- Themes: add neon (cyber gradient), terminal (green CRT), blueprint (graph
paper) and sunset (vaporwave) alongside the default Light (Y2K paper) and
Dark. Theme toggle now cycles all; profile selector lists them; server
validates against a shared whitelist.
- Bounty cards now show the project (customer) name.
- Remove the celebratory emoji from the empty Review Queue.
- Full-width h1 underline rule; My Tasks columns stack vertically for more
room per task; card action buttons wrap/right-align so they never overflow.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- theme rework (user request): white paper bg, brown ink, ordered-dither
halftone textures, hard offset Y2K shadows, dithered masthead bands;
dark theme matched; token test + DECISIONS updated
- fix: .card + .card stacking margin leaked into grid layouts, shifting
every card except the first (the 'always the first item' reports)
- fix: CSP style-src 'self' silently dropped every inline style attribute
(misaligned save button, stat values, editor attach button, bell badge);
styles now allow inline, scripts remain strict per §12
- fix: [hidden] is now display:none !important so flex containers cannot
defeat it (chat panel/footers)
- board + metrics filters live in boxed .toolbar rows with baseline-aligned
controls; metric stat cards use a uniform .stat layout
- new-conversation dialog: fixed 440px width and 180px results list (no
more resizing while searching), full-width result rows, picked people
drop out of the list
- floating messages bubble bottom-right on all pages (except /messages):
unread badge, mini panel with conversation list, thread view, quick
composer, live WS updates; toasts moved up to clear it
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- embedded Go templates + vanilla ES-module JS + hand-written CSS, no build step
- exact §10 beige light / dark design tokens, square edges (radius 2px),
system font stack, visible focus rings
- theme toggle persisted to localStorage and the user profile
- login/register/change-password pages wired to the auth API
- profile page: avatar upload (image-sniffed, old file cleanup), bio,
contacts, arbitrary extra key/value fields, optimistic-concurrency 409
- role-based top navigation with placeholders for later-phase areas
- GET /files/{id} with scope-based access (session) or signed token (§5.1)
- security headers incl. CSP without unsafe-inline scripts
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>