Repository navigation
chore(wiki-v2): promote #57 platform-admin entry seam onto the durable branch - #2
Merged
Merged
Conversation
Fork-owned, additive UI: features/admin-entry/AdminEntryLink self-gates on the platform's /admin/context (same-origin, cookie-auth) and surfaces a link to the standalone admin console at /console ONLY for a platform workspace admin. Advisory-only visibility gating — grants no Docmost capability; every console action is re-enforced server-side by the PDP, and the platform admin stays a non-privileged Docmost member. One-line seam in the authed app-header mounts it (documented as seam #17 in UPSTREAM_MODIFICATIONS.md). Co-Authored-By: Claude Opus 4.8 <[email protected]>
This was referenced Sep 2, 2026
PMQ9
added a commit
that referenced
this pull request
Sep 8, 2026
…ge, DTO validation, keyset hardening
All four round-justifying (non-blocking Level-3) findings from the 7-lens review, plus overlapping Level-2
robustness folded in while in the same files:
- [Testing L3 / DevOps L3] listByPage: give it opt-in {limit,before} keyset paging (consistent with the
members/ACL reads), and add service-attachment.pg.spec.ts — resolvePage + listByPage now execute on real
Postgres (a raw-sql column/table typo no longer ships green), and the paging keyset walks a shared-ms tie
with no skip / no duplicate.
- [Testing L3] Add dto-validation.spec.ts — the new class-validator DTOs (ContentSearchDto, ContentSortDto,
ContentCursorDto, ContentListDto incl. nested sort) now run through validate(), so dropping a constraint
(@Max/@IsUUID/@IsIn/@IsNotEmpty/@IsISO8601, …) reds a test.
- [Correctness L3] Add a real-Postgres walk for the generalized TIMESTAMP keyset (only title was walked) and
for value='' (null-title) as a mid-walk cursor bound.
- [Security F1 / Correctness #1 / Testing P2] A malformed keyset/cursor timestamp now 400s instead of
500-ing at the ::timestamptz cast: a shared isIsoInstant() guard (rejects Date.parse-lenient-but-PG-invalid
values like '2026') used by parseSubCollectionQuery and the content keyset builder.
- [Correctness #2] A text sort (title/name) now REQUIRES its cursor `value` (400) instead of silently
falling back to a timestamp `updatedAt` and paginating on the wrong boundary.
- [DevOps #3] Bump service-bridge.openapi.json version 1.1.1 → 1.2.0 (additive expansion).
Non-blocking Level ≤2 polish is deferred to a follow-up issue. Verified: nest build, 19 service-bridge suites
(179 tests), 3 real-Postgres pg specs (30 tests), eslint, import-boundary — all green.
Co-Authored-By: Claude Opus 4.8 <[email protected]>
This was referenced Sep 14, 2026
PMQ9
added a commit
that referenced
this pull request
Sep 17, 2026
… content write when Redis off (docmost#344) Two pre-existing content-write defects on the collaboration path, both found while tracing docmost#282 and both able to lose or silently drop a page's content. docmost#342 — a content `replace` emptied the Yjs fragment BEFORE building the new document from the request body. If `TiptapTransformer.toYdoc` threw (a body that passed `jsonToNode` but the Yjs transformer rejects), the connection's closing store persisted the emptied fragment: the page was WIPED while the request also failed. Build the new state first, then delete+apply — a conversion failure now aborts before any mutation and the original content survives. Shared by the ordinary `updatePageContent` handler and the docmost#282 conditional write. docmost#344 — custom collab events route only through the RedisSync extension, so with COLLAB_DISABLE_REDIS (single-node standalone) `handleYjsEvent('updatePageContent')` returned undefined and `PageService.update` ignored it: a REST/`/v1` content write returned 200 while persisting nothing. Fail that one un-routable write loudly instead. Narrowest boundary: the supported standalone mode still boots, interactive editing (direct Hocuspocus path) is untouched, and the docmost#282 seams keep their fail-closed `undefined` contract. Tests: build-before-delete leaves the fragment intact on a throwing toYdoc; the gateway guard throws for updatePageContent with Redis off, stays quiet for best-effort events, and routes normally with Redis on. UPSTREAM_MODIFICATIONS.md seams #2/#3 updated. Co-Authored-By: Claude Opus 4.8 <[email protected]>
Merged
10 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this promotes
Fast-forwards the fork's durable
wiki-v2branch to include the one #57 seam commit45f8960— afork-owned
features/admin-entry/AdminEntryLink+ a one-line mount in the authedapp-header.tsx.Why (merge ordering)
The wiki-v2 parent PR cccvu/wiki-v2#65 pins the
docmostsubmodule at45f8960. A DevOps review flaggedthat
.gitmodulesdeclaresbranch = wiki-v2while that SHA lived only on the feature branch — so this PRpromotes it onto
wiki-v2so the pin is reachable from the branch the parent declares (and survives feature-branch cleanup). This is a clean fast-forward (parent of
45f8960is the currentwiki-v2tip). Merge thisbefore/with the parent PR, exactly as the passwordless work (PR #61) advanced
wiki-v2on merge.Boundary
The seam is documented in the parent repo's
UPSTREAM_MODIFICATIONS.md(#17);features/admin-entry/**isfork-owned/additive (excluded from the boundary check). Advisory-only visibility gating — grants no Docmost
capability; all authority is re-enforced server-side by the platform PDP.
🤖 Generated with Claude Code