fix: complete issues 1 3 6 validation and knowledge ACL
2026-08-06T09:12:50+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 36 | core 0 | module 0 | forbidden 0
Flags:
Последние изменения из mirror GitHub. Здесь видны не только SHA, но и автор, дата, количество файлов и зоны риска.
Показаны 1498 commit'ов, страница 13 из 30.
fix: complete issues 1 3 6 validation and knowledge ACL
2026-08-06T09:12:50+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 36 | core 0 | module 0 | forbidden 0
Flags:
fix: keep idea info table within sidebar
2026-08-06T07:31:31+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 2 | core 0 | module 0 | forbidden 0
Flags:
feat: enable rich task descriptions
2026-08-06T07:22:43+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 10 | core 0 | module 0 | forbidden 0
Flags:
feat: enable safe rich comments
2026-08-06T06:53:55+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 7 | core 0 | module 0 | forbidden 0
Flags:
fix: preserve custom menu link URLs
2026-08-06T06:14:27+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix: show counterparty extra fields in edit modal
2026-08-06T06:05:55+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 2 | core 0 | module 0 | forbidden 0
Flags:
deploy: publish current CRM changes to demo
2026-08-06T06:00:17+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 13 | core 0 | module 0 | forbidden 0
Flags:
fix: unify project status labels
2026-08-05T20:05:39+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix: preserve custom project task key prefix
2026-08-05T19:46:53+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix: add project list view toggle
2026-08-05T19:39:38+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix: menu links and counterparty knowledge attachment
2026-08-05T19:26:17+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 5 | core 0 | module 0 | forbidden 0
Flags:
fix(installer): post-install 'update available' notice now compares builds via the update-center update-plan (current_build=0) instead of a semver compare that never fires because every build ships VERSION 1.0.0 - a fresh install now sees the update hint when a newer build is published; docs(changelog): record ТЗ 6/7 client-project-status features and the installer notice fix
2026-08-05T14:07:30+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 2 | core 0 | module 0 | forbidden 0
Flags:
revert(test): remove E2E update marker E2E_UPDATE_MARKER_20260805_161124
2026-08-05T13:23:58+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 7 | core 0 | module 0 | forbidden 0
Flags:
test(e2e): add E2E update marker E2E_UPDATE_MARKER_20260805_161124
2026-08-05T13:11:25+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 7 | core 0 | module 0 | forbidden 0
Flags:
feat(projects, ТЗ 7.3): project-close modal now offers both options - 'Close all tasks' (paged bulk) and 'Move to another project' (paged per-task PATCH project_public_id) with a target-project selector; new i18n keys (ru+en)
2026-08-05T13:02:28+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 3 | core 0 | module 0 | forbidden 0
Flags:
fix(projects, ТЗ 7.3): mass-close open tasks loops by pages (bulk endpoint caps at 100 per request) so 'Close all tasks' actually closes all open tasks for large projects; added no_open_tasks_found i18n key (ru+en)
2026-08-05T12:52:01+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 3 | core 0 | module 0 | forbidden 0
Flags:
fix(i18n): add contacts.opt_custom_role/role_custom_placeholder to en-gb web section (i18n_key_parity unit test)
2026-08-05T12:48:26+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix(projects, ТЗ 7): 7.2a - admin statuses page now renders two independent tables 'Статусы задач' and 'Статусы проектов' (split by scope; legacy single-table fallback kept); 7.2b/7.2c - project workflow edit form loads project statuses from the admin dictionary (api/v1/statuses?scope=project) with fallback including 'planning'/'active' (previously only new/in_progress/blocked/done, so 'Планирование' was missing from project transitions); 7.3 - completing a project with open tasks now raises PROJECT_HAS_OPEN_TASKS (already server-side) and the UI offers a confirm modal 'Close all tasks' that bulk-closes open tasks then retries the completion; open_task_count now returned in error meta; new i18n keys (ru+en)
2026-08-05T12:40:10+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 5 | core 0 | module 0 | forbidden 0
Flags:
fix(clients, ТЗ 6): 6.2 - client card gets 'Create task'/'Create project' buttons that open the global modals with the client prefilled (window._taskClientPrefill/_projectClientPrefill); fixed the detail-page inline script to read client_public_id; 6.3 - contact role is now a hybrid select+free-text field (backend already stored arbitrary strings; UI option '__custom__' reveals an input; unknown stored roles display as text instead of '—' in the list); 6.6 - compact-view toggle active state now readable (solid primary bg + white text instead of green-on-green), added missing clients.normal_view/compact_view i18n keys (EN already had them, RU showed English fallback); 6.1/6.4/6.5 verified already present (tax fields not required, address_actual round-trips, extra_attributes chips + search)
2026-08-05T12:19:01+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 6 | core 0 | module 0 | forbidden 0
Flags:
