Commit Graph

16 Commits

Author SHA1 Message Date
schalli 48e3a693aa feat(06-01): scaffold apps/desktop as @tessera/desktop Tauri 2.x project
- Create Tauri project structure with Cargo.toml, tauri.conf.json, build.rs
- Implement lib.rs with store plugin and server URL navigation on startup
- Configure capabilities with core:default and store:default permissions
- Set frontendDist to ../src for local setup page (no bundled frontend)
- Add placeholder icons for build compatibility (to be replaced in 06-02)
- Add Cargo target/ to .gitignore
- Window config: 1280x800, centered, native decorations, resizable

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-25 10:13:20 +02:00
schalli 9ec6313f4d feat(05-03): calendar backend — model, crypto, source CRUD module
- Add CalendarSource Prisma model with encrypted credentials (AES-256-GCM)
- Create CalendarCryptoService with encrypt/decrypt using CALENDAR_ENCRYPTION_KEY
- Create CalendarController with source CRUD endpoints (GET/POST/PATCH/DELETE)
- Create CalendarService with ownership checks and SSRF URL validation
- Add DTOs with https-only URL validation and class-validator decorators
- Register CalendarModule in AppModule
- Install tsdav, node-ical, ews-javascript-api, @microsoft/microsoft-graph-client
- Stub provider files for Task 2 compilation
2026-06-24 15:09:03 +02:00
schalli dd0209898b feat(05-02): add search and note widgets with tests
- SearchWidget: provider dropdown, text input, button; opens search in new tab via window.open (D-14/D-15)
- NoteWidget: MDEditor with compact toolbar, debounced autosave (1500ms), AbortController for in-flight cancellation (D-16/D-17/D-18)
- rehype-sanitize enabled for Markdown XSS prevention (T-05-05)
- Widget registry updated with wireSearchWidget/wireNoteWidget (no more placeholders)
- dashboard-api.ts: added fetchSearchProviders, addSearchProvider, removeSearchProvider, signal support on updateWidgetConfig
- 9 new tests passing (search: 5, note: 4)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 11:33:01 +02:00
schalli d5e1c42e64 feat(05-01): dashboard grid, clock widget, widget registry, store, and tests
- Install react-grid-layout@2.2.3 and react-resizable
- Create widget-registry.tsx with all 4 widget types, WIDGET_CONSTRAINTS, WidgetProps
- Create dashboard-api.ts with fetch/save layout and widget CRUD functions
- Create dashboard-store.ts (Zustand, NO persist — D-05) with edit mode and auto-save on exit
- Create DashboardGrid with react-grid-layout v2 Responsive, ResizeObserver width
- Create ClockWidget using Intl.DateTimeFormat (no manual UTC offsets)
- Create WidgetWrapper with drag handle and delete button in edit mode
- Create EditModeToggle (pencil/checkmark), WidgetCatalogModal (2x2 grid)
- Rewrite portal page.tsx as dashboard with grid, edit toggle, widget catalog
- Add ResizeObserver polyfill in test setup, CSS mock support in vitest config
- All 5 tests green (dashboard grid + clock widget)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 11:21:43 +02:00
schalli e50b3c76c5 chore(04-01): install and configure Vitest test infrastructure for apps/web
- Add vitest, @testing-library/react, @testing-library/jest-dom, jsdom, @vitejs/plugin-react as dev deps
- Create vitest.config.ts with jsdom environment and @ path alias
- Create test setup file importing jest-dom/vitest matchers
- Add test scripts to apps/web and root package.json
- Add test task to turbo.json pipeline
2026-06-22 14:45:54 +02:00
schalli 8c24c1e267 feat(03-01): add Module SDK package and Prisma module registry schema
- Create @tessera/module-sdk with TesseraModule, ModuleRoute, ModuleManifest, ModuleCategory types
- Add Module and TenantModuleActivation Prisma models with tenant-scoped unique constraint
- Apply migration add-module-registry to PostgreSQL
- Framework-agnostic ComponentType for lazy-loaded module UIs
2026-06-19 12:33:55 +02:00
schalli f928cd7713 feat(02-04): LdapModule with sync service, config service, scheduler, and controller
- LdapService uses ldapts for DIRECTORY SYNC ONLY (anti-pattern avoidance)
- LdapConfigService creates default field mappings per D-16 (displayName, mail, sAMAccountName)
- Custom field mappings can be added/removed per D-17
- Per-tenant LDAP config per D-18
- syncUsersForTenant deactivates users removed from LDAP per D-15
- LdapSyncScheduler sets tenant context explicitly per Pitfall 2
- Manual sync endpoint POST /ldap/sync per D-14
- Auto-sync cron checks syncIntervalMin per D-14
- Test connection endpoint for LDAP config validation
- OpenLDAP + phpLDAPadmin added to docker-compose.dev.yml
- LDAP search filter sanitization per T-02-16
- bindPassword never returned in API responses per T-02-17
2026-06-19 08:38:07 +02:00
schalli ac617f4fe5 feat(02-03): password reset flow, force-change interceptor, MailModule
- MailModule with SMTP transport configured from ENV variables
- MailService for password reset and welcome emails (plain text, i18n)
- Password reset flow: request-reset (public), reset-password (token-based)
- Change password for logged-in users with current password verification
- Admin reset password endpoint (ADMIN/SUPER_ADMIN only, D-03)
- ForcePasswordChangeInterceptor blocks all routes except change-password,
  logout, me when mustChangePassword=true (D-06, Pitfall 5)
- Frontend: reset-password request page, token reset page, change-password page
- Forgot password link added to login page
- MailHog service added to docker-compose.dev.yml for dev email testing
- SMTP env vars added to docker-compose.yml (defaults to MailHog)
- Complete DE/EN i18n coverage for reset and change password flows
- SUS packages installed: @nestjs-modules/mailer, nodemailer, ldapts

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-18 13:48:23 +02:00
schalli bfb04eac66 feat(02-02): user CRUD API + admin page, tenant CRUD API + admin page
- Create UserController with GET/POST/PATCH/DELETE endpoints at /users
  - ADMIN sees own-tenant users only; SUPER_ADMIN sees all (T-02-10)
  - ADMIN cannot escalate to SUPER_ADMIN role (T-02-08)
  - ADMIN cannot delete self or cross-tenant users
- Create TenantController with GET/POST/PATCH/DELETE at /tenants
  - SUPER_ADMIN-only access (D-10)
  - Tenant deletion blocked if active users exist (T-02-09)
- Create CreateUserDto, UpdateUserDto, CreateTenantDto with class-validator
- Create admin/users page with user table, create/edit/delete modals
- Create admin/tenants page with tenant table, create/edit/deactivate (SUPER_ADMIN only)
- Add admin section to sidebar: Verwaltung > Benutzer + Mandanten
  - Verwaltung visible for ADMIN/SUPER_ADMIN; Tenants link SUPER_ADMIN only
- Install @nestjs/mapped-types for PartialType DTO pattern

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-18 13:38:54 +02:00
schalli cdf4d60038 feat(02-02): auth infrastructure -- route groups, middleware, session, auth-actions, auth store
- Create (auth) route group with standalone layout (no sidebar/header, D-04)
- Create (portal) route group wrapping children with AppShell
- Move dashboard page into (portal) route group
- Add Next.js middleware for JWT-based route protection using jose
- Create session.ts with verifySession/getSessionFromCookies helpers
- Create auth-actions.ts server actions: login, logout, fetchCurrentUser
- Create Zustand auth-store for client-side user state
- Install jose and zod dependencies

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-18 13:32:53 +02:00
schalli 6190f3dd39 feat(02-01): AuthModule with Passport strategies, guards, and decorators
- Create LocalStrategy (username/password via argon2) and JwtStrategy (cookie extractor)
- Create JwtAuthGuard with @Public() decorator support for route opt-out
- Create RolesGuard checking SUPER_ADMIN/ADMIN/USER roles per D-12
- Create AuthService with validateUser, login (30-day httpOnly cookie), logout
- Create AuthController with POST /auth/login, POST /auth/logout, GET /auth/me
- Create LoginDto with class-validator decorators
- Create @Public, @Roles, @CurrentUser decorators
- Update main.ts with ValidationPipe, CORS credentials, cookie-parser
- Install cookie-parser for httpOnly JWT cookie support
2026-06-18 13:24:59 +02:00
schalli d0b36c8f22 feat(02-01): Prisma schema expansion, RLS migration, and PrismaModule
- Add User, Role enum, PasswordResetToken, LdapConfig, LdapFieldMapping models
- Expand Tenant model with isActive, users relation, ldapConfig relation
- Create RLS migration with tenant isolation policies on all tenant-scoped tables
- Create PrismaModule (global), PrismaService, and forTenant extension
- Add JWT_SECRET, TESSERA_ADMIN_*, TESSERA_FORCE_CHANGE env vars to docker-compose
- Install @nestjs/jwt, @nestjs/passport, passport, argon2, class-validator deps
2026-06-18 13:22:38 +02:00
schalli f3791c6cdd feat(01-02): design token system, i18n framework, and theme provider setup
- OKLCH design tokens with yellow #ffed00 primary and dark gray-blue dark mode
- next-intl cookie-based locale with DE/EN message files
- next-themes provider with system/light/dark support
- Sidebar and header layout dimension tokens
- Root layout with ThemeProvider and NextIntlClientProvider wrappers
2026-06-18 10:22:42 +02:00
schalli 2c12878cb1 feat(01-01): Next.js app + Docker Compose stack with network segmentation
- Next.js 15 app with Tailwind CSS v4, standalone output for Docker
- Root layout with de locale, page with Tessera placeholder
- Multi-stage Dockerfile for web with monorepo root context
- Docker Compose with 4 services: traefik, web, api, db
- Three segregated networks: frontend-net, backend-net, data-net (internal)
- Traefik v2.11 reverse proxy routing / to web, /api to api
- API strip prefix middleware for clean routing
- PostgreSQL 16-alpine with health checks and named volume
- Fixed API Dockerfile for pnpm monorepo node_modules structure
- Fixed Next.js standalone path for monorepo (apps/web/server.js)
- Fixed Traefik Docker API version compatibility
- Network segmentation: web NOT on data-net, api NOT on frontend-net
2026-06-18 10:17:21 +02:00
schalli 04c78b4bdc feat(01-01): NestJS API with health endpoint and Prisma schema
- NestJS app with ConfigModule and HealthModule
- GET /health endpoint returning {status, timestamp} using HealthResponse type
- Prisma schema with PostgreSQL datasource and Tenant model (multi-tenancy foundation)
- Multi-stage Dockerfile with non-root nestjs user, monorepo root as build context
- Workspace dependency on @tessera/shared for shared types
- Type-check passes successfully
2026-06-18 10:04:08 +02:00
schalli b75d7c3b58 feat(01-01): monorepo scaffold with root configs and shared package
- Root package.json with pnpm workspace, Turborepo, Biome, TypeScript
- pnpm-workspace.yaml defining apps/* and packages/* workspaces
- turbo.json with build, dev, lint, type-check task definitions
- tsconfig.base.json with strict mode and bundler module resolution
- biome.json with formatter and linter configuration
- .gitignore, .env.example, .dockerignore
- @tessera/shared package with APP_NAME constant and HealthResponse type
- pnpm-lock.yaml generated from successful install
2026-06-18 10:02:21 +02:00