Merge krystie-improvements into main
Resolves 24 conflicts between Hermes (DC-008/009/010 + response-helper
envelope standardization) and Krystie (DC-005 src/ refactor path fixes,
DC-006 TOTP integration, DC-007 new test suites, cloud backup
destinations).
Conflict resolutions:
- src/utils/logging.js: took ours (consumers depend on logError/
safeErrorMessage/createLogger exports)
- src/config/site.js: merged (her factored validateAndLogConfig +
applyConfigFields helpers)
- src/context/dns.js: took hers (admin/readonly role iteration for
write operations)
- src/utilities/backup-
manager.js: took hers (Dropbox/WebDAV/SFTP cloud feature)
- status/dist/*, status/
sw.js: took hers (minified bundles + newer SW cache)
Additional fix (post-merge regression):
- src/monitoring/health-checker.js: fixed DC-005 path miss —
'require(./platform-paths)' → 'require(../../platform-paths)'
Test status: 921/922 passing. One known failure in logging.test.js
(async file-handle timing) tracked as follow-up.
This commit is contained in:
@@ -39,6 +39,33 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
- Stale root-level files: `*.bak`, `server-old.js`, and ad-hoc reports (`DEPLOYMENT-SUCCESS.md`, `FINAL-DEPLOYMENT-REPORT.md`, `DESLOPIFICATION-ROADMAP.md`, etc.) — disk-only cleanup, already gitignored.
|
||||
- Dead `routes/` directory at API root (replaced by `src/routes/`).
|
||||
|
||||
### Security (TOTP integration)
|
||||
- TOTP integration tests now cover the full `/api/auth/check` → session → endpoint flow (DC-006). 25 new tests including: `setup` (generate + normalize + reject invalid Base32), `verify-setup` (missing/bad/no-pending/valid-code paths), `verify` login (400/400/401/200), `check-session` (passthrough when disabled + 401 no-session + 200 valid-session), `disable`, `config` (valid/invalid/never-disables), and full end-to-end setup→login→check-session→disable.
|
||||
|
||||
### Fixed (from merge)
|
||||
- **routes/updates.js** — krystie's branch had `if (!ok)` referencing the helper function instead of the `secretOk` boolean. Would have 500'd every `/system/update-notify` request. Caught during merge, kept my version with the correct boolean check.
|
||||
- **routes/notifications.js** — two places where she replaced `res.json({success: result.success, ...})` with `ok(...)` would have forced `success: true` for partial-failure delivery. Kept my version with explicit `res.json` to preserve the semantic.
|
||||
|
||||
## [1.13.4] - 2026-06-12
|
||||
|
||||
### Changed
|
||||
- Standardized all route handler responses to use helpers from `src/utils/responses.js`
|
||||
(`ok`, `errorResponse`, `successMessage`, `notFound`, `validationError`, `forbidden`,
|
||||
`unauthorized`, `conflict`). ~160 raw `res.json()` calls converted across 32+ files.
|
||||
No behavior changes — response shapes are identical. This ensures future schema
|
||||
changes (e.g., adding a `requestId` envelope) only need to update one module.
|
||||
- Fixed `error` vs `errorResponse` signature mismatch in `routes/health.js` CA cert
|
||||
endpoint. The `error` helper takes `(res, message, statusCode)` while `errorResponse`
|
||||
takes `(res, statusCode, message, extras)` — the wrong alias was being used for
|
||||
calls that needed the 4-argument form.
|
||||
- Updated `middleware.js`, `csrf-protection.js`, `error-handler.js`, and
|
||||
`license-manager.js` to use response helpers for rejection/error responses
|
||||
instead of inline `res.status().json()`.
|
||||
|
||||
### Note
|
||||
- 4 pre-existing test failures in `services.routes.test.js` (credential storage)
|
||||
remain from before this release. They are unrelated to the standardization pass.
|
||||
|
||||
## [1.5.0] - 2026-05-17
|
||||
|
||||
### Changed (BREAKING)
|
||||
|
||||
Reference in New Issue
Block a user