Skip to content

Enhance backend API with project management features and documentation - #31

Merged
MathCunha16 merged 5 commits into
feature/backend/refactor-to-golangfrom
feture/go-project-use-cases
Aug 3, 2026
Merged

Enhance backend API with project management features and documentation#31
MathCunha16 merged 5 commits into
feature/backend/refactor-to-golangfrom
feture/go-project-use-cases

Conversation

@MathCunha16

@MathCunha16 MathCunha16 commented Aug 1, 2026

Copy link
Copy Markdown
Owner

🚀 Feature: Complete Project Module Implementation, Web Adapters, Testing & API Docs

📌 Summary

This PR delivers the complete implementation of the Project module following Hexagonal Architecture, including CRUD use cases, HTTP adapters, middleware, OpenAPI documentation, database migration updates, and comprehensive unit/integration tests.


✨ What's Included

⚙️ Domain & Use Cases (internal/usecase/)

Implemented ProjectUseCase with:

  • Create
  • GetByID
  • GetAll (paginated)
  • Update (PATCH with partial updates)
  • Archive / Unarchive
  • Delete

Added:

  • CreateProjectCommand
  • UpdateProjectCommand

with validation tags (required, min, max, hexcolor).


🌐 Web Layer (internal/adapter/in/web/)

Organized into:

  • handler/
  • middleware/
  • common/

ProjectHandler

  • RESTful CRUD endpoints
  • Location: /api/v1/projects/{id} on 201 Created
  • Request binding
  • UUID parsing
  • Standardized JSON responses

Router

  • Routes grouped under /api/v1/projects
  • Dynamic port binding:
    • :8080 (APP_ENV=dev)
    • :0 (desktop releases)

Middleware

  • AuthMiddleware

    • Validates DEVAULTY_INTERNAL_TOKEN
    • Uses dev-token in development
  • CORSMiddleware

    • Handles CORS
    • Supports OPTIONS preflight requests

Common

Added PaginationQuery for standardized page and size query binding.


💾 Persistence & Migrations

Updated migrations 000002000008:

  • created_at and updated_at now use DATETIME
  • Native time.Time support
  • Removed the need for custom time converters

📚 OpenAPI & Scalar

Added:

  • Complete OpenAPI 3.0 specification (docs/openapi.yaml)
  • Scalar API Reference (/docs) in development mode

Documentation includes:

  • DEVAULTY_INTERNAL_TOKEN
  • Default dev-token authentication

🧪 Testing

Unit Tests

  • internal/usecase/project_usecase_test.go
  • 11 mock-driven unit tests
  • Success and failure scenarios

HTTP Integration Tests

Added reusable SQLite test harness:

  • test_helper_test.go

Implemented 18 integration tests covering:

  • ✅ Create
  • ✅ Get
  • ✅ GetAll
  • ✅ Update
  • ✅ Archive
  • ✅ Unarchive
  • ✅ Delete
  • ✅ Validation errors
  • ✅ Invalid UUID
  • ✅ Unauthorized
  • ✅ Not Found
  • ✅ Duplicate archive state

Also introduced app.DoRequest to reduce duplicated request setup.


🛠️ Build

Updated .gitignore root rules to correctly track:

cmd/api/main.go

✅ Verification

Run:

go test ./... -v

Output:

ok  devaulty-backend/internal/adapter/in/web/handler  0.050s
ok  devaulty-backend/internal/usecase                 0.007s

Additional verification:

  • go vet ./...
  • ✅ 100% passing test suite

Summary by CodeRabbit

  • Novos Recursos

    • Adicionada API para criar, consultar, atualizar, excluir, arquivar e desarquivar projetos.
    • Incluídas paginação, autenticação por token interno, endpoint de saúde e suporte a CORS.
    • Disponibilizada documentação interativa da API em ambiente de desenvolvimento.
  • Correções

    • Ajustado o armazenamento de datas e horários para maior consistência.
  • Testes

    • Adicionados testes para operações de projetos, validações, autenticação e cenários de erro.

- Implement main.go as the entry point for the backend API
- Add `ProjectUseCase` with CRUD, archive, and unarchive methods for projects
- Write unit tests for the project use case with a mock repository
- Update go.mod and go.sum with new dependencies for testing and validation
…tions

- Extend `main.go` with server setup, project routing, and UUID token handling
- Implement `ProjectHandler` for project creation and retrieval via Gin
- Add CORS and auth middleware to secure and facilitate API requests
- Update database migrations to use `DATETIME` for timestamps
- Add validation to `CreateProjectCommand`
- Update dependencies in `go.mod` and `go.sum` for API and middleware functionality
…e and enhance test coverage

- Move `ProjectHandler` to `handler` package for better modularity
- Add comprehensive test coverage for project handler, including success and failure cases
- Introduce `GetAll`, `Update`, `Archive`, `Unarchive`, and `Delete` methods to `ProjectHandler`
- Implement pagination support via `PaginationQuery` in `GetAll`
- Adjust router and test helper to reflect structural changes
… routes

- Introduce `/docs` and `/openapi.yaml` routes for hosting API documentation
- Implement `registerDocsRoutes` function to serve documentation in development environment
- Add dependency `go-scalar-api-reference` for generating interactive API reference
- Include OpenAPI YAML specification for Devaulty API
@MathCunha16 MathCunha16 self-assigned this Aug 1, 2026
@MathCunha16 MathCunha16 added documentation Improvements or additions to documentation enhancement New feature or request Backend Backend feature or modification labels Aug 1, 2026
@coderabbitai

coderabbitai Bot commented Aug 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: e8ff7f77-bd32-4bbf-870d-5da39a75ceee

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 11

🧹 Nitpick comments (1)
backend-go/go.mod (1)

14-14: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Classifique as dependências diretamente importadas no bloco principal.

Mova github.com/MarceloPetrucio/go-scalar-api-reference e github.com/gin-gonic/gin para o bloco principal de require. Execute go mod tidy e inclua as atualizações correspondentes em go.sum.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend-go/go.mod` at line 14, Move
github.com/MarceloPetrucio/go-scalar-api-reference and github.com/gin-gonic/gin
from the indirect dependency block into the primary require block in go.mod,
remove any resulting duplicate entries, then run go mod tidy and commit the
corresponding go.sum updates.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@backend-go/cmd/api/main.go`:
- Around line 31-35: Remove the production exposure of devaultyInternalToken
from the log.Printf call in main. Only log or otherwise expose the full token
when APP_ENV is "dev"; for other environments, do not emit the token and
preserve its use by AuthMiddleware through the existing router configuration.
- Around line 46-49: Altere a definição de addr em main para fazer bind
exclusivamente ao loopback, substituindo tanto o endereço padrão quanto o usado
quando APP_ENV é "dev" por endereços locais; preserve a porta aleatória no modo
padrão e a porta 8080 no modo dev.
- Line 19: Atualize o fluxo de inicialização em main usando configuração para
tornar os caminhos do banco e das migrations ajustáveis, resolvendo-os de forma
independente do diretório de trabalho atual. Garanta que o diretório pai do
banco seja criado antes de chamar persistence.InitDB e preserve os caminhos
configurados para o banco SQLite e as migrations.

In `@backend-go/docs/openapi.yaml`:
- Around line 100-104: Alinhe o pattern do campo color no schema OpenAPI com a
validação de CreateProjectCommand: aceite também os formatos `#RGBA` e `#RRGGBBAA`,
mantendo os formatos `#RGB` e `#RRGGBB`, ou restrinja o validador hexcolor para
aceitar somente 3 e 6 dígitos. Garanta que ambos os lados aceitem exatamente o
mesmo conjunto de formatos.

In `@backend-go/internal/adapter/in/web/common/pagination_query.go`:
- Around line 1-6: Limite os parâmetros de paginação em PaginationQuery: valide
PageNumber com binding gte=0 e PageSize com binding gte=1 e um limite máximo
consistente, como 100. Em backend-go/docs/openapi.yaml, atualize o schema
ProjectPage para incluir maxItems em content e maximum no parâmetro size, usando
o mesmo limite aplicado no backend.

In `@backend-go/internal/adapter/in/web/handler/project_handler.go`:
- Around line 145-159: Update the success response in ProjectHandler.Delete to
use c.Status(http.StatusNoContent) instead of c.JSON, ensuring the 204 response
has no JSON body while preserving the existing error handling.
- Around line 129-143: In ProjectHandler.Unarchive, change the success response
message capitalization to match Archive’s existing "Project archived"
convention, preserving the current status and response structure.

In `@backend-go/internal/adapter/in/web/middleware/auth_middleware.go`:
- Around line 9-18: Atualize AuthMiddleware para rejeitar imediatamente uma
configuração com apiToken vazio, independentemente do header recebido. Substitua
a comparação direta de strings por crypto/subtle.ConstantTimeCompare, comparando
os valores como bytes e mantendo a resposta Unauthorized para tokens ausentes ou
inválidos.

In `@backend-go/internal/adapter/in/web/middleware/cors_middleware.go`:
- Around line 9-18: Update CORSMiddleware to stop reflecting arbitrary Origin
values: use an explicit, environment-configured allowlist and set
Access-Control-Allow-Origin only for matching origins, or remove
Access-Control-Allow-Credentials if browser credentials are not required.
Preserve credentialed CORS only when paired with validated allowlisted origins.

In `@backend-go/internal/usecase/project_usecase.go`:
- Around line 61-133: Diferencie projetos inexistentes dos demais erros: em
backend-go/internal/usecase/project_usecase.go#L61-L133, defina
ErrProjectNotFound e reutilize-o nos caminhos project == nil de Update, Archive
e Unarchive. Em
backend-go/internal/adapter/in/web/handler/project_handler.go#L85-L143, faça os
handlers Update, Archive e Unarchive verificarem errors.Is(err,
usecase.ErrProjectNotFound) e retornarem 404; mantenha 400 para os demais erros.
- Around line 25-31: Adicione tags de validação binding aos campos Name,
Description, Icon e Color de UpdateProjectCommand, alinhando-as às restrições
correspondentes de CreateProjectCommand: Name entre 2 e 255 caracteres,
Description entre 1 e 255, Icon com no máximo 100 e Color validado como
hexcolor. Preserve os ponteiros e a tag json existentes.

---

Nitpick comments:
In `@backend-go/go.mod`:
- Line 14: Move github.com/MarceloPetrucio/go-scalar-api-reference and
github.com/gin-gonic/gin from the indirect dependency block into the primary
require block in go.mod, remove any resulting duplicate entries, then run go mod
tidy and commit the corresponding go.sum updates.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cd777550-ba54-438e-bc48-2f11904351d2

📥 Commits

Reviewing files that changed from the base of the PR and between c8a0913 and 4487827.

⛔ Files ignored due to path filters (1)
  • backend-go/go.sum is excluded by !**/*.sum
📒 Files selected for processing (20)
  • backend-go/.gitignore
  • backend-go/cmd/api/main.go
  • backend-go/docs/openapi.yaml
  • backend-go/go.mod
  • backend-go/internal/adapter/in/web/common/pagination_query.go
  • backend-go/internal/adapter/in/web/handler/project_handler.go
  • backend-go/internal/adapter/in/web/handler/project_handler_test.go
  • backend-go/internal/adapter/in/web/handler/test_helper_test.go
  • backend-go/internal/adapter/in/web/middleware/auth_middleware.go
  • backend-go/internal/adapter/in/web/middleware/cors_middleware.go
  • backend-go/internal/adapter/in/web/router.go
  • backend-go/internal/usecase/project_usecase.go
  • backend-go/internal/usecase/project_usecase_test.go
  • backend-go/migrations/000002_create_projects_table.up.sql
  • backend-go/migrations/000003_create_snippets_table.up.sql
  • backend-go/migrations/000004_create_links_table.up.sql
  • backend-go/migrations/000005_create_problems_table.up.sql
  • backend-go/migrations/000006_create_notes_table.up.sql
  • backend-go/migrations/000007_create_credentials_table.up.sql
  • backend-go/migrations/000008_create_tags_table.up.sql

