Commit Graph
31 Commits
Author SHA1 Message Date
bruno 3fcc12ad8c feat: sweep complet — tous les émojis → outline SVG icons
Templates modifiés (22 fichiers):
- _icons.html: +14 new icons (paperclip, external-link, sparkles, lightbulb, tag,
  file-text, save, upload, trending-up, zap, alert-triangle, user, eye-off)
- base.html: +8 JS icons, 🦎🐙🔑🔗👁📋🔲📑❓⚠️→SVG
- page_editor.html: 43→0 émojis (📎📄🔒🔗⭐📋📁✨📝🗄📑📊📅🗓🖼📥🌐✏💬💡 etc)
- settings.html: 30→0 (⚙️📋🏷🧩👥💾🙈👁🔒🌙☀️🌳📊📝⚠🦎✅🐙🔗✏🗑)
- local_workspace.html: 25→0 (📄📁✏🗑⚠📋➕)
- gitea_workspace.html: 25→0 (🔗📄📤🔄⚙📁📄🔒✏🗑💾)
- board.html: 13→0 (📁📊📋☰📈👥✕✓🗑⚡🔍)
- workspace.html: 11→0 (🏠🔑⚙📁🔗📂🐙)
- landing.html: 8→0 (📚🚀📝📊🦎🌐🔒⚡)
- trash.html, table_view, dashboard, accounts, card_detail, public_page,
  workspaces, team_load, notes, _header, detailed_board, card, board_fragment
- Ajouté import _icons.html aux fragments standalone
- 143 tests passent
2026-07-21 08:27:10 -04:00
bruno b835dd6b5e fix: WORKSPSACES section + remaining emoji icons replaced
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- base.html: séparateur entre version et Log out, _local_workspaces_for_user
- board.py: _local_workspaces_for_user helper, app_version, fix emoji icons
- dashboard.py: _local_workspaces_for_user helper
- library.html: 📚📁📄🕒⭐👥🌐🔒📦 → SVG + icon map
- workspaces.html: 📁🔍🗑📝 → SVG
- local_workspace.html: page_icon, empty states, icon functions → SVG
- settings.html: 👤🔔 → SVG nav icons
- _icons.html: +'bell' icon
- CSS: .nav-icon-inline, .empty-state-icon
- 143 tests passent
2026-07-20 20:58:02 -04:00
bruno 63773cb904 fix: 4 correctifs UX — workspace +, library empty, settings spacing
FlowDeck CI / test (push) Failing after 3s
FlowDeck CI / docker (push) Has been skipped
- Workspaces: bouton bleu '+' maintenant centré, 48px, min-height 140px (plus coupé)
- Library no-workspace: 'Open a Workspace...' avec lien Go to Workspaces au lieu de Loading
- Library: boutons '+ Add new' et 'New page' cachés quand pas de workspace
- Settings: espacement bouton Upload photo (margin-bottom, margin-top augmentés)
- 143 tests passent
2026-07-20 11:21:14 -04:00
bruno 6f1eabf91d fix: Windows path handling, light theme default, file viewer in editor, first-user admin logic
FlowDeck CI / test (push) Failing after 18s
FlowDeck CI / docker (push) Has been skipped
Config:
- Fixed SQLite path parsing on Windows (handle drive letters without prepending /)
- Changed default theme from dark to light
- Updated OAuth test credentials (gitea_oauth_client_id/secret)

Auth:
- First real user (excluding default admin with no password) becomes admin
- Changed user count query to exclude users without password_hash

File viewer:
- Removed separate _render_file_viewer() —
2026-07-17 20:38:39 -04:00
bruno d4fb095baf feat: unified header across all pages (Notion-inspired breadcrumb + actions)
FlowDeck CI / test (push) Failing after 5s
FlowDeck CI / docker (push) Has been skipped
Created a shared _header.html template with:
- Hamburger button (toggle sidebar)
- Breadcrumb navigation with clickable segments and separators
- Page icon + title display
- Right-side action buttons (configurable per page)
- Dropdown panel CSS for More/New menus

