Commit Graph
155 Commits
Author SHA1 Message Date
Dmitry Ng dc2fd43928 feat(assistants): support flowID=0 in REST API to create assistant with new flow
- Allow POST /flows/0/assistants/ to create a new flow together with the assistant, mirroring the existing GraphQL createAssistant(flowID: 0) behavior
- Require both assistants.create and flows.create permissions when flowID=0
- Add explicit flow ownership check for non-zero flowID using flows.admin scope
- Load flow data in the response by fetching it via assistant.FlowID after creation, ensuring AssistantFlow is fully populated in all cases
2026-05-08 18:54:14 +03:00
Sergey KozyrenkoandCursor 95893bf502 feat(knowledge): rich tiptap editor for content with per-panel scrolling
- replace plain textarea with a tiptap-based markdown editor (StarterKit, tiptap-markdown, placeholder) and a basic formatting toolbar so authors can edit knowledge content with rich formatting while keeping markdown as the storage format for embeddings
- introduce a reusable MarkdownEditor shared component and a tiptap Storage type augmentation
- move the save action from the input addon into the page header on the right
- give each desktop resizable panel its own internal scroll so long meta or content no longer makes the whole page scroll

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 17:55:38 +07:00
Sergey KozyrenkoandCursor 318acc9f77 feat(knowledge): add knowledge documents UI with list and detail pages
Wire up KnowledgesProvider with Apollo subscriptions and cache policies,
add /knowledges routes and sidebar entry, plus minor formatting cleanups
across file-manager, upload-validation and resources upload helpers.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 17:55:38 +07:00
Sergey KozyrenkoandCursor 012cb741ad refactor(file-manager): chevron drill-in, responsive bulk bar and tri-state toggle fix
- File manager core:
  - Chevron click on folder rows now drills in via `onOpenDirectory`
    (when set), matching the existing double-click / Enter semantics.
    Consumers that don't wire the prop keep the legacy expand/collapse
    behaviour, so flow-files / resources trees stay unchanged.
  - Bulk actions bar wraps and collapses to icon-only buttons (Cancel
    included) on small viewports so the bar stays usable on mobile.
  - Fix tri-state subtree toggle requiring two clicks when the
    directory's own path was never in the selection (e.g. user ticked
    children one-by-one). \`toggleSubtreeOnSet\` now accepts an optional
    \`rootPath\` and ignores it for the "all selected?" check, mirroring
    what \`computeDirSelectionState\` shows on the visible checkbox.
    Covered by new regression tests in \`file-manager-utils.test.ts\`.
  - Built-in icons swapped: copy-path uses \`ClipboardCopy\` instead of
    \`Copy\`; bulk \"Save as resources\" uses \`FolderOutput\` instead of
    \`BookmarkPlus\`.

- Pull dialog: flatten the container listing (\`name\` as \`path\`,
  absolute path in \`id\`) so the chevron / double-click drill into
  real subfolders instead of toggling a synthetic \`work/\` wrapper that
  has no meaningful navigation target. Selection is mapped back to
  absolute paths via a name → absolute lookup before pulling.

- Resources page: drop the focus-derived \`currentDir\` plumbing —
  toolbar mkdir / upload always target the library root, row context
  menu loses \"Upload files here\" and renames \"New folder here\" to
  \"New folder\". Page wraps in \`h-[calc(100dvh-3rem)]\` so the bulk
  bar stays inside the viewport. Tooltips simplified accordingly.

- Flow files toolbar: replace the standalone Info icon with rich
  per-button tooltips that explain where each gesture lands
  (/work/uploads, /work/resources, separate Container snapshot area);
  upload button uses the standard \`Upload\` glyph.

- Attach resources dialog: switch the ad-hoc footer to a proper
  \`DialogFooter\` with responsive layout, tighten the dialog title.

- \`Dialog\` / \`Sheet\` footers always apply the inter-button gap,
  not only at the \`sm+\` breakpoint.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 17:55:37 +07:00
Sergey KozyrenkoandCursor d743bf5105 refactor(flow-files): share upload validator and rely on subscriptions for cache sync
Two cleanups closing the remaining P2/P3 gaps in the flow-files / resources
upload + delete paths.

