etalon
|
f87b954f27
|
feat: atomization pipeline with job queue, atomizer client, WS hub, and board UI (phase 7)
- internal/extsvc: circuit breaker (§11.16) + retrying bearer JSON client
- atomizer client: §5.1 contract incl. defensive coefficient normalization
and extension coefficient range (0,2]
- persisted jobs collection: atomic claim, panic recovery, exponential
backoff (max 3), stale-running requeue, shutdown-safe bookkeeping
- subdivide (async 202, atomizing status, re-run replaces unpublished
children after confirm) and extend (sibling task, source budget)
- failure path reverts status and notifies the consultant on final attempt
- PATCH task editing with bounty recompute, budget cascade to descendants
- publish single + bulk; task detail endpoint role-scoped
- coder/websocket hub: multiplexed channels, origin check, 30s heartbeats;
client ws.js with reconnect + 15s polling fallback
- consultant atomization board: tree by root, coefficient sliders with live
per-parent sum indicator, bounty preview, modals, shimmer, atomizer-down
gating via /api/v1/service-health
- fix: tasks external-ref unique index is partial, not sparse (compound
sparse indexed every task through customerId and broke child inserts)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
2026-06-12 19:17:09 +02:00 |
|
etalon
|
c1cc781279
|
feat: authentication with local accounts, sessions, CSRF, RBAC, and OIDC PKCE (phase 3)
- argon2id (t=3, m=64MiB, p=2) PHC hashing honoring embedded params
- token-bucket rate limiting (10/15min per IP+email) on login/register
- opaque 32B session tokens in Mongo, 30-day sliding expiry, logout-all
- CSRF double-submit cookie/header on authenticated mutations
- bootstrap admin from env with forced first-login password change
- requireAuth/requireRole middleware with disabled-account enforcement
- OIDC code flow with PKCE: lazy discovery, account linking only on
verified email, auto-created developer accounts
- unit tests (RBAC matrix, CSRF, password, rate limiter) + integration
suite covering the full auth matrix incl. an in-test fake IdP
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
2026-06-12 18:31:25 +02:00 |
|
etalon
|
f2c534f636
|
feat: store layer with indexes, optimistic concurrency, GridFS, credential crypto (phase 2)
- mongo-driver v2 connection with bounded startup retry + /readyz gate
- idempotent creation of all §4.9 indexes
- UpdateVersioned: version-filtered updates, conflict vs not-found errors
- AES-256-GCM Seal/Open for ticketing credentials, base64(nonce|ct)
- GridFS file store: MIME sniffing, MAX_UPLOAD_MB cap, sha256 metadata
- HMAC-signed short-lived file URL tokens (§5.1, 1h TTL)
- integration tests against compose Mongo via docker-compose.test.yml overlay
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
2026-06-12 18:17:26 +02:00 |
|