fix(tasks, ТЗ 4): subtasks always get a task key inheriting the parent/project prefix (MYPRF-1 -> MYPRF-2) - SubtaskService now generates the key via TaskKeyService (was inserting empty task_key), the prefix is read from the full task row (parentTaskByPublicId selected a minimal column set), TaskKeyService global scope now respects the passed prefix, and subtask API responses include task_key/task_key_prefix/task_sequence_number; hierarchy tree levels now indent as a ladder on desktop (padding-left via --task-level, previously only mobile grid indented); subtask modal pinned to viewport with internal scroll + body scroll lock
2026-08-05T11:48:01+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 5 | core 0 | module 0 | forbidden 0
Flags:
feat(timer): parallel multi-timers (ТЗ 2.3) - cookie state is now a per-task map {user_public_id, timers:{task:startedAt}} with legacy single-timer migration; starting a timer in another task is no longer blocked - each task is tracked separately and the topbar widget sums all running timers; with 2+ timers the topbar shows the total + a xN badge and clicking opens a dropdown listing every running task with its own elapsed time (titles fetched once, cached); task page shows a hint when timers run in other tasks; exact per-task span preserved on stop ([HH:MM:SS] in the worklog note)
2026-08-05T11:22:07+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 9 | core 0 | module 0 | forbidden 0
Flags:
feat(updater): usable emergency recovery - rescue.php no longer mints a recovery key for anonymous visitors (security hole + dead-end UX), instead it explains where the key comes from and sorts jobs by mtime; new authenticated POST /api/v1/core/updates/recovery-key rotates and returns the key exactly once; admin-updates page gains an 'Emergency recovery' section with a show/rotate button that copies the key to the clipboard; installer generates the key at finalize and displays it once on the success screen (all 7 locales); maintenance screens now point to both the admin-updates page and rescue.php with a hint on where to find the key
2026-08-05T10:59:57+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 14 | core 0 | module 0 | forbidden 0
Flags:
fix(updater): reliable core updates on any shared hosting - cURL fallback for allow_url_fopen=Off in updater/API clients (binary-safe download via CURLOPT_FILE), login reachable during held maintenance for recovery, admin-updates JS auto-refreshes the updater token on invalid/expired and resumes the same job, JobState::latest()/status/history sort jobs by mtime so a stale failed job (upd_e2e_...) never surfaces as latest with its old error, TokenVerifier allows apply_step/rollback_step continuations when the base action is allowed (version-mixed trees), stale error cleared on job resume/finalize, retried apply reuses the complete first backup
2026-08-05T10:05:30+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 15 | core 0 | module 0 | forbidden 0
Flags:
feat(topbar): running task timer is now the first item in global-actions (before search toggle); timer log note (Что было сделано) is no longer required - keep field, drop client-side + HTML5 required check, worklog note accepts empty (server already allows it)
2026-08-05T06:23:27+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 3 | core 0 | module 0 | forbidden 0
Flags:
fix(web): keep core/version reachable during maintenance hold - the admin-updates page loadStatus() calls it, and a 503 MAINTENANCE_MODE there surfaces 'Core update maintenance mode is active' instead of update progress while apply legitimately holds maintenance
2026-08-05T06:18:05+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix(notifications): hasColumn via information_schema - SHOW COLUMNS LIKE ? is a SHOW command that MariaDB rejects with prepared params (EMULATE_PREPARES=false -> 1064 near '?'); match IndexHelper introspection pattern
2026-08-05T06:14:28+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix(notifications): driver-aware ensureSchema for push subscriptions - AUTOINCREMENT is SQLite-only and made the hourly notification sweep log a schema error on MySQL/MariaDB; use AUTO_INCREMENT id + SHOW COLUMNS introspection on mysql (mirrors SchemaManager canonical table), keep PRAGMA path for sqlite, hasColumn() fails safe to avoid destructive ALTER
2026-08-05T05:18:11+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix(db): portable JSON_CONTAINS member check - CAST(? AS JSON) is MySQL-only and breaks auth menu + worklog team visibility on MariaDB (demo server); bind the JSON fragment literal instead
2026-08-04T19:51:08+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 2 | core 0 | module 0 | forbidden 0
Flags:
docs(changelog): note admin_updates i18n completion across all 7 locales
2026-08-04T19:42:07+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix(security): DatabaseRateLimiter handles duplicate-key insert race (1062) as expected instead of logging an error
2026-08-04T19:37:39+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
feat(i18n): translate admin_updates section (184 keys) into de/es/fr/pt/zh - all 7 locales now complete for the updates page
2026-08-04T19:37:39+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 5 | core 0 | module 0 | forbidden 0
Flags:
fix(db): portable CONSTRAINT...UNIQUE table constraints in SchemaManager - SQLite rejected MySQL-only UNIQUE KEY (near KEY syntax error) when the updater applied the initial_schema migration on sqlite installs
2026-08-04T19:37:38+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
feat(updater): resumable step-machine apply/rollback/download - chunked file backup/apply, DB dump (LIMIT/OFFSET) + restore (byte-position replay), migrateUpLimit per-request, heartbeat lock with renew, apply_step/rollback_step tokens (sliding expiry), streaming package download + budgeted extraction; admin-updates page drives step loop with progress; WorkBudget budgets in api/config/update.php
2026-08-04T19:37:22+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 20 | core 0 | module 0 | forbidden 0
Flags:
refactor(richtext): drop dead self-contained RTE path (enhance/buildToolbar/sanitizer/exec/sync) - keep only live delegation to VisualEditor; remove orphaned crm-rte-* CSS and 11 unused richtext.* i18n keys (keep description_hint)
2026-08-04T12:16:09+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 9 | core 0 | module 0 | forbidden 0
Flags:
fix(security): sanitizeHtml now drops SCRIPT/STYLE/IFRAME/SVG/FORM/etc subtrees entirely (was dead code - unwrap leaked script content as text and nested <script> survived); re-walk children moved by unwrap so nested dangerous tags cannot survive
2026-08-04T12:00:11+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix(visual-editor): quick chips clickable (pointer-events), paste/drop images insert at caret (was appended at end), Enter makes <p> not <div> (lines no longer merge on save), readonly editors keep captions non-editable, image border per ТЗ 5.3, image toolbar absolute-positioned (was fixed => drifted on scroll), undo/redo refresh UI state
2026-08-04T11:17:06+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 4 | core 0 | module 0 | forbidden 0
Flags:
fix(db): route all remaining migration CREATE INDEX DDL through driver-aware IndexHelper (vanilla MySQL has no IF NOT EXISTS); drop dead fallback branches
2026-08-04T10:58:22+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 6 | core 0 | module 0 | forbidden 0
Flags:
fix(security): strip financial rates for non-root in user create/update, forbid non-root rate writes at service layer, explicit select() on users queries, findAdmins JOIN + dedupe
2026-08-04T10:27:51+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 4 | core 0 | module 0 | forbidden 0
Flags:
fix(admin): show real error state in logs table on API failure instead of misleading empty row; i18n admin.logs_load_error in 7 locales
2026-08-04T10:05:55+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 8 | core 0 | module 0 | forbidden 0
Flags:
fix(web): show real error states on API failure instead of misleading empty states on tasks (uses template error slot), projects, notifications and calendar pages; i18n in 7 locales
2026-08-04T09:57:58+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 8 | core 0 | module 0 | forbidden 0
Flags:
fix(dashboard): show real error state in Today Tasks, Reminders and My Day widgets when their API requests fail (previously misleading empty state), i18n in 7 locales
2026-08-04T09:43:32+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 8 | core 0 | module 0 | forbidden 0
Flags:
fix(api-client): typed-client comments use task-scoped route; add local api links contract test
2026-08-04T09:34:59+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
fix(links): broken routes in dashboard worklog widget (worklogs -> time-analytics), docs chat link (chats -> chat), Jira migration task links (route=task&id -> task-detail&task_public_id)
2026-08-04T08:26:10+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 3 | core 0 | module 0 | forbidden 0
Flags:
feat(tasks): add "unassigned" option to assignee filter dropdown - URL assignee=none now reflects in UI (searchable select sync), i18n in 7 locales
2026-08-04T08:19:29+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 8 | core 0 | module 0 | forbidden 0
Flags:
feat(dashboard): unassigned tasks widget - API filter assignee=none (whereNull), board/list consistency, view-all link honored by tasks page, i18n in 7 locales
2026-08-04T08:13:05+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 11 | core 0 | module 0 | forbidden 0
Flags:
feat(i18n): translate 4 new dashboard widgets (intake, my_week, recurring, mentions) into de, fr, es, pt, zh
2026-08-04T08:03:08+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 5 | core 0 | module 0 | forbidden 0
Flags:
fix(dashboard): my_week widget - timezone-safe week start (parse date parts, avoid UTC shift) and Date-aware dayKey
2026-08-04T07:59:40+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags:
feat(dashboard): 4 new widgets - incoming requests (intake), my week agenda, recurring tasks, my mentions
2026-08-04T07:54:10+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 6 | core 0 | module 0 | forbidden 0
Flags:
feat(web)+fix: TZ batch 3 - quick client create from dropdown (3.1), custom fields in counterparty/client list + search (6.5)
2026-08-04T07:38:50+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 8 | core 0 | module 0 | forbidden 0
Flags:
fix(api): TZ 6.1 - counterparty can be created with name only (drop required INN/KPP/OGRN validation)
2026-08-04T07:29:13+00:00
Anton Barinov <55404783+Anton-Barinov@users.noreply.github.com>
Files: 1 | core 0 | module 0 | forbidden 0
Flags: