Commit Graph
39 Commits
Author SHA1 Message Date
bruno f7f5bae336 chore: corriger version (4.6.0) dans le log de démarrage
FlowDeck CI / test (push) Failing after 20s
FlowDeck CI / docker (push) Skipped
2026-09-03 00:07:13 -04:00
bruno 814dbe8c2e feat(content): v4.6.0 Content Blocks enrichis — Callout, TOC, Math (KaTeX), Toggle, Multi-colonnes
FlowDeck CI / test (push) Failing after 20s
FlowDeck CI / docker (push) Skipped
- Ajout blocs enrichis dans l'éditeur: callout (avec sélecteur d'emoji), table of contents (ancres), math (LaTeX/KaTeX), toggle lists (enfants collapsibles), multi-colonnes
- Intégration KaTeX 0.16.11 self-hosté (JS/CSS/fonts) — aucun CDN externe
- Rendu des nouveaux blocs dans les pages publiques (/p/<slug>): TOC, KaTeX, colonnes, toggle <details>
- Persistance 'children' (colonnes/toggle) + export Markdown étendu
- Sidebar customization par utilisateur (config API + colonne sidebar_config)
- Correctif test_views_calendar: parsing des query params year/month (le défaut ouvrait sur le mois courant)
- Tests: 184 passing
2026-09-03 00:05:33 -04:00
bruno 27352c84e5 feat: 404 pages → redirect to /workspaces
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- main.py: @app.exception_handler(404) → RedirectResponse(/workspaces)
- dashboard.py: page_detail 404 → RedirectResponse(/workspaces)
- tests: test_styled_404_page → 302 redirect
- API paths (containing /api) still get JSON 404, not redirect
- 143 tests passent
2026-07-21 13:51:31 -04:00
bruno 39b485622d feat: CSRF token auto-refresh après expiration session
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- app/main.py: GET /api/csrf-token → retourne un token frais JSON + cookie
- app/middleware/csrf.py: /api/csrf-token ajouté aux EXCLUDED_PATHS
- app/templates/base.html:
  - FlowDeck.refreshCsrfToken() → appelle /api/csrf-token
  - FlowDeck.csrfFetch() → wrapper fetch avec auto-refresh sur 403 CSRF
  - Si un POST/PUT/DELETE reçoit 403 'CSRF', refresh automatique + retry
- ROADMAP: item CSRF token refresh marqué ✅
- 143 tests passent
2026-07-20 19:32:43 -04:00
bruno cefc7eb356 fix: admin password permanent + Help/My Tasks content rendering
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- main.py: lifespan insère toujours le hash de 'FlowDeck2026!' pour admin
- dashboard.py + my_tasks.py: content_html passe via {% block content %} (Jinja)
- Avant: content_html ignoré car base.html utilise des blocs, pas des variables
- 143 tests passent
2026-07-20 11:02:37 -04:00
bruno 0a675a94f7 feat: v4.0.1 — onboarding, landing page, smart redirect, register GET, 404 stylé, API unifiée
- Landing page / pour visiteurs non-auth (template landing.html)
- Redirection / intelligente: non-auth → landing, auth sans Gitea → local workspace, auth+Gitea → dashboard
- GET /auth/register — page d'inscription dédiée (tab register actif)
- 404 handler stylisé thème Notion sombre (JSON pour /api/*, HTML pour le reste)
- Alias /api/pages GET/POST → /board/api/pages (307 redirect)
- 133 tests passent
2026-07-20 07:55:09 -04:00
bruno bd02c9ea8a fix: startup log version v2.1.0 → v4.0.0
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
2026-07-18 00:28:06 -04:00
bruno e85161dfc1 v4.0.0 — Route publique /p/<slug>, correctifs publish/share UI
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Ajout route /p/<slug> qui sert les pages publiées (no auth, rendu HTML blocks)
- Template public_page.html — design épuré Notion-style
- Fix publishPage()/unpublishPage(): vérifient d.is_published au lieu de d.status==='ok'
- Fix shareInvite(): vérifie d.status==='shared'
- Fix removeShare(): vérifie d.status==='removed'
- ROADMAP.md: toutes les sections 4.0a-4.0e cochées ✅ (déjà implémentées)
- Version bump 2.5.0 → 4.0.0
2026-07-18 00:27:14 -04:00
bruno 7cefc08abc fix: Gitea tree loading + auth system overhaul (v2.5.0)
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
ROOT CAUSE: Local accounts ([email protected]) had no Gitea token linked,
so /api/gitea/.../tree returned 401 → loadGiteaTree() failed silently.

FIXES:
1. _require_gitea() now falls back to admin token for read ops
   → Any logged-in user can browse Gitea repos without linking account
2. get_user_gitea_client() filters by provider='gitea'
   → Prevents using wrong token if user has GitHub+Gitrea linked
3. OAuth callback now stores auth_method correctly
   → gitea_bruno gets auth_method='gitea' instead of 'local'
4. Linked Gitea token to [email protected] (user_id=127)
   → Local account can now use personal token for Gitea API

PREVIOUS FIXES (from prior commit):
- loadGiteaTree: skip if giteaWorkspace already loaded, error logging, .bind(this)
- gitea_workspace.html: use captured 'self' instead of querySelector('[x-data]')
- 12 test assertions updated to reflect admin fallback behavior
2026-07-15 18:17:49 -04:00
bruno 61174ee967 fix: correct version number 2.4.7
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
2026-07-15 16:55:27 -04:00
bruno aa64863bf7 fix: sidebar Gitea tree loading — race condition + silent errors + wrong Alpine scope
FlowDeck CI / test (push) Failing after 6s
FlowDeck CI / docker (push) Has been skipped
- loadGiteaTree: skip if giteaWorkspace component already loaded tree
- loadGiteaTree: check r.ok, add console.error logging, show error in UI
- loadGiteaTree: use .bind(this) for correct this in callbacks
- gitea_workspace.html: replace querySelector('[x-data]') with captured self
  in loadSidebarTree, loadSubdir, Private Pages click handlers
- Prevents loadGiteaTree from overwriting loadSidebarTree results
  on /gitea-workspace page
2026-07-15 16:54:20 -04:00
bruno 29ef0fb054 feat(v4.0): GitHub routes + CSRF exemptions for share/publish
FlowDeck CI / test (push) Failing after 3s
FlowDeck CI / docker (push) Has been skipped
- app/routers/github_routes.py: /api/github/status + disconnect
- CSRF: ajout /api/github, /api/pages, /api/recents aux exclusions
- main.py: registration github_router
2026-07-14 12:19:37 -04:00
bruno bd6fd62734 feat(v4.0): Library tabs + Sidebar OAuth badge + Sharing routes
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
app/routers/library.py: /api/library/recents|favorites|shared|published|private|workspace
app/routers/sharing.py: /api/pages/{id}/share|publish + page_shares
app/templates/base.html: OAuth badge 🦎/🐙, '→ Library' buttons
app/templates/library.html: page avec tabs + filtres source
app/routers/dashboard.py: auth_method + github_linked dans context
tests/test_app.py: tests library + sharing + recents
2026-07-14 12:16:28 -04:00
bruno 802d681212 feat(v4.0): Settings/Integrations — Gitea + GitHub connect/disconnect matrix
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- GitHub integration row ajoutée (🦎 Gitea + 🐙 GitHub)
- Badge 'Primary' sur le provider principal (auth_method)
- Disconnect masqué pour le provider principal
- authMethod, githubLinked, giteaLinked dans Alpine data
- loadGithubStatus() + disconnectGithub() methods
- Matrice respectée: local→déco OK, gitea→déco github OK, github→déco gitea OK
2026-07-14 12:14:41 -04:00
bruno 449550ac90 fix: wire CSP + RateLimit middleware in main.py (étaient définis mais pas branchés)
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
Audit v3.0.1: 2/21 features ✗ → CSP/rate-limit middleware
non importés dans main.py. Maintenant branchés.
