Commit graph

1064 commits

Author SHA1 Message Date
ABird
34dbb83948
feat(spaces): support custom icons and emoji (#6287) 2026-09-07 23:12:18 +08:00
Johnny
2d75439ecc
feat(memos): support moving memos between spaces (#6285) 2026-09-07 20:45:59 +08:00
johnnyjoygh
0716eaac2c fix(editor): preserve memo timestamp edits when closing popover 2026-09-07 09:25:51 +08:00
Johnny
230e3a1d11
feat(spaces): deliver invitations to the inbox (#6266) 2026-09-04 08:58:49 +08:00
johnnyjoygh
e963d326ab chore(mcp): satisfy revive lint rules 2026-09-04 08:19:44 +08:00
johnnyjoygh
652957c0f9 fix(mcp): expose standard JSON Schema formats in tool schemas
The gnostic OpenAPI generator hardcodes `format: enum`, `format: bytes`,
and `format: field-mask` on string properties. These are OpenAPI-only
markers; MCP clients treat tool schemas as JSON Schema 2020-12 and warn
or fail on them (zod-based parsers log "unknown format" for every tool
on every load, ajv strict mode rejects the definitions).

Normalize schemas as they leave the resolver and when parameter schemas
are cloned: drop `format: enum` (the `enum` keyword is already present),
rewrite `format: bytes` to `contentEncoding: base64`, and drop
`format: field-mask`. The generated openapi.yaml is unchanged.

A catalog test now walks every curated tool's input and output schema
and fails on any format outside the registered allowlist.

