Commit graph

4564 commits

Author SHA1 Message Date
greymoth
a5c10a7221
i18n(ja): complete Japanese translations — fill 24 missing keys (#6048) 2026-06-25 18:11:23 +08:00
boojack
5f7e038aa7 fix(editor): support backslash-escaping literal #tags
Memos layers #tag syntax on top of CommonMark, but there was no way to
write a literal "#NAS" — it always became a clickable tag (issue #6035).

Handle escapes lexically, the way TipTap/prosemirror-markdown do, with no
"escaped tag" node in the document model:

- Parse: marked's built-in backslash escape already turns "\#NAS" into
  plain text; the read-only renderer (remark-tag) now honors the same
  escape by lexing from the original source slice and falling back to the
  prior value-based parse when it can't faithfully reconstruct the text.
- Serialize: a tag-aware Markdown extension (tagMarkdown.ts) backslash-
  escapes a "#" that would re-parse into a tag, skipping links and code
  where tags never form.
- The editor's #tag lexing moves to the canonical @tiptap/markdown
  markdownTokenizer; tag-in-link skipping moves to a tree pass so the
  editor and renderer agree.

The capped tag-run grammar is consolidated into utils/tag-grammar.ts
(TAG_RUN), shared by the tokenizer, the serialize-escape, and the
renderer so they can't drift. README documents why the markdown manager
is worked around in three places.
2026-06-23 23:00:54 +08:00
boojack
20c19ef82d feat(storage): add insecure_skip_tls_verify option for S3
Adds an opt-in toggle to skip TLS certificate verification when connecting
to the S3 endpoint, for self-hosted S3-compatible backends (e.g. rustfs,
MinIO) that use self-signed certificates. Exposed in both the store/API
protos and the storage settings UI, mirroring the existing use_path_style
toggle. When enabled, the AWS client uses an HTTP transport with
InsecureSkipVerify; default behavior is unchanged.

This governs backend-initiated S3 calls (uploads, deletes, thumbnails, and
image/document streaming). Video/audio playback redirects the browser to a
presigned URL, so that path still requires the browser to trust the cert.

Closes #6039
2026-06-23 00:04:54 +08:00
boojack
1e3ec38fa1 refactor(editor): modularize formatting and simplify editor state
Behavior-preserving restructure of the MemoEditor subsystem for simplicity
and extensibility:

- Add a data-driven command catalog (editorCommands.ts) as the single source
  for formatting verbs; the toolbar, active-state hook, and WYSIWYG handle all
  derive from it, so adding a verb is a one-file change.
- Add a createSuggestionExtension factory; TagSuggestion consumes it, so new
  `/` or `@` triggers reuse the shared popup in ~10 lines.
- Collapse FormattingController into a single EditorController with an optional
  `formatting` capability; PlainEditor is an honest textarea fallback (no faked
  formatting); replace stringly-typed isActive with typed getActiveFormats.
- Move audio-recorder state out of the reducer into useAudioRecorder, keeping a
  single recorderBusy flag in the store.
- Convert the editor context to an external store (useSyncExternalStore) with
  per-slice subscriptions, so typing no longer re-renders the toolbar, insert
  menu, or metadata.
- Extract the shared #tag lexing grammar (tag-grammar.ts) used by both the
  editor tokenizer and the remark renderer.
- Remove dead reducer actions/cases and fix a preview blob-URL leak on the
  upload path.

Add tests for the command catalog, suggestion factory, and autosave.
2026-06-22 23:51:59 +08:00
boojack
26f4b73cb9 feat(filter): standard CEL now variable, time accessors, set ops
Replace the custom now() function with an idiomatic `now` timestamp variable (host-injected, frozen once per compile) and retype created_ts/updated_ts/create_time to CEL timestamp. Filters now use standard timestamp/duration arithmetic, e.g. `created_ts >= now - duration("24h")` and `timestamp("2025-01-01T00:00:00Z")`.

Add standard CEL surface that compiles to SQL across SQLite/MySQL/Postgres: timestamp accessors (getFullYear/getMonth/getDate/getDayOfWeek/..., with 0-based month and weekday normalized), ext.Sets() (sets.contains/intersects/equivalent over tags), tags.exists_one(), size() on string fields, and division/modulo folding. A frozen clock is injectable for deterministic tests.

BREAKING CHANGE: now() is removed (use the `now` variable) and time fields are timestamps, so bare-epoch comparisons need timestamp(<epoch>). Existing saved shortcuts using the old syntax must be updated.
2026-06-22 22:42:44 +08:00
johnnyjoygh
cafa56f1a8 chore: make compact mode an opt-in view setting
Memo list views hard-coded compact rendering, truncating long memos by
default. Make full content the default and add a persisted 'Compact mode'
toggle (default off) in the display-settings popover, backed by the
localStorage ViewContext. Wire Home/Explore/Archived/UserProfile to read
it; add the compact-mode label across all locales.
2026-06-21 22:55:56 +08:00
johnnyjoygh
8fa2ff4423 fix(mcp): allow reverse-proxied instances to serve /mcp
The go-sdk Streamable HTTP handler enables DNS-rebinding protection that
rejects any request whose Host header is non-loopback while the server is
bound to a loopback address. memos is commonly run bound to loopback behind a
reverse proxy (e.g. the public demo), so every /mcp request was rejected with
"403 Forbidden: invalid Host header" before authentication ran.

Disable the SDK's localhost protection and rely on memos' own Origin/Host
allowlist (isAllowedMCPOrigin) for CSRF / DNS-rebinding protection. Add a
regression test covering the proxied shape and confirming disallowed origins
are still rejected.
2026-06-21 22:20:00 +08:00
johnnyjoygh
96cb65320b fix(instance): add needs_setup so admin-less instances aren't treated as fresh
The frontend keyed first-run setup off a null InstanceProfile.admin, but a
null admin only means "no admin-role user exists" — which also happens on a
populated instance that has lost all its admins. Such an instance was wrongly
redirected to signup, where the new account is created as a normal user (the
first-user promotion only triggers when there are zero users), leaving the
instance permanently admin-less.

Add an explicit InstanceProfile.needs_setup derived from user count == 0, and
switch the signup redirect and host tip to use it. admin stays for display only.
2026-06-21 22:14:15 +08:00
johnnyjoygh
6eb17864df feat: surface newly created memo above pinned list 2026-06-21 14:11:46 +08:00
johnnyjoygh
deddf71d7b feat(editor): add focus-mode formatting toolbar
Add a rich-text formatting toolbar as the focus-mode header when the
WYSIWYG editor is active: heading dropdown, bold/italic/code, lists, and
link, with a priority+overflow responsive layout and live active-state
highlighting. The toolbar is a self-contained component driven through a
new FormattingController surface routed via EditorContent.

Remove the now-redundant slash-command feature (/todo, /code, /link,
/table) and its "Type / for commands" hint, since the toolbar covers
those actions; the shared suggestion renderer stays for #tag.
2026-06-21 11:57:45 +08:00
johnnyjoygh
f727ad217c fix(comments): list all memo comments via pagination
Memo detail only showed the first 10 comments: the frontend requested
pageSize=0, which the backend normalizes to DefaultPageSize (10), and the
returned nextPageToken was never followed.

Add useInfiniteMemoComments (mirrors useInfiniteMemos) so the detail page
paginates through every comment, with a "Load more" control in
MemoCommentSection. Page size defaults to DEFAULT_LIST_MEMOS_PAGE_SIZE to
match the memo list convention.
2026-06-21 09:55:37 +08:00
johnnyjoygh
f5a60263b2 chore(ui): align frontend on shadcn kit
Design system:
- add semantic --success/--warning OKLCH tokens across themes; replace
  hardcoded green/amber feedback colors and their manual dark: overrides
- drop the unused @emotion dependency

Kit usage:
- migrate raw <button>/<input> to ui-kit components (actions) or
  <div>/<span> (non-action surfaces); keep genuinely custom looks as
  raw HTML with their own styles
- make kit usage prop-only (no className overrides): add Button
  size="icon-sm", Badge "warning" variant + "pill" shape
- extract a shared Tabs primitive (segmented/underline) and migrate
  Inboxes + UserProfile onto it
- tokenize z-index tiers as z-overlay/z-dropdown/z-tooltip
- export variant types (ButtonVariant/Size, BadgeVariant/Shape, TabsVariant)
- document the kit and its policy in components/ui/README.md
2026-06-21 09:17:04 +08:00
boojack
3b07f78fd8 chore: tweak demo data
- Trim sponsor memo to CodeRabbit + SSD Nodes, concise single-tier layout
- Add a demo personal access token (Bearer memos_pat_demo) for the admin user
- Stagger memo created_ts relative to seed time so the demo timeline always
  looks recent; lead the pinned section with the Welcome memo
- Unpin the Scratchpad promo and drop the fixed "June" movie-marathon label
2026-06-19 13:38:02 +08:00
boojack
f0e4a5624f feat(filter): expand CEL filter surface with startsWith/endsWith, matches(), and all()
Let users write three more CEL constructs in the filter field, each compiled to
SQL across SQLite/MySQL/Postgres:

- Scalar startsWith()/endsWith() on content/filename/mime_type (case-insensitive)
- matches() regex: PG ~, MySQL/SQLite REGEXP (Go-backed SQLite fn), validated at
  compile time via cel.ValidateRegexLiterals()
- all() comprehension over tags via per-element subqueries, non-empty required

Also: contains() now escapes LIKE metacharacters (%, _, \); cross-dialect render
tests plus behavioral tests; cel-go bumped to v0.28.1; new operators surfaced in
the frontend shortcut guide.
2026-06-15 23:22:28 +08:00
boojack
817561df8f fix(editor): collapse lingering select-all selection after delete
Ctrl+A creates a whole-document AllSelection; deleting it (Backspace, Delete, or Cut) maps the AllSelection onto the now-empty paragraph instead of collapsing to a caret, so the view paints a "selected" empty block. A ProseMirror appendTransaction now collapses a leftover AllSelection to a caret after any doc-changing edit.
2026-06-15 09:33:16 +08:00
ManJieqi
46685b1906
chore: update Chinese translations in zh-Hans.json (#6033)
Signed-off-by: ManJieqi <40858189+manjieqi@users.noreply.github.com>
2026-06-14 23:23:18 +08:00
boojack
385fa22056 fix(cors): open API to any origin for token auth, keep cookies same-origin
Reflect any Origin so token-authenticated clients (Access Token V2 / PAT)
can call the API cross-origin, but emit Access-Control-Allow-Credentials
only for trusted origins (same host / configured InstanceURL). This keeps
the SameSite=Lax refresh cookie unreadable by untrusted (incl. same-site
subdomain) origins. Origin: null is not reflected.

Note for operators: cross-origin token access is now open by default; if
you front memos with a caching proxy, ensure it honors `Vary: Origin`.
2026-06-14 23:20:34 +08:00
boojack
00225db922 refactor(web): share markdown element styles between viewer and editor
Extract the Tailwind classes for common markdown elements (paragraph,
blockquote, lists, inline code, link, hr, headings) into a single
markdownStyles.ts consumed by both the read-only MemoContent components
and the WYSIWYG editor, replacing the duplicated per-element strings and
the .memo-wysiwyg CSS block. Heading classes are precomputed per level so
the hot renderHTML path is a lookup, not a cn() merge.

Also require at least one character after `#` before opening the tag
suggestion menu so a bare `#` (or `# ` heading) no longer conflicts with
markdown headings.
2026-06-13 22:17:00 +08:00
boojack
2c0efeba7c refactor(web): rename editor dirs and simplify raw mode to a plain textarea 2026-06-13 01:08:38 +08:00
boojack
797f1ff15d
feat(web): markdown WYSIWYG editor with raw-mode toggle (#6030)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-06-12 09:34:51 +08:00
boojack
8080bd10e1 docs: add README for mcp 2026-06-09 23:54:58 +08:00
boojack
f497f009ce fix(webhook): fail loud on malformed signing secret and add tests
Follow-up to #6013. The signing path silently fell back to using the raw
secret string as the HMAC key when a whsec_-prefixed secret had invalid
base64, producing signatures no receiver could verify with no server-side
signal.

