bot-hermes
1059512888
feat: add server error logging and tighten workspace isolation
2026-08-10 12:41:46 +00:00
bot-hermes
a60b75f075
feat: full plan execution - CI/CD, critical fixes, UX polish, secondary/advanced features, E2E + docs
...
Phase 0 (CI/CD): fix root typecheck to cover api+worker+web; reconcile migration
story into idempotent db:migrate (db:sync + db:triggers); add Gitea Actions
quality/deploy/smoke workflow; rewrite README/AGENTS/DEPLOY docs; add
requireWorkspaceAccess + recordActivityForEntity conventions.
Phase 1 (critical fixes): calendar delete + drag/resize DnD; canvas card CRUD +
bulk save + debounced autosave; logout route; graph edge workspaceId derivation;
real analytics endpoints (drop Math.random); task board droppable columns +
reorder persistence; Tiptap notes editor with sanitized HTML rendering; remove
insecure passkey auth; domain/owner scoping (IDOR) on all by-ID routes + search/
export/realtime scoping; command palette routing + agent mention fetch; agent
activity SSE handler; graph fly-to with tracked positions.
Phase 2 (UX polish): login on design system; Sonner toasts app-wide; shared
Loading/Empty/Error state components; working density/sidebarPos/reduce-motion
settings; Inter typography; consolidated status-colors lib; unified detail
routes; dashboard sort/realtime/responsive fixes; mobile responsive; a11y
(radiogroups, sanitized snippets, badge labels).
Phase 3 (features): daily notes timezone fix + delete + autosave + mood/energy
create; active-domain store + topbar picker; graph domain picker + navigable
entity links; tag assign/remove UI + server-side tag filter; real CSV export +
import validation; custom fields on tasks.
Phase 4 (advanced): migrate job worker into apps/worker (webhook delivery with
HMAC, recurring spawn, ai_dispatch disabled); webhook queue helper + entity
event enqueuing + test endpoint fix; recurring scheduledJobs pipeline; agents
CRUD + permission editing + activity filters; real notifications feed; MCP
polish (validation, error codes, domain scoping, dead sql leftover).
Phase 5 (E2E + docs): rewrite Playwright suite for the Vite SPA (15 specs, new
auth helpers, chromium-only in CI); add ephemeral-Postgres e2e CI job; rewrite
docs/API.md for the real Hono API.
2026-08-10 08:53:18 +00:00
Hermes
118617c892
fix: MCP endpoint at /api/mcp (Bug #2 ) + REST API key auth (Bug #3 )
...
Bug #2 (LOW): MCP endpoint was mounted at /mcp instead of /api/mcp,
inconsistent with all other API routes. Changed app.route("/mcp", ...)
to app.route("/api/mcp", ...) in apps/api/src/index.ts.
Bug #3 (MEDIUM): REST API endpoints only accepted JWT cookie/session
auth, not API key auth. Added authenticateApiKey() to authMiddleware
in apps/api/src/middleware/auth.ts so REST endpoints now accept
Authorization: Bearer <api_key> as a fallback after JWT verification.
2026-08-01 11:33:12 +00:00
Hermes
c1c95f727a
T4/Phase 2C-1: port search routes to Hono (3 routes) + new DB tables
2026-08-01 01:47:25 +00:00
Hermes
23d2a96dd1
T3/Phase 2B-4: port notes routes to Hono (~7 routes) + wikilink service + route registration
2026-08-01 01:38:25 +00:00
Hermes
e4a241b38f
T2/Phase 2A: port auth + infrastructure routes to Hono (~8 routes)
...
- /api/health: DB ping + version + uptime
- /api/auth/*: NextAuth -> Auth.js standalone (credentials + passkey)
- /api/domains: full CRUD
- /api/realtime: SSE with PostgreSQL LISTEN/NOTIFY
- /mcp: JSON-RPC 2.0 (initialize, tools/list, tools/call, resources/*)
Parent: t_e1cbd87d -> t_d8654a91 (T1)
2026-08-01 01:25:01 +00:00
Hermes
fca56ab77e
T1/Phase 1: scaffold Vite SPA + Hono API + Bun worker
...
- apps/web: Vite + React 19 + TanStack Router/Query + shadcn/ui
- apps/api: Hono + Bun on :3001 with /api/health, /api/auth/*, /mcp stubs
- apps/worker: Bun worker stub, DB connection, graceful SIGTERM
- apps/web-legacy/: old Next.js code moved aside (preserved for T2-T8 reference)
- Dockerfiles: api (Bun), worker (Bun), spa (multi-stage Caddy)
- Caddyfile: serves dist + reverse-proxies /api/* + /mcp to api
- docker-compose.yml: 4-service target (api, spa, db, worker)
- packages/db/src/client.ts: shared Drizzle client for api + worker
- db/client.ts: root-level alias for convenience
Parent: t_e1cbd87d -> t_24c9c3fd (T0)
2026-08-01 01:15:31 +00:00