Siddharth Kumar Sah
ab370a74fe
feat(api): add teams CRUD routes and update auth team references
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
62fbb5484c
feat: implement Files page with persistent storage and version tracking
...
Three-panel file manager (nav, list, details) modeled after Stirling-PDF.
- Backend: user_files table, /api/v1/files/* CRUD routes, file storage
helpers, thumbnail generation via Sharp, recursive CTE version chains
- Frontend: FilesNav, FileList, FileDetails, FileUploadArea components,
Zustand store, mobile layout with bottom sheet
- Integration: tool-factory auto-saves results as new versions when
fileId is provided, "Open File" loads file into tool processing flow
- Search, bulk select/delete/download, version badges, tool chain tags
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
926b52d330
feat(db): add teams table and migration
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
dda37e90cc
feat(db): add userFiles table and migration
...
Introduces the user_files table to track uploaded files per user,
including metadata fields for dimensions, versioning, and tool chains.
2026-03-26 01:10:50 +08:00
Siddharth Kumar Sah
432cc92471
feat: harden auth, security headers, SVG sanitization, and pipeline ownership
...
- Add password strength validation (8+ chars, uppercase, lowercase, number)
- Add username validation rules
- Optimize API key lookup with SHA-256 prefix (O(1) vs O(n) scan)
- Require password change on default admin first login
- Revoke API keys on password change
- Add session cleanup cron (hourly expired session purge)
- Add Permissions-Policy, HSTS, and CSP security headers in production
- Strengthen SVG sanitizer: block XInclude, foreignObject, processing
instructions, javascript/data/file URI schemes
- Add userId ownership to pipelines with authorization checks
- Add keyPrefix column to api_keys table
- Update integration tests for new auth behavior
2026-03-24 21:38:06 +08:00
Siddharth Kumar Sah
263447a81e
feat(api): add pipeline execution, save, and list endpoints
...
Add pipelines table to SQLite schema with Drizzle migration.
Implement POST /api/v1/pipeline/execute (sequential multi-tool processing),
POST /api/v1/pipeline/save, GET /api/v1/pipeline/list,
DELETE /api/v1/pipeline/:id. Pipeline execution validates all tool IDs
and settings before processing, chains output of each step as input
to the next.
2026-03-22 04:41:51 +08:00
Siddharth Kumar Sah
a24c6dd014
feat: add SQLite database with Drizzle ORM schema and migrations
2026-03-22 02:51:57 +08:00