A.4 — unify upload-batch validation
- New shared validator at `frontend/src/lib/upload-validation.ts` (with
  tests) exposing `validateUploadBatch(files, limits)`. Mirrors the
  per-file / per-batch / empty-file rules enforced by both backends
  (`pkg/resources/resources.go`, `pkg/flowfiles/files.go`).
- `useResourcesUpload` migrated off its private validator onto the shared
  helper; behaviour and toast strings unchanged.
- `useFlowFilesUpload` now runs the same preflight before constructing
  the FormData. Hitting any of the 300 MB / 1000 files / 2 GB / 0-byte
  rules surfaces a synchronous toast instead of a network round-trip
  followed by a generic 413.
- Added `FLOW_FILES_MAX_FILE_SIZE_MB`, `FLOW_FILES_MAX_UPLOAD_TOTAL_SIZE_MB`
  and `FLOW_FILES_MAX_UPLOAD_FILES_PER_REQUEST` to flow-files-constants
  alongside the existing resources constants — kept as a separate set so
  the two backends can diverge later without touching unrelated call
  sites.

C.2 — drop redundant refetchFiles() after flow-file mutations
- The backend already publishes per-file flowFileAdded / flowFileDeleted
  events (with directory expansion on delete), `lib/apollo.ts` already
  maps them through the universal subscriptionCacheLink, and
  `useFlowFilesRealtime` already wires the three subscriptions. Only the
  imperative `await refetchFiles()` in upload/delete plus the
  `onSuccess={refetchFiles}` props on pull/attach dialogs were left over
  from the pre-subscription era.
- Dropped `refetchFiles` from `useFlowFilesUpload` and `useFlowFilesDelete`
  param types and removed the matching `await` calls. Added optional
  `onAfterDelete` to the delete hook (mirrors `useResourcesDelete`) for
  callers that want a UI hook without driving a refetch.
- Made `onSuccess` optional on `FlowFilesPullDialog` and
  `FlowFilesAttachResourcesDialog`; removed the `onSuccess={refetchFiles}`
  passthroughs in `flow-files.tsx`. The pull dialog's internal
  `refetchListing` over the container listing (a separate hook) is kept.

Verified: vitest 140/140, eslint clean on touched files, tsc shows only
the same pre-existing errors as before this change (`User.ts`/`user.ts`
casing; `single possibly undefined` in unrelated delete branches).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 17:55:37 +07:00
Sergey KozyrenkoandCursor 3540407aa6 feat(frontend): atomic batch resource ops and context-aware uploads
- Send `sources[]` (was single `source`) to /resources/copy,
  /resources/move and /files/to-resources so multi-select operations
  execute in one DB transaction; replace the per-feature 409 aggregation
  state and the now-unused `resources-conflict-dialog` with the shared
  `useOverwriteAction` workflow returning `OverwriteOutcome`.
- Extend `FileManager` with `emptyAreaActions` (right-click context menu
  over the tree's empty area), `appliesToFiles` filter (companion to
  `appliesToDirs`), `onActiveRowChange` focus reporting and row-level
  external-file drop (`onExternalFileDrop`).
- `useFilesDragAndDrop`: capture-phase `onDropCapture` resets the
  internal counter / `isDragging` flag before any descendant claims the
  drop with `stopPropagation`, fixing the page-level upload overlay
  staying stuck after a row-level drop.
- `useResourcesUpload` gains `defaultDir` (read via ref so `uploadFiles`
  stays reference-stable) and `openFilePickerForDir` so toolbar /
  sidebar / CTA pickers upload into the focused folder by default and
  per-row "Upload here" actions can target a specific directory.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 17:55:37 +07:00
Sergey KozyrenkoandCursor 76cb4c1283 refactor(frontend): unify overwrite flow and atomic multi-path file APIs
- Extract shared OverwriteConfirmDialog, OverwriteCtaButtons, and
  useOverwriteAction hook; reuse across Pull, Attach, Promote, Move, Copy
  dialogs to drop per-dialog overwrite switches in favour of explicit
  "… with overwrite" CTA + Replace-all confirm.
- Move file-manager into components/shared, add bulkDownloadAction and
  onOpenDirectory navigation override for navigation-style browsers.
- Switch flow files / resources delete and download to atomic multi-path
  endpoints via paths[]= query, drop Promise.allSettled fan-out.
- Add useFlowContainerFiles + container browse in Pull dialog with
  client-side conflict preflight (flow-files-conflicts).
- Extract getApiErrorStatusCode helper to deduplicate 409 detection.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 17:55:36 +07:00
Sergey KozyrenkoandCursor 0c65579066 feat(file-manager): extensible bulk actions API and additive shift-click selection
Replace the single `onBulkDelete` prop with a generic `bulkActions` array so the
host owns which gestures appear in the footer bar. Built-in helpers (`bulkDeleteAction`,
`bulkCopyPathsAction`, `bulkMoveAction`, `bulkCopyAction`, `bulkPromoteAction`)
match the row-action pattern; each entry supports inline button or trailing
overflow menu, optional confirm dialog, isDisabled / isHidden predicates, and
receives the deduped FileNode[]. The bar also surfaces a cumulative size
summary alongside the item count.

Fix Shift+click range selection so it matches user expectations and the rest
of the file-manager's folder semantics:

- Range clicks are now ADDITIVE: the visible-order slice is unioned onto the
  previous selection instead of replacing it, so Cmd-clicked picks, earlier
  shift-ranges, and explicitly clicked folder subtrees survive a follow-up
  Shift+click.
- Folders inside the slice expand to their full subtree via `dirSubtreePaths`,
  mirroring the contract of a plain folder click. Without this, a Shift+click
  across collapsed sibling folders left the folder paths in `selectedPaths`
  but rendered their tri-state checkboxes as unchecked because no descendants
  had been added to the selection.
- Anchor preservation across chained Shift+clicks is unchanged; toggle/single
  still move the anchor.

Migrate `flow-files`, `resources`, and the move/copy/promote dialogs to the
new `bulkActions` API.

Tests: 131 passing — covers reverse direction, expanded vs. collapsed folders,
nested folders, mixed file/folder anchors, empty folders in range, omitted
`dirSubtreePaths` (tree-less callers), anchor=null and off-screen anchor
fallbacks, chained shift-clicks accumulating subtrees, toggle + shift-click
combinations, idempotent same-row range clicks, and the additive contract's
explicit divergence from Finder/Explorer (range never shrinks the selection).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 17:55:36 +07:00
Dmitry Ng a348e41a31 feat(settings): add version and isDevelopMode fields to Settings model and GraphQL schema
- Introduced new fields `version` and `isDevelopMode` in the Settings model to provide application versioning and development mode status.
- Updated GraphQL schema and resolvers to support the new fields, ensuring they are accessible via the Settings query.
- Enhanced Swagger documentation to reflect the changes in the Settings API endpoint.
- Added necessary validation and response handling for the new fields in the Settings service.
2026-05-08 13:06:07 +03:00
Dmitry Ng 6890584c64 feat(resources): add multi-source move, copy and flow-file promotion
- Add Sources []string to MoveResourceRequest, CopyResourceRequest and AddResourceFromFlowRequest; merged with Source, deduplicated; multi-source uses destination as base dir and runs in a single atomic DB transaction
- Fix MoveResource response to return Added + Updated (not Updated only) so Apollo cache receives new parent directory entries alongside moved items
- Add missing errResourceNotFound case in CopyResource (was 500 instead of 404)
- Cover all new behaviour with table-driven tests (basename conflict, force overwrite, missing source, empty input, dir-into-itself guard, etc.)
2026-05-06 17:03:13 +03:00
Dmitry Ng 3a52079278 feat(knowledge): add pgvector knowledge base management
- GraphQL/REST CRUD + semantic search for knowledge documents
- KnowledgeStore with admin/user-scoped filtering, re-embedding on update
- Real-time subscriptions (created/updated/deleted) per user and admin
- user_id tracking in all agent-stored documents (guide/answer/code/memory)
- sqlc queries, goose migrations, privilege grants, user_id backfill
- Memory cleanup on flow deletion; stale orphan purge via migration
- Unit tests for all KnowledgeStore operations including security cases
- Frontend GraphQL schema and TypeScript types regenerated
2026-05-05 01:09:20 +03:00
Dmitry Ng ca9f4a0211 feat: add multi-path support and ZIP improvements across file APIs
- Added `paths[]` query/body parameter to DeleteFlowFile, DownloadFlowFile,
  GetFlowContainerFiles, PullFlowFiles, ListResources, DeleteResource, and
  DownloadResource; single `path` parameter retained for backward compatibility.
- Introduced `DeduplicatePaths` in flowfiles package with coverage-based
  deduplication (parent covers children), path normalization, and traversal safety.
- Added `ZipRelativePaths` to create ZIP archives from cache-relative paths,
  sharing `zipWriteFile` helper with refactored `ZipDirectory`.
- Switched all ZIP and single-file responses to buffered `DataFromReader` with
  explicit `Content-Length`, fixing Swagger UI download rendering.
- Expanded response payloads: delete and pull operations now enumerate all
  affected nested files; list responses include ancestor directories for tree
  completeness.
- Extended test coverage across flowfiles, flow_files, and resources packages
  with batch, deduplication, atomicity, Docker exec, and security scenarios.
2026-05-04 14:32:39 +03:00
Dmitry Ng f57e988586 feat(cast): add JSON control character sanitization for tool call arguments
- Implemented `SanitizeJSONControlChars` to escape literal control characters in JSON string values, ensuring compliance with the JSON specification.
- Enhanced `SanitizeToolCallArguments` method to apply sanitization across tool call arguments in the chain.
- Added comprehensive tests for both sanitization functions to validate behavior with various input scenarios.
2026-05-03 00:48:47 +03:00
Dmitry Ng 9cd52b102a fix(csum): prevent out-of-range errors in recent section determination
- Updated the logic in `determineRecentSectionsToKeep` to clamp the lower bound of the recent sections to keep, ensuring it does not exceed the available sections. This prevents potential out-of-range errors when `keepQASections` is greater than the total number of sections.
2026-05-03 00:47:47 +03:00
Dmitry Ng 46c7807af9 fix(main): router initialization
- Updated router initialization to include the Docker client
2026-05-03 00:47:04 +03:00
Dmitry Ng e370450dab feat(browser): enhance HTML and MD content handling with warnings for small content and errors for binary URLs
- Updated `getHTML` and `getMD` methods to return warnings for small content instead of errors.
- Implemented checks for binary URLs, returning descriptive errors when such URLs are encountered.
- Added new tests to validate the updated behavior for small and empty content handling.
2026-05-03 00:45:27 +03:00
Dmitry Ng b254ff6f90 refactor(flow_manager): improve error handling for running tasks 2026-05-03 00:43:51 +03:00
Dmitry Ng 75eb8e0f1e fix(aslog): implement TryLock to prevent deadlock in workerMsgUpdater
- Added TryLock mechanism to avoid deadlock situations when reading from the channel while the mutex is held.
- Enhanced timer handling to reset when the mutex is not available, ensuring continuous operation of the stream.
2026-05-03 00:42:17 +03:00
Dmitry Ng c068d86bf0 feat(docker): update Dockerfile and add new vLLM configurations
- Added new provider configurations for vLLM Qwen 3.6 in both thinking and non-thinking modes.
- Updated the Dockerfile to include the new configuration files for vLLM Qwen 3.6 and ensure proper setup for deployment.
2026-05-02 18:57:42 +03:00
Sergey KozyrenkoandCursor 268732f610 feat(file-manager): add subtree selection, open gesture, and parent-dir drop forwarding
- Folder rows now surface a tri-state checkbox derived from descendant selection;
  clicking / shift-clicking / toggling a folder flips the entire subtree in one
  gesture, including descendants of a collapsed folder.
- Files get a new onOpen prop, fired on double-click and Enter; directories keep
  expanding/collapsing. The resources page wires it to the existing download flow.
- Drop on a file row forwards to its parent folder so the whole folder acts as a
  single drop zone (Finder/Explorer semantics), with a shared drag-enter counter
  so highlight stays stable when moving the cursor between sibling rows.
- Extract pure data layer into useFileManagerData and pure selection reducers
  (computeRowClickSelection / computeToggleSelection / computeToggleSelectAll /
  computeDirSelectionState) into file-manager-utils; bundle per-tree row props
  into display / handlers so memoized rows stay reference-stable across parent
  re-renders, keyboard expansion, and selection changes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-02 17:24:42 +07:00
Dmitry Ng ba14913c0e refactor: standardize resource ID handling and improve flow file management
- Updated resource ID handling to ensure consistent string coercion for numeric IDs across components.
- Enhanced sorting of resources in the FlowForm to use alphabetical order based on path.
- Improved resource attachment logic in the FlowFilesAttachResourcesDialog to avoid deduplication of descendants.
- Introduced utility functions for converting REST resource entries to a consistent format for Apollo cache.
- Adjusted upload handling to ensure proper type consistency between REST and GraphQL responses.
- Refactored promote functionality to align with updated resource ID handling and improve clarity in parameters.
2026-05-01 16:11:45 +03:00
Dmitry Ng 8830ae7010 fix: update resource handling and API documentation
- Adjusted descriptions in API documentation to clarify paths for uploads, resources, and containers.
- Updated data models to use consistent naming conventions (e.g., `isDir` to `is_dir`, `modifiedAt` to `modified_at`).
- Changed resource ID types from string to uint64 for better consistency across the application.
- Enhanced flow file upload functionality to support batch processing of resource files.
- Removed deprecated code related to resource entry responses in tests.
2026-05-01 16:11:09 +03:00
Dmitry Ng 629c018a68 fix: bug with retrieving resources recursive via graphql 2026-05-01 16:09:06 +03:00
Dmitry Ng b6f7fd7ef8 feat: enhance task and subtask handling with interruption management 2026-05-01 16:05:12 +03:00
Sergey Kozyrenko 3da56244dd feat: integrate user resources into flows and polish file manager
- Replace resources feature mocks with real GraphQL + REST integration
  (Apollo subscriptions-backed cache, dedicated hooks for search, upload,
  copy, move, mkdir, delete, plus conflict / mkdir / copy / move dialogs
  and a shared FileDropZone UI component).
- Let flows attach user resources on creation and in chat messages:
  FlowForm exposes resourceIds as a form field with a multi-select
  dropdown (file/folder icons), wired through createFlow, createAssistant,
  putUserInput and callAssistant mutations.
- Add attach-resources and save-as-resource (promote) dialogs to the
  flow files page; unify drag-and-drop via a shared
  hooks/use-files-drag-and-drop.
- Harden file manager: align skeleton layout (grid + column config) with
  real rows, extract use-file-manager-dnd, add group selection state and
  tree-node accessibility fixes.
- Normalize numeric id/userId from REST /resources/ responses to strings
  so GraphQL ID-typed consumers (zod-validated resource picker) work.
  Marked with TODO(backend) for removal once the REST endpoint matches
  the GraphQL ID scalar.
- Ignore *.tsbuildinfo artifacts.

Made-with: Cursor
2026-05-01 04:34:42 +07:00
Sergey Kozyrenko 0c412cedf9 refactor(flow-files): naming 2026-05-01 04:34:42 +07:00
Sergey Kozyrenko ca747b867a chore: remove unused shadcn AI and crud reference components
Drops `components/ai/file-tree.tsx` and `components/blocks/{crud,skeleton}/*`
reference snippets that were never imported anywhere; the real
file manager lives under `components/file-manager/` and is the only
implementation in use.

Made-with: Cursor
2026-05-01 04:34:41 +07:00
Sergey Kozyrenko f35d2cc0ae refactor(file-manager): polish API, accessibility, and naming
- split monolithic FileManager into FileManagerTreeNode, FileManagerBulkActionsBar, and useFileManagerKeyboardNavigation
- group FileManagerProps columns/search into nested configs and rename visibility booleans from show* to is*Visible per project convention
- replace abbreviations (idx, i, Sep, Item) with full names across components, hooks, and tests
- add ARIA tree-pattern attributes (aria-level, aria-posinset, aria-setsize, aria-multiselectable) and fix aria-hidden hiding the Select-all checkbox
- add labels.formatModified to localize the date column
- make walkTree strictly pure by hiding its internal accumulator
- move side effects out of the setState updater in useFileManagerSelection
- drop redundant stopPropagation in favor of the data-fm-skip-row-click marker

Made-with: Cursor
2026-05-01 04:34:41 +07:00
Sergey Kozyrenko 58f3c09cb0 chore: add shadcn AI and crud reference components
- vendor the shadcn ai/file-tree primitive (recursive collapsible tree with shared expand/select context) for future AI chat surfaces
- vendor the shadcn crud-file-manager and skeleton-file-manager demo blocks as design references; not wired into any route yet

Made-with: Cursor
2026-05-01 04:34:41 +07:00
Sergey Kozyrenko 929ee4e8c2 style: reformat flow-form long lines
- collapse multi-line imports and helpers in flow-form back onto single lines per the active prettier config; no behavioral changes

Made-with: Cursor
2026-05-01 04:34:41 +07:00
Sergey Kozyrenko 2b8d4186c6 feat: support async handlers in ConfirmationDialog
- handleConfirm now accepts () => Promise<void> | void; the dialog awaits the promise before closing
- show a Loader2 spinner on the confirm button while the handler is in flight, and disable both confirm and cancel
- block onOpenChange and outside-clicks while processing so the dialog can't be dismissed mid-action
- caller no longer needs to manage its own loading state for confirm-then-async flows

Made-with: Cursor
2026-05-01 04:34:40 +07:00
Sergey Kozyrenko 52825cadeb refactor: introduce typed axios api wrapper and migrate consumers
- add ApiResponse<T> / ApiSuccessResponse<T> / ApiErrorResponse / ApiHttpError types describing the backend protocol
- expose a typed api wrapper with helper methods (api.get / api.post / api.put / api.delete) that returns ApiResponse<T> directly and accepts per-call AxiosRequestConfig
- add unwrapApiResponse(...) and getApiErrorMessage(...) helpers so callers no longer reimplement success/error branching
- set a sensible default request timeout (30s) on the shared axios instance; long uploads still opt out via { timeout: 0 }
- migrate user-provider and password-change-form from the raw axios instance to the new typed api helpers, dropping their bespoke error-shape interfaces

Made-with: Cursor
2026-05-01 04:34:40 +07:00
Sergey Kozyrenko d390fb1dba refactor: integrate FileManager into flow files page
- replace the inline file tree implementation in flow-files with the new FileManager component
- compose row actions via factory helpers (downloadAction / copyPathAction / deleteAction) instead of bespoke menus
- delegate search highlighting, expand/collapse, multi-select and bulk delete to the shared component; the page now only owns upload, drag-and-drop, pull-from-container and per-file delete confirmation
- switch to the typed axios helpers (api / unwrapApiResponse / getApiErrorMessage) for upload, pull and delete calls

Made-with: Cursor
2026-05-01 04:34:40 +07:00
Sergey Kozyrenko d9416363dd feat: add reusable file manager component
- introduce src/components/file-manager with tree rendering, search highlighting, multi-select (single / toggle / shift-range), keyboard navigation (arrows, Home/End, Space, Cmd+A, Esc) and bulk delete
- expose unified actions[] API with downloadAction / copyPathAction / deleteAction factory helpers instead of separate built-in props
- split orchestration into useFileManagerExpansion and useFileManagerSelection hooks; derive expanded/selected state during render without useEffect, preserving Set identity for memo-friendly downstream
- add ARIA tree semantics (role=tree on the container, treeitem rows, roving tabindex via activeRowPath, aria-expanded/aria-selected)
- pure tree utils: O(1) folder lookup via Map, normalizeRootGroups, dedupeOverlappingPaths, findNodeByPath, plus 37 vitest unit tests
- ship shadcn checkbox primitive (depends on @radix-ui/react-checkbox) which the file manager uses for row and select-all controls

Made-with: Cursor
2026-05-01 04:34:40 +07:00
Sergey Kozyrenko 3002b2bf5e feat: add resourses 2026-05-01 04:34:39 +07:00
Dmitry NgandOctopus 956c11eadc feat: introduce engagement-log/technical-channel language policy across agent prompts
- Replaced ambiguous "user's language" guidance in tools/args.go with explicit engagement-log vs technical-channel markers per field, with strong English-only requirement for vector-store and search-engine queries.
- Added a unified LANGUAGE POLICY block to every agent prompt (primary_agent, assistant, pentester, coder, installer, searcher, memorist, generator, refiner, reporter, enricher), tailored per agent based on its actual tool set.
- Extended template variables and tool access (TerminalToolName, FileToolName) for coder, pentester, installer, memorist, generator, refiner, and enricher to match their runtime tool registrations.
- Fixed inverted UseAgents condition and removed misleading vector-store write references in assistant prompt; corrected MEMORY SYSTEM INTEGRATION for mode-specific tool references.
- Compressed COMPLETION REQUIREMENTS across templates and aligned closing-tool guidance with the channel mapping (engagement-log message vs technical-channel result).

