Skip to content

Commit 8efb82f

Browse files
authored
Merge branch 'main' into feat/admin-only-workspace-creation
2 parents fb8c332 + edbcaa6 commit 8efb82f

61 files changed

Lines changed: 12424 additions & 412 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.env.sample‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
# General URLs
22
KANEO_CLIENT_URL=http://localhost:5173
33
# KANEO_API_URL=http://localhost:1337 # optional - defaults to KANEO_CLIENT_URL/api
4+
# KANEO_INTERNAL_API_URL=http://127.0.0.1:1337 # optional - internal MCP tool requests only
45
# CORS_ORIGINS= # optional - comma-separated; defaults to KANEO_CLIENT_URL
56

67
# Database
Lines changed: 102 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,102 @@
1+
name: Publish PLANKA Import Package
2+
3+
on:
4+
release:
5+
types: [published]
6+
push:
7+
branches: [main]
8+
paths:
9+
- packages/planka-import/package.json
10+
11+
permissions:
12+
contents: write
13+
id-token: write
14+
15+
concurrency:
16+
group: publish-planka-import
17+
cancel-in-progress: false
18+
19+
jobs:
20+
publish:
21+
runs-on: ubuntu-24.04
22+
if: ${{ github.event_name == 'push' || startsWith(github.event.release.tag_name, 'planka-import-v') }}
23+
24+
steps:
25+
- name: Checkout repository
26+
uses: actions/checkout@v7.0.1
27+
with:
28+
persist-credentials: false
29+
30+
- name: Setup pnpm
31+
uses: pnpm/action-setup@v6
32+
with:
33+
version: 10.32.1
34+
35+
# No registry-url here on purpose: it writes an .npmrc referencing
36+
# NODE_AUTH_TOKEN, and npm only attempts the tokenless OIDC exchange when
37+
# no auth is configured. Node 24 is required for npm >= 11.5.1 (OIDC).
38+
- name: Setup Node.js
39+
uses: actions/setup-node@v7
40+
with:
41+
node-version: 24
42+
cache: pnpm
43+
44+
- name: Install dependencies
45+
run: pnpm install --frozen-lockfile
46+
47+
- name: Run PLANKA import checks
48+
run: |
49+
pnpm --filter @kaneo/planka-import test
50+
pnpm --filter @kaneo/planka-import build
51+
52+
- name: Validate PLANKA import release tag
53+
if: ${{ github.event_name == 'release' }}
54+
run: |
55+
PACKAGE_VERSION=$(node -p "require('./packages/planka-import/package.json').version")
56+
TAG_VERSION="${GITHUB_REF_NAME#planka-import-v}"
57+
58+
if [ "${GITHUB_REF_NAME}" = "${TAG_VERSION}" ]; then
59+
echo "Release tag must start with planka-import-v, got ${GITHUB_REF_NAME}"
60+
exit 1
61+
fi
62+
63+
if [ "${TAG_VERSION}" != "${PACKAGE_VERSION}" ]; then
64+
echo "Release tag version (${TAG_VERSION}) does not match packages/planka-import version (${PACKAGE_VERSION})"
65+
exit 1
66+
fi
67+
68+
- name: Check whether @kaneo/planka-import version is already published
69+
id: version_check
70+
run: |
71+
PACKAGE_VERSION=$(node -p "require('./packages/planka-import/package.json').version")
72+
73+
if npm view "@kaneo/planka-import@${PACKAGE_VERSION}" version >/dev/null 2>&1; then
74+
echo "already_published=true" >> "$GITHUB_OUTPUT"
75+
echo "@kaneo/planka-import@${PACKAGE_VERSION} is already published; skipping publish."
76+
else
77+
echo "already_published=false" >> "$GITHUB_OUTPUT"
78+
fi
79+
80+
- name: Publish @kaneo/planka-import
81+
if: ${{ steps.version_check.outputs.already_published == 'false' }}
82+
run: |
83+
cd packages/planka-import
84+
npm publish --access public --provenance
85+
86+
- name: Create PLANKA import release
87+
if: ${{ github.event_name == 'push' }}
88+
run: |
89+
PACKAGE_VERSION=$(node -p "require('./packages/planka-import/package.json').version")
90+
91+
if gh release view "planka-import-v${PACKAGE_VERSION}" --repo "${GITHUB_REPOSITORY}" >/dev/null 2>&1; then
92+
echo "Release planka-import-v${PACKAGE_VERSION} already exists; skipping."
93+
exit 0
94+
fi
95+
96+
gh release create "planka-import-v${PACKAGE_VERSION}" \
97+
--target "${GITHUB_SHA}" \
98+
--title "@kaneo/planka-import v${PACKAGE_VERSION}" \
99+
--notes "Published [@kaneo/planka-import@${PACKAGE_VERSION}](https://www.npmjs.com/package/@kaneo/planka-import/v/${PACKAGE_VERSION}) to npm." \
100+
--latest=false
101+
env:
102+
GH_TOKEN: ${{ github.token }}

‎AGENTS.md‎

Lines changed: 99 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,99 @@
1+
# Kaneo agent guide
2+
3+
Kaneo is a fast, deliberately simple, self-hosted project-management platform. The Hono API owns domain behavior and authorization, the React app consumes its typed client, PostgreSQL stores durable state, and events plus WebSockets keep clients current. Redis is optional and coordinates realtime delivery across multiple API instances.
4+
5+
This is an operating guide, not a README. These rules are good defaults; explicit developer and user instructions take precedence.
6+
7+
## Principles
8+
9+
- Simplicity is a product requirement. Build the smallest model that makes correct behavior obvious.
10+
- Features should solve a real problem without making routine work heavier.
11+
- Protect performance, especially on task-heavy boards and realtime views.
12+
- Keep self-hosting straightforward and single-instance deployments first-class. Do not make Redis or another managed service mandatory without an explicit product decision.
13+
- Support both bundled same-origin deployments and separately hosted API and web deployments.
14+
- Protect user data, workspace boundaries, and authorization checks.
15+
- Read the relevant implementation before changing it. Follow an established local pattern when it fits, but do not preserve accidental complexity merely because it exists.
16+
- Stay focused. Do not mix requested work with speculative features, broad refactors, or unrelated cleanup.
17+
18+
## Architecture
19+
20+
- `apps/api` — Hono API, Better Auth, controllers, database access, events, integrations, MCP HTTP routes, and WebSockets.
21+
- `apps/web` — React/Vite UI, TanStack Router and Query, fetchers, hooks, and realtime cache updates.
22+
- `apps/docs` — product and API documentation content; `apps/site` — public Next.js site and documentation host.
23+
- `packages/libs` — shared typed Hono client and URL helpers.
24+
- `packages/permissions` — canonical permission vocabulary and built-in roles.
25+
- `packages/mcp` — published stdio MCP package.
26+
- `charts/kaneo` — Helm deployment surface.
27+
- `tests/api` contains API unit tests; `tests/api-integration` contains PostgreSQL-backed integration tests.
28+
29+
## Boundaries that must hold
30+
31+
- The API is the authority for authentication and authorization. Hiding an action in the UI is not an authorization check.
32+
- Workspace-scoped operations must use the existing `@kaneo/permissions` vocabulary and API middleware.
33+
- Do not expose secrets, credentials, internal fields, or private workspace data through responses, logs, events, WebSockets, or MCP tools.
34+
- Public API behavior must retain accurate Valibot validation and OpenAPI metadata.
35+
- Mutations that affect realtime state must consider event publication, WebSocket delivery, and client cache invalidation.
36+
- Database changes must work for existing installations, not only empty development databases.
37+
- User-facing web copy must use static i18n keys. `i18n/en-US.json` is the source of truth.
38+
39+
## Follow a change through
40+
41+
Before calling a behavior change complete, decide which surfaces apply:
42+
43+
- API route, validator, controller, authorization, error behavior, and OpenAPI description.
44+
- Typed client, web fetcher, query or mutation hook, cache invalidation, and UI states.
45+
- Events, project- or user-scoped WebSockets, and optional Redis fan-out.
46+
- Permission definitions, API enforcement, and UI capability checks.
47+
- MCP, API keys, webhooks, and relevant external integrations.
48+
- Schema, relations, generated migration, indexes, cascades, and existing data.
49+
- Translations, accessibility, user documentation, Docker, and Helm.
50+
- Reverse states: create/delete, assign/unassign, enable/disable, connect/disconnect, and a visible current state.
51+
52+
Not every change touches every surface. Make the decision deliberately rather than expanding scope automatically.
53+
54+
## Project conventions
55+
56+
- Keep API handlers thin and domain behavior in controllers or focused utilities.
57+
- Validate API inputs with Valibot unless an existing integration requires another library. Use `HTTPException` for expected HTTP failures.
58+
- Use `requireWorkspacePermission` rather than duplicating role checks.
59+
- Use `publishEvent()` when a mutation drives activity, notifications, integrations, or realtime updates.
60+
- Keep web requests in `apps/web/src/fetchers/` and server state in TanStack Query hooks.
61+
- Use the client from `@kaneo/libs`; do not create a parallel untyped request layer.
62+
- Define database schema in `apps/api/src/database/schema.ts` and relations in `apps/api/src/database/relations.ts`.
63+
- Generate migrations with `pnpm --filter @kaneo/api db:generate`, inspect the SQL, and include it with the schema change.
64+
- Prefer inferred TypeScript types and `type` over `interface` unless extension or declaration merging is required.
65+
- Comments should explain constraints or surprising decisions, not narrate code.
66+
67+
## Safety and tooling
68+
69+
- Use pnpm 10.32.1 and Node.js 20.19 or newer. Server environment variables come from the root `.env`; local Vite-only overrides belong in `apps/web/.env.local`. See `ENVIRONMENT_SETUP.md`.
70+
- Never use production databases, storage, or credentials for development or tests.
71+
- Preserve unrelated work in a dirty worktree. Do not delete data or generated files unless the task requires it and the target is verified.
72+
- Track processes you start and stop only those processes; never kill by broad name or path patterns.
73+
- The root and package `lint` scripts run Biome with `--write` and can modify unrelated files. Prefer targeted checks while iterating and inspect formatter changes.
74+
- Do not commit, push, or open a pull request unless explicitly requested.
75+
76+
## Verification
77+
78+
Use the smallest proof that covers the changed behavior, then broaden it when the blast radius requires it.
79+
80+
- Utility or UI logic: focused unit/component tests and the affected package typecheck.
81+
- API behavior: focused API tests; use integration tests when routing, authentication, authorization, or PostgreSQL behavior matters.
82+
- Database changes: relevant integration tests and migration inspection.
83+
- Cross-package contracts: typecheck or build all affected consumers.
84+
- Realtime changes: verify the event-to-WebSocket-to-cache path and consider both in-memory and Redis delivery.
85+
- Deployment changes: validate the affected Docker, Helm, or startup path.
86+
- User-visible flows: use a real browser pass when requested or when it is the only meaningful proof.
87+
88+
Run repository-wide checks when a change crosses packages broadly, before a requested commit or pull request, or when explicitly asked. Report what ran and what did not.
89+
90+
## Glossary
91+
92+
- **instance**: one deployed Kaneo installation.
93+
- **workspace**: the top-level collaboration and authorization boundary.
94+
- **project**: a task container inside a workspace.
95+
- **role**: a workspace-scoped set of permission statements.
96+
- **activity**: durable, user-visible history.
97+
- **event**: an internal notification used by activity, integrations, notifications, or realtime updates.
98+
99+
Update this guide only for recurring, observed failure modes. Put narrow workflows in skills or dedicated documentation.

‎CHANGELOG.md‎

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,47 @@
1+
## [2.17.6](https://github.com/usekaneo/kaneo/compare/v2.17.5...v2.17.6) (2026-08-11)
2+
3+
4+
### Bug Fixes
5+
6+
* **planka-import:** explain unmatched assignees, keep dependencies, attribute comments ([15f6868](https://github.com/usekaneo/kaneo/commit/15f68683620b5fcfbed7970b77210b7cc706f74b))
7+
## [2.17.5](https://github.com/usekaneo/kaneo/compare/v2.17.4...v2.17.5) (2026-08-11)
8+
9+
10+
### Bug Fixes
11+
12+
* **billing:** send one trial reminder per owner, not per workspace ([ae2e579](https://github.com/usekaneo/kaneo/commit/ae2e57919d4703b4fcb2e4452b2c7b171abedd97))
13+
## [2.17.4](https://github.com/usekaneo/kaneo/compare/v2.17.3...v2.17.4) (2026-08-11)
14+
15+
16+
### Bug Fixes
17+
18+
* **billing:** throttle trial reminders so they cannot exhaust the quota ([c4150a8](https://github.com/usekaneo/kaneo/commit/c4150a89f826ce5a4f7bbf24346c313b7fd2c5d4))
19+
## [2.17.3](https://github.com/usekaneo/kaneo/compare/v2.17.2...v2.17.3) (2026-08-11)
20+
21+
22+
### Bug Fixes
23+
24+
* **planka-import:** default to the real Kaneo Cloud host ([3863eb6](https://github.com/usekaneo/kaneo/commit/3863eb6ba1d5a6ec9833e4b4a383cffc3fa10fff))
25+
26+
27+
### Features
28+
29+
* **billing:** email trial reminders before and after expiry ([0e481a9](https://github.com/usekaneo/kaneo/commit/0e481a9c8223f36b03a35ad0cbb7456af99466d9))
30+
## [2.17.2](https://github.com/usekaneo/kaneo/compare/v2.17.1...v2.17.2) (2026-08-11)
31+
32+
33+
### Bug Fixes
34+
35+
* **auth:** resolve the client IP behind multiple proxy hops ([9e8a448](https://github.com/usekaneo/kaneo/commit/9e8a44835768a70d6d2f68dc3e1add53e90bbc10))
36+
* **billing:** grant the trial once per owner, not per workspace ([14adb9d](https://github.com/usekaneo/kaneo/commit/14adb9dfd8af0d0dbe5951d0994d1bcf0fcdf8b1))
37+
* use internal URL for MCP tool requests ([#1556](https://github.com/usekaneo/kaneo/issues/1556)) ([7d9d9d2](https://github.com/usekaneo/kaneo/commit/7d9d9d212d13e98e9aa3d84c0179f4a49384b9fc))
38+
39+
40+
### Features
41+
42+
* **planka-import:** add PLANKA to Kaneo migration CLI ([5c91feb](https://github.com/usekaneo/kaneo/commit/5c91febedf4e2cbb356c451676d4df3ae2acc6fa))
43+
* **planka-import:** authenticate with a PLANKA API key ([ff5e3fc](https://github.com/usekaneo/kaneo/commit/ff5e3fc6b91ae351c6002fb358d75265a0435dbd))
44+
* **site:** add PLANKA comparison page ([579a975](https://github.com/usekaneo/kaneo/commit/579a9752f7775e9239680053a6ed68d437d90e36))
145
## [2.17.1](https://github.com/usekaneo/kaneo/compare/v2.17.0...v2.17.1) (2026-08-10)
246

347

0 commit comments

Comments
 (0)