Commit Graph
31 Commits
Author SHA1 Message Date
bruno 36a4030c09 securite: #87 T5a supprime 16 handlers inline au profit de listeners (CSP inchangee) 2026-09-26 22:32:01 -04:00
bruno 94ea5909f4 fix(forge): le parent quitte aussi le plein ecran avant l'assistant IA (BUG-056)
CI / lint (push) Successful in 1m34s
CI / security (push) Successful in 1m1s
CI / test (push) Successful in 2m11s
CI / build (push) Successful in 57s
CI / e2e (push) Successful in 10m50s
2026-09-17 09:19:06 -04:00
bruno 3131277b19 feat(forge): assistant IA partage et plein ecran Forge/Editer (#101)
CI / lint (push) Successful in 1m33s
CI / security (push) Successful in 1m1s
CI / test (push) Successful in 2m50s
CI / build (push) Successful in 1m6s
CI / e2e (push) Successful in 10m48s
2026-09-17 08:30:32 -04:00
bruno 788d84a2bf fix(editeur): #93 garde-fous de session d'edition inline (onglets, ecriture externe) + hooks de versionnage documentes
CI / lint (push) Successful in 1m27s
CI / security (push) Successful in 57s
CI / test (push) Successful in 2m52s
CI / build (push) Successful in 53s
CI / e2e (push) Successful in 10m45s
Une session d'edition inline (Editer/Forge) qui possede la zone de contenu etait detruite par deux chemins qui vident cette zone : activation d'onglet (TabManager.activate, PaneTabManager.activate) -> detachInlineEditor() avant le placeholder ; evenement SSE index_updated -> reloadExternalWrite() recharge le tampon de l'editeur au lieu de re-rendre la vue lecture. Nouveau helper queryEditor() ; closeEditor() remet le conteneur dans la modale avant de restaurer en-tete/pied/marque. docs/CONTRIBUTING.md documente scripts/install-hooks.sh.
2026-09-16 11:43:41 -04:00
bruno e3df4bbf00 feat(editeur): #93 edition inline — Editer/Forge remplacent la vue lecture
CI / lint (push) Successful in 1m26s
CI / security (push) Successful in 1m0s
CI / test (push) Successful in 3m17s
CI / build (push) Successful in 56s
CI / e2e (push) Successful in 10m47s
Le conteneur d'edition (#editor-container, CodeMirror ou iframe Forge) est deplace dans la zone de contenu du document (#content-area ou pane active) au lieu de l'overlay plein ecran : le mode edition remplace la vue lecture. L'overlay reste monte (transparent, pointer-events: none) car le ruban d'edition mobile y est ancre ; il ne sert plus que de repli quand la cible n'est pas le document affiche. Garde-fou dans renderFile() pour liberer proprement la session (destroy CodeMirror/Yjs, retrait de l'iframe Forge) ; forge-close passe par closeEditor() ; cache d'onglet invalide au retour en lecture.

Assistant IA : app_context.editing annonce le document en cours d'edition (frontend bookslm.js + backend bookslm.py), et chaque ecriture d'outil (edit_file, append_to_file, create_file, restore_backup) recharge le document affiche (obsigate:file-written) — tampon CodeMirror remplace avec auto-save neutralisee, parent-reload pour l'iframe Forge, re-rendu de la vue lecture sinon.

Tests : tests/frontend/editor-inline.test.mjs (19), tests/test_bookslm.py::TestGeneralPrompt (3 nouveaux). Fiche : docs/features/editeur-inline.md.
2026-09-15 23:40:10 -04:00
bruno 162a5b4acc fix(security): consolidation & securite phase 1 (#84, BUG-021 a BUG-034)
CI / lint (push) Successful in 1m20s
CI / security (push) Successful in 47s
CI / test (push) Successful in 2m21s
CI / build (push) Successful in 43s
CI / e2e (push) Successful in 10m48s
- sanitizer XSS serveur (markdown + page de partage) [BUG-021/022]
- rate-limit/lockout MFA [BUG-023]
- isolation vaults par segments [BUG-024]
- caps regex ReDoS [BUG-025]
- SSRF webhooks + secrets externalises [BUG-026]
- rotation/revocation des jetons [BUG-027]
- politique de mot de passe + invalidation sessions [BUG-028]
- verrous users.json [BUG-029]
- IP reelle dans les audits [BUG-030]
- rate-limit par compte [BUG-031]
- symlinks hors vault ignores [BUG-032]
- recherche simple via inverted index [BUG-033]
- token en memoire + cookie HttpOnly, CSP durcie [BUG-034]

Tests: pytest 961 passed / 6 skipped, ruff 0, mypy 0, frontend vert.
2026-09-13 10:51:42 -04:00
bruno 7cf7d33b6d fix(pwa): BUG-005 chargement mobile via Cloudflare (SW network-first + no-cache)
CI / lint (push) Successful in 58s
CI / security (push) Successful in 40s
CI / test (push) Successful in 1m19s
CI / build (push) Successful in 37s
CI / e2e (push) Successful in 10m53s
Desktop Build / build-windows (push) Canceled after 0s
Desktop Build / build-linux (push) Canceled after 0s
2026-09-11 17:13:16 -04:00
bruno c3c5f11e9b Move sidebar and offline imports to lazy loading
CI / lint (push) Failing after 21s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after 10s
2026-07-20 22:31:07 -04:00
bruno 790f97e501 Replace hardcoded French strings with i18n calls
CI / lint (push) Failing after 1m28s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after 17s
Initialize i18n before auth so t() works when rendering
auth-dependent UI, and build the command palette lazily so
translations are loaded first. Bump service worker cache version.
2026-07-20 20:16:34 -04:00
bruno 48023620e6 i18n: complete remaining roadmap tasks
CI / lint (push) Failing after 19s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after 11s
JS files:
- ai.js: add t() import, replace 10 hardcoded French strings
- sync.js: add t() import, replace 20 hardcoded French strings (toasts, status labels, events, AI panel)
- graph.js: add t() import, replace 6 hardcoded French strings (tooltips, badges)

Locales:
- +36 new keys for ai.js, sync.js, graph.js
- 1206 keys in each locale file (perfectly synchronized)
- 0 French characters remaining in en.json

Documentation:
- README.fr.md created (French version)
- ROADMAP.md point #63 updated to 100% complete
2026-06-19 10:37:00 -04:00
bruno 659c227e6a i18n: complete audit — 55 new keys, all hardcoded strings converted to t()
CI / lint (push) Failing after 22s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after 9s
- Added 4 missing keys: button.cancel, toast.dir_renamed, toast.file_deleted, toast.file_renamed
- Replaced 41 hardcoded showToast() strings with t() calls across 13 JS files
- Replaced 10 hardcoded textContent/title/innerHTML strings with t() calls
- Fixed theme labels: Sombre/Clair -> t('theme.dark')/t('theme.light')
- Fixed vault selector: Tous les vaults -> t('help.all_vaults')
- Both locale files: 983 -> 1032 keys, perfectly matched
- Bidirectional EN<->FR switching verified in browser
2026-06-18 22:49:19 -04:00
bruno daab917ed1 Add autocomplete status check and restructure test environments
CI / lint (push) Failing after 26s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after 10s
Add Ollama autocomplete status endpoint to AI routes, update sync panel
UI to display autocomplete state, replace monolithic test compose files
with separate Linux/Windows variants, and add PowerShell build script
for Windows deployment
2026-06-18 09:40:09 -04:00
bruno 36c1546098 fix: header Forge — affiche Forge + titre/fichier, restaure ObsiGate a la fermeture
CI / lint (push) Failing after 10s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after -7s
2026-06-16 10:13:19 -04:00
bruno 66039028a5 feat: panneau A propos elegant + retrait Editor POC
CI / lint (push) Failing after 2s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after -8s
- Remplace Editor POC par A propos (sparkles) dans le menu header
- Modale About avec animation fade+scale, logo SVG, hero gradient
- Stats live: fichiers, vaults (API /health), tests (285)
- Stack techno: 12 badges (FastAPI, vanilla JS, Docker, etc.)
- Footer: date livraison, blague aleatoire (10 variantes humour)
- Touche d'humour: git push --force accidentels, CSS > backend
- Fermeture: bouton X, clic overlay, Escape
- initAboutModal dans sync.js + config.js export
2026-06-16 07:37:39 -04:00
bruno d1841a057d feat: #65 systeme de themes — 15 themes x dark/light
CI / lint (push) Failing after 2s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after -8s
- themes.js: 15 palettes (Defaut ObsiGate, GitHub, Linear, Spotify, Notion,
  Discord, Dracula, One Dark, Tokyo Night, Nord, Night Owl, Anthracite,
  Cyberpunk, Navy Elegance, Tons Terreux)
- Chaque theme a un mode sombre ET clair
- UI: grille de themes dans Configuration → Themes
- Toggle Sombre/Clair par theme
- Persistance localStorage (obsigate-theme + obsigate-theme-mode)
- Preview visuel: barre de couleur + accent bouton
- initThemes() appele au startup dans sync.js
- Defaut ObsiGate conserve le theme actuel
2026-06-15 23:20:35 -04:00
bruno feeb46b873 feat: finalisation éditeur Forge + mode hors-ligne PWA + consolidation roadmap
CI / lint (push) Failing after 7s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / security (push) Failing after -7s
- Forge: Tab indent, Ctrl+K, auto-focus, AI status, messages erreur FR
- Forge: slash commands clean, cache-bust iframe, preview serveur
- Forge: iframe 82vh, hauteur auto, table inline, sélecteur langage
- PWA hors-ligne: IndexedDB (offline-db.js + offline.js)
- Mermaid: thème dark complet, highlight.js preview
- Backend: màj CSP, rename chain, bookmarks/history/shares
- Roadmap: consolidation dans docs/ROADMAP.md (75 items)
- Infra: docker-compose.podman.yml, suppression test-vault
- .gitignore: exclusion odysseus/
2026-06-14 20:27:37 -04:00
bruno fc1a4e336e fix: vault home recursive + backup viewer fixes + AI status at startup
CI / security (push) Failing after 10m56s
CI / lint (push) Failing after 11m14s
CI / test (push) Has been cancelled
CI / build (push) Has been cancelled
- Vault home (#12): recursive file listing (rglob), rel_dir in metadata,
  'recursif' badge, updated roadmap description
- Backup viewer: fix close button (inline onclick + event delegation
  fallback for text nodes), improve error messages
- Backup API: remove response_model to prevent Pydantic 500 errors,
  add try/except + logging on backups/diff/restore endpoints,
  per-entry error handling in _list_backup_files,
  encoding safety (errors='replace') on read_text
- AI status: call /api/ai/status at startup in _initAIStatus
  instead of waiting for user click on sync badge
2026-06-04 09:28:57 -04:00
bruno b077c24bf1 fix: corrections UI — indicateur voute, couleurs, statut IA, spinner éditeur
CI / lint (push) Failing after 6s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / security (push) Successful in 11s
1. Suppression du badge vault-context-pill doublon en mobile
2. Couleurs dynamiques indicateur header:
   - Bleu pour 'All' (.vault-ctx-all)
   - Mauve/violet pour les vaults (.vault-ctx-vault)
   - Jaune/ambre pour les répertoires (.vault-ctx-dir)
3. Statut IA: vérifie la présence du toolbar AI dans le DOM
   au lieu d'appeler /api/ai/status (qui ne fonctionnait pas)
4. Indicateur de traitement AI dans l'éditeur (spinner + badge
   'AI...' dans le header de l'editor modal) au lieu du flash
   blanc sur le badge sync
2026-06-04 08:31:32 -04:00
bruno 90dffdf26c fix: indicateur voute visible en mobile + debug log statut IA
CI / lint (push) Failing after 18s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / security (push) Successful in 10s
- Indicateur de contexte de voute (#vault-context-indicator) n'est plus
  caché en mobile (display: none retiré), conserve le même look que desktop
- Ajout console.log temporaire dans _checkAIStatus() pour déboguer
  pourquoi l'API /api/ai/status retourne configured:false
2026-06-04 08:11:08 -04:00
bruno 873c7a572f fix: statut IA — suppression endpoint redondant + lecture runtime des clés API
CI / lint (push) Failing after 4s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / security (push) Successful in 8s
Problème: l'indicateur affichait 'IA non configurée' alors que les
actions AI fonctionnaient.

Causes:
1. Deux endpoints /api/ai/status en conflit (main.py + ai_routes.py)
2. ai_routes.py lisait PROVIDERS évalué à l'import (os.getenv figé)
3. Cache côté frontend (_aiStatusChecked) empêchait de re-vérifier

Fixes:
- Suppression de l'endpoint redondant dans main.py
- ai_routes.py: lecture os.getenv au runtime (pas depuis PROVIDERS)
- sync.js: _checkAIStatus() appelée à chaque ouverture du panneau
2026-06-04 07:55:42 -04:00
bruno 6700b78004 fix: import manquant openFile dans sync.js (ReferenceError)
CI / lint (push) Failing after 4s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / security (push) Successful in 8s
sync.js appelait openFile() après un index update SSE mais la fonction
n'était pas importée depuis viewer.js. Ajout de l'import manquant.
2026-06-04 07:36:52 -04:00
bruno 7a4b3d1329 feat: points 11a + 11b — Indicateur AI Actif & Page d'accueil voute
CI / lint (push) Failing after 4s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / security (push) Successful in 8s
Point 11a — Indicateur AI Actif:
- Badge sync flashe en blanc pendant traitement AI (animation CSS)
- Événements ai-processing-start/end dans ai.js
- Section statut IA dans panneau sync (configurée/non configurée/en cours)
- Endpoint GET /api/ai/status vérifiant les clés API configurées

Point 11b — Page d'accueil de voute:
- Endpoint GET /api/vault/{vault}/files?dir=... (trié par mtime)
- Module vaulthome.js: affichage style résultats de recherche
- Breadcrumb navigable, mise à jour auto sur clic dossier dans tree
- Déclenché auto quand un vault spécifique est sélectionné
2026-06-03 22:36:31 -04:00
bruno 4748a75687 fix: initDashboardTabs non exporté de sync.js → importé dans viewer.js
CI / lint (push) Successful in 12s
CI / security (push) Successful in 7s
CI / test (push) Successful in 15s
CI / build (push) Successful in 2s
2026-05-29 11:39:31 -04:00
bruno 876c6c8de0 fix: repair corrupted sync.js import line
CI / lint (push) Successful in 12s
CI / security (push) Successful in 8s
CI / test (push) Successful in 16s
CI / build (push) Successful in 2s
2026-05-29 08:17:48 -04:00
bruno 4418c725f8 fix: export refreshSidebarTreePreservingState, loadRecentFiles; add imports sync.js, config.js
CI / lint (push) Successful in 12s
CI / security (push) Successful in 17s
CI / test (push) Successful in 15s
CI / build (push) Successful in 2s
2026-05-29 08:11:44 -04:00
bruno 148b3851ae fix: add missing state. prefix to all bare state variable references across all modules
CI / lint (push) Successful in 15s
CI / security (push) Successful in 8s
CI / test (push) Successful in 16s
CI / build (push) Successful in 2s
2026-05-28 18:33:39 -04:00
bruno a2ff9297ce fix: strip line number prefixes from all JS files
CI / lint (push) Successful in 13s
CI / security (push) Successful in 8s
CI / test (push) Successful in 18s
CI / build (push) Successful in 2s
2026-05-28 16:46:17 -04:00
bruno deadf1e1ea fix: repair broken import blocks in sync.js and legacy.js
CI / lint (push) Successful in 12s
CI / security (push) Successful in 13s
CI / test (push) Successful in 19s
CI / build (push) Successful in 3s
2026-05-28 16:41:15 -04:00
bruno 643a73e0f5 fix: strip read_file line numbers accidentally injected into JS files
CI / lint (push) Successful in 13s
CI / security (push) Successful in 8s
CI / test (push) Successful in 16s
CI / build (push) Successful in 3s
2026-05-28 16:40:14 -04:00
bruno 7866f93778 refactor: state.js → mutable object to fix 'assignment to constant' errors
CI / lint (push) Successful in 13s
CI / security (push) Successful in 8s
CI / test (push) Successful in 16s
CI / build (push) Successful in 6s
ES module imports are read-only live bindings — can't reassign
imported let/const variables. Replace individual 'export let' with
single 'export const state = {...}' mutable object.

All modules updated: import { state } from './state.js'
All state access changed to state.xxx pattern.

Fixes cascade of 'Assignment to constant variable' errors.
2026-05-28 16:34:39 -04:00
bruno 4836d6f1d0 refactor: split app.js (8875 lines) into 12 ES modules
CI / lint (push) Successful in 10s
CI / security (push) Successful in 8s
CI / build (push) Has been cancelled
CI / test (push) Has been cancelled
frontend/js/ structure:
  state.js      (55 lines)  — Shared mutable state, constants
  utils.js      (510 lines) — EXT_ICONS, getFileIcon, escapeHtml, safeCreateIcons
  auth.js       (547 lines) — api(), AuthManager, initLoginForm, AdminPanel
  search.js     (1106 lines)— SearchHistory, QueryParser, Autocomplete, performSearch
  sidebar.js    (1091 lines)— Vault tree, sidebar filter, TagFilterService, loadTags
  viewer.js     (1554 lines)— openFile, Outline, ScrollSpy, Frontmatter, Editor
  ui.js         (2250 lines)— Theme, Toast, Sidebar, Dropdowns, Tabs, ContextMenu
  dashboard.js  (461 lines) — Dashboard widgets (Recent, Stats, Bookmarks)
  config.js     (999 lines) — Config panel, Hidden files, About, Sidebar tabs
  sync.js       (436 lines) — SSE/IndexUpdateManager, PWA registration
  graph.js      (401 lines) — GraphViewManager (force-directed canvas graph)
  legacy.js     (550 lines) — Remaining bridge functions (goHome, showWelcome, initSearch)
  app.js        (80 lines)  — Thin orchestrator: imports all modules, calls init()

index.html: switched from <script src="app.js"> to <script type="module" src="js/app.js">
Original app.js preserved for backward compatibility.
All 14 modules pass node --check syntax validation.
2026-05-28 14:04:50 -04:00