Brings the Work Package Suite from a browser-local prototype to a multi-tenant, SQL-backed deployment hardened for customer IP. Auth & access control - Local username/password login (bcrypt + JWT in an HttpOnly cookie), admin-managed users, per-project membership, and project-scoped API access. - Admin console: change user roles, view the audit trail, manage settings. Security hardening - CSP / HSTS / X-Frame-Options / nosniff headers in nginx; Secure cookie via X-Forwarded-Proto; CSRF Origin check; attribute-safe output escaping. - Login lockout, token_version session revocation, stronger password policy, fail-closed secret loading, encrypted (AES-256) database backups. Persistence & schema - SOPs and Work Packages are now DB-backed and shared across users, written through a durable client sync outbox that queues offline edits. - Alembic migrations applied automatically on container start. New capabilities - Phase 2 dashboard (progress, gating, pagination, archive). - Phase 3 PWA "Field View" with offline caching and auth fallback. - WP owner assignment with OPTIONAL email notifications, OFF by default and toggled from the admin console. SMTP password is read only from the SMTP_PASSWORD env var (never stored); emails carry a WP number + deep link, never customer IP. Also: IBM Carbon restyle, Help section, and DEPLOYMENT.md brought up to date. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
31 lines
488 B
Plaintext
31 lines
488 B
Plaintext
# Python
|
|
__pycache__/
|
|
*.py[cod]
|
|
.venv/
|
|
venv/
|
|
*.egg-info/
|
|
|
|
# Local env / secrets
|
|
.env
|
|
|
|
# Local SQLite dev database
|
|
*.db
|
|
wpsuite.db
|
|
|
|
# Runtime directories (created by containers)
|
|
logs/
|
|
|
|
# Database backup dumps (large + sensitive) — keep the folder, ignore contents
|
|
/backups/*
|
|
!/backups/.gitkeep
|
|
|
|
# Local server logs
|
|
*.log
|
|
|
|
# Local scratch / test artifacts (curl cookie jars hold live session tokens)
|
|
_*.txt
|
|
cookies.txt
|
|
|
|
# Claude Code local workspace (agent memory, session data)
|
|
.claude/
|