Updated all pages to use the unified header:
- workspaces.html: Home / Workspaces + login/settings
- workspace.html: Workspace — Projects + login/settings
- local_workspace.html: workspace name
- gitea_workspace.html: Home / owner/repo + New/Upload/Refresh/Settings
- page_editor.html: title + Edited/Share/Copy/Favorite/More dropdown
- settings.html: Settings

Added CSS for breadcrumb, dropdown panel components.
2026-07-16 12:30:18 -04:00
bruno 3fdcc41d10 fix: auto-refresh page when closing Settings with X
FlowDeck CI / test (push) Failing after 5s
FlowDeck CI / docker (push) Has been skipped
closeSettings() now:
- Refreshes the parent page (history.back + reload)
- Handles tab navigation between settings sections
- Falls back to /workspaces redirect if no history
2026-07-15 08:10:01 -04:00
bruno 17666b51c2 fix: two UX issues
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
1. Settings X button: closeSettings() goes back, skipping hash-only navigation
   → No more double-click to close

2. Workspaces page: Connect Gitea link now includes &mode=link
   → Same link as Settings → Integrations (was missing mode=link)
2026-07-15 07:56:21 -04:00
bruno 802d681212 feat(v4.0): Settings/Integrations — Gitea + GitHub connect/disconnect matrix
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- GitHub integration row ajoutée (🦎 Gitea + 🐙 GitHub)
- Badge 'Primary' sur le provider principal (auth_method)
- Disconnect masqué pour le provider principal
- authMethod, githubLinked, giteaLinked dans Alpine data
- loadGithubStatus() + disconnectGithub() methods
- Matrice respectée: local→déco OK, gitea→déco github OK, github→déco gitea OK
2026-07-14 12:14:41 -04:00
bruno e2043123f0 fix: title_prefix block for browser tab — évite conflit Jinja2 page_title double
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
Erreur: block 'page_title' defined twice → TemplateAssertionError
Fix: title_prefix (nouveau bloc) pour <title>, page_title (existant) pour Alpine

10 templates mis à jour avec title_prefix.
2026-07-14 09:35:52 -04:00
bruno de40c2d83e v3.0.1: qualité & stabilité — tests, sécurité, UX consolidée
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
🧪 Tests: 73 → 130 (+57 tests)
- Upload API, labels sync, commit history (401/400/502/cached)
- File create/update (sha=null, sha=abc)
- Admin delete cascade (12 tests: oauth, tags, workspaces, pages…)
- Gitea status (linked/unlinked/disconnect)
- OAuth link mode (session, redirect, callback)

🔒 Sécurité
- ContentSecurityPolicyMiddleware (CSP headers)
- RateLimitMiddleware (100 req/min/IP)
- Pydantic models: ErrorResponse, SuccessResponse
- Input validation upload (10MB, allowed extensions)
- Pydantic request models

🎨 UX
- static/css/design-tokens.css (500 lines, thèmes + skeletons)
- Toast system: 16 alert() remplacés par toast()
- 59 lignes CSS dupliquées retirées (6 templates)
- Skeletons cohérents sur toutes les vues

⚡ Performance
- Cache TTL sur get_file_commits (consistant avec les autres méthodes)
2026-07-13 23:08:53 -04:00
bruno e3851b4f12 feat: OAuth link mode + settings light mode CSS variables
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
1. /auth/login?provider=gitea&mode=link:
   - Sauve 'oauth_mode=link' dans la session
   - Callback: link OAuth token à l'utilisateur courant (pas de nouveau compte)
   - Redirige vers /settings#integrations

2. Bouton Connect dans Settings → mode=link

3. Settings light mode: remplacé 12 couleurs codées en dur par CSS variables
   - .settings-panel, .modal-box, .settings-input
   - .admin-table th/td, .stat-card
   - .btn-sm, .btn-sm:hover
2026-07-13 21:24:04 -04:00
bruno ef88ee4c55 fix: virgule manquante après saveDefaultView() — SyntaxError cassait tout le JS
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
settings.html:773: '} async' → '}, async'
Cette SyntaxError empêchait Alpine.data('settingsInit') d'être parsé
→ toutes les variables Alpine étaient undefined
2026-07-13 20:56:42 -04:00
bruno 0d66b5d543 fix: scope Alpine gitea_workspace + commit admin fallback + settings cleanup
FlowDeck CI / test (push) Failing after 6s
FlowDeck CI / docker (push) Has been skipped
1. gitea_workspace.html: owner/repo en Jinja2 dans la topbar (pas Alpine)
2. gitea.py: save_file/delete_file → _require_gitea (admin token can write)
3. settings.html: retrait doublon defaultView, fix workspace_name Jinja2
2026-07-13 20:47:46 -04:00
bruno e22efc1d9c fix: retirer bouton dark/light mode du sidebar, ajouter dans Settings
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Sidebar: retrait du bouton 🌓 (dark/light) + bouton 🚪 logout
- Settings → Account → Preferences: nouveau sélecteur de thème (Dark/Light)
- Persistance localStorage 'fd_theme' — appliqué au chargement de chaque page
- initTheme() dans base.html + applyTheme() dans settings.html
- toggleTheme() conservé dans le JS mais plus utilisé dans l'UI
2026-07-13 17:08:30 -04:00
bruno e9d1c32b4f feat: Gitea — register, settings connect, tabs org, search
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
1. Pas de Gitea sans config: _require_gitea() → 401 si pas de token OAuth
2. Register Gitea: boutons "Login/Register with Gitea" dynamiques selon l'onglet
3. Settings → Integrations: ✅ Active / 🔗 Connect / Disconnect + API status/disconnect
4. Workspaces: tabs par org (All | org1 | org2) + barre recherche 🔍 filtrage live
5. API: GET /api/gitea/status, DELETE /api/gitea/disconnect
2026-07-13 15:17:17 -04:00
bruno 4ea512d007 feat: My Account — modifier username, nom, email, mot de passe
FlowDeck CI / test (push) Failing after 3s
FlowDeck CI / docker (push) Has been skipped
Backend:
- PUT /api/settings/account (full_name, login, email, password)
- Vérifie que le username n'est pas déjà pris
- Password min 6 caractères

Frontend (Settings → My Account):
- Champs éditables: Username, Full name, Email
- Section Change password avec toggle 👁/🙈
- Bouton Save changes + Update password
- Message de confirmation ✓ / ✗ avec timeout 3s
2026-07-13 13:42:11 -04:00
bruno e01e410d43 fix: CSRF token dans toutes les requêtes admin (adminFetch)
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
Tous les appels /api/admin/* passent maintenant par adminFetch()
qui ajoute X-CSRF-Token depuis le cookie csrf_token
2026-07-13 13:26:07 -04:00
bruno 057ff9f524 ui: settings panel 1050px (était 820px) pour afficher tous les champs admin
FlowDeck CI / test (push) Failing after 5s
FlowDeck CI / docker (push) Has been skipped
2026-07-13 13:14:26 -04:00
bruno 97d6ad7a91 feat: administration — users, roles, stats, audit
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
DB:
- login_history table (user_id, ip, user_agent, timestamp)
- Migration v2.5: alter users + create login_history

Auth:
- Premier utilisateur = admin (is_admin=1)
- _log_login() après chaque connexion (register, local-login, OAuth)

Backend (app/routers/admin.py):
- admin_required middleware (vérifie is_admin)
- GET  /api/admin/users     → liste users + stats par user
- POST /api/admin/users     → créer user
- PUT  /api/admin/users/:id → modifier (name, email, password, admin, active)
- DELETE /api/admin/users/:id → supprimer + cascade
- GET  /api/admin/stats     → totaux globaux
- GET  /api/admin/audit     → historique login

Frontend (settings.html):
- Nav Admin visible seulement si userIsAdmin
- Users & Roles: stats cards, create/edit/delete users, table complète
- Audit Log: historique login avec date, IP, user-agent
- CSS professionnel: table-wrap, admin-table, stat-card, role-badge, status-dot
2026-07-13 12:59:36 -04:00
bruno ea591bd577 fix: input rename tag en dark theme
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
Ajout .settings-input: fond #2A2A2A, bordure #555, texte #ddd, focus bleu
2026-07-13 12:42:19 -04:00
bruno 91032de704 fix: 5 corrections — modals opaques, tags visibles, fermeture menu, filtrage, pastilles
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
1. Settings modals: fond rgba(0,0,0,.85) + boîte #1E1E1E (plus opaque)
2. Tags existants: sync forcé via menuEl._x_dataStack en plus de _ctxMenuData
3. Ajout tag: ferme .ctx-menu après succès (style.display='none')
4. Filtrage tags: toggleTagFilter() appelle doFilter() + _filterTreeByTag
5. Pastilles: tag-dot supprimé, :style="{background: t.color}" sur tag-chip
   → 7 occurrences mises à jour (filter bar, tree, preview, JS gen)
2026-07-13 11:55:29 -04:00
bruno 51c6002f08 fix: 5 bugs — couleur tag, tags existants, modal settings, rename, filtrage
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
1. ctxAddNewTag lit window._ctxMenuData.ctxNewTagColor (pas this.ctxNewTagColor)
   → la couleur sélectionnée dans le menu est maintenant sauvegardée

2. onContextMenu: charge workspaceTags si vide avant de calculer ctxAvailTags
   → les tags existants apparaissent dans le dropdown

3. Settings: CSS modal-overlay/modal-box/.btn-danger ajouté
   → le modal delete n'est plus transparent

4. Rename tag: modal avec input au lieu de prompt()
   → double-clic → modal avec couleur + input + autofocus

5. doFilter: _filterTreeByTag filtre displayTree quand tagFilter est actif
   → le filtrage par tags fonctionne dans toutes les vues
2026-07-13 11:34:43 -04:00
bruno 53865f136d fix: tags contextuels + rename/delete confirm dans Settings
FlowDeck CI / test (push) Failing after 8s
FlowDeck CI / docker (push) Has been skipped
Context menu (_ctxMenuData):
- Remplacé getters par propriétés simples (Alpine ne réagit pas aux getters)
- Sync _wsInitData → _ctxMenuData dans onContextMenu, ctxAddNewTag, ctxRemoveTag
- Les 4 tags existants apparaissent maintenant dans le dropdown

Settings > Tags:
- Double-clic sur un tag → prompt rename (PUT /api/settings/tags/<id>)
- Suppression: modal de confirmation au lieu de confirm() natif
- Affiche le nombre d'items impactés si tag utilisé
2026-07-13 11:20:51 -04:00
bruno ed0510ec9b fix: Default view dropdown settings — 5 vues + style + persistence
FlowDeck CI / test (push) Failing after 10s
FlowDeck CI / docker (push) Has been skipped
- Select remplacé: class sort-select (mal stylé) → settings-select (adapté)
- 5 vues: Tree, List, Details, Cards, Content (plus seulement 3)
- x-model="defaultView" + @change="saveDefaultView()"
- Sauvegarde localStorage 'fd_default_view'
- workspace page lit localStorage pour viewMode initial
- Settings → Default view persiste entre sessions et s'applique au workspace
2026-07-12 16:48:41 -04:00
bruno 48f33964b0 fix: avatar persistant — correction référence template + avatar dropdown
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- settings.html: avatarUrl lisait user.avatar_url (dict session, inexistant)
  → corrigé en {{ avatar_url }} (variable template top-level de _sidebar_data)
- settings.html: avatarColor lisait user.get("avatar_color") (idem)
  → corrigé en {{ avatar_color }}
- base.html: dropdown user-menu affiche maintenant l'avatar avec couleur/URL
  au lieu du workspaceInitial statique (pas de synchronisation)
2026-07-12 16:44:18 -04:00
bruno 7fe7a91788 feat: avatars prédéfinis par couleur + fix CSRF avatar/tags
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Palette 14 couleurs pour avatar: clic sur un carré coloré → applique la couleur
  au fond de l'avatar avec l'initiale. API POST /api/settings/avatar-color
- Upload photo: efface la couleur custom et utilise l'image uploadée
- Color swatches tags: border-radius 6px (carrés arrondis) au lieu de 50% (ovales)
- CSRF: /api/settings ajouté à EXCLUDED_PATHS → 403 corrigé sur avatar + tags
2026-07-12 15:32:30 -04:00
bruno 6d0647f83d fix: CSRF avatar upload + tags settings + color swatches carrés
FlowDeck CI / test (push) Failing after 3s
FlowDeck CI / docker (push) Has been skipped
- /api/settings ajouté à EXCLUDED_PATHS → avatar upload et tags CRUD
  n'étaient pas exemptés du CSRF → 403 Forbidden sur POST/PUT/DELETE
- Color swatches: border-radius 6px (carrés arrondis) au lieu de 50% (ovales)
- Avatar upload et tags create/update/delete fonctionnent maintenant
2026-07-12 15:30:23 -04:00
bruno e3968356e2 feat: settings panel overlay Notion-style + avatar upload + sections
FlowDeck CI / test (push) Failing after 5s
FlowDeck CI / docker (push) Has been skipped
- Settings page refaite en panneau overlay (position:fixed + backdrop-blur)
- Layout 2 panes: nav sidebar gauche + contenu droit
- Sections: Account (profile + avatar upload), Notifications, Workspace,
  Tags management, Features (integrations), Admin (security)
- Avatar: upload image (POST /api/settings/avatar), preview instantané,
  stockage /data/avatars/, mise à jour users.avatar_url
- GET /api/avatar/{user_id} redirige vers l'image avatar
- Tags: palette couleurs, création, suppression, changement couleur
- Fermeture: bouton × ou Escape (window.history.back)
2026-07-12 15:22:31 -04:00
bruno 004c47df34 feat: sidebar user menu Notion-style + settings page + tag colors + preview images/PDF
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Sidebar header: user menu dropdown (Settings, Switch workspace, Log out)
  avec avatar + nom + email, chevron animé, fond opaque #1E1E1E
- Nouvelle page /settings avec gestion globale des tags:
  créer tag avec couleur, changer couleur, supprimer, liste avec compteurs
- API tag management: POST/PUT/DELETE /api/settings/tags, GET /api/settings/tags/all
- Preview panel: affichage images (img tag), PDF (lien viewer), détection format
- workspace-chevron CSS: rotation 180° quand menu ouvert
2026-07-12 12:35:17 -04:00
bruno c5398757ca fix: hamburger menu sur toutes les pages + cookies path="/" Chrome fix
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- local_workspace.html: supprimé Alpine.data dupliqué + ajout hamburger
- workspaces.html, workspace.html, settings.html, page_editor.html: +hamburger
- auth.py: +path="/" sur tous les set_cookie de session (Chrome compat)
- csrf.py: +path="/" sur cookie CSRF

Root cause des bugs:
1. Chrome: cookie sans path="/" → non envoyé sur certaines routes
2. Firefox: les templates écrasaient le block topbar → pas de hamburger
   → sidebar inaccessible sur mobile (overlay + slide-in ne fonctionnaient pas)
2026-07-11 00:30:59 -04:00
bruno 32c1f70c53 feat: multi-user auth — local accounts, settings page, OAuth prep
FlowDeck CI / test (push) Failing after 6s
FlowDeck CI / docker (push) Has been skipped
Phase 1 foundation:
- DB: users table extended (password_hash, is_active, login_attempts, locked_until)
- DB: user_oauth_tokens table (user_id, provider, access_token, refresh_token)
- password_utils.py: SHA-256+salt hashing, verify, rate-limit lock check
- auth.py: POST /auth/register + POST /auth/local-login + /auth/login?provider=local
- Login page: tabs Login/Register with Gitea OAuth button
- settings.html: profile (name/password), forges, API tokens, sessions
- ALTER TABLE migrations for existing DBs
2026-07-10 15:34:58 -04:00