Fixes #6262
2026-09-03 21:53:03 +08:00
Abdellatif Anaflous
d5849bdf52
fix(attachment): detect heic/heif mime type from filename extension (#6246)
Signed-off-by: Abdel <hktitof@gmail.com>
2026-08-30 09:09:53 +08:00
boojack
5b6d8f87bf
refactor(server): remove RSS feed support (#6243) 2026-08-28 23:06:25 +08:00
amblued
9d2b77ced8 feat(space): add client-defined UIDs and identity cues
- Generate UUID v4 values in the client with validated custom UID
  support.\n- Show immutable UIDs where Space titles need
  disambiguation.\n- Standardize Space surfaces on the Lucide Astroid
  icon.
2026-08-28 00:33:09 +08:00
ABird
854d893fc6
feat(spaces): add settings management (#6234) 2026-08-26 22:20:40 +08:00
ABird
05f882e43a
feat(spaces): add consent-based member invitations (#6232) 2026-08-25 23:21:19 +08:00
amblued
45c3a79b12 fix(settings): validate memo content length limit 2026-08-24 23:35:32 +08:00
ABird
66b9cb49c1
feat(spaces): add space-aware UI and filtering (#6230) 2026-08-24 23:13:55 +08:00
amblued
6da8461e1d
feat(spaces): add multi-space memo collaboration (#6228) 2026-08-23 19:36:50 +08:00
amblued
76a7629243
feat(instance): persist access mode independently of URL (#6225) 2026-08-22 14:15:31 +08:00
amblued
fe9a9bdf64
refactor(reaction): link reactions to memo IDs (#6221) 2026-08-22 00:12:35 +08:00
amblued
57a4b7aee6
chore(go): upgrade to Go 1.27 (#6217) 2026-08-20 23:37:02 +08:00
amblued
38412eb75a
fix(storage): proxy S3 attachments through authenticated routes (#6210) 2026-08-18 23:38:35 +08:00
amblued
cf1be15f3e
refactor(fileserver): fix stale README and simplify file serving (#6208) 2026-08-18 21:22:26 +08:00
Johnny
16cd3107bf
feat(link-preview): support standards-based metadata (#6206) 2026-08-18 09:16:04 +08:00
questfever
011a0e8360
refactor: replace Split in loops with more efficient SplitSeq (#6187)
Signed-off-by: questfever <questfever@outlook.com>
2026-08-16 21:46:16 +08:00
Johnny
7d971b1c61
feat(storage): add named attachment storage drivers (#6184) 2026-08-13 22:37:11 +08:00
Johnny
da81b6b48f
feat: persist and display client media metadata (#6180) 2026-08-11 23:47:21 +08:00
Johnny
bd636a4365
feat: support memo-scoped Markdown attachment images (#6169) 2026-08-09 23:27:18 +08:00
Johnny
4e8b262d6d
refactor(memo-views): replace shortcuts with saved views (#6167) 2026-08-09 20:27:27 +08:00
Johnny
bdf87e8699
fix(api): omit unset message fields from gateway JSON (#6156) 2026-08-06 23:21:21 +08:00
Johnny
8648b97b9e
feat(user): define username format and mention syntax (#6134) 2026-08-02 19:57:16 +08:00
johnnyjoygh
464e45b447 chore: update demo data 2026-08-02 16:31:24 +08:00
Johnny
c68e3d5bf9
feat(markdown): unify tag syntax and recognition (#6132) 2026-08-02 14:46:04 +08:00
boojack
dd18002b12 perf(sse): reduce redundant connections and fanout overhead
- Share one visible-tab connection across a browser and harden retries.\n- Preframe hub events, disconnect slow clients, and reset idle heartbeats.\n- Add cross-tab, concurrency, race, and fanout benchmark coverage.
2026-07-29 21:47:54 +08:00
johnnyjoygh
c536434b81 test(release): cover 0.30.0 changelog promises 2026-07-26 22:21:19 +08:00
johnnyjoygh
1236d9ba94 test(ci): add upgrade and startup smoke coverage
Exercise real server startup on backend test runs and gate releases on fresh-install, previous-stable upgrade, and entrypoint smoke checks across supported databases.
2026-07-26 21:21:15 +08:00
johnnyjoygh
415a3ec73d fix(auth): enforce private instance access boundaries
- Resolve Gateway procedures from matched HTTP bindings before authorization.\n- Disable anonymous RSS on private instances.\n- Limit share-token access to the shared memo and its attachments.
2026-07-26 21:13:21 +08:00
johnnyjoygh
0d2cbd4f5a refactor: expose shared memo as memo resource
Rename GetMemoByShare to GetSharedMemo and move REST resolution to /api/v1/shares/{share_token}/memo.\n\nBREAKING CHANGE: remove GET /api/v1/shares/{share_id} and the GetMemoByShare RPC.
2026-07-26 21:13:18 +08:00
Johnny
390126f1cd
fix(mcp): harden tool schemas and request routing (#6115) 2026-07-25 09:54:12 +08:00
Johnny
019f4f9adc
fix(auth): provision SSO users atomically (#6114) 2026-07-25 09:47:16 +08:00
Chad Harp
03e34bd0da
fix(mcp): accept canonical resource names in path params and keep error results schema-valid (#6108) 2026-07-24 00:15:13 +08:00
boojack
b7d5d09f8a fix(api): update UID compatibility
Use the original UID format consistently across API, username, and store validation so UUID-based callers continue to work. Regenerate API documentation and add regression coverage for UUID memo IDs.
2026-07-20 19:41:55 +08:00
johnnyjoygh
88c6ee8ebc perf(web): reduce demo bandwidth usage
- Cache fingerprinted frontend assets for one month.
- Load media, rich renderers, dialogs, and editors only when needed.
- Simplify seeded demo content and cover deferred-loading behavior.
2026-07-18 22:06:14 +08:00
johnnyjoygh
0bfeb91d50 fix(api): show clean RPC error messages 2026-07-18 11:20:15 +08:00
johnnyjoygh
84776cc106 fix(api): align resource IDs with AIP conventions
Validate new user-provided IDs using the AIP-122 format while retaining legacy UID compatibility. Correct resource annotations and canonical names returned by user stats.
2026-07-18 11:12:28 +08:00
johnnyjoygh
715306ea66 chore: enrich access tokens setting page
Settings drops the all-in-one bordered card for a de-carded layout in
the property-rail design language: a sticky table-of-contents rail at
md+ (Settings wordmark, uppercase group labels, quiet anchor rows) and
a horizontally swipeable chip strip below md, replacing the mobile
section dropdown. Nav items are real anchors with aria-current, and
switching sections scrolls back to the top.

Access Tokens becomes a first-class section with an explainer panel:
what a PAT is and a copyable curl example (real instance origin,
memos_pat_ prefix) beside token-safety guidelines in a two-column band,
with a Learn more docs link and the tokens table beneath. Successful
PAT authentication now records the token's lastUsedAt asynchronously
inside resolveBearer, with a clone-before-mutate cache guard and
monotonic writes in the store, surfaced in a Last used column.

Also localizes the create dialog's 90 Days label, lets the My Account
row wrap instead of clipping on narrow screens, and drops the dead
select-section key from all locales.
2026-07-18 10:41:53 +08:00
boojack
0038295bbc feat(config): provision settings from secret files
- Load IdPs and supported instance-setting groups as runtime overlays from /etc/secrets.
- Reject API mutations of deployment-managed resources and serialize authentication safety checks across database drivers.
- Preserve upgrade compatibility, demo SSO policy, stable IdP ordering, and driver-specific transaction retries.
2026-07-13 22:34:24 +08:00
boojack
4bc3928029 fix(user): implement ListUsers pagination
Rework ListUsers to match the ListMemos pagination contract: opaque
PageToken, normalizePageSize, DB-level limit+1 look-ahead, and a
next_page_token. Adds Offset to store.FindUser with an OFFSET clause in
all three dialects, and an `id DESC` ORDER BY tiebreaker so offset pages
stay stable when created_ts ties.

Also align pagination across list endpoints:
- Bump DefaultPageSize 10 -> 50 to match the documented default; use
  normalizePageSize in ListAttachments.
- Remove the never-implemented total_size field from all six list
  responses (ListUsers, ListAttachments, ListMemoComments,
  ListMemoReactions, ListUserSettings, ListPersonalAccessTokens) and
  regenerate.
- useListUsers now pages through next_page_token so the admin members
  view still loads every user past the default page size.
2026-07-12 20:51:04 +08:00
boojack
3fe145083f chore: reorganize backend and frontend modules
- remove the unused internal cron package
- split API service implementations by responsibility
- clarify frontend shared-module ownership
2026-07-12 17:59:12 +08:00
TowyTowy
c9b356b46a
fix(memo): populate parent relation in comment webhook payload (#6083)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-12 17:23:58 +08:00
boojack
d1cef7a9ab feat(auth): add private instance mode derived from instance_url
Run the instance in private mode when instance_url is not configured: the API rejects anonymous requests except the auth-bootstrap set (sign-in, token refresh, instance profile/settings, SSO providers, share-link access) plus first-run user creation, and the web UI redirects anonymous visitors to /auth instead of /explore. Setting instance_url keeps the current public behavior. Access tokens and personal access tokens are never gated.

Enforcement lives in a shared Authorizer used by both the Connect interceptor and the gRPC-gateway middleware; the file server applies the same rule to public-memo attachments and avatars. Also merges the duplicated Authenticate/AuthenticateToUser token dispatch behind resolveBearer, dedups the AuthContext unauthenticated state, extracts the redirect decision into a pure shouldGatePrivateInstance helper, and prints the access mode at startup.
2026-07-05 22:48:00 +08:00
grandpig
76aee4e177
refactor: use the built-in max/min to simplify the code (#6060)
Signed-off-by: grandpig <grandpig@outlook.com>
2026-07-02 08:35:47 +08:00
boojack
0e1d821fb8 feat(mcp): expose create_attachment tool
Add AttachmentService_CreateAttachment to the curated MCP allowlist so
agents can upload files (inline base64 content) alongside memos, closing
the gap where the MCP server could list/get/delete attachments but not
create them.

Closes #6057
2026-07-01 22:15:58 +08:00
boojack
047175dbed chore(mcp): improve tool discoverability, add orientation tools and evals
Make the OpenAPI-driven MCP surface more usable by agents, following the
mcp-builder guidance.

- Enrich proto descriptions (single source of truth, flows to OpenAPI + MCP
  tool descriptions): document the memo `filter` CEL grammar with fields and
  examples (replacing the dangling "Refer to Shortcut.filter"), clarify the
  created_ts/updated_ts vs create_time/update_time naming, the visibility
  enum, the declarative replace semantics of Set* ops, and steer tag filters
  to `"x" in tags` (not the unsupported `tag == "x"`).
- Mark SetMemoAttachments / SetMemoRelations idempotent via a per-operation
  override the HTTP-method heuristic can't express.
- Curate two read-only orientation tools: shortcut_list_shortcuts (surfaces
  reusable CEL filters) and auth_get_current_user (the single allowed
  auth/identity op, for resolving the current user); guard test updated to
  keep the rest of the auth/user surface excluded.
- Add a task-level evaluation suite (server/router/mcp/evals) with 10
  verified questions, pinned to the deterministic demo seed.
2026-06-27 10:32:42 +08:00