Repository navigation
Layout refactor - #13
Merged
Merged
Conversation
* ui polishing * frontend and backend fixes
fuscodev
pushed a commit
to fuscodev/docmost
that referenced
this pull request
Jun 29, 2025
Feat/allow email change2
nulluserid
pushed a commit
to N2con-Inc/docmost
that referenced
this pull request
Dec 17, 2025
Layout refactor
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 20, 2026
…rver-validated)' (docmost#13) from feat/mcp-per-user-auth into develop
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 20, 2026
Post-merge hardening from the docmost#13 security review: - isInitializeRequestBody now delegates to the SDK isInitializeRequest (same predicate as packages/mcp/http.ts), so a bare {method:'initialize'} with no id/params no longer triggers the side-effecting login() (audit-spam / user_sessions growth) before http.ts 400s it. - Bind the Bearer path to the instance workspace: verifyBearerAccess rejects a token whose payload.workspaceId != the instance workspace (resolved via workspaceRepo.findFirst, consistent with the Basic path); optional param so it's a no-op when unset. - Close the user-enumeration timing oracle in verifyUserCredentials: the missing/disabled branch now runs a bcrypt compare against a module-level dummy hash whose cost (12) matches production saltRounds, so both paths take one equal-cost bcrypt compare; the exact CREDENTIALS_MISMATCH_MESSAGE is preserved. - Document the trusted-proxy requirement for the spoofable per-IP brute-force limiter in .env.example (trustProxy is on; deploy behind a trusted proxy). - Add real-execution coverage for enforceBasicLoginGate (SSO enforced / EE-MFA bundled vs not / user-MFA / workspace-enforced-MFA) instead of stubbing the gate. Co-Authored-By: Claude Opus 4.8 <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jul 11, 2026
…регрессии) (docmost#488) 1 [stability] Позитивные attach-исходы гвардятся по ИСХОДНОЙ фазе. Одного epoch- фильтра мало: POLL_TERMINAL использует to() (epoch не инкрементит) и не шлёт abortAttach, поэтому медленный GET, вернувший live 2xx уже ПОСЛЕ того как армленный poll увёл машину в idle, воскрешал осевший ран в фантомный streaming. RECONNECT_ ATTACHED теперь bail'ит если фаза != reconnecting; ATTACH_LIVE/ATTACH_NONE — если != attaching. Тест на гонку (POLL_TERMINAL до RECONNECT_ATTACHED → idle) + mutation. 2 [regressions] ownership сбрасывается в "local" на ВСЕХ терминальных переходах (FINISH_CLEAN/ABORT/ERROR, POLL_TERMINAL, RUN_FACT{null}→idle, honor-in-stopping, disconnect→idle). Иначе observer-attach + очередь + clean-финиш → idle, но ownership навсегда observer → «Send now» скрыт при свободном композере. Безопасно для I2: рантайм захватывает wasObserver из machineRef ДО dispatch. Тест + mutation. 3 [coverage] Тест happy-path CAS-supersede: SUPERSEDE_READY-dispatch (200-исход transport.fetch) раньше НЕ исполнялся ни в одном тесте — риск залипания в superseding на весь стрим B. Тест вводит в superseding, гонит A.onFinish→B, затем POST 200 → SUPERSEDE_READY → streaming, проверяет повторный supersede (не залип). Сиблинги: 409 SUPERSEDE_TARGET_MISMATCH → getRun/verify; plain-409 A_RUN_ALREADY_ACTIVE → классифицированный баннер. Mutation (no-op READY → красный). 4 [regressions] Inactivity-бэкстоп для poll, армленного в stopping. STOP_REQUESTED армит poll и входит в stopping, но idle-cap покрывал только polling/reconnecting → observer-стоп без SDK-стрима и без серверного терминала поллил БД вечно. Добавлен stopping в фаза-чек эффекта + переход POLL_IDLE_CAP: stopping→idle+disarm (НЕ stalled — Stop уже нажат). FSM + компонент-тест (idle-cap→disarm) + mutation. 5 [docs] Счёт §2 «Net»: 8→FSM (#1-6,docmost#11,docmost#13) + 3 deleted + reconnectTimerRef (effect-owned) + mountedRef (retained) = 13; attachAbortRef вне набора #1-13. Не трогал DROP-блок (мёртвый FINISH_* в superseding, ErrorKind.kind, неиспользуемые enum-варианты, epochRef-зеркало). Всё прошлое цело (disconnect-first, epoch, honor- in-stopping, render-gate, supersede). Полный ai-chat 35 файлов / 388 / 0; tsc 0. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jul 12, 2026
…r-refs (docmost#507 review) Review follow-up to the base64→entity-XML content= switch. The whole mxfile XML now lives in one content="..." attribute; XML attribute-value normalization collapses a LITERAL tab/newline/CR to a single space on DOM read (jsdom and the real draw.io editor alike), silently flattening multi-line labels and tab-bearing values that the old base64 form stored verbatim. Finding 1 (data-loss): both encode paths — buildDrawioSvg's xmlEscape (mcp) and the import service's escape — now append 	/
/
 after the four &<>" replaces (numeric char-refs survive normalization, as draw.io's own export does). The extractContentAttr regex fallback now decodes those char-refs (hex case-insensitive plus decimal &docmost#9;/&docmost#10;/&docmost#13;) so it agrees with the DOM path; & stays decoded last so an escaped &#x9; reads back as literal text. Finding 2 (dedup): the server's private xmlEscapeAttr is replaced by the shared htmlEscape helper (& < > " ' — a strict superset, the extra ' is harmless in a "-delimited value) wrapped in xmlEscapeContent, which adds the three control-char char-refs on top (htmlEscape does not escape them). Finding 3 (docs): narrow the CHANGELOG healing claim — only a diagram still holding its original correct-UTF-8 base64 (not yet opened/autosaved) is recoverable; one already opened in the editor persisted mojibake at rest and its text is lost. Tests: new mcp round-trip test with literal tab/newline/CR in a value (DOM path, byte-stable) plus a fallback-branch test forcing a malformed wrapper so both decode paths are proven to agree; new server spec asserting char-ref encoding. Mutation-checked: dropping the encode replaces reddens both new mcp tests; dropping only the fallback decode reddens just the fallback test. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jul 12, 2026
…most#529) Introduce a `ru_en` FTS configuration (english_stem over ascii token classes, russian_stem over Cyrillic ones) and flip every stored + query side to it IN LOCKSTEP (acceptance docmost#13): - new migration creates ru_en, swaps the pages.tsv trigger + reindexes existing rows (row-lock UPDATE, no ACCESS EXCLUSIVE), and swaps the page_embeddings.fts generated column (documented rewrite/lock trade-off for large tenants, mirroring the docmost#443 trgm migration). down() reverts tsv/fts to english BEFORE dropping the config (dependency order). - page-embedding.repo.ts hybridSearch query config english -> ru_en, so the RAG lexical leg's query config matches its fts column config. - search.service.ts current query literals english -> ru_en so the column and query configs stay paired (this commit is independently revertable; the engine itself is rewritten in the A2-A9 commit). The reindex is atomic within the single migration transaction (this repo's Migrator wraps all pending migrations in one tx), so no morphology-desync window exists and no dual-config read path is needed. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
PMQ9
referenced
this pull request
in cccvu/docmost
Aug 30, 2026
…iction gate, collab guard, PEP↔PDP consumer contract; timeout/chunking bug-exposers (#10/#15) Adds to the fork's authz compatibility suite (Task #16 / Epic #7): - search/pdp-search.completeness.spec.ts — I5 authorized-k-under-truncation (match beyond the first window still returned) - page-restriction/page-restriction.service.spec.ts — only a space-admin may restrict/grant - collab/collab-disconnect.controller.spec.ts — constant-time service-secret guard + fail-safe re-check - contract/pep-pdp-consumer.contract.spec.ts — the consumer half of the PEP↔PDP HTTP contract (#13) - platform-authz.client.contract.spec.ts — INTENTIONALLY-RED bug-exposers: no request timeout (#10), no 1000-cap chunking (#15) All additions live under apps/server/src/authz/ (upstream boundary intact). The two client-contract failures are real defects to fix in #17; they assert intended behavior and are not weakened. Co-Authored-By: Claude Opus 4.8 <[email protected]>
PMQ9
added a commit
to cccvu/docmost
that referenced
this pull request
Sep 4, 2026
… review-round-1 gaps Addresses the /pr-review-comprehensive round-1 findings on docmost#13 / wiki-v2#173: - Cap regression: ContentListDto.ids was @ArrayMaxSize(1000) while the platform forwards up to content.maxListAuthorizedIds (default 10000), so a principal authorized on 1001-10000 objects passed the PDP belt then got a 400 on /v1 lists. Raise the cap to CONTENT_LIST_MAX_IDS (10000) and set the canonical maxItems in service-bridge.openapi.json. The provider contract test now binds the DTO caps (ids + limit) to the spec so the three can never silently diverge. - Add service-workspace.service.spec.ts: proves the settings JSONB coalesce shallow-merge preserves sibling keys. This merge was untested in either repo (the platform docstring wrongly claimed fork coverage). - Pin deleted_at + workspace_id confidentiality predicates in the content service spec, so a future edit dropping either fails CI instead of leaking trashed/cross-workspace content into /v1. Also cover listSpacesByIds, resolvePageSpace (default + includeDeleted), and listPagePermissions. - Tighten scope-coverage to assert the exact least-privilege ServiceScope per route (documents the intentional pages:read vs content:read split), plus a no-stale-entries guard. - Validate ContentCursorDto.updatedAt as ISO-8601 so a malformed cursor is a 400, not a 500. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.