Enable the third sidebar sort mode — a freely defined order.
- api: `PATCH /pages/:id/position` (before/after neighbour) recomputes only
the moved page's fractional `sort_key`. Pure `sort-key.ts` helpers
(`nextKeyOrRebalance`, `evenlySpacedKeys`) decide between the cheap
single-key path and a full pond rebalance to evenly-spaced keys when a key
would exceed MAX_SORT_KEY_LENGTH or the client's neighbours are stale;
rebalance runs in one transaction. Order is server-authoritative.
- web: enable 'manual' in the sort-mode switch; in manual mode the owner can
reorder via native drag-and-drop (drop above/below by pointer half) or the
keyboard (per-row up/down buttons), each announced through an aria-live
region. Reordering is hidden while a label filter narrows the list. New
pages already append at the end (create uses generateKeyBetween(last, null)).
Pure `reorder.ts` neighbour helpers, unit-tested.
- i18n: manual sort mode + reorder strings (de + en).
- tests: sort-key property test (10.000 adversarial reorders never collide or
overflow — rebalance verified); reposition db test (persist, server-order,
sort-mode switch keeps manual order); reorder e2e pack (keyboard reorder
persists across reload + identical on a fresh read; aria-live announced).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
Build the M4 label experience on top of the #43 label API.
- shared: `flattenLabelTree` (tree → depth-first list) for chip lookup,
filtering, and the picker; `PageListItemView` adds each page's `labelIds`
to the sidebar list response.
- api: `GET /ponds/:id/pages` now includes `labelIds` per page (one grouped
query), so the sidebar can render chips and filter without extra calls.
- web:
- Pond settings page (`/p/:pondSlug/settings`) with a `LabelManager`
tree: inline create, rename, recolour (`<input type=color>`), move via a
parent picker that excludes the label's own subtree, and delete that
confirms then force-detaches assigned pages. Every control is a native
button/input/select — the tree is fully keyboard-operable.
- `LabelPicker` panel on the page editor: searchable, hierarchy-indented
multi-select that assigns/unassigns immediately and refreshes the page's
labels and the sidebar.
- Sidebar: colored label chips on page entries (readable text via a
luminance-based contrast helper) and a descendant-inclusive label filter
(selecting a parent matches pages tagged with its children, via the
shared `collectSubtreeIds`). Owner link to pond settings.
- i18n `labels` namespace (de + en).
- e2e `labels.spec.ts` (new CI pack): full lifecycle from the settings UI
and picker-assign + parent-filter-includes-child. Selectors are
language-independent because the UI language follows the user's locale.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
Users can see who changed what and restore old states (ADR 0013).
- shared: dependency-free word-level Markdown diff (diffMarkdown) with a
unit test; PageVersionContentView; PAGE_RESTORE_CHANNEL + PageRestoreRequest.
- api: GET /pages/:id/versions (list), GET .../:versionId (read-only HTML +
Markdown for diffing), POST .../:versionId/restore. Every route requires
write access — viewing history is gated like editing (permissions.md).
Restore checks permission, then emits the page_restore NOTIFY; history is
append-only (the api never deletes a version).
- collab: a page_restore listener applies the restore on the live document via
openDirectConnection — it snapshots the current state as a PRE_RESTORE
version, then replaces the content in one transaction, so every connected
client converges and the change persists like a normal edit.
- web: HistoryPanel (version list with time/trigger/label/contributors, a
read-only render of a selected version, a Markdown diff against the current
page, and a restore action), toggled from the page menu. de+en strings.
Tests: shared diff (added/removed/round-trip/edges); collab restore DB test
(a connected client converges on the restored content; a pre-restore snapshot
is appended alongside the original — append-only); api list/get/restore
(newest-first, rendered content, write-permission gate, restore returns the
target without mutating history).
This completes M3 (real-time collaboration & history, #33–#42).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
Revoking write access must terminate live sessions and let a user with
pending offline edits export them rather than lose them silently.
Backend (generic, reused by M5 grants #53):
- packages/shared: POND_ACCESS_CHANGED_CHANNEL, the LISTEN/NOTIFY channel
shared by api and collab.
- api: PondAccessNotifier emits pg_notify(pond_access_changed, pondId) on
a permission-relevant change; the single generic seam for revocation.
Wired into pond soft-delete as the interim trigger (see==modify until
#53).
- collab: a dedicated-connection LISTEN listener (LISTEN is connection-
bound, not pooled) that, on a notification, closes every open connection
to the pond's open pages. Clients then reconnect and the api re-issues a
token reflecting current access (downgrade to ro, or 403/404). Reconnects
and re-LISTENs if its connection drops.
Frontend:
- use-collab-provider: a refused token (403/404) on (re)connect sets
accessRevoked and stops the reconnect loop; exposes discardLocal.
- AccessRevokedDialog: keeps local content visible and offers Markdown
copy/download (derived from the live editor doc, so offline edits are
included) and an explicit discard that clears IndexedDB. de+en strings.
Tests: collab DB-backed integration test proves a direct NOTIFY closes a
live session within seconds (AC1) and leaves unrelated ponds untouched;
listener unit tests; api test asserts soft-delete fires the notifier;
web test for the export Markdown derivation.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
The offline pack passed locally but flaked in CI. Make its timing-sensitive
steps robust without changing the feature:
- Before going offline, wait until the service worker not only controls the
page but has actually populated Cache Storage (app-shell precache complete),
so the offline reload is guaranteed to be servable from cache.
- After coming back online, wait for the reloaded tab to reconnect (so it has
pushed its local state) before checking a second client converges.
- Raise the service-worker-ready and convergence timeouts, and the IndexedDB
flush wait, for headroom on slower runners.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
Editing continues without a connection and merges conflict-free on
reconnect (ADR 0003, realtime-collaboration.md §Offline).
- y-indexeddb mirrors every opened page's Y.Doc to IndexedDB, sharing the
document with the collab provider. The local copy is discarded when the
page is left after a successful server sync (bounding IndexedDB growth)
and kept otherwise so offline edits survive to the next visit.
- vite-plugin-pwa service worker precaches the app shell (build assets only)
with a navigation fallback; `/api` and `/collab` are denylisted and there
is no runtime caching, so API responses are never cached or poisoned.
- Offline page resolution WITHOUT caching API responses: the app itself
persists the small metadata it needs to reopen a visited page (page/pond
ids + slugs, bounded LRU in localStorage) and the last signed-in user, so
after an offline tab reload the app stays signed in, resolves the page, and
restores its content from IndexedDB. Both are revalidated when the network
returns (a 401 clears the cached user).
- Local-only UI: a banner when there are edits held only on this device
(provider `onUnsyncedChanges`), de + en.
Tests: `page-cache` unit test (remember/recall + bounded eviction); a new
`offline` e2e pack (validated locally against the full stack and wired into
CI): edit, reload while offline (shell from the SW, content from IndexedDB),
assert an API call fails offline (no SW API caching), then reconnect and a
second client converges. The e2e static server serves `.webmanifest`.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
Seeing other participants live (ADR 0003/0004, realtime-collaboration.md
§Awareness):
- The collaboration-caret extension renders remote carets and selections
with a name flag and a per-user colour. Colours come from a small,
hand-picked palette hashed by user id (FNV-1a), so they are stable across
sessions; a unit test asserts each palette colour clears WCAG AA contrast
(4.5:1) against the white label text.
- A presence strip at the top of the page shows an avatar (initials) per
connected participant, deduplicated by user id, with an overflow count.
Read-only participants appear in the strip (with a marker) but broadcast
no caret — the caret render suppresses read-only users — so the same
awareness feed drives both cursors and presence. Own identity (id +
display name) comes from the auth context into the awareness `user` field.
- Presence updates on every awareness change, so a disconnect drops the
participant within seconds.
The collab e2e pack gains a test: two browsers see each other in the
presence strip, one participant's named caret appears in the other's editor,
and disconnecting removes them. Validated locally against the full stack.
de + en strings and cursor/presence styles added.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
The editor now edits over the collaboration server instead of REST — the
moment Dorfteich becomes collaborative (ADR 0003, realtime-collaboration.md).
Web:
- New `useCollabProvider` hook binds a page's Y.Doc to a HocuspocusProvider.
The document loads and persists through the collab server (#35); there is
no REST autosave and no REST seed (a REST seed would fork the doc lineage
and duplicate content). The collab token is fetched lazily on every
(re)connect via an async token function, so an expired token is replaced
transparently and a permission change takes effect on the next reconnect.
- Connection-state UI replaces the save indicator: connecting / connected
("Live") / reconnecting / offline, driven by provider status + navigator
online state. Read-only (`ro`) tokens make the editor non-editable with a
reason; an oversize-document stateless error (#35) surfaces a banner.
- Removed `use-page-autosave.ts` and `yjs-base64.ts` (no longer used).
API:
- `PUT /pages/:id/state` is retired and returns 410 `rest_state_write_retired`
(the criterion deferred here from #35). Collab is the sole writer of page
state; the read paths remain. Removed the now-dead `saveState` service.
e2e / CI:
- The e2e static server proxies the `/collab` WebSocket upgrade (mirrors
Caddy); vite dev gains a `/collab` ws proxy. The auth-e2e CI job starts the
collab server and runs a new collab pack.
- New `collab.spec.ts`: two browsers converge on one page (the milestone
headline), and offline edits continue locally and sync on reconnect. The
read-only live assertion is a `test.fixme` until real read-only grants
exist — under interim access seeing and modifying coincide, so no `ro`
token is issued yet (that arrives with #53). Reworked the api/trash tests
and the content editor-basics test off the retired REST write path.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
Bootstrap apps/collab as a Hocuspocus WebSocket server (ADR 0003):
- pino JSON logging (service=collab) and shared Zod env validation
(collabEnvSchema); structured connection open/close logs.
- /healthz endpoint (process liveness + PostgreSQL ping) served via the
onRequest hook, matching the container-internal path and the proxied
/collab/healthz path; any WebSocket handshake is accepted for now
(authentication arrives with #34, persistence with #35).
- Dockerfile (ESM workspace build) and a compose service on the frontend
and internal networks with a healthcheck; dev overlay service and a new
COLLAB_PORT variable.
- CD builds, pushes, and promotes the collab image; CI builds it on PRs;
the smoke suite asserts /collab/healthz through the reverse proxy.
- deployment.md/stages.md: proxy routing, per-stage COLLAB_PORT, checklist.
Closes#33
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Seed script extends the fixture matrix with a shared "Content Fixtures"
pond (owned by fixture-user): an "Every Element" page covering every
editor schema node and mark (#24), and a "Fixture Image" page with one
real, servable uploaded image. "Every Element" loads a checked-in Yjs
snapshot (prisma/fixtures/content-page.yjs) generated from a
human-readable Markdown source (content-page.md) via a deterministic
regeneration script (pinned Y.Doc clientID; refuses to write a
snapshot that isn't a fixed point of the Markdown round-trip).
New apps/web/e2e/content.spec.ts consolidates the M2 content
regression pack: page lifecycle, editor basics, image paste, trash,
and — the pack's actual regression pin — a byte-for-byte comparison of
the fixture page's exported Markdown against the checked-in fixture.
Verified this catches regressions: temporarily mutated
docToMarkdown's heading serializer, rebuilt, re-seeded, confirmed the
comparison failed, then reverted.
This pack now runs in CI (a second step in the existing auth-e2e job,
reusing its already-built-and-seeded stack) alongside the existing
local-only feature packs.
Closes#32
Backend: a generic maintenance-job scheduler (SchedulerService, `jobs`
table) that any later maintenance job registers with instead of
growing its own timer loop. Due-ness and the run-mutex both live in
the DB row (`lastRunAt` survives a restart; claiming a due job is one
atomic `UPDATE ... WHERE status != 'RUNNING'`), and an injectable
ClockService lets tests simulate retention elapsing without waiting or
faking the global clock.
Trash endpoints: GET /ponds/:id/trash (list), POST /pages/:id/restore,
DELETE /pages/:id/purge (manual, bypasses retention) — all sharing the
same purge logic as the scheduled daily job (default 30-day retention,
new trash.retentionDays instance setting). Purging deletes a page's
content cache, update log, and attachment files/quota; page_versions
is a placeholder until M3 exists. Direct navigation to a trashed page
now 404s with a distinguishable `page_trashed` code for editors (a
plain 404 for everyone else) instead of the generic not-found.
Attachment.pageId — added in #27 but never wired up — now gets set on
every page state save to whichever page's document currently embeds
the file, which is what lets purge find a page's files.
Frontend: a per-pond trash view (restore/purge), a "move to trash"
action with confirmation in the page menu, and a trash link in the
sidebar for pond owners. Also fixes react-query retrying 4xx responses
for several seconds by default, which was masking the trash-hint 404
in the UI (and would have affected any other not-found/permission
error the same way).
Closes#31
Wires docToMarkdown/markdownToDoc into the editor clipboard: copying
selected content puts Markdown on text/plain alongside the browser's
own HTML (so pasting into a plain-text destination yields Markdown),
and pasting plain text that looks like a Markdown document converts it
to rich nodes; content with real HTML on the clipboard is left to
ProseMirror's normal HTML-based paste, and the heuristic requires two
or more distinct Markdown-shaped lines (or a fenced code block) so
ordinary prose is never mangled.
Both directions need the parsed/selected doc re-hydrated against
whichever schema instance is on the other side of the boundary: the
canonical editorSchema (packages/shared) for markdownToDoc's output
before inserting it into the live view, and the live view's schema
wrapped back into editorSchema before handing a slice to docToMarkdown
— they're structurally identical but not the same object, and
ProseMirror's content checks are identity-based.
Adds GET /pages/:id/export/markdown (downloads <slug>.md), serving the
already-derived page_content_cache.markdown (#23) rather than
re-decoding the Yjs state. "Copy as Markdown" and "Download as
Markdown" actions in the page header both read from that same
endpoint, so they always agree with each other and with the last saved
state.
Closes#30
A bubble menu on link selection offers "edit URL", "open in new tab",
and "remove link"; Mod-k opens the same editor for the current
selection (creating a link if there isn't one yet), and the toolbar
button does the same. Invalid protocols (e.g. javascript:) show a
localized inline error instead of silently no-oping. Pasting a URL
over selected text links it instead of replacing the text.
Links always render with target="_blank" so read mode opens them in a
new tab by default; edit mode suppresses the resulting navigate-on-
click (Mod-click still follows it), since a plain click there should
place the cursor instead.
Closes#29
Paste and drag-and-drop of image files upload via the #27 API and insert
a real image node only once the upload succeeds; the in-flight state is
a ProseMirror decoration, not a document node, so a failed upload cannot
leave anything broken behind (it shows a transient inline error instead).
The toolbar's image button opens a native file picker into the same
upload path. Selecting an image reveals inline alt-text and width-preset
(small/medium/full) controls. Also fixes the image node's parseDOM,
which had no getAttrs and would drop the required fileId attribute on
internal copy/paste.
Closes#28
GET /ponds/:id/pages lists a pond's pages ordered by the pond's
persisted sidebarSort setting (alpha/created; manual arrives with #45).
The sidebar consumes it to show the page list with an active-page
highlight, an owner-only sort switch (persists via the existing
PATCH /ponds/:id), and an inline "new page" flow. The top bar gains a
pond switcher; a new /p/:pondSlug route gives it somewhere to land,
redirecting to the pond's first page once loaded. Sidebar collapse
gains a Ctrl/Cmd+\ shortcut and a slightly refined transition.
Closes#26
TipTap is bound to the canonical ProseMirror schema (packages/shared,
#24) via a generic bridge (spec-utils.ts) that re-derives every
node/mark's attrs/parseDOM/toDOM from editorSchema instead of
duplicating them, so the editor's schema stays byte-for-byte identical
to what the api decodes Yjs states against — guarded by a schema-
fidelity + real Yjs round-trip test (@tiptap/y-tiptap client encoding
against y-prosemirror server decoding).
Route /p/:pondSlug/:pageSlug (RequireAuth) resolves the page via a new
GET /ponds/:pondId/pages/:slug endpoint, binds a local Y.Doc via
@tiptap/extension-collaboration (fragment "default"), and offers a
view/edit mode toggle (sidebar auto-hides in edit mode via a small
AppLayout context). Page state saves debounced to PUT /pages/:id/state
with a truthful saving/saved/error(retrying) indicator; title saves
separately via PATCH /pages/:id.
Toolbar covers headings, marks, lists, blockquote, code block, hr,
table (insert/row/column/header ops via prosemirror-tables), a minimal
link mark, and an image placeholder (real upload is #27/#28).
Closes#25
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Playwright's request context resolves localhost to ::1 while Vite in
the CI container listened on IPv4 only — the fixture-login helper got
ECONNREFUSED. Vite now starts with --host in the auth-e2e job. The
redirect test also reports the server's error message instead of a
bare URL mismatch when a login fails.
Part of #20
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
React StrictMode double-invokes effects in development; the second
POST consumed-token 400 could win the state race and show an error
for a successful verification (flaked in CI, passed locally). A ref
guards the single-use call; Playwright test-results are ignored.
Part of #20
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Composing z.object() in the web app around a schema imported from
@dorfteich/shared mixes two zod type instances and breaks the
zodResolver overload on fresh installs (CI). Like the other forms,
the schema now lives in the shared package.
Part of #20
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The seed script now provisions the documented fixture matrix
(fixture-admin / fixture-user / fixture-pending, idempotent upserts,
rate-limit reset for disposable databases). A six-test Playwright pack
drives the real UI against a full local stack with Mailpit: complete
signup→mail→verify→first-login journey, wrong-password error, guarded
route redirect honoring ?next (race between the login page and the
anonymous guard fixed by teaching the guard about ?next), menu logout,
site-admin gating, and a profile rename reflected in the top bar. The
pack self-skips without E2E_MAILPIT_URL, so the CD smoke stage (now
pinned to smoke.spec.ts) stays untouched; a new CI job boots api +
web dev server against postgres/mailpit service containers and runs
the pack on every PR and push. Also fixed: the web api client choked
on empty 201 bodies. e2e/README.md documents targets and fixtures.
Closes#20
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The web app grows its account surface: login (with next-redirect,
unverified-hint + resend), signup (react-hook-form + shared Zod
schemas, field-level api errors, closed-registration state fed by the
new public GET /auth/registration), e-mail verification, forgot/reset
password; a settings page with profile (locale applies immediately),
password change, and active-session management; a Site-Admin page for
instance name, default locale, and registration mode. AuthProvider
holds /auth/me, applies the profile locale, and backs route guards
(RequireAuth/RequireAnonymous/RequireSiteAdmin); the top bar gains a
user menu. All strings ship in the new auth/settings namespaces (de+
en); the exception filter now preserves handler-specific error codes.
Verified live: signup → Mailpit → verify → login → profile through
the Vite proxy.
Closes#16Closes#17Closes#18Closes#19
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
apps/web now has a Vitest config excluding e2e/ — those specs run via
Playwright (pnpm e2e) against a deployed stage, not in unit test runs.
Part of #8
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
On every push to main: build both images once (SHA + moving `test`
tag), push to the Gitea registry, SSH-deploy the Test stage, wait for
readiness, run the new Playwright smoke suite (SPA shell, web
liveness, api healthz/readyz) against https://test.dorfteich.cloud,
and on green retag the identical SHA images as `int` and deploy Int.
The CI image-build job becomes PR-only to avoid double builds on main.
Part of #8
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Multi-stage images: web (workspace build baked into unprivileged
nginx with SPA fallback, asset caching, /healthz) and api (pnpm deploy
bundle with the prisma CLI for migrate-on-start, non-root, node-based
healthcheck). deploy/compose/docker-compose.yml defines the stage
stack (web, api, db) with frontend/internal networks, localhost-only
published ports for the host reverse proxy, log rotation, and named
volumes; .env.example documents every variable. compose.dev.yml layers
hot-reloading dev containers (or database-only usage) over the same
definition. Verified locally: full stack healthy, SPA fallback, readyz
green after automatic migration, db not reachable from outside.
Closes#6
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Translation resources live in packages/shared/i18n/<lang>/<ns>.json
(common, errors) and ship with de and en. The web app initializes
react-i18next with bundled resources (?lng= wins, then the browser
language); all shell components use useTranslation and the temporary
t() stub is gone. The api localizes its uniform error bodies via a
minimal i18next instance negotiated from Accept-Language. `pnpm
i18n:check` fails CI when any key is missing in any language, backed
by tested helpers in @dorfteich/shared.
Closes#5
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
apps/web becomes a Vite + React application: React Router with home
and 404 routes, base layout (top bar, collapsible sidebar remembered
per user via localStorage, main area), CSS design tokens including the
three font slots from ADR 0016, TanStack Query, and a typed fetch
helper showing live API health on the home page. All UI strings go
through a t() stub that issue #5 replaces with i18next. The Vite dev
server proxies /api to the api dev port (3001).
Closes#4
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
pnpm workspace with apps/web, apps/api, apps/collab, and
packages/shared; strict TypeScript base config, repo-wide ESLint (flat)
+ Prettier, Vitest per package, and root scripts lint/typecheck/test/
build. @dorfteich/shared ships a first health-response helper consumed
by apps/api to prove workspace linking. Existing markdown docs are
reformatted once by the new Prettier setup.
Closes#1
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>