- Extract resolveSigningKey helper that errors on invalid whsec_ base64
- Post returns that error (logged by the async dispatcher); ValidateSigningSecret
  rejects it at write time so a bad secret is never stored
- Fix stale comment referencing a nonexistent Authorization header
- Add Go tests: key derivation, secret validation, end-to-end signature
  round-trip, and the invariant that the secret never leaks into API responses
2026-06-09 22:58:10 +08:00
Yiges.M.x.
063a44498d
feat: add optional webhook signing secret (Standard Webhooks HMAC-SHA256) (#6013) 2026-06-09 22:45:01 +08:00
boojack
1052c04d33 fix(web): improve mobile control spacing 2026-06-09 21:04:47 +08:00
boojack
418398587c feat(i18n): add searchable locale picker 2026-06-09 09:33:17 +08:00
boojack
777d227eb9
feat: add OpenAPI-driven MCP support (#6026) 2026-06-09 09:16:50 +08:00
boojack
a47d04954e feat(i18n): expand European locale coverage 2026-06-09 09:07:28 +08:00
boojack
6870e863de chore(github): improve issue templates with structured triage fields
Add area dropdowns, reproduction requirements, regression info, and
compatibility sections to reduce back-and-forth on bug reports and
feature requests.
2026-06-08 22:21:33 +08:00
boojack
ecbe2ab797 fix(memo): preserve expanded todo list state 2026-06-08 19:11:29 +08:00
ay5399
8f1377324f
fix(editor): wire Ctrl+B and Ctrl+I markdown shortcuts to textarea (#6016)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: boojack <stevenlgtm@gmail.com>
2026-06-08 00:24:05 +08:00
boojack
9eabb554d5
feat(settings): move tag metadata to user settings (#6017) 2026-06-07 23:58:00 +08:00
boojack
a50ce09e81 fix(markdown): ignore tags inside links 2026-06-06 00:01:28 +08:00
boojack
5e71c0a737 docs: rewrite agent repository guide 2026-06-05 09:17:22 +08:00
boojack
2a4638b332 chore: remove MCP server 2026-06-05 08:38:57 +08:00
boojack
5f194da7d3
chore(main): release 0.29.1 (#5985) 2026-06-05 08:06:30 +08:00
boojack
bb76949fc0 chore(server): centralize CORS policy 2026-06-04 22:37:41 +08:00
boojack
d69f1aab27 chore: tweak demo data 2026-06-03 00:21:45 +08:00
boojack
0e2a9a9c0c fix(web): render video attachment posters on mobile 2026-06-02 23:08:16 +08:00
goingforstudying-ctrl
e8d32e87d1
fix: support <meta name=description> in link previews (#6000)
Co-authored-by: goingforstudying-ctrl <goingforstudying-ctrl@users.noreply.github.com>
2026-06-02 23:02:21 +08:00
boojack
0d31e3c2fb chore(media): add zoom controls to preview dialog 2026-06-02 22:46:07 +08:00
boojack
fadc974364 docs: consolidate agent guidance 2026-05-31 18:53:37 +08:00
boojack
53abb8020e refactor(frontend): remove react-use dependency 2026-05-31 18:32:17 +08:00
boojack
7c3bff4e98 fix(markdown): keep task item content in one grid column 2026-05-27 23:57:23 +08:00
boojack
f22c4bd5c2
chore(main): release 0.29.0 (#5909) 2026-05-27 20:48:29 +08:00
boojack
e0bb3a2e68 fix(editor): wrap selected text when pasting URL 2026-05-27 20:36:27 +08:00
boojack
648b3bd812
feat(memo): add task list quick actions (#5983) 2026-05-27 09:13:55 +08:00
boojack
e564c1a993 chore: update about page 2026-05-26 21:14:59 +08:00
boojack
e53b7d96e7
fix: delete user cleanup (#5981) 2026-05-25 22:10:29 +08:00
boojack
d1208a68e9 chore: update sponsors 2026-05-25 20:39:25 +09:00
boojack
3c3382a3c6
fix: avoid update event on memo create attachments (#5961) 2026-05-16 21:18:44 +08:00