Skip to content

Feat: Complete Link Module Implementation, Integration Tests & OpenAPI Documentation - #33

Merged
MathCunha16 merged 2 commits into
feature/backend/refactor-to-golangfrom
feature/go-links
Aug 4, 2026
Merged

Feat: Complete Link Module Implementation, Integration Tests & OpenAPI Documentation#33
MathCunha16 merged 2 commits into
feature/backend/refactor-to-golangfrom
feature/go-links

Conversation

@MathCunha16

@MathCunha16 MathCunha16 commented Aug 4, 2026

Copy link
Copy Markdown
Owner

Summary

This Pull Request completes the end-to-end implementation of the Link domain module for the Go backend.

It includes:

  • Complete LinkUseCase implementation and validation
  • REST HTTP Handler improvements
  • Route mapping fixes
  • Comprehensive Unit and Integration Test coverage
  • OpenAPI 3.0 documentation

✨ Key Changes

⚙️ 1. Use Case Layer (internal/usecase/)

link_usecase.go

  • Verified and validated the existing business logic.
  • Ensured alignment with the project's domain architecture.

Unit Tests (link_usecase_test.go)

Added 13 unit tests covering:

  • Create
  • GetByID
  • GetAllByProjectID
  • Update
  • Delete

Coverage includes:

  • Successful operations
  • Project not found
  • Link not found
  • Error paths using testify mocks

🌐 2. Web Layer (internal/adapter/in/web/)

link_handler.go

Implemented several handler improvements:

  • Added missing return statements in error branches to prevent duplicated HTTP responses.

  • Fixed missing return after UUID parsing failures.

  • Standardized context usage with:

    c.Request.Context()
  • Added internal error logging with log.Printf.

router.go

Added the missing route:

DELETE /api/v1/projects/:project_id/links/:link_id

under mapLinkRoutes.


🧪 3. Integration Testing

Updated test_helper_test.go to wire:

  • Link repository
  • Link use case
  • Link handler

into the shared SetupTestApp.

HTTP Integration Tests (link_handler_test.go)

Added 27 integration tests using Gin and an in-memory SQLite database (:memory:).

Coverage includes:

  • Successful creation with Location header validation
  • Retrieval by ID
  • Paginated project listing
  • Tenant/project isolation
  • Partial updates (PATCH)
  • Deletion with persistence validation
  • Invalid UUIDs
  • Invalid URL format
  • Missing required fields
  • Title minimum length validation
  • Page size validation (size > 100)
  • Unauthorized requests (401)
  • Not found responses (404) for projects and links

📚 4. OpenAPI 3.0 Documentation

Updated docs/openapi.yaml with:

Schemas

  • Link
  • CreateLinkCommand
  • UpdateLinkCommand
  • LinkPage

Endpoints

Documented all Link endpoints:

  • POST
  • GET
  • PATCH
  • DELETE

under:

/projects/{project_id}/links
/projects/{project_id}/links/{link_id}

🧪 Test Execution

Run the full test suite:

cd backend-go
go test ./... -v

Run only the Link use case tests:

go test ./internal/usecase/... -v -run TestLink

Run only the Link handler integration tests:

go test ./internal/adapter/in/web/handler/... -v -run TestLinkHandler

Summary by CodeRabbit

  • Novos Recursos

    • Adicionado o gerenciamento de links associados a projetos.
    • É possível criar, listar, consultar, atualizar e excluir links.
    • A listagem oferece paginação e validação de dados, URLs e identificadores.
    • Links são protegidos por autenticação e permanecem isolados entre projetos.
  • Documentação

    • Adicionada documentação da API, incluindo exemplos, respostas de erro e códigos HTTP.
  • Testes

    • Incluídos testes para operações de links, autenticação, validações, paginação e cenários de erro.

