214 Commits

Author SHA1 Message Date
Benjamin
8ef5bb38cb fix: accept 'ref' as fallback for 'doc' query parameter
Keep backward compatibility for external integrations that still use
the old ?ref= parameter while recommending ?doc= to avoid privacy
extensions blocking.
v1.3.2
2026-02-05 23:35:09 +01:00
Benjamin
d3e7c9911c fix: rename API parameter 'ref' to 'doc' for privacy extensions compatibility
ClearURLs and similar privacy extensions block the 'ref' parameter
as it's commonly used for referrer tracking. Renamed to 'doc' which
is not targeted by these extensions.

Closes #19
2026-02-05 22:33:03 +01:00
Benjamin
2fb9339962 fix: update signature count after signing & add API documentation
- Fix HomePage.vue to update signatureCount after user signs
- Fix EmbedPage.vue to use signatureCount from API instead of signatures.length
- Adapt E2E tests to reflect signature visibility security model
- Create missing API documentation (docs/en/api.md, docs/fr/api.md)
- Document Docker healthcheck in deployment guides
- Document signature endpoint access control rules
- Fix MagicLink auto-detection description in READMEs
2026-02-05 21:55:45 +01:00
Benjamin
f43c3c53a9 feat: add healthcheck support for container image
- Add 'health' subcommand to ackify binary for Docker HEALTHCHECK
- Add HEALTHCHECK directive to Dockerfile
- Add healthcheck configuration to all compose files
- Supports custom port via ACKIFY_LISTEN_ADDR

Closes #21
2026-02-05 20:57:30 +01:00
Benjamin
635f8c7021 fix: restrict signature list visibility to document owner/admin
- Signatures endpoint now returns only user's own signature for non-owner/admin
- Owner/admin can see all signatures, others see only their own (if signed)
- Added signatureCount to FindOrCreateDocument response for public count display
- Frontend shows signature count header even when detailed list is restricted

Closes #20
2026-02-05 20:57:30 +01:00
Benjamin
2449e7ccee feat: add owner-based expected signers management
Allow non-admin document owners to add and remove expected signers for their documents via new endpoints:
- POST /users/me/documents/{docId}/signers
- DELETE /users/me/documents/{docId}/signers/{email}

Closes #17

fix: escape database names in SQL and add owner-based document management

- Quote PostgreSQL identifiers with double-quotes in migrations to support database names containing special characters like hyphens (fixes #16)
- Add CanManageDocument to Authorizer interface for ownership checks
- Add owner-based document management
- Non-admin users can now manage documents they created when ACKIFY_ONLY_ADMIN_CAN_CREATE=false (fixes #17)
- Return 403 for owner routes when ACKIFY_ONLY_ADMIN_CAN_CREATE=true

Closes #16

refactor: move TenantProvider interface to pkg/providers
- Centralize all provider interfaces in pkg/providers package for consistency with Authorizer and other capability provider interfaces.
2026-02-05 20:57:30 +01:00
Benjamin
c84d7d69e0 fix: add image extension fallback for content type detection
Go's http.DetectContentType fails to recognize minimal/malformed image
files and returns application/octet-stream. Added common image extensions
(.png, .jpg, .jpeg, .gif, .webp) to the extension-based fallback map
so content type is correctly determined from filename when magic byte
detection fails.
v1.3.1
2026-01-22 19:39:56 +01:00
Benjamin
bff75aafbe fix: persist options when uploading documents & dynamic config OnlyAdminCanCreate
Reader options (readMode, allowDownload, requireFullRead, verifyChecksum)
were not being saved during document upload.

SimpleAuthorizer now reads the setting dynamically from ConfigService
instead of using a static value set at startup. This allows admins to
toggle document creation permissions via the settings UI without
requiring a server restart.

Fixes #14
Fixes #15
2026-01-22 15:14:13 +01:00
Benjamin
92f97eff43 docs: fix install run line v1.3.0 2026-01-21 01:51:02 +01:00
Benjamin
71e5d66550 fix: update SHM sdk 2026-01-21 00:21:44 +01:00
Benjamin
af50e6b7d7 fix: disable telemetry on e2e on CI 2026-01-20 23:39:42 +01:00
Benjamin
77975cef1a fix: add SHM directory to store identity file (must be persisted on host) 2026-01-20 23:24:03 +01:00
Benjamin
6ce67b02d4 fix: add SHM directory to store identity file (must be persisted on host) 2026-01-20 22:42:40 +01:00
Benjamin
37d023a80d fix: missing traductions & docker hub push provenance 2026-01-20 15:40:38 +01:00
Benjamin
12169ba7e0 docs: readme screenshot 2026-01-20 14:57:26 +01:00
Benjamin
b6e17f510c fix: local upload for test e2e on CI 2026-01-20 13:41:34 +01:00
Benjamin
122eb42f2a fix: missing translation 2026-01-20 13:20:05 +01:00
Benjamin
8a0d79ac65 fix: user document allocation
refacto: vue components extract, sign & reminder list, align tests to new components
2026-01-20 09:54:36 +01:00
Benjamin
de1d9cd5e5 doc: add missing env to .env.example 2026-01-19 00:10:12 +01:00
Benjamin
998d227898 refacto(backend): cleaning dead code 2026-01-17 01:49:41 +01:00
Benjamin
493d915fa7 refactor(server): encapsulate service initialization in ServerBuilder
Move all service creation (I18n, Email, MagicLink, Session, Config)
from main.go into ServerBuilder.Build(), making main.go minimal and
self-contained.

- ServerBuilder now only requires WithDB() and WithTenantProvider()
- AuthProvider and Authorizer have sensible CE defaults
- Rename DynamicAuthProvider → auth.Provider for simplicity
- Remove unused With* methods for internal services
2026-01-16 14:43:58 +01:00
Benjamin
b0ef28b0ae refactor(config): replace window variables with /api/v1/config endpoint
- Add new config handler to serve public app configuration
- Create Pinia config store to load and cache configuration
- Remove window variable injection from static.go and index.html
- Update all components to use config store instead of window vars
- Remove deprecated /api/v1/auth/config endpoint (merged into /config)
- Update Cypress tests with proper type annotations
2026-01-16 01:04:53 +01:00
Benjamin
421ffb3288 refacto: mv internal/domain/models/ → pkg/models/ 2026-01-15 16:16:56 +01:00
Benjamin
c4133c4017 test(cypress): update embed page tests for i18n changes
Update test assertions to match new terminology:
- "Sign this document" → "Confirm this document"
- "No signatures" → "No confirmations"
2026-01-15 15:45:37 +01:00
Benjamin
50fcd815ec feat(webapp): improve error handling with translated messages
- Add extractErrorDetails() to get both error code and message
- Use error codes to show appropriate translated messages in DocumentCreateForm
- Add translation keys for auth and permission errors
2026-01-15 15:45:31 +01:00
Benjamin
7689c26608 refactor(auth): load auth config from API instead of window variables
Replace static window variables (ACKIFY_OAUTH_ENABLED, ACKIFY_MAGICLINK_ENABLED)
with dynamic API call to /api/v1/auth/config. This allows auth methods to be
changed without rebuilding the frontend and supports dynamic tenant configuration.
2026-01-15 15:45:26 +01:00
Benjamin
ab3818146d feat(storage): auto-create S3 bucket if it doesn't exist
Instead of failing when bucket doesn't exist, attempt to create it.
This improves the initial setup experience with MinIO and other S3
compatible storage providers.
2026-01-15 15:45:21 +01:00
Benjamin
393fc1c984 refactor(db): remove unused admin_repository and fix signature test
- Remove admin_repository.go which was not RLS-compliant and unused
- Add missing UserEmail field in signature test fixtures
2026-01-15 15:45:15 +01:00
Benjamin
dbd667dea6 fix(db): use dbctx.GetQuerier in MagicLinkRepository for RLS support
MagicLinkRepository was bypassing RLS by using r.db directly instead of
dbctx.GetQuerier(ctx, r.db). This meant queries ran outside the
transaction with app.tenant_id set, causing RLS policies to not apply.

All methods now use dbctx.GetQuerier to properly participate in the
RLS transaction context.
2026-01-15 15:44:03 +01:00
Benjamin
82b695baeb Merge branch 'feat/reader'
# Conflicts:
#	install/compose.yml
#	webapp/cypress/e2e/01-signature-workflow.cy.ts
#	webapp/cypress/e2e/02-signature-uniqueness.cy.ts
#	webapp/cypress/e2e/03-admin-signers-management.cy.ts
#	webapp/cypress/e2e/04-admin-email-reminders.cy.ts
#	webapp/cypress/e2e/06-my-signatures-page.cy.ts
#	webapp/cypress/e2e/07-admin-document-deletion.cy.ts
#	webapp/cypress/e2e/08-admin-route-protection.cy.ts
#	webapp/cypress/e2e/09-complete-workflow.cy.ts
#	webapp/cypress/e2e/10-unexpected-signatures.cy.ts
#	webapp/cypress/e2e/13-embed-page.cy.ts
#	webapp/cypress/e2e/14-csv-preview.cy.ts
#	webapp/src/components/DocumentForm.vue
#	webapp/src/components/layout/AppHeader.vue
#	webapp/src/locales/de.json
#	webapp/src/locales/es.json
#	webapp/src/locales/it.json
#	webapp/src/pages/EmbedPage.vue
#	webapp/src/pages/HomePage.vue
#	webapp/src/pages/admin/AdminDashboard.vue
#	webapp/src/pages/admin/AdminDocumentDetail.vue
#	webapp/tests/components/SignButton.test.ts
2026-01-14 22:25:27 +01:00
Benjamin
fb33fd424d refactor: consolidate dependency injection and improve auth architecture
- Move service initialization (MagicLink, Email, i18n) to main.go
- Change signature lookup from user_sub to email for cross-auth consistency
- Remove OauthService wrapper, simplify auth layer
- Pass parent context to workers for graceful shutdown
- Fix IP extraction from RemoteAddr with port
- Add compact mode to SignatureList component
- Update Cypress tests with new data-testid attributes
2026-01-14 12:34:11 +01:00
Benjamin
2d78294f55 refactor(auth): unify AuthProvider interface with dynamic config support
- Create unified AuthProvider interface in pkg/providers/interfaces.go
  supporting OIDC, MagicLink, and session management
- Implement DynamicAuthProvider that reads config from ConfigService
  on each request, enabling hot-reload of auth settings
- Simplify ServerBuilder by removing separate oauthProvider and flags
- Consolidate auth handlers into single handler.go using unified interface
- Remove obsolete providers (oauth_provider.go, magiclink_provider.go)
- Remove separate magic_link_handler.go and reminder_auth_handler.go
- Update tests with new mockAuthProvider implementing full interface
- Fix config_service_test.go SMTP validation (requires Host + From)
2026-01-13 08:59:20 +01:00
Benjamin
9b28f78ce9 feat(admin): add tenant configuration UI with hot-reload support
Add admin settings page allowing runtime configuration of:
- SMTP settings with connection testing
- OIDC/OAuth2 authentication with validation
- S3 storage configuration with connectivity check

Backend includes config service with atomic hot-reload,
encrypted secrets storage, and environment seeding on startup.
2026-01-12 22:46:04 +01:00
Benjamin
a272cc7de9 feat(storage): improve MIME type detection and add ODF format support
- Add extension-based MIME type refinement for text formats (.md, .docx, .xlsx, .odt, .ods)
- Add charset=utf-8 for text-based MIME types in Content-Type header
- Support ODF formats (OpenDocument Text/Spreadsheet)
- Unify compose templates into single compose.yml.template with region markers
- Add update mode to install script to preserve existing configuration
- Extend file upload accept list in DocumentCreateForm
- Remove binary file from repository
2026-01-08 23:16:54 +01:00
Benjamin
fb9dab2f0f feat: add document storage and integrated PDF viewer
Storage:
- Add S3 and local storage providers for document uploads
- Support file upload with checksum calculation
- Fix S3 upload for non-TLS connections (MinIO)

Document viewer:
- Add PDF.js-based viewer with scroll tracking
- Implement checksum verification on document load
- Add reader options (read mode, download, require full read)
- Auto-detect read completion for signed documents

API:
- Add document upload endpoint with storage integration
- Add proxy endpoint for stored documents
- Extend document metadata with storage and reader fields
2026-01-08 20:39:34 +01:00
Benjamin
a025a102d0 fix: install db config 2025-12-29 22:35:21 +01:00
Benjamin
70eb52735b fix: install db config 2025-12-29 22:28:59 +01:00
Benjamin
c887305b7a feat: improve e2e with data-testid for futur ui evolution 2025-12-29 21:52:13 +01:00
Benjamin
29d8012c22 feat: improvement of user name display 2025-12-29 16:00:25 +01:00
Benjamin
c2c096dd3c wip 2025-12-27 22:16:54 +01:00
Benjamin
e4521d87c7 feat(webapp): UI redesign with Technical Trust design system
- New design system (IBM Plex fonts, slate palette, dark mode)
- Complete refactor of components and pages
- Add favicon, PWA icons and new logo
- Minor fixes (null handling, translations, navigation)
2025-12-23 11:31:16 +01:00
Benjamin
c374021675 Merge branch 'feat/telemetry' 2025-12-22 22:17:03 +01:00
Benjamin
3f745405c7 feat(install): add telemetry option to installation script
- Add interactive telemetry prompt with GDPR compliance explanation
- Document collected metrics (documents, signatures, webhooks, reminders)
- Add ACKIFY_TELEMETRY to .env.example, compose.yml and compose-traefik.yml
- Update README.md with telemetry documentation
- Default to disabled but encourage users to opt-in
2025-12-22 20:37:45 +01:00
Benjamin
bc53b3ece9 feat: add anonymous telemetry for usage metrics
- Integrate SHM SDK (v1.2.0) to collect anonymous usage statistics
- Track documents, confirmations, webhooks and reminders count
- Add ACKIFY_TELEMETRY env var (disabled by default, opt-in)
2025-12-22 19:04:32 +01:00
Benjamin
296c06f374 docs: update examples 2025-12-20 10:11:54 +01:00
Benjamin
eb320cb239 fix: install script env var 2025-12-19 23:02:43 +01:00
Benjamin Touchard
7218cbfd0f fix: install script app password for db 2025-12-19 15:19:21 +01:00
Benjamin
32c5fef0a5 Merge branch 'main' into feat/telemetry 2025-12-18 18:02:01 +01:00
Benjamin
cd0b751966 fix: ensures the SessionService is created whenever ANY authentication method is enabled. v1.2.8 2025-12-18 11:44:10 +01:00
Benjamin
41881c02b5 wip 2025-12-18 11:43:05 +01:00