Commit graph

106 commits

Author SHA1 Message Date
ABird
66b9cb49c1
feat(spaces): add space-aware UI and filtering (#6230) 2026-08-24 23:13:55 +08:00
amblued
6da8461e1d
feat(spaces): add multi-space memo collaboration (#6228) 2026-08-23 19:36:50 +08:00
amblued
76a7629243
feat(instance): persist access mode independently of URL (#6225) 2026-08-22 14:15:31 +08:00
amblued
fe9a9bdf64
refactor(reaction): link reactions to memo IDs (#6221) 2026-08-22 00:12:35 +08:00
amblued
57a4b7aee6
chore(go): upgrade to Go 1.27 (#6217) 2026-08-20 23:37:02 +08:00
amblued
38412eb75a
fix(storage): proxy S3 attachments through authenticated routes (#6210) 2026-08-18 23:38:35 +08:00
Johnny
7d971b1c61
feat(storage): add named attachment storage drivers (#6184) 2026-08-13 22:37:11 +08:00
Johnny
da81b6b48f
feat: persist and display client media metadata (#6180) 2026-08-11 23:47:21 +08:00
Johnny
bd636a4365
feat: support memo-scoped Markdown attachment images (#6169) 2026-08-09 23:27:18 +08:00
Johnny
4e8b262d6d
refactor(memo-views): replace shortcuts with saved views (#6167) 2026-08-09 20:27:27 +08:00
Johnny
8648b97b9e
feat(user): define username format and mention syntax (#6134) 2026-08-02 19:57:16 +08:00
Johnny
c68e3d5bf9
feat(markdown): unify tag syntax and recognition (#6132) 2026-08-02 14:46:04 +08:00
boojack
dd18002b12 perf(sse): reduce redundant connections and fanout overhead
- Share one visible-tab connection across a browser and harden retries.\n- Preframe hub events, disconnect slow clients, and reset idle heartbeats.\n- Add cross-tab, concurrency, race, and fanout benchmark coverage.
2026-07-29 21:47:54 +08:00
johnnyjoygh
c536434b81 test(release): cover 0.30.0 changelog promises 2026-07-26 22:21:19 +08:00
johnnyjoygh
415a3ec73d fix(auth): enforce private instance access boundaries
- Resolve Gateway procedures from matched HTTP bindings before authorization.\n- Disable anonymous RSS on private instances.\n- Limit share-token access to the shared memo and its attachments.
2026-07-26 21:13:21 +08:00
johnnyjoygh
0d2cbd4f5a refactor: expose shared memo as memo resource
Rename GetMemoByShare to GetSharedMemo and move REST resolution to /api/v1/shares/{share_token}/memo.\n\nBREAKING CHANGE: remove GET /api/v1/shares/{share_id} and the GetMemoByShare RPC.
2026-07-26 21:13:18 +08:00
Johnny
019f4f9adc
fix(auth): provision SSO users atomically (#6114) 2026-07-25 09:47:16 +08:00
boojack
b7d5d09f8a fix(api): update UID compatibility
Use the original UID format consistently across API, username, and store validation so UUID-based callers continue to work. Regenerate API documentation and add regression coverage for UUID memo IDs.
2026-07-20 19:41:55 +08:00
johnnyjoygh
84776cc106 fix(api): align resource IDs with AIP conventions
Validate new user-provided IDs using the AIP-122 format while retaining legacy UID compatibility. Correct resource annotations and canonical names returned by user stats.
2026-07-18 11:12:28 +08:00
johnnyjoygh
715306ea66 chore: enrich access tokens setting page
Settings drops the all-in-one bordered card for a de-carded layout in
the property-rail design language: a sticky table-of-contents rail at
md+ (Settings wordmark, uppercase group labels, quiet anchor rows) and
a horizontally swipeable chip strip below md, replacing the mobile
section dropdown. Nav items are real anchors with aria-current, and
switching sections scrolls back to the top.

Access Tokens becomes a first-class section with an explainer panel:
what a PAT is and a copyable curl example (real instance origin,
memos_pat_ prefix) beside token-safety guidelines in a two-column band,
with a Learn more docs link and the tokens table beneath. Successful
PAT authentication now records the token's lastUsedAt asynchronously
inside resolveBearer, with a clone-before-mutate cache guard and
monotonic writes in the store, surfaced in a Last used column.

Also localizes the create dialog's 90 Days label, lets the My Account
row wrap instead of clipping on narrow screens, and drops the dead
select-section key from all locales.
2026-07-18 10:41:53 +08:00
boojack
0038295bbc feat(config): provision settings from secret files
- Load IdPs and supported instance-setting groups as runtime overlays from /etc/secrets.
- Reject API mutations of deployment-managed resources and serialize authentication safety checks across database drivers.
- Preserve upgrade compatibility, demo SSO policy, stable IdP ordering, and driver-specific transaction retries.
2026-07-13 22:34:24 +08:00
boojack
4bc3928029 fix(user): implement ListUsers pagination
Rework ListUsers to match the ListMemos pagination contract: opaque
PageToken, normalizePageSize, DB-level limit+1 look-ahead, and a
next_page_token. Adds Offset to store.FindUser with an OFFSET clause in
all three dialects, and an `id DESC` ORDER BY tiebreaker so offset pages
stay stable when created_ts ties.

Also align pagination across list endpoints:
- Bump DefaultPageSize 10 -> 50 to match the documented default; use
  normalizePageSize in ListAttachments.
- Remove the never-implemented total_size field from all six list
  responses (ListUsers, ListAttachments, ListMemoComments,
  ListMemoReactions, ListUserSettings, ListPersonalAccessTokens) and
  regenerate.
- useListUsers now pages through next_page_token so the admin members
  view still loads every user past the default page size.
2026-07-12 20:51:04 +08:00
boojack
d1cef7a9ab feat(auth): add private instance mode derived from instance_url
Run the instance in private mode when instance_url is not configured: the API rejects anonymous requests except the auth-bootstrap set (sign-in, token refresh, instance profile/settings, SSO providers, share-link access) plus first-run user creation, and the web UI redirects anonymous visitors to /auth instead of /explore. Setting instance_url keeps the current public behavior. Access tokens and personal access tokens are never gated.

Enforcement lives in a shared Authorizer used by both the Connect interceptor and the gRPC-gateway middleware; the file server applies the same rule to public-memo attachments and avatars. Also merges the duplicated Authenticate/AuthenticateToUser token dispatch behind resolveBearer, dedups the AuthContext unauthenticated state, extracts the redirect decision into a pure shouldGatePrivateInstance helper, and prints the access mode at startup.
2026-07-05 22:48:00 +08:00
johnnyjoygh
96cb65320b fix(instance): add needs_setup so admin-less instances aren't treated as fresh
The frontend keyed first-run setup off a null InstanceProfile.admin, but a
null admin only means "no admin-role user exists" — which also happens on a
populated instance that has lost all its admins. Such an instance was wrongly
redirected to signup, where the new account is created as a normal user (the
first-user promotion only triggers when there are zero users), leaving the
instance permanently admin-less.

Add an explicit InstanceProfile.needs_setup derived from user count == 0, and
switch the signup redirect and host tip to use it. admin stays for display only.
2026-06-21 22:14:15 +08:00
boojack
9eabb554d5
feat(settings): move tag metadata to user settings (#6017) 2026-06-07 23:58:00 +08:00
boojack
e53b7d96e7
fix: delete user cleanup (#5981) 2026-05-25 22:10:29 +08:00
boojack
f3f059b2f7 chore: add batch get settings API 2026-05-09 09:30:28 +08:00
boojack
21303e879d fix(sse): stream initial response and refresh tokens 2026-05-09 09:15:50 +08:00
boojack
88ac3ec31e feat(stats): support filtered all-user stats
- Add state and filter inputs to ListAllUserStats and reuse it for explore/archive sidebar stats.
- Reduce duplicate home initialization requests by sharing stats/settings data paths.
- Include memo paragraph regression coverage from the current working tree.
2026-05-09 09:11:04 +08:00
boojack
4a1e401bd9 fix(memo): enforce parent visibility for comments 2026-05-08 23:22:56 +08:00
boojack
5ccba98adc
refactor: split STT and Audio-LLM into separate interfaces (#5928) 2026-05-03 00:21:58 +08:00
boojack
238f27dea1
feat(transcription): explicit STT settings with provider, model, prompt (#5926) 2026-05-02 19:35:18 +08:00
Steven
8daef1dc89 feat(activity-calendar): aggregate by ViewContext.timeBasis
Fixes the inconsistency where switching the memo list to update_time
left the activity heatmap aggregating by created_time. The heatmap
now follows the same time basis as the list it sits next to.

