Skip to content

feat: search - #10

Merged
Philipinho merged 1 commit into
mainfrom
search
Jan 29, 2024
Merged

Philipinho merged 1 commit into
mainfrom
search

Conversation

@Philipinho

Copy link
Copy Markdown
Member

No description provided.

@Philipinho
Philipinho merged commit 9444281 into main Jan 29, 2024
@Philipinho
Philipinho deleted the search branch February 26, 2024 11:38
auxa-m45 added a commit to auxa-m45/docmost that referenced this pull request Apr 13, 2025
* feat: billing sync (cloud) (docmost#899)

* Set page history to 5 minutes interval

* * Configure default queue options

* sync

* * stripe seats sync (cloud)

* Revert "feat: auto focus emoji-picker search when opened (docmost#894)" (docmost#900)

This reverts commit 5734574.

* null check

* Move suspense above popover dropdown

* Refetch space list on mount

* Adds Spotify embed support (#7)

Introduces new Spotify icon, view, and extension for embedding playlists.
Updates menu commands to include Spotify and removes outdated Nicovideo embed.

* * fix color check
* update lock file

* fix collab token refresh which leads to collab editor reconnection loop (docmost#933)

* feat: add version check (docmost#922)

* Add version endpoint

* version indicator

* refetch

* * Translate strings
* Handle error

* adds missing command for down migration (docmost#908)

* telemetry module (docmost#934)

* update lockfile

* fix color check

* telemetry

* complete

* Use interval

* update env file

* don't replace line breaks

* v0.9.0

---------

Co-authored-by: Philip Okugbe <[email protected]>
Co-authored-by: Hoie Kim <[email protected]>
fuscodev pushed a commit to fuscodev/docmost that referenced this pull request Jun 29, 2025
nulluserid pushed a commit to N2con-Inc/docmost that referenced this pull request Dec 17, 2025
full-text search feature
vvzvlad pushed a commit to vvzvlad/gitmost that referenced this pull request Jun 20, 2026
…ge + a11y + refactors' (docmost#10) from feat/ai-chat-review-followups into develop
vvzvlad pushed a commit to vvzvlad/gitmost that referenced this pull request Jun 20, 2026
…o an admin field

Convert the htmlEmbed node from same-origin raw-HTML execution to a sandboxed
iframe (sandbox="allow-scripts allow-popups allow-forms", no allow-same-origin,
srcdoc) with postMessage auto-resize (validated by event.source) and an optional
manual height attr. The block now runs in an opaque origin and cannot reach the
viewer's cookies/session/API, so it is safe for any member.

Because the block is now harmless, remove the entire admin/role gating apparatus:
drop htmlEmbedAllowed/canAuthorHtmlEmbed/stripDisallowedHtmlEmbedNodes/
collectHtmlEmbedSources and every role-based strip on the write paths (collab
REST/MCP + socket, page create/duplicate, import x2, transclusion unsync), along
with the now-unused WorkspaceRepo/UserRepo injections and the PageService.create
callerRole param. Keep one strip: prepareContentForShare still removes htmlEmbed
on the anonymous public-share read path when the workspace master toggle is OFF.

The workspace settings.htmlEmbed toggle is now a plain feature switch (gates the
slash-menu and share rendering); when ON the block is available to all members.

Add settings.trackerHead: an admin-only raw HTML/JS analytics snippet injected
verbatim into the <head> of public share pages only (ShareSeoController), for
trackers that genuinely need same-origin. Admin-gated via the existing CASL
Manage/Settings ability; never injected into the authenticated app shell.

Closes security-review findings #1, #2, docmost#4, docmost#5, docmost#10 (and docmost#3 as a security issue).

Co-Authored-By: Claude Opus 4.8 <[email protected]>
vvzvlad pushed a commit to vvzvlad/gitmost that referenced this pull request Jun 25, 2026
docmost#159)

updatePage (markdown) and updatePageJson wrote the title via REST FIRST, then
the body via collab. If the body write failed (e.g. a collab persist timeout),
the page was left with the NEW title over its OLD body — a split-brain the tool
reported as an error but never repaired (red-team finding docmost#10).

Reorder both: write the body first, and only set the title after the body has
persisted. Now a body-write failure leaves the title untouched (no split-brain).
A title write failing after a successful body is rarer (REST is fast) and leaves
correct content under a stale title — the strictly lesser inconsistency — which
is the same trade-off the issue's "atomic, or roll back the title" intends,
without the fragility of a rollback write that could itself fail.

