Skip to content

fix(integrations): enforce current task ownership - #1867

Merged
tinsever merged 17 commits into
mainfrom
fix/review-06-integration-scope
Sep 30, 2026
Merged

tinsever merged 17 commits into
mainfrom
fix/review-06-integration-scope

Conversation

@tinsever

@tinsever tinsever commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

what changed?

stale integration links could update tasks after they moved out of the integration’s project or workspace. check ownership inside locked transactions for imports and webhooks, and remove incompatible links during moves.

finding 06 from the codebase review.

how did you check it?

provider unit tests and postgres ownership/move regressions, including stale links and concurrent scope changes.

checked the combined fix tree with the full workspace test run, uncached workspace typechecks, lint, i18n and openapi checks. postgres integration tests used disposable local test databases; provider and s3 calls were mocked.

Native GitHub stack #1885 (bottom to top): #1867 (this PR) → #1874. Stack base: main. The independent board stack #1886 (#1873 → #1876 → #1877 → #1878 → #1879) also depends on this foundation.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T03:52:42.357934Z 2fca490 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Mixed activity

Activity patterns show a mix of organic and automated signals.

View full analysis →

This is an automated analysis by AgentScan

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Enforce current task ownership across integration sync

🐞 Bug fix 🧪 Tests 🕐 40+ Minutes

Grey Divider

AI Description

• Prevent stale integration links from changing tasks outside their current project or workspace.
• Check ownership within locked transactions and remove incompatible links during moves.
• Add provider and PostgreSQL regressions for stale links and concurrent moves.
Diagram

graph TD
  Incoming["Imports and webhooks"] --> Guard["Locked transaction"] --> Owner{"Current owner?"} -->|yes| Writes["Scoped task writes"] --> Events["Postcommit events"]
  Owner -->|no| Skip["Skip stale link"]
  Moves["Task and project moves"] --> Cleanup["Remove invalid links"] --> Skip
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Enforce link ownership with database triggers
  • ➕ Protects writes from every caller, including future code paths.
  • ➖ Requires schema-level enforcement and migration work; triggers alone do not define the transaction boundaries needed for provider side effects.

Recommendation: Use the shared locked transaction guard for this fix: it covers existing provider workflows and coordinates ownership checks with their related writes. Database-level enforcement is worth considering separately if more writers create external links.

Files changed (31) +2036 / -992

Bug fix (22) +1421 / -980
import-gitea-issues.tsScope Gitea issue imports to current ownership +91/-59

Scope Gitea issue imports to current ownership

• Existing-task updates run only while the task belongs to the integration project. New tasks, links, labels, and comments are written in the same scoped transaction; out-of-scope imports are skipped.

apps/api/src/gitea-integration/controllers/import-gitea-issues.ts

import-issues.tsLock ownership during GitHub import continuation +27/-6

Lock ownership during GitHub import continuation

• Import transactions verify the project's workspace under a lock. Continuations lock their scoped task, and pull-request links require a task still in the import project.

apps/api/src/github-integration/controllers/import-issues.ts

import-gitlab-issues.tsScope GitLab issue imports to current ownership +91/-54

Scope GitLab issue imports to current ownership

• Existing-task updates are skipped when their link no longer points into the integration project. Task creation and related link, label, and note writes share one scoped transaction.

apps/api/src/gitlab-integration/controllers/import-gitlab-issues.ts

issue-closed.tsGuard Gitea close sync against moved tasks +80/-58

Guard Gitea close sync against moved tasks

• Status and link metadata updates now require current task ownership and commit together. Status-change events are published after commit.

apps/api/src/plugins/gitea/webhooks/issue-closed.ts

issue-comment-created.tsReject Gitea comments on out-of-scope tasks +24/-22

Reject Gitea comments on out-of-scope tasks

• Comment activity is inserted inside the ownership-checked transaction rather than through the unscoped database connection.

apps/api/src/plugins/gitea/webhooks/issue-comment-created.ts

issue-edited.tsScope Gitea edit and link updates +84/-78

Scope Gitea edit and link updates

• Issue edits check the task's current project under a lock. Task text and link metadata changes use the same transaction.

