Board

Tasks

Click a task title to expand or collapse its content.

To Do
Rojo Character Editor Allow changing colors and selecting layers of a Rojo character from within the rojo-settings-panel. Colors map to fill/stroke/both targets on SVG elements; layers toggle visibility of named groups or swap between variants. The appearance field (colors[], layers[]) is already in the settings.rojo schema. Rojo Character Animation Box Animation system for emotional feedback during conversations. Animations can be scripted (predefined sequences) or driven dynamically by an LLM that emits emotion tags alongside its response. The animation box plays character animations (idle, happy, thinking, surprised, etc.) in the portrait area of the rojo-settings-panel and rojo-chat-panel. File tree: drag-and-drop move for files and directories Allow files and directories to be moved by dragging them within the file tree. Dragging a file onto a directory moves it inside; dragging a directory onto another directory moves the whole subtree. Use the existing file rename API (POST /api/files/:projectId/rename) — moving is a rename to a new parent path. Tab context menu on right-click (tabs and empty tab bar area) The tab ⋮ menu already works but should also open on right-click anywhere on the tab bar — both on individual tabs and on the empty space to the right of the tabs. Right-clicking a specific tab should also offer a "Close this tab" action directly. File tree double-click: auto-open or focus existing editor When a file is double-clicked in the file tree: — If an editor panel that can handle the file type is already open and not pinned, focus that panel's tab and load the file into it. — If no suitable unpinned editor exists, open a new panel of the correct type in the active section before loading the file. Single-click keeps current behaviour (selection only, no open). Remote Projects in Electron Allow the Electron app to connect to roject.rokojori.com and list remote projects alongside local ones. The JWT is already available; it's a matter of pointing requests at the remote URL with the token. Unauthenticated Landing Screen Unauthenticated users currently crash on dashboard components. They should land on a screen that explains the app and shows a login link. Replace browser confirm() in group editor and account delete The group editor and account delete button still use the browser confirm() dialog. Replace with the custom <confirm-dialog> component already used elsewhere. MediaViewerPanel for images and PDFs Non-text files (images, PDFs) are visible in the file tree but not openable. Add a MediaViewerPanel and register it in FileEditorRegistry for common media types. Investigate Gitea webhook auto-deploy The webhook did not fire on the last two pushes to main. Check the Gitea webhook delivery log for the response code from /api/deploy. Also run journalctl -u roject -n 100 on the server to see whether the endpoint was reached at all. Most likely causes: signature mismatch, wrong branch ref, or the deploy command failing silently. Roject: wire lookup-email for member storage migration The rokojori-auth side (POST /api/auth/lookup-email) is live. Remaining Roject-side work: — Add SERVICE_SECRET to Roject .env (must match rokojori-auth SERVICE_SECRET) — In POST /api/projects/:id/members: call account.rokojori.com/api/auth/lookup-email, receive the user ID, store member_id as the user ID instead of the email — In source/server/projectAccess.ts change memberMatchesUser() from member.member_id === user.email to member.member_id === user.userId — Write a one-off migration script: for each member row, call lookup-email with the stored email and replace member_id with the returned user ID Investigate session logout after ~1 hour Users are logged out after a couple of hours. The access token issued by rokojori-auth expires after 1 hour; the refresh token lasts 30 days. Roject should silently refresh via GET account.rokojori.com/api/auth/refresh-session before the token expires. Investigate: — Is the 401 response from any API route triggering a redirect to refresh-session? — Is the refreshToken cookie present and being sent cross-domain? — Is the refresh-session endpoint actually rotating both cookies correctly? — Check journalctl on the server for 401 patterns and the browser network tab for which request first returns 401. Switch Gitea webhook to dev branch The Gitea webhook currently triggers on pushes to main, redeploying on every commit. Switch to a dev branch so main is the stable release target.
In Progress
rokojori-tunnel — Phase 2 Production-deployed at tunnel.rokojori.com. Complete so far: relay server, CRUD API, streaming WebSocket protocol (res_start / res_data / res_end), HTTP proxy with SSE streaming, Electron Tunnel Agent (tray, login, tunnel list), Roject browse-tunnels button, Roject LLM chat via tunnel, client-side chunk animation. Remaining: — Allowed users list enforcement (multi-user private access) — Public access mode (no auth required on proxy route) — GET /api/tunnels/available with ?purpose= filter surfaced in Roject provider picker styles.rokojori.com — complete deployment Service is built and running manually via npm start on the server. Remaining work: — Set up systemd service (styles-rokojori.service) so it survives restarts — Download Barlow from /add-fonts (weights 100, 400, 700, 900) — Verify CORS is working for roject.rokojori.com font imports — Add to the add-subdomain deployment guide as a reference example Local Filesystem Access Extend the file tree to browse arbitrary directories on the host machine using Node.js fs rather than the server's JSON-backed project storage.
Done
CI deploy email notification EmailService added to Roject (SMTP via Nodemailer, same credentials as rokojori-auth). Startup email sent from startServer() listen callback; deploy email sent from /api/deploy after signature verification passes. reportEmail defined as a static field on EmailService. Electron Desktop App Shell Login window, JWT auth via API, Authorization header injection, token persistence, ROJECT_ROOT path fix, ELECTRON_RUN_AS_NODE workaround. Full local-only Electron app working.