From 6d7af3fb6490363df8cc063c30cc67bf238368c3 Mon Sep 17 00:00:00 2001 From: Bruno Charest Date: Fri, 2 Oct 2026 16:56:29 -0400 Subject: [PATCH] =?UTF-8?q?feat:=20=C3=A9diteur=20visuel=20d'automations?= =?UTF-8?q?=20(pipeline=20steps)=20+=20fix=20CSP=20multi-instructions=20(v?= =?UTF-8?q?7.45.0)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Added — Settings → Automations, pipeline visuel (API steps v7.0) : - Cartes ordinees (trigger/condition/delay/action) : resume + edition TYPÉE par kind/type (datalist evenements, 7 ops, 8 types d'action avec leurs champs reels), ajout/edition/suppression/haut-bas via POST/PUT/DELETE /workspace/automations[/steps]/... - ✨ Convertir le JSON en pipeline (legacy → steps ordonnes) ; textareas JSON masques des qu'un step existe. - Gate E2E « editeur visuel de steps » : creation → edition → ajout → carte « Action · webhook » sous CSP reel. Fixed (trouve par le gate) — 51 expressions Alpine MULTI-INSTRUCTIONS (`a=1; b()`) = interdites par le parseur CSP (une seule expression par directive ; ';' = token inattendu) — INVISIBLE pour le scan par tokens : - Conversion en methodes dans 11 fichiers : nav settings x8 (navTo), menu section base x7 (closeAndSetCount/Move/...), parts+editeur x13 (setSharePerm, more*, markAndSave...), breadcrumb x5 (hover*/goClose), library/local x6 (menus popup), board x3 (pickStatus/...), ctx-menu x2 (addTagAndClear), agent/card/gitea/workspaces x6. - Scanner dedie scan_semi (inventaire ';' hors chaines) ajoute au lot. Verifs : 39 templates Jinja parse OK · scan expressions = 0 incompatible (4 faux positifs en chaines) · **E2E 8/8** · suite **1094/1094** · ruff OK · docs a jour --- CHANGELOG.md | 34 ++++++ ROADMAP.md | 2 +- VERSION | 2 +- WORKLOAD.md | 2 +- app/main.py | 2 +- app/templates/_ctx_menu.html | 4 +- app/templates/_header.html | 13 +- app/templates/_page_editor_content.html | 26 ++-- app/templates/agent_panel.html | 2 +- app/templates/base.html | 20 ++-- app/templates/board.html | 6 +- app/templates/card_detail.html | 3 +- app/templates/gitea_workspace.html | 2 +- app/templates/library.html | 6 +- app/templates/local_workspace.html | 6 +- app/templates/settings.html | 152 ++++++++++++++++++++++-- app/templates/workspaces.html | 4 +- docs/openapi-v2.json | 2 +- e2e/csp_preview.spec.js | 35 ++++++ static/js/_ctx_menu.js | 4 + static/js/agent_panel_2.js | 1 + static/js/board.js | 3 + static/js/gitea_workspace.js | 5 + static/js/library.js | 15 +++ static/js/local_workspace.js | 14 +++ static/js/page_editor_scripts.js | 10 ++ static/js/settings.js | 129 ++++++++++++++++++++ static/js/workspaces.js | 1 + 28 files changed, 445 insertions(+), 60 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b641baa..973c346 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,39 @@ # Changelog - FlowDeck +## v7.45.0 (2026-10-01) — Éditeur visuel d'automations + correction CSP (multi-instructions) + +### Added + +- **Pipeline visuel (steps) dans Settings → Automations** : cartes + ordonnées par étape avec badge + résumé (`📡 Déclencheur · event`, + `⚖ Condition · prop op val`, `⏳ Attente · Xs`, `⚡ Action · type → …`), + **éditeur typé par kind/type** (événements en datalist, 7 ops de + condition, 8 types d'action avec leurs champs réels : url, property/value, + collection/title, message, webhook_url/text, to/subject/body, + owner/repo/labels, agent_id/message), ajout/édition/suppression/**↑↓** via + `POST/PUT/DELETE /workspace/automations[/steps]/…`, conversion legacy + **✨ Convertir le JSON en pipeline** (trigger + conditions + actions + ordonnés) ; les textareas JSON disparaissent dès qu'un step existe. +- **Gate E2E** « éditeur visuel de steps » : création → édition → ajout + d'étape → carte `Action · webhook` visible (sous CSP réel). + +### Fixed (trouvé par le gate) + +- **51 expressions Alpine multi-instructions** (`activeSection='x'; + loadX()` etc.) = **interdites par le parseur CSP** (une seule expression + par directive ; `;` = token inattendu) — invisible pour le scan par + tokens ! Conversion en **méthodes** : settings nav ×8 (`navTo`), menu de + section base ×7 (`closeAndSetCount/…`), parts/éditeur ×13 + (`setSharePerm`, `more*`, `markAndSave`…), breadcrumb ×5 + (`hoverEllipsis/goClose`), library/local ×6 (menus), board ×3 + (`pickStatus/…`), ctx-menu ×2 (`addTagAndClear`), agent/card/gitea/ + workspaces ×6. Scanner dédié `scan_semi` (inventaire `;` hors chaînes). + +### Notes + +- 39 templates Jinja parse OK, scan d'expressions = 0 incompatibilité + (4 faux positifs en chaînes), E2E **8/8**, suite **1094/1094**. + ## v7.44.0 (2026-10-01) — Palette Ctrl+K : onglets Pages / ✨ Réponses IA ### Added diff --git a/ROADMAP.md b/ROADMAP.md index fd3845a..8be1a4f 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -1001,7 +1001,7 @@ Détails livrés : - [x] **Migrations 26** — `automation_steps`, `workers`, `worker_runs`, `automations.trigger_mode`, `collection_properties.button_automation_id` - [x] **Tests** — `tests/test_v70_automations_workers.py` (**31 tests** : migration, steps CRUD/validation/auth, mode any/all, `form.submitted`, chaînes + interpolation, condition, delay, slack + secret chiffré, email no-SMTP, forge mock + sans-token, agent mock + 404, button press/validation, legacy single-run, workers CRUD/auth/rejet code/run ok/error/timeout/budget/fork/privacy/usage/cron/masquage code) - [x] **Version** — 7.0.0 (`VERSION` + `app/main.py`) · `ruff check` OK -- [ ] **Éditeur visuel** — canvas Settings → Automations (reporté : API steps livrée, UI en follow-up) +- [x] **Éditeur visuel** — **pipeline steps** dans Settings → Automations (v7.45.0) : cartes ordonnées (trigger/condition/delay/action) avec **config typée par type** (8 actions : webhook/set_property/create_page/notify/slack/email/forge_issue/agent_trigger + ops condition + datalist événements), ajout/édition/suppression/réordonnancement (↑↓) via l'API `/steps` + bouton **✨ Convertir le JSON en pipeline** (legacy → steps ordonnés). **Bonus trouvé par le gate** : **51 expressions multi-instructions** (`a=1; b()` — `;` = SEULE expression par directive interdit sous le parseur CSP, non couvert par le scan `tokens`) → converties en méthodes dans **11 fichiers** (nav settings ×8, menu section base ×7, partages/éditeur ×13, breadcrumb ×5, lib/local ×6, board ×3, ctx/agent/workspaces/card/gitea ×6). Nouveau scanner `scan_semi` ajouté au lot. ### v7.1.0 — Calendar sync + Meeting Notes ✅ (2026-09-28) > **Objectif** : calendrier bidirectionnel + transcription → agents (cf. Notion 07/2026 : Meeting Notes trigger Custom Agents). diff --git a/VERSION b/VERSION index a1350b5..3ed5a78 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -7.44.0 +7.45.0 diff --git a/WORKLOAD.md b/WORKLOAD.md index 8f3d2ff..fe529ff 100644 --- a/WORKLOAD.md +++ b/WORKLOAD.md @@ -1,6 +1,6 @@ # WORKLOAD — FlowDeck Notion Clone -> **Début**: 2026-07-08 | **Version**: v7.44.0 (UI palette : onglets Pages / ✨ Réponses IA — POST /api/v2/search/ask rendu + sources citées) | **Statut**: EN COURS 🔄 +> **Début**: 2026-07-08 | **Version**: v7.45.0 (Éditeur visuel d'automations = pipeline steps CRUD + conversion JSON + **fix CSP : 51 expressions multi-instructions → méthodes** (30 fichiers-tpl)) | **Statut**: EN COURS 🔄 > **Cible**: parité Notion + intégration forge · **Follow-ups v7.3 livrés**: sidebar teamspaces, notif `page.updated`, charts `number` + dashboards multi-DB, unfurl forge, UI Settings → Audit — voir `ROADMAP.md § v7.3.0` ## Avancement Global diff --git a/app/main.py b/app/main.py index bf84a59..4462014 100644 --- a/app/main.py +++ b/app/main.py @@ -185,7 +185,7 @@ async def lifespan(_app: FastAPI): app = FastAPI( title="FlowDeck", - version="7.44.0", + version="7.45.0", docs_url="/docs", redoc_url="/redoc", lifespan=lifespan, diff --git a/app/templates/_ctx_menu.html b/app/templates/_ctx_menu.html index 45ca865..a1869ae 100644 --- a/app/templates/_ctx_menu.html +++ b/app/templates/_ctx_menu.html @@ -163,9 +163,9 @@
- +
diff --git a/app/templates/_header.html b/app/templates/_header.html index c7858b8..2fdd79c 100644 --- a/app/templates/_header.html +++ b/app/templates/_header.html @@ -60,14 +60,14 @@ {# ── Collapsed "…" segment ── #}