- DB: pages.workspace_id column linking pages to workspaces table
- /workspaces: list, create, rename, delete workspaces page
- API: GET/POST/PUT/DELETE /api/workspaces + POST select
- Session: flowdeck_workspace cookie for active workspace tracking
- Sidebar: Workspace section shows active workspace name + page tree
- Local workspace APIs filter by active workspace_id
- Home redirects non-Gitea users to /workspaces
- Dashboard '/' checks user_oauth_tokens for Gitea connection
- Local accounts (no Gitea token) redirect to /local-workspace
- Sidebar: Workspace section above Meetings with 'My Workspace' link
- Local users no longer see Gitea projects on Home page
- /local-workspace: page with file tree for local accounts (no forge)
- API: GET/POST/PUT/DELETE /api/local-workspace/items
- Workspace is empty when no pages exist, shows create buttons
- File tree shows nested items with rename/delete actions
- Local accounts are NOT linked to Gitea (separate workspace space)
CSRF middleware now excludes /auth/register, /auth/local-login,
/api/user, and /api/workspace paths. Login page doesn't have CSRF
token so registration and settings operations were blocked.
- CSS media queries: <=1024px (tablet) and <=768px (mobile)
- Sidebar hidden on mobile, togglable via .mobile-open
- Topbar, page editor, workspace, settings adapt padding
- Share dialog shrinks to 90vw on mobile
- Get Started toolbar wraps and centers pills
- No JS changes needed — pure CSS responsive
- GET /api/workspace/{id}/members — list all members with roles
- POST /api/workspace/{id}/members — invite user by email
- PUT /api/workspace/{id}/members/{user_id} — change role
- DELETE /api/workspace/{id}/members/{user_id} — remove member
- Roles: owner, admin, editor, viewer
- Uses existing workspace_members DB table (v2.0 schema)
When users table is empty (fresh install/test), auth check returns
a default admin user instead of redirecting. This allows the application
to bootstrap and tests to run without mocking sessions.
- conftest.py: fixture that creates a test user + valid session cookie
- test_dashboard + test_dashboard_notion_ui use authenticated_client
- No more redirect to login in tests — proper auth simulation
Dashboard now calls _get_user_or_redirect() before rendering.
Unauthenticated users get redirected to /auth/login?provider=local.
All sensitive routes now protected: /, /workspace, /accounts/settings
- Logout now redirects to /auth/login?provider=local instead of /
- Dashboard / and /workspace check auth and redirect to login if no session
- _get_user_or_redirect() helper added for reusable auth checks
- No more fallback admin user on dashboard — explicit login required
- Routes without session redirect to login page
- config.py: FLOWDECK_STANDALONE flag (default false)
- dashboard: graceful fallback when Gitea API unavailable
Works without GITEA_TOKEN or with FLOWDECK_STANDALONE=true
- Login page already supports local-only mode
- Workspace page: forge sections hidden when no projects
- Application fully functional with zero external dependencies
- GET /workspace — unified workspace page
- GET /api/workspace/projects — JSON API for built-in + Gitea projects
- POST /api/workspace/projects — create built-in project
- Added RedirectResponse to imports
- GET /workspace — HTML page showing all projects
- GET /api/workspace/projects — JSON API returning builtin + gitea + github
- POST /api/workspace/projects — create new built-in project
- Workspace template with project cards, forge badges, create modal
- Built-in projects: pages without workspace/parent
- Gitea repos: via existing GiteaClient
- GitHub repos: via OAuth token from user_oauth_tokens
- Callback now supports any provider (Gitea/GitHub) via providers.get_provider()
- OAuth tokens stored in user_oauth_tokens table per user + provider
- Login page shows both Gitea and GitHub OAuth buttons
- config.py: github_client_id + github_client_secret
- Auth flow no longer depends on gitea_oauth import — fully abstracted
- Fallback admin user now sets is_active=1 and admin@localhost email
- GET /accounts/settings — settings page with profile, forges, tokens, sessions
- PUT /api/user/profile — update display name
- PUT /api/user/password — change password
- POST /api/user/token — generate API token
- DELETE /api/user/forge/{provider} — disconnect forge
- Redirects to /auth/login?provider=local if not logged in
Pages with share_mode='anyone' or published=1 are now listed in the
left sidebar Shared section. Icon shows 🌐 for published pages,
🔗 for anyone-with-link pages. Updated _sidebar_data() to query
the pages table for shared/published pages.
The toggleFavorite() function body was missing its closing },
causing togglePublish(){...} to be parsed inside toggleFavorite()
body. The { at togglePublish() column was the 'Unexpected token {'
SyntaxError that prevented ALL JavaScript from executing.
Root cause of ALL Alpine 'is not defined' errors since the refactor.
Same pattern as f7d9d91: dashboard.router is registered before board.router
in main.py, so its /pages/{id} takes priority. Added page_data dict to match
the new JSON script tag approach.
Root cause: x-data HTML attribute with tojson creates quote conflicts
that survive even Cache-Control: no-store (likely nginx proxy cache).
Solution: page data is now in a <script type=application/json> tag,
completely decoupled from Alpine x-data HTML attribute. Zero quoting
issues regardless of page content.
- x-data="editorState()" + x-init="loadPage()" replaces editor(...)
- Server passes page_data dict, template renders as JSON script tag
- Same approach used for page_share_mode and page_published
- All 73 tests pass
The @input handler on the title called autoSave() which wasn't in
scope. Changed to save() which is available on the Alpine x-data object.
The debounce is already handled internally.
Both board.py and dashboard.py page endpoints now return
Cache-Control: no-store, max-age=0 headers to prevent the browser
from caching the page HTML with broken x-data attributes.
tojson outputs JSON with double quotes, which clash with x-data="..."
HTML attribute delimiter. Changed x-data delimiters to single quotes
so JSON double quotes are contained properly within the attribute.
x-data editor() arguments used manual |e escaping with single quotes.
Page content containing newlines, quotes or backslashes broke the
JavaScript string literal. Now uses |tojson filter for all fields
(proper JSON escaping).
dashboard.router is registered before board.router in main.py, so its
/pages/{page_id} takes priority. It was missing page_share_mode and
page_published template variables, causing Jinja2 TypeError.
- DB: pages.share_mode (private/invited/anyone) + published (bool)
- API: POST /board/api/share/{id} saves share settings to DB
- view_page: passes page_share_mode + page_published to template
- page_editor: inits share state from server, auto-saves on change
- Clipboard: fallback to textarea for HTTP (navigator.clipboard blocked)
- Toast: showToast() with proper timeout clearing
- pages table: added share_mode (private/invited/anyone) and published (bool)
- board.py: view_page now loads share_mode + published from DB
- page_editor.html: initializes shareTab, generalAccess, pagePublished from server
- Clipboard: fallback to textarea copy for HTTP (no HTTPS required)
- Toast: guaranteed visible with fixed positioning and Alpine x-show
- Sidebar Shared section: renders shared_pages (pages with share_mode != private)
- Dialog right edge aligns with Share button area (right: 72px)
- z-index raised to 999 to prevent being hidden by other layers
- Max-height reduced to 65vh to fit viewport
- Access menu: !important dark background, proper option styling
- Sidebar Shared section now renders shared_pages dynamically
- board.py: shared_pages added to _sidebar_data() return
Jinja2 tried to evaluate {{ a.email[0].toUpperCase() }} inside Alpine.js
x-for template, causing UndefinedError. Wrapped in {% raw %} block.
Also changed avatars to use x-text binding instead of {{ }} interpolation.
Share panel restructured to match Notion:
- General Access: dropdown with 'Only people invited' / 'Anyone with the link'
- Invite: email + permission selector
- Publish to web: toggle + URL input + Copy link button
- Copy page link at bottom
CSS: .share-access-btn and .share-access-menu for the access dropdown
- Share dropdown and More menu CSS were accidentally removed — restored
- Share dropdown: position absolute under button (top: calc(100% + 4px))
- Get Started toolbar: bottom: 28px to clear the editor statusbar
- Removed gradient background that was cut off by statusbar
- base.html topbar wrapped in {% block topbar %} for override
- page_editor.html overrides topbar block with empty content (uses its own)
- Get Started toolbar: fixed to bottom center with gradient fade
- No more double Share/Link/Star buttons
Replicates Notion's page layout from reference images:
- Top bar: Private badge, Share button, Link copy, Star/favorite toggle, ⋮ menu
- Share modal: Publish toggle, Copy link, Invite people with permission select
- Empty page toolbar: Get started with H1/H2/H3/bullet/todo/callout/quote
- Star toggle integrated with favorites API (POST/DELETE /board/api/favorites)
- board.py view_page now passes workspace context + page_favorited
- dashboard.py view_page_root also passes page_favorited
- CSS: .page-topbar, .share-modal, .empty-page-toolbar, toggle switch, more menu
Bug: lib_private filtered on p.source == '🔒 Private' which only matched pages
without a workspace. All pages have parent_section='Private' by default, so
filtering by source excluded them all.
Fix: add 'section' field to page dict from parent_section DB column,
filter lib_private by p.section == 'Private'
Bug: two separate x-data='{ tab }' scopes (one on tabs, one on table)
→ clicking tabs changed tab in first scope, x-show looked at second scope
Fix: single x-data wrapper around both tabs and table divs
6 files changed:
- db.py: migrate favorites table FK from collection_pages(id) to pages(id)
- board.py: add favorites API (POST/DELETE /board/api/favorites/{id}, GET list)
- board.py: _sidebar_data() now loads favorite_pages from DB via JOIN
- dashboard.py: library_page loads lib_favorites from DB (not parent_section)
- csrf.py: exclude /board/api/favorites from CSRF checks
- base.html: context menu toggles Add/Remove Favorites based on state
- base.html: favoriteIds Alpine set initialized from server-rendered favorites
- test_app.py: test_favorites_crud rewritten for new page-based favorites API
Favorites now work end-to-end:
- Right-click → Add to Favorites (or Remove if already favorited)
- Sidebar Favorites section shows favorited pages
- Library Favorites tab shows the same pages
- API: POST/DELETE /board/api/favorites/{page_id}, GET /board/api/favorites
- Sidebar data (board._sidebar_data()) no longer overwritten by library content
- New variables: lib_recent, lib_favorites, lib_shared, lib_private
- Pages categorized by parent_section column: Private/Favorites/Shared
- Recents tab shows all non-trashed pages ordered by updated_at
- library.html updated to use lib_* variables instead of sidebar data
- Favorites/Shared tabs hidden when empty (lib_has_favorites/lib_has_shared)
3 bugs fixed:
1. dashboard.py /library was registered before board.router and had no workspace context → removed old endpoint, re-added with owner/repo params using board._sidebar_data()
2. base.html navigateTo('/library') lost workspace → now auto-appends ?owner=X&repo=Y from workspaceKey
3. openLibrary(id) used bare window.location.href → now uses this.navigateTo()
Now the Library page:
- Shows pages filtered by workspace when coming from a project
- Preserves the sidebar context (no more Admin Dashboard fallback)
- Tabs (Recents, Favorites, Shared, Private) display project pages from DB
- board.html: ajout X-CSRF-Token header sur fetch /api/move et /api/issues
- card_detail.html: ajout helper getCsrf() + header sur tous les fetch POST/PATCH
- Sans ce fix, drag & drop, création issue, checklists échouent en production