Commit graph

4665 commits

Author SHA1 Message Date
Anupam Mediratta
3b8d2558ed
fix: upgrade golang.org/x/crypto to 0.52.0 (CVE-2026-39829) (#6152) 2026-08-06 15:25:04 +08:00
boojack
5192732cee fix(web): keep task checkboxes controlled so check-all updates render
remark-gfm passes checked as undefined for unchecked task items, so the
Base UI Checkbox mounted uncontrolled and permanently ignored the
checked=true arriving after "Check all tasks" rewrote the memo content.
Coerce the prop to a boolean so the checkbox is always controlled.

Also drop the `${updateTime}` suffixes from memo React keys and the
comment editor cache key: a protobuf-es Timestamp stringifies to
"[object Object]", so the suffix was a constant — the keys were
effectively name-only already, and now say so honestly.

Fixes usememos/memos#6143
2026-08-06 09:09:37 +08:00
johnnyjoygh
4eee9a5fb4 chore(web): prune frontend dependencies
- Upgrade Base UI and i18n packages for TypeScript 7 support
- Remove unused runtime, type, and build dependencies
- Delete the orphaned UUID helper
2026-08-06 00:13:09 +08:00
johnnyjoygh
b930b1090a refactor(sidebar): reduce tooltip noise and refine tags
- Centralize tooltip timing and limit hints to useful content.\n- Simplify tag hierarchy presentation and align compact tag rows.
2026-08-05 23:52:13 +08:00
johnnyjoygh
6fbc81337f chore(sidebar): improve view and tag controls
- expose display settings from the Views header and refine layout controls
- add explicit tag list/tree navigation with accessible expansion behavior
- cover view persistence, menu behavior, and tag tree construction
2026-08-05 23:12:49 +08:00
johnnyjoygh
d14a542002 chore(web): add static navigation for default routes
- Show auth-aware common destinations when a route has no contextual sidebar.
- Restore About as a standalone page and route all About entries to it.
2026-08-05 21:46:34 +08:00
johnnyjoygh
83eab44695 fix(web): preserve memo scope across global navigation 2026-08-05 09:32:41 +08:00
Johnny
4d2667983f
feat(web): unify navigation in a route-aware sidebar (#6144) 2026-08-05 09:05:57 +08:00
Justin Zobel
156ee7edac
chore(ci): remove stale issue and pull request automation (#6133)
Remove the aggressive 14-day stale and 3-day close policy so valid issues and contributions are not discarded during maintainer review delays.
2026-08-02 21:19:03 +08:00
Johnny
d617f652b0
fix(markdown): support word-internal apostrophes in tags (#6135) 2026-08-02 21:08:57 +08:00
Johnny
8648b97b9e
feat(user): define username format and mention syntax (#6134) 2026-08-02 19:57:16 +08:00
johnnyjoygh
464e45b447 chore: update demo data 2026-08-02 16:31:24 +08:00
Johnny
c68e3d5bf9
feat(markdown): unify tag syntax and recognition (#6132) 2026-08-02 14:46:04 +08:00
boojack
571e0a3ff6 chore: scope memo providers to authenticated routes 2026-07-30 23:42:37 +08:00
boojack
b895a462da chore: update demo banner 2026-07-30 23:18:13 +08:00
boojack
dd18002b12 perf(sse): reduce redundant connections and fanout overhead
- Share one visible-tab connection across a browser and harden retries.\n- Preframe hub events, disconnect slow clients, and reset idle heartbeats.\n- Add cross-tab, concurrency, race, and fanout benchmark coverage.
2026-07-29 21:47:54 +08:00
boojack
c4221c6dfe fix(attachments): link media to source memos
Close https://github.com/usememos/memos/issues/6120
2026-07-29 09:06:42 +08:00
boojack
6f1ff135fb chore: add global quick-create entry
Use the authenticated navigation logo to open the existing focus-mode editor and preserve the draft cursor across reopenings.
2026-07-29 08:57:04 +08:00
johnnyjoygh
9328413797 fix(ui): keep select menus above parent popovers 2026-07-27 22:05:20 +08:00
johnnyjoygh
b4fefa94d7 fix(editor): restore Windows emoji input 2026-07-27 22:05:16 +08:00
boojack
2036c1ffc1
chore(main): release 0.30.0 (#6110)
Co-authored-by: johnnyjoygh <johnnyjoygg@gmail.com>
2026-07-26 23:45:43 +08:00
johnnyjoygh
c536434b81 test(release): cover 0.30.0 changelog promises 2026-07-26 22:21:19 +08:00
johnnyjoygh
8054cd536d chore(release): disable prerelease 2026-07-26 21:30:23 +08:00
johnnyjoygh
1236d9ba94 test(ci): add upgrade and startup smoke coverage
Exercise real server startup on backend test runs and gate releases on fresh-install, previous-stable upgrade, and entrypoint smoke checks across supported databases.
2026-07-26 21:21:15 +08:00
johnnyjoygh
415a3ec73d fix(auth): enforce private instance access boundaries
- Resolve Gateway procedures from matched HTTP bindings before authorization.\n- Disable anonymous RSS on private instances.\n- Limit share-token access to the shared memo and its attachments.
2026-07-26 21:13:21 +08:00
johnnyjoygh
0d2cbd4f5a refactor: expose shared memo as memo resource
Rename GetMemoByShare to GetSharedMemo and move REST resolution to /api/v1/shares/{share_token}/memo.\n\nBREAKING CHANGE: remove GET /api/v1/shares/{share_id} and the GetMemoByShare RPC.
2026-07-26 21:13:18 +08:00
Johnny
390126f1cd
fix(mcp): harden tool schemas and request routing (#6115) 2026-07-25 09:54:12 +08:00
Johnny
019f4f9adc
fix(auth): provision SSO users atomically (#6114) 2026-07-25 09:47:16 +08:00
Johnny
7cedcc9c22
test(email): make SMTP failure test deterministic (#6113) 2026-07-25 09:33:00 +08:00
Chad Harp
03e34bd0da
fix(mcp): accept canonical resource names in path params and keep error results schema-valid (#6108) 2026-07-24 00:15:13 +08:00
boojack
41dd3d1740
chore(main): release 0.30.0-rc.2 (#6096) 2026-07-20 23:35:59 +08:00
boojack
cc20327b8a chore(access-token): default expiration to never 2026-07-20 20:03:05 +08:00
boojack
b7d5d09f8a fix(api): update UID compatibility
Use the original UID format consistently across API, username, and store validation so UUID-based callers continue to work. Regenerate API documentation and add regression coverage for UUID memo IDs.
2026-07-20 19:41:55 +08:00
boojack
d149a96566 chore(release): enable prerelease 2026-07-20 08:54:41 +08:00
johnnyjoygh
249b331596 perf(web): reduce memo feed startup and rendering work 2026-07-20 00:15:26 +08:00
johnnyjoygh
7c78320999 chore: cleanup docs 2026-07-19 23:51:11 +08:00
johnnyjoygh
06ecef33bc chore(web): update about page and access token settings 2026-07-19 22:23:51 +08:00
johnnyjoygh
f94697496b docs: polish README and add web clipper 2026-07-18 23:43:21 +08:00
johnnyjoygh
6c1055f483 perf(web): deduplicate explore data requests
Share canonical user and memo query caches across creator, reaction, comment, mention, and relation lookups. Reuse list data for relation snippets and cover overlapping queries with regression tests.
2026-07-18 23:25:59 +08:00
johnnyjoygh
88c6ee8ebc perf(web): reduce demo bandwidth usage
- Cache fingerprinted frontend assets for one month.
- Load media, rich renderers, dialogs, and editors only when needed.
- Simplify seeded demo content and cover deferred-loading behavior.
2026-07-18 22:06:14 +08:00
johnnyjoygh
0bfeb91d50 fix(api): show clean RPC error messages 2026-07-18 11:20:15 +08:00
johnnyjoygh
84776cc106 fix(api): align resource IDs with AIP conventions
Validate new user-provided IDs using the AIP-122 format while retaining legacy UID compatibility. Correct resource annotations and canonical names returned by user stats.
2026-07-18 11:12:28 +08:00
johnnyjoygh
715306ea66 chore: enrich access tokens setting page
Settings drops the all-in-one bordered card for a de-carded layout in
the property-rail design language: a sticky table-of-contents rail at
md+ (Settings wordmark, uppercase group labels, quiet anchor rows) and
a horizontally swipeable chip strip below md, replacing the mobile
section dropdown. Nav items are real anchors with aria-current, and
switching sections scrolls back to the top.

Access Tokens becomes a first-class section with an explainer panel:
what a PAT is and a copyable curl example (real instance origin,
memos_pat_ prefix) beside token-safety guidelines in a two-column band,
with a Learn more docs link and the tokens table beneath. Successful
PAT authentication now records the token's lastUsedAt asynchronously
inside resolveBearer, with a clone-before-mutate cache guard and
monotonic writes in the store, surfaced in a Last used column.

Also localizes the create dialog's 90 Days label, lets the My Account
row wrap instead of clipping on narrow screens, and drops the dead
select-section key from all locales.
2026-07-18 10:41:53 +08:00
Dedy F. Setyawan
2d01420c23
fix(web): align radio button group indicator (#6097)
Signed-off-by: Dedy F. Setyawan <dedyfajars@gmail.com>
2026-07-18 01:47:45 +08:00
boojack
469c995cc0 chore: dump demo data
Login on the demo instance is SSO-only, so visitors always arrive as a
fresh user and consume seed content through Explore. Rebuild the seed
around that funnel: four personas (steven the maintainer, alice, ben,
zoe), a public feed mixing short captures with long-form anchors, and
protected memos that visibly appear after sign-in to teach the
visibility model.

Every headline feature is now demonstrated: nested tags, memo
references, comments with mentions, reactions, locations, a database-
stored image attachment, and a rendering test memo covering math,
mermaid, code, tables, and task lists.
2026-07-17 00:14:01 +08:00
boojack
d4b5a1695b feat(web): redesign memo detail sidebar as property rail
Rework MemoDetailSidebar into a Linear-style rail: a quiet icon action
cluster (pin, copy link, share image, share links) followed by
label/value property rows for visibility, created/edited times, author,
and location, then hairline-separated sections for tags, attachments,
relations, and the outline. Attachments and reference relations were
previously not surfaced in the sidebar at all.

- Visibility is editable in place, reusing VisibilitySelector with a
  new compact size variant that matches the 13px row grammar
- Pin toggle and visibility changes go through useUpdateMemo
- MemoOutline gains active-section tracking (scroll-spy), depth
  indentation, and tick-rail styling; drops the animated underline
  and native title tooltips
- Widen the detail rail from w-56 to w-60
2026-07-16 23:59:31 +08:00
boojack
e497895bf3 feat(web): restore scroll position across navigation 2026-07-16 22:31:00 +08:00
boojack
773e56e537 fix(web): position tooltip arrows outside content
Closes #6095
2026-07-15 22:29:38 +08:00
boojack
49516395da chore(release): disable prerelease 2026-07-15 21:53:27 +08:00
boojack
57d579a2a2
chore(main): release 0.30.0-rc.1 (#6015) 2026-07-15 00:19:47 +08:00