Sync with upstream - #3
Merged
Merged
Conversation
* Add shutdown announcement Signed-off-by: Artem Savchenko <armisav@gmail.com> * Update notice and move to header Signed-off-by: Artem Savchenko <armisav@gmail.com> * Update announcement Signed-off-by: Artem Savchenko <armisav@gmail.com> --------- Signed-off-by: Artem Savchenko <armisav@gmail.com>
Signed-off-by: Alexander Onnikov <Alexander.Onnikov@xored.com>
Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
* Add backup download button Signed-off-by: Artem Savchenko <armisav@gmail.com> * Fix formatting Signed-off-by: Artem Savchenko <armisav@gmail.com> --------- Signed-off-by: Artem Savchenko <armisav@gmail.com>
…n process-resources (#10936) Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
… (#10924) - billing-assets: add 33 missing Polish translations (file management, storage limits, plan restrictions) - contact-assets: add missing Timezone translation Polish translation completeness: 4101/4135 -> 4135/4135 (100%) Signed-off-by: Toni Nowak <acidkill@users.noreply.github.com> Co-authored-by: Toni Nowak <acidkill@users.noreply.github.com>
Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
* Update shutdown announcement Signed-off-by: Artem Savchenko <armisav@gmail.com> * Update readme Signed-off-by: Artem Savchenko <armisav@gmail.com> --------- Signed-off-by: Artem Savchenko <armisav@gmail.com>
Signed-off-by: Artem Savchenko <armisav@gmail.com>
…els and UI components (#10940) Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
* Fix backup clean blobs issue Signed-off-by: Andrey Sobolev <haiodo@gmail.com> * Restore accounts Signed-off-by: Andrey Sobolev <haiodo@gmail.com> * Allow skip queue for backup-restore Signed-off-by: Andrey Sobolev <haiodo@gmail.com> * Fix backup of wrong social ids Signed-off-by: Andrey Sobolev <haiodo@gmail.com> * Filter backup logs Signed-off-by: Andrey Sobolev <haiodo@gmail.com> * Fix doRestoreWorkspace signature after accounts-restore port The 'Restore accounts' cherry-pick updated the workspace-service restore call site to pass accountsDbUrl/accountsDbNs through to doRestoreWorkspace, but doRestoreWorkspace itself was never updated to accept them (this mismatch existed in the upstream fork too and only surfaced once types were rebuilt). Extend doRestoreWorkspace to open an AccountDB from the given URL/ns, mirroring the existing doBackup pattern, and thread it into restore() so the automatic workspace-service restore flow can also restore accounts, not just the manual dev-tool CLI restore. Signed-off-by: Artyom Savchenko <armisav@gmail.com> --------- Signed-off-by: Andrey Sobolev <haiodo@gmail.com> Signed-off-by: Artyom Savchenko <armisav@gmail.com> Co-authored-by: Andrey Sobolev <haiodo@gmail.com>
Signed-off-by: Artem Savchenko <armisav@gmail.com>
…… (#10941) * feat: implement reference versioning functionality across various components and plugins Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com> * fix: simplify provider function calls and label retrieval in MentionPopup component Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com> * refactor: improve readability of version selection and reference handling in MentionVersionPopup and reference.ts Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com> * feat: add CardReferenceObjectProvider and integrate into card model and resources Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com> --------- Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
…… (#10944) * feat: add OnExecutionDone trigger and related functionality for process management Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com> * Fix Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com> --------- Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
Signed-off-by: Artyom Savchenko <armisav@gmail.com>
Signed-off-by: Artyom Savchenko <armisav@gmail.com>
…uild (#10948) Signed-off-by: Artyom Savchenko <armisav@gmail.com>
The desktop preload script explicitly overrides serverConfig.MODEL_VERSION with the value baked into the desktop binary at build time. This causes the "New version is available" dialog to fire for self-hosted users whenever desktop CI builds from a different commit than the server image (i.e., when v* and s* tags diverge in version.txt). Use the server's authoritative MODEL_VERSION instead, falling back to the bundled value when the server does not report one. Signed-off-by: Shannon Kerr <shannon@exaviz.com> Co-authored-by: Artyom Savchenko <armisav@gmail.com>
Signed-off-by: Artyom Savchenko <armisav@gmail.com>
This reverts commit 5bda0e7.
Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
Signed-off-by: Artyom Savchenko <armisav@gmail.com>
Signed-off-by: Artyom Savchenko <armisav@gmail.com>
Signed-off-by: Artyom Savchenko <armisav@gmail.com>
Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
…s components (#10957) Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
…itor to prevent rendering issues (#10958) Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
* Allow to export documents without children Signed-off-by: Artem Savchenko <armisav@gmail.com> * Fix tests Signed-off-by: Artem Savchenko <armisav@gmail.com> --------- Signed-off-by: Artem Savchenko <armisav@gmail.com>
* feat: Add ability to schedule notifications Signed-off-by: Artem Savchenko <armisav@gmail.com> * Clean up Signed-off-by: Artem Savchenko <armisav@gmail.com> * Clean up Signed-off-by: Artem Savchenko <armisav@gmail.com> * Add docker file Signed-off-by: Artem Savchenko <armisav@gmail.com> * Rename pod Signed-off-by: Artem Savchenko <armisav@gmail.com> * Add debug logging Signed-off-by: Artem Savchenko <armisav@gmail.com> * Reminder fixes Signed-off-by: Artem Savchenko <armisav@gmail.com> * Fix reminders Signed-off-by: Artem Savchenko <armisav@gmail.com> * Support reminders for all events Signed-off-by: Artem Savchenko <armisav@gmail.com> * Clean up Signed-off-by: Artem Savchenko <armisav@gmail.com> * Support for project todo Signed-off-by: Artem Savchenko <armisav@gmail.com> * Fix mismatched dependency Signed-off-by: Artem Savchenko <armisav@gmail.com> * Use base event class Signed-off-by: Artem Savchenko <armisav@gmail.com> --------- Signed-off-by: Artem Savchenko <armisav@gmail.com>
Signed-off-by: Artyom Savchenko <armisav@gmail.com>
Signed-off-by: Alexander Onnikov <Alexander.Onnikov@xored.com>
Signed-off-by: Alexander Onnikov <Alexander.Onnikov@xored.com>
…version bump (#10851) * feat(tracker): add Gantt scheduling schema (startDate + IssueRelation) Schema-only foundation for the upcoming Gantt-chart view in tracker. No UI in this PR. Changes: - Issue.startDate: Timestamp | null (interface + IssueDraft + @prop with @Index) - Milestone.startDate: Timestamp | null (interface + @prop, reusing the existing tracker.string.StartDate IntlString) - New DependencyKind type ('finish-to-start' | 'start-to-start' | 'finish-to-finish' | 'start-to-finish') - New IssueRelation AttachedDoc class with kind: DependencyKind, signed lag: number — registered in models/tracker via TIssueRelation - 7 new IntlString keys: IssueStartDate, GanttDependency, GanttDependency{FinishToStart,StartToStart,FinishToFinish,StartToFinish}, GanttLag — all 13 locales updated - Cross-plugin literal updates in importer + github sync to satisfy the new required Issue.startDate / Milestone.startDate fields: - packages/importer/src/importer/importer.ts: AttachedData<Issue> literal - services/github/pod-github/src/sync/issueBase.ts: 'startDate' added to GithubIssueData Omit list (github sync does not own scheduling) - services/github/pod-github/src/sync/issues.ts + pullrequests.ts: AttachedData<Issue|GithubPullRequest> literals Out of scope (deferred to follow-up PRs): - UI for Gantt view, drag/resize, dependency editor, critical path - blockedBy → IssueRelation migration (ships atomically with the writer redirect in the dependency-UI PR) - LinkIssues permission (tracker uses forbid-style permissions; needs maintainer discussion) - Activity-feed wiring for IssueRelation (needs a producer to test against) - IssueTemplate.startDate (template propagation semantics undecided) Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * test(model-tracker): add migrateAddStartDate jest tests 3 tests covering migrateAddStartDate: - writes startDate=null to Issues in DOMAIN_TASK with the right filter - writes startDate=null to Milestones in DOMAIN_TRACKER with the right filter - issues exactly two update calls (one per class) Follows the MigrationClient mock pattern from models/chat/src/__tests__/migration.test.ts. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * feat(model-tracker): add migrateAddStartDate + wire into trackerOperation Backfills startDate=null on existing Issues (DOMAIN_TASK) and Milestones (DOMAIN_TRACKER) so the new schema field has a defined value on every pre-existing document. Idempotent via the standard tryMigrate state-key mechanism (state: 'gantt-add-startdate'). Verified domain choices against existing migration helpers: - migrateIdentifiers / passIdentifierToParentInfo use DOMAIN_TASK for Issues (lines 145, 161 in this file). - TMilestone @model decorator confirms DOMAIN_TRACKER for Milestones (models/tracker/src/types.ts:372). Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * feat(tracker): expose Issue.startDate / Milestone.startDate in UI; tighten typing UI changes (so the new schema fields are actually editable, in chronological order Start → Due/Target): - New StartDateEditor.svelte (mirrors DueDateEditor.svelte for startDate) - ControlPanel: render Start Date row above Due Date row in the issue side panel; both always-visible (no `!== null` guard) so users can set them on issues that don't have a date yet - NewMilestone form: Start Date input above Target Date input - Milestone list view: Start Date column before Target Date column - TIssueRelation: tighten interface to `extends AttachedDoc<Issue, 'relations'>` so attachedTo + collection are statically typed. The model class re-declares `collection: 'relations'` to match the narrower base. - Drop 4 unused Dependency-kind IntlString keys (FinishToFinish, FinishToStart, StartToFinish, StartToStart) — they had no consumer in PR 1; will be re-introduced in PR 4 (dependency editor). - Simplify migration.ts comments — drop ageing line-references. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * fix(tracker): set explicit @prop ranks for Milestone date fields The DocAttributeBar side panel sorts attributes by attr.rank ?? toRank(_id) (see plugins/view-resources/src/components/ClassAttributeBar.svelte:42-47), so without explicit ranks the visible order on a Milestone was hash-based (startDate before Status, breaking the chronological flow the user expects). Set ranks so the side panel renders Status → Start date → Target date. Comments and attachments stay where they are (they're collections, filtered out of the attribute panel by categorizeFields). Issues are unaffected — the Issue side panel is the custom ControlPanel.svelte which renders Start date / Due date in explicit slots (see PR 1's UI commit). Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * fix(tracker-resources): EditMilestone renders Status/Start/Target in body in chronological order The right-side DocAttributeBar sorts attributes by attr.rank ?? toRank(_id), giving startDate before status (toRank('startDate') < toRank('status') lexicographically). Setting an explicit rank via @prop's third arg did not propagate through the workspace upgrade for existing Attribute documents in the model TX log — the rank made it into the bundled txes but the existing Attribute creation TXes are not replaced on upgrade-workspace. Pivot: render Status, Start date, Target date in the EditMilestone body in explicit chronological order, and add 'status', 'startDate', 'targetDate' to ignoreKeys so they don't appear duplicated in the side panel. This mirrors how Issue's ControlPanel.svelte handles its date fields. Reverts the no-op @prop rank attempt. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * fix(fulltext): bump model version to 0.7.423 to match deployed workspaces The fulltext-pod's compiled model version (baked into bundle/model.json via common/scripts/version.txt at build time) lags whenever the workspaces have been migrated to a newer patch but the pod was not rebuilt. In that state the indexer rejects every incoming Tx with a `wrong version` warning, new issues silently fail to land in Elasticsearch, and search returns empty results for any document created after the migration. Bumping `version.txt` aligns the compiled model with the workspaces. All future builds (front, transactor, workspace, tool, fulltext) will emit 0.7.423, the indexer accepts the Tx stream again, and the deferred backlog gets consumed automatically — no manual reindex needed. This commit is the build-side companion to the schema migration in this same PR. Without it the fulltext-pod cannot consume the migrated workspace's Tx events. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * chore: apply rush format after develop merge Resolves the failing formatting check requested by @ArtyomSavchenko in review of #10851 after the develop branch merge. Affects three files in our PR scope: - models/tracker/src/migration.ts: collapse short multi-line client.update call - plugins/tracker/src/index.ts: inline DependencyKind union + IssueRelation comment - plugins/tracker-resources/src/components/milestones/EditMilestone.svelte: reformat inline arrow handlers, move QueryIssuesList block ahead of <style> No logic changes; deterministic prettier output. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * test(tracker): fix milestone page-object selectors after startDate field addition The Gantt schema PR added Milestone.startDate, which: 1. Adds a second datetime-button to the NewMilestone form pool. The existing 'div.antiCard-pool button.datetime-button' locator matched both buttons and tripped Playwright's strict-mode check. Scope the target-date locator to .last() and add a sibling .first() helper for the start-date button. 2. Moves Status / Start date / Target date editors from the auto-generated side panel into EditMilestone's body (div.dates-row > div.date-cell > span.cell-label + <button>) in chronological order. The label span no longer has a sibling <div> wrapping the button — the button is a direct sibling. Switch the buttonStatus/buttonTargetDate XPath to following-sibling::button[1] and match the new class="cell-label" span. Add a buttonStartDate helper for the new editor row. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * test(tracker): shift buttonEstimation index after startDate row addition ControlPanel.svelte (issue side panel) now renders the Start date and Due date rows unconditionally — pre-PR the Due date row was conditional on issue.dueDate !== null and the Start date row didn't exist at all. Both new rows emit a <div><button> pair via DueDatePresenter, which the existing (//span[text()='Estimation']/../div/button)[3] XPath counts as extra matches and pushes the Estimation button from the 3rd to the 5th direct div/button under the popupPanel-body__aside-grid. Direct div/button order under the grid (document order): 1. CreatedBy (EmployeeBox > UserBox div > Button) 2. Assignee (AssigneeEditor div > Button) 3. Start date (NEW — StartDateEditor > DueDatePresenter div > button.datetime-button) 4. Due date (NEW — DueDateEditor > DueDatePresenter div > button.datetime-button) 5. Estimation (AttributeBarEditor div > Button) buttonAssignee at [2] is unchanged. textEstimation uses 'following-sibling::div[1]' (first sibling), which is unaffected by additions earlier in the grid. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * chore: apply rush format (prettier compliance for CI) CI's rush fast-format --branch develop step flagged tests/sanity/tests/model/tracker/milestones-details-page.ts for a missing blank line between the buttonTargetDate locator (introduced in 86b1c19) and the next field. Apply the local 'rush format' result. The two other files CI flagged (plugins/process-resources/src/components/settings/BindingsEditor.svelte and ImportSlotsPopup.svelte) were actually upstream changes from PR #10921 (Fix add tag) that landed after our last develop merge — the preceding merge of upstream/develop into this branch resolves those diffs. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> * fix(tests/tracker): use contains() for cell-label class to survive Svelte CSS scoping The Svelte 4 compiler appends a scoped `svelte-<hash>` class to every element matched by a component-local CSS selector. EditMilestone.svelte styles `.cell-label` locally, so each label span ends up as `<span class="cell-label svelte-XXXXX">` at runtime, not the bare `<span class="cell-label">` shipped in source. The previous XPath locator used strict `@class="cell-label"` and never matched. Switch buttonStatus / buttonStartDate / buttonTargetDate to the standard `contains(concat(' ', normalize-space(@Class), ' '), ' cell-label ')` class-match idiom so the locators tolerate the added scoped class. Verified against the playwright accessibility snapshot from the failed run (artifact playwright-results, hash 07a8f36b...md): the Status row renders as a generic with text 'Status' immediately followed by a button 'In progress' as the next direct sibling, matching the rest of the XPath. Fixes 5 milestone.spec.ts failures observed in run 27816114236: - Create a Milestone (locator timeout on checkIssue → buttonStatus) - Edit a Milestone (locator timeout on editIssue → buttonStatus.click) - Delete a Milestone (locator timeout on checkIssue → buttonStatus) plus their two retries each. Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> --------- Signed-off-by: Michael Uray <michaeluray@users.noreply.github.com> Co-authored-by: Michael Uray <michaeluray@users.noreply.github.com> Co-authored-by: Artyom Savchenko <armisav@gmail.com>
ArtyomSavchenko
pushed a commit
that referenced
this pull request
Jul 21, 2026
Backend blockers found during review of the office/video port: - rpc.ts (#1 broken access control, #2 modifiedBy spoofing): the six direct /api/v1/{create,addCollection,update,createMixin,updateMixin, remove} endpoints build their client via wrapPipeline(...,true), which runs as the system account and bypasses space/role/read-only checks. Gate them to system/service accounts (the only legitimate caller, e.g. the love service which connects with a system token). Regular clients must use the permission-checked /api/v1/tx path. This also stops non-system callers from spoofing modifiedBy. - guests.ts (#3 guest-token secret): sign/verify the guest platform token with the platform SECRET instead of the LiveKit API secret, so it validates against the transactor without conflating the two secrets. - transient.ts (#4 TransientMiddleware): clear the ttlChecker interval in a new close() override (timer leak); detect removes via tx._class (was tx.objectClass, never TxRemoveDoc, so removes re-added the object with a fresh TTL); delete expired entries from ttlObjectMap in checkTTL (map grew unbounded and re-broadcast every second). - FloorPreview.svelte (#9 committed debug scaffolding): remove the dev-only Debug/Clear-AI-Bot/Search-Accounts menu actions and their functions, which hardcoded personal emails and logged PII. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BZnVtCWH1hTH7EisaBdT7T
ArtyomSavchenko
added a commit
that referenced
this pull request
Jul 24, 2026
Backend blockers found during review of the office/video port: - rpc.ts (#1 broken access control, #2 modifiedBy spoofing): the six direct /api/v1/{create,addCollection,update,createMixin,updateMixin, remove} endpoints build their client via wrapPipeline(...,true), which runs as the system account and bypasses space/role/read-only checks. Gate them to system/service accounts (the only legitimate caller, e.g. the love service which connects with a system token). Regular clients must use the permission-checked /api/v1/tx path. This also stops non-system callers from spoofing modifiedBy. - guests.ts (#3 guest-token secret): sign/verify the guest platform token with the platform SECRET instead of the LiveKit API secret, so it validates against the transactor without conflating the two secrets. - transient.ts (#4 TransientMiddleware): clear the ttlChecker interval in a new close() override (timer leak); detect removes via tx._class (was tx.objectClass, never TxRemoveDoc, so removes re-added the object with a fresh TTL); delete expired entries from ttlObjectMap in checkTTL (map grew unbounded and re-broadcast every second). - FloorPreview.svelte (#9 committed debug scaffolding): remove the dev-only Debug/Clear-AI-Bot/Search-Accounts menu actions and their functions, which hardcoded personal emails and logged PII. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BZnVtCWH1hTH7EisaBdT7T Signed-off-by: Artem Savchenko <armisav@gmail.com>
ArtyomSavchenko
added a commit
that referenced
this pull request
Jul 24, 2026
Backend blockers found during review of the office/video port: - rpc.ts (#1 broken access control, #2 modifiedBy spoofing): the six direct /api/v1/{create,addCollection,update,createMixin,updateMixin, remove} endpoints build their client via wrapPipeline(...,true), which runs as the system account and bypasses space/role/read-only checks. Gate them to system/service accounts (the only legitimate caller, e.g. the love service which connects with a system token). Regular clients must use the permission-checked /api/v1/tx path. This also stops non-system callers from spoofing modifiedBy. - guests.ts (#3 guest-token secret): sign/verify the guest platform token with the platform SECRET instead of the LiveKit API secret, so it validates against the transactor without conflating the two secrets. - transient.ts (#4 TransientMiddleware): clear the ttlChecker interval in a new close() override (timer leak); detect removes via tx._class (was tx.objectClass, never TxRemoveDoc, so removes re-added the object with a fresh TTL); delete expired entries from ttlObjectMap in checkTTL (map grew unbounded and re-broadcast every second). - FloorPreview.svelte (#9 committed debug scaffolding): remove the dev-only Debug/Clear-AI-Bot/Search-Accounts menu actions and their functions, which hardcoded personal emails and logged PII. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BZnVtCWH1hTH7EisaBdT7T Signed-off-by: Artem Savchenko <armisav@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.