…tions

- Enhance error responses in ProjectHandler and SnippetHandler with proper status codes and logging.
- Modify repository delete methods to return success status and adjust use cases accordingly.
- Update integration and unit tests to validate deletion behavior and persistence.
- Extend OpenAPI documentation with 500 error responses and specific error scenarios for delete endpoints.
@MathCunha16 MathCunha16 self-assigned this Aug 4, 2026
@MathCunha16 MathCunha16 added documentation Improvements or additions to documentation enhancement New feature or request Backend Backend feature or modification labels Aug 4, 2026
@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: d80faf59-e9b3-4b1e-8009-2acd25029534

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (3)
backend-go/internal/adapter/in/web/handler/link_handler_test.go (2)

139-149: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Adicione um teste de isolamento entre dois projetos existentes.

Os subtestes usam o UUID zero como projeto inexistente, o que retorna 404 já na verificação ensureProjectExists. O predicado project_id do repositório não é exercitado nesse caminho. O escopo por projeto é a mudança central de FindByIDAndProjectID e DeleteByIDAndProjectID. Crie dois projetos válidos e acesse um link do projeto A pela rota do projeto B. O resultado esperado é 404 em GET, PATCH e DELETE.

♻️ Teste proposto
t.Run("Get failure - link belongs to another project", func(t *testing.T) {
	respOther := app.DoRequest(t, http.MethodPost, "/api/v1/projects", []byte(`{"name":"Other Project"}`), true)
	require.Equal(t, http.StatusCreated, respOther.StatusCode)
	var otherProject map[string]interface{}
	require.NoError(t, json.NewDecoder(respOther.Body).Decode(&otherProject))
	otherProjectID := otherProject["id"].(string)

	urlGet := fmt.Sprintf("/api/v1/projects/%s/links/%s", otherProjectID, linkID)
	resp := app.DoRequest(t, http.MethodGet, urlGet, nil, true)
	assert.Equal(t, http.StatusNotFound, resp.StatusCode)
})
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend-go/internal/adapter/in/web/handler/link_handler_test.go` around lines
139 - 149, Add isolation coverage to the link handler tests by creating a second
valid project and requesting the existing link from that project’s route. In the
relevant test setup, exercise GET, PATCH, and DELETE with the other project ID
while retaining the link’s original project ownership, and assert each returns
404; use the created project’s ID rather than an all-zero UUID so
FindByIDAndProjectID and DeleteByIDAndProjectID are tested.

110-124: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use require nas etapas de preparação dos testes.

O erro do decode é descartado e o valor é convertido com createdProject["id"].(string). Se a criação do projeto ou do link falhar, a conversão gera panic e a causa real não aparece. TestLinkHandler_Create já aplica require nas linhas 20-24. Aplique o mesmo padrão nas preparações de TestLinkHandler_Get, TestLinkHandler_GetAll, TestLinkHandler_Update e TestLinkHandler_Delete.

♻️ Refatoração proposta
 	projectBody := []byte(`{"name":"Parent Project"}`)
 	respProject := app.DoRequest(t, http.MethodPost, "/api/v1/projects", projectBody, true)
+	require.Equal(t, http.StatusCreated, respProject.StatusCode)
 	var createdProject map[string]interface{}
-	_ = json.NewDecoder(respProject.Body).Decode(&createdProject)
+	require.NoError(t, json.NewDecoder(respProject.Body).Decode(&createdProject))
 	projectID := createdProject["id"].(string)
 
 	linkBody := []byte(`{
 		"title": "Seeded Link",
 		"url": "https://example.com"
 	}`)
 	urlCreate := fmt.Sprintf("/api/v1/projects/%s/links", projectID)
 	respLink := app.DoRequest(t, http.MethodPost, urlCreate, linkBody, true)
+	require.Equal(t, http.StatusCreated, respLink.StatusCode)
 	var createdLink map[string]interface{}
-	_ = json.NewDecoder(respLink.Body).Decode(&createdLink)
+	require.NoError(t, json.NewDecoder(respLink.Body).Decode(&createdLink))
 	linkID := createdLink["id"].(string)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend-go/internal/adapter/in/web/handler/link_handler_test.go` around lines
110 - 124, Atualize a preparação dos testes TestLinkHandler_Get,
TestLinkHandler_GetAll, TestLinkHandler_Update e TestLinkHandler_Delete para
usar require em cada etapa de criação do projeto e do link: valide as respostas,
verifique os erros de json.Decoder.Decode e confirme a presença e o tipo dos
campos id antes de utilizá-los. Siga o padrão já aplicado em
TestLinkHandler_Create, evitando descartar erros ou causar panic nas conversões.
backend-go/internal/usecase/link_usecase_test.go (1)

314-367: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Adicione testes para falhas do repositório.

