Ashim and GitHub
5a45bcbc8f
feat: production-grade RBAC with editor role, custom roles, API key scoping, and audit log ( #89 )
...
* feat(rbac): add editor role, 3 new permissions, ownership helper
* feat(rbac): add audit_log table, apiKeys.permissions column, editor role to schema
* feat(rbac): wire requirePermission into all routes, add editor role support
* refactor(rbac): replace ad-hoc role checks with permission-based ownership
* feat(rbac): add audit log DB writes + query endpoint
Dual-write audit events to stdout (existing) and SQLite audit_log table.
Add GET /api/v1/audit-log with pagination, action filter, and date range
filtering, gated behind audit:read permission.
* feat(rbac): add API key permission scoping with ceiling enforcement
* feat(rbac): add escalation prevention and last-admin protection
* feat(rbac): add editor role to UI, API key permission scoping in settings
* test(rbac): add full permission matrix integration test
* test(rbac): add editor role E2E tests
* feat(rbac): add custom roles with CRUD API and DB-backed permission lookup
* feat(rbac): add API key expiration
* feat(rbac): add roles management UI and API key expiration to settings
* feat(rbac): add audit log UI to settings
* fix: remove any cast in API key permission validation
* test(rbac): add unit tests for username validation rules
* test(rbac): add unit tests for effective permissions and ownership
* test(rbac): add comprehensive route permission matrix (all routes × all roles)
* test(rbac): add auth route edge case tests (login failures, session expiry, password side effects)
* test(rbac): add escalation prevention tests (register, update, self-demote, last-admin)
* test(rbac): add ownership enforcement tests (files, pipelines, editor access, cross-user isolation)
* test(rbac): add API key edge cases (name validation, delete behavior, key revocation)
* test(rbac): add audit log edge cases (all events, pagination clamping, structure)
* test(rbac): add custom roles edge case tests (validation, CRUD, functional permissions)
* test(rbac): add comprehensive E2E tests (roles UI, audit log, custom role, API key scoping)
2026-04-22 18:10:04 +08:00
Siddharth Kumar Sah
432cc92471
feat: harden auth, security headers, SVG sanitization, and pipeline ownership
...
- Add password strength validation (8+ chars, uppercase, lowercase, number)
- Add username validation rules
- Optimize API key lookup with SHA-256 prefix (O(1) vs O(n) scan)
- Require password change on default admin first login
- Revoke API keys on password change
- Add session cleanup cron (hourly expired session purge)
- Add Permissions-Policy, HSTS, and CSP security headers in production
- Strengthen SVG sanitizer: block XInclude, foreignObject, processing
instructions, javascript/data/file URI schemes
- Add userId ownership to pipelines with authorization checks
- Add keyPrefix column to api_keys table
- Update integration tests for new auth behavior
2026-03-24 21:38:06 +08:00
Siddharth Kumar Sah
263447a81e
feat(api): add pipeline execution, save, and list endpoints
...
Add pipelines table to SQLite schema with Drizzle migration.
Implement POST /api/v1/pipeline/execute (sequential multi-tool processing),
POST /api/v1/pipeline/save, GET /api/v1/pipeline/list,
DELETE /api/v1/pipeline/:id. Pipeline execution validates all tool IDs
and settings before processing, chains output of each step as input
to the next.
2026-03-22 04:41:51 +08:00