No unit test: both paths require a live collab provider and the suite has no
provider mock; the change is a pure reordering. All 306 mcp tests still pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad pushed a commit to vvzvlad/gitmost that referenced this pull request Jun 25, 2026
…hangelog, jsonb seam)

8-point multi-aspect review of the batch PR; security/regressions were clean.

1. Lease leak: the docmost#180 reorder moved `toolsFor` (which leases external MCP
   clients, refCount+1) ahead of buildSystemPrompt + forUser, but the only
   release (closeExternalClients) was bound to the streamText callbacks. A throw
   in between leaked the lease (refCount stuck, undici sockets held until
   restart). Define closeExternalClients right after the lease and wrap
   buildSystemPrompt+forUser in try/catch that closes-then-rethrows.
2. Cover the patch_node/delete_node dup-id refusal (docmost#159 docmost#6): extract the guard
   into a pure `assertUnambiguousMatch` (node-ops) and unit-test 0/1/>1.
3. Regress the body-before-title order (docmost#159 docmost#10): mock-HTTP test (collab fails
   fast against a server with no WS upgrade) asserts /pages/update (title) is
   NEVER posted when the body write fails — for updatePage AND updatePageJson.
4. CHANGELOG [Unreleased]: docmost#180, docmost#168 (Added); docmost#163 (Fixed).
5. Add the missing en-US i18n keys (Back to references / {{label}}).
6. Drop the duplicate content/empty/blank cases in ai-chat.prompt.spec.ts (they
   repeat the buildMcpToolingBlock unit tests); keep only sandwich placement +
   both-safety-copies.
7. CI Postgres pg16 -> pg18 (match docker-compose).
8. jsonb decode seam: shared `parseJsonbValue(value, guard)` in database/utils.ts
   holds the legacy double-encoding self-heal in one place; parseToolAllowlist /
   parseModelConfig keep only a type-guard.

Verified: server build + 124 unit + 15 integration; mcp 311; prettier clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad pushed a commit to vvzvlad/gitmost that referenced this pull request Jul 12, 2026
…r-refs (docmost#507 review)

Review follow-up to the base64→entity-XML content= switch. The whole mxfile XML
now lives in one content="..." attribute; XML attribute-value normalization
collapses a LITERAL tab/newline/CR to a single space on DOM read (jsdom and the
real draw.io editor alike), silently flattening multi-line labels and
tab-bearing values that the old base64 form stored verbatim.

Finding 1 (data-loss): both encode paths — buildDrawioSvg's xmlEscape (mcp) and
the import service's escape — now append &#x9;/&#xa;/&#xd; after the four
&<>" replaces (numeric char-refs survive normalization, as draw.io's own export
does). The extractContentAttr regex fallback now decodes those char-refs (hex
case-insensitive plus decimal &docmost#9;/&docmost#10;/&docmost#13;) so it agrees with the DOM path;
&amp; stays decoded last so an escaped &amp;#x9; reads back as literal text.

Finding 2 (dedup): the server's private xmlEscapeAttr is replaced by the shared
htmlEscape helper (& < > " ' — a strict superset, the extra ' is harmless in a
"-delimited value) wrapped in xmlEscapeContent, which adds the three control-char
char-refs on top (htmlEscape does not escape them).

Finding 3 (docs): narrow the CHANGELOG healing claim — only a diagram still
holding its original correct-UTF-8 base64 (not yet opened/autosaved) is
recoverable; one already opened in the editor persisted mojibake at rest and its
text is lost.

Tests: new mcp round-trip test with literal tab/newline/CR in a value (DOM path,
byte-stable) plus a fallback-branch test forcing a malformed wrapper so both
decode paths are proven to agree; new server spec asserting char-ref encoding.
Mutation-checked: dropping the encode replaces reddens both new mcp tests;
dropping only the fallback decode reddens just the fallback test.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad pushed a commit to vvzvlad/gitmost that referenced this pull request Jul 17, 2026
…seHash

Three unrelated CI failures accumulated on develop, each a feature drifting
from its test/mirror:

- static.module.spec: add the getOfflineGrace stub (docmost#640) to the integration
  test's EnvironmentService mock; its absence threw in onModuleInit and reddened
  the whole SPA-catch-all describe.
- metrics/mcp: route the three RYOW metrics the @docmost/mcp package now emits
  (mcp_ryow_live/dbrow/expired_total, docmost#654) onto prom counters — previously
  routeMcpMetric had no branch, so the samples were silently discarded
  (invariant docmost#10). dbrow's `reason` label is bounded {not_loaded,
  owner_unreachable}->other. Extend the drift-guard + no-op-when-disabled tests.
- mcp e2e: thread a fresh baseHash into the four full-body overwrites in
  test-e2e.mjs (updatePage/updatePageJson), now that docmost#647/docmost#672 made the
  server-side write-CAS mandatory; title-only/no-op calls left untouched.

Verified: server static.module.spec + mcp.service.spec + metrics.spec green
(160 tests); test-e2e.mjs passes node --check.
vvzvlad pushed a commit to vvzvlad/gitmost that referenced this pull request Aug 2, 2026
…ntic search (docmost#696)

The picker exposed 112 curated icons of 1995; the rest were reachable only by
English substring search (≤120 hits). Now the whole catalog (1746 canonical
icons) is browsable, virtualized, and searchable by meaning (tags, aliases,
common Russian words), and the scroll-drifting Mantine name-tooltip is gone.

- lucide-catalog.generated.ts: one committed artifact (a .ts wrapper, not .json
  — a JSON import blows tsc to ~294k types), built by a hand-run generator
  (apps/client/scripts/gen-lucide-catalog.mjs; default / --tarball / --offline
  modes; NOT in CI). The dynamicIconImports parse rule is a single source
  (scripts/lucide-imports.mjs) shared by the generator and the guard test
  (AGENTS.md docmost#7). The artifact carries degraded[]; the guard test fails the
  build on a non-empty degraded not matching the allowlist (AGENTS.md docmost#10).
- lucide-icon-grid.tsx: @tanstack/react-virtual grid (explicit measure() so the
  estimateSize-not-in-deps memo recomputes on model switch), a loading|ready|
  failed state machine, imperative dynamic import of the catalog (never eager,
  and a reject can't burn the app-wide reload budget), visible failed+limited
  mode with Retry. Tooltip removed. The catalog is reachable ONLY via the one
  dynamic import (image-smoke.sh S5 guards against it entering an eager chunk).
- lucide-search.ts: canonicalOf (a stored alias still resolves), tag/alias
  search, Russian synonyms (ru-icon-synonyms.ts). Curated aliases funnel /
  circle-question-mark canonicalized.
- i18n: picker strings in en-US (source) + ru-RU.

Verified: pnpm --filter client typecheck / build / test all pass (1748 tests,
incl. the guard + search suites against the real catalog); generator idempotent
and byte-identical across all three network modes; degraded-guard mutation-checked
non-vacuous.
vvzvlad pushed a commit to vvzvlad/gitmost that referenced this pull request Aug 2, 2026
…ost#681)

editor_tx_ms only measures the synchronous ProseMirror transaction and is
blind to the React re-render/paint that follows a keystroke. Add
editor_key_latency_ms = the full keydown->next-paint duration, captured with a
PerformanceObserver on the Event Timing entry type.

- vitals.ts: a passive PerformanceObserver({type:"event", durationThreshold:16,
  buffered:false}), wrapped in the same commented try/catch graceful-degrade as
  the longtask observer (inv docmost#10). A single filter reportEditorKeyLatency() keeps
  name==="keydown" && live .ProseMirror focus, reporting entry.duration through
  the existing reportClientMetric sink (self-gated by isVitalsActive). editor_tx_ms
  is untouched.
- client ALLOWED_NAMES + reportClientMetric union + server ALLOWED_METRIC_NAMES:
  the metric name declared in all three lockstep sites (inv docmost#7), each guarded.
- 6 client tests drive the REAL filter through real jsdom focus + a wiring test
  proving the observer is installed with the right options and connected to the
  filter (inv docmost#8); 1 server validator test asserts the name is accepted.

Closes docmost#681
PMQ9 referenced this pull request in cccvu/docmost Aug 30, 2026
…iction gate, collab guard, PEP↔PDP consumer contract; timeout/chunking bug-exposers (#10/#15)

Adds to the fork's authz compatibility suite (Task #16 / Epic #7):
- search/pdp-search.completeness.spec.ts — I5 authorized-k-under-truncation (match beyond the first window still returned)
- page-restriction/page-restriction.service.spec.ts — only a space-admin may restrict/grant
- collab/collab-disconnect.controller.spec.ts — constant-time service-secret guard + fail-safe re-check
- contract/pep-pdp-consumer.contract.spec.ts — the consumer half of the PEP↔PDP HTTP contract (#13)
- platform-authz.client.contract.spec.ts — INTENTIONALLY-RED bug-exposers: no request timeout (#10), no 1000-cap chunking (#15)

All additions live under apps/server/src/authz/ (upstream boundary intact). The two client-contract
failures are real defects to fix in #17; they assert intended behavior and are not weakened.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant