Commit Graph

2441 Commits

Author SHA1 Message Date
google-labs-jules[bot] 040f4dcdd4 fix N+1 query in list_shared_links
Replaced the N+1 query in `list_shared_links` which fetched `FileRecord` for each link. It now uses a single query with an `outerjoin` to fetch `original_filename` alongside the `SharedLink` object.
Measured a significant improvement from ~0.4547s to ~0.0579s per 1000 links.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 09:14:36 +00:00
github-actions[bot] fa36ec6987 docs(changelog): update changelog [skip ci] 2026-03-16 09:13:07 +00:00
Christian Krakau-Louis 5529b32d54 Merge pull request #701 from christianlouis/fix-db-migrate-sqli-17066903272609783485
🔒 Fix potential SQL injection in database migration preview
2026-03-16 10:12:45 +01:00
github-actions[bot] 2cfbea29a9 style: apply ruff auto-fix
- Auto-formatted code with ruff format
- Applied ruff linting fixes with --fix

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-03-16 09:12:15 +00:00
google-labs-jules[bot] 433d1eb639 🔒 Fix potential SQL injection in db_migrate preview
Added a strict regex validation allowlist for table names in `preview_migration` before using them in raw SQL queries. This ensures that only alphanumeric characters and underscores are allowed, preventing potential SQL injection even if the source of table names were to be manipulated.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 09:11:57 +00:00
google-labs-jules[bot] 6e3e6238a1 Fix ruff lint formatting and imports.
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 09:09:21 +00:00
google-labs-jules[bot] 726e4dfdc4 feat: Extract embedded PDF metadata using pypdf in upload_to_email
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 09:09:04 +00:00
github-actions[bot] c76e51391b style: apply ruff auto-fix
- Auto-formatted code with ruff format
- Applied ruff linting fixes with --fix

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-03-16 09:05:43 +00:00
github-actions[bot] 522cefad93 style: apply ruff auto-fix
- Auto-formatted code with ruff format
- Applied ruff linting fixes with --fix

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-03-16 09:05:21 +00:00
google-labs-jules[bot] df64aece2c feat: Extract embedded PDF metadata using pypdf in upload_to_email
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 09:05:02 +00:00
google-labs-jules[bot] 8eb2e97113 Add unit tests for generate_api_token function
Enhance the coverage and robustness of the `generate_api_token` helper
in `app/api/api_tokens.py` by introducing three unit tests.

The new tests verify:
- The exact character length of the generated string based on `TOKEN_BYTES`.
- The character set strictly adheres to URL-safe characters and the expected `TOKEN_PREFIX`.
- `secrets.token_urlsafe` is explicitly called with `TOKEN_BYTES`.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 09:04:58 +00:00
google-labs-jules[bot] 9c1be9ec10 🔒 Fix potential command injection in rclone task
Adds `--` separator to `rclone copy`, `mkdir`, and `link` commands in `upload_with_rclone.py`. This explicitly tells rclone to stop processing options and treat subsequent arguments strictly as positional arguments, preventing malicious user-controlled paths (starting with `-`) from being executed as arbitrary command flags.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 09:04:25 +00:00
google-labs-jules[bot] 7a004f782e 🧪 Add unit test for hash_token function
Adds a specific unit test `test_hash_token_known_value` to `tests/test_api_tokens.py` to assert that the `hash_token` pure function accurately computes the expected PBKDF2 digest for a known input string. This provides a hard check against any accidental regressions to the cryptographic hashing logic, iteration counts, or salt values used.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 09:03:54 +00:00
google-labs-jules[bot] c3d06d1876 Fix naming inconsistency in Google Drive API
The function handling the `/google-drive/save-settings` endpoint was incorrectly named `save_dropbox_settings`, likely due to a copy-paste error. This commits renames it to `save_google_drive_settings` and updates all the tests referencing it.

Tested using standard procedures, although test execution resulted in missing dependency errors due to lack of network access in the environment.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 08:59:13 +00:00
google-labs-jules[bot] ae9ed6e9a7 test: add 500 error test for saved search deletion
Adds test coverage for the 500 Internal Server Error path when deleting
a saved search fails due to a database error. The 404 path was already
covered, so this brings full coverage to the deletion error handling in
app/api/saved_searches.py.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 08:58:59 +00:00
google-labs-jules[bot] 5e911ed268 🔒 fix(tasks): prevent command injection in rclone commands
Added the `--` argument before positional arguments in rclone subprocess calls (link, mkdir, copy) in `app/tasks/upload_with_rclone.py`. This ensures that filenames or destinations starting with a hyphen are treated as paths rather than unintended command-line flags.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-16 08:57:57 +00:00
github-actions[bot] 2732dafba9 chore(release): update build metadata files [skip ci] 2026-03-15 21:39:28 +00:00
semantic-release 987974b317 0.145.2
Automatically generated by python-semantic-release
2026-03-15 21:39:26 +00:00
Christian Krakau-Louis 237af31f5f Merge pull request #691 from christianlouis/copilot/update-user-login-case-sensitivity 2026-03-15 22:39:04 +01:00
copilot-swe-agent[bot] f58b8943fb fix(auth): case-insensitive login + mobile auth debug logging
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-15 21:15:19 +00:00
github-actions[bot] 95b8c42244 chore(release): update build metadata files [skip ci] 2026-03-15 21:07:52 +00:00
semantic-release 279ae44e29 0.145.1
Automatically generated by python-semantic-release
2026-03-15 21:07:48 +00:00
Christian Krakau-Louis 4b06e850d5 Merge pull request #690 from christianlouis/copilot/fix-ios-build-error
fix(mobile): suppress Node.js [DEP0169] url.parse() deprecation and document Apple session expiry fix
2026-03-15 22:07:25 +01:00
copilot-swe-agent[bot] dd02ff5677 fix(mobile): suppress Node.js url.parse() deprecation and document Apple session fix
- Add NODE_NO_WARNINGS=1 to all eas.json build profiles (development,
  preview, production) to suppress [DEP0169] url.parse() deprecation
  warnings emitted by EAS CLI when the build image's system Node is 22+
- Add NODE_NO_WARNINGS=1 env to both EAS Cloud Workflow jobs
  (.eas/workflows/create-builds.yml) with explanatory comments
- Fix outdated Node.js prerequisite in docs/MobileApp.md (was "18 or
  later", now "20.19.4 or later" with nvm guidance)
- Add troubleshooting sections in docs/MobileApp.md and mobile/README.md
  covering both the "Session expired Local session" error (Apple ID
  session expiry + App Store Connect API key recommendation) and the
  [DEP0169] Node.js deprecation warning

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-15 21:06:07 +00:00
copilot-swe-agent[bot] 4ee43bb9a4 Initial plan 2026-03-15 21:05:04 +00:00
github-actions[bot] 4de574370c docs(changelog): update changelog [skip ci] 2026-03-15 21:01:26 +00:00
Christian Krakau-Louis 02e74185bd Merge pull request #689 from christianlouis/copilot/fix-webdav-localhost-test
test: fix webdav localhost SSRF assertion to match actual error message
2026-03-15 22:01:03 +01:00
copilot-swe-agent[bot] fe48e2aedc test: fix webdav localhost assertion to match actual error message
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-15 20:49:52 +00:00
copilot-swe-agent[bot] db115a3c5d Initial plan 2026-03-15 20:46:23 +00:00
github-actions[bot] 8fe91e198e chore(release): update build metadata files [skip ci] 2026-03-15 20:46:03 +00:00
copilot-swe-agent[bot] 800d1051a7 Initial plan 2026-03-15 20:46:01 +00:00
semantic-release cb7bb22780 0.145.0
Automatically generated by python-semantic-release
2026-03-15 20:46:00 +00:00
Christian Krakau-Louis 91ff221ccb Merge pull request #688 from christianlouis/copilot/localize-admin-files-page
feat(i18n): localize admin files page
2026-03-15 21:45:40 +01:00
copilot-swe-agent[bot] 2bb47e7631 feat(i18n): localize admin files page (filemanager.html)
Replace all hardcoded English strings in the admin file manager
template with _() translation calls and add 47 new admin_files.*
keys to en.json.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-15 18:06:27 +00:00
copilot-swe-agent[bot] ad092b8c15 Initial plan 2026-03-15 17:55:49 +00:00
github-actions[bot] e7621f1ffd chore(release): update build metadata files [skip ci] 2026-03-15 17:55:07 +00:00
semantic-release 5c96c76e89 0.144.0
Automatically generated by python-semantic-release
2026-03-15 17:55:05 +00:00
Christian Krakau-Louis 5fdf5365e7 Merge pull request #687 from christianlouis/copilot/update-readme-and-check-docs
docs: rewrite README.md and update UserGuide/Troubleshooting
2026-03-15 18:54:46 +01:00
Christian Krakau-Louis c326bc4899 Merge pull request #686 from christianlouis/copilot/localize-admin-plans-page
feat(i18n): localize admin plans page (/admin/plans)
2026-03-15 18:54:26 +01:00
copilot-swe-agent[bot] de8922bb8e fix(i18n): fix overage buffer sentence spacing in admin_plans template
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-15 17:53:13 +00:00
copilot-swe-agent[bot] 36aef73969 feat(i18n): localize admin plans page
Add 108 admin_plans.* translation keys to en.json and update
admin_plans.html to use _() for all static text and window.__i18nAdminPlans
for dynamic Alpine.js / JavaScript strings.

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-15 17:51:10 +00:00
copilot-swe-agent[bot] fcf2452b62 docs: rewrite README.md and update UserGuide and Troubleshooting docs
- Rewrite README.md to reflect current state of the project:
  - Updated Overview with all 12 storage, 7 AI, 6 OCR providers
  - Comprehensive Features section (mobile, CLI, browser ext, pipelines, etc.)
  - Updated Workflow with all ingestion channels and distribution targets
  - Expanded Documentation index with all doc links organized by category
  - Updated Tech Stack table (Meilisearch, MkDocs, Expo, etc.)
  - Added Kubernetes/Helm quick start
  - Added status-view screenshot
  - Updated dependency licenses table
- Updated docs/UserGuide.md with cross-references to Mobile App, CLI,
  Browser Extension, and API docs
- Expanded docs/Troubleshooting.md from 175 to 300+ lines with new
  sections for Search, Pipelines, Mobile App, CLI, Performance, and
  updated all existing sections with current information

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-15 17:51:09 +00:00
github-actions[bot] 87a2311234 chore(release): update build metadata files [skip ci] 2026-03-15 17:46:26 +00:00
semantic-release 178ce70a4a 0.143.1
Automatically generated by python-semantic-release
2026-03-15 17:46:23 +00:00
Christian Krakau-Louis f3c12a6122 Merge pull request #685 from christianlouis/copilot/fix-sso-browser-widget-issue
fix(mobile): SSO callback closes browser and delivers token to app; Expo Go support; SafeAreaView deprecation
2026-03-15 18:46:01 +01:00
copilot-swe-agent[bot] 14285567d5 fix(auth): Expo Go support via Linking.createURL; safe token URL construction; clean up return type annotation
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
2026-03-15 17:42:36 +00:00
copilot-swe-agent[bot] 474706da44 Initial plan 2026-03-15 17:41:35 +00:00
github-actions[bot] 6ab9d120c4 chore(release): update build metadata files [skip ci] 2026-03-15 17:40:26 +00:00
copilot-swe-agent[bot] 6e86919336 Initial plan 2026-03-15 17:40:23 +00:00
semantic-release c03ac42bff 0.143.0
Automatically generated by python-semantic-release
2026-03-15 17:40:23 +00:00