Repository navigation
feat: search - #10
Merged
Merged
feat: search#10
Conversation
auxa-m45
added a commit
to auxa-m45/docmost
that referenced
this pull request
Apr 13, 2025
* feat: billing sync (cloud) (docmost#899) * Set page history to 5 minutes interval * * Configure default queue options * sync * * stripe seats sync (cloud) * Revert "feat: auto focus emoji-picker search when opened (docmost#894)" (docmost#900) This reverts commit 5734574. * null check * Move suspense above popover dropdown * Refetch space list on mount * Adds Spotify embed support (#7) Introduces new Spotify icon, view, and extension for embedding playlists. Updates menu commands to include Spotify and removes outdated Nicovideo embed. * * fix color check * update lock file * fix collab token refresh which leads to collab editor reconnection loop (docmost#933) * feat: add version check (docmost#922) * Add version endpoint * version indicator * refetch * * Translate strings * Handle error * adds missing command for down migration (docmost#908) * telemetry module (docmost#934) * update lockfile * fix color check * telemetry * complete * Use interval * update env file * don't replace line breaks * v0.9.0 --------- Co-authored-by: Philip Okugbe <[email protected]> Co-authored-by: Hoie Kim <[email protected]>
fuscodev
pushed a commit
to fuscodev/docmost
that referenced
this pull request
Jun 29, 2025
…tPassword BadRequestException
nulluserid
pushed a commit
to N2con-Inc/docmost
that referenced
this pull request
Dec 17, 2025
full-text search feature
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 20, 2026
…ge + a11y + refactors' (docmost#10) from feat/ai-chat-review-followups into develop
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 20, 2026
…o an admin field Convert the htmlEmbed node from same-origin raw-HTML execution to a sandboxed iframe (sandbox="allow-scripts allow-popups allow-forms", no allow-same-origin, srcdoc) with postMessage auto-resize (validated by event.source) and an optional manual height attr. The block now runs in an opaque origin and cannot reach the viewer's cookies/session/API, so it is safe for any member. Because the block is now harmless, remove the entire admin/role gating apparatus: drop htmlEmbedAllowed/canAuthorHtmlEmbed/stripDisallowedHtmlEmbedNodes/ collectHtmlEmbedSources and every role-based strip on the write paths (collab REST/MCP + socket, page create/duplicate, import x2, transclusion unsync), along with the now-unused WorkspaceRepo/UserRepo injections and the PageService.create callerRole param. Keep one strip: prepareContentForShare still removes htmlEmbed on the anonymous public-share read path when the workspace master toggle is OFF. The workspace settings.htmlEmbed toggle is now a plain feature switch (gates the slash-menu and share rendering); when ON the block is available to all members. Add settings.trackerHead: an admin-only raw HTML/JS analytics snippet injected verbatim into the <head> of public share pages only (ShareSeoController), for trackers that genuinely need same-origin. Admin-gated via the existing CASL Manage/Settings ability; never injected into the authenticated app shell. Closes security-review findings #1, #2, docmost#4, docmost#5, docmost#10 (and docmost#3 as a security issue). Co-Authored-By: Claude Opus 4.8 <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 25, 2026
docmost#159) updatePage (markdown) and updatePageJson wrote the title via REST FIRST, then the body via collab. If the body write failed (e.g. a collab persist timeout), the page was left with the NEW title over its OLD body — a split-brain the tool reported as an error but never repaired (red-team finding docmost#10). Reorder both: write the body first, and only set the title after the body has persisted. Now a body-write failure leaves the title untouched (no split-brain). A title write failing after a successful body is rarer (REST is fast) and leaves correct content under a stale title — the strictly lesser inconsistency — which is the same trade-off the issue's "atomic, or roll back the title" intends, without the fragility of a rollback write that could itself fail. No unit test: both paths require a live collab provider and the suite has no provider mock; the change is a pure reordering. All 306 mcp tests still pass. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 25, 2026