Fixes #285.

Co-Authored-By: Octopus <liyuan851277048@icloud.com>
2026-04-30 15:29:56 +03:00
Dmitry Ng 47044dd1cf Merge pull request #294 from mason5052/codex/issue-289-web-ui-account-guidance
docs: clarify web UI account setup
2026-04-30 12:05:17 +04:00
Dmitry Ng c0035ac130 Merge pull request #293 from mason5052/codex/issue-291-fix-processor-doc-links
docs: fix processor wizard integration links
2026-04-30 12:03:07 +04:00
Dmitry Ng b9ac8fef5f Merge pull request #292 from mason5052/codex/issue-192-assistant-flow-management-docs
docs: explain assistant flow management for active flows
2026-04-30 12:01:12 +04:00
Dmitry Ng 47de4e44e6 docs: update links in configuration and flow execution documents, add directory for proposals 2026-04-30 10:09:03 +03:00
MasonandMason Kim 6257612689 docs: add OSINT integration scenarios (#278)
* docs: add OSINT integration scenarios

* docs: clarify OSINT scenario payloads

* docs: clarify OSINT provider identifiers

* docs: distinguish OSINT provider ids

---------

Co-authored-by: Mason Kim(ZINUS US_SALES) <mkim@zinus.com>
2026-04-30 10:47:08 +04:00
mason5052 4a8c491299 docs: clarify web UI account setup 2026-04-29 11:00:50 -04:00
mason5052 29d5723620 docs: fix processor wizard integration links 2026-04-29 10:58:03 -04:00
Mason Kim(ZINUS US_SALES) 9666cf35ca docs: explain assistant flow management 2026-04-28 19:19:57 -04:00
Dmitry Ng 402dfbe0ee Merge pull request #277 from mason5052/codex/issue-235-evidence-chain-rfc
docs: add evidence chain RFC
2026-04-29 01:35:59 +04:00
Dmitry Ng 425f075a96 Merge pull request #276 from mason5052/codex/issue-71-scope-of-work-template
docs: add scope-of-work pentest template
2026-04-29 01:08:29 +04:00
Dmitry NgandCopilot de6f527e6f Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Dmitry Ng <19asdek91@gmail.com>
2026-04-29 01:07:47 +04:00
Dmitry Ng a8289fcbba Merge pull request #275 from mason5052/codex/issue-69-openvas-custom-image-guide
docs: add OpenVAS custom image guide
2026-04-29 01:05:19 +04:00
Dmitry Ng fb607a8bc7 Merge branch 'feature/next-release' into codex/issue-69-openvas-custom-image-guide
Signed-off-by: Dmitry Ng <19asdek91@gmail.com>
2026-04-29 01:05:07 +04:00
Dmitry Ng 1d6f842bb9 test: add comprehensive coverage for FlowFileService HTTP handlers
- Added table-driven scenarios for all 8 endpoints (Get/Upload/Delete/Download flow files, Pull from container, GetContainerFiles, AddResourcesToFlow, AddResourceFromFlow) covering success paths, all privilege combinations (view/upload/admin/cross-user), error responses (forbidden/not-found/conflict/invalid request), and security checks (path traversal, symlink rejection).
- Introduced reusable test infrastructure: sqlite-backed flows/user_resources schema, fakeDockerClient implementing the full docker.DockerClient interface, flowFileCaptureSubscriptions recording both FlowPublisher and ResourcePublisher events, and helpers for multipart upload bodies and container TAR fixtures.
- Added direct unit tests for shellQuote, parseFlowIDParam, cleanupPendingUploads, and flowScopeForFiles privilege matrix.
- Lifts handler coverage from 0% to 60-90% across the file and total services package coverage from 10.2% to 28.6%.
2026-04-28 22:48:23 +03:00