1. Drag & drop interne: déplacer fichiers/dossiers existants vers d'autres
dossiers ou racine via l'API /api/local-workspace/items/{id}/move.
Items rendus draggable dans le template x-for et renderChildren.
2. File viewer pour fichiers uploadés: détection content_format='file',
visualiseur intégré avec rendu adapté au type MIME:
- Images: affichage direct
- PDF: iframe
- Texte/Code (.py .js .md .html .ps1 etc.): <pre> avec fetch du contenu
- Autres: lien de téléchargement
Route GET /api/files/{ws_id}/{filename:path} pour servir les fichiers.
3. Sidebar persistante: expandedFolders sauvegardé dans localStorage,
restauré au chargement, préservé avant navigation vers un dossier.
4. Suppression: nettoie aussi le fichier disque pour content_format='file'
Backend:
- POST /api/local-workspace/upload: upload fichiers via multipart, stockage
disque (/data/uploads/workspace_{id}/), page DB avec content_format='file'
- POST /api/local-workspace/upload-folder: upload récursif de dossiers
(structure JSON + fichiers), crée l'arborescence complète
Frontend:
- Drop zones sur la page workspace (racine + dossiers ciblés)
- Visual: overlay 'Drop files here', highlight du dossier cible
- webkitGetAsEntry pour walk récursif des dossiers
- Progress bar en bas à droite pendant l'upload
- Auto-reload après upload réussi
- Déduplication automatique des noms de fichiers
- API /api/local-workspace/tree: arbre récursif complet (support optionnel ?folder=ID)
- API /api/local-workspace/breadcrumb: fil d'Ariane parent pour un dossier
- Page /local-workspace: supporte ?folder=ID pour naviguer dans un dossier
- Sidebar: expand/collapse (▶/▼) sur les dossiers, clic dossier → /local-workspace?folder=ID
- CSS: styles chevron .tree-chevron, .tree-folder-link
- Alpine.js: expandedFolders, toggleTreeFolder, navigateToFolder
Bug: create_workspace in dashboard.py set uid=1 when session was
invalid, but user 1 might not exist in the users table, causing
sqlite3.IntegrityError: FOREIGN KEY constraint failed (HTTP 500).
Fix: ensure user row exists (INSERT OR IGNORE) before inserting
workspace with FK reference, matching the pattern in workspace.py.
Also: add name validation, use INSERT OR IGNORE for members.
- local_workspace.html: supprimé Alpine.data dupliqué + ajout hamburger
- workspaces.html, workspace.html, settings.html, page_editor.html: +hamburger
- auth.py: +path="/" sur tous les set_cookie de session (Chrome compat)
- csrf.py: +path="/" sur cookie CSRF
Root cause des bugs:
1. Chrome: cookie sans path="/" → non envoyé sur certaines routes
2. Firefox: les templates écrasaient le block topbar → pas de hamburger
→ sidebar inaccessible sur mobile (overlay + slide-in ne fonctionnaient pas)
Alpine processes DOM top-to-bottom. x-data='wsInit()' was evaluated
before the script defining wsInit() was parsed. Moved Alpine.data
registration to a script tag BEFORE the x-data div. Also removed
duplicate script block at the bottom.
The template had x-data="{inline object}" with x-init="init()" but the
inline object had no init method. wsInit() function was defined but
never referenced. Changed x-data to wsInit() which returns the full
component with init() — Alpine auto-calls init() on mount.
Complete rewrite of local_workspace.html with:
- flatten() as standalone function (not in Alpine component)
- wsInit() uses x-init for async loading
- No optional chaining or template literals (broader compat)
- :key uses array index to avoid undefined keys
- Simple var declarations throughout
- All modals unified with x-show toggles
- tree starts as [] (not undefined) so x-for doesn't crash
- :key uses node.db_id || 'item-'+idx for uniqueness
- _loaded guard prevents rendering before async init completes
- Empty state shows while loading, tree only renders after load()
The tree API returns {type: 'folder'|'page'} but flattenTree() was
accessing node.is_folder which is undefined for all items. All items
got is_folder: undefined → no children → but more critically, the
conditionals in the template also broke. Fixed to check node.type.
Both sidebar and workspace page DnD handlers now use @drop.prevent
to stop browser's default text insertion behavior. Without .prevent,
the browser tries to navigate to the dragged text as a URL, breaking
the drop event.
Added x-cloak directive and [x-cloak] CSS so button never flashes
before Alpine loads. Button is in base.html so appears on all pages
that extend the base template.
When sidebarCollapsed=true, a hamburger button appears at top-left
corner to restore the sidebar. CSS fixed positioning outside sidebar
so it's always visible even when sidebar is collapsed.
Same bug as tree API — sqlite3.Row doesn't implement .get(),
only __getitem__ (bracket notation). Fixed icon detection for
folders vs files in sidebar workspace section.
Server-side rendered sidebar doesn't auto-update after AJAX creation.
Changed create modal to reload page after success so sidebar picks up
new pages from workspace_pages template variable.
sqlite3.Row objects only support __getitem__ (r['key']), not the .get()
method. Changed r.get('parent_section') to r['parent_section'] in
folder type detection logic.
The roots query only had id, title columns but the tree builder
accessed r['parent_section'] which didn't exist in the result row.
Added parent_section to the SELECT to fix folder type detection.
- Topbar: removed New File/New Folder buttons + 'Files' label
- Breadcrumb: Workspace / work1 instead of work1 / Files
- Modals: single shared create modal with focus auto, @keydown.enter
- parent_id param: recursive folder/file creation inside folders
- Sidebar buttons use same POST /api/local-workspace/items
- newPageInWorkspace/newFolderInWorkspace now both use unified API
- Login redirect (all modes) now goes to /workspaces
- Workspace tree API filters by active workspace_id (no leak)
- Workspace name in sidebar from cookie (active_ws_name)
- Sidebar workspace section: 📄 new page + 📁 new folder buttons
- deleteWorkspacePage() in sidebar with confirmation
- _load_workspace_pages() helper with workspace_id filter
- CSS for sidebar-item-delete button (× on hover)
- Home button now links to /workspaces (universal workspace page)
- Sidebar workspace section shows active workspace name from cookie
- _sidebar_data reads flowdeck_workspace cookie for active_ws_name
- local-workspace APIs filter by workspace_id (not global)
- newPageInWorkspace() JS function added to sidebar
- CSRF exemption for /api/local-workspace routes
- DB: pages.workspace_id column linking pages to workspaces table
- /workspaces: list, create, rename, delete workspaces page
- API: GET/POST/PUT/DELETE /api/workspaces + POST select
- Session: flowdeck_workspace cookie for active workspace tracking
- Sidebar: Workspace section shows active workspace name + page tree
- Local workspace APIs filter by active workspace_id
- Home redirects non-Gitea users to /workspaces
- Dashboard '/' checks user_oauth_tokens for Gitea connection
- Local accounts (no Gitea token) redirect to /local-workspace
- Sidebar: Workspace section above Meetings with 'My Workspace' link
- Local users no longer see Gitea projects on Home page
- /local-workspace: page with file tree for local accounts (no forge)
- API: GET/POST/PUT/DELETE /api/local-workspace/items
- Workspace is empty when no pages exist, shows create buttons
- File tree shows nested items with rename/delete actions
- Local accounts are NOT linked to Gitea (separate workspace space)
CSRF middleware now excludes /auth/register, /auth/local-login,
/api/user, and /api/workspace paths. Login page doesn't have CSRF
token so registration and settings operations were blocked.
- GET /api/workspace/{id}/members — list all members with roles
- POST /api/workspace/{id}/members — invite user by email
- PUT /api/workspace/{id}/members/{user_id} — change role
- DELETE /api/workspace/{id}/members/{user_id} — remove member
- Roles: owner, admin, editor, viewer
- Uses existing workspace_members DB table (v2.0 schema)
When users table is empty (fresh install/test), auth check returns
a default admin user instead of redirecting. This allows the application
to bootstrap and tests to run without mocking sessions.
Dashboard now calls _get_user_or_redirect() before rendering.
Unauthenticated users get redirected to /auth/login?provider=local.
All sensitive routes now protected: /, /workspace, /accounts/settings
- Logout now redirects to /auth/login?provider=local instead of /
- Dashboard / and /workspace check auth and redirect to login if no session
- _get_user_or_redirect() helper added for reusable auth checks
- No more fallback admin user on dashboard — explicit login required
- Routes without session redirect to login page
- config.py: FLOWDECK_STANDALONE flag (default false)
- dashboard: graceful fallback when Gitea API unavailable
Works without GITEA_TOKEN or with FLOWDECK_STANDALONE=true
- Login page already supports local-only mode
- Workspace page: forge sections hidden when no projects
- Application fully functional with zero external dependencies
- GET /workspace — unified workspace page
- GET /api/workspace/projects — JSON API for built-in + Gitea projects
- POST /api/workspace/projects — create built-in project
- Added RedirectResponse to imports
- GET /workspace — HTML page showing all projects
- GET /api/workspace/projects — JSON API returning builtin + gitea + github
- POST /api/workspace/projects — create new built-in project
- Workspace template with project cards, forge badges, create modal
- Built-in projects: pages without workspace/parent
- Gitea repos: via existing GiteaClient
- GitHub repos: via OAuth token from user_oauth_tokens
- Callback now supports any provider (Gitea/GitHub) via providers.get_provider()
- OAuth tokens stored in user_oauth_tokens table per user + provider
- Login page shows both Gitea and GitHub OAuth buttons
- config.py: github_client_id + github_client_secret
- Auth flow no longer depends on gitea_oauth import — fully abstracted
- Fallback admin user now sets is_active=1 and admin@localhost email
- GET /accounts/settings — settings page with profile, forges, tokens, sessions
- PUT /api/user/profile — update display name
- PUT /api/user/password — change password
- POST /api/user/token — generate API token
- DELETE /api/user/forge/{provider} — disconnect forge
- Redirects to /auth/login?provider=local if not logged in
Pages with share_mode='anyone' or published=1 are now listed in the
left sidebar Shared section. Icon shows 🌐 for published pages,
🔗 for anyone-with-link pages. Updated _sidebar_data() to query
the pages table for shared/published pages.
The toggleFavorite() function body was missing its closing },
causing togglePublish(){...} to be parsed inside toggleFavorite()
body. The { at togglePublish() column was the 'Unexpected token {'
SyntaxError that prevented ALL JavaScript from executing.
Root cause of ALL Alpine 'is not defined' errors since the refactor.
Same pattern as f7d9d91: dashboard.router is registered before board.router
in main.py, so its /pages/{id} takes priority. Added page_data dict to match
the new JSON script tag approach.
Root cause: x-data HTML attribute with tojson creates quote conflicts
that survive even Cache-Control: no-store (likely nginx proxy cache).
Solution: page data is now in a <script type=application/json> tag,
completely decoupled from Alpine x-data HTML attribute. Zero quoting
issues regardless of page content.
- x-data="editorState()" + x-init="loadPage()" replaces editor(...)
- Server passes page_data dict, template renders as JSON script tag
- Same approach used for page_share_mode and page_published
- All 73 tests pass
The @input handler on the title called autoSave() which wasn't in
scope. Changed to save() which is available on the Alpine x-data object.
The debounce is already handled internally.
Both board.py and dashboard.py page endpoints now return
Cache-Control: no-store, max-age=0 headers to prevent the browser
from caching the page HTML with broken x-data attributes.
tojson outputs JSON with double quotes, which clash with x-data="..."
HTML attribute delimiter. Changed x-data delimiters to single quotes
so JSON double quotes are contained properly within the attribute.
x-data editor() arguments used manual |e escaping with single quotes.
Page content containing newlines, quotes or backslashes broke the
JavaScript string literal. Now uses |tojson filter for all fields
(proper JSON escaping).
dashboard.router is registered before board.router in main.py, so its
/pages/{page_id} takes priority. It was missing page_share_mode and
page_published template variables, causing Jinja2 TypeError.