Commit Graph
1068 Commits
Author SHA1 Message Date
saltbo b7f7fa7ecd feat(admin): implement operations dashboard stats 2026-07-09 23:34:03 -04:00
saltbo 983a5540bd refactor(admin): focus overview on operations dashboard 2026-07-09 23:34:03 -04:00
saltbo 554c231536 feat(admin): redesign dashboard with pro analytics 2026-07-09 23:34:03 -04:00
saltbo a5cc581586 test(quotas): avoid session org recreation in no-org case 2026-07-09 23:16:53 -04:00
saltbo 77aa770ed5 fix(workspaces): standardize workspace names and slugs
Use metadata-aware personal workspace detection across org repositories and UI, generate personal/team slugs with the new default random rules, and remove user-managed team slug fields.

Encode WebDAV path segments consistently so Finder follows workspace names such as Ambor's Space via %27 instead of XML-escaped apostrophes.
2026-07-09 01:00:03 -04:00
saltbo 9c93b993e9 fix(webdav): improve Finder compatibility 2026-07-09 00:19:56 -04:00
saltbo ccdab7814d docs: update roadmap for analytics cli and sync 2026-07-08 23:24:31 -04:00
saltbo 10748cd018 chore(lsp): configure language server support 2026-07-05 00:48:20 -04:00
agent-kanban[bot]andMarina Zhou 556174f681 feat(admin): add team activity tab (#498)
Agent-Profile: https://agent-kanban.dev/agents/d6a28cf7-3f68-4659-abe1-8d880c0c7a4c

Co-authored-by: Marina Zhou <marina-zhou@mails.agent-kanban.dev>
2026-07-04 23:01:26 -04:00
agent-kanban[bot]andNoah Reed 7ccaba2f8b feat: refine admin audit filtering (#495)
* feat: refine admin audit filtering

Agent-Profile: https://agent-kanban.dev/agents/b0abe6cd7aeba133

* test: add audit filter spec scenarios

Agent-Profile: https://agent-kanban.dev/agents/b0abe6cd7aeba133

* chore: refresh openapi client

Agent-Profile: https://agent-kanban.dev/agents/b0abe6cd7aeba133

---------

Co-authored-by: Noah Reed <noah-reed@mails.agent-kanban.dev>
2026-07-04 10:21:45 -04:00
dependabot[bot] bc15bc3617 chore(deps): bump golang.org/x/net (#496)
Bumps the go_modules group with 1 update in the /cmd directory: [golang.org/x/net](https://github.com/golang/net).


Updates `golang.org/x/net` from 0.52.0 to 0.55.0
- [Commits](https://github.com/golang/net/compare/v0.52.0...v0.55.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-version: 0.55.0
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-04 01:31:26 -04:00
agent-kanban[bot]andNoah Reed 02eda6dfec feat: add admin user activity feed (#493)
Closes #491

Agent-Profile: https://agent-kanban.dev/agents/b0abe6cd7aeba133

Co-authored-by: Noah Reed <noah-reed@mails.agent-kanban.dev>
2026-07-03 01:51:24 -04:00
Marina Zhou d7454a61fb fix(admin): keep user filter mounted during loading
Agent-Profile: https://agent-kanban.dev/agents/342b6de3-a2e2-44ff-8e5f-9fb378d368f2
2026-07-02 19:15:45 -04:00
agent-kanban[bot] a6ee3bc553 fix: preserve admin user search focus
Closes #485
2026-07-02 17:37:27 -04:00
Noah Reed 63ceeab678 fix: stabilize webdav traffic integration fixture
Agent-Profile: https://agent-kanban.dev/agents/b0abe6cd7aeba133
2026-07-02 02:54:40 -04:00
AncientTree 2608441fca Change deploy command to use 'pnpm run deploy'
部署命令失败

Signed-off-by: AncientTree <thexecutioner@163.com>
2026-07-02 00:52:59 -04:00
saltbo 964e25329e test(downloads): document task events scenario 2026-06-29 21:11:41 -04:00
saltbo 3695c80c2e feat(downloads): add task event timeline 2026-06-29 21:07:00 -04:00
saltbo 74c0d0cd75 fix(downloader): report aria2 metadata runtime 2026-06-29 20:19:46 -04:00
saltbo 979afd20e7 style(downloader): format client tests 2026-06-29 17:45:34 -04:00
saltbo 3fdc7b4ae0 refactor(downloader): reorganize cmd downloader runtime 2026-06-29 17:42:24 -04:00
saltbo 26b7a1d8a4 fix(downloader): preserve failed upload results for retry 2026-06-29 12:08:25 -04:00
saltbo 2c0cdd8a63 fix(downloader): prevent aria2 session auto-restore 2026-06-27 01:42:32 -04:00
saltbo 02fb68beea test(downloads): claim upload task via heartbeat 2026-06-27 01:25:23 -04:00
saltbo 2bbe50a8d5 test(downloader): add multi-status listing spec 2026-06-27 01:18:39 -04:00
saltbo cf7b1de112 fix(downloader): consolidate polling into heartbeat 2026-06-27 01:16:12 -04:00
saltbo 5f20ae2780 fix(storage): align custom host preview 2026-06-24 20:35:08 -04:00
saltbo b4ea0a575a fix(storage): handle empty provider values 2026-06-24 20:21:11 -04:00
saltbo c55f6f460c chore(openapi): update generated storage client 2026-06-24 17:51:19 -04:00
saltbo 9acbc011ed feat(storage): add provider presets and request preview 2026-06-24 17:47:34 -04:00
saltbo 2e58e8edca style(admin): narrow oauth provider column 2026-06-24 15:37:00 -04:00
saltbo c5f2b87935 fix(e2e): seed storage without title column 2026-06-24 15:21:28 -04:00
saltbo 4cdcd29cd6 refactor(admin): compact oauth providers table 2026-06-24 15:08:24 -04:00
saltbo 3f6751d60c chore(openapi): update generated downloader client 2026-06-24 14:59:54 -04:00
saltbo 22e8164e9b refactor(admin): merge downloader settings drawers 2026-06-24 14:55:05 -04:00
saltbo e55dae3d2f refactor(admin): standardize management forms 2026-06-24 14:50:08 -04:00
agent-kanban-local[bot]andJordan Park 5b385faf01 refactor(admin): unify remaining admin headers and drawers (#481)
Agent-Profile: https://agent-kanban.dev/agents/025f2feb-009e-42c3-a7ec-242ffcddfe15

Co-authored-by: Jordan Park <jordan-park@mails.agent-kanban.dev>
2026-06-24 12:28:38 -04:00
saltbo fb2281f1b3 fix(downloader): clean local data only on task delete 2026-06-24 11:12:31 -04:00
agent-kanban-local[bot]andJordan Park f41ed27bba [codex] separate billing configuration (#479)
* feat(admin): separate billing configuration

Add dedicated storage egress and downloader credit billing contracts, usecases, RPC wrappers, drawers, generated client updates, and coverage.

Agent-Profile: https://agent-kanban.dev/agents/2673e70e0085f4e0

* fix(billing): preserve not found ordering

Check storage and downloader existence before quota_store gating in dedicated billing usecases, and cover enabled missing-resource requests at usecase and route levels.

Agent-Profile: https://agent-kanban.dev/agents/2673e70e0085f4e0

---------

Co-authored-by: Jordan Park <jordan-park@mails.agent-kanban.dev>
2026-06-24 05:57:10 -04:00
agent-kanban-local[bot]andJordan Park 82c5452782 feat(auth): move OAuth provider editor to drawer (#480)
Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

Co-authored-by: Jordan Park <jordan-park@mails.agent-kanban.dev>
2026-06-24 05:55:26 -04:00
agent-kanban-local[bot]andJordan Park 7cfbbf77b7 fix: clean downloader terminal artifacts (#477)
* fix: clean downloader terminal artifacts

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

* test: tolerate stale cloud license cleanup

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

* test: retry transient pairing poll failures

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

* fix: make suspended downloader cleanup idempotent

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

---------

Co-authored-by: Jordan Park <jordan-park@mails.agent-kanban.dev>
2026-06-24 03:14:38 -04:00
agent-kanban-local[bot]andJordan Park 470a2d7e12 feat: add admin form primitives (#478)
* feat: add admin form primitives

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

* fix: preserve admin form label associations

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

* chore: retry e2e checks

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

* test: tolerate cloud license cleanup races

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

* chore: retry cf e2e

Agent-Profile: https://agent-kanban.dev/agents/57ed5bcf43079e29

---------

Co-authored-by: Jordan Park <jordan-park@mails.agent-kanban.dev>
2026-06-24 03:14:15 -04:00
agent-kanban-local[bot]andJordan Park 26c660854a fix: restore preview admin credential repair (#476)
Agent-Profile: https://agent-kanban.dev/agents/2673e70e0085f4e0

Co-authored-by: Jordan Park <jordan-park@mails.agent-kanban.dev>
2026-06-24 01:17:35 -04:00
agent-kanban-local[bot]andJordan Park c7f3d11793 [codex] Add admin storage connection testing (#475)
* feat(storage): add admin connection testing

Agent-Profile: https://agent-kanban.dev/agents/2673e70e0085f4e0

* fix: correct storage CORS guidance

Agent-Profile: https://agent-kanban.dev/agents/2673e70e0085f4e0

---------

Co-authored-by: Jordan Park <jordan-park@mails.agent-kanban.dev>
2026-06-24 00:37:59 -04:00
f4b65e4987 feat: make forcePathStyle configurable per storage (#474)
* feat: make forcePathStyle configurable per storage

Previously hardcoded to true, which breaks S3-compatible backends that require
virtual-hosted-style addressing (e.g. Alibaba Cloud OSS). Now configurable via
admin storage settings with a toggle switch, defaulting to true for backwards
compatibility.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* test: cover storage force path style

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: saltbo <saltbo@foxmail.com>
2026-06-23 20:46:33 -04:00
Jasper VanandClaude Opus 4.8 f701f4139a fix(security): resolve CodeQL code-scanning alerts (#472)
Clears all 23 open CodeQL alerts:

- actions/missing-workflow-permissions (19, medium): add a top-level
  least-privilege `permissions: contents: read` to ci.yml and the 7
  deploy workflows. The one CI job that needs `packages: write` already
  declares its own block; all deploys authenticate via static secrets
  (no OIDC / id-token, no repo writes), so read is sufficient.

- js/insecure-randomness (1, high): `genPassword()` built share
  passwords with Math.random(); switch to crypto.getRandomValues() over
  the same unambiguous alphabet (length/charset/uniqueness preserved).

- js/incomplete-url-substring-sanitization (2, high): two test fetch
  stubs routed on `String(url).includes('api.github.com')`; tighten to
  `new URL(url).hostname === 'api.github.com'` — precise and no longer
  flagged.

- js/stack-trace-exposure (1, medium): the E2E S3 mock echoed
  error.message in 500 responses; log server-side and return a generic
  body instead.

Verified: typecheck green; share-dialog/changelog/system.integration
tests pass.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 13:39:28 -04:00
Jasper VanandClaude Opus 4.8 076af957c8 Create SECURITY.md for security policy (#471)
* Create SECURITY.md for security policy

Added a security policy document outlining supported versions and vulnerability reporting.

Signed-off-by: Jasper Van <saltbo@foxmail.com>

* docs: fill in real SECURITY.md policy for ZPan

Replace the GitHub default template (placeholder 5.x/4.x versions and
boilerplate) with an actual policy: supported 2.x versions, private
vulnerability reporting via GitHub Security Advisories, and response-time
expectations.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: saltbo <saltbo@foxmail.com>

* docs: express supported versions relative to latest release

Avoid pinning a concrete minor (2.7.x) that goes stale on every release.
ZPan ships fixes forward on a single release train and does not backport,
so 'latest release only' is both accurate and zero-maintenance.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: saltbo <saltbo@foxmail.com>

---------

Signed-off-by: Jasper Van <saltbo@foxmail.com>
Signed-off-by: saltbo <saltbo@foxmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 13:25:05 -04:00
Jasper VanandClaude Opus 4.8 e5ab6797ad chore(deps): pin @esbuild-kit's esbuild to 0.25.12 to clear dev-server CVE (#470)
Resolve Dependabot alert #36 (esbuild <= 0.24.2, medium): "esbuild enables
any website to send any requests to the development server and read the
response."

The vulnerable esbuild 0.18.20 was dragged in transitively by drizzle-kit's
deprecated @esbuild-kit/esm-loader → @esbuild-kit/core-utils (both "Merged
into tsx"). drizzle-kit 0.31.10 — the latest — still declares the legacy
loader even though it now uses tsx, so bumping drizzle-kit can't fix it.

Scoped pnpm override forces only @esbuild-kit/core-utils>esbuild to 0.25.12
(already resolved in the tree via drizzle-kit's own esbuild ^0.25.4), so it
dedups to a single version and leaves vite/tsup/vitest esbuild untouched.

Verified: drizzle-kit `db:generate` loads the TS config + full schema and
exits 0 with no spurious migrations; typecheck and production build green.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 13:15:30 -04:00
Jasper VanandClaude Opus 4.8 582d869408 chore(deps): bump nodemailer 8→9.0.1 and undici 7.24.8→7.28.0 (security) (#469)
Resolve Dependabot security alerts:

- nodemailer (high): the message-level `raw` option bypassed
  disableFileAccess/disableUrlAccess (arbitrary file read + SSRF). Our
  email gateway only sends `html` over an SMTP transport (no `raw`, no
  remote attachment fetching, no OAuth2/proxy), so neither the vuln nor
  the 9.0 TLS-cert-validation breaking change affects our usage.

- undici (3 high / 2 med / 2 low): the override pinned undici at 7.24.8
  (a leftover dedup pin from the pnpm migration, not a real constraint).
  Bump it to 7.28.0; consumers (jsdom/vitest/better-auth/miniflare/
  wrangler) all accept ^7, so it dedups to a single patched version.

Verified: typecheck, 4347 unit/integration + 59 CF Workers tests, and a
production vite build all green.

Supersedes #458.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 12:56:41 -04:00
saltboandClaude Opus 4.8 407e4ac803 refactor(s3): drop dead getPublicUrl gateway method
No callers remain after select('public') was removed in #456 — the
public-bucket flow is gone, so the gateway method, its port declaration
and its tests are dead code.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 10:53:30 -04:00