Commit graph

3,180 commits

Author SHA1 Message Date
50de5f412f
chore(release): bump version via gitversion for 1.0.8-rc3 2026-08-23 23:19:48 +01:00
5274d7bdf5 Merge pull request 'release/1.0.8-rc1' (#42) from release/1.0.8-rc1 into main
All checks were successful
Dotnet build and test / build (push) Successful in 7m4s
Reviewed-on: #42
2026-08-23 23:19:06 +01:00
48feb27277
changelog: align 1.0.8-rc1 section title with release workflow
All checks were successful
Dotnet build and test / build (pull_request) Successful in 5m31s
Forgejo Release / release (push) Successful in 7m20s
1.0.8-rc1
The Forgejo release workflow validates the section title against the
channel derived from tag parity: '[TAG] - stable', '[TAG] - preview',
or '[TAG] - unstable'. The 2026-08-21 entry broke the validation with
'## [1.0.8-rc1] - 2026-08-21' (date suffix instead of channel). Move
the date into the body of the section (it is already mentioned in the
'Fixed' subsection) and use '## [1.0.8-rc1] - unstable' to match the
1.0.6 / 1.0.7 convention.
2026-08-21 23:07:34 +01:00
cec482625d
release unstables
Some checks failed
Dotnet build and test / build (pull_request) Successful in 7m37s
Forgejo Release / release (push) Failing after 15s
2026-08-21 22:51:25 +01:00
39ec739eab
changelog: section for 1.0.8-rc1
Some checks failed
Forgejo Release / release (push) Failing after 15s
Dotnet build and test / build (pull_request) Has been cancelled
Ajoute la section [1.0.8-rc1] au CHANGELOG.md, en français, au format
Keep a Changelog (### Added / ### Changed / ### Fixed). Couvre :
- le fix backend du 500 sur POST /api/v1/blogacl (commit d2a0c263)
- le fix client PostIt (commit b82b6722)
- le passage de CheckOwner en async (commit e48ede1e)
- le seed one-shot de la fixture BlogsWebServerFixture
- les tests de non-régression (sentinelles 'never 500' et 'shape PostIt')
- la règle 'Pas de object' dans CONTRIBUTING.md

Met aussi à jour le bloc de liens de comparaison en bas du fichier
pour pointer [1.0.8-rc1] vers 1.0.7...1.0.8-rc1.
2026-08-21 22:43:31 +01:00
9da6888e03 Merge pull request 'feat/postit-acl-members' (#41) from feat/postit-acl-members into release/1.0.8-rc1
Reviewed-on: #41
2026-08-21 22:31:58 +01:00
d2a0c263dd
acl post: reject BlogPostId <= 0 with 400, no 500
All checks were successful
Dotnet build and test / build (pull_request) Successful in 9m18s
The 2026-08-21 prod 500 on POST /api/v1/blogacl was caused by the
PostIt client sending { circleId } only — the server deserialised
into CircleAuthorizationToBlogPost with BlogPostId = default(long) = 0,
and EF Core refused the INSERT with InvalidOperationException.

The PostIt-side fix lives in b82b6722 (enrich the payload with
blogPostId). This commit is the server-side guard: validate
BlogPostId > 0 in the controller and return 400 BadRequest instead
of letting the request reach SaveChangesAsync. The same shape that
crashed on 2026-08-21 now fails fast at the validation layer.

Verified by BlogAclApiTests.PostCircleAuthorization_dosent_return_500:
sentinel that asserts 'never 500' on a payload with BlogPostId = -1.
Previously red (500 from EF Core), now green (400 from the new guard).
2026-08-21 22:08:05 +01:00
e48ede1e84
acl post: never 500 regression sentinel + async CheckOwner + fixture seed
The hard rule on POST /api/v1/blogacl is: a 500 is never acceptable,
regardless of the payload shape. The prod 500 logged on 2026-08-21 on
mercure was caused by the PostIt client sending { circleId } only, which
the server deserialised into CircleAuthorizationToBlogPost with
BlogPostId = default(long) = 0; EF Core refused the INSERT with
InvalidOperationException: The value of
'CircleAuthorizationToBlogPost.BlogPostId' is unknown. The PostIt fix
lives in b82b6722 (enrich the payload with blogPostId). The server-side
guard lives in this commit:

- BlogAclApiController.CheckOwner is now async and uses FirstOrDefaultAsync
  instead of First, so it does not deadlock the request thread and
  returns false on a missing circle (which the controller already maps
  to ChallengeResult).
- BlogsWebServerFixture now seeds Alice, her Circle and her BlogPost
  in ConfigurePipelineAsync, once at host startup, against the shared
  SqliteConnection (Cache=Shared). EnsureCreated is idempotent and
  runs against the connection that every DbContext resolves through,
  so the test theory can POST payloads with real FK ids against a
  schema that actually has the Circle / BlogSpot tables.
- BlogAclApiTests:
    - PostCircleAuthorization_returns_201_when_payload_mirrors_PostIt_shape
      is the regression sentinel for the prod fix.
    - PostCircleAuthorization_never_returns_500 is a [Theory] over
      several payload shapes; any future commit that reintroduces a
      500 path turns it red. CleanupAcl at the start of each insert-
      bearing test isolates against xUnit's no-guarantee-of-order
      execution: a successful POST in test N would otherwise conflict
      with test N+1 against the same (CircleId, BlogPostId) pair.
2026-08-21 22:00:27 +01:00
4956890236
refacto seed test db
Some checks failed
Dotnet build and test / build (pull_request) Failing after 8m8s
2026-08-21 20:45:46 +01:00
c645973b52
no object
Some checks failed
Dotnet build and test / build (pull_request) Failing after 9m2s
2026-08-21 20:33:30 +01:00
34c7b153ff
warnings 2026-08-21 20:33:15 +01:00
4b9b8d5e78
fixes the compile
Some checks failed
Dotnet build and test / build (pull_request) Has been cancelled
2026-08-21 20:25:13 +01:00
107c4d0b00
test some failling pathes
Some checks failed
Dotnet build and test / build (pull_request) Failing after 4m37s
2026-08-21 19:37:22 +01:00
76a3660dcf
workaround on testing the null CloseButton
Some checks failed
Dotnet build and test / build (pull_request) Failing after 7m41s
2026-08-21 18:46:26 +01:00
404d406931
Testing circle was authorized
Some checks failed
Dotnet build and test / build (pull_request) Has been cancelled
2026-08-21 17:21:54 +01:00
b82b6722c7
fixes a 500 in prod and the associated test 2026-08-21 16:58:27 +01:00
8f91cbed02
A Circle must pre-exist before beeing used by an authorization 2026-08-21 16:40:24 +01:00
88461786ee
Roll back refacto on Posit.Tests 2026-08-21 16:18:20 +01:00
06672c4c90
remove dead 'Comment' field from CircleAuthorizationToBlogPost
The bool Comment on CircleAuthorizationToBlogPost was dead code:
never read or written by any caller in src/, no UI exposure, no
behavioural semantics. The wire DTO (CircleAuthorization in
Yavsc.Abstract) doesn't carry it, no reader consumes it, and the
PostIt client builds its payload without it.

What changes:
- src/Yavsc.Server/Models/Access/CircleAuthorizationToBlogPost.cs:
  remove the property.
- src/Yavsc.Blogs.Tests/BlogAclApiTests.cs: drop 'Comment = true'
  from the existing test payload and trim the now-inaccurate XML
  doc comment ('CircleId + BlogPostId + Comment' -> 'CircleId +
  BlogPostId'). Also adds a new [Fact] pinning the prod bug
  reported on 2026-08-21 (HTTP 500 'BlogPostId is unknown' when
  PostIt POSTs the bare { circleId } shape). That test stays red:
  the real fix for the 500 is in PostIt (payload needs blogPostId)
  + on the wire DTO + server-side validation, and lives in a
  follow-up commit.

Migration:
- src/Yavsc.Org/Migrations/20260820232152_DropCommentFromCircleAuthorizationToBlogPost
  drops the boolean 'Comment' column on CircleAuthorizationToBlogPost.
  The generated scaffold also wanted to drop three 'ClientId1'
  shadow FK columns on ClientScopes / ClientRedirectUris /
  ClientGrantTypes (from leftover HasOne<Client>() overrides in
  ApplicationDbContext.OnModelCreating); those were removed from
  the .cs to keep the migration scoped to this fix. Cleaning up the
  shadow property declarations themselves is left as a separate
  task.

The ModelSnapshot still reflects the shadow 'ClientId1' columns
intentionally: they exist in the prod database today (all NULL),
and EF will rescaffold a drop migration for them on the next
'migrations add' regardless. No data loss.
2026-08-21 00:27:27 +01:00
a44c04ad77
feat(postit): circles+ACL UI, blog fixture→SQLite, seed default user
Bundled end-of-branch commit on feat/postit-acl-members.

PostIt UI for circles + per-post ACL
- Reorganise PostIt.Tests into Auth/ and Blogs/ subfolders
  (Bearer/OIDC scope tests vs. blog API fakes live where they
  belong) and introduces PostItHeadlessCollection so the
  Avalonia.Headless tests share a single xUnit collection
  instead of contending with the EF-Core test host.
- Adds BlogAclApiTests (a brand-new behavioural layer over
  POST /api/v1/blogacl) and the fakes it relies on
  (BlogApiTestFakes, BlogPostAuthorDtoTests, AddCircleMember
  DialogTests); pulls UserId-through-OIDC-sub path into
  BearerScopeTests / FakeAuthorizingBrowser /
  OidcStubAuthority.
- App.axaml.cs gets a small PushPageAsync touch-up the new
  tests rely on.
- Drops UnitTest1.cs (xUnit scaffold, never used).

Yavsc.Blogs.Tests — SQLite instead of InMemory
- Bumps Yavsc.Blogs.Tests.csproj on
  Microsoft.EntityFrameworkCore.Sqlite and rewrites
  BlogsWebServerFixture to hold a single shared
  SqliteConnection (Cache=Shared) for the fixture lifetime,
  with a sync Dispose close to dodge async teardown hangs.
  Reason: the EF Core InMemory provider silently ignores FKs,
  which masked the kind of bug we are about to pin in the
  ACL tests. SQLite enforces them, so any future INSERT that
  forgets to seed its parent rows fails loudly here instead
  of passing the test and breaking prod.
- PublishEndpointTests and BlogApiSmokeTests get a one-line
  tweak to follow the new connection lifecycle.

Foreign-key fallout: seed the default user in the fixture
- Adds BlogsWebServerFixture.SeedUser(userName). Now that
  SQLite enforces BlogPost.AuthorId → AspNetUsers.Id, every
  test that POST/PUT/DELETE a BlogPost and sends AuthorId=
  'tester' in the payload needs an AspNetUsers row to satisfy
  the FK or it returns 500 with SQLite Error 19.
- BlogApiTests wraps the existing ResetDatabase with a
  ResetAndSeedDefaultUser helper for the six mutating tests;
  the four GET-only and ModelState-only tests keep the bare
  ResetDatabase.
- Side benefit: every test in Yavsc.Blogs.Tests now finishes
  cleanly instead of hanging at teardown — previously a stuck
  test held the shared SqliteConnection open and the next
  tests waited indefinitely.

Verified: dotnet test src/Yavsc.Blogs.Tests passes 25/25
green from a clean run, no fixture teardown hang.
2026-08-20 23:59:21 +01:00
6825f74308
refacto API prefix + nav.back 2026-08-20 20:50:52 +01:00
995a02197d Merge pull request 'fix(postit): repair Circles bindings + align UserSearchApi route' (#40) from feat/postit-acl-members into release/1.0.8-rc1
Reviewed-on: #40
2026-08-20 07:24:19 +01:00
bd6ca9d11f
fix(postit): repair Circles bindings + align UserSearchApi route
All checks were successful
Dotnet build and test / build (pull_request) Successful in 12m51s
- CirclesPage: drop VisualRoot/MainWindow hack, switch to App.PushPageAsync(vm)
- CirclesPageViewModel: make OpenAddMemberAsync public so Avalonia XAML trampoline can call it
- AddCircleMemberDialog: bind SearchAsync/Add (drop Command suffix)
- UserSearchApiController: route under Constants.APIPrefix (= api/v1/user-search), matching the rest of Yavsc.Blogs controllers and the PostIt client's BlogsApiUrl default
2026-08-20 07:22:07 +01:00
e75993ea36 Merge pull request 'fix/postit-acl' (#39) from fix/postit-acl into release/1.0.8-rc1
Reviewed-on: #39
2026-08-20 01:24:42 +01:00
46a9a84fbc
fixes the cirle POST
All checks were successful
Dotnet build and test / build (pull_request) Successful in 12m37s
2026-08-20 01:23:14 +01:00
ecfdca8f01
gixes the path to circles API 2026-08-19 21:02:28 +01:00
803e778208
access the post selector 2026-08-19 20:30:34 +01:00
a5ccfde7e1 Merge pull request 'fix/inactive-toolbar-buttons' (#38) from fix/inactive-toolbar-buttons into release/1.0.8-rc1
Reviewed-on: #38
2026-08-19 20:02:48 +01:00
e88920485a
chore(vscode): remove local mcp.json (openclaw moved to global User config).
Some checks failed
Dotnet build and test / build (pull_request) Failing after 17m50s
2026-08-19 19:59:50 +01:00
21a79074cc
chore(vscode): add PATH env to openclaw MCP server config
Lets the openclaw MCP server spawned by VS Code locate dotnet, adb
and other SDK tools (android-sdk, .dotnet/tools) used during
integration sessions.
2026-08-19 19:55:23 +01:00
6d9bb82b61
PostIt: register dialog pages in DI for ViewLocator resolution 2026-08-19 19:53:38 +01:00
600bb81be1
PostIt: show ViewLocator fallback errors in navigation 2026-08-19 17:32:51 +01:00
4cda942fb4
doc: lift PostIt navigation rule to top-level section
The 'Navigation (PostIt)' rule was buried as a sub-item under
'Conventions de code', mixed with style rules. Lift it to a
top-level section between 'Tests' and 'Conventions de code' so
contributors looking for nav guidance find it without scrolling
through editorconfig preferences.

Add a pointer to doc/architecture/postit.md for the full
topology (NavRoot, SessionStatusViewModel, lifecycle signals
vs user-driven nav). Content of the rule itself is unchanged
from 12a71ada — only the placement and the cross-link.
2026-08-19 17:19:43 +01:00
12a71ada6a
doc: align navigation docs with VM-first pattern
The two recent commits (3fbbafc4, 0065de70) replaced the
OpenSettingsRequested event + CurrentViewModel assignment with
App.PushPageAsync(vm): the VM resolves the target ViewModel
through DI, App resolves the Control through the ViewLocator,
guards against double-push, and pushes via NavRoot. The docs
were still describing the pre-refactor world.

Update three places:

- CONTRIBUTING.md — the "Navigation (PostIt)" rule now
  describes App.PushPageAsync as the single channel and shows
  the canonical OpenSettings command as the example.
- doc/architecture/postit.md — the Navigation section
  distinguishes VM-first navigation (App.PushPageAsync) from
  lifecycle signals (LoginSucceeded, LogoutCompleted) and
  drops the obsolete OpenSettingsRequested row.
- src/PostIt/PostIt/App.axaml.cs — refresh the SettingsPage
  singleton justification: point (c) now describes the
  anti-empilement guard inside PushPageAsync, not the
  OpenSettingsRequested handler that no longer exists.

No production behaviour change — doc only (and the inline
comment that referenced a removed event).
2026-08-19 17:17:22 +01:00
0065de7000
PostIt: homogenize VM-first navigation flows 2026-08-19 17:06:46 +01:00
3fbbafc454
PostIt: route VM navigation through ViewLocator 2026-08-19 17:01:58 +01:00
30a0e10bae
fixes the compilation 2026-08-19 15:45:49 +01:00
aa098daed5
doc: codify PostIt navigation rule via ViewLocator
Navigation in PostIt is owned by src/PostIt/PostIt/ViewLocator.cs.
To open a screen, the caller assigns the target ViewModel to the
host's CurrentViewModel (which binds the IContentControl.Content);
the ViewLocator decides which Control instance to push and resolves
it through DI. ViewModels never instantiate views nor resolve them
from DI directly. Add the rule and a canonical example to
CONTRIBUTING.md so contributors do not re-derive the pattern from
scratch each time.
2026-08-19 15:20:29 +01:00
e35bc273a3
refacto BlogPost 2026-08-19 14:19:45 +01:00
84f3ffa9c2
test(postit): pin inoperative toolbar buttons (ACL, Mes cercles, [DEV] Signature) with headless UI tests
Three buttons on MainPage's toolbar are reported as inoperative
in the running app: ACL, Mes cercles, and [DEV] Signature. They
click but no dialog / page opens.

This commit adds headless UI tests that drive each button via
the Avalonia headless harness (KeyPressQwerty(Enter) on a
focused, x:Name'd button, per the CalculatorTests pattern in
Avalonia.Samples) and asserts the post-click top of
NavRoot.NavigationStack is a non-null Page.

The tests fail today on every button (stack size before == after
== 1): the click does not push anything. The bug is the user's
real complaint — the test is now wired to catch it.

To make the buttons reachable by the harness without walking
the visual tree (which does not see buttons hosted inside a
NavigationPage), name the two unnamed buttons:

- ACL  -> ManageAclButton
- Mes cercles -> OpenCirclesButton

([DEV] Signature was already named OpenSignatureDevButton.)

The XAML change is cosmetic; bindings and commands are
untouched. The test pattern follows SessionStatusBannerTests:
new MainWindow().Show(), PushAsync(MainPage), drive controls via
their generated x:Name fields.
2026-08-18 23:24:08 +01:00
f36679aa65
fix(blog): replace IApplicationUser Author with concrete BlogPostAuthorDto
System.Text.Json cannot materialise an interface without a
polymorphic converter. Until this commit, BlogPostDto.Author
was typed as the abstract interface IApplicationUser, which
crashed the "load posts" call in PostIt whenever the server
returned a post with a populated Author object (the common
case — GET /api/BlogApi).

Fix:

* Introduce a minimum-viable wire DTO BlogPostAuthorDto in
  Yavsc.Abstract.Blogspot (record: Id, UserName, Avatar).
  These are the only fields the client UI actually needs;
  the server-side ApplicationUser navigation is preserved
  for permission checks and authorisation.
* Change IBlogPost.Author and BlogPostDto.Author from
  IApplicationUser to BlogPostAuthorDto? (interface change,
  breaking). The EF entity BlogPost keeps its full
  ApplicationUser navigation property and exposes
  IBlogPost.Author via an explicit interface implementation
  that projects to BlogPostAuthorDto on demand (so EF can
  still lazy-load the navigation without forcing an eager
  join on every read).
* Restore the using directive that was accidentally removed
  when the BlogPostDto property was rewritten (needed for
  ICircleAuthorization in GetACL()).

Regression coverage (the missing test Paul flagged):

* Add BlogPostAuthorDtoTests in PostIt.Tests with four
  scenarios that exercise the wire shape on the client side:
  - A BlogPostDto JSON with a populated Author round-trips
    through JsonSerializer without throwing and the three
    fields (Id, UserName, Avatar) survive intact.
  - A BlogPostDto JSON with explicit "author": null
    deserialises with Author == null.
  - A BlogPostDto JSON without any Author field at all
    deserialises with Author == null (forward compat).
  - The serialised shape of BlogPostAuthorDto uses camelCase
    property names (matching the server's Web defaults), so
    the field names on the wire don't drift without a test
    catching it.

Tests: 55/55 PostIt.Tests (+4 new), 24/24 Yavsc.Blogs.Tests,
44/44 Yavsc.Org.Tests. No regressions.

Side note: yavsc.sln picks up Yavsc.Api.Client (added by
'feat/postit-acl' in 1.0.7 but never registered in the
solution file until now — probably auto-added by a recent
'dotnet build' that discovered the .csproj).
2026-08-18 22:01:09 +01:00
40d992ee18 Merge pull request 'feat/postit-fs' (#37) from feat/postit-fs into release/1.0.8-rc1
Reviewed-on: #37
2026-08-18 21:33:37 +01:00
d245d3972d
ci: retrigger Forgejo Actions on PR #37
All checks were successful
Dotnet build and test / build (pull_request) Successful in 7m48s
PR #37 (feat/postit-fs -> release/1.0.8-rc1) was opened before
the buildAndTest.yml workflow trigger was widened to include
release/*. Forgejo Actions does not re-evaluate the workflow
file on its own — a push event on the PR is needed to
re-trigger the CI. This empty commit is the push.
2026-08-18 21:26:40 +01:00
6695c9ed4d
build and test release/*
Some checks failed
Dotnet build and test / build (pull_request) Has been cancelled
2026-08-18 21:25:06 +01:00
65f6ad8752
cleanup 2026-08-18 21:14:52 +01:00
72d6497455
Merge branch 'release/1.0.8-rc1' into feat/postit-fs2 2026-08-18 19:32:30 +01:00
1ab6e59fe2
chore(release): bump version via gitversion for 1.0.8-rc1 2026-08-18 19:18:36 +01:00
1167169aa8 Merge pull request 'release/1.0.7' (#34) from release/1.0.7 into main
All checks were successful
Dotnet build and test / log-the-inputs (push) Successful in 31s
Dotnet build and test / build (push) Successful in 9m5s
Reviewed-on: #34
2026-08-18 19:05:46 +01:00
03fc898af5
chore(release): add 1.0.7 preview section to CHANGELOG
All checks were successful
Dotnet build and test / log-the-inputs (pull_request) Successful in 14s
Dotnet build and test / build (pull_request) Successful in 10m53s
Forgejo Release / release (push) Successful in 8m42s
1.0.7
The release workflow's validate-release job requires a
'## [TAG] - channel' section in CHANGELOG.md before allowing
the tag to ship. Without this entry, the 1.0.7 tag push
fails the workflow with:

  ::error::No section matching '## [1.0.7]' found in CHANGELOG.md.
  Add a '## [1.0.7] - preview' section before tagging.

The section collects the 35 commits shipped between 1.0.6 and
1.0.7: ACL feature (per-post grants + circle membership), the
Publish toggle that replaces the abandoned Visibility enum,
the make release target, the IYavscApiClient abstraction, the
IContactService/IUserDirectory split, and the Forgejo Actions
release workflow rewrite (bash + jq, runner-provided
GITHUB_TOKEN, .csproj projects built directly inside the
runner container).

The '## [Unreleased]' block is consumed by this section, and
the trailing link reference is updated to point at
1.0.6...1.0.7 for the standard Keep-a-Changelog compare URL.
2026-08-18 18:33:40 +01:00
b613927409
MEF 2026-08-18 18:09:30 +01:00