Read-side only — write paths land with claim_task / complete_task
in the next epic. Keyset pagination on started_at, three procedures
(listRecent, listForTask, summary), and a /settings/runs view that
mirrors the audit page's visual language.
Co-authored-by: Cursor <cursoragent@cursor.com>
Soft-delete cascade was the missing half of archive: stamping
workspaces.archived_at alone left objects visible to anyone with a
direct id. The cascade runs in one transaction so the partial state
isn't reachable, and restore inverts it for any archived row in the
workspace — provenance-blind on purpose until we have a use case
that needs to distinguish per-workspace from per-object archives.
audit_log keeps the keyset index on (workspace_id, created_at) and
the actor_user_id FK with onDelete set null. recordAudit() refuses
to write a null actor without a metadata.system_actor label so the
audit view always has something to render. workspaces and invites
mutations call recordAudit on success; objects-router instrumentation
and the markdown importer's system-actor flow are filed as P2
follow-ups because each needs a thoughtful "what's audit-worthy?"
pass, not mechanical wiring.
Settings → Audit log lives at /<slug>/settings/audit, owner-gated,
keyset-paginated. ACTION_LABELS is small on purpose; new actions
fall back to their raw key so missing a label degrades gracefully.
Co-authored-by: Cursor <cursoragent@cursor.com>
Schema half of Task-workspace-invites-and-roles. Lands the table, the
invites router (create/list/revoke/accept), and the two new workspaces
procedures (updateMemberRole/removeMember). UI ships in part 2/2.
This is a stable checkpoint for Task 3 (invite-recipient-autocomplete)
to start building against — the procedure surface area is frozen and the
new identity helper from Task 1 is in the accept path.
Schema:
* workspace_invites: id, workspace_id, email (lowercased), role
(owner/admin/member), invited_by_user_id, token (base64url 32B),
expires_at (DEFAULT now() + 14d), accepted_at, revoked_at, created_at.
* Indexes: workspace_id, UNIQUE(token), and a PARTIAL UNIQUE on
(workspace_id, email) WHERE accepted_at IS NULL AND revoked_at IS NULL.
An open invite is unique per (workspace, email); closed invites
(accepted or revoked) fall out of the constraint so re-invites work.
* Drizzle relations wired: workspaceInvites.workspace,
workspaceInvites.invitedBy, workspaces.invites.
* Migration 0006_broad_lethal_legion applied to dev DB.
invites router:
* create({email, role}) on workspaceProcedure (owner/admin only).
Generates a base64url token from 32 random bytes via node:crypto.
Idempotent on (workspace, email) — if an open invite already exists,
returns it instead of inserting (the partial unique would block it
anyway). Refuses self-invite. Refuses if the email is already a
member.
* list() returns pending (non-accepted, non-revoked) invites with
inviter name/email joined for UI display.
* revoke({inviteId}) authorizes against the invite's workspace, not
the caller's input (the inviteId carries its own tenant scope).
* accept({token}) is protectedProcedure (no workspace handle). Calls
userOwnsEmail() from Task 1 — if the caller doesn't own the invited
email under any of their verified identities, throws FORBIDDEN with
a structured cause ({reason: "email_not_owned", invitedEmail}) so
the redeem page can render the "link this email" explainer. Handles
expiry, revoked, already-accepted states with clear messages.
Idempotent on existing membership — if you've already been added by
another flow, accept just closes the invite without re-inserting.
workspaces additions:
* updateMemberRole: admin/owner only. Three guards:
1. Can't change your own role (avoids accidental lockout).
2. Can't demote the only owner-role member (would leave the
membership-level ownership empty even though workspaces.owner_user_id
still points there — see ADR-pragmatic decision documented in the
Task-multi-email-identity convoy discussion).
3. Only owners can promote to owner; admins move people between
admin/member but cannot create a new owner.
* removeMember: admin/owner OR self (the leave-workspace affordance).
Same last-owner guard. Admins can't remove owners (only owners can,
via demote-then-remove).
Wired both new routers into root.ts as `invites` and `identity`
(identity was landed in Task 1; this commit just keeps the registration
visible alongside invites).
All three CI gates green: 0 lint errors, 14 unchanged warnings, 6/6
type-check, 14/14 tests (no new tests yet — apps/web vitest harness is
filed as Task-bootstrap-vitest-for-apps-web P2).
Co-authored-by: Cursor <cursoragent@cursor.com>
First half of Task-multi-email-identity. Lays down everything except the
NextAuth callback wiring, which is gated on a research subagent finishing
its survey of OAuth provider behavior for the email_verified claim
across GitHub, Google, and Authentik.
Schema (packages/database):
* New user_email_identities table colocated with `users` in users.ts.
Columns: id, user_id (FK), email (lowercased), verified_at, source,
created_at, last_used_at.
* Indexes: user_id, email, unique(user_id, email), and a PARTIAL unique
index on email WHERE verified_at IS NOT NULL — a verified email
resolves to exactly one users row globally, while unverified rows
(none today; placeholder for the manual-verification follow-up) do
not share the constraint.
* Drizzle relation: users.emailIdentities -> userEmailIdentities, and
the inverse one(users) relation.
* Migration 0005 generated by db:generate, augmented with a backfill
INSERT that seeds one source='primary' identity per existing users
row using created_at as verified_at. Migration applied to dev DB;
existing admin@tasks.dev user verified as 1:1 mapped.
Server (apps/web/server):
* apps/web/server/lib/identity.ts exports two pure read helpers:
- userOwnsEmail(userId, email): boolean used by the (upcoming)
invite-accept procedure to verify the human controls the invited
address under any of their linked identities.
- findUserIdByVerifiedEmail(email): the replacement for the old
ensureUserIdByEmail lookup. Will be called from auth.ts once the
OAuth research subagent returns.
* apps/web/server/routers/identity.ts exposes identity.listMine — a
protected procedure returning the caller's identities ordered by
verifiedAt desc. Cross-user identity surface is intentionally NOT
exposed here; that lives behind the workspace-scoped autocomplete
in Task 3 with its own tenancy fence.
UI (apps/web/app):
* New route /[workspaceSlug]/settings/profile renders a read-only
"Linked emails" section with per-identity row (email, source badge,
verified state, last-used relative time) plus a hint that explains
how to add another email (sign in via that email's OAuth provider).
* Empty / loading / error states all handled. The "no identities"
branch should never fire post-backfill but renders a friendly
message instead of throwing.
What's NOT in this commit:
* auth.ts changes (ensureUserIdByEmail -> ensureUserIdByVerifiedEmail,
OAuth callback identity upsert, cross-user conflict rejection).
Waiting on subagent research to land the callback wiring correctly
on the first try across all three providers.
* Vitest tests. The pure helpers are 10-line query shims and the
behavior-relevant assertion is the auth callback path — easier to
write meaningful tests once that lands.
All three CI gates green: pnpm lint (14 pre-existing warnings,
unchanged), pnpm type-check (6/6 packages), pnpm test (14/14
existing tests across @tasks/shared, @tasks/database, @tasks/ai).
Co-authored-by: Cursor <cursoragent@cursor.com>
Three pieces of authentication work that need to land together so OAuth
sign-ins produce a usable session.
* `ensureUserIdByEmail` upserts a `users` row on every OAuth sign-in
matched case-insensitively on email, then stamps `token.id` with the
resulting UUID so workspace-scoped tRPC procedures can resolve
membership. Credentials sign-in already returned the DB id from
`authorize`; OAuth now does the equivalent.
* `ensureUserHasWorkspace` mints a personal workspace (and `owner`
member row) on first sign-in for any user that doesn't already
belong to one, so fresh OAuth accounts don't land in the app with
no tenant scope. Idempotent; slug collisions retry with a random
suffix and cap at 5 attempts.
* Migration 0004 adds a `UNIQUE (lower(email))` index on `users` to
match the lookup pattern and prevent two providers from minting
rows that differ only in casing. Existing rows are normalized to
lowercase first; the column-level UNIQUE catches any pre-existing
duplicates so they get resolved by a human rather than silently
merged.
Sign-in / sign-up pages add an Authentik SSO button (gated on
`AUTH_AUTHENTIK_*` env vars). Layout switches to GitHub+Google on top
with Authentik full-width below.
Co-authored-by: Cursor <cursoragent@cursor.com>
Block A of the EchoDo plan. Workspaces used to live as `objects(type='workspace')`,
which made it impossible to put a real RLS-friendly tenant boundary on the schema
or to give each workspace a stable URL slug. This commit:
- Adds a top-level `workspaces` table (slug unique, owner FK, plan_tier hook).
- Migrates the 8 anchor tables (objects, workspace_members, object_type_defs,
property_definitions, templates, forms, markdown_backlog_items,
cursor_sync_mappings) to FK into `workspaces.id` instead of `objects.id`,
with a hand-augmented data-copy migration that preserves IDs and slug-collision-
proofs on backfill.
- Introduces a `workspaceProcedure` tRPC middleware + `resolveWorkspace` helper
that take a UUID-or-slug `workspace` handle and expose `ctx.workspace`. All
tenant-scoped routers (objects, types, properties, templates, forms, search,
ai, relations, favorites) now flow through it.
- Updates the web app to pass `workspace` slugs from the URL (or store) instead
of the old `workspaceId`, including a workspace-sync layer that rewrites
/<UUID>/... links to /<slug>/...
- Updates the MCP tools (list_objects, create_object, search_objects) and the
workspace://{handle}/tree resource to accept either a slug or UUID so existing
agents keep working.
- Adds a Create Workspace dialog and a Workspace Settings page (rename + slug
rename with redirect, owner-only archive).
Verified locally against a fresh Postgres: migration applies cleanly, slug
uniqueness holds, tenant data is isolated by workspace_id, slug↔UUID resolution
works in both directions, and ON DELETE CASCADE cleans up child rows in the
correct workspace only.
Co-authored-by: Cursor <cursoragent@cursor.com>