…hangelog, jsonb seam) 8-point multi-aspect review of the batch PR; security/regressions were clean. 1. Lease leak: the docmost#180 reorder moved `toolsFor` (which leases external MCP clients, refCount+1) ahead of buildSystemPrompt + forUser, but the only release (closeExternalClients) was bound to the streamText callbacks. A throw in between leaked the lease (refCount stuck, undici sockets held until restart). Define closeExternalClients right after the lease and wrap buildSystemPrompt+forUser in try/catch that closes-then-rethrows. 2. Cover the patch_node/delete_node dup-id refusal (docmost#159 docmost#6): extract the guard into a pure `assertUnambiguousMatch` (node-ops) and unit-test 0/1/>1. 3. Regress the body-before-title order (docmost#159 docmost#10): mock-HTTP test (collab fails fast against a server with no WS upgrade) asserts /pages/update (title) is NEVER posted when the body write fails — for updatePage AND updatePageJson. 4. CHANGELOG [Unreleased]: docmost#180, docmost#168 (Added); docmost#163 (Fixed). 5. Add the missing en-US i18n keys (Back to references / {{label}}). 6. Drop the duplicate content/empty/blank cases in ai-chat.prompt.spec.ts (they repeat the buildMcpToolingBlock unit tests); keep only sandwich placement + both-safety-copies. 7. CI Postgres pg16 -> pg18 (match docker-compose). 8. jsonb decode seam: shared `parseJsonbValue(value, guard)` in database/utils.ts holds the legacy double-encoding self-heal in one place; parseToolAllowlist / parseModelConfig keep only a type-guard. Verified: server build + 124 unit + 15 integration; mcp 311; prettier clean. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jul 12, 2026
…r-refs (docmost#507 review) Review follow-up to the base64→entity-XML content= switch. The whole mxfile XML now lives in one content="..." attribute; XML attribute-value normalization collapses a LITERAL tab/newline/CR to a single space on DOM read (jsdom and the real draw.io editor alike), silently flattening multi-line labels and tab-bearing values that the old base64 form stored verbatim. Finding 1 (data-loss): both encode paths — buildDrawioSvg's xmlEscape (mcp) and the import service's escape — now append 	/
/
 after the four &<>" replaces (numeric char-refs survive normalization, as draw.io's own export does). The extractContentAttr regex fallback now decodes those char-refs (hex case-insensitive plus decimal &docmost#9;/&docmost#10;/&docmost#13;) so it agrees with the DOM path; & stays decoded last so an escaped &#x9; reads back as literal text. Finding 2 (dedup): the server's private xmlEscapeAttr is replaced by the shared htmlEscape helper (& < > " ' — a strict superset, the extra ' is harmless in a "-delimited value) wrapped in xmlEscapeContent, which adds the three control-char char-refs on top (htmlEscape does not escape them). Finding 3 (docs): narrow the CHANGELOG healing claim — only a diagram still holding its original correct-UTF-8 base64 (not yet opened/autosaved) is recoverable; one already opened in the editor persisted mojibake at rest and its text is lost. Tests: new mcp round-trip test with literal tab/newline/CR in a value (DOM path, byte-stable) plus a fallback-branch test forcing a malformed wrapper so both decode paths are proven to agree; new server spec asserting char-ref encoding. Mutation-checked: dropping the encode replaces reddens both new mcp tests; dropping only the fallback decode reddens just the fallback test. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jul 17, 2026
…seHash Three unrelated CI failures accumulated on develop, each a feature drifting from its test/mirror: - static.module.spec: add the getOfflineGrace stub (docmost#640) to the integration test's EnvironmentService mock; its absence threw in onModuleInit and reddened the whole SPA-catch-all describe. - metrics/mcp: route the three RYOW metrics the @docmost/mcp package now emits (mcp_ryow_live/dbrow/expired_total, docmost#654) onto prom counters — previously routeMcpMetric had no branch, so the samples were silently discarded (invariant docmost#10). dbrow's `reason` label is bounded {not_loaded, owner_unreachable}->other. Extend the drift-guard + no-op-when-disabled tests. - mcp e2e: thread a fresh baseHash into the four full-body overwrites in test-e2e.mjs (updatePage/updatePageJson), now that docmost#647/docmost#672 made the server-side write-CAS mandatory; title-only/no-op calls left untouched. Verified: server static.module.spec + mcp.service.spec + metrics.spec green (160 tests); test-e2e.mjs passes node --check.
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Aug 2, 2026
…ntic search (docmost#696) The picker exposed 112 curated icons of 1995; the rest were reachable only by English substring search (≤120 hits). Now the whole catalog (1746 canonical icons) is browsable, virtualized, and searchable by meaning (tags, aliases, common Russian words), and the scroll-drifting Mantine name-tooltip is gone. - lucide-catalog.generated.ts: one committed artifact (a .ts wrapper, not .json — a JSON import blows tsc to ~294k types), built by a hand-run generator (apps/client/scripts/gen-lucide-catalog.mjs; default / --tarball / --offline modes; NOT in CI). The dynamicIconImports parse rule is a single source (scripts/lucide-imports.mjs) shared by the generator and the guard test (AGENTS.md docmost#7). The artifact carries degraded[]; the guard test fails the build on a non-empty degraded not matching the allowlist (AGENTS.md docmost#10). - lucide-icon-grid.tsx: @tanstack/react-virtual grid (explicit measure() so the estimateSize-not-in-deps memo recomputes on model switch), a loading|ready| failed state machine, imperative dynamic import of the catalog (never eager, and a reject can't burn the app-wide reload budget), visible failed+limited mode with Retry. Tooltip removed. The catalog is reachable ONLY via the one dynamic import (image-smoke.sh S5 guards against it entering an eager chunk). - lucide-search.ts: canonicalOf (a stored alias still resolves), tag/alias search, Russian synonyms (ru-icon-synonyms.ts). Curated aliases funnel / circle-question-mark canonicalized. - i18n: picker strings in en-US (source) + ru-RU. Verified: pnpm --filter client typecheck / build / test all pass (1748 tests, incl. the guard + search suites against the real catalog); generator idempotent and byte-identical across all three network modes; degraded-guard mutation-checked non-vacuous.
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Aug 2, 2026
…ost#681) editor_tx_ms only measures the synchronous ProseMirror transaction and is blind to the React re-render/paint that follows a keystroke. Add editor_key_latency_ms = the full keydown->next-paint duration, captured with a PerformanceObserver on the Event Timing entry type. - vitals.ts: a passive PerformanceObserver({type:"event", durationThreshold:16, buffered:false}), wrapped in the same commented try/catch graceful-degrade as the longtask observer (inv docmost#10). A single filter reportEditorKeyLatency() keeps name==="keydown" && live .ProseMirror focus, reporting entry.duration through the existing reportClientMetric sink (self-gated by isVitalsActive). editor_tx_ms is untouched. - client ALLOWED_NAMES + reportClientMetric union + server ALLOWED_METRIC_NAMES: the metric name declared in all three lockstep sites (inv docmost#7), each guarded. - 6 client tests drive the REAL filter through real jsdom focus + a wiring test proving the observer is installed with the right options and connected to the filter (inv docmost#8); 1 server validator test asserts the name is accepted. Closes docmost#681
PMQ9
referenced
this pull request
in cccvu/docmost
Aug 30, 2026
…iction gate, collab guard, PEP↔PDP consumer contract; timeout/chunking bug-exposers (#10/#15) Adds to the fork's authz compatibility suite (Task #16 / Epic #7): - search/pdp-search.completeness.spec.ts — I5 authorized-k-under-truncation (match beyond the first window still returned) - page-restriction/page-restriction.service.spec.ts — only a space-admin may restrict/grant - collab/collab-disconnect.controller.spec.ts — constant-time service-secret guard + fail-safe re-check - contract/pep-pdp-consumer.contract.spec.ts — the consumer half of the PEP↔PDP HTTP contract (#13) - platform-authz.client.contract.spec.ts — INTENTIONALLY-RED bug-exposers: no request timeout (#10), no 1000-cap chunking (#15) All additions live under apps/server/src/authz/ (upstream boundary intact). The two client-contract failures are real defects to fix in #17; they assert intended behavior and are not weakened. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.