Backend
- UserStats gains memo_updated_timestamps (additive proto field, tag 8).
- GetUserStats and ListAllUserStats populate it alongside the existing
  memo_created_timestamps. No DB migration; memo.updated_ts already
  exists on every row.

Frontend
- useFilteredMemoStats reads timeBasis from ViewContext and selects
  the matching timestamp source.
- StatisticsView and MonthNavigator forward timeBasis through to
  MonthCalendar / YearCalendar so tooltip text matches the basis
  ("X memos in DATE" vs "X memos updated on DATE").
- Falls back to memoCreatedTimestamps when an old server returns an
  empty memoUpdatedTimestamps array (detected by length divergence,
  since protobuf-es deserializes missing repeated fields as []).

Tests
- Backend: TestGetUserStats_MemoUpdatedTimestamps verifies the field
  is populated and reflects post-creation updates.
- Frontend: filtered-memo-stats covers create/update source switching
  and the old-server fallback path; activity-calendar-tooltip covers
  basis-aware label selection.

Spec and implementation plan committed under docs/superpowers/.
2026-05-02 00:26:53 +08:00
Steven
ea0625da45 feat(stats): admin instance resource statistics 2026-05-01 23:15:56 +08:00
Steven
cd4f28ae10 feat(notification): add smtp email settings
- Add admin notification email settings UI and test-email RPC
- Dispatch privacy-first comment and mention emails through server notification layer
- Keep SMTP secrets write-only and require passwords when SMTP identity changes
2026-05-01 18:48:21 +08:00
Steven
35bf761b8c fix(security): enforce attachment ownership on memo updates 2026-05-01 18:23:53 +08:00
boojack
1df3fe7955
fix(user): omit internal settings from list responses (#5917) 2026-04-30 08:49:03 +08:00
boojack
94ce1e5347 chore(settings): show build commit in version info 2026-04-27 08:51:11 +08:00
boojack
c268551a16
feat(memos): choose created or updated time for memos (#5894) 2026-04-26 11:50:26 +08:00
boojack
0fb83a745d
fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
boojack
ee1799851e
feat: redesign account and SSO management (#5886) 2026-04-24 09:08:58 +08:00
boojack
30c0611a82
fix: fix legacy username auth flows (#5885) 2026-04-23 22:35:38 +08:00
boojack
d688914b28
feat(auth): add SSO user identity linkage (#5883) 2026-04-23 08:51:45 +08:00
boojack
50638040f6
fix: reduce list memo query overhead (#5880) 2026-04-22 09:31:48 +08:00
boojack
01be01f4b7
fix: mixed-case user resource names (#5853) 2026-04-19 10:44:25 +08:00
boojack
c45663761d fix(api): reduce memory pressure in backend paths 2026-04-16 23:08:48 +08:00
boojack
8479e1d5a3 test: close SSE response body explicitly 2026-04-16 22:57:31 +08:00
boojack
a5ddd5adaf fix(server): close SSE clients during shutdown
Close long-lived SSE streams before HTTP shutdown so graceful shutdown is not held until the deadline. Also wait for background runners before closing the store to make shutdown ordering explicit.
2026-04-16 22:49:10 +08:00
boojack
101704c8ea
feat(ai): add BYOK audio transcription (#5832) 2026-04-13 22:09:24 +08:00
boojack
0ad0fec8d4 feat(ai): add Anthropic provider option 2026-04-12 21:42:17 +08:00