feat: ECHODO app shell, Coolify deploy, Authentik + Umami
Bundles in-flight ECHODO work with the Coolify deployment configuration:
App
- New routes: ai, forms, planner, settings (templates/types), teams,
doc detail, whiteboard detail
- New components: app shell rework (icon-rail, top-header), forms
builder/renderer/responses, types manager, objects creation dialog,
card primitive, form + overview views
- New tRPC routers: favorites, forms, types, workspaces; updates to
health and objects routers
- Markdown backlog sync (packages/database) + cursor-sync schema/migrations
- Schema additions: forms, types, favorites, markdown_backlog, cursor_sync
- Initial Drizzle migrations checked in
Deployment
- docker/docker-compose.coolify.yml: drops bundled Postgres/Redis
(uses CT 102 shared services), removes host port mappings, adds
Coolify SERVICE_FQDN_* magic vars for web + collab
- .env.example rewritten as the full ECHODO/Coolify variable manifest
- NextAuth gains an Authentik OIDC provider (gated on env presence)
- Root layout injects Umami tracking script when configured;
metadata title flipped to ECHODO
Security
- .gitignore expanded to exclude AGENT-DEPLOY.md, .env.*, secrets/,
credentials.*, *.key, *.crt, *.pem, ssh keys
Made-with: Cursor
2026-04-26 15:34:34 -04:00
|
|
|
{
|
|
|
|
|
"version": "7",
|
|
|
|
|
"dialect": "postgresql",
|
|
|
|
|
"entries": [
|
|
|
|
|
{
|
|
|
|
|
"idx": 0,
|
|
|
|
|
"version": "7",
|
|
|
|
|
"when": 1774617985473,
|
|
|
|
|
"tag": "0000_nervous_ogun",
|
|
|
|
|
"breakpoints": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"idx": 1,
|
|
|
|
|
"version": "7",
|
|
|
|
|
"when": 1774632231368,
|
|
|
|
|
"tag": "0001_parched_red_hulk",
|
|
|
|
|
"breakpoints": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"idx": 2,
|
|
|
|
|
"version": "7",
|
|
|
|
|
"when": 1777225115319,
|
|
|
|
|
"tag": "0002_markdown_backlog_cursor_sync",
|
|
|
|
|
"breakpoints": true
|
multi-tenancy: promote workspaces to top-level table
Block A of the EchoDo plan. Workspaces used to live as `objects(type='workspace')`,
which made it impossible to put a real RLS-friendly tenant boundary on the schema
or to give each workspace a stable URL slug. This commit:
- Adds a top-level `workspaces` table (slug unique, owner FK, plan_tier hook).
- Migrates the 8 anchor tables (objects, workspace_members, object_type_defs,
property_definitions, templates, forms, markdown_backlog_items,
cursor_sync_mappings) to FK into `workspaces.id` instead of `objects.id`,
with a hand-augmented data-copy migration that preserves IDs and slug-collision-
proofs on backfill.
- Introduces a `workspaceProcedure` tRPC middleware + `resolveWorkspace` helper
that take a UUID-or-slug `workspace` handle and expose `ctx.workspace`. All
tenant-scoped routers (objects, types, properties, templates, forms, search,
ai, relations, favorites) now flow through it.
- Updates the web app to pass `workspace` slugs from the URL (or store) instead
of the old `workspaceId`, including a workspace-sync layer that rewrites
/<UUID>/... links to /<slug>/...
- Updates the MCP tools (list_objects, create_object, search_objects) and the
workspace://{handle}/tree resource to accept either a slug or UUID so existing
agents keep working.
- Adds a Create Workspace dialog and a Workspace Settings page (rename + slug
rename with redirect, owner-only archive).
Verified locally against a fresh Postgres: migration applies cleanly, slug
uniqueness holds, tenant data is isolated by workspace_id, slug↔UUID resolution
works in both directions, and ON DELETE CASCADE cleans up child rows in the
correct workspace only.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-07 00:02:55 -04:00
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"idx": 3,
|
|
|
|
|
"version": "7",
|
|
|
|
|
"when": 1778124738113,
|
|
|
|
|
"tag": "0003_damp_green_goblin",
|
|
|
|
|
"breakpoints": true
|
2026-06-02 00:45:00 -04:00
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"idx": 4,
|
|
|
|
|
"version": "7",
|
|
|
|
|
"when": 1779987416637,
|
|
|
|
|
"tag": "0004_medical_blob",
|
|
|
|
|
"breakpoints": true
|
feat(identity): schema + helpers + read-only profile UI (Task 1, part 1/2)
First half of Task-multi-email-identity. Lays down everything except the
NextAuth callback wiring, which is gated on a research subagent finishing
its survey of OAuth provider behavior for the email_verified claim
across GitHub, Google, and Authentik.
Schema (packages/database):
* New user_email_identities table colocated with `users` in users.ts.
Columns: id, user_id (FK), email (lowercased), verified_at, source,
created_at, last_used_at.
* Indexes: user_id, email, unique(user_id, email), and a PARTIAL unique
index on email WHERE verified_at IS NOT NULL — a verified email
resolves to exactly one users row globally, while unverified rows
(none today; placeholder for the manual-verification follow-up) do
not share the constraint.
* Drizzle relation: users.emailIdentities -> userEmailIdentities, and
the inverse one(users) relation.
* Migration 0005 generated by db:generate, augmented with a backfill
INSERT that seeds one source='primary' identity per existing users
row using created_at as verified_at. Migration applied to dev DB;
existing admin@tasks.dev user verified as 1:1 mapped.
Server (apps/web/server):
* apps/web/server/lib/identity.ts exports two pure read helpers:
- userOwnsEmail(userId, email): boolean used by the (upcoming)
invite-accept procedure to verify the human controls the invited
address under any of their linked identities.
- findUserIdByVerifiedEmail(email): the replacement for the old
ensureUserIdByEmail lookup. Will be called from auth.ts once the
OAuth research subagent returns.
* apps/web/server/routers/identity.ts exposes identity.listMine — a
protected procedure returning the caller's identities ordered by
verifiedAt desc. Cross-user identity surface is intentionally NOT
exposed here; that lives behind the workspace-scoped autocomplete
in Task 3 with its own tenancy fence.
UI (apps/web/app):
* New route /[workspaceSlug]/settings/profile renders a read-only
"Linked emails" section with per-identity row (email, source badge,
verified state, last-used relative time) plus a hint that explains
how to add another email (sign in via that email's OAuth provider).
* Empty / loading / error states all handled. The "no identities"
branch should never fire post-backfill but renders a friendly
message instead of throwing.
What's NOT in this commit:
* auth.ts changes (ensureUserIdByEmail -> ensureUserIdByVerifiedEmail,
OAuth callback identity upsert, cross-user conflict rejection).
Waiting on subagent research to land the callback wiring correctly
on the first try across all three providers.
* Vitest tests. The pure helpers are 10-line query shims and the
behavior-relevant assertion is the auth callback path — easier to
write meaningful tests once that lands.
All three CI gates green: pnpm lint (14 pre-existing warnings,
unchanged), pnpm type-check (6/6 packages), pnpm test (14/14
existing tests across @tasks/shared, @tasks/database, @tasks/ai).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-02 11:07:50 -04:00
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"idx": 5,
|
|
|
|
|
"version": "7",
|
|
|
|
|
"when": 1780412597413,
|
|
|
|
|
"tag": "0005_cooing_midnight",
|
|
|
|
|
"breakpoints": true
|
feat: ECHODO app shell, Coolify deploy, Authentik + Umami
Bundles in-flight ECHODO work with the Coolify deployment configuration:
App
- New routes: ai, forms, planner, settings (templates/types), teams,
doc detail, whiteboard detail
- New components: app shell rework (icon-rail, top-header), forms
builder/renderer/responses, types manager, objects creation dialog,
card primitive, form + overview views
- New tRPC routers: favorites, forms, types, workspaces; updates to
health and objects routers
- Markdown backlog sync (packages/database) + cursor-sync schema/migrations
- Schema additions: forms, types, favorites, markdown_backlog, cursor_sync
- Initial Drizzle migrations checked in
Deployment
- docker/docker-compose.coolify.yml: drops bundled Postgres/Redis
(uses CT 102 shared services), removes host port mappings, adds
Coolify SERVICE_FQDN_* magic vars for web + collab
- .env.example rewritten as the full ECHODO/Coolify variable manifest
- NextAuth gains an Authentik OIDC provider (gated on env presence)
- Root layout injects Umami tracking script when configured;
metadata title flipped to ECHODO
Security
- .gitignore expanded to exclude AGENT-DEPLOY.md, .env.*, secrets/,
credentials.*, *.key, *.crt, *.pem, ssh keys
Made-with: Cursor
2026-04-26 15:34:34 -04:00
|
|
|
}
|
|
|
|
|
]
|
|
|
|
|
}
|