Os 13 testes cobrem sucesso, projeto inexistente e link inexistente. Nenhum teste cobre o retorno de erro do repositório. Nesses caminhos, o caso de uso encapsula o erro com fmt.Errorf("...: %w", err) e o handler responde 500. Um teste por operação confirma que o erro é propagado e que não é convertido em ErrLinkNotFound.

♻️ Exemplo de teste para erro na exclusão
func TestLinkUseCase_Delete_RepositoryError(t *testing.T) {
	mockLinkRepo := new(MockLinkRepository)
	mockProjectRepo := new(MockProjectRepository)
	uc := usecase.NewLinkUseCase(mockLinkRepo, mockProjectRepo)
	ctx := context.Background()

	projectID := uuid.New()
	linkID := uuid.New()
	repoErr := errors.New("db failure")

	mockProjectRepo.On("ExistsByID", ctx, projectID).Return(true, nil)
	mockLinkRepo.On("DeleteByIDAndProjectID", ctx, projectID, linkID).Return(false, repoErr)

	err := uc.Delete(ctx, projectID, linkID)

	assert.ErrorIs(t, err, repoErr)
	assert.NotErrorIs(t, err, usecase.ErrLinkNotFound)
	mockLinkRepo.AssertExpectations(t)
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend-go/internal/usecase/link_usecase_test.go` around lines 314 - 367,
Adicione testes para erros de repositório em cada operação do LinkUseCase
coberta pelo arquivo, incluindo Delete, configurando os mocks para retornar um
erro sentinel. Verifique que o erro original é propagado com assert.ErrorIs e
que não é convertido em ErrLinkNotFound ou outros erros de ausência; mantenha as
expectativas dos repositórios validadas.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@backend-go/docs/openapi.yaml`:
- Around line 415-432: Atualize o schema UpdateLinkCommand removendo nullable:
true de title, url e description, pois campos ausentes já representam “não
alterar” e valores null não produzem alteração na implementação. Preserve os
demais tipos, formatos, limites e exemplos existentes.

---

Nitpick comments:
In `@backend-go/internal/adapter/in/web/handler/link_handler_test.go`:
- Around line 139-149: Add isolation coverage to the link handler tests by
creating a second valid project and requesting the existing link from that
project’s route. In the relevant test setup, exercise GET, PATCH, and DELETE
with the other project ID while retaining the link’s original project ownership,
and assert each returns 404; use the created project’s ID rather than an
all-zero UUID so FindByIDAndProjectID and DeleteByIDAndProjectID are tested.
- Around line 110-124: Atualize a preparação dos testes TestLinkHandler_Get,
TestLinkHandler_GetAll, TestLinkHandler_Update e TestLinkHandler_Delete para
usar require em cada etapa de criação do projeto e do link: valide as respostas,
verifique os erros de json.Decoder.Decode e confirme a presença e o tipo dos
campos id antes de utilizá-los. Siga o padrão já aplicado em
TestLinkHandler_Create, evitando descartar erros ou causar panic nas conversões.

In `@backend-go/internal/usecase/link_usecase_test.go`:
- Around line 314-367: Adicione testes para erros de repositório em cada
operação do LinkUseCase coberta pelo arquivo, incluindo Delete, configurando os
mocks para retornar um erro sentinel. Verifique que o erro original é propagado
com assert.ErrorIs e que não é convertido em ErrLinkNotFound ou outros erros de
ausência; mantenha as expectativas dos repositórios validadas.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 8b101241-f3e7-4f71-83cd-d8a1de45347b

📥 Commits

Reviewing files that changed from the base of the PR and between 786bdfd and 88522dc.

📒 Files selected for processing (10)
  • backend-go/cmd/api/main.go
  • backend-go/docs/openapi.yaml
  • backend-go/internal/adapter/in/web/handler/link_handler.go
  • backend-go/internal/adapter/in/web/handler/link_handler_test.go
  • backend-go/internal/adapter/in/web/handler/test_helper_test.go
  • backend-go/internal/adapter/in/web/router.go
  • backend-go/internal/adapter/out/persistence/link_repository.go
  • backend-go/internal/domain/port/link_repository.go
  • backend-go/internal/usecase/link_usecase.go
  • backend-go/internal/usecase/link_usecase_test.go

Comment thread backend-go/docs/openapi.yaml
@MathCunha16
MathCunha16 merged commit 6ca615e into feature/backend/refactor-to-golang Aug 4, 2026
1 check was pending
@MathCunha16
MathCunha16 deleted the feature/go-links branch August 4, 2026 19:03
MathCunha16 added a commit that referenced this pull request Aug 14, 2026
…dules (#40)

* feat: integrate Tauri framework with initial splash screen, IPC commands, and automatic version synchronization script

* refactor: migrate to Tauri-based packaging by bundling the backend JAR and removing legacy Java desktop components.

* feat(backend-go): setup initial sql migrations and domain models" -m "- Initialize Go module (go.mod, go.sum) and
  project structure
    - Add 9 SQL database migrations mirroring Java Liquibase changesets
    - Add domain entity models (BaseEntity, AppSetting, Project, Snippet, Link, Problem, Note, Credential, Tag, ItemTag)
    - Add .gitignore for Go backend"

* Feat: (GO) add repository interfaces and implement persistence layer (#30)

* feat(backend-go): add repository interfaces for domain models

* feat(backend-go): implement persistence layer and adapters for repositories

* fix(backend-go): improve error handling and update repository method consistency

- Handle `sql.ErrNoRows` in `FindByID` to return `nil` instead of error.
- Standardize method naming (`ExistsById` → `ExistsByID`).
- Simplify and optimize `NewPage` calculations.
- Align `ItemTagRepository` methods with additional `projectID` parameter for consistency and data integrity.

* Enhance backend API with project management features and documentation (#31)

* feat(backend-go): add API entry point, project use case, and unit tests

- Implement main.go as the entry point for the backend API
- Add `ProjectUseCase` with CRUD, archive, and unarchive methods for projects
- Write unit tests for the project use case with a mock repository
- Update go.mod and go.sum with new dependencies for testing and validation

* feat(backend-go): add project API with middleware, routing, and migrations

- Extend `main.go` with server setup, project routing, and UUID token handling
- Implement `ProjectHandler` for project creation and retrieval via Gin
- Add CORS and auth middleware to secure and facilitate API requests
- Update database migrations to use `DATETIME` for timestamps
- Add validation to `CreateProjectCommand`
- Update dependencies in `go.mod` and `go.sum` for API and middleware functionality

* refactor(backend-go): reorganize project handler into separate package and enhance test coverage

- Move `ProjectHandler` to `handler` package for better modularity
- Add comprehensive test coverage for project handler, including success and failure cases
- Introduce `GetAll`, `Update`, `Archive`, `Unarchive`, and `Delete` methods to `ProjectHandler`
- Implement pagination support via `PaginationQuery` in `GetAll`
- Adjust router and test helper to reflect structural changes

* feat(backend-go): add OpenAPI documentation hosting and API reference routes

- Introduce `/docs` and `/openapi.yaml` routes for hosting API documentation
- Implement `registerDocsRoutes` function to serve documentation in development environment
- Add dependency `go-scalar-api-reference` for generating interactive API reference
- Include OpenAPI YAML specification for Devaulty API

* feat(backend-go): enhance error handling, validation, and CORS middleware

- Add detailed error handling in project APIs for "not found" and invalid states
- Update pagination validation with binding rules for `PageNumber` and `PageSize`
- Improve CORS middleware with restricted allowed origins list
- Replace direct string comparisons with constant-time comparison in auth middleware
- Extend OpenAPI specification with validation, error responses, and pagination constraints
- Enhance test coverage for new validation and error scenarios

* Feat: Complete Snippet Module Implementation, Integration Tests & API Docs (#32)

* feat(backend-go): add Snippet use case with tests and repository adjustments

- Implement `SnippetUseCase` for Create, Read, Update, and Delete operations.
- Add unit tests for Snippet use case.
- Modify repository to support project-scoped Snippet operations with `FindByIDAndProjectID` and `DeleteByIDAndProjectID`.
- Refactor auxiliary functions to ensure project existence.

* feat(backend-go): add SnippetHandler with tests and OpenAPI documentation

- Implement SnippetHandler for Create, Read, Update, and Delete endpoints.
- Add integration tests for SnippetHandler.
- Extend OpenAPI documentation to include Snippet operations.
- Introduce `ExtractUUIDParam` helper for parameter validation.

* reafactor(backend-go): improve error handling and extend delete operations

- Enhance error responses in ProjectHandler and SnippetHandler with proper status codes and logging.
- Modify repository delete methods to return success status and adjust use cases accordingly.
- Update integration and unit tests to validate deletion behavior and persistence.
- Extend OpenAPI documentation with 500 error responses and specific error scenarios for delete endpoints.

* Feat: Complete Link Module Implementation, Integration Tests & OpenAPI Documentation (#33)

* reafactor(backend-go): improve error handling and extend delete operations

- Enhance error responses in ProjectHandler and SnippetHandler with proper status codes and logging.
- Modify repository delete methods to return success status and adjust use cases accordingly.
- Update integration and unit tests to validate deletion behavior and persistence.
- Extend OpenAPI documentation with 500 error responses and specific error scenarios for delete endpoints.

* docs(openapi): remove nullable attribute from several fields

* Feat: Complete Problem Module Implementation (#34)

* feat(backend-go): implement problem use case with repository and unit tests

- Added `ProblemUseCase` handling CRUD operations and business logic for problems.
- Implemented `Create`, `Update`, `UpdateStatus`, `GetByID`, `GetAllByProjectID`, and `Delete` methods.
- Updated `ProblemRepository` to include project-scoped methods (`FindByIDAndProjectID`, `DeleteByIDAndProjectID`, `ExistsByIDAndProjectID`).
- Added comprehensive unit tests to validate problem use case functionality.

* feat(backend-go): add problem handler, routes, and integration tests

- Implemented `ProblemHandler` to handle HTTP operations for problems.
- Added CRUD and pagination routes for problem management under `/projects/:project_id/problems`.
- Extended OpenAPI documentation with schemas and endpoints for problems.
- Updated integration test suite with comprehensive tests for problem API operations.
- Modified `ProblemUseCase` and repository types to include summary support.

* Feat: Complete Tag & ItemTag Module Implementation (#35)

* feat(tag): enhance tag repository methods and add use cases

- Update repository methods to include project scope (`FindByIDAndProjectID`, `DeleteByIDAndProjectID`).
- Implement `TagUseCase` with create, update, delete, and search operations.
- Add unit tests for `TagUseCase` methods.
- Introduce `ItemTagUseCase` for associating/disassociating tags with items.

* feat(usecase): integrate item-tag repository into use cases

- Extend `ProblemUseCase`, `SnippetUseCase`, and `LinkUseCase` to manage item-tag associations.
- Remove all related tags during deletion of problems, snippets, and links.
- Update constructors and unit tests to include `ItemTagRepository`.
- Adjust API handlers and test helpers to support the new dependency.

* feat(handler): implement tag and item-tag HTTP handlers with tests

- Add `TagHandler` to manage CRUD operations and search functionality for tags.
- Introduce `ItemTagHandler` to handle tag associations and disassociations with items.
- Update `router.go` and initialization logic to register new routes and handlers.
- Add comprehensive unit tests for both handlers covering success and error scenarios.

* refactor(dto): replace inline command structs with DTO package

- Move command structs (`CreateProblemCommand`, `UpdateProblemCommand`, etc.) to `dto` package for better reuse and consistency.
- Update use cases, handlers, and tests to use the new DTO package.
- Refactor logic in related use case methods (`Create`, `Update`, etc.) to map domain models to view models.
- Adjust unit tests to align with the DTO-based refactor.

* docs: update security and tag architecture docs for Go backend

- Revise local development token documentation to align with Go backend implementation.
- Update token naming conventions, middleware logic, and local testing instructions.
- Rewrite tag system architecture docs to reflect Go backend design, including database schema, use cases, and DTO changes.

* refactor(usecase): update tag use cases to return DTOs and enhance item-tag handling

- Refactor `TagUseCase` methods to return `TagView` DTOs instead of domain models.
- Add mapping functions to convert domain models to DTOs (`mapTagToView`, `mapTagsToViews`) for consistency.
- Extend `ItemTagUseCase` to properly handle duplicate item IDs during tag associations.
- Update related tests to reflect DTO usage and improved item-tag logic.
- Introduce better error logging for tag removal failures across use cases (`LinkUseCase`, `SnippetUseCase`, `ProblemUseCase`).
- Modify OpenAPI spec to reflect supported item types for tag operations.

* Feat: implement note module (#36)

* feat(backend-go): implement project-scoped note use cases and repository updates

- Update `NoteRepository` with project-scoped methods:
  - `FindByIDAndProjectID`
  - `DeleteByIDAndProjectID`
- Introduce `NoteUseCase` for CRUD operations on notes, ensuring project context.
- Add DTOs (`CreateNoteCommand`, `NoteView`, `NoteSummary`) for note-related operations.
- Update `ItemTagUseCase` to support `ItemTypeNote`.

* feat(backend-go): enhance note use cases with update and delete operations, add associated tests

- Implement `NoteUseCase.Update` and `NoteUseCase.Delete` methods.
- Update `NoteUseCase.GetByID` to improve error handling and tag retrieval.
- Integrate `NoteRepository` into `ItemTagUseCase`.
- Add mock repository for notes in tests.
- Adjust `NoteView` and `NoteSummary` DTO fields for consistency.
- Add unit tests for note use cases.

* feat(backend-go): add NoteHandler for managing notes with full CRUD operations

- Implement `NoteHandler` for handling notes within project context.
- Add router mappings and integrate `NoteHandler` into the API.
- Update test helpers and add extensive tests for note routes and handler logic.

* feat(api-docs): add OpenAPI documentation for notes management

- Document CRUD operations for notes: create, read (single and paginated), update, and delete.
- Add schemas for `Note`, `NoteSummary`, `NoteSummaryPage`, `CreateNoteCommand`, and `UpdateNoteCommand`.
- Extend `ItemType` enum with `NOTE`.
- Define paths for `/projects/{project_id}/notes` and `/projects/{project_id}/notes/{note_id}`.

* fix(backend-go): improve error logging in NoteHandler and update OpenAPI docs for NOTE item type

- Log detailed error information in `NoteHandler.Create` on internal server errors.
- Extend OpenAPI `ItemType` descriptions to include support for `NOTE` in tag association endpoints.

* feat:  Vault Security Engine & AppSettings (#37)

* feat(backend-go): implement secure vault use case and key management

- Add VaultUseCase to manage master password setup, unlocking, and session status.
- Introduce MasterKeySession and Argon2KeyDeriver adapters for secure key handling.
- Add DTOs for handling API interactions related to the vault and app settings.
- Implement unit tests for VaultUseCase methods.
- Upgrade dependencies in go.mod and go.sum for crypto and security improvements.

* feat(backend-go): add SecurityHandler and integrate Vault APIs

- Introduce SecurityHandler to manage master password setup, unlocking, session status, and vault locking.
- Extend Gin router with security-related routes.
- Update DTO validation for master password constraints.
- Add OpenAPI documentation for security endpoints.
- Implement unit tests for SecurityHandler functions.
- Refactor memory hygiene guide to align with backend-go security standards.

* refactor(backend-go): improve memory handling and add comprehensive security tests

- Enhance memory hygiene in SecurityHandler by ensuring proper password reference clearing.
- Add extensive unit tests for Argon2KeyDeriver and MasterKeySessionHolder for key derivation, salt generation, and session management.
- Simplify VaultUseCase by consolidating app setting save operations with `SaveMasterPasswordSettings`.
- Improve synchronization and defensive copying in MasterKeySessionHolder.
- Introduce transaction handling and constraints for saving master password settings in AppSettingRepository.

* Feat: Credentials Module Implementation & AES-256-GCM Security Integration (#38)

* feat(backend-go): implement AES-GCM crypto adapter and related DTOs

- Add AES-GCM encryption/decryption implementation (`AESGCMCryptoAdapter`)
- Create Crypto port interface for encryption abstraction
- Include tests for AES-GCM encryption/decryption scenarios
- Add credential-related DTOs for command and view models
- Update `CredentialRepositoryAdapter` to refine query for credential retrieval

* **feat(backend-go): add credential use case with unit tests and repository enhancements**

- Implement `CredentialUseCase` for CRUD operations, including:
  - `Create`, `GetById`, `GetAllByProjectID`, `Update`, and `Delete`.
- Add corresponding unit tests to ensure robustness.
- Extend `CredentialRepository` interface for project-scoped queries.
- Update `CredentialRepositoryAdapter` with project-specific operations for `FindByID` and `DeleteByID`.

* **feat(backend-go): add CredentialHandler and API routes for credential management**

- Introduced `CredentialHandler` with CRUD operations (`Create`, `GetAll`, `GetById`, `Update`, `Delete`).
- Mapped routes under `/projects/:project_id/credentials`.
- Updated dependency injection for `CredentialHandler` in `main.go`.
- Enhanced test coverage with integration tests for credential APIs.

* **feat(backend-go): add VaultAutoLock scheduler to purge expired sessions**

- Introduced `VaultAutoLock` in the `scheduler` package to handle automatic session purging.
- Integrated the scheduler into `main.go` for periodic cleanup of expired sessions.
- Refactored `MasterKeySession` field casing for consistency across the codebase.

* **feat: extend OpenAPI spec to include credential management and secret payload handling**

- Added schemas for `CredentialSecretType`, `CreateCredentialCommand`, `UpdateCredentialCommand`, `CredentialView`, and paginated responses.
- Documented new endpoints under `/projects/{project_id}/credentials` for CRUD operations.
- Updated handling for item types to support `CREDENTIAL`.
- Improved sensitive data marshaling using `SecretBytes` for enhanced memory hygiene.

* **refactor(backend-go): improve test memory hygiene and update credential update logic**

- Refactored unit tests to ensure zeroing of sensitive `masterKey` during runtime.
- Updated `UpdateCredential` to handle partial updates with secret payload merging.
- Improved error messages for decryption failure scenarios.
- Adjusted OpenAPI spec error description for clarity on UUID validation.

* Feature/adapt frontend to golang (#39)

* feat(frontend): adapt REST API client to Go backend

- Update internal security token header to DEVAULTY_INTERNAL_TOKEN
- Adapt error interceptor to handle Go backend error payload format ({ error: string })
- Align MasterPassword setup check response with MasterPasswordSetupRequiredView schema
- Update tag search query parameter to tag_name
- Add tag badges rendering and tag search filtering to Snippets list view

* feat(tauri): integrate native Go backend and optimize memory usage

- Replace Java JRE integration in Tauri Rust shell with native Go sidecar execution
- Implement secure IPC using CSPRNG UUID token and stdout stream handshake
- Embed SQL migrations inside Go binary via go:embed for a self-contained executable
- Reduce Go backend RAM footprint down to 19MB via Gin ReleaseMode and GOGC tuning
- Implement 3-phase app startup (handshake, HTTP health check, minimum 2s splash screen)
- Update cross-platform build scripts and purge all remaining Java/Spring dependencies

* refactor: migrate backend from Gradle/Java to Go and update CI/CD pipelines to build installers via Tauri

* fix: improve backend data directory resolution, clean build artifacts, and normalize application versioning for Tauri compatibility.

* refactor!: replace Java backend with native Go backend and update Tauri v2 pipeline
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Backend Backend feature or modification documentation Improvements or additions to documentation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant