Edouard Vanbelle
1cd934d594
refactor(resourceList): move grid/list view into a resourceList component, purpose normalize on all sections views
2026-05-28 00:15:04 +02:00
Edouard Vanbelle
c65f2b5385
feat(api): cursor listing contract — PageCursor trait + resource field
...
- Add src/application/dtos/cursor.rs with three shared types:
· PageCursor trait — default base64url+JSON encode/decode; one bare
impl line per cursor struct
· CursorQuery struct — standard limit/cursor/sort_by query params with
limit_clamped() and decode_cursor<C>() helpers; compose via flatten
· CursorListResponse<T> — standard {items, next_cursor?} envelope with
from_oversized() and with_cursor() builders
- Migrate GrantCursor to impl PageCursor (remove duplicate encode/decode)
- Update GET /api/grants/incoming/resources:
· SharedWithMeQuery now embeds CursorQuery via #[serde(flatten)]
· Replace file/folder nullable pair with ResourceContentDto (untagged
enum) under a single always-present 'resource' field
· SharedWithMeDto is now a type alias for CursorListResponse<SharedWithMeItemDto>
· Handler uses q.paging.limit_clamped() and decode_cursor<GrantCursor>()
- Add docs/architecture/resource-listing.md — authoritative contract for
all listing endpoints (cursor design, SQL keyset WHERE, sort_by naming,
Rust + JS skeletons, compliance table, migration guide)
- Register doc in VitePress sidebar and architecture index
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-28 00:15:04 +02:00
Dionisio Pozo
9a2782b67e
Merge pull request #394 from EdouardVanbelle/feat/user-image-avatar
2026-05-27 21:33:45 +02:00
Edouard Vanbelle
7a849be3d8
chore(playwright): upgrade to version 1.60.0
2026-05-27 11:50:02 +02:00
EdouardVanbelle
2dc2b0876d
test(e2e): update playwright linux snapshots
2026-05-27 09:48:25 +00:00
Edouard Vanbelle
7ddbbc94cc
test(e2e): update all images and grow snapshot comparaison sensitivity
2026-05-27 11:35:42 +02:00
Edouard Vanbelle
891ff89a5d
test(playwright): add playwright report to track changes + correct playwright parameters
...
ci: fix actions/checkout@v6 → @v4 (v6 does not exist)
GitHub started rejecting invalid action versions at parse time,
causing every CI run to fail with 0s / 'workflow file issue'
before any jobs could start.
* test(e2e): only no retry
* test(e2e): use static name in tests to facilitate screenshot comparaison
* test(e2e): update linux screenshots
* test(e2e): adapt test due to user-vignette generation
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-27 11:29:58 +02:00
Edouard Vanbelle
4a5e9a67ca
permits img-src from external website, other solution is to store base64 image of user in DB
...
note: if we need to keep this security, we need to store all user's images (blob_storage can be a good candidate)
2026-05-27 11:29:33 +02:00
Edouard Vanbelle
b0c5e7827e
feat(user-avatar): users can now edit there image (image is taken from OIDC picture)
2026-05-27 11:29:33 +02:00
Dionisio Pozo
8b6c8e345b
Merge pull request #390 from EdouardVanbelle/feat/shared-with-me
2026-05-26 00:00:37 +02:00
Edouard Vanbelle
3e786daea5
fix(grants): correct the removal of a users from a grant
2026-05-25 23:24:04 +02:00
Edouard Vanbelle
8365608bd5
feat(list view): show the owner of the File or Folder in list view
2026-05-25 22:48:59 +02:00
Edouard Vanbelle
79c1a37931
feat(ui): 1 modal to manage shares (users & public share)
...
fix(share): ensure Authz parent is created/updated on publicShare create/update
fix(ShareModal): do not show Token (public) grants in People section
2026-05-25 22:47:36 +02:00
Edouard Vanbelle
a88e4c2733
refactor: move modal into components (prepare a mode autonomous components)
2026-05-25 22:47:36 +02:00
Edouard Vanbelle
12466d4b83
feat(roles): simplify roles to only Viewer, Editor, Admin
...
┌────────┬──────┬─────────┬────────┬────────┬───────┬────────┐
│ Role │ read │ comment │ create │ update │ share │ delete │
├────────┼──────┼─────────┼────────┼────────┼───────┼────────┤
│ viewer │ ✓ │ │ │ │ │ │
├────────┼──────┼─────────┼────────┼────────┼───────┼────────┤
│ editor │ ✓ │ ✓ │ ✓ │ ✓ │ │ │
├────────┼──────┼─────────┼────────┼────────┼───────┼────────┤
│ admin │ ✓ │ ✓ │ ✓ │ ✓ │ ✓ │ ✓ │
└────────┴──────┴─────────┴────────┴────────┴───────┴────────┘
2026-05-25 22:47:36 +02:00
Edouard Vanbelle
d64beb43a7
feat(ui): add addressBook and systemUsers model + show person who shared an item with me in tooltip
2026-05-25 22:47:36 +02:00
Edouard Vanbelle
7fd444259f
fix(breadcrumb): simplify breadcrumb logic and fix issue with shared items
2026-05-25 22:47:36 +02:00
Edouard Vanbelle
60d53ea779
feat(ui): add section 'Shared with me'
2026-05-25 22:47:32 +02:00
Edouard Vanbelle
143b13d7bc
security(authz): a shared item must not return it's full path
2026-05-25 22:47:01 +02:00
Edouard Vanbelle
093c1ad3a5
feat(grants): add /api/grants/incoming/resources with a cursor for pagination
2026-05-25 22:47:01 +02:00
Edouard Vanbelle
50d13943fc
fix(grants): show /grants on openapi
2026-05-25 22:47:01 +02:00
Edouard Vanbelle
1dbd56e9cc
tests(load): prepare a load repository to test response time under load in the future
2026-05-25 22:47:01 +02:00
Edouard Vanbelle
80425aed03
chore(justfile): add 'front-check' for lazy devs
2026-05-25 22:47:01 +02:00
Dionisio Pozo
7cc57db262
Merge pull request #391 from TW199501/refactor/i18n-rename-safet
...
refactor(i18n): rename safeT to t, drop export alias
2026-05-24 18:10:48 +02:00
Eddie Yang
32ad2a4f0e
refactor(i18n): rename safeT to t, drop export alias
...
Follow-up to PR #373 review feedback (thanks @EdouardVanbelle): with the
local t() removed in that PR, the safeT defensive name no longer earns
its purpose. There is no global t() left to shadow it, so the wrapper-
style name just creates confusion against callers writing i18n.t().
- function safeT -> function t
- export { t: safeT, ... } -> { t, ... }
- Remove stale comments in translateElement and above the definition
that explained the safeT/admin.js shadowing history
No call-site changes - every external caller already uses i18n.t(...),
which now points directly at the function of the same name.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-24 21:17:58 +08:00
Dionisio Pozo
daf25b5830
Merge pull request #388 from EdouardVanbelle/refactor/file_life_cycle
2026-05-22 22:17:27 +02:00
Edouard Vanbelle
73f0b0fa47
refactor(lifecycle hooks): simplify integration of new services
...
* make more coherent lifecycles
* remove specific implementation on different handlers (they do not need to know existence of ThumbnailSerice nor AudioMetadataService)
* reduce risk of orphean objects
* ensure additional services are correctly wired (ex: Thumbnail generation was not covering all upload cases)
* more details on docs/architecture/file-and-blob-lifecycle.md :
```rust
// application/ports/file_lifecycle.rs
pub trait FileLifecycleHook {
fn on_file_created(file_id, blob_hash, content_type, is_new_blob);
fn on_file_updated(file_id, blob_hash, content_type);
fn on_file_copied(file_id, blob_hash, content_type, source_id)
fn on_file_deleted(file_id);
}
// application/ports/blob_lifecycle.rs
pub trait BlobLifecycleHook {
fn on_blob_created(blob_hash, content_type);
fn on_blob_deleted(blob_hash);
}
```
2026-05-22 13:40:58 +02:00
Dionisio Pozo
9206669ee6
Merge pull request #387 from EdouardVanbelle/feat/trash-item-with-thumbnail-and-path
2026-05-22 08:12:39 +02:00
Edouard Vanbelle
191f725199
feat(ui/trash): show original file path in tooltip on mouse over + display thumbnails
...
* fix: permission also check elements trashed elements
* tested manually
* all automated tests ok
2026-05-22 02:26:11 +02:00
Dionisio Pozo
0cd2f24b7f
Merge pull request #383 from EdouardVanbelle/permissions
2026-05-22 00:43:43 +02:00
Edouard Vanbelle
76a85949e7
fix(trash)+refactor(file life cycle)
...
* fix issue with the empty trash (wasn't calling thumbnail clean up)
* refactor file service life cycle (TrashService don't call directly ThumbnailService, but call the on_file_deleted() hook
* remove unused mehod: _validate_user_ownership()
2026-05-22 00:28:39 +02:00
Edouard Vanbelle
dd68d783e0
fix(authz): permit policiy: a user with Delete permission can delete a file/folder. Only the owner can permanently delete or restore a trashed item
2026-05-21 22:45:49 +02:00
Edouard Vanbelle
a1c21ce446
refactor(authz): permet require_permission() as has_permission(), more explicit
2026-05-21 21:50:42 +02:00
Edouard Vanbelle
cb35775f77
fix(dedub): correct ref count on hashes, many thanks to you api tests...
2026-05-21 21:12:38 +02:00
Edouard Vanbelle
eb95567a7d
feat(authz): test & cover batch cases
...
┌────────────────────────────────┬─────────────────────────────────┬───────────────────────┬─────────────────┬──────────────────────────────┐
│ Endpoint │ Phase 3A no-grant │ Phase 3B Viewer │ Phase 3C Editor │ Phase 3D Admin │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/files/get │ 400 (all failed) │ 200 (2 successful) │ — │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/files/move │ 400 │ 400 (no Update) │ 200 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/files/copy │ 400 │ — │ 200 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/files/delete │ 400 │ 400 │ 400 (no Delete) │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/get │ 400 │ 200 │ — │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/create │ 400 │ — │ 201 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/move │ 400 │ — │ 200 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/copy │ 400 │ — │ 200 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/delete │ 400 │ — │ 400 (no Delete) │ 200 │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/trash │ 400 │ — │ — │ 400 (owner-only, documented) │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/download │ 404 (NotFound) │ 200 + application/zip │ — │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ GET /api/batch/download?... │ 404 │ 200 + zip │ — │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ Phase 3E lifecycle cleanup │ grants table empty after delete │ │ │ │
└────────────────────────────────┴─────────────────────────────────┴───────────────────────┴─────────────────┴──────────────────────────────┘
2026-05-21 20:30:58 +02:00
Edouard Vanbelle
a53c09f361
feat(authz): covert and test chunked upload with permissions
2026-05-21 20:30:58 +02:00
Edouard Vanbelle
bd1b17b589
test(grants): full coverate of /api/files and /api/folders
2026-05-21 20:30:58 +02:00
Edouard Vanbelle
3362e277ab
feat(authz): check permission on read handlers + check create permission on folder
2026-05-21 20:30:53 +02:00
Edouard Vanbelle
cba9be8c21
feat(rebac): first pass
2026-05-20 22:56:00 +02:00
Edouard Vanbelle
2c53f99089
ai: save ReBAC Permission, Grants, Cascading plan
2026-05-20 21:49:25 +02:00
Edouard Vanbelle
dfb082fdf4
refactor(server): file_management_service: move all method without owner check into private, add folder_ports
2026-05-20 15:39:53 +02:00
Edouard Vanbelle
ac42a6d3cc
test(api): check right management for folder creation and folder move + check also webdsav MKCOL protection
...
│ Steps 1-6 │ Setup: admin's resources + create bob + bob's home folder │
│ Step 7 │ REST: bob can't create a folder inside admin's home → 404 │
│ Step 8 │ REST: bob can't create inside admin's private folder → 404 │
│ Step 9 │ REST: parent_id: null auto-resolves to bob's home (documents the convenience) │
│ Step 10 │ REST: positive control — bob creates in his own home → 201 │
│ Step 12 │ REST: bob can't move his file into admin's folder → 404 │
│ Step 13 │ REST: bob moves file to root (null) → 200 (legitimate root state) │
│ Step 14 │ REST: bob can't read admin's file → 404 │
│ Step 15 │ REST: admin's tree integrity preserved │
│ Step 16 │ WebDAV: path-prefix isolation rewrites cross-user paths into caller's tree │
│ Step 17 │ WebDAV: positive control MKCOL in bob's own tree → 201 │
│ Step 18 │ WebDAV: bob's home contains the rewritten "My Folder - admin" sub-folder, proving the isolation rerouted the attack │
│ Step 19 │ WebDAV: admin's tree never sees bob's WebDAV traffic │
2026-05-20 13:04:15 +02:00
Edouard Vanbelle
f8b30e78a6
refactor(create_folder): add an ownership check while creating a folder + refactor code
2026-05-20 12:59:04 +02:00
Dionisio Pozo
91ff3df35f
Merge pull request #381 from EdouardVanbelle/fix/253-scrolldown-on-shares
2026-05-19 23:25:36 +02:00
Edouard Vanbelle
3c3be9b930
feat(share): permit scrolldown+ keep header sticky on the top
...
this solve issue raised on #253
2026-05-19 22:52:46 +02:00
Dionisio Pozo
032e283867
Merge pull request #375 from dscso/patch-1
2026-05-19 18:22:04 +02:00
Dionisio Pozo
6734bbbd09
Merge pull request #374 from EdouardVanbelle/style/type
2026-05-19 18:21:20 +02:00
Dionisio Pozo
3d105d76fe
Merge pull request #380 from EdouardVanbelle/front/logo
2026-05-19 18:15:03 +02:00
Dionisio Pozo
6396270167
Merge pull request #379 from EdouardVanbelle/fix/front-duplicate-declaration
2026-05-19 18:14:48 +02:00
Edouard Vanbelle
623773f5e3
feat(ui): increase logo by reducing viewbox
2026-05-19 17:52:00 +02:00