notes)
- Add blocked badges on Kanban cards
- Add dashboard breakdown by blocked category
- Add 30d metrics period, per-agent breakdown, streaming NDJSON
- Add 8 migration tests, all 112 tests passing
- Fix attachment test regex to allow hyphens in IDs

US-1501, US-1502, US-1503, US-1504, US-1505, US-1506, US-1507, US-1403
2026-01-28 07:30:05 -06:00
Brad Groux
3c2eb55ca8 US-1501: Rename TaskStatus review → blocked in shared types
- Updated TaskStatus union from 'review' to 'blocked' in shared/src/types/task.types.ts
- Updated Zod enum in server/src/routes/tasks.ts
- ReviewComment and ReviewState interfaces unchanged (still valid for code review)
2026-01-28 06:47:57 -06:00
Brad Groux
75cee87a3d fix: browser compatibility for shared api-client
- Add typeof check for process.env to avoid ReferenceError in browser
- process.env only exists in Node.js, not browser environments
- Fixes white screen issue when loading web frontend
2026-01-28 06:22:29 -06:00
Brad Groux
39eccf3556 feat: Sprint US-1200 Refactoring batch — 13 tasks complete
Completed refactors:
- RF-02: Fix dependency vulnerabilities (xlsx → exceljs, Hono updates)
- RF-05: Add React error boundaries (FeatureErrorBoundary wrapper)
- RF-06: Server error handling middleware (AppError classes, asyncHandler)
- RF-10: Split shared types.ts into domain modules (6 files)
- RF-11: Consolidate frontend API layer (hooks now use api.ts)
- RF-13: TaskConfigContext — eliminate prop drilling
- RF-14: Split god components (GitSection, TaskDetailPanel, CreateTaskDialog, DiffViewer)
- RF-16: Frontend accessibility (ARIA labels, sr-only text)
- RF-17: Modularize CLI (899 → commands/ structure)
- RF-18: Modularize MCP (843 → tools/ structure)
- RF-19: Create shared API client library
- RF-21: Server performance (batch loading, memory limits, timeouts, graceful shutdown)
- RF-23: Extract shared utilities (path, format, constants)

Stats: ~59 files changed, significant code reduction through modularization
2026-01-28 06:08:59 -06:00
Brad Groux
f0c72717d3 feat(US-1101, US-1102): settings infrastructure + feature toggle hooks
- Added FeatureSettings types (Board, Tasks, Agents, Telemetry, Notifications, Archive)
- AppConfig.features field with backward-compatible defaults
- ConfigService auto-merges defaults for missing keys on load
- Deep merge utility for partial config updates
- GET/PATCH /api/settings/features endpoints
- useFeatureSettings, useFeatureSetting, useUpdateFeatureSettings hooks
- Debounced update helper for rapid toggle changes
- Optimistic updates with rollback on error
2026-01-28 02:16:23 -06:00
Brad Groux
ce5eda58b1 feat: add drag-and-drop task reordering within columns
- Add position field to Task type (shared/types.ts)
- Add POST /api/tasks/reorder endpoint to persist ordering
- Update task-service with reorderTasks() method
- Switch TaskCard from useDraggable to useSortable (@dnd-kit/sortable)
- Wrap KanbanColumn tasks in SortableContext with verticalListSortingStrategy
- Update KanbanBoard DnD handlers to support both within-column reorder
  and cross-column status changes
- Sort tasks by position in useTasksByStatus hook
- Use closestCorners collision detection for better sortable support

Fixes: task_20260128_4qCzGr
2026-01-28 01:08:21 -06:00
Brad Groux
2b5d07c1f1 Convert hardcoded sprints to managed list
- Added SprintConfig interface extending ManagedListItem in shared types
- Created SprintService with seed migration from existing tasks
- Added /api/sprints endpoints using managed list router pattern
- Implemented useSprints and useSprintsManager hooks
- Updated TaskDetailPanel and CreateTaskDialog to use dynamic sprint list
- Added sprint management UI to SettingsDialog
- Sprint IDs match existing task.sprint values for backward compatibility
- Reference counter prevents deletion of sprints with tasks
2026-01-28 00:29:16 -06:00
Brad Groux
331fd966a8 refactor: remove tags feature entirely, fix TS errors and path traversal sanitization
- Removed tag-service, TagPicker, useTags hook, tags routes, tags.json
- Stripped tag references from TaskCard, TaskDetailPanel, CreateTaskDialog,
  ApplyTemplateDialog, SettingsDialog, ArchiveSidebar, KanbanBoard/Column
- Removed tags from shared Task type and template types
- Fixed ManagedListManager prop types (Promise<void> → Promise<any>)
- Fixed unused imports in FilterBar, CreateTaskDialog, TaskDetailPanel
- Fixed unused generic param in UseManagedListOptions
- Fixed path traversal in attachment filename sanitization (collapse ..)
- All tests passing (62/62), full build clean
2026-01-27 23:33:15 -06:00