Commit Graph
56 Commits
Author SHA1 Message Date
Codex 0736983bc5 feat: protect sensitive catalog samples 2026-08-30 12:14:23 +02:00
Codex 376dd5a09d feat: add AI catalog description generation 2026-08-29 16:42:56 +02:00
Codex 58ee9cffe4 feat: add metadata catalog cleanup commands 2026-08-28 00:37:43 +02:00
Codex 79c4c925b5 feat: implement metadata catalog database management 2026-08-27 22:43:54 +02:00
marcopan 3ed00ff086 feat(auth): include authentication in workspace and tht diagnostics 2026-08-17 15:51:16 +02:00
marcopan cb0e873ed7 fix(auth): pin native auth storage operations 2026-08-17 14:52:21 +02:00
marcopan be1724890a fix(auth): make diagnostics bounded and portable 2026-08-17 12:19:19 +02:00
marcopan 4fe51cbeb1 feat(auth): add generic OIDC login with mandatory groups 2026-08-17 05:44:10 +02:00
marcopan 09e546c1ef fix(auth): bind request auth snapshots 2026-08-17 01:11:25 +02:00
marcopan 94c2cd3709 fix(auth): bind current local registry and CORS 2026-08-17 00:34:58 +02:00
marcopan 29bfb41363 feat(auth): add local login and CSRF-protected sessions 2026-08-16 23:23:55 +02:00
marcopan 2e0489ce22 feat(auth): centralize ThothII permission enforcement 2026-08-16 17:52:03 +02:00
marcopan e54ce15426 fix(auth): fail closed configuration compatibility 2026-08-16 17:35:40 +02:00
marcopan ae1215dc98 test: isolate workspace secret vaults under vitest 2026-08-14 17:32:22 +02:00
marcopan 87cefd120c feat: configure workspace runtime secrets through API 2026-08-14 17:30:35 +02:00
marcopan 10edca5a09 fix: default the settings workspace to the active registry workspace 2026-08-13 22:02:02 +02:00
marcopan a72ae2549a fix: ping the active workspace runtime for /health/dwh instead of the legacy config 2026-08-13 21:06:32 +02:00
marcopan a6dbe1d023 fix: retire active pgvector artifacts 2026-08-08 19:27:05 +02:00
marcopan bc8afe0205 feat: render private semantic service endpoints 2026-08-08 17:17:02 +02:00
marcopan bd798b1c96 fix: render registry workspaces for harness 2026-08-05 16:03:45 +02:00
marcopan d6b4a08a02 feat: expose safe pi management api 2026-08-05 00:31:44 +02:00
marcopan 935bb1db0e fix: harden embedded Pi lifecycle recovery 2026-08-04 23:14:47 +02:00
marcopan a368889838 fix: finalize durable Pi lifecycle 2026-08-04 21:34:08 +02:00
marcopan 5ba2821a1b fix: harden Pi lifecycle recovery 2026-08-04 20:28:09 +02:00
marcopan 5b3ce93e31 fix: acknowledge pi maintenance barrier 2026-08-04 19:32:05 +02:00
marcopan 0b9ad7f53f fix: harden pi maintenance lifecycle 2026-08-04 19:09:04 +02:00
marcopan e4fdbed864 fix: harden workspace activation and snapshot retention 2026-08-04 09:25:06 +02:00
marcopan 802b564200 fix: harden workspace registry deployment 2026-08-04 07:42:35 +02:00
marcopan 90894176b6 feat: pin sessions to workspace revisions 2026-08-04 04:52:06 +02:00
marcopan f95a18ab0d feat: expose workspace registry API 2026-08-04 01:01:57 +02:00
marcopan 319d1add2e fix: harden workspace diagnostics probes 2026-08-03 22:59:06 +02:00
marcopan 2087fbb0c9 feat: manage workspace Git checkout and snapshots 2026-08-03 22:21:10 +02:00
marcopan 5d7ebc5b01 fix: harden workspace runtime snapshots 2026-08-03 22:10:09 +02:00
marcopan 801f847ec4 fix: use Pi user auth and handle startup failures 2026-07-21 14:01:47 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
marcopanandClaude Opus 4.6 3b52c8c08c feat: DWH connectivity probe at startup — modal alert within 5s if unreachable
Backend: GET /health/dwh (unauthenticated) calls tht db ping with a 5s
timeout. Frontend: checkDwhHealth() races a 5s timer against the fetch;
on failure a non-dismissable Dialog with Retry appears immediately.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-20 13:59:11 +02:00
marcopanandClaude Opus 4.8 3453f3ae23 feat: pre-check DWH reachability before creating a session (local dev only)
New session now refuses to spawn a Pi runtime that would only die in bootstrap
retrieval when the DWH/vector host is unreachable (e.g. a dropped VPN). Before
`session new`, POST /sessions probes the DWH via `tht db ping`; if it is down it
returns 503 {code:"dwh_unreachable"} with a clear message and creates nothing.