apps/api/src/plugins/gitea/webhooks/issue-edited.ts

issue-labeled.tsKeep Gitea label sync within task scope +122/-99

Keep Gitea label sync within task scope

• Priority, status, and label changes run in the ownership-checked transaction. Status events are deferred until commit.

apps/api/src/plugins/gitea/webhooks/issue-labeled.ts

issue-reopened.tsGuard Gitea reopen sync against moved tasks +84/-58

Guard Gitea reopen sync against moved tasks

• Reopen handling scopes the task lookup and updates to its integration project. Link metadata commits with the status change before an event is published.

apps/api/src/plugins/gitea/webhooks/issue-reopened.ts

integration-task-scope.tsIntroduce locked integration task ownership guard +74/-0

Introduce locked integration task ownership guard

• Adds a transaction helper that checks the integration project and optional workspace, then locks an in-project task before applying writes. It also provides scope predicates and a postcommit effect callback.

apps/api/src/plugins/github/services/integration-task-scope.ts

link-manager.tsFilter stale links and validate new link ownership +32/-3

Filter stale links and validate new link ownership

• Link lookups exclude tasks no longer in their integration project. Link creation checks ownership under a task lock, and link metadata updates can use a caller's transaction.

apps/api/src/plugins/github/services/link-manager.ts

task-service.tsAllow transactional, project-scoped status updates +10/-8

Allow transactional, project-scoped status updates

• Status updates accept the active database transaction and constrain the write to the task's current project. The updated row is returned directly for event decisions.

apps/api/src/plugins/github/services/task-service.ts

issue-closed.tsScope GitHub close sync and defer its event +56/-40

Scope GitHub close sync and defer its event

• Close handling verifies ownership before changing status or link metadata. Both writes share a transaction, with status events published after commit.

apps/api/src/plugins/github/webhooks/issue-closed.ts

issue-comment-created.tsGuard GitHub comment activity creation +22/-20

Guard GitHub comment activity creation

• Incoming comments create task activity only within a transaction that confirms current integration ownership.

apps/api/src/plugins/github/webhooks/issue-comment-created.ts

issue-edited.tsScope GitHub issue edits to their integration project +110/-104

Scope GitHub issue edits to their integration project

• Task text updates require current ownership. Corresponding external-link metadata is written in the same transaction.

apps/api/src/plugins/github/webhooks/issue-edited.ts

issue-labeled.tsGuard GitHub priority, status, and label sync +99/-82

Guard GitHub priority, status, and label sync

• Label webhook writes now share an ownership-checked transaction. Status events run only after its changes commit.

apps/api/src/plugins/github/webhooks/issue-labeled.ts

issue-reopened.tsScope GitHub reopen sync and defer its event +56/-40

Scope GitHub reopen sync and defer its event

• Reopen handling checks current task ownership before status and link metadata writes. Status events are published after commit.

apps/api/src/plugins/github/webhooks/issue-reopened.ts

issue-closed.tsGuard GitLab close sync against stale links +83/-64

Guard GitLab close sync against stale links

• Close handling scopes status and metadata writes to a currently owned task in one transaction. It defers the status event until commit.

apps/api/src/plugins/gitlab/webhooks/issue-closed.ts

issue-reopened.tsGuard GitLab reopen sync against stale links +82/-63

Guard GitLab reopen sync against stale links

• Reopen handling checks current ownership, commits task status with link metadata, and publishes status events afterward.

apps/api/src/plugins/gitlab/webhooks/issue-reopened.ts

issue-updated.tsScope GitLab text and label webhook updates +116/-96

Scope GitLab text and label webhook updates

• Text, priority, status, label, and link metadata changes use an ownership-checked transaction. Status-change events are deferred until commit.

apps/api/src/plugins/gitlab/webhooks/issue-updated.ts

note-created.tsGuard GitLab note activity creation +27/-25

Guard GitLab note activity creation

• Note deduplication and activity insertion now run within the scoped task transaction, preventing stale links from adding comments.

apps/api/src/plugins/gitlab/webhooks/note-created.ts

move-project.tsRemove incompatible legacy links during project moves +24/-0

Remove incompatible legacy links during project moves

• A project move deletes links on its tasks whose integrations belong to another project. Cleanup occurs within the move transaction.

apps/api/src/project/controllers/move-project.ts

move-task.tsDetach external links when moving a task +27/-1

Detach external links when moving a task

• Task moves recheck and lock both projects, constrain the update to the source project, and delete the task's external links in the move transaction.

apps/api/src/task/controllers/move-task.ts

Tests (9) +615 / -12
github-description-sync.test.tsAdapt description sync fixture to ownership checks +13/-3

Adapt description sync fixture to ownership checks

• The integration fixture now includes a persisted GitHub binding. The link-update assertion accepts the transaction argument.

tests/api-integration/github-description-sync.test.ts

integration-task-ownership.test.tsCover stale links, cleanup, and concurrent moves in PostgreSQL +288/-0

Cover stale links, cleanup, and concurrent moves in PostgreSQL

• Regression tests exercise moved-task imports and Gitea webhooks, link cleanup on task and project moves, and serialization between scoped writes and a task move. Provider calls are mocked.

tests/api-integration/integration-task-ownership.test.ts

import-gitlab-issues.test.tsKeep GitLab importer unit tests transaction-aware +30/-0

Keep GitLab importer unit tests transaction-aware

• Mocks the ownership transaction wrapper so existing importer behavior tests use their database mock; ownership locking has separate coverage.

tests/api/gitlab-integration/import-gitlab-issues.test.ts

comment-sync.test.tsAdapt Gitea comment tests to scoped transactions +30/-0

Adapt Gitea comment tests to scoped transactions

• Supplies a transaction-wrapper mock that preserves the provider tests' existing database behavior and postcommit callbacks.

tests/api/plugins/gitea/comment-sync.test.ts

integration-task-scope.test.tsTest ownership locks and postcommit behavior +113/-0

Test ownership locks and postcommit behavior

• Verifies project and task lock modes, scope predicates, skips for moved resources, and event behavior after commit or failed writes.

tests/api/plugins/github/integration-task-scope.test.ts

issue-reopened.test.tsAdapt GitHub reopen tests to transaction arguments +44/-6

Adapt GitHub reopen tests to transaction arguments

• Updates link metadata assertions for the transaction parameter and mocks the ownership wrapper for existing webhook behavior cases.

tests/api/plugins/github/issue-reopened.test.ts

issue-reopened.test.tsAdapt GitLab reopen tests to scoped writes +37/-3

Adapt GitLab reopen tests to scoped writes

• Accounts for the transaction parameter on link updates and supplies a wrapper mock for provider behavior tests.

tests/api/plugins/gitlab/webhooks/issue-reopened.test.ts

issue-updated.test.tsKeep GitLab update tests compatible with scoped transactions +30/-0

Keep GitLab update tests compatible with scoped transactions

• Mocks the ownership wrapper around the existing database fixture while preserving postcommit effect handling.

tests/api/plugins/gitlab/webhooks/issue-updated.test.ts

note-created.test.tsKeep GitLab note tests compatible with scoped transactions +30/-0

Keep GitLab note tests compatible with scoped transactions

• Mocks the ownership wrapper so note-handling unit tests continue exercising provider behavior with their database fixture.

tests/api/plugins/gitlab/webhooks/note-created.test.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 85e07cf4bf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/api/src/task/controllers/move-task.ts Outdated
Comment thread apps/api/src/gitea-integration/controllers/import-gitea-issues.ts Outdated
@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Moving a task deletes its saved links ✓ Resolved
Description
moveTask deletes every external link for the task, including manually added links whose
integrationId is null. A move to another project therefore removes links the user added to the
task, even though those links do not belong to the former project's integration.
Code

apps/api/src/task/controllers/move-task.ts[R164-166]

+    await tx
+      .delete(externalLinkTable)
+      .where(eq(externalLinkTable.taskId, taskId));
Evidence
The new deletion is scoped only by task ID, while the manual-link controller inserts links with a
null integration ID. This removes user-created task data during a mutation that is intended to clean
up incompatible integration links.

Grey Divider

Tip of the day
💡 Did you know, you can route each severity your way: inline, summary, both, or drop

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread apps/api/src/task/controllers/move-task.ts Outdated
Comment thread apps/api/src/task/controllers/move-task.ts Outdated
Comment thread apps/api/src/gitea-integration/controllers/import-gitea-issues.ts Outdated
Comment thread apps/api/src/plugins/github/services/link-manager.ts
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8787420435

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/web/src/hooks/use-project-websocket.ts
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 394cd414ec

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/api/src/project/controllers/move-project.ts
Comment thread apps/api/src/task/controllers/move-task.ts
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ca29c96133

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/api/src/task/controllers/move-task.ts
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 71e2a3e0aa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/api/src/plugins/gitea/webhooks/issue-closed.ts
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f2e252753b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/api/src/task/controllers/move-task.ts
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: 088a8f1718

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 802c5bd338

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +50 to +51
if (!task)
throw new Error("Task no longer belongs to the integration project");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Compensate provider issue creation when ownership changes

When a newly created task is moved while the asynchronous task.created integration handler is awaiting GitHub, Gitea, or GitLab, those handlers create the provider issue before calling createExternalLink; this new ownership failure then leaves the remote issue orphaned and the moved task permanently unlinked. For Gitea and GitLab, the resulting issue-opened webhook can also import that orphan as a second task in the source project. Use a durable ownership reservation or compensate by closing/deleting the provider issue when the final link cannot be committed.

AGENTS.md reference: AGENTS.md:L32-L32

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the same remote-creation compensation race already reviewed in PRRT_kwDONkPybM6nQtaK and deferred as a separate delivery/recovery change. The final ownership guard must reject the moved task to protect workspace isolation. Provider cleanup would need durable recovery and webhook handling across GitHub, Gitea and GitLab; ordinary association or label failures already have the same orphan outcome. Keeping this isolation PR scoped and reporting compensation as a follow-up.

@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ca6e4f7e15

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/api/src/github-integration/controllers/import-issues.ts
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cf2b030ca5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/api/src/plugins/github/webhooks/issue-opened.ts Outdated
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b62c486f6f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

const priority = extractIssuePriority(adaptedLabels);
const status = extractIssueStatus(adaptedLabels);

const comments = await fetchIssueComments(issue.number, config, client);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Recheck issue links after fetching comments

When an issue is initially unlinked and its opened webhook creates a task while this potentially paginated provider request is pending, existingLink remains null and the importer proceeds down the creation branch without rechecking. Because external_link has no uniqueness constraint for an integration/resource/external ID, both paths can commit separate tasks and links for the same provider issue. Serialize creation with the webhook or recheck under a shared lock after the fetch; the GitLab notes path at import-gitlab-issues.ts:196 has the same race.

AGENTS.md reference: AGENTS.md:L5-L5

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified this creation race, including in the pre-PR main implementation: it checks for an issue link before creation but does not recheck under a creation lock or enforce an external-resource uniqueness constraint. Moving comment/notes requests outside ownership transactions widens an existing window; the current ownership guards still prevent writes crossing project/workspace boundaries. Coordinating importer and opened-webhook creation is separate provider-creation idempotency work, alongside the previously reported remote-orphan compensation followup. I am reporting it without expanding this ownership PR into that lifecycle redesign.

@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Chef's kiss.

Reviewed commit: 53c75ea88a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: 2fca490169

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

tinsever added a commit that referenced this pull request Sep 30, 2026
@tinsever
tinsever added this pull request to stack #1885 September 30, 2026 11:20
@tinsever
tinsever merged commit ca79249 into main Sep 30, 2026
23 checks passed
github-actions Bot added a commit to capital-shield/kaneo that referenced this pull request Oct 3, 2026
### Features

- **web:** redesign settings: usekaneo#1905
- **site:** link community projects from resources: [69ba99d](69ba99d)
- **site:** add a community projects page: [961c309](961c309)
- **site:** sync product preview with home, inbox and my tasks: [30ba825](30ba825)
- missing french translation: usekaneo#1903
- add short task links like /acme/task/KAN-12: usekaneo#1891
- **web:** add home, inbox and my tasks pages: usekaneo#1898
- **web:** wire the task copy shortcuts: usekaneo#1897
- **web:** move task delete into the action group: usekaneo#1896
- **site:** add guides and retarget alternatives: [58f6d47](58f6d47)
- **web:** track the cloud signup funnel: [abacad7](abacad7)
- **docker:** support file-backed secrets for container deployments: usekaneo#1853
- sort labels alphabetically: usekaneo#1856
- **web:** select task ranges with shift-click: usekaneo#1838
- clickable task PR list, task link matching, and reopen completed tasks for new work: usekaneo#1864
- **mcp:** get tasks by ticket ID: usekaneo#1839
- **web:** guide cloud users through invites and plan choice during onboarding: usekaneo#1840
- rank new issue priority with Jev: [594e016](594e016)
- **web:** cloud sign-up and onboarding layout: usekaneo#1832
- gitlab integration: usekaneo#1727
- **tasks:** show subtask progress on cards and list rows: usekaneo#1703
- added project backgrounds: usekaneo#1654
- multiselect for customfield: usekaneo#1735
- **ci:** discord actions webhook: usekaneo#1792
- **ci:** adding zizmor: usekaneo#1790
- **project:** move a project to another workspace: usekaneo#1525
- duplicate a task from the card context menu: usekaneo#1609
- allow manual external resource links: usekaneo#1661
- **ci:** trufflehog implementation: usekaneo#1787
- **task:** let images be resized in the task description: usekaneo#1529
- **web:** add a change-password screen under account settings: usekaneo#1719
- **auth:** add password recovery from the login screen: usekaneo#1773
- add instance user administration panel: usekaneo#1400
- **site:** bring product preview up to date with current app: [dd855f7](dd855f7)
- **site:** refresh marketing site and interactive product previews: [90aec99](90aec99)
- **calendar:** add label-filtered project calendar feeds: usekaneo#1763

### Bug Fixes

- **web:** send subscription revenue as a property: [445b735](445b735)
- **site:** list GitLab with the git integrations: [3c01517](3c01517)
- **site:** serve favicon.ico: [e7ef050](e7ef050)
- **docs:** load the docs font from its real path: [22c7a02](22c7a02)
- **tasks:** make bulk status changes atomic: usekaneo#1873
- **integrations:** preserve rapid legitimate edits: usekaneo#1874
- **integrations:** enforce current task ownership: usekaneo#1867
- **ws:** revoke removed workspace members: usekaneo#1865
- **migrations:** record workflow migration completion: usekaneo#1872
- **auth:** enforce api key quotas and rate limits: usekaneo#1869
- **mcp:** share tools and support workspace label deletion: usekaneo#1871
- **reminders:** persist notification and claim atomically: usekaneo#1870
- **integrations:** require task update permission for imports: usekaneo#1868
- **ci:** publish npm provenance on GitHub-hosted runners: [50779a4](50779a4)
- **gitea:** reject saved tokens for changed servers: usekaneo#1866
- **ci:** pass the GitHub token to AgentScan: usekaneo#1862
- **ci:** resolve nightly warnings and errors: usekaneo#1858
- **api:** make legacy MCP HTTP requests replica independent: usekaneo#1850
- **docker:** disable wget proxy for loopback health checks: usekaneo#1841
- **billing:** resize Creem seats by subscription item id: usekaneo#1836
- **gitea:** prevent outbound comment echoes: usekaneo#1834
- **deps:** migrate Sentry SDKs together to v11 (usekaneo#1826): usekaneo#1826
- **ci:** grant nightly reusable CI scan permission: [0216067](0216067)
- **board:** allow column moves while sorting by task number: usekaneo#1816
- **auth:** backfill instance admin on legacy installations: [b7c6aee](b7c6aee)
- **admin:** harden the user administration panel: usekaneo#1805
- **admin:** allow updating your own email without changing role: [3d57439](3d57439)
- **security:** close permission and integration gaps: usekaneo#1802
- **project:** secure integrations across workspace moves: usekaneo#1801
- **editor:** preserve formatting when pasting Markdown: usekaneo#1797
- **auth:** report invitation email delivery failures: usekaneo#1798
- **gitea:** verify saved repository connections: usekaneo#1796
- **mcp:** keep OAuth requests valid outside UTC: usekaneo#1795
- **i18n:** translate calendar in remaining locales: [1d61ceb](1d61ceb)
- **ci:** zizmor findings: usekaneo#1791
- **integrations:** resolve PRs through linked issue identities: usekaneo#1739
- **auth:** prevent repeated 401s for pending invitations after session expiry: usekaneo#1715
- **auth:** gate sign-in emails to deliverable addresses: usekaneo#1758
- **web:** preserve image uploads across editor recreation: usekaneo#1738
- **reminders:** calculate deadlines from the end of the due day: usekaneo#1762
- **mcp:** support whoami with API keys: usekaneo#1748
- **web:** respect DISABLE_WORKSPACE_CREATION on the onboarding screen: usekaneo#1744
- **backlog:** prevent task remounts during list interactions: usekaneo#1734
- **auth:** prevent role changes from removing the last admin: usekaneo#1733
- **npm:** fixing GHSA-2xp9-vwfh-vxw4: usekaneo#1777
- **web:** guard tiptap setHardBreak against invalid-content schema error: [be3ffb5](be3ffb5)
- **i18n:** prevent locale module crash on stale dynamic import: usekaneo#1775
- **site:** improve search metadata and product discovery: [121183e](121183e)
- **web:** allow non-root runtime configuration writes: usekaneo#1767
- **site:** poof away preview cursor on interaction: [08dcaee](08dcaee)
- **nginx:** allow larger OAuth session headers: usekaneo#1761
- **deps:** resolve open dependabot advisories: [b8432a0](b8432a0)
- **web:** preserve comment markdown spacing: usekaneo#1521

### Performance Improvements

- **project:** stop returning tasks with project details: usekaneo#1800

### Documentation

- update sponsors: [1c51887](1c51887)
- add AI Policy badge to README: [011c8ee](011c8ee)
- update sponsors: [e45c8ac](e45c8ac)
- assign issue types from templates: [4725cfa](4725cfa)
- simplify issue and pull request templates: [cb6ce20](cb6ce20)
- adopt Human Voice AI contribution policy: [b090123](b090123)
- overhaul agents.md: [4d619aa](4d619aa)
- **readme:** highlight cloud and current features: usekaneo#1831
- update contributors and sponsors: [c200d70](c200d70)
- rebuild guides around current Kaneo workflows: usekaneo#1814
- acknowledge BrowserStack testing: [e389a68](e389a68)
- update contributors and sponsors: [fa07f10](fa07f10)
- **site:** add Blacksmith partner badge to site and README: [08a93b8](08a93b8)
- update contributors and sponsors: [8432a45](8432a45)
- **site:** refresh press kit with product screenshots: [3470b0a](3470b0a)
- update blog comparisons for current Kaneo features: [b97bf7d](b97bf7d)
- update contributors and sponsors: [6c7001c](6c7001c)

### Credits

Huge thanks to @tinsever, @MonsPropre, @andrejsshell, @tuttucodes, @druwan, @randoneering, @mazzz1y, @zaralX, @TymekV, @rdlugs, @tbringuier, @mohiuddin000, @shiminshen, @yavilavi, @thejdubb02, @yigit-serin, @OmG3r, and @zerodarkzone for helping!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant