Cause racine : {% set right_actions = '…' ~ fd_icon(…) ~ '…' %} —
fd_icon est une macro → Markup, et Markup.__radd__/__add__ ÉCHAPPE ses
arguments str → tous les segments littéraux sortent entité-és ("/<),
et le |safe de _header:141 est no-op sur un Markup déjà échappé.
Régression probable depuis A10 (activation d'autoescape).
Fix (5 templates, forme idiomatique) : conversion en block-set
{% set right_actions %}…{{ fd_icon(…) }}…{% endset %} — source brute,
interpolation Markup brute : gitea_workspace, page_editor,
page_editor_collection, workspace, workspaces. (Piège script : regex
greedy multi-lignes avalait le set suivant → matcher sur UNE ligne.)
Tests :
- NOUVEAU tests/test_topbar_right_actions.py (permanent) : /workspaces
doit servir class="topbar-btn" parsé et ZÉRIE entité "
- gate éditeur CSP : assertion .star-btn RÉTABLIE (les boutons rendent)
- debug temporaires (DBGCLS/DBGVAL) retirés
suite **1094/1094** (+1 nouveau test) · ruff OK · E2E **7/7** (5
csp_preview + 2 smoke) · docs à jour (CHANGELOG détail, ROADMAP bug →
CORRIGÉ)
4.7 KiB
WORKLOAD — FlowDeck Notion Clone
Début: 2026-07-08 | Version: v7.42.0 (BUG TOPBAR CORRIGÉ : « 'literal' ~ fd_icon » échappait les boutons → block-set ×5 + test permanent) | Statut: EN COURS 🔄 Cible: parité Notion + intégration forge · Follow-ups v7.3 livrés: sidebar teamspaces, notif
page.updated, chartsnumber+ dashboards multi-DB, unfurl forge, UI Settings → Audit — voirROADMAP.md § v7.3.0
Avancement Global
| Version | Description | Statut | Tests |
|---|---|---|---|
| v0.2–v0.9 | Base → Backend | ✅ | — |
| v1.0 | Production (lifespan, CI/CD) | ✅ | 28/28 |
| v1.1 | Pages & Sidebar Notion | ✅ | — |
| v1.2 | Éditeur Notion (slash menu, blocs) | ✅ | — |
| v1.3 | Database Concept (collections) | ✅ | 34/34 |
| v1.4 | Propriétés Avancées (21 types) | ✅ | 38/38 |
| v1.5 | Relations, Rollups, Formulas | ✅ | 43/43 |
| v1.6 | Vues (Calendar, Gallery, List, Timeline) | ✅ | 49/49 |
| v1.7 | Vues Améliorées (view config, save-as) | ✅ | — |
| v1.8 | Sub-items & Dépendances | ✅ | 56/56 |
| v1.9 | My Tasks Dashboard | ✅ | 60/60 |
| v2.0 | Multi-User + Editor Complete | ✅ | 67/67 |
| v2.1 | Public API, Webhooks, PWA | ✅ | 73/73 |
| v2.2 | Share/Publish, Favorites, Library | ✅ | 73/73 |
| v3.0 | Auth locale, Multi-Forge, Standalone | ✅ | — |
| v4.x–v5.x | MVP → Agent IA, palette, automations, import, calendrier, wiki-links, synced blocks | ✅ | 523+ |
| v6.0–v6.3 | PWA offline, permissions granulaires, web clipper, API publique v2 | ✅ | 668+ |
| v6.4.0 | Realtime production (merge 3-voix, broadcast non bloquant) | ✅ | 749+ |
| v6.5.0–v6.5.1 | Synced blocks production (databases/vues) + webhooks v2 complets | ✅ | 749 |
| v6.6.0 | Agent phase 5 — API publique agent & skill marketplace | ✅ | 764+ |
| v6.7.0 | SSO / SAML + OIDC entreprise (Enterprise Auth) | ✅ | 802 |
| v6.8.0 | Sites multi-pages + Forms publics (doc) | ✅ | 20 |
| v6.9.0 | Recherche hybride + Ask AI RAG (doc) | ✅ | 24 |
| v7.0.0 | Automations multi-étapes + Workers lite (doc) | ✅ | 31 |
| v7.1.0 | Calendar sync + Meeting Notes (doc) | ✅ | 15 |
| v7.2.0 | SCIM + 2FA + Audit UI + gouvernance agents (doc) | ✅ | 52 |
| v7.3.0 | Teamspaces + Verified + Polish + follow-ups (doc) | ✅ | 72 |
Suites de régression :
test_v72_enterprise.py(52) +test_v73_wiki_polish.py(72) = 124 verts · suite complète-n auto= 1016 passed. Follow-ups v7.3 livrés (voir § v7.3.0 duROADMAP.md): sidebar par teamspace, chartsnumber/multi-DB, notifpage.updatedaux followers, unfurlgitea:/github:, page Settings → Audit — + 21 casses SSO corrigées (installpython3-saml/authlib).
Blocs Complétés
| Bloc | Features | Statut |
|---|---|---|
| Bloc 1 | Database Concept | ✅ 6/6 |
| Bloc 2 | Propriétés Avancées | ✅ 14/14 |
| Bloc 3 | Vues Manquantes | ✅ 10/10 |
| Bloc 4 | Sub-items & Dépendances | ✅ 7/7 |
| Bloc 5 | My Tasks | ✅ 7/7 |
| Bloc 6 | Éditeur Complet | ✅ 8/8 |
| Bloc 7 | Fonctions Transversales | ✅ |
Total: 52/52 features (100%)
Architecture
Tables (21)
users, user_tokens, boards, cards, notes, col_mapping, checklists, checklist_items, project_properties, property_values, ai_keywords, pages, collections, collection_pages, collection_views, collection_properties, workspaces, workspace_members, comments, page_history, favorites, database_templates, page_templates, webhook_subscriptions
Routeurs (11)
dashboard, board, notes, api, auth, webhooks, collections, my_tasks, workspace, public_api + app-level routes
Services (6)
GiteaClient, FormulaEngine, RollupEngine, GiteaBoardCompat, property_types, webhook_outbound
Endpoints (85+)
CRUD collections/pages, 5 vues HTML, relations/rollups/formulas, sub-items/dependencies, my-tasks, workspaces, comments, history, favorites, templates, CSV import/export, public sharing, public API v1, webhooks, PWA manifest
Stack
- Backend: Python 3.12 + FastAPI + httpx
- Frontend: Jinja2 + HTMX + Alpine.js + SortableJS + CSS 31KB
- BDD: SQLite WAL mode, 21 tables, foreign keys ON
- Auth: OAuth2 Gitea + sessions signed (itsdangerous) + token API
- Déploiement: Docker (python:3.12-slim), docker-compose, port 8080
- Tests: pytest, 764+ tests, TestClient avec SQLite temporaire
- CI/CD: Gitea Actions (.gitea/workflows/ci.yml)