rojects/workspace/boards/tasks.html

281 lines
13 KiB
HTML

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Tasks - Roject</title>
<link rel="stylesheet" href="../_assets_/styles.css">
<link rel="stylesheet" href="../_assets_/nav.css">
<link rel="stylesheet" href="../_assets_/boards.css">
</head>
<body>
<div class="board-page">
<header>
<p class="date">Board</p>
<h1>Tasks</h1>
<p class="subtitle">Click a task title to expand or collapse its content.</p>
</header>
<div class="board">
<div class="lane">
<div class="lane-header">To Do</div>
<task-item class="blue hide-content">
<task-title>Tab-container: split function broken, panel border update unreliable</task-title>
<task-content>
The tab-container split function does not work correctly in its current state.
Additionally, the update and moving of panel borders is not always applied —
borders can appear stuck or misaligned after panel resize or split operations.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Mobile: editor layout too tall, chat input not reachable</task-title>
<task-content>
On mobile the overall editor layout is still too tall — panels overflow the
viewport and the chat input area is pushed out of view even after the
min-height: 0 fix on rojo-chat-panel. Needs a broader mobile layout pass
on the panel/section/editor structure.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Code syntax highlighting in rojo-chat (Highlight.js)</task-title>
<task-content>
Code blocks in assistant responses are rendered as plain text inside pre/code tags.
Integrate Highlight.js to apply syntax highlighting after markdown-it renders each
response chunk. Apply highlighting to all code blocks in the assistant bubble.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Rojo Character Editor</task-title>
<task-content>
Allow changing colors and selecting layers of a Rojo character from within
the rojo-settings-panel. Colors map to fill/stroke/both targets on SVG elements;
layers toggle visibility of named groups or swap between variants.
The appearance field (colors[], layers[]) is already in the settings.rojo schema.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Rojo Character Animation Box</task-title>
<task-content>
Animation system for emotional feedback during conversations.
Animations can be scripted (predefined sequences) or driven dynamically by
an LLM that emits emotion tags alongside its response. The animation box
plays character animations (idle, happy, thinking, surprised, etc.) in the
portrait area of the rojo-settings-panel and rojo-chat-panel.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>File tree: drag-and-drop move for files and directories</task-title>
<task-content>
Allow files and directories to be moved by dragging them within the file tree.
Dragging a file onto a directory moves it inside; dragging a directory onto another
directory moves the whole subtree. Use the existing file rename API
(POST /api/files/:projectId/rename) — moving is a rename to a new parent path.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Tab context menu on right-click (tabs and empty tab bar area)</task-title>
<task-content>
The tab ⋮ menu already works but should also open on right-click anywhere on
the tab bar — both on individual tabs and on the empty space to the right of the tabs.
Right-clicking a specific tab should also offer a "Close this tab" action directly.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Remote Projects in Electron</task-title>
<task-content>
Allow the Electron app to connect to roject.rokojori.com and list remote projects
alongside local ones. The JWT is already available;
it's a matter of pointing requests at the remote URL with the token.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Unauthenticated Landing Screen</task-title>
<task-content>
Unauthenticated users currently crash on dashboard components.
They should land on a screen that explains the app and shows a login link.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Replace browser confirm() in group editor and account delete</task-title>
<task-content>
The group editor and account delete button still use the browser confirm() dialog.
Replace with the custom &lt;confirm-dialog&gt; component already used elsewhere.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>MediaViewerPanel for images and PDFs</task-title>
<task-content>
Non-text files (images, PDFs) are visible in the file tree but not openable.
Add a MediaViewerPanel and register it in FileEditorRegistry for common media types.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Investigate Gitea webhook auto-deploy</task-title>
<task-content>
The webhook did not fire on the last two pushes to main. Check the Gitea
webhook delivery log for the response code from /api/deploy. Also run
journalctl -u roject -n 100 on the server to see whether the endpoint
was reached at all. Most likely causes: signature mismatch, wrong branch
ref, or the deploy command failing silently.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Roject: wire lookup-email for member storage migration</task-title>
<task-content>
The rokojori-auth side (POST /api/auth/lookup-email) is live.
Remaining Roject-side work:
— Add SERVICE_SECRET to Roject .env (must match rokojori-auth SERVICE_SECRET)
— In POST /api/projects/:id/members: call account.rokojori.com/api/auth/lookup-email,
receive the user ID, store member_id as the user ID instead of the email
— In source/server/projectAccess.ts change memberMatchesUser()
from member.member_id === user.email
to member.member_id === user.userId
— Write a one-off migration script: for each member row, call lookup-email
with the stored email and replace member_id with the returned user ID
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Switch Gitea webhook to dev branch</task-title>
<task-content>
The Gitea webhook currently triggers on pushes to main, redeploying on every commit.
Switch to a dev branch so main is the stable release target.
</task-content>
</task-item>
<task-item class="blue hide-content">
<task-title>Ensure time is not depending on the user's clock</task-title>
<task-content>
JWT verification on the local server failed because the Windows client clock was
~65 minutes ahead of the production auth server clock. Any time-based logic that
compares client-side time against server-issued timestamps (JWT exp, token TTL,
session validity) is broken when clocks diverge.
Work to do:
— Audit all places where Date.now() / new Date() is used for security or
session decisions; replace with server-authoritative time where possible.
— On the auth side: use clockTolerance in jwt.verify as a configurable
escape hatch (JWT_CLOCK_TOLERANCE env var, already added for local dev).
— Write a developer guide covering: why user/client clock cannot be trusted,
how to use server time for all authoritative checks, how to diagnose clock
skew issues, and the JWT_CLOCK_TOLERANCE workaround for local dev.
— Consider syncing advice in the local dev setup docs (future local-dev task).
</task-content>
</task-item>
</div>
<div class="lane">
<div class="lane-header">In Progress</div>
<task-item class="yellow hide-content">
<task-title>rokojori-tunnel — Phase 2</task-title>
<task-content>
Production-deployed at tunnel.rokojori.com. Complete so far:
relay server, CRUD API, streaming WebSocket protocol (res_start / res_data / res_end),
HTTP proxy with SSE streaming, Electron Tunnel Agent (tray, login, tunnel list),
Roject browse-tunnels button, Roject LLM chat via tunnel, client-side chunk animation.
Remaining:
— Allowed users list enforcement (multi-user private access)
— Public access mode (no auth required on proxy route)
— GET /api/tunnels/available with ?purpose= filter surfaced in Roject provider picker
</task-content>
</task-item>
<task-item class="yellow hide-content">
<task-title>styles.rokojori.com — complete deployment</task-title>
<task-content>
Service is built and running manually via npm start on the server.
Remaining work:
— Set up systemd service (styles-rokojori.service) so it survives restarts
— Download Barlow from /add-fonts (weights 100, 400, 700, 900)
— Verify CORS is working for roject.rokojori.com font imports
— Add to the add-subdomain deployment guide as a reference example
</task-content>
</task-item>
<task-item class="yellow hide-content">
<task-title>Local Filesystem Access</task-title>
<task-content>
Extend the file tree to browse arbitrary directories on the host
machine using Node.js fs rather than the server's JSON-backed project storage.
</task-content>
</task-item>
</div>
<div class="lane">
<div class="lane-header">Done</div>
<task-item class="green hide-content">
<task-title>Mobile: nav bar z-index too low on projects / index view</task-title>
<task-content>
Added z-index: 10 to .pld-nav in project-list-default.css.
The nav has position: fixed but lacked a z-index, so stacking contexts
from position: relative project rows buried it on mobile.
Overlays remain above at z-index: 200.
</task-content>
</task-item>
<task-item class="green hide-content">
<task-title>Electron Roject app: local dev fixes</task-title>
<task-content>
Several fixes to make the Electron app usable for local development:
— extractToken now checks Authorization Bearer before the accessToken cookie,
so stale browser cookies cannot shadow the injected token.
— JWT_CLOCK_TOLERANCE env var (seconds) passed to jwt.verify as clockTolerance;
set to 7200 in .env to absorb clock skew between local and production auth server.
— Startup token refresh: on launch with saved tokens, main.ts calls
POST account.rokojori.com/api/auth/refresh before opening the main window;
shows login window if refresh fails.
— Quit-on-login fix: createMainWindow() is now async; login-success handler
awaits it before closing the login window, preventing window-all-closed → quit.
— Credential persistence: email and password saved to userData on successful login;
remember-me checkbox controls whether they are saved; clear button deletes them.
</task-content>
</task-item>
</div>
</div>
<footer>
Roject &mdash; tasks
</footer>
</div>
<script>var NAV_ROOT = '../';</script>
<script src="../_assets_/nav-data.js"></script>
<script src="../_assets_/nav.js"></script>
<script>
document.querySelectorAll( 'task-title' ).forEach( title =>
{
title.addEventListener( 'click', () =>
{
title.closest( 'task-item' ).classList.toggle( 'hide-content' );
} );
} );
</script>
</body>
</html>