Release: Frontend i18n, desktop table fixes, test infrastructure, and agent tooling #18

Merged
gabogg merged 51 commits from dev into master 2026-08-21 17:15:05 +00:00
Owner

Summary of Changes (dev -> master)

This release PR promotes all completed features, bug fixes, and infrastructure improvements from dev into master.

1. Bug Fixes & UI Enhancements

  • Table Data Persistence & Isolation: Fixed stale data persistence across table navigation using {#key currentPage} and reactive loading in ListPage.svelte.
  • Users & Roles Table Views: Corrected relationship rendering for user roles and branches, and added alias for locations to /api/states.
  • Desktop Settings & Diagnostics: Added public /api/test/version and /api/test/health endpoints, enriched /api/test/info with system diagnostics, and resolved CORS/connection issues.

2. Internationalization (i18n)

  • Integrated typesafe-i18n with full English (en) and Spanish (es) localization across all desktop pages, forms, scanner, toasts, and navigation.

3. Testing Infrastructure & CI

  • Added full Playwright E2E test suites with configurable test endpoints and credentials.
  • Added Testcontainers PostgreSQL integration tests, JaCoCo coverage (>=50%), and standalone desktop-pure-logic Rust tests in parallel CI.

4. Agent Tooling

  • Added agent skills collection and Claude Code skill symlinks.
## Summary of Changes (dev -> master) This release PR promotes all completed features, bug fixes, and infrastructure improvements from `dev` into `master`. ### 1. Bug Fixes & UI Enhancements - **Table Data Persistence & Isolation**: Fixed stale data persistence across table navigation using `{#key currentPage}` and reactive loading in `ListPage.svelte`. - **Users & Roles Table Views**: Corrected relationship rendering for user roles and branches, and added alias for `locations` to `/api/states`. - **Desktop Settings & Diagnostics**: Added public `/api/test/version` and `/api/test/health` endpoints, enriched `/api/test/info` with system diagnostics, and resolved CORS/connection issues. ### 2. Internationalization (i18n) - Integrated `typesafe-i18n` with full English (`en`) and Spanish (`es`) localization across all desktop pages, forms, scanner, toasts, and navigation. ### 3. Testing Infrastructure & CI - Added full Playwright E2E test suites with configurable test endpoints and credentials. - Added Testcontainers PostgreSQL integration tests, JaCoCo coverage (>=50%), and standalone `desktop-pure-logic` Rust tests in parallel CI. ### 4. Agent Tooling - Added agent skills collection and Claude Code skill symlinks.
Analysis covers architecture, security audit, code quality issues,
potential bug fixes, and recommendations for the entire system.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
- Correct entity count: 15 JPA entities + 3 enums
- Correct controller count: 16 total
- Add finding about inconsistent @Transactional across controllers
  (StateController, CategoryController, PermissionController missing it)

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
- Fix line number reference for commitDelete dead code
- Add bug finding: globally unique item.name prevents cross-branch inventory
- Verified all findings against actual source code
- Confirmed 213/213 tests passing

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Security fixes:
- Require ADMIN_PASSWORD env var at startup (fail hard if not set)
- Replace JWT byte-repeat key derivation with SHA-256 hashing
- Align CORS default between code and config
- Add tokenVersion to User entity for JWT revocation (V5 migration)

Code quality fixes:
- Extract service layer: 12 domain services with @Transactional boundaries
- Move @Transactional from controllers to services
- Remove dead code in AuditService.commitDelete
- Move PageUtil from web/ to common/ package
- Inject app version from build properties instead of hardcoding

Bug fixes:
- Check ADMIN_PASSWORD on re-seed + increment tokenVersion on password change
- Keep item quantity at 0 instead of deleting on disincorporation/adjustment
- Add pre-validation of entry fields matching request type in executeRequest
- Change Item.name unique constraint to composite (name, branch_id) (V6 migration)
- Fix BagController audit: use long arithmetic, remove Optional wrapper
- Use configurable constant for default Inbound department name

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Flaw 11 - Repetitive @JsonIgnoreProperties:
Remove 'hibernateLazyInitializer' and 'handler' from all entity
@JsonIgnoreProperties annotations — Hibernate6Module handles
these globally via Jackson configuration.

Flaw 12 - Fragile bag barcode lookup:
Change endpoint from /api/bags/barcode/{barcode} (@PathVariable)
to /api/bags/by-barcode?barcode= (@RequestParam) for better
handling of special characters in barcodes.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Each finding now shows whether it's been fixed (✅) and references
PR #8 (fix/codebase-flaws). Recommendations section updated to
show all items as completed. Barcode endpoint updated in flow doc.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Remove the JavaFX desktop frontend and all associated files as it's
being rebuilt from scratch with a different technology stack.

Changes:
- Delete frontend/ directory (source, tests, i18n, pom.xml, README)
- Remove frontend module from root pom.xml
- Remove javafx.version property from root pom.xml
- Remove frontend version check from .github/workflows/ci.yml
- Remove frontend JAR build/upload from .github/workflows/release.yml
- Remove frontend JAR build from .forgejo/workflows/release.yml
- Remove frontend/pom.xml from release-please-config.json extra-files
- Remove frontend references from scripts/release.sh
- Remove frontend references from README.md, docs/, setup-server.sh
- Remove DEMO-GUIDE.md (frontend-specific), STYLE-GUIDE.md (JavaFX)
- Remove staged_diff patch files and pom.xml.versionsBackup
- Update copilot-instructions.md and test_mcp.js

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Reviewed-on: #9
Covers full architecture breakdown, technology rationale, development
standards, styling standards, testing/QA strategy, barcode vs QR
analysis, build optimization & tree-shaking, dependency manifest,
API contract compatibility, and phased implementation plan.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Full implementation of the desktop inventory manager:
- Svelte 5 frontend with dark-mode-first UI, keyboard-driven design
- Rust backend with Tauri commands (login, API proxy, auth storage)
- 12 CRUD views: items, bags, branches, departments, categories,
  locations, users, roles, permissions, displacements, item requests
- Barcode/QR scanner page (BarcodeDetector API + WASM fallback)
- Audit log viewer with entity/ID search
- Dashboard with entity counts
- ESBuild-minified bundle: 71 KB JS + 7 KB CSS

Test suites (13/13 passing, ~150ms):
- auth (4 tests): init, login, clear, error handling
- api client (4 tests): URL construction, error handling, CRUD paths
- router (3 tests): navigation, params, back
- components (2 tests): toast API, table filtering/sorting

E2E (Playwright):
- Login page rendering, empty-submit error, form visibility
- Tauri driver integration script (tauri-e2e.sh)

CI/CD:
- .github/workflows/desktop.yml: svelte-check + vitest +
  cargo clippy/test + Playwright E2E
- Svelte TS strict mode, Rust stable

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Rust (api.rs):
- Refactored HTTP logic into testable api module (no Tauri deps)
- 10 unit tests: URL building, base URL resolution, token extraction
- auth.rs tests: serialization, config defaults, roundtrip

JS integration tests (api.integration.test.js):
- 6 tests against real Spring backend with H2 test DB
- Auth flow: login (valid + invalid), GET /auth/me, CRUD endpoints
- Isolated from unit tests via vitest.integration.config.js

Test runner (test-helpers.sh):
- Starts Spring backend in test profile on port 14000
- Waits for health check, runs integration tests, stops gracefully
- Works as standalone script or sourced for modular use

CI (desktop.yml):
- Added backend-integration job: installs Java 21, starts backend,
  runs vitest integration + Playwright E2E against live backend
- Only runs on PRs (10min timeout)

Test results:
- Unit: 13/13 (~100ms)
- Integration: 6/6 against real backend (~650ms)
- Build: 71KB JS + 7KB CSS

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
- Fix api.js BASE_URL: strip trailing /api from VITE_API_URL so
  paths like /api/items produce http://host/api/items (no double prefix)
- Fix api-invoke.js: add ReferenceError guard for process.env in browser
- Add httpFallback to api-invoke.js for browser/Tauri bridge commands
  (store_auth, get_stored_auth, clear_auth fall to localStorage)
- Add test:e2e:headed npm script for visual Playwright testing
- Fix CORS: test-helpers.sh now passes --app.cors-origin=$CORS_ORIGIN
  (defaults to http://localhost:1420 for Vite dev server)
- Update Playwright E2E to test full login + navigate all pages + logout

E2E verified: headed browser session completes login, visits all 9
CRUD pages, scanner, audit log, and returns to login screen.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Test suite (23.3s headed, 12/12 passing):

Login + Dashboard:
- Login form accepts credentials, dashboard shows stat cards
- All 7 entity pages render data tables with seed data
  (Branches, Departments, Categories, Items, Users, Bags)

Categories CRUD (only entity where generic inline form works):
- Create via UI modal, verify in table and via API
- Edit name, verify update in table and API
- Delete, verify removed from table and API

Scanner + Audit pages:
- Scanner page renders camera button and help text
- Audit log page renders entity selector and search

Bug fixes discovered during testing:
- getToken() was async causing "Bearer [object Promise]" header
- ListPage response parsing lacked `data` field support
- DashboardPage lacked `total` field support
- api-invoke.js lacked browser/http fallback for Tauri commands
- CORS needed explicit --app.cors-origin for dev server
- BASE_URL double-/api prefix stripping

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Complete E2E test suite covering every functional area:

1. Login flow + Dashboard stat cards
2. All 7 entity page renderings (Branches, Categories, Items, Bags,
   Roles, Users, Departments)
3. Permissions table
4. Locations page
5. Categories full CRUD: create, edit, delete
6. Filter/search within data tables (match + empty state)
7. Pagination button visibility
8. Item inline form modal (name, description, quantity fields)
9. Scanner page (camera button, help text)
10. Audit log search controls
11. All 12 sidebar nav items present + navigable without errors
12. API CRUD verification for all 5 entity types (categories,
    departments, items, branches, bags)

27/27 tests passing, 42.4s headed, real backend + H2 test DB + seed data.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
- SettingsPage component for configuring backend server URL
- Reactive baseUrl store in api.js (supports localStorage persistence)
- LoginPage settings panel with URL test/save functionality
- Wire SettingsPage into App.svelte navigation
- Fix api.js to use svelte store get() for dynamic base URL
feat: merge desktop settings panel and E2E coverage confirmation
- TESTING_BEST_PRACTICES_RESEARCH.md: 1,877-line research covering
  Spring Boot, Vitest/Svelte, Tauri, Playwright, Rust, and CI/CD
  best practices with concrete config snippets and code examples
- TESTING_IMPROVEMENTS.md: actionable 5-phase plan with effort/impact
  matrix, addressing current issues (H2 vs PG, DirtiesContext,
  stale E2E, no CI, missing system deps)
test(phase 3 & 4): fix E2E login and Svelte pagination bugs, run all tests in parallel CI
Some checks failed
CI / backend-test (pull_request) Successful in 1m33s
CI / frontend-test (pull_request) Failing after 7s
CI / rust-test (pull_request) Failing after 14s
5006859879
ci: trigger workflow on push to test/infra-issues and pull requests to dev
Some checks failed
CI / backend-test (push) Successful in 1m21s
CI / frontend-test (push) Successful in 40s
CI / rust-test (push) Failing after 35s
CI / backend-test (pull_request) Successful in 1m19s
CI / frontend-test (pull_request) Successful in 16s
CI / rust-test (pull_request) Failing after 9s
8c5e751d12
ci: prevent duplicate workflow runs by removing feature branch push trigger
Some checks failed
CI / backend-test (pull_request) Successful in 1m21s
CI / frontend-test (pull_request) Successful in 16s
CI / rust-test (pull_request) Failing after 9s
08bd3c7d37
ci: use local target-dir in rust container to avoid permission issues
Some checks failed
CI / backend-test (pull_request) Successful in 1m15s
CI / frontend-test (pull_request) Successful in 16s
CI / rust-test (pull_request) Failing after 8s
fcd7f13d4b
ci: set CARGO_HOME to writable tmp directory in rust container
Some checks failed
CI / backend-test (pull_request) Successful in 1m16s
CI / frontend-test (pull_request) Successful in 16s
CI / rust-test (pull_request) Failing after 9s
11648a7bb6
ci: use latest rust image to ensure compile compatibility with newer crates
All checks were successful
CI / backend-test (pull_request) Successful in 1m15s
CI / frontend-test (pull_request) Successful in 15s
CI / rust-test (pull_request) Successful in 58s
86b61973a0
fix: address PR review comments including @Transactional removal and actions/checkout integration
Some checks failed
CI / backend-test (pull_request) Failing after 4s
CI / frontend-test (pull_request) Successful in 17s
CI / rust-test (pull_request) Failing after 2s
c1dee9e031
ci: use manual checkout with git http.extraheader to fix containers lacking Node.js
All checks were successful
CI / backend-test (pull_request) Successful in 2m8s
CI / frontend-test (pull_request) Successful in 17s
CI / rust-test (pull_request) Successful in 26s
1299513cf1
fix: refactor backend and frontend pagination to use standard 0-indexed page and size
All checks were successful
CI / backend-test (pull_request) Successful in 2m9s
CI / frontend-test (pull_request) Successful in 19s
CI / rust-test (pull_request) Successful in 27s
82a240ffa5
test: update extract_token_field test in pure-logic to use ***
All checks were successful
CI / backend-test (pull_request) Successful in 2m7s
CI / frontend-test (pull_request) Successful in 18s
CI / rust-test (pull_request) Successful in 26s
2578c1d4a7
Merge pull request 'test(infra): implement TESTING_IMPROVEMENTS.md testing roadmap' (#15) from test/infra-issues into dev
All checks were successful
CI / backend-test (push) Successful in 2m1s
CI / frontend-test (push) Successful in 18s
CI / rust-test (push) Successful in 27s
59f414bc76
Reviewed-on: #15
fix: support multiple allowed CORS origins to prevent local dev UI CORS blocks
Some checks failed
CI / frontend-test (push) Waiting to run
CI / rust-test (push) Waiting to run
CI / backend-test (push) Has been cancelled
43d2d7a643
feat: add start-app.sh script
All checks were successful
CI / backend-test (push) Successful in 2m9s
CI / frontend-test (push) Successful in 18s
CI / rust-test (push) Successful in 26s
00d5dfdf79
docs: i18n roadmap for Svelte 5 desktop frontend — typesafe-i18n, 5-phase plan
All checks were successful
CI / backend-test (pull_request) Successful in 2m9s
CI / frontend-test (pull_request) Successful in 18s
CI / rust-test (pull_request) Successful in 26s
a8491f40a0
feat(i18n): Phase 3 - fix relative import path in DashboardPage.svelte and update E2E assertions
All checks were successful
CI / backend-test (pull_request) Successful in 2m8s
CI / frontend-test (pull_request) Successful in 18s
CI / rust-test (pull_request) Successful in 27s
da209147e2
Merge pull request #16 - feat: internationalize Svelte 5 frontend using typesafe-i18n
All checks were successful
CI / backend-test (push) Successful in 2m4s
CI / frontend-test (push) Successful in 19s
CI / rust-test (push) Successful in 27s
a88d512c43
- Add reactive entity reloading and key-based component isolation for ListPage
- Update column definitions and renderers for users, roles, permissions, items, bags, and departments
- Add alias for locations to states endpoint in API client
- Add Playwright E2E test verifying entity data isolation and empty-state handling
- Add public connectivity/version endpoint to backend SecurityConfig and TestController
fix(review): address PR review comments
All checks were successful
CI / backend-test (pull_request) Successful in 2m12s
CI / frontend-test (pull_request) Successful in 20s
CI / rust-test (pull_request) Successful in 29s
9876dcec7b
- Retargeted base branch from master to dev
- Dropped agent skills symlinks and scripts/demo-espanol.sh from PR scope
- Parameterized E2E test URLs and credentials using env vars with localhost defaults
- Corrected TestController version default to 1.12.1-SNAPSHOT and differentiated info() diagnostics
- Removed unreachable displacements columnDef and extracted getEndpoint helper in ListPage
Merge pull request 'Fix table system data loading and navigation isolation' (#17) from fix/table-views-data-persistence-and-loading into dev
Some checks failed
CI / frontend-test (push) Waiting to run
CI / rust-test (push) Waiting to run
CI / backend-test (push) Has been cancelled
ddb44da1c5
feat(agents): add Matt's agent skills collection and Claude Code skill links
All checks were successful
CI / backend-test (push) Successful in 2m11s
CI / frontend-test (push) Successful in 21s
CI / rust-test (push) Successful in 31s
CI / backend-test (pull_request) Successful in 2m11s
CI / frontend-test (pull_request) Successful in 20s
CI / rust-test (pull_request) Successful in 28s
d0130466c4
Author
Owner

Assessment — recommend closing and re-splitting, don't pull as-is

Thanks for putting this together. One concrete blocker here needs its own fix before this lands on master, and the rest is just scoping. I'd close this PR and split the work rather than pull the whole 1406-file promotion in one shot.

Blocker: 1.1 GB of Rust build artifacts are being committed to master

The diff adds 1030 files under desktop/pure-logic/target/ — about 1.1 GB on disk, 2265 files on the filesystem. This is the only thing I'd treat as a hard "don't merge" issue:

  • master currently has 231 tracked files; this PR pushes it to ~1462, with build artifacts making up 70% of the repo.
  • They came in back in 694f3b0 (the "extract tauri pure-logic to standalone crate" commit) and have been tracked on dev since.
  • .gitignore already has target/ and **/target/, but those rules only apply to untracked files. Once a file is tracked, gitignore can't help — so this needs git rm -r --cached desktop/pure-logic/target plus a commit, not another ignore rule.

Every clone (and every CI run) pays for that 1.1 GB for no reason, and it's the same root cause as the oversized diffs we've been tripping over.

Why split instead of one mega-merge

The PR is four independent workstreams under a "release" label:

  1. Table fixes + diagnostics (the already-reviewed PR #17).
  2. i18n (typesafe-i18n + generated types).
  3. Test infra + CI (the commit that accidentally dragged in target/).
  4. Agent tooling (.agents/skills/ + .claude/skills/ symlinks).

For a one-team effort this level of batching is understandable — there's no need to enforce heavy process here. But splitting at least the build-artifact cleanup into its own fix branch is worth it, because it's the one thing that would otherwise be permanently baked into master's history. The rest can reasonably ride together if you want to keep the release simple.

What's already clean (not blockers)

  • CI is green: backend, frontend, and rust tests all pass on the head commit.
  • No real secrets in the diff — the JWT_SECRET is a clearly-labeled test value, and the rest of the secret-scan hits are documentation text.
  • The earlier dangling-symlink issue is resolved: .agents/skills is now tracked, so the .claude/skills/* links resolve.
  • staged_diff*.patch, pom.xml.versionsBackup, and test_mcp.js are being deleted, which is good cleanup.
  1. Close this PR.
  2. Cut a small fix branch off dev that runs git rm -r --cached desktop/pure-logic/target (plus any other stray build output), and merge that back into dev.
  3. Re-open the dev → master release after the artifacts are out of history — or bring master up in a couple of smaller slices if that's easier to review.

Nothing else here is urgent; it's just the target/ commit that should not reach master.

## Assessment — recommend closing and re-splitting, don't pull as-is Thanks for putting this together. One concrete blocker here needs its own fix before this lands on `master`, and the rest is just scoping. I'd close this PR and split the work rather than pull the whole 1406-file promotion in one shot. ### Blocker: 1.1 GB of Rust build artifacts are being committed to `master` The diff **adds 1030 files under `desktop/pure-logic/target/`** — about 1.1 GB on disk, 2265 files on the filesystem. This is the only thing I'd treat as a hard "don't merge" issue: - `master` currently has **231 tracked files**; this PR pushes it to ~1462, with build artifacts making up **70% of the repo**. - They came in back in `694f3b0` (the "extract tauri pure-logic to standalone crate" commit) and have been tracked on `dev` since. - `.gitignore` already has `target/` and `**/target/`, but those rules only apply to *untracked* files. Once a file is tracked, gitignore can't help — so this needs `git rm -r --cached desktop/pure-logic/target` plus a commit, not another ignore rule. Every clone (and every CI run) pays for that 1.1 GB for no reason, and it's the same root cause as the oversized diffs we've been tripping over. ### Why split instead of one mega-merge The PR is four independent workstreams under a "release" label: 1. Table fixes + diagnostics (the already-reviewed PR #17). 2. i18n (typesafe-i18n + generated types). 3. Test infra + CI (the commit that accidentally dragged in `target/`). 4. Agent tooling (`.agents/skills/` + `.claude/skills/` symlinks). For a one-team effort this level of batching is understandable — there's no need to enforce heavy process here. But splitting at least the **build-artifact cleanup** into its own fix branch is worth it, because it's the one thing that would otherwise be permanently baked into `master`'s history. The rest can reasonably ride together if you want to keep the release simple. ### What's already clean (not blockers) - CI is green: backend, frontend, and rust tests all pass on the head commit. - No real secrets in the diff — the `JWT_SECRET` is a clearly-labeled test value, and the rest of the secret-scan hits are documentation text. - The earlier dangling-symlink issue is resolved: `.agents/skills` is now tracked, so the `.claude/skills/*` links resolve. - `staged_diff*.patch`, `pom.xml.versionsBackup`, and `test_mcp.js` are being deleted, which is good cleanup. ### Recommended next step 1. Close this PR. 2. Cut a small fix branch off `dev` that runs `git rm -r --cached desktop/pure-logic/target` (plus any other stray build output), and merge that back into `dev`. 3. Re-open the `dev → master` release after the artifacts are out of history — or bring `master` up in a couple of smaller slices if that's easier to review. Nothing else here is urgent; it's just the `target/` commit that should not reach `master`.
chore: remove tracked desktop/pure-logic/target build artifacts from git index
All checks were successful
CI / backend-test (push) Successful in 2m2s
CI / frontend-test (push) Successful in 15s
CI / rust-test (push) Successful in 23s
CI / backend-test (pull_request) Successful in 2m2s
CI / frontend-test (pull_request) Successful in 14s
CI / rust-test (pull_request) Successful in 24s
6b5efcd996
Author
Owner

Resolution to Assessment:

  1. Blocker Resolved: Untracked and removed all 1030 desktop/pure-logic/target/ build artifact files from the git index on dev via 6b5efcd.
  2. Diff Streamlined: The changed files count on this PR dropped from 1,406 files down to 376 files.
  3. Artifact Audit: Verified via git ls-files that no other build targets, node_modules, dist/, or temporary logs are tracked.
  4. Validation: All backend tests, frontend unit tests (Vitest), and Playwright E2E suites continue to pass cleanly.
## Resolution to Assessment: 1. **Blocker Resolved**: Untracked and removed all 1030 `desktop/pure-logic/target/` build artifact files from the git index on `dev` via `6b5efcd`. 2. **Diff Streamlined**: The changed files count on this PR dropped from **1,406 files** down to **376 files**. 3. **Artifact Audit**: Verified via `git ls-files` that no other build targets, `node_modules`, `dist/`, or temporary logs are tracked. 4. **Validation**: All backend tests, frontend unit tests (Vitest), and Playwright E2E suites continue to pass cleanly.
gabogg merged commit c2aa3ec5d3 into master 2026-08-21 17:15:05 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
PCivil/inventory-system!18
No description provided.