Comment thread backend-go/cmd/api/main.go
Comment thread backend-go/cmd/api/main.go Outdated
Comment thread backend-go/cmd/api/main.go Outdated
Comment thread backend-go/docs/openapi.yaml
Comment thread backend-go/internal/adapter/in/web/common/pagination_query.go
Comment thread backend-go/internal/adapter/in/web/handler/project_handler.go
Comment thread backend-go/internal/adapter/in/web/middleware/auth_middleware.go
Comment thread backend-go/internal/adapter/in/web/middleware/cors_middleware.go
Comment thread backend-go/internal/usecase/project_usecase.go
Comment thread backend-go/internal/usecase/project_usecase.go
…ware

- Add detailed error handling in project APIs for "not found" and invalid states
- Update pagination validation with binding rules for `PageNumber` and `PageSize`
- Improve CORS middleware with restricted allowed origins list
- Replace direct string comparisons with constant-time comparison in auth middleware
- Extend OpenAPI specification with validation, error responses, and pagination constraints
- Enhance test coverage for new validation and error scenarios
@MathCunha16
MathCunha16 merged commit a1deebc into feature/backend/refactor-to-golang Aug 3, 2026
1 check passed
@MathCunha16
MathCunha16 deleted the feture/go-project-use-cases branch August 3, 2026 13:55
@coderabbitai coderabbitai Bot mentioned this pull request Aug 9, 2026
MathCunha16 added a commit that referenced this pull request Aug 14, 2026
…dules (#40)

* feat: integrate Tauri framework with initial splash screen, IPC commands, and automatic version synchronization script

* refactor: migrate to Tauri-based packaging by bundling the backend JAR and removing legacy Java desktop components.

* feat(backend-go): setup initial sql migrations and domain models" -m "- Initialize Go module (go.mod, go.sum) and
  project structure
    - Add 9 SQL database migrations mirroring Java Liquibase changesets
    - Add domain entity models (BaseEntity, AppSetting, Project, Snippet, Link, Problem, Note, Credential, Tag, ItemTag)
    - Add .gitignore for Go backend"

* Feat: (GO) add repository interfaces and implement persistence layer (#30)

* feat(backend-go): add repository interfaces for domain models

* feat(backend-go): implement persistence layer and adapters for repositories

* fix(backend-go): improve error handling and update repository method consistency

- Handle `sql.ErrNoRows` in `FindByID` to return `nil` instead of error.
- Standardize method naming (`ExistsById` → `ExistsByID`).
- Simplify and optimize `NewPage` calculations.
- Align `ItemTagRepository` methods with additional `projectID` parameter for consistency and data integrity.

* Enhance backend API with project management features and documentation (#31)

* feat(backend-go): add API entry point, project use case, and unit tests

- Implement main.go as the entry point for the backend API
- Add `ProjectUseCase` with CRUD, archive, and unarchive methods for projects
- Write unit tests for the project use case with a mock repository
- Update go.mod and go.sum with new dependencies for testing and validation

* feat(backend-go): add project API with middleware, routing, and migrations

- Extend `main.go` with server setup, project routing, and UUID token handling
- Implement `ProjectHandler` for project creation and retrieval via Gin
- Add CORS and auth middleware to secure and facilitate API requests
- Update database migrations to use `DATETIME` for timestamps
- Add validation to `CreateProjectCommand`
- Update dependencies in `go.mod` and `go.sum` for API and middleware functionality

* refactor(backend-go): reorganize project handler into separate package and enhance test coverage

- Move `ProjectHandler` to `handler` package for better modularity
- Add comprehensive test coverage for project handler, including success and failure cases
- Introduce `GetAll`, `Update`, `Archive`, `Unarchive`, and `Delete` methods to `ProjectHandler`
- Implement pagination support via `PaginationQuery` in `GetAll`
- Adjust router and test helper to reflect structural changes

* feat(backend-go): add OpenAPI documentation hosting and API reference routes

- Introduce `/docs` and `/openapi.yaml` routes for hosting API documentation
- Implement `registerDocsRoutes` function to serve documentation in development environment
- Add dependency `go-scalar-api-reference` for generating interactive API reference
- Include OpenAPI YAML specification for Devaulty API

* feat(backend-go): enhance error handling, validation, and CORS middleware

- Add detailed error handling in project APIs for "not found" and invalid states
- Update pagination validation with binding rules for `PageNumber` and `PageSize`
- Improve CORS middleware with restricted allowed origins list
- Replace direct string comparisons with constant-time comparison in auth middleware
- Extend OpenAPI specification with validation, error responses, and pagination constraints
- Enhance test coverage for new validation and error scenarios

* Feat: Complete Snippet Module Implementation, Integration Tests & API Docs (#32)

* feat(backend-go): add Snippet use case with tests and repository adjustments

- Implement `SnippetUseCase` for Create, Read, Update, and Delete operations.
- Add unit tests for Snippet use case.
- Modify repository to support project-scoped Snippet operations with `FindByIDAndProjectID` and `DeleteByIDAndProjectID`.
- Refactor auxiliary functions to ensure project existence.

* feat(backend-go): add SnippetHandler with tests and OpenAPI documentation

- Implement SnippetHandler for Create, Read, Update, and Delete endpoints.
- Add integration tests for SnippetHandler.
- Extend OpenAPI documentation to include Snippet operations.
- Introduce `ExtractUUIDParam` helper for parameter validation.

* reafactor(backend-go): improve error handling and extend delete operations

- Enhance error responses in ProjectHandler and SnippetHandler with proper status codes and logging.
- Modify repository delete methods to return success status and adjust use cases accordingly.
- Update integration and unit tests to validate deletion behavior and persistence.
- Extend OpenAPI documentation with 500 error responses and specific error scenarios for delete endpoints.

* Feat: Complete Link Module Implementation, Integration Tests & OpenAPI Documentation (#33)

* reafactor(backend-go): improve error handling and extend delete operations

- Enhance error responses in ProjectHandler and SnippetHandler with proper status codes and logging.
- Modify repository delete methods to return success status and adjust use cases accordingly.
- Update integration and unit tests to validate deletion behavior and persistence.
- Extend OpenAPI documentation with 500 error responses and specific error scenarios for delete endpoints.

* docs(openapi): remove nullable attribute from several fields

* Feat: Complete Problem Module Implementation (#34)

* feat(backend-go): implement problem use case with repository and unit tests

- Added `ProblemUseCase` handling CRUD operations and business logic for problems.
- Implemented `Create`, `Update`, `UpdateStatus`, `GetByID`, `GetAllByProjectID`, and `Delete` methods.
- Updated `ProblemRepository` to include project-scoped methods (`FindByIDAndProjectID`, `DeleteByIDAndProjectID`, `ExistsByIDAndProjectID`).
- Added comprehensive unit tests to validate problem use case functionality.

* feat(backend-go): add problem handler, routes, and integration tests

- Implemented `ProblemHandler` to handle HTTP operations for problems.
- Added CRUD and pagination routes for problem management under `/projects/:project_id/problems`.
- Extended OpenAPI documentation with schemas and endpoints for problems.
- Updated integration test suite with comprehensive tests for problem API operations.
- Modified `ProblemUseCase` and repository types to include summary support.

* Feat: Complete Tag & ItemTag Module Implementation (#35)

* feat(tag): enhance tag repository methods and add use cases

- Update repository methods to include project scope (`FindByIDAndProjectID`, `DeleteByIDAndProjectID`).
- Implement `TagUseCase` with create, update, delete, and search operations.
- Add unit tests for `TagUseCase` methods.
- Introduce `ItemTagUseCase` for associating/disassociating tags with items.

* feat(usecase): integrate item-tag repository into use cases

- Extend `ProblemUseCase`, `SnippetUseCase`, and `LinkUseCase` to manage item-tag associations.
- Remove all related tags during deletion of problems, snippets, and links.
- Update constructors and unit tests to include `ItemTagRepository`.
- Adjust API handlers and test helpers to support the new dependency.

* feat(handler): implement tag and item-tag HTTP handlers with tests

- Add `TagHandler` to manage CRUD operations and search functionality for tags.
- Introduce `ItemTagHandler` to handle tag associations and disassociations with items.
- Update `router.go` and initialization logic to register new routes and handlers.
- Add comprehensive unit tests for both handlers covering success and error scenarios.

* refactor(dto): replace inline command structs with DTO package

- Move command structs (`CreateProblemCommand`, `UpdateProblemCommand`, etc.) to `dto` package for better reuse and consistency.
- Update use cases, handlers, and tests to use the new DTO package.
- Refactor logic in related use case methods (`Create`, `Update`, etc.) to map domain models to view models.
- Adjust unit tests to align with the DTO-based refactor.

* docs: update security and tag architecture docs for Go backend

- Revise local development token documentation to align with Go backend implementation.
- Update token naming conventions, middleware logic, and local testing instructions.
- Rewrite tag system architecture docs to reflect Go backend design, including database schema, use cases, and DTO changes.

* refactor(usecase): update tag use cases to return DTOs and enhance item-tag handling

- Refactor `TagUseCase` methods to return `TagView` DTOs instead of domain models.
- Add mapping functions to convert domain models to DTOs (`mapTagToView`, `mapTagsToViews`) for consistency.
- Extend `ItemTagUseCase` to properly handle duplicate item IDs during tag associations.
- Update related tests to reflect DTO usage and improved item-tag logic.
- Introduce better error logging for tag removal failures across use cases (`LinkUseCase`, `SnippetUseCase`, `ProblemUseCase`).
- Modify OpenAPI spec to reflect supported item types for tag operations.

* Feat: implement note module (#36)

* feat(backend-go): implement project-scoped note use cases and repository updates

- Update `NoteRepository` with project-scoped methods:
  - `FindByIDAndProjectID`
  - `DeleteByIDAndProjectID`
- Introduce `NoteUseCase` for CRUD operations on notes, ensuring project context.
- Add DTOs (`CreateNoteCommand`, `NoteView`, `NoteSummary`) for note-related operations.
- Update `ItemTagUseCase` to support `ItemTypeNote`.

* feat(backend-go): enhance note use cases with update and delete operations, add associated tests

- Implement `NoteUseCase.Update` and `NoteUseCase.Delete` methods.
- Update `NoteUseCase.GetByID` to improve error handling and tag retrieval.
- Integrate `NoteRepository` into `ItemTagUseCase`.
- Add mock repository for notes in tests.
- Adjust `NoteView` and `NoteSummary` DTO fields for consistency.
- Add unit tests for note use cases.

* feat(backend-go): add NoteHandler for managing notes with full CRUD operations

- Implement `NoteHandler` for handling notes within project context.
- Add router mappings and integrate `NoteHandler` into the API.
- Update test helpers and add extensive tests for note routes and handler logic.

* feat(api-docs): add OpenAPI documentation for notes management

- Document CRUD operations for notes: create, read (single and paginated), update, and delete.
- Add schemas for `Note`, `NoteSummary`, `NoteSummaryPage`, `CreateNoteCommand`, and `UpdateNoteCommand`.
- Extend `ItemType` enum with `NOTE`.
- Define paths for `/projects/{project_id}/notes` and `/projects/{project_id}/notes/{note_id}`.

* fix(backend-go): improve error logging in NoteHandler and update OpenAPI docs for NOTE item type

- Log detailed error information in `NoteHandler.Create` on internal server errors.
- Extend OpenAPI `ItemType` descriptions to include support for `NOTE` in tag association endpoints.

* feat:  Vault Security Engine & AppSettings (#37)

* feat(backend-go): implement secure vault use case and key management

- Add VaultUseCase to manage master password setup, unlocking, and session status.
- Introduce MasterKeySession and Argon2KeyDeriver adapters for secure key handling.
- Add DTOs for handling API interactions related to the vault and app settings.
- Implement unit tests for VaultUseCase methods.
- Upgrade dependencies in go.mod and go.sum for crypto and security improvements.

* feat(backend-go): add SecurityHandler and integrate Vault APIs

- Introduce SecurityHandler to manage master password setup, unlocking, session status, and vault locking.
- Extend Gin router with security-related routes.
- Update DTO validation for master password constraints.
- Add OpenAPI documentation for security endpoints.
- Implement unit tests for SecurityHandler functions.
- Refactor memory hygiene guide to align with backend-go security standards.

* refactor(backend-go): improve memory handling and add comprehensive security tests

- Enhance memory hygiene in SecurityHandler by ensuring proper password reference clearing.
- Add extensive unit tests for Argon2KeyDeriver and MasterKeySessionHolder for key derivation, salt generation, and session management.
- Simplify VaultUseCase by consolidating app setting save operations with `SaveMasterPasswordSettings`.
- Improve synchronization and defensive copying in MasterKeySessionHolder.
- Introduce transaction handling and constraints for saving master password settings in AppSettingRepository.

* Feat: Credentials Module Implementation & AES-256-GCM Security Integration (#38)

* feat(backend-go): implement AES-GCM crypto adapter and related DTOs

- Add AES-GCM encryption/decryption implementation (`AESGCMCryptoAdapter`)
- Create Crypto port interface for encryption abstraction
- Include tests for AES-GCM encryption/decryption scenarios
- Add credential-related DTOs for command and view models
- Update `CredentialRepositoryAdapter` to refine query for credential retrieval

* **feat(backend-go): add credential use case with unit tests and repository enhancements**

- Implement `CredentialUseCase` for CRUD operations, including:
  - `Create`, `GetById`, `GetAllByProjectID`, `Update`, and `Delete`.
- Add corresponding unit tests to ensure robustness.
- Extend `CredentialRepository` interface for project-scoped queries.
- Update `CredentialRepositoryAdapter` with project-specific operations for `FindByID` and `DeleteByID`.

* **feat(backend-go): add CredentialHandler and API routes for credential management**

- Introduced `CredentialHandler` with CRUD operations (`Create`, `GetAll`, `GetById`, `Update`, `Delete`).
- Mapped routes under `/projects/:project_id/credentials`.
- Updated dependency injection for `CredentialHandler` in `main.go`.
- Enhanced test coverage with integration tests for credential APIs.

* **feat(backend-go): add VaultAutoLock scheduler to purge expired sessions**

- Introduced `VaultAutoLock` in the `scheduler` package to handle automatic session purging.
- Integrated the scheduler into `main.go` for periodic cleanup of expired sessions.
- Refactored `MasterKeySession` field casing for consistency across the codebase.

* **feat: extend OpenAPI spec to include credential management and secret payload handling**

- Added schemas for `CredentialSecretType`, `CreateCredentialCommand`, `UpdateCredentialCommand`, `CredentialView`, and paginated responses.
- Documented new endpoints under `/projects/{project_id}/credentials` for CRUD operations.
- Updated handling for item types to support `CREDENTIAL`.
- Improved sensitive data marshaling using `SecretBytes` for enhanced memory hygiene.

* **refactor(backend-go): improve test memory hygiene and update credential update logic**

- Refactored unit tests to ensure zeroing of sensitive `masterKey` during runtime.
- Updated `UpdateCredential` to handle partial updates with secret payload merging.
- Improved error messages for decryption failure scenarios.
- Adjusted OpenAPI spec error description for clarity on UUID validation.

* Feature/adapt frontend to golang (#39)

* feat(frontend): adapt REST API client to Go backend

- Update internal security token header to DEVAULTY_INTERNAL_TOKEN
- Adapt error interceptor to handle Go backend error payload format ({ error: string })
- Align MasterPassword setup check response with MasterPasswordSetupRequiredView schema
- Update tag search query parameter to tag_name
- Add tag badges rendering and tag search filtering to Snippets list view

* feat(tauri): integrate native Go backend and optimize memory usage

- Replace Java JRE integration in Tauri Rust shell with native Go sidecar execution
- Implement secure IPC using CSPRNG UUID token and stdout stream handshake
- Embed SQL migrations inside Go binary via go:embed for a self-contained executable
- Reduce Go backend RAM footprint down to 19MB via Gin ReleaseMode and GOGC tuning
- Implement 3-phase app startup (handshake, HTTP health check, minimum 2s splash screen)
- Update cross-platform build scripts and purge all remaining Java/Spring dependencies

* refactor: migrate backend from Gradle/Java to Go and update CI/CD pipelines to build installers via Tauri

* fix: improve backend data directory resolution, clean build artifacts, and normalize application versioning for Tauri compatibility.

* refactor!: replace Java backend with native Go backend and update Tauri v2 pipeline
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Backend Backend feature or modification documentation Improvements or additions to documentation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant