| feat: dev issue list & kankan | 3 个月前 |
| docs: add contributing guide, issue/PR templates, and good-first list Give newcomers a clear path to run the app, claim starter tasks, and open focused PRs for open-source collaboration. Co-authored-by: Cursor <cursoragent@cursor.com> | 3 天前 |
| fix(agent): reject illegal state suggestions and retry unsubmitted ones Found while testing triage from the issue page: - suggest_issue_changes now checks a proposed state against the issue's workflow, drops illegal ones and tells the agent the legal targets, so it can correct itself instead of the user hitting a skipped apply. - When a reply describes one-click suggestions that were never recorded, the agent gets one more turn to actually submit them; the notice stays as the last resort. - Agent capability chips show category labels instead of raw tool names. Co-authored-by: Cursor <cursoragent@cursor.com> | 1 天前 |
| docs: mark V2EX reply as posted Co-authored-by: Cursor <cursoragent@cursor.com> | 1 天前 |
| fix(agent): reject illegal state suggestions and retry unsubmitted ones Found while testing triage from the issue page: - suggest_issue_changes now checks a proposed state against the issue's workflow, drops illegal ones and tells the agent the legal targets, so it can correct itself instead of the user hitting a skipped apply. - When a reply describes one-click suggestions that were never recorded, the agent gets one more turn to actually submit them; the notice stays as the last resort. - Agent capability chips show category labels instead of raw tool names. Co-authored-by: Cursor <cursoragent@cursor.com> | 1 天前 |
| docs: add GitCode hub promo checklist and paste kit Point CN promotion ops at GitCode welcome/GFI/dynamic steps; keep external channels paused. Co-authored-by: Cursor <cursoragent@cursor.com> | 3 天前 |
| feat(ai-connect): one-click Cursor/Claude Code setup, PR write-back and link_pull_request MCP tool - Workspace settings: create a PAT, copy MCP snippets or install via Cursor deeplink, test the connection, token usage status and revoke - GitHub PR webhooks link issues by key in title/branch/body, complete them on merge (idempotent) and comment deep links back on the PR - Manual PR linking from the issue Git tab and the new link_pull_request MCP tool - resolveIssueCode looks up by sequence_id first so KEY-N resolves reliably Co-authored-by: Cursor <cursoragent@cursor.com> | 1 天前 |
| test(e2e): full-product E2E coverage run; fix 20 test defects + 2 product bugs Full end-to-end coverage run across the product. tests/ now passes 361/361 (was 302 passed / 41 failed / 17 not run); frontend/e2e exercised on all three browser projects; backend go test and frontend vitest fully green. Product fixes - Project.vue: ?tab=settings|pages|dashboards deep links rendered a blank content area. The redirect lived in a non-immediate watcher on activeTab, which never fires when the tab is seeded from the query, and there is no template block for those tab ids. projectId is a ref(0) filled in onMounted, so the fix is a once-on-projectId watcher placed after its declaration (an immediate:true watcher would redirect to /project/0/...). - project_settings_service.go: DeleteWorkspaceState returned 500 when the workspace had no default state. Skip the issue migration instead of failing. Test fixes (tests/, 13 files / 20 cases) - all confirmed test-side defects - interactions hitting elements behind the IssueDetailPanel overlay: scope to the panel / confirm dialog and bound the clicks, so a blocked click fails fast instead of burning the 60s test timeout - deterministic beforeEach readiness gates, replacing fixed sleeps plus if(isVisible) guards that silently skipped the precondition and made every following assertion fail with an inscrutable error - submit-button label mismatch: forms use t('common.create') = the Chinese word for "create", the specs were clicking "save/confirm" and matched nothing - wrong route for workflows (?tab=workflows is not a Project.vue tab) - strict-mode violations from multi-match locators missing .first() - unique comment text per run instead of a fixed accumulating string Tooling - tests/ and frontend/ playwright configs: actionTimeout / navigationTimeout - frontend/vite.config.ts: preview proxy config plus a proxy error handler (an upstream ECONNREFUSED used to kill the preview process outright) - new tests/14-ai-agent/run-detail.spec.ts covering the two previously uncovered agent run-detail routes (7 cases, all passing) - new scripts: fix-invalid-text-locators.mjs, e2e-coverage-report.mjs, run-full-e2e.ps1; .gitignore covers E2E run artifacts Docs - E2E_COVERAGE_REPORT.md: coverage matrix, per-class failure analysis, product findings, follow-up recommendations - docs/bug-list.md: BUG-46..49 | 16 天前 |
| feat: 全面测试 + 多特性完善 测试: - 新增 Go 后端单元测试: common (100%覆盖), i18n (94%覆盖) - 新增前端 Vitest 测试: auth store (11), API 模块 (14) - 修复 Bug: ErrAlreadyAssigned/ErrAlreadyLabelled 返回 500 改为 409 - 修复 vitest.config.ts 配置,不再包含 Playwright 测试 - API 集成冒烟测试 51/53 通过 (96%) - 全面测试报告 TEST_REPORT.md 特性: - Agent/MCP/GitHub/Slack 集成 - AI Sprint Planning + SSE 实时通知 - 前后端多语言 (i18n) - 自动化规则 (Automation Rule) - Initiatives 高层级目标 - Project Page Tabs 配置 - Dark Mode 暗色模式 基础设施: - Docker 容器化部署 - MCP Server (14 tools) - E2E Playwright 测试 (5 specs) Co-Authored-By: vinthuy@qq.com | 3 个月前 |
| fix(pm): ship workspace workflows and core customization QA gate Implement workspace state-machine workflow CRUD (fixes 501), harden Analytics/IssueDetail, Stage B agent hide, and mark product-core acceptance PASS including types/fields/workflows/automations. Co-authored-by: Cursor <cursoragent@cursor.com> | 3 天前 |
| fix: final review wave — warn on plaintext remote MCP HTTP, e2e hardening, repo hygiene | 22 天前 |
| docs: scrub third-party product names from docs and comments Remove competitor brand references to avoid trademark/copyright confusion; keep product narrative focused on ReqMango AI project management. Co-authored-by: Cursor <cursoragent@cursor.com> | 3 天前 |
| security(go): enable gosec, close token-leak paths, fix CI; all frontend/e2e green Security (backend) - Enable gosec + bodyclose via .golangci.yml; migrate to golangci-lint v2.13.2 (v1.x refuses to analyse a go 1.25 module). 355 lint findings -> 0. - Tokens can no longer leak through code: * access log no longer writes SSE ?token= query values (RedactQuery, with a middleware-level regression test) * webhook URLs (Slack/GitHub embed credentials in the path) and response bodies are masked/truncated before logging * SECRET_KEY no longer falls back to the public "change-me-in-production": a random per-process key is generated with a loud warning; docs/compose/env example require a real value, and the unreferenced config.yaml was deleted * RQL executor no longer prints SQL + arguments on every query * uploads dir 0750 + sanitized extension, worktree names validated, Slack webhook restricted to https://hooks.slack.com - Fix vulnerabilities reachable from this module (govulncheck 3 -> 0): golang-jwt/jwt v5.2.2, jackc/pgx v5.9.2 (SQL injection GO-2026-5004), golang.org/x/text v0.39.0. Real bugs found by the new linters - skill_executor: regexes used Perl lookahead (unsupported by RE2) -> MustCompile panicked, so SKILL.md parsing was broken - conditional fields: numeric ids were converted with string(rune(id)), so type/state/assignee/label conditions could never match - workflow_service: Delete/DeleteNode/DeleteEdge used Delete(&struct{}{}), which produced DELETE FROM "" (SQLSTATE 42601) -> every workflow delete returned 500 - seed release indexing, budget alert message, swallowed JSON bind error, dead code CI - golangci-lint-action@v9 (pinned linter v2.13.2), GO_VERSION 1.25 (+ Dockerfile), @vitest/coverage-v8 added so vitest run --coverage works, ESLint step replaced by a real vue-tsc --noEmit check, new Security job: gitleaks (blocking, .gitleaks.toml) + govulncheck (advisory) frontend/e2e: 91 failures -> 0 - automation specs rewritten against the real AutomationRuleBuilder and the dot-notation event names the bus actually subscribes to - chat: inject token+user_id, wait for the SSE connection before sending (messages were silently dropped before the chat id resolved) - issue-detail: 8 tabs, label-based navigation, sub-issues asserted on the relations tab; pages/plugin specs declared serial (they share one project's state); dark-mode preset via storage; i18n title bilingual; copilot tab by title - root causes of the "mass failure" runs: backend rate limit (1880x HTTP 429) raised for E2E runs, and a local worker count of 12 starving the dev servers (now fixed at 2) docs: bug-list.md BUG-50..BUG-59, E2E_COVERAGE_REPORT.md section 11 | 15 天前 |
| docs: position GitCode as CN hub and GitHub as mirror Document one product narrative across dual remotes so contributors know where to discuss and how maintainers sync master. Co-authored-by: Cursor <cursoragent@cursor.com> | 3 天前 |
| docs: position GitCode as CN hub and GitHub as mirror Document one product narrative across dual remotes so contributors know where to discuss and how maintainers sync master. Co-authored-by: Cursor <cursoragent@cursor.com> | 3 天前 |
| refactor: rename reqmanpy to reqmango across entire codebase - Go modules: github.com/reqmanpy/backend to github.com/reqmango/backend - Docker: container names, DB name/user/password defaults updated - Frontend: localStorage keys (reqmango-dark-mode, reqmango:rql:history) - UI brand: Reqman/ReqManPy to ReqMango (Login, Register, Sidebar) - Configs: .env, docker-compose, Makefile, config.yaml - Docs: renamed reqmanpy-*.md to reqmango-*.md, all references updated - Tests: full-api-test.js, e2e tests - package.json: reqman-frontend to reqmango-frontend - Fix: RQLHistory.vue imports HISTORY_KEY from useRQL.ts (dedup) - All unit tests (Go + Vitest) and API integration tests pass | 3 个月前 |
| docs: update SDK README with Python/Node quickstart; add test-python/test-node to Makefile | 22 天前 |
| Merge remote-tracking branch 'origin/master' | 2 天前 |
| Merge remote-tracking branch 'origin/master' | 2 天前 |
| security(go): enable gosec, close token-leak paths, fix CI; all frontend/e2e green Security (backend) - Enable gosec + bodyclose via .golangci.yml; migrate to golangci-lint v2.13.2 (v1.x refuses to analyse a go 1.25 module). 355 lint findings -> 0. - Tokens can no longer leak through code: * access log no longer writes SSE ?token= query values (RedactQuery, with a middleware-level regression test) * webhook URLs (Slack/GitHub embed credentials in the path) and response bodies are masked/truncated before logging * SECRET_KEY no longer falls back to the public "change-me-in-production": a random per-process key is generated with a loud warning; docs/compose/env example require a real value, and the unreferenced config.yaml was deleted * RQL executor no longer prints SQL + arguments on every query * uploads dir 0750 + sanitized extension, worktree names validated, Slack webhook restricted to https://hooks.slack.com - Fix vulnerabilities reachable from this module (govulncheck 3 -> 0): golang-jwt/jwt v5.2.2, jackc/pgx v5.9.2 (SQL injection GO-2026-5004), golang.org/x/text v0.39.0. Real bugs found by the new linters - skill_executor: regexes used Perl lookahead (unsupported by RE2) -> MustCompile panicked, so SKILL.md parsing was broken - conditional fields: numeric ids were converted with string(rune(id)), so type/state/assignee/label conditions could never match - workflow_service: Delete/DeleteNode/DeleteEdge used Delete(&struct{}{}), which produced DELETE FROM "" (SQLSTATE 42601) -> every workflow delete returned 500 - seed release indexing, budget alert message, swallowed JSON bind error, dead code CI - golangci-lint-action@v9 (pinned linter v2.13.2), GO_VERSION 1.25 (+ Dockerfile), @vitest/coverage-v8 added so vitest run --coverage works, ESLint step replaced by a real vue-tsc --noEmit check, new Security job: gitleaks (blocking, .gitleaks.toml) + govulncheck (advisory) frontend/e2e: 91 failures -> 0 - automation specs rewritten against the real AutomationRuleBuilder and the dot-notation event names the bus actually subscribes to - chat: inject token+user_id, wait for the SSE connection before sending (messages were silently dropped before the chat id resolved) - issue-detail: 8 tabs, label-based navigation, sub-issues asserted on the relations tab; pages/plugin specs declared serial (they share one project's state); dark-mode preset via storage; i18n title bilingual; copilot tab by title - root causes of the "mass failure" runs: backend rate limit (1880x HTTP 429) raised for E2E runs, and a local worker count of 12 starving the dev servers (now fixed at 2) docs: bug-list.md BUG-50..BUG-59, E2E_COVERAGE_REPORT.md section 11 | 15 天前 |