Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
239 commits
Select commit Hold shift + click to select a range
b25ab2f
feat/ready-apps-cli
dominikpalatynski Apr 1, 2026
bc4312d
fix(cli): improve error handling in create-mercato-app script
dominikpalatynski Apr 1, 2026
95bcef5
feat(cli): add --skip-agentic-setup option to create-mercato-app
dominikpalatynski Apr 1, 2026
78ca9c8
feat/ready-apps-cli (#1130)
pkarw Apr 2, 2026
0d768e9
chore(deps): bump vulnerable transitive resolutions
pkarw Apr 2, 2026
4b37381
fix: bump vulnerable lodash-es and serialize-javascript resolutions (…
pkarw Apr 2, 2026
c693e6d
feat: SPEC 046c decoupling example module from CRM (#1144)
haxiorz Apr 5, 2026
5803a5a
feat(agentic): standalone app skills, navigation guide, and module-le…
pat-lewczuk Apr 6, 2026
54d40d1
docs(spec): add customers lead funnel specification (#1149)
itrixjarek Apr 6, 2026
50152f3
Spec/perspectives views panel (#1148)
zielivia Apr 6, 2026
574a071
feat: advanced datatable CRM (spec + implementation) (#1150)
haxiorz Apr 6, 2026
0acff7b
spec(catalog): add SPEC-071 SEO helper validation visibility (#1155)
zielivia Apr 7, 2026
20ce92f
feat: move backend chrome hydration to the client (#1145)
pkarw Apr 7, 2026
aeb2d4c
docs(spec): add SPEC-072 CRM detail pages UX enhancements (#1156)
zielivia Apr 7, 2026
4cf8d12
fix(cli): add yarn build:packages step to quickstart instructions in …
lukaszbos Apr 8, 2026
2f08706
docs(spec): add portal custom domain routing specification (#1173)
pat-lewczuk Apr 8, 2026
b9a9ec6
devexp: yarn dev optimization + support for structural changes (#1141)
pkarw Apr 8, 2026
f6aab77
Fix/suppress notice bars during integration testing (#1167)
Marynat Apr 8, 2026
0b70505
feat(entities): add date and datetime custom field kinds (#1172)
muhammadusman586 Apr 8, 2026
e4d4555
fix: dev container build fixes and personal override support (#1146)
kurrak Apr 8, 2026
adda600
optimization: add empty app starter preset spec (#1142)
pkarw Apr 8, 2026
27a299b
fix: stabilization fixes (#1174)
pkarw Apr 8, 2026
ff2df43
feat: init repo flow + AI coding flow, dev splash & search fixes (#1175)
pkarw Apr 9, 2026
9dccf69
fix: cleanup + dependabot fixes
pkarw Apr 10, 2026
d277f8b
Merge branch 'develop' of https://github.com/open-mercato/open-mercat…
pkarw Apr 10, 2026
556dc05
fix(ui): prevent duplicate custom fields in CrudForm when explicitly …
muhammadusman586 Apr 10, 2026
ca9984f
feat(auth): invite users via email instead of admin-set passwords (#…
muhammadusman586 Apr 10, 2026
1d6f5b5
Block enterprise tests when OM_ENABLE_ENTERPRISE_MODULES is false (#1…
strzesniewski Apr 11, 2026
b7ea911
fix(cli): fix db:generate metadata leak and migration filename collis…
staskolukasz Apr 11, 2026
3f0baf2
feat(cli): add seed:defaults command for existing databases (#1181)
amtmich Apr 11, 2026
c2dd4eb
fix(catalog): keep product actions visible in list (#1186)
amtmich Apr 11, 2026
17c40d4
fix(docs): correct outdated statements in README files (#1187)
matkowalski Apr 11, 2026
798a1a6
hackon(HCK-0003): README getting-started grammar: 'a quickest way' (#…
pawelleszczewicz Apr 11, 2026
8c93470
Fix organization tenant selection and switcher refresh for issue #959…
amtmich Apr 11, 2026
da2b0d7
hackon(HCK-0007): docs: add missing sidebar entry for user-guide/chec…
pawelleszczewicz Apr 11, 2026
63b93c8
fix(checkout): resolve ESM import errors and Docker dev env (#1153)
Paul-Mlodochowki Apr 11, 2026
658a9bb
feat(sales): add name, sku to invoice/credit memo lines and reason to…
lbajsarowicz Apr 11, 2026
b0f8ae5
fix(directory): honor All Organizations for ACL __all__ non-superAdmi…
BarWyDev Apr 11, 2026
eebeab7
hackon(HCK-0011): tests: add low-level coverage for appResolver.ts (#…
pawelleszczewicz Apr 11, 2026
964c5df
fix(dev): splash stuck on "preparing" when warmup login returns 401 (…
jtomaszewski Apr 11, 2026
b0e4c16
hackon(HCK-0013): tests: add low-level coverage for jwt.ts (#1198)
pawelleszczewicz Apr 11, 2026
54adc3c
hackon(HCK-0009): tests: re-enable skipped test "should export genera…
pawelleszczewicz Apr 11, 2026
b42f9dd
hackon(HCK-0018): tests: add low-level coverage for metadata.ts (#1209)
pawelleszczewicz Apr 11, 2026
bce5946
hackon(HCK-0012): tests: add low-level coverage for boolean.ts (#1200)
pawelleszczewicz Apr 11, 2026
8724d71
hackon(HCK-0015): tests: add low-level coverage for crud.ts (#1205)
pawelleszczewicz Apr 11, 2026
1c3fc12
hackon(HCK-0016): tests: add low-level coverage for featureMatch.ts (…
pawelleszczewicz Apr 11, 2026
23456ab
fix: roll out sticky actions column to wide backend lists (#1233)
amtmich Apr 11, 2026
ee1b247
hackon(HCK-0021): tests: add low-level coverage for list.ts (#1231)
pawelleszczewicz Apr 11, 2026
c31ede7
fix: handle missing xdg-open in dev container by catching async spawn…
MarekUrzon Apr 11, 2026
6f0670c
Sales Documents Tenant Scope Fixes
strzesniewski Apr 11, 2026
dcc5b7c
hackon(HCK-0014): tests: add low-level coverage for passwordPolicy.ts…
pawelleszczewicz Apr 11, 2026
d1632de
Fix missing tenant scope on public quote endpoints (Sales Module) (#1…
strzesniewski Apr 11, 2026
e541eae
fix(progress): enforce tenant isolation in isCancellationRequested (#…
MarekUrzon Apr 11, 2026
934fbff
fix(security): revoke customer sessions after admin password reset (#…
MarekUrzon Apr 11, 2026
e6b6814
fix(auth): reject customer JWTs issued before session revocation
MarekUrzon Apr 11, 2026
488e9e1
fix(sales): reorder document detail tabs (#1245)
amtmich Apr 11, 2026
6949009
hackon(HCK-0025): tests: add low-level coverage for module-entities.t…
pawelleszczewicz Apr 11, 2026
782f6e8
hackon(HCK-0047): bug: Logout from develop environment redirects to d…
pawelleszczewicz Apr 11, 2026
4dc5d01
Improve reliability of webhooks and fix cross-org data leak in webhoo…
strzesniewski Apr 11, 2026
7393d84
hackon(HCK-0020): tests: add low-level coverage for inspect.ts (#1234)
pawelleszczewicz Apr 11, 2026
0a4f1af
Docs/design system audit 2026 04 10 (#1226)
zielivia Apr 11, 2026
0d89123
tests
MarekUrzon Apr 11, 2026
c4ce931
add Tenant org/scoped to all nativeDelete calls (#1244)
strzesniewski Apr 11, 2026
9bf3fe3
Fix findOneWithDecryption
strzesniewski Apr 11, 2026
86c8a72
fix(workflows): visual editor step delete does not work with nested c…
RadnoK Apr 11, 2026
a301962
Fix/superadmin privilege escalation (#1266)
WH173-P0NY Apr 11, 2026
a843d29
Fix markAllAsRead to emit read + SSE events per notification (#1248)
Tomeckyyyy Apr 11, 2026
a751437
fix(workflows): accept date strings in definition form schema
RadnoK Apr 11, 2026
9529b8c
hackon(HCK-0077): bug: add screenshot to workflows documentation
pawelleszczewicz Apr 11, 2026
3790c18
fix(core): align business rules page RBAC metadata
WXYZx Apr 11, 2026
bad1aba
hackon(HCK-0071): docs: add missing sidebar entry for user-guide/self…
pawelleszczewicz Apr 11, 2026
c57c3df
Fix stored XSS in attachment uploads
WH173-P0NY Apr 11, 2026
ff6d340
fix(search): hide navbar search when search module is disabled
jtomaszewski Apr 11, 2026
97ab3c6
chore: gitignore .ai/qa/test-results in root and app template
jtomaszewski Apr 11, 2026
9e51a94
chore: consolidate .ai/qa gitignore entries at root level
jtomaszewski Apr 11, 2026
0334a90
fix(sales): add email and phone validation to shipment form (#1018)
pawelleszczewicz Apr 11, 2026
be510e8
chore: use global test-results/ and playwright-report/ ignore patterns
jtomaszewski Apr 11, 2026
5af5293
chore: use global coverage/ ignore pattern
jtomaszewski Apr 11, 2026
8e6aa9b
test(attachments): reset findOne mock between tests to fix pollution
WH173-P0NY Apr 11, 2026
12b69ee
fix(ui): consistent timestamp formatting in table views and tooltips …
pawelleszczewicz Apr 11, 2026
a8be155
fix
MarekUrzon Apr 11, 2026
12791c8
fix: add missing open-api specs for responses for workflows api #333
Marynat Apr 12, 2026
2657b6d
test(workflows): add integration tests for workflow definition and in…
Marynat Apr 12, 2026
c2de759
fix(auth): reject non-superadmin actors with null tenant in roleTenan…
MarekUrzon Apr 12, 2026
da376a7
tests: add integration tests for sales, customers, and auth modules #622
Marynat Apr 12, 2026
4680454
fix(customers): clarify invalid timeline entity errors (#1262)
amtmich Apr 12, 2026
c045ec6
fix: add missing open-api specs for responses for workflows api #333 …
dominikpalatynski Apr 12, 2026
2e30822
test(workflows): add integration tests for workflow definition and in…
dominikpalatynski Apr 12, 2026
d1e760f
hackon(HCK-0094): tests: add low-level coverage for agentic-init.ts
pawelleszczewicz Apr 12, 2026
c25467a
hackon(HCK-0097): tests: add low-level coverage for merger.ts
pawelleszczewicz Apr 12, 2026
dfeed91
hackon(HCK-0094): tests: add low-level coverage for agentic-init.ts
pawelleszczewicz Apr 12, 2026
0f5bd9c
hackon(HCK-0097): tests: add low-level coverage for merger.ts
pawelleszczewicz Apr 12, 2026
b044c57
hackon(HCK-0097): tests: add low-level coverage for merger.ts
pawelleszczewicz Apr 12, 2026
b8ba170
hackon(HCK-0094): tests: add low-level coverage for agentic-init.ts
pawelleszczewicz Apr 12, 2026
8f28c7c
fix(inbox_ops): add missing i18n translation files (#897) (#1354)
pawelleszczewicz Apr 12, 2026
9047df6
fix: prevent build failures when the example module is disabled #601 …
Marynat Apr 12, 2026
c9b08b5
tests: add low-level coverage for agentic-init.ts (#1351)
haxiorz Apr 12, 2026
0f3e971
tests: add integration tests for sales, customers, and auth modules #…
haxiorz Apr 12, 2026
3046f91
fix flaky test
strzesniewski Apr 12, 2026
ac5e2c6
fix/Jwt not expired (#1252)
haxiorz Apr 12, 2026
127ed09
fix(security): preserve sandbox CSP on attachment file downloads
WH173-P0NY Apr 12, 2026
ff70daf
tests: add low-level coverage for merger.ts (#1352)
haxiorz Apr 12, 2026
8432e9e
bug: add screenshot to workflows documentation (#1284)
haxiorz Apr 12, 2026
0a03fd8
fix(sales): add email and phone validation to shipment form (#1018) (…
haxiorz Apr 12, 2026
84065e7
docs: add missing sidebar entry for user-guide/self-service-onboardin…
haxiorz Apr 12, 2026
7e4d06a
fix(workflows): accept date strings in definition form schema (#1275)
dominikpalatynski Apr 12, 2026
cc4ac42
Fixed rbac issue (#1283)
AK-300codes Apr 12, 2026
b23ccf6
Sales Documents Tenant Scope Fixes (#1236)
dominikpalatynski Apr 12, 2026
c7e05d3
fix: ensure tag filters display labels instead of UUIDs across affect…
Marynat Apr 12, 2026
539ff56
fix flaky test (#1367)
haxiorz Apr 12, 2026
4a8943f
fix: gitignore test-results and playwright-report globally (#1298)
haxiorz Apr 12, 2026
57e1c45
fix(search): hide navbar search when search module is disabled (#1297)
haxiorz Apr 12, 2026
945454a
Enforce RBAC on customer detail endpoints and add guardrail test (#1327)
Tomeckyyyy Apr 12, 2026
eaee649
fix(directory): honor All Organizations for ACL __all__ non-superAdmi…
pawelleszczewicz Apr 12, 2026
f87df92
Feature/smart test skill (#1374)
AK-300codes Apr 12, 2026
2511ae3
Fix business rules page RBAC metadata alignment (#1288)
haxiorz Apr 12, 2026
78d3d1b
fix: improve product search in sales line item dialog (#1373)
amtmich Apr 12, 2026
7d2e421
tests: add low-level coverage for agentic-setup.ts (#1322)
pawelleszczewicz Apr 12, 2026
1f10889
docs: improve customization guide with fixes and enrichments (issue #…
pawelleszczewicz Apr 12, 2026
fbed453
fix(ui): consistent timestamp formatting in table views and tooltips …
haxiorz Apr 12, 2026
885e704
fix(attachments): enforce tenant scope on public-partition file acces…
RMN-45 Apr 12, 2026
3dfcf2f
fix(business_rules): allow creating rules without conditionExpression…
pawelleszczewicz Apr 12, 2026
19b0a96
fix(security): reject forged payment gateway webhooks (#1311)
WH173-P0NY Apr 12, 2026
3169920
fix(query-index): enforce trusted tenant scope in subscribers (#1389)
WXYZx Apr 12, 2026
c91f31f
hackon(HCK-0104): tests: add low-level coverage for interceptors.ts (…
pawelleszczewicz Apr 12, 2026
d2ce6ca
docs: fix broken spec references in AGENTS.md files (#1084) (#1301)
pawelleszczewicz Apr 12, 2026
48b44ab
add error handling and encryption-safe lookups to notification subscr…
strzesniewski Apr 12, 2026
01776c4
fix(cli): resolve app-level workers and exports from .ts source files…
pawelleszczewicz Apr 12, 2026
c03899a
fix(webhooks): dedupe inbound replays without message id (#1394)
WXYZx Apr 12, 2026
8b0ae9b
tests: add low-level coverage for metadata.ts (#1308)
pawelleszczewicz Apr 12, 2026
e819c58
feat(skills): add review-pr skill for automated PR reviews (#1385)
pkarw Apr 12, 2026
6234aa9
fix(workflows): serialize workflow instance execution (#1391)
WXYZx Apr 12, 2026
16234e5
fix(security): enforce tenant isolation on sudo challenge configs (#1…
WH173-P0NY Apr 12, 2026
d120c34
fix(attachments): replace PDF OCR delegate chain with pdfjs-dist (#1250)
WH173-P0NY Apr 12, 2026
517d719
fix(sales): prevent concurrent shipment overshipping (#1247)
WXYZx Apr 12, 2026
461acab
fix(auth): restore admin nav module source (#1239)
adam-marszowski Apr 12, 2026
b892e2d
fix(sales): prevent concurrent return double credits (#1249)
WXYZx Apr 12, 2026
1fcb594
fix(ai-assistant): enforce endpoint RBAC in code mode api requests (#…
WXYZx Apr 12, 2026
991fce6
Fix/hackon/005 sales payments integrity (#1221)
strzesniewski Apr 12, 2026
71c0c0a
fix(docs): replace ghost `modules:prepare` references with `yarn gene…
matkowalski Apr 12, 2026
8fe74db
Prevent unsafe protocols in inline URL custom fields (#1296)
WXYZx Apr 12, 2026
be37b7b
Fix customer auth compound rate-limit identifiers (#1292)
WXYZx Apr 12, 2026
b6098e7
hackon(HCK-0078): tests: add low-level coverage for appResolver.ts (#…
pawelleszczewicz Apr 12, 2026
e117165
Fix staff session token rotation on login (#1293)
WXYZx Apr 12, 2026
46b23ba
Fixes (#1278)
strzesniewski Apr 12, 2026
169bef9
Harden attachment image rendering before sharp processing (#1294)
WXYZx Apr 12, 2026
2dc93c0
feat(sales): add invoice and credit memo CRUD commands, API routes, a…
lbajsarowicz Apr 12, 2026
0436f3b
fix(auth): prevent open redirect in locale switch endpoint (#1264)
MarekUrzon Apr 12, 2026
e34f3af
refactor: move default encryption maps to per-module registration (#1…
amtmich Apr 12, 2026
693d2e5
Fix missing idempotency in shipping carrier webhook processing (#1360)
WXYZx Apr 12, 2026
0ebd81c
Feat/ds semantic tokens v2 (#1281)
zielivia Apr 12, 2026
6b4c40a
Fix tenant isolation and race conditions in customer_accounts module …
strzesniewski Apr 12, 2026
6ca81ea
docs(ds): Design System enforcement — AGENTS.md rules, PR checklist, …
zielivia Apr 12, 2026
3696d98
Fix API dispatcher auth default (#1305)
WH173-P0NY Apr 12, 2026
ba9bec5
fix(tests): replace flaky TC-ADMIN-008 integration test with unit tes…
pkarw Apr 13, 2026
423f883
Serialize workflow instance execution (#1393)
WXYZx Apr 13, 2026
2b28232
fix: add OPENCODE_* env var fallbacks for AI provider keys (#1438)
lchrusciel Apr 13, 2026
362a642
fix(scheduler): show system and tenant-scoped jobs on list page (#815…
RMN-45 Apr 13, 2026
0c64ff1
Serialize quote acceptance to order conversion (#1392)
WXYZx Apr 13, 2026
fe7e3fd
fix(security): cap one-time API key TTL and use soft-delete for clean…
RMN-45 Apr 13, 2026
b42e973
fix(sales): resolve merge conflict with develop — rebase UoM fix on t…
pawelleszczewicz Apr 13, 2026
5f87639
fix: unit tests stabilization + disabled-example-module-build test di…
pkarw Apr 13, 2026
1509339
Merge branch 'develop' of https://github.com/open-mercato/open-mercat…
pkarw Apr 13, 2026
cc0974c
fix(workflows): prevent privilege escalation via CALL_API admin-by-na…
RMN-45 Apr 13, 2026
159f9e2
fix(security): re-resolve customer portal ACL on every request (#1316)
WH173-P0NY Apr 13, 2026
4594a66
feat: add product variant media display and default fallback logic #8…
Marynat Apr 13, 2026
1d166d1
fix(auth): apply input validation to feature-check endpoint to preven…
staskolukasz Apr 13, 2026
ec65328
fix(attachments): normalize empty/null extracted text in attachment p…
pawelleszczewicz Apr 13, 2026
6f5de46
fix: unit tests stabilization
pkarw Apr 13, 2026
48731d5
Merge branch 'develop' of https://github.com/open-mercato/open-mercat…
pkarw Apr 13, 2026
1527897
feat: live coding - simplified AI specs (#1251)
pkarw Apr 13, 2026
04bcc42
feat(workflows): link workflow instance ID to detail page in list tab…
jtomaszewski Apr 13, 2026
0f53c78
bug(customers): #793 #792 add normalization for nested profile payloa…
Marynat Apr 13, 2026
d6ea365
fix: unit tests stabilization
pkarw Apr 13, 2026
a1b9a55
Merge branches 'develop' and 'develop' of https://github.com/open-mer…
pkarw Apr 13, 2026
243750a
feat: extend review-pr skill for worktree reviews and fix-forward flo…
pkarw Apr 13, 2026
5a9117a
merge: resolve conflicts with develop
pkarw Apr 13, 2026
d61bbf1
fix(attachments): replace hardcoded error strings with i18n translations
pkarw Apr 13, 2026
71aa550
feat(review-pr): add duplication check and fix doubled PR link
pkarw Apr 13, 2026
b755c32
fix(i18n): sort attachment locale keys alphabetically
pkarw Apr 13, 2026
db05864
feat(review-pr): add i18n key sort check to auto-detections and valid…
pkarw Apr 13, 2026
fc35d62
Fix coverage warmup and prevent DB connection pool exhaustion (#1439)
staskolukasz Apr 13, 2026
db9753a
fix(security): migrate feature_toggles from requireRoles to requireFe…
pkarw Apr 13, 2026
cd4c4eb
chore(skills): add conventional-commit PR title conventions to fix an…
pkarw Apr 13, 2026
bdb3301
fix(feature_toggles): add ACL unit tests and make skills fully autono…
pkarw Apr 13, 2026
12ac858
Fix stored XSS in attachment uploads (carry-forward #1302) (#1442)
pkarw Apr 13, 2026
2a7444f
tests(onboarding): add unit test coverage for onboarding package
pawelleszczewicz Apr 11, 2026
6dd5ec9
test(onboarding): tighten service test typing
pkarw Apr 13, 2026
ec57359
fix: integration tests stabilziation
pkarw Apr 13, 2026
9d30407
fix(workflows): halt workflow on activity failure by default
jtomaszewski Apr 13, 2026
742a01c
test(workflows): add tests for activity failure halt behavior
jtomaszewski Apr 13, 2026
3045449
Fix customer signup account enumeration
WH173-P0NY Apr 11, 2026
8588c06
fix
WH173-P0NY Apr 11, 2026
a670f7b
tests(content): add unit test coverage for content package (#1303)
pawelleszczewicz Apr 13, 2026
de078b8
fix(sync-akeneo): block Akeneo SSRF and credential leaks (#1285)
WH173-P0NY Apr 13, 2026
6ccddc9
fix(customers): apply entityId filter in comments list endpoint (#110…
pawelleszczewicz Apr 13, 2026
b2b37af
fix(ai-assistant): backport isolated-vm sandbox from main to develop …
RMN-45 Apr 13, 2026
836b063
feat: add docs to user guide section about attachments (#1190)
pawelleszczewicz Apr 13, 2026
2c5d87d
fix standalone dist cleanup for integration parity (#1471)
pkarw Apr 13, 2026
192fce7
fix(business_rules): wire CRUD events to rule engine via wildcard sub…
RMN-45 Apr 13, 2026
08a06d4
fix(webhooks): block SSRF in outbound webhook delivery URLs (#1369)
RMN-45 Apr 13, 2026
e52e08a
fix(workflows): prevent ReDoS in event trigger regex filter condition…
RMN-45 Apr 13, 2026
4ba270e
tests: add low-level coverage for debug.ts (#1355)
pawelleszczewicz Apr 13, 2026
d3a54c8
tests: add low-level coverage for presenter-enricher.ts (#1356)
pawelleszczewicz Apr 13, 2026
ab16b9a
tests: add low-level coverage for openapi-paths.ts (#1238)
pawelleszczewicz Apr 13, 2026
9895703
fix: standardize organization validation error when org context is mi…
pawelleszczewicz Apr 13, 2026
4e0a246
tests: add low-level coverage for check.ts (#1230)
pawelleszczewicz Apr 13, 2026
dd92ccf
bug: Custom fields of `kind: relation` render as raw UUIDs instead of…
pawelleszczewicz Apr 13, 2026
4f2040b
fix(workflows): UI contract violations + DS token migration (carry-fo…
pkarw Apr 14, 2026
1bcc935
fix(webhooks): add view-details action to delivery log (carry-forward…
pkarw Apr 14, 2026
895057a
fix(security): hash staff session and password-reset tokens with HMAC…
pkarw Apr 14, 2026
abf6b23
fix(runtime): preserve Redis URL semantics across queue and scheduler…
pkarw Apr 14, 2026
e061455
fix: handle missing conditionExpression when creating business rules …
pkarw Apr 14, 2026
2ab787d
fix(customers): deassign deal from customer/company detail instead of…
pkarw Apr 14, 2026
74b97df
feat: add default value support for custom fields (#824) (#1473)
pkarw Apr 14, 2026
846e8e7
security: upgrade next and @hono/node-server to fix Dependabot alerts…
pkarw Apr 14, 2026
f70d8cc
fix(business_rules): accept date strings in rule form schema (carry-f…
pkarw Apr 14, 2026
52f3d70
fix(attachments): remove markitdown shell-out, replace with pure-JS e…
WH173-P0NY Apr 14, 2026
ade41e4
test(planner): integration tests for availability rule sets and CRUD …
pkarw Apr 14, 2026
31b2ede
fix: fixing missing ast generator (#1219)
pkarw Apr 14, 2026
81b9071
fix(auth): reset attacker-controlled scope params and add auth.view g…
pkarw Apr 14, 2026
03b04c1
fix(entities): sanitize HTML rich text fields at persistence boundary…
pkarw Apr 14, 2026
f9b25be
fix(auth): enforce tenantId requirement for roles (#1470)
pkarw Apr 14, 2026
acba877
fix(directory): trim whitespace-padded organization scope IDs (carry-…
pkarw Apr 14, 2026
935e1df
fix(sales): add tag description to filters and fix useMemo deps (carr…
pkarw Apr 14, 2026
10854e1
feat(ui): redesign perspectives panel as Views with DS compliance (#1…
pkarw Apr 14, 2026
8e46d47
spec: PR label workflow — streamlined review & QA pipeline (#1456)
pkarw Apr 14, 2026
eb1951f
fix(auth): reject deleted users during session token refresh (carry-f…
pkarw Apr 14, 2026
a4e4c09
fix(sales,workflows): add pessimistic locking to prevent duplicate si…
pkarw Apr 14, 2026
b311627
fix(security): make JWTs revocable and isolate staff/customer audienc…
pkarw Apr 14, 2026
e176d10
fix(sales): regression test + findOneWithDecryption for quote-to-orde…
pkarw Apr 14, 2026
904d6ed
fix(catalog): prevent variant table overflow (carry-forward #1240) (#…
pkarw Apr 14, 2026
ea3399f
fix(i18n): sync missing translations + restore BC-critical exports (c…
pkarw Apr 14, 2026
1d1dfaf
docs: finalize pr label workflow (#1489)
pkarw Apr 14, 2026
55cb8b4
fix(security): hash message access and quote acceptance tokens at res…
pkarw Apr 14, 2026
6a15309
fix(workflows): use filterIds for org scoping in all GET handlers (ca…
pkarw Apr 14, 2026
52320e1
Fix/windows build (#1459)
PawelSydorow Apr 14, 2026
4ea1246
fix(ci): remove YARN_ENABLE_IMMUTABLE_INSTALLS workaround from snapsh…
yokoszn Apr 14, 2026
4f27ff8
fix(ci/security): scope id-token to snapshot job; add dependabot and …
yokoszn Apr 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
224 changes: 224 additions & 0 deletions .ai/analysis/generated-files-comparison.md

Large diffs are not rendered by default.

6,352 changes: 6,352 additions & 0 deletions .ai/design-system-audit-2026-04-10.md

Large diffs are not rendered by default.

367 changes: 367 additions & 0 deletions .ai/docs/ds-v0-usage-guide.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,367 @@
# Design System v0 — Usage Guide

How to use the DS v0 components, tokens, and tooling in Open Mercato.

---

## 1. Semantic Status Tokens

### What changed
Instead of hardcoded Tailwind colors (`text-red-600`, `bg-green-100`), use semantic tokens that automatically handle dark mode.

### Token structure
```
{property}-status-{status}-{role}
```
- **property**: `text`, `bg`, `border`
- **status**: `error`, `success`, `warning`, `info`, `neutral`
- **role**: `bg`, `text`, `border`, `icon`

### Usage examples

```tsx
// BEFORE (broken dark mode, inconsistent)
<span className="text-red-600 dark:text-red-400">Error</span>
<div className="bg-green-50 dark:bg-green-950/20">Success</div>
<div className="border-amber-300">Warning</div>

// AFTER (dark mode automatic, consistent)
<span className="text-status-error-text">Error</span>
<div className="bg-status-success-bg">Success</div>
<div className="border-status-warning-border">Warning</div>
```

### Full token list

| Token | Light | Dark | When to use |
|-------|-------|------|-------------|
| `text-status-error-text` | dark red | light red | Error messages, validation |
| `text-status-error-icon` | medium red | light red | Error icons |
| `bg-status-error-bg` | pale red | dark red | Error backgrounds |
| `border-status-error-border` | red border | dark red border | Error borders |
| `text-status-success-text` | dark green | light green | Success messages |
| `text-status-success-icon` | medium green | light green | Success icons |
| `bg-status-success-bg` | pale green | dark green | Success backgrounds |
| `border-status-success-border` | green border | dark green border | Success borders |
| `text-status-warning-text` | dark amber | light amber | Warning messages |
| `text-status-warning-icon` | medium amber | light amber | Warning icons |
| `bg-status-warning-bg` | pale amber | dark amber | Warning backgrounds |
| `border-status-warning-border` | amber border | dark amber border | Warning borders |
| `text-status-info-text` | dark blue | light blue | Info messages |
| `text-status-info-icon` | medium blue | light blue | Info icons |
| `bg-status-info-bg` | pale blue | dark blue | Info backgrounds |
| `border-status-info-border` | blue border | dark blue border | Info borders |
| `text-status-neutral-text` | gray | light gray | Neutral/default states |
| `bg-status-neutral-bg` | pale gray | dark gray | Neutral backgrounds |
| `border-status-neutral-border` | gray border | dark gray border | Neutral borders |

### Opacity support
Tokens work with Tailwind opacity modifiers:
```tsx
<div className="bg-status-warning-bg/50">Semi-transparent warning</div>
```

### What NOT to migrate
- Decorative colors (brand, charts, gradients) — keep as-is
- `text-destructive`, `bg-destructive` — already semantic, keep
- Non-status colors (`text-muted-foreground`, `bg-card`) — not in scope

---

## 2. Typography Scale

### Rule
Never use arbitrary text sizes (`text-[11px]`, `text-[13px]`). Use the Tailwind scale:

| Arbitrary | Replace with | Size |
|-----------|-------------|------|
| `text-[10px]` | `text-xs` | 12px |
| `text-[11px]` | `text-overline` | 11px (custom token) |
| `text-[12px]` | `text-xs` | 12px |
| `text-[13px]` | `text-sm` | 14px |
| `text-[14px]` | `text-sm` | 14px |
| `text-[15px]` | `text-base` | 16px (manual review) |

### `text-overline` usage
For 11px uppercase section labels:
```tsx
<span className="text-overline font-semibold uppercase tracking-wider text-muted-foreground">
SECTION LABEL
</span>
```

### Typography hierarchy

| Role | Tailwind | When to use |
|------|----------|-------------|
| Page title | `text-2xl font-bold tracking-tight` | One per page |
| Section title | `text-xl font-semibold` | Major sections |
| Subsection | `text-sm font-semibold` | Card titles, detail sections |
| Body | `text-sm` | Default body text |
| Caption | `text-xs text-muted-foreground` | Timestamps, secondary info |
| Label | `text-sm font-medium` | Form labels |
| Overline | `text-overline font-semibold uppercase tracking-wider` | Category tags, section labels |

---

## 3. New Components

### StatusBadge

Display entity status with consistent visual mapping.

```tsx
import { StatusBadge, type StatusMap } from '@open-mercato/ui/primitives/status-badge'

// 1. Define a status map for your entity
const orderStatusMap: StatusMap<'draft' | 'confirmed' | 'shipped' | 'cancelled'> = {
draft: 'neutral',
confirmed: 'info',
shipped: 'success',
cancelled: 'error',
}

// 2. Use in your component
<StatusBadge variant={orderStatusMap[order.status]} dot>
{order.status}
</StatusBadge>
```

Variants: `error`, `success`, `warning`, `info`, `neutral`

### FormField

Wrap standalone form inputs with label + error display. Use in portal pages, auth forms, custom pages. Do NOT use inside CrudForm (it handles fields internally).

```tsx
import { FormField } from '@open-mercato/ui/primitives/form-field'

<FormField label="Email" required error={errors.email}>
<Input
type="email"
value={email}
onChange={(e) => setEmail(e.target.value)}
/>
</FormField>
```

Props:
- `label` — field label text
- `description` — help text below the field
- `error` — error message string (shows in red)
- `required` — adds asterisk to label
- `id` — links label to input for accessibility

### SectionHeader

Section title with optional count badge and action button.

```tsx
import { SectionHeader } from '@open-mercato/ui/backend/SectionHeader'

<SectionHeader
title="Line Items"
count={items.length}
action={{ label: 'Add Item', onClick: handleAdd }}
/>
```

### CollapsibleSection

```tsx
import { CollapsibleSection } from '@open-mercato/ui/backend/SectionHeader'

<CollapsibleSection title="Advanced Settings" defaultOpen={false}>
<p>Content here</p>
</CollapsibleSection>
```

---

## 4. Alert Variants

Alert now supports status variants:

```tsx
import { Alert, AlertDescription, AlertTitle } from '@open-mercato/ui/primitives/alert'

<Alert variant="destructive"> {/* error */}
<AlertTitle>Error</AlertTitle>
<AlertDescription>Something went wrong.</AlertDescription>
</Alert>

<Alert variant="success">
<AlertTitle>Saved</AlertTitle>
<AlertDescription>Changes applied.</AlertDescription>
</Alert>

<Alert variant="warning">
<AlertTitle>Attention</AlertTitle>
<AlertDescription>Review before proceeding.</AlertDescription>
</Alert>

<Alert variant="info">
<AlertTitle>Note</AlertTitle>
<AlertDescription>New feature available.</AlertDescription>
</Alert>
```

Use `Alert` instead of deprecated `Notice`.

---

## 5. DS Guardian — AI Enforcement Skill

DS Guardian is an agentic skill that Claude Code uses automatically when working on UI code. You can also invoke it directly.

### Slash commands

| Command | What it does |
|---------|-------------|
| `analyze the [module] module for DS violations` | Scans for hardcoded colors, arbitrary sizes, deprecated components, missing aria-labels |
| `migrate [module] to DS` | Full workflow: analyze, plan, confirm, migrate, review, report |
| `DS health` / `DS report` | Runs health check, shows metrics with delta vs baseline |
| `DS review` | Reviews current file/diff against DS rules, gives score 0-10 |
| `scaffold a list page for [entity]` | Generates a DS-compliant page from templates |

### Example workflows

**Migrate a module:**
```
> analyze the workflows module for DS violations
> migrate workflows to DS
```

**Check project health:**
```
> DS health
```

**Review before PR:**
```
> DS review my changes
```

### What DS Guardian checks
1. Hardcoded status colors (`text-red-*`, `bg-green-*`, `text-amber-*`, `bg-blue-*`)
2. Arbitrary text sizes (`text-[11px]`, `text-[13px]`)
3. Deprecated `Notice`/`ErrorNotice` imports
4. Inline `<svg>` (should use lucide-react)
5. Missing `aria-label` on icon-only buttons
6. Missing `EmptyState` on list pages
7. Missing `LoadingMessage` on async pages
8. Raw `fetch()` instead of `apiCall`

---

## 6. Health Check Script

Run manually to see current DS metrics:

```bash
bash .ai/scripts/ds-health-check.sh
```

Output saved to `.ai/reports/ds-health-YYYY-MM-DD.txt`. Automatically compares with the previous report to show delta.

### Metrics tracked

| Metric | Target | Description |
|--------|--------|-------------|
| Hardcoded status colors | 0 | `text-red-*`, `bg-green-*`, etc. in .ts/.tsx files |
| Arbitrary text sizes | 1 | `text-[Npx]` (1 allowed: `text-[9px]` for notification badge) |
| Notice imports | 0 | Deprecated `Notice` component usage |
| ErrorNotice imports | 0 | Deprecated `ErrorNotice` component usage |
| Inline SVG | 0 | `<svg>` in .tsx files (use lucide-react) |
| Raw fetch files | 0 | `fetch()` in backend pages (use apiCall) |
| Empty state coverage | 100% | Pages with EmptyState / total list pages |
| Loading state coverage | 100% | Pages with LoadingMessage / total pages |
| Semantic token usages | growing | Count of `status-error-*`, `status-success-*` etc. |

---

## 7. Migration Scripts

Two codemod scripts for bulk migration:

```bash
# Migrate hardcoded colors in a module
bash .ai/skills/ds-guardian/scripts/ds-migrate-colors.sh packages/core/src/modules/MODULE_NAME/

# Migrate arbitrary text sizes in a module
bash .ai/skills/ds-guardian/scripts/ds-migrate-typography.sh packages/core/src/modules/MODULE_NAME/

# Review the diff
git diff packages/core/src/modules/MODULE_NAME/
```

Always review the diff after running scripts — edge cases (decorative colors, opacity modifiers, conditional expressions) need manual attention.

---

## 8. Boy Scout Rule

When editing any file that contains DS violations, you MUST fix at minimum the lines you touched:

- If you edit a line with `text-red-600` for a status, change it to `text-status-error-text`
- If you edit a line with `text-[11px]`, change it to `text-overline`
- You don't have to fix the entire file, but fix what you touch

This is enforced via AGENTS.md rules and PR template checklist.

---

## 9. PR Compliance Checklist

Every PR template now includes a Design System Compliance section:

- [ ] No hardcoded status colors (`text-red-*`, `bg-green-*`, etc.)
- [ ] No arbitrary text sizes (`text-[11px]`)
- [ ] Empty state handled where applicable
- [ ] Loading state handled where applicable
- [ ] Icon-only buttons have `aria-label`
- [ ] Uses DS components (`Alert`, `StatusBadge`, `FormField`) instead of ad-hoc markup

---

## 10. Quick Reference Card

### Imports

```tsx
// Status display
import { StatusBadge, type StatusMap } from '@open-mercato/ui/primitives/status-badge'

// Form fields (standalone forms only)
import { FormField } from '@open-mercato/ui/primitives/form-field'

// Section headers
import { SectionHeader, CollapsibleSection } from '@open-mercato/ui/backend/SectionHeader'

// Alerts (replacing Notice)
import { Alert, AlertDescription, AlertTitle } from '@open-mercato/ui/primitives/alert'

// Icons (always lucide-react)
import { Check, X, AlertTriangle, Info } from 'lucide-react'
```

### Decision table

| I need to... | Use |
|---|---|
| Show entity status | `<StatusBadge variant={map[status]} dot>` |
| Show error/success/warning inline | `<Alert variant="destructive\|success\|warning\|info">` |
| Show toast | `flash('message', 'success')` |
| Wrap form input with label | `<FormField label="..." error={...}>` |
| Section header with count | `<SectionHeader title="..." count={n}>` |
| Red text for error | `text-status-error-text` (not `text-red-600`) |
| Green background for success | `bg-status-success-bg` (not `bg-green-50`) |
| 11px uppercase label | `text-overline font-semibold uppercase tracking-wider` |
| Icon | `<IconName className="size-4" />` from lucide-react |
| Icon-only button | Add `aria-label="description"` |

### Reference module
When building new UI, use the **customers module** as reference implementation:
- List: `packages/core/src/modules/customers/backend/customers/people/page.tsx`
- Detail: `packages/core/src/modules/customers/backend/customers/people/[id]/page.tsx`
- Status mapping: `packages/core/src/modules/customers/components/formConfig.tsx`
Loading