SnapOtter
fda4e25296
test(oidc): add integration tests for OIDC auth flow
...
Covers session response fields, password guards, users list,
config endpoint, login redirect, callback edge cases, and
backward compatibility. Also adds migration to make password_hash
nullable (required for OIDC-only users) and vitest aliases for
@fastify/cookie and openid-client.
2026-05-13 19:14:34 +08:00
SnapOtter
877475d1c9
feat(oidc): add OIDC columns to users and sessions tables
2026-05-13 18:47:54 +08:00
SnapOtter
16af9c573a
feat: remove app name and logo customization feature
...
Users can no longer customize the app name or logo. The branding API
endpoints, permission, frontend UI, env vars (APP_NAME, MAX_LOGO_SIZE_KB),
and all related tests are removed. Includes a migration to clean up
branding data from existing databases.
2026-05-07 19:41:30 +08:00
ashim-hq
c2130148c4
fix: add statement-breakpoint separators to analytics migration
2026-04-22 19:15:38 +08:00
ashim-hq
4904e8d140
feat: add analytics env vars, DB schema columns, instance ID generation
2026-04-22 19:00:15 +08:00
Ashim and GitHub
5a45bcbc8f
feat: production-grade RBAC with editor role, custom roles, API key scoping, and audit log ( #89 )
...
* feat(rbac): add editor role, 3 new permissions, ownership helper
* feat(rbac): add audit_log table, apiKeys.permissions column, editor role to schema
* feat(rbac): wire requirePermission into all routes, add editor role support
* refactor(rbac): replace ad-hoc role checks with permission-based ownership
* feat(rbac): add audit log DB writes + query endpoint
Dual-write audit events to stdout (existing) and SQLite audit_log table.
Add GET /api/v1/audit-log with pagination, action filter, and date range
filtering, gated behind audit:read permission.
* feat(rbac): add API key permission scoping with ceiling enforcement
* feat(rbac): add escalation prevention and last-admin protection
* feat(rbac): add editor role to UI, API key permission scoping in settings
* test(rbac): add full permission matrix integration test
* test(rbac): add editor role E2E tests
* feat(rbac): add custom roles with CRUD API and DB-backed permission lookup
* feat(rbac): add API key expiration
* feat(rbac): add roles management UI and API key expiration to settings
* feat(rbac): add audit log UI to settings
* fix: remove any cast in API key permission validation
* test(rbac): add unit tests for username validation rules
* test(rbac): add unit tests for effective permissions and ownership
* test(rbac): add comprehensive route permission matrix (all routes × all roles)
* test(rbac): add auth route edge case tests (login failures, session expiry, password side effects)
* test(rbac): add escalation prevention tests (register, update, self-demote, last-admin)
* test(rbac): add ownership enforcement tests (files, pipelines, editor access, cross-user isolation)
* test(rbac): add API key edge cases (name validation, delete behavior, key revocation)
* test(rbac): add audit log edge cases (all events, pagination clamping, structure)
* test(rbac): add custom roles edge case tests (validation, CRUD, functional permissions)
* test(rbac): add comprehensive E2E tests (roles UI, audit log, custom role, API key scoping)
2026-04-22 18:10:04 +08:00
Siddharth Kumar Sah
ab370a74fe
feat(api): add teams CRUD routes and update auth team references
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
62fbb5484c
feat: implement Files page with persistent storage and version tracking
...
Three-panel file manager (nav, list, details) modeled after Stirling-PDF.
- Backend: user_files table, /api/v1/files/* CRUD routes, file storage
helpers, thumbnail generation via Sharp, recursive CTE version chains
- Frontend: FilesNav, FileList, FileDetails, FileUploadArea components,
Zustand store, mobile layout with bottom sheet
- Integration: tool-factory auto-saves results as new versions when
fileId is provided, "Open File" loads file into tool processing flow
- Search, bulk select/delete/download, version badges, tool chain tags
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
926b52d330
feat(db): add teams table and migration
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
dda37e90cc
feat(db): add userFiles table and migration
...
Introduces the user_files table to track uploaded files per user,
including metadata fields for dimensions, versioning, and tool chains.
2026-03-26 01:10:50 +08:00
Siddharth Kumar Sah
432cc92471
feat: harden auth, security headers, SVG sanitization, and pipeline ownership
...
- Add password strength validation (8+ chars, uppercase, lowercase, number)
- Add username validation rules
- Optimize API key lookup with SHA-256 prefix (O(1) vs O(n) scan)
- Require password change on default admin first login
- Revoke API keys on password change
- Add session cleanup cron (hourly expired session purge)
- Add Permissions-Policy, HSTS, and CSP security headers in production
- Strengthen SVG sanitizer: block XInclude, foreignObject, processing
instructions, javascript/data/file URI schemes
- Add userId ownership to pipelines with authorization checks
- Add keyPrefix column to api_keys table
- Update integration tests for new auth behavior
2026-03-24 21:38:06 +08:00
Siddharth Kumar Sah
263447a81e
feat(api): add pipeline execution, save, and list endpoints
...
Add pipelines table to SQLite schema with Drizzle migration.
Implement POST /api/v1/pipeline/execute (sequential multi-tool processing),
POST /api/v1/pipeline/save, GET /api/v1/pipeline/list,
DELETE /api/v1/pipeline/:id. Pipeline execution validates all tool IDs
and settings before processing, chains output of each step as input
to the next.
2026-03-22 04:41:51 +08:00
Siddharth Kumar Sah
a24c6dd014
feat: add SQLite database with Drizzle ORM schema and migrations
2026-03-22 02:51:57 +08:00