First Path-B task. Path A landed daily-driver features without a
test runner; Path B is "harden so the next batch of changes can't
silently regress what just shipped." Step 1 is making `pnpm test`
real and gating CI on it.
Test runner:
* Install vitest + @vitest/coverage-v8 at the workspace root.
* Add vitest.config.ts (environment: "node", no JSDOM) + test /
test:watch scripts to packages/shared, packages/database,
packages/ai. Wire `test` into turbo.json with dependsOn: ^build
for future-proofing; add `pnpm test` to root package.json.
Three real tests (no snapshot theater — verified by mutation):
* packages/shared/src/utils/id.test.ts: asserts generateId() matches
the RFC 4122 v4 regex and produces 1000 distinct values. Mutating
generateId() to a constant fails both assertions.
* packages/shared/src/types/objects.test.ts: pins objectTypes and
objectStatuses arrays. These back the zod enum on objects.create
and the "open tasks" count on the workspace-home dashboard; a
silent reorder/rename would otherwise corrupt the dashboard math.
* packages/database/src/markdown-backlog/parse.test.ts: covers
parseBacklogMarkdown across three shapes (well-formed Task,
no-frontmatter Plan with path inference, malformed YAML that
must NOT throw — the importer runs in a file watcher). Plus
hashFileContents determinism.
* packages/ai/src/actions/index.test.ts: five tests across the
prompt builders (summarize/expand/rewrite × 3 tones / translate /
generateFromPrompt). Pure functions; no model mocking needed.
CI:
* .github/workflows/ci.yml runs on pull_request and push to main.
Node 20, pnpm 9 pinned explicitly (per AGENTS.md). Uses
setup-node's built-in pnpm cache. Steps: install --frozen-lockfile,
lint, type-check, test. Concurrency group cancels superseded runs
on non-main branches.
Docs:
* AGENTS.md: drop the "no test runner configured" disclaimer.
Document pnpm test / test:watch. Update the PR-readiness rule
from `pnpm lint && pnpm type-check` to
`pnpm lint && pnpm type-check && pnpm test`.
All 14 tests pass; lint + type-check still green across all 6
packages. The CI workflow's first run is gated on the operator
pushing this branch — that's the only acceptance criterion left
unverified in this commit.
Closes plans/Plan-multitenant-saas-hardening/Epic-test-foundation/
Task-bootstrap-vitest-and-ci.md.
Co-authored-by: Cursor <cursoragent@cursor.com>
Path-A task 3/5. Replaces the setTimeout mock that returned the literal
"Full AI integration is coming soon!" string with a real streaming
provider call.
* apps/web/app/api/chat/route.ts (new): POST handler that runs the
same auth + resolveWorkspace pipeline workspaceProcedure uses, then
streams a response from streamText().toDataStreamResponse(). Maps
resolveWorkspace's TRPCError codes to HTTP status (401/403/404/400).
Returns a structured 503 with a human-readable hint when
OPENAI_API_KEY is unset, so the misconfiguration is surfaced rather
than masked by a fake stream.
* apps/web/app/(app)/[workspaceSlug]/ai/page.tsx: replace the local
message-state + setTimeout placeholder with useChat from
@ai-sdk/react. workspace slug is sent on every request body so the
server can enforce tenant scoping. Adds a ChatErrorBanner that
parses the JSON error body the route emits and renders amber for
the "unavailable" case, destructive for other failures.
* apps/web/package.json: pull in @ai-sdk/react as a direct dep
(previously only transitive via `ai`).
The existing aiRouter.chat tRPC mutation is left intact — it powers
the right-panel command palette via the non-streaming generateText
path, and rebuilding that as streaming was outside the scope of
making the dedicated chat page usable.
Provider selection still flows from env per packages/ai conventions:
OPENAI_API_KEY gates availability, OPENAI_BASE_URL lets operators
route through Ollama on CT 108 transparently, OPENAI_MODEL overrides
the default gpt-4o-mini.
`pnpm lint && pnpm type-check` clean. Closes
plans/Plan-daily-driver-finish/Epic-shipping-the-shell/
Task-wire-ai-chat-to-trpc.md.
Co-authored-by: Cursor <cursoragent@cursor.com>
Path-A first task: get the repo's two repo-wide quality gates passing.
Both were failing from a clean clone in ways that were silently hiding
each other.
Headline fixes:
* apps/web: add an eslint 9 flat config (eslint.config.mjs) using
FlatCompat against next/core-web-vitals + next/typescript, and switch
the `lint` script from `next lint` to `eslint .`. Previously `next
lint` fell into its interactive setup prompt because there was no
config at all in apps/web, which made `pnpm lint` permanently fail
before any rule ever ran.
* packages/shared/src/utils/id.ts: replace `randomUUID` from `node:crypto`
with `globalThis.crypto.randomUUID`. `@tasks/shared` is forbidden from
using Node-only APIs (per AGENTS.md / repo-overview.mdc) because it
has to be importable from the browser bundle.
Adjacent fixes pulled in to make the gates actually green:
* apps/mcp-server/tsconfig.json: drop vestigial rootDir / declaration*
/ outDir / sourceMap (build is via tsup, not tsc emit) and add
allowImportingTsExtensions. The MCP server uses `.ts`-extension
re-export shims (db.ts / schema.ts / shared-types.ts) so tsup can
inline workspace .ts sources into the bundle.
* apps/collab-server/tsconfig.json: same simplification.
* apps/mcp-server/package.json: add @types/node so `process.env` in
packages/database/src/client.ts (transitively pulled into the MCP
server's type-check) resolves.
* apps/web/components/ui/input.tsx: empty `interface InputProps extends
React.InputHTMLAttributes<HTMLInputElement> {}` -> `type` alias.
* apps/web/server/lib/workspace-guard.ts: `from(args.table as any)` ->
`as unknown as PgTable` with a comment. Standard drizzle escape
hatch for structural generic tables.
* apps/web/components/whiteboard/shapes/{document,project,task}-card.tsx:
`BaseBoxShapeUtil<any>` -> `BaseBoxShapeUtil<{Shape}>` plus inline
`declare module "@tldraw/tlschema"` augmentation of
TLGlobalShapePropsMap. Required adding @tldraw/tlschema as a direct
devDep of apps/web so the augmentation target resolves; previously
it was only present transitively under tldraw's own deps.
Result: `pnpm lint && pnpm type-check` exits 0 across all 6 packages.
16 unused-import / exhaustive-deps warnings remain; they're pre-existing
housekeeping and out of scope for this task.
Closes plans/Plan-daily-driver-finish/Epic-shipping-the-shell/
Task-fix-lint-and-shared-types.md (status: done).
Co-authored-by: Cursor <cursoragent@cursor.com>
The collab server was using createRequire() with hardcoded relative paths
(../../../packages/database/package.json, ../node_modules/@hocuspocus/server/...)
to grab `eq` from drizzle-orm and `Forbidden` from @hocuspocus/common. That
worked under tsx in dev but fell apart in the bundled prod image because
those paths don't exist there and pnpm's symlink topology in the runtime
node_modules wasn't reachable from inside the bundled dist file.
Result at runtime: Cannot find module '@hocuspocus/common' on every
collab restart, infinite crash loop.
Switch both to plain ESM imports — tsup bundles them into dist/index.mjs
directly, no runtime resolution needed. Add @hocuspocus/common and
drizzle-orm as explicit deps so they're properly tracked.
Verified locally: bundle now resolves cleanly with no createRequire calls
(actually shrinks from 304 KB to 102 KB after dead-code elimination).
Made-with: Cursor
Two AI components were importing from ../../../../packages/ai/src using
relative paths that escape the workspace root. This worked locally because
all packages are siblings on disk, but failed in Docker where Dockerfile.web
only copies apps/web, packages/database, and packages/shared into the
build context — packages/ai never made it in.
Changes:
- Add @tasks/ai as a workspace dependency in apps/web/package.json
- Switch both imports (command-palette.tsx, ai-block.tsx) to "@tasks/ai"
- Add @tasks/ai to transpilePackages in next.config.ts and the docker variant
- Copy packages/ai into the Docker build context (Dockerfile.web)
- Refresh pnpm-lock.yaml for the new workspace edge
Verified locally: web builds compile cleanly past the previously failing
"Module not found" errors. (Local final step hits an unrelated ENOSPC on
the dev disk; Coolify's volume has plenty of headroom.)
Made-with: Cursor