etalon
c69c028028
feat: seed script, forgot-password, hover cards, shortcuts, OpenAPI docs, runbook (phase 12)
...
- scripts/seed.go: idempotent demo data per §11.11 (make seed)
- forgot/reset password: SMTP-gated, one-shot TTL tokens, uniform responses
against enumeration, sessions revoked on reset; login page link + pages
- profile hover cards on [data-user-card] elements (§11.13)
- keyboard shortcuts: g b/m/t/h navigation, / focuses search (§10)
- bulk archive endpoint (§11.9)
- hand-written OpenAPI 3.1 covering §6, served at /api/docs + yaml download
- make backup / make restore (mongodump archive via the mongo container)
- README: quick start, demo data, runbook, breaker/job operations, working
Caddy + nginx reverse-proxy samples (WS block, client_max_body_size),
documented later-stubs (§11.24)
- smoke.sh now exercises register → logout → login → me → board → pages
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-06-12 20:39:38 +02:00
etalon
70a813edfa
feat: bounty board, task lifecycle, AI work performer flow, notifications (phase 8)
...
- whitelist HTML sanitizer (stdlib tokenizer) with XSS vector tests
- developer board: pool-scoped visibility, customer/search/minBounty/sort
filters, stale-task age badges, competing-claims visibility setting,
saved filters in profile extras
- claims: request/withdraw (developer), approve/decline (consultant) with
notifications to winners and losers; unassign/abandon back to board
- work tracking: start, sanitized comments with @mention notifications,
time logging, submit for review
- review queue + review with per-AC checklist stored on the timeline;
approve writes the immutable bountyAwards row (human assignees only)
- assign-to-AI: §5.2 job submission, HMAC-verified callback endpoint,
idempotent by jobId, artifacts downloaded into GridFS, failure path
keeps the task assigned with timeline + notification
- notifications API + bell with unread badge, dropdown, page, WS toasts
- pages: bounty board, my-tasks kanban, task detail (role-driven actions,
review dialog, AI dialog), review queue, developer pool
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-06-12 20:11:05 +02:00
etalon
34bf5b5ac2
feat: base UI shell with themes, auth pages, profile, and role navigation (phase 4)
...
- embedded Go templates + vanilla ES-module JS + hand-written CSS, no build step
- exact §10 beige light / dark design tokens, square edges (radius 2px),
system font stack, visible focus rings
- theme toggle persisted to localStorage and the user profile
- login/register/change-password pages wired to the auth API
- profile page: avatar upload (image-sniffed, old file cleanup), bio,
contacts, arbitrary extra key/value fields, optimistic-concurrency 409
- role-based top navigation with placeholders for later-phase areas
- GET /files/{id} with scope-based access (session) or signed token (§5.1)
- security headers incl. CSP without unsafe-inline scripts
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-06-12 18:39:38 +02:00