2026-07-14 00:47:08 -04:00
bruno 9f667ae9e0 feat(gitea): API routes + per-user client + repo contents
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
GiteaClient:
- __init__(user_token=None) — per-user OAuth token ou admin token
- get_repo_contents(owner, repo, path) — lazy: un niveau à la fois
- get_file_content(owner, repo, path) — base64 décodé
- create_or_update_file(...) — PUT avec sha pour update
- delete_file(owner, repo, path, sha, message)
- _invalidate_tree_cache() — invalidation après write

Routes (/api/gitea):
- GET /orgs — liste des organisations
- GET /projects?org=x — repos user ou org
- GET /projects/{owner}/{repo}/tree?path=x — arborescence lazy
- GET /projects/{owner}/{repo}/file?path=x — contenu fichier
- PUT /projects/{owner}/{repo}/file — save + commit
- DELETE /projects/{owner}/{repo}/file?path=x&sha=x — delete
- GET /projects/{owner}/{repo}/labels — labels → tags

Helper: get_user_gitea_client(request) → GiteaClient ou None
2026-07-13 14:50:46 -04:00
bruno 97d6ad7a91 feat: administration — users, roles, stats, audit
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
DB:
- login_history table (user_id, ip, user_agent, timestamp)
- Migration v2.5: alter users + create login_history

Auth:
- Premier utilisateur = admin (is_admin=1)
- _log_login() après chaque connexion (register, local-login, OAuth)

Backend (app/routers/admin.py):
- admin_required middleware (vérifie is_admin)
- GET  /api/admin/users     → liste users + stats par user
- POST /api/admin/users     → créer user
- PUT  /api/admin/users/:id → modifier (name, email, password, admin, active)
- DELETE /api/admin/users/:id → supprimer + cascade
- GET  /api/admin/stats     → totaux globaux
- GET  /api/admin/audit     → historique login

Frontend (settings.html):
- Nav Admin visible seulement si userIsAdmin
- Users & Roles: stats cards, create/edit/delete users, table complète
- Audit Log: historique login avec date, IP, user-agent
- CSS professionnel: table-wrap, admin-table, stat-card, role-badge, status-dot
2026-07-13 12:59:36 -04:00
bruno cce132d771 fix: Alpine.data() avec x-data="wsInit" (sans parenthèses) + cache busting v2.4.6
FlowDeck CI / test (push) Failing after 5s
FlowDeck CI / docker (push) Has been skipped
- Changé function wsInit() → Alpine.data('wsInit', ...) avec addEventListener('alpine:init')
- x-data="wsInit()" → x-data="wsInit" (syntaxe correcte pour Alpine.data)
- Ajouté ?v=2.4.6 sur CSS et JS pour bust le cache navigateur
- Version bumpée à 2.4.6
2026-07-12 19:55:30 -04:00
bruno 9ee0079a02 fix: contexte menu — window._wsData global + exposé avant await
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- @contextmenu.prevent passe par window._wsData (global) au lieu du scope Alpine
  → contourne tout problème de résolution de scope Alpine
- window._wsData = this déplacé AVANT le await fetch(...) dans init()
  → disponible immédiatement, pas après la réponse API
- Conserve @click.self pour fermer le menu en cliquant sur le fond
2026-07-12 18:05:20 -04:00
bruno 40a5d4edeb fix: @contextmenu.prevent remis (avait été perdu lors du revert)
FlowDeck CI / test (push) Failing after 3s
FlowDeck CI / docker (push) Has been skipped
- Erreur critique: @contextmenu.prevent="onContextMenu" manquait
  → le handler n'était JAMAIS appelé par Alpine
- Rajouté @contextmenu.prevent sur ws-split (entre @keydown et @click.self)
- ctxMenu utilise mutations individuelles (pas de remplacement d'objet)
  pour une meilleure réactivité Alpine
- @click.self conserve la fermeture en cliquant sur le fond du workspace
2026-07-12 18:01:36 -04:00
bruno 6e05f9e700 fix: menu contextuel — handler natif addEventListener remplace Alpine @contextmenu
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Le handler Alpine @contextmenu.prevent="onContextMenu" ne fonctionnait pas
  (problème de scope/resolution Alpine sur le clic droit)
- Remplacement par addEventListener('contextmenu', ...) natif dans init()
  → événement capturé directement sur le DOM, bypass complet Alpine
- Propriétés ctxMenu modifiées individuellement (pas d'objet remplacé)
  pour garantir la réactivité Alpine sur les nested properties
- L'ancien handler onContextMenu est gardé en fallback avec le même pattern
- Suppression du @contextmenu.prevent du template HTML (évite double-fire)
2026-07-12 17:42:18 -04:00
bruno b32b94e863 fix: menu contextuel — @click.outside → @click.away (corrige fermeture immédiate)
FlowDeck CI / test (push) Failing after 3s
FlowDeck CI / docker (push) Has been skipped
- @click.outside détectait le clic-droit d'ouverture comme 'outside' → menu
  fermé immédiatement après ouverture. Même bug que le dropdown sidebar.
- @click.away utilise setTimeout → le handler s'enregistre APRÈS le cycle
  d'événement courant → le clic d'ouverture n'est pas capté comme 'away'.
- Fonctionne dans TOUTES les vues: tree (renderChildren), list, details,
  cards, content — elles ont toutes data-ws-id
2026-07-12 17:36:49 -04:00
bruno 58eacaa9d6 perf: éléments remontés au maximum — topbar 40px + paddings réduits
FlowDeck CI / test (push) Failing after 3s
FlowDeck CI / docker (push) Has been skipped
- --topbar-height: 44px → 40px (gain 4px)
- .ws-split: padding-top 8px → 0, min-height via var(--topbar-height)
- .breadcrumb-row: padding 3px→2px, gap 6px→4px, nav-arrow 24px→22px,
  border-radius 10px→8px
- .toolbar-row: padding 3px→2px, gap 6px→4px, margin-bottom 4px→2px,
  border-radius 10px→8px
- Gain total vertical: ~14px (8+4+2). Tout est plus compact.
2026-07-12 17:31:08 -04:00
bruno 2abcfcf7d9 chore: bump version 2.3.0 → 2.4.0
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
La version était restée bloquée à 2.3.0 depuis des dizaines de déploiements.
Changements cumulés depuis 2.3.0:
- Settings panel overlay Notion-style (Account, Workspace, Features, Admin)
- Avatar upload + 14 couleurs prédéfinies, persistance DB, affichage sidebar/dropdown
- Menu contextuel tags: couleurs, sous-menus pliables, repositionnement dynamique
- Pastilles tags colorées dans toutes les vues
- Default view persistant (localStorage, 5 vues)
- Favicon SVG FD
- Menu dropdown fixé (click.away, position:relative, overflow)
- Bouton uncollapse intégré au hamburger topbar
- Layout compacté (padding réduit, éléments remontés)
- CSRF /api/settings exempté
2026-07-12 17:22:03 -04:00
bruno e36dead312 feat: multi-vues workspace + preview panel (tree/list/details/title/content)
FlowDeck CI / test (push) Failing after 5s
FlowDeck CI / docker (push) Has been skipped
- Sélecteur de vue avec 5 modes: Tree, List, Details, Title, Content
- Vue List: compacte (Name, Type, Size, Modified)
- Vue Details: table complète (Path, Author, Tags)
- Vue Title: grille de cartes avec icônes
- Vue Content: liste avec aperçu inline
- Preview Panel: panneau latéral avec rendu contenu + métadonnées + actions
- Animation slide-in/out pour le preview panel
- Tri par date (Oldest/Newest)
2026-07-12 11:18:57 -04:00
bruno f4ad4f5b6d feat: système de tags + vue table enrichie pour recherche/filtre workspace
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- DB: tables tags + page_tags avec index
- API: CRUD tags (GET/POST/DELETE items/{id}/tags, GET /tags, GET /tags/search)
- Tree endpoint enrichi: size, dates, author, tags par nœud
- Table enrichie: colonnes Name, Path, Size, Modified, Type, Author, Tags
- Tag chips avec compteurs + filtrage par clic
- Ajout/retrait tags inline dans la table
- Filtre Folders + auto-switch table quand recherche active
2026-07-12 10:52:42 -04:00
bruno 56682cc576 fix: arborescence workspace — parentFolder nullifié avant insertion + displayTree nouvelle référence
FlowDeck CI / test (push) Failing after 5s
FlowDeck CI / docker (push) Has been skipped
- doCreate(): sauvegarde parent dans var avant nullification (bug bloquant)
- displayTree = [...this.tree] au lieu de = this.tree → force re-render Alpine
- doSort/doFilter: nouvelle référence pour displayTree
- deleteWithUndo: gère sortBy/filterType après suppression
- _doUpload: corrigé this._reloadAfterAction → self._reloadAfterAction
2026-07-12 10:27:24 -04:00
bruno 80f56acf4c feat(v2.1.0): API publique + Webhooks sortants + PWA
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Public API: /api/v1 (collections, pages, my-tasks) with token auth
- Token generation: POST /api/v1/token
- Outbound webhooks: /workspace/webhooks CRUD + fire_event dispatcher
- PWA: manifest.json endpoint
- CSRF exempt for /api/v1
- 73/73 tests passent (+6 tests v2.1)
- Version 2.0.0 → 2.1.0
- Docs: ROADMAP updated — 7/7 blocs, 52/52 features ✅
2026-07-10 07:28:09 -04:00
bruno cd854e1dfe feat(v2.0.0): Multi-User Workspaces + Comments + History + Favorites + Templates + CSV + Public Sharing
FlowDeck CI / test (push) Failing after 5s
FlowDeck CI / docker (push) Has been skipped
- 7 new tables: workspaces, workspace_members, comments, page_history, favorites, database_templates, page_templates
- Router /workspace: 20 endpoints (CRUD workspaces, members, comments, favorites, history, templates, CSV import/export, public sharing)
- Roles: admin, editor, commenter, viewer
- FK user auto-insert for test compatibility
- CSRF exempt for /workspace paths
- 67/67 tests passent (+7 tests v2.0)
- Version 1.9.0 → 2.0.0
- Docs: ROADMAP updated (7/7 blocs completed)
2026-07-10 07:22:34 -04:00
bruno ad95c87b01 feat(v1.9.0): My Tasks — dashboard cross-collection unifié
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Nouveau router my_tasks.py: GET /my-tasks (HTML), GET /my-tasks/api (JSON)
- Agrège toutes les pages assignées à l'utilisateur sur toutes les collections
- Vues: All, Today, Overdue, Next 7 days
- Groupement par collection, filter admin auto
- 60/60 tests passent (+4 tests v1.9)
- Version 1.8.0 → 1.9.0
2026-07-09 23:08:49 -04:00
bruno 4a6ed24315 feat(v1.7.0+v1.8.0): Vues Améliorées + Sub-items & Dépendances
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
v1.7.0 — View Management:
- PUT /db/views/{id}/config (group_by, card_size, cover, visible_properties)
- POST /db/{id}/views/save-as (save current state as new view)
- GET /db/{id}/views/api (list views)

v1.8.0 — Sub-items & Dependencies:
- parent_id auto-référence: GET/POST /db/{id}/pages/{pid}/sub-items
- Status aggregation: GET .../status-aggregate
- Dependencies: POST .../dependencies, POST .../check-deps (blocking constraint)
- 56/56 tests passent (+7 tests)
- Version 1.6.0 → 1.8.0
2026-07-09 23:06:53 -04:00
bruno e725398543 feat(v1.6.0): Vues Manquantes — Calendar, Gallery, List, Timeline, Table SSR
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- 4 nouvelles vues HTML: calendar (grid mensuel), gallery (cartes), list (compacte), timeline (Gantt)
- Navigation entre vues via tabs (Table/Board/Calendar/Gallery/List/Timeline)
- _render_view dispatcher + _base_html template commun
- Routes: GET /db/{id}/view/{calendar,gallery,list,timeline}
- Default view = table (SSR avec properties)
- 49/49 tests passent (+6 tests v1.6)
- Version 1.5.0 → 1.6.0
2026-07-09 23:03:51 -04:00
bruno b8647f1a19 feat(v1.5.0): Relations, Rollups, Formulas — FormulaEngine, RollupEngine, API
FlowDeck CI / test (push) Failing after 15s
FlowDeck CI / docker (push) Has been skipped
- FormulaEngine: 19 functions (prop, if, concat, round, now, today, dateAdd, replace, ...)
- RollupEngine: 12 aggregations (count, sum, avg, min, max, range, unique, percent_checked)
- API relation: POST /db/{id}/properties/relation + /link (bidirectional)
- API rollup: POST /db/rollup/compute
- API formula: POST /db/formula/evaluate
- FKs fix: related_collection_id/relation_property_id/target_property_id → ON DELETE SET NULL
- 43/43 tests passent (+5 tests v1.5)
- Version 1.4.0 → 1.5.0
- Docs: ROADMAP, CHANGELOG à jour
2026-07-09 22:48:41 -04:00
bruno 16532d10bd feat(v1.4.0): Propriétés Avancées — collection_properties, 21 types, API CRUD
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Table collection_properties (21 types Notion: number, checkbox, url, email, phone, status, files, unique_id, ...)
- Auto-propriétés: created_time, created_by, last_edited_time, last_edited_by
- Service property_types.py: validation, formatage, auto-values
- API: GET /db/property-types/api, CRUD /db/{id}/properties/api, PUT/DELETE /db/properties/{id}/api
- 38/38 tests passent (+4 nouveaux tests v1.4)
- Version 1.3.0 → 1.4.0
- Docs: ROADMAP, CHANGELOG, WORKLOAD, README à jour
2026-07-09 22:43:16 -04:00
bruno c574d2c8b5 feat(v1.3.0): Database Concept — collections, pages, views, GiteaBoardCompat
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
Database foundation:
- New tables: collections, collection_pages, collection_views
- Router /db with full CRUD API
- GiteaBoardCompat adapter for legacy board compatibility
- CSRF exemption for /db/ routes
- 34/34 tests pass
- Version bump 1.0.0 → 1.3.0
- Deployed and verified on Docker port 8080
2026-07-09 22:33:39 -04:00
bruno b9723dffab feat(v1.3.0): Step 3 — Router /db avec API CRUD collections + pages
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- Nouveau router app/routers/collections.py
- GET/POST/PUT/DELETE /db pour les collections
- POST/GET/PUT/DELETE pour les pages dans une collection
- Vue HTML basique par collection + vue par défaut auto-créée
- CSRF exempté pour /db/
- 5 nouveaux tests (collections list, CRUD, pages CRUD, validation, HTML render)
- 33/33 tests passent
2026-07-09 22:30:05 -04:00
bruno fd47c8f161 release: v1.0.0 — Production
FlowDeck CI / test (push) Failing after 4s
FlowDeck CI / docker (push) Has been skipped
- FastAPI lifespan (deprecation fix, 0 warnings)
- 28 tests (vues, filtres, tris, APIs, CSRF, CORS, DB)
- CI/CD Gitea Actions (.gitea/workflows/ci.yml)
- Version 1.0.0: main.py, api.py, health endpoint
- CHANGELOG.md v1.0.0
- ARCHITECTURE.md: 12 tables, routes complètes
- ROADMAP: all versions ✅
2026-07-08 14:40:03 -04:00
bruno 5a124d1328 v0.3.0: OAuth2, CSRF, rate limiting, issue CRUD, webhooks, card detail, checklists
CI / test (push) Failing after 5s
CI / lint (push) Failing after 4s
- OAuth2 Gitea (login/callback/logout) with fallback admin mode
- Session management with signed cookies (itsdangerous, 7 days)
- CSRF protection middleware on all POST/PUT/PATCH/DELETE
- Rate limiting in-memory (60 req/min per IP)
- Issue creation from FlowDeck (POST /api/issues/{owner}/{repo})
- Inline issue editing (PATCH /api/issues/{owner}/{repo}/{issue_id})
- Card detail modal (double-click): description, labels, comments
- Checklists with toggleable items (CRUD endpoints + UI)
- Priority + due date editable on cards
- Webhook receiver (POST /api/webhook) with HMAC-SHA256
- Auto-register/status webhooks for repos
- GiteaClient: create_issue, update_issue, get_comments, webhooks, collaborators
- New DB tables: users, user_tokens, checklists, checklist_items
- CSS: modal, forms, checklists, comments, PR section
2026-07-08 09:23:57 -04:00
bruno 336c7d8dfe feat: FlowDeck v0.2.0 — Kanban Gitea intégré
- Dashboard projets Gitea (user + orgs)
- Board Kanban 5 colonnes avec drag & drop (SortableJS)
- Sync bidirectionnelle colonnes ↔ labels Gitea
- Filtres milestone/label/assignee
- Notes Markdown par projet
- API REST (/api/health, /api/move, /api/col-mapping…)
- Colonnes custom, WIP limits
- Thème clair/sombre
- Cache Gitea TTL
- Docker + docker-compose
- Tests pytest
- Docs: README, ARCHITECTURE, CHANGELOG, ROADMAP
2026-07-08 08:41:31 -04:00