- Gated behind the THT_DWH_PRECHECK flag (default off), enabled only by the local
  dev launcher (run-stack.sh) — containers/CI never pay the probe, and existing
  tests that don't set it are unaffected.
- ThtRunner.dbPing() runs `tht db ping` with a 10s timeout (run() gains an optional
  timeout that SIGKILLs a hung child).
- Frontend: apiFetch throws a typed ApiError (status + parsed payload); the new-
  session composer shows the specific alert on `dwh_unreachable` instead of the
  generic retry hint, keeping the question for retry.

Verified live on an isolated backend (precheck on + broken DWH host → 503
dwh_unreachable, no session created) and via unit tests (backend 228, frontend 308).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 12:08:47 +02:00
User 5cacf70a0d fix: bootstrap user preferences without invalidating DWH cache 2026-07-16 20:32:20 +02:00
User 458eb13c89 feat(backend): enforce user-owned sessions 2026-07-16 18:32:52 +02:00
User df1e7dea9c fix(resume): recover cleanly after Pi exits 2026-07-14 21:35:50 +02:00
User 3d23d0543c fix(backend): validate configured model provider pair 2026-07-14 18:39:37 +02:00
User 6dbf93fff9 feat: harden runtime readiness and session workflow 2026-07-14 10:27:25 +02:00
User 2bd2f72356 Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
User 9d987f639a fix(backend): configPath from THT_CONFIG env (routes senza workspace fallivano in container)
app.ts hardcodava configPath='config/tht.yaml' (symlink solo in dev). Nel container
i route che non passano workspace esplicito (sessionList/sessionShow/documents)
cercavano config/tht.yaml inesistente -> 500. Ora legge THT_CONFIG (entrypoint lo
setta a workspaces/local.yaml), fallback al default per dev. Compose lo esplicita.
Verificato: GET /sessions ora ritorna la lista.
2026-07-12 18:25:38 +02:00
marcopan a3a266fd81 fix(deploy): close container final review 2026-07-12 00:44:39 +02:00
marcopan c6c00c336a feat(backend): support container runtime paths 2026-07-11 21:32:33 +02:00
marcopanandClaude Sonnet 4.6 90a26dafce feat(backend): Ollama embeddings preflight on session create/resume (503 hard-fail)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-29 19:37:39 +02:00
marcopan 387ae56583 test(backend): make mgr injectable; assert teardown-before-delete ordering 2026-06-29 12:36:29 +02:00
marcopanandClaude Opus 4.8 bd29ac517c feat(backend): rename/group/archive/unarchive/delete/documents routes + resume read-only guard
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-29 12:32:52 +02:00
marcopanandClaude Opus 4.8 f59d6d1478 fix(backend): allow PUT in CORS methods so browser can save settings
Found via live browser test: PUT /settings preflight was rejected because
@fastify/cors default methods omit PUT. GET/POST were unaffected.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 16:54:30 +02:00