Skip to content

Feat: Complete Problem Module Implementation - #34

Merged
MathCunha16 merged 2 commits into
feature/backend/refactor-to-golangfrom
feature/go-problems
Aug 6, 2026
Merged

Feat: Complete Problem Module Implementation#34
MathCunha16 merged 2 commits into
feature/backend/refactor-to-golangfrom
feature/go-problems

Conversation

@MathCunha16

@MathCunha16 MathCunha16 commented Aug 6, 2026

Copy link
Copy Markdown
Owner

Summary

This Pull Request completes the end-to-end implementation of the Problem domain module for the Go backend.

It includes:

  • Complete ProblemUseCase implementation
  • Optimized list queries using a lightweight ProblemSummary read model
  • REST HTTP Handler improvements
  • Route mapping updates
  • Comprehensive Unit and Integration Test coverage
  • OpenAPI 3.0 documentation

✨ Key Changes

⚙️ 1. Domain & Persistence (internal/domain/, internal/adapter/out/persistence/)

ProblemSummary Read Model

Introduced a lightweight ProblemSummary model for list operations.

Benefits:

  • Avoids loading heavy fields such as:
    • error_description
    • solution
  • Reduces database I/O.
  • Reduces response payload size.
  • Improves list endpoint performance.

Query Optimization

Updated FindAllByProjectID to select only the required columns:

SELECT
    id,
    project_id,
    title,
    status,
    severity,
    created_at,
    updated_at

instead of using:

SELECT *

⚙️ 2. Use Case Layer (internal/usecase/)

problem_usecase.go

Updated GetAllByProjectID to return:

model.Page[port.ProblemSummary]

instead of loading the full entity.

Unit Tests (problem_usecase_test.go)

Added 16 unit tests covering:

  • Create
  • GetByID
  • GetAllByProjectID
  • Update
  • UpdateStatus
  • Delete

Coverage includes:

  • Successful operations
  • Project not found
  • Problem not found
  • Edge cases using testify mocks

🌐 3. Web Layer (internal/adapter/in/web/)

problem_handler.go

Implemented several handler improvements:

  • Added the missing return when handling ErrProjectNotFound in GetAll, preventing duplicate 404 and 500 responses.
  • Fixed Update, UpdateStatus, and Delete to correctly return 404 Not Found when usecase.ErrProblemNotFound occurs instead of falling through to 500 Internal Server Error.
  • Corrected the logging tag in UpdateStatus ([ProblemHandler.UpdateStatus]).

router.go

Registered the dedicated status update endpoint:

PATCH /api/v1/projects/:project_id/problems/:problem_id/status

🧪 4. Integration Testing

Updated test_helper_test.go to wire:

  • Problem repository
  • Problem use case
  • Problem handler

into the shared SetupTestApp.

HTTP Integration Tests (problem_handler_test.go)

Added 31 integration tests using Gin and an in-memory SQLite database (:memory:).

Coverage includes:

  • Successful creation with Location header validation
  • Retrieval by ID
  • Paginated ProblemSummary listing
  • Project isolation
  • Partial updates (PATCH)
  • Status transitions (PATCH /status)
  • Permanent deletion with persistence verification
  • Invalid UUIDs
  • Missing required fields
  • Title validation
  • Page size validation (size > 100)
  • Unauthorized requests (401)

📚 5. OpenAPI 3.0 Documentation

Updated docs/openapi.yaml with:

Schemas

  • Problem
  • ProblemSummary
  • ProblemStatus
  • ProblemSeverity
  • CreateProblemCommand
  • UpdateProblemCommand
  • UpdateProblemStatusCommand
  • ProblemSummaryPage

Endpoints

Documented all Problem endpoints:

  • POST
  • GET (List)
  • GET (By ID)
  • PATCH (Update)
  • PATCH (Status Update)
  • DELETE

🧪 Test Execution

Run the full test suite:

cd backend-go
go test ./... -v

Run only the Problem use case tests:

go test ./internal/usecase/... -v -run TestProblem

Run only the Problem handler integration tests:

go test ./internal/adapter/in/web/handler/... -v -run TestProblemHandler

Summary by CodeRabbit

  • Novos recursos

    • Adicionado gerenciamento completo de problemas vinculados a projetos.
    • É possível criar, consultar, listar com paginação, atualizar, alterar status e excluir problemas.
    • Incluídas validações de autenticação, identificadores, campos obrigatórios e isolamento por projeto.
    • Adicionados status, severidade, resumos e respostas padronizadas para erros e sucessos.
  • Documentação

    • Atualizada a especificação da API com modelos, endpoints, paginação, validações e códigos de resposta.
  • Testes

    • Incluídos testes unitários e de integração para os principais fluxos e cenários de erro.

… tests

- Added `ProblemUseCase` handling CRUD operations and business logic for problems.
- Implemented `Create`, `Update`, `UpdateStatus`, `GetByID`, `GetAllByProjectID`, and `Delete` methods.
- Updated `ProblemRepository` to include project-scoped methods (`FindByIDAndProjectID`, `DeleteByIDAndProjectID`, `ExistsByIDAndProjectID`).
- Added comprehensive unit tests to validate problem use case functionality.
- Implemented `ProblemHandler` to handle HTTP operations for problems.
- Added CRUD and pagination routes for problem management under `/projects/:project_id/problems`.
- Extended OpenAPI documentation with schemas and endpoints for problems.
- Updated integration test suite with comprehensive tests for problem API operations.
- Modified `ProblemUseCase` and repository types to include summary support.
@MathCunha16 MathCunha16 self-assigned this Aug 6, 2026
@MathCunha16 MathCunha16 added documentation Improvements or additions to documentation enhancement New feature or request Backend Backend feature or modification labels Aug 6, 2026
@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 7117f43d-4286-441c-8e42-42bc0488d460

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • ✅ Review completed - (🔄 Check again to review again)

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (3)
backend-go/internal/adapter/in/web/handler/problem_handler.go (1)

37-45: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Registre o erro antes de responder 500 em Create.

Os outros métodos deste handler chamam log.Printf antes de retornar 500. Create não registra o erro. Isso remove a informação de diagnóstico do único caminho de falha inesperada da criação.

♻️ Correção proposta
 		if errors.Is(err, usecase.ErrProjectNotFound) {
 			c.JSON(http.StatusNotFound, gin.H{"error": err.Error()})
 			return
 		}
+		log.Printf("[ProblemHandler.Create] %v", err)
 		c.JSON(http.StatusInternalServerError, gin.H{"error": "Internal server error"})
 		return
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend-go/internal/adapter/in/web/handler/problem_handler.go` around lines
37 - 45, In the Create method’s unexpected-error branch, log the returned err
with log.Printf before sending the HTTP 500 response, matching the logging
behavior of the handler’s other methods. Keep the existing not-found response
and internal-server-error response unchanged.
backend-go/internal/adapter/in/web/handler/problem_handler_test.go (2)

214-223: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use require nas asserções de tipo da resposta paginada.

assert.Equal não interrompe o subteste. Se o status não for 200, page["content"] fica nil e a asserção de tipo em content := page["content"].([]interface{}) provoca panic. Isso oculta a causa real da falha. O mesmo padrão aparece nas linhas 241 e nos blocos de setup que usam createdProblem["id"].(string).

♻️ Correção proposta
-		resp := app.DoRequest(t, http.MethodGet, urlPath, nil, true)
-		assert.Equal(t, http.StatusOK, resp.StatusCode)
+		resp := app.DoRequest(t, http.MethodGet, urlPath, nil, true)
+		require.Equal(t, http.StatusOK, resp.StatusCode)
 
 		var page map[string]interface{}
 		err := json.NewDecoder(resp.Body).Decode(&page)
 		require.NoError(t, err)
 
-		content := page["content"].([]interface{})
+		content, ok := page["content"].([]interface{})
+		require.True(t, ok, "campo content ausente ou com tipo inesperado")
 		assert.Len(t, content, 10) // default page size is 10
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend-go/internal/adapter/in/web/handler/problem_handler_test.go` around
lines 214 - 223, Substitua por require as asserções que validam tipos e valores
essenciais na resposta paginada, especialmente antes de acessar page["content"]
em problem handler tests. Aplique o mesmo padrão ao bloco próximo da linha 241 e
aos setups que fazem createdProblem["id"].(string), garantindo que a execução
seja interrompida antes de qualquer type assertion que possa causar panic.

144-166: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Adicione um teste de isolamento entre projetos com dois projetos existentes.

Os casos de falha usam apenas o UUID zero, que corresponde a um projeto inexistente. Isso não verifica o cenário em que os dois projetos existem e o problema pertence ao outro projeto. TestProblemHandler_GetAll já cria o Projeto A e o Projeto B para esse fim. Aplique o mesmo padrão a Get, Update, UpdateStatus e Delete, e espere 404 quando o problema pertencer a outro projeto.

💚 Caso de teste sugerido
t.Run("Get failure - problem belongs to another project", func(t *testing.T) {
	respOther := app.DoRequest(t, http.MethodPost, "/api/v1/projects", []byte(`{"name":"Other Project"}`), true)
	var otherProject map[string]interface{}
	require.NoError(t, json.NewDecoder(respOther.Body).Decode(&otherProject))
	otherProjectID := otherProject["id"].(string)

	urlGet := fmt.Sprintf("/api/v1/projects/%s/problems/%s", otherProjectID, problemID)
	resp := app.DoRequest(t, http.MethodGet, urlGet, nil, true)
	assert.Equal(t, http.StatusNotFound, resp.StatusCode)
})
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend-go/internal/adapter/in/web/handler/problem_handler_test.go` around
lines 144 - 166, Adicione testes de isolamento entre projetos nos fluxos de Get,
Update, UpdateStatus e Delete em TestProblemHandler, criando dois projetos reais
e associando o problema a um deles. Para cada operação, use o ID do outro
projeto na URL e valide HTTP 404, mantendo os testes existentes para UUIDs
inexistentes e formatos inválidos.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@backend-go/internal/adapter/out/persistence/problem_repository.go`:
- Around line 53-54: Atualize a consulta definida em selectQuery para ordenar
primeiro por created_at DESC e, em seguida, por id como critério secundário
determinístico, preservando o filtro por project_id e a paginação existente.

In `@backend-go/internal/usecase/problem_usecase.go`:
- Around line 101-123: Evite perda de atualizações concorrentes nos fluxos de
edição de problema: em backend-go/internal/usecase/problem_usecase.go, linhas
101-123, substitua o Save após a leitura por uma atualização condicional usando
versão ou updated_at; em linhas 130-141, aplique o mesmo controle à alteração de
status. Preserve as validações existentes e faça a operação falhar quando o
registro tiver sido alterado desde a leitura.

---

Nitpick comments:
In `@backend-go/internal/adapter/in/web/handler/problem_handler_test.go`:
- Around line 214-223: Substitua por require as asserções que validam tipos e
valores essenciais na resposta paginada, especialmente antes de acessar
page["content"] em problem handler tests. Aplique o mesmo padrão ao bloco
próximo da linha 241 e aos setups que fazem createdProblem["id"].(string),
garantindo que a execução seja interrompida antes de qualquer type assertion que
possa causar panic.
- Around line 144-166: Adicione testes de isolamento entre projetos nos fluxos
de Get, Update, UpdateStatus e Delete em TestProblemHandler, criando dois
projetos reais e associando o problema a um deles. Para cada operação, use o ID
do outro projeto na URL e valide HTTP 404, mantendo os testes existentes para
UUIDs inexistentes e formatos inválidos.

In `@backend-go/internal/adapter/in/web/handler/problem_handler.go`:
- Around line 37-45: In the Create method’s unexpected-error branch, log the
returned err with log.Printf before sending the HTTP 500 response, matching the
logging behavior of the handler’s other methods. Keep the existing not-found
response and internal-server-error response unchanged.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 2d900464-64a1-4de0-b9f8-952cff63d0b0

📥 Commits

Reviewing files that changed from the base of the PR and between 6ca615e and 9ce6413.

📒 Files selected for processing (10)
  • backend-go/cmd/api/main.go
  • backend-go/docs/openapi.yaml
  • backend-go/internal/adapter/in/web/handler/problem_handler.go
  • backend-go/internal/adapter/in/web/handler/problem_handler_test.go
  • backend-go/internal/adapter/in/web/handler/test_helper_test.go
  • backend-go/internal/adapter/in/web/router.go
  • backend-go/internal/adapter/out/persistence/problem_repository.go
  • backend-go/internal/domain/port/problem_repository.go
  • backend-go/internal/usecase/problem_usecase.go
  • backend-go/internal/usecase/problem_usecase_test.go

Comment thread backend-go/internal/adapter/out/persistence/problem_repository.go
Comment thread backend-go/internal/usecase/problem_usecase.go
@MathCunha16
MathCunha16 merged commit 4f79bae into feature/backend/refactor-to-golang Aug 6, 2026
1 check passed
@MathCunha16
MathCunha16 deleted the feature/go-problems branch August 6, 2026 00:37
MathCunha16 added a commit that referenced this pull request Aug 14, 2026
…dules (#40)

* feat: integrate Tauri framework with initial splash screen, IPC commands, and automatic version synchronization script

* refactor: migrate to Tauri-based packaging by bundling the backend JAR and removing legacy Java desktop components.

* feat(backend-go): setup initial sql migrations and domain models" -m "- Initialize Go module (go.mod, go.sum) and
  project structure
    - Add 9 SQL database migrations mirroring Java Liquibase changesets
    - Add domain entity models (BaseEntity, AppSetting, Project, Snippet, Link, Problem, Note, Credential, Tag, ItemTag)
    - Add .gitignore for Go backend"

* Feat: (GO) add repository interfaces and implement persistence layer (#30)

* feat(backend-go): add repository interfaces for domain models

* feat(backend-go): implement persistence layer and adapters for repositories

* fix(backend-go): improve error handling and update repository method consistency

- Handle `sql.ErrNoRows` in `FindByID` to return `nil` instead of error.
- Standardize method naming (`ExistsById` → `ExistsByID`).
- Simplify and optimize `NewPage` calculations.
- Align `ItemTagRepository` methods with additional `projectID` parameter for consistency and data integrity.

* Enhance backend API with project management features and documentation (#31)

* feat(backend-go): add API entry point, project use case, and unit tests

- Implement main.go as the entry point for the backend API
- Add `ProjectUseCase` with CRUD, archive, and unarchive methods for projects
- Write unit tests for the project use case with a mock repository
- Update go.mod and go.sum with new dependencies for testing and validation

* feat(backend-go): add project API with middleware, routing, and migrations

- Extend `main.go` with server setup, project routing, and UUID token handling
- Implement `ProjectHandler` for project creation and retrieval via Gin
- Add CORS and auth middleware to secure and facilitate API requests
- Update database migrations to use `DATETIME` for timestamps
- Add validation to `CreateProjectCommand`
- Update dependencies in `go.mod` and `go.sum` for API and middleware functionality

* refactor(backend-go): reorganize project handler into separate package and enhance test coverage

- Move `ProjectHandler` to `handler` package for better modularity
- Add comprehensive test coverage for project handler, including success and failure cases
- Introduce `GetAll`, `Update`, `Archive`, `Unarchive`, and `Delete` methods to `ProjectHandler`
- Implement pagination support via `PaginationQuery` in `GetAll`
- Adjust router and test helper to reflect structural changes

* feat(backend-go): add OpenAPI documentation hosting and API reference routes

- Introduce `/docs` and `/openapi.yaml` routes for hosting API documentation
- Implement `registerDocsRoutes` function to serve documentation in development environment
- Add dependency `go-scalar-api-reference` for generating interactive API reference
- Include OpenAPI YAML specification for Devaulty API

* feat(backend-go): enhance error handling, validation, and CORS middleware

- Add detailed error handling in project APIs for "not found" and invalid states
- Update pagination validation with binding rules for `PageNumber` and `PageSize`
- Improve CORS middleware with restricted allowed origins list
- Replace direct string comparisons with constant-time comparison in auth middleware
- Extend OpenAPI specification with validation, error responses, and pagination constraints
- Enhance test coverage for new validation and error scenarios

* Feat: Complete Snippet Module Implementation, Integration Tests & API Docs (#32)

* feat(backend-go): add Snippet use case with tests and repository adjustments

- Implement `SnippetUseCase` for Create, Read, Update, and Delete operations.
- Add unit tests for Snippet use case.
- Modify repository to support project-scoped Snippet operations with `FindByIDAndProjectID` and `DeleteByIDAndProjectID`.
- Refactor auxiliary functions to ensure project existence.

* feat(backend-go): add SnippetHandler with tests and OpenAPI documentation

- Implement SnippetHandler for Create, Read, Update, and Delete endpoints.
- Add integration tests for SnippetHandler.
- Extend OpenAPI documentation to include Snippet operations.
- Introduce `ExtractUUIDParam` helper for parameter validation.

* reafactor(backend-go): improve error handling and extend delete operations

- Enhance error responses in ProjectHandler and SnippetHandler with proper status codes and logging.
- Modify repository delete methods to return success status and adjust use cases accordingly.
- Update integration and unit tests to validate deletion behavior and persistence.
- Extend OpenAPI documentation with 500 error responses and specific error scenarios for delete endpoints.

* Feat: Complete Link Module Implementation, Integration Tests & OpenAPI Documentation (#33)

* reafactor(backend-go): improve error handling and extend delete operations

- Enhance error responses in ProjectHandler and SnippetHandler with proper status codes and logging.
- Modify repository delete methods to return success status and adjust use cases accordingly.
- Update integration and unit tests to validate deletion behavior and persistence.
- Extend OpenAPI documentation with 500 error responses and specific error scenarios for delete endpoints.

* docs(openapi): remove nullable attribute from several fields

* Feat: Complete Problem Module Implementation (#34)

* feat(backend-go): implement problem use case with repository and unit tests

- Added `ProblemUseCase` handling CRUD operations and business logic for problems.
- Implemented `Create`, `Update`, `UpdateStatus`, `GetByID`, `GetAllByProjectID`, and `Delete` methods.
- Updated `ProblemRepository` to include project-scoped methods (`FindByIDAndProjectID`, `DeleteByIDAndProjectID`, `ExistsByIDAndProjectID`).
- Added comprehensive unit tests to validate problem use case functionality.

* feat(backend-go): add problem handler, routes, and integration tests

- Implemented `ProblemHandler` to handle HTTP operations for problems.
- Added CRUD and pagination routes for problem management under `/projects/:project_id/problems`.
- Extended OpenAPI documentation with schemas and endpoints for problems.
- Updated integration test suite with comprehensive tests for problem API operations.
- Modified `ProblemUseCase` and repository types to include summary support.

* Feat: Complete Tag & ItemTag Module Implementation (#35)

* feat(tag): enhance tag repository methods and add use cases

- Update repository methods to include project scope (`FindByIDAndProjectID`, `DeleteByIDAndProjectID`).
- Implement `TagUseCase` with create, update, delete, and search operations.
- Add unit tests for `TagUseCase` methods.
- Introduce `ItemTagUseCase` for associating/disassociating tags with items.

* feat(usecase): integrate item-tag repository into use cases

- Extend `ProblemUseCase`, `SnippetUseCase`, and `LinkUseCase` to manage item-tag associations.
- Remove all related tags during deletion of problems, snippets, and links.
- Update constructors and unit tests to include `ItemTagRepository`.
- Adjust API handlers and test helpers to support the new dependency.

* feat(handler): implement tag and item-tag HTTP handlers with tests

- Add `TagHandler` to manage CRUD operations and search functionality for tags.
- Introduce `ItemTagHandler` to handle tag associations and disassociations with items.
- Update `router.go` and initialization logic to register new routes and handlers.
- Add comprehensive unit tests for both handlers covering success and error scenarios.

* refactor(dto): replace inline command structs with DTO package

- Move command structs (`CreateProblemCommand`, `UpdateProblemCommand`, etc.) to `dto` package for better reuse and consistency.
- Update use cases, handlers, and tests to use the new DTO package.
- Refactor logic in related use case methods (`Create`, `Update`, etc.) to map domain models to view models.
- Adjust unit tests to align with the DTO-based refactor.

* docs: update security and tag architecture docs for Go backend

- Revise local development token documentation to align with Go backend implementation.
- Update token naming conventions, middleware logic, and local testing instructions.
- Rewrite tag system architecture docs to reflect Go backend design, including database schema, use cases, and DTO changes.

* refactor(usecase): update tag use cases to return DTOs and enhance item-tag handling

- Refactor `TagUseCase` methods to return `TagView` DTOs instead of domain models.
- Add mapping functions to convert domain models to DTOs (`mapTagToView`, `mapTagsToViews`) for consistency.
- Extend `ItemTagUseCase` to properly handle duplicate item IDs during tag associations.
- Update related tests to reflect DTO usage and improved item-tag logic.
- Introduce better error logging for tag removal failures across use cases (`LinkUseCase`, `SnippetUseCase`, `ProblemUseCase`).
- Modify OpenAPI spec to reflect supported item types for tag operations.

* Feat: implement note module (#36)

* feat(backend-go): implement project-scoped note use cases and repository updates

- Update `NoteRepository` with project-scoped methods:
  - `FindByIDAndProjectID`
  - `DeleteByIDAndProjectID`
- Introduce `NoteUseCase` for CRUD operations on notes, ensuring project context.
- Add DTOs (`CreateNoteCommand`, `NoteView`, `NoteSummary`) for note-related operations.
- Update `ItemTagUseCase` to support `ItemTypeNote`.

* feat(backend-go): enhance note use cases with update and delete operations, add associated tests

- Implement `NoteUseCase.Update` and `NoteUseCase.Delete` methods.
- Update `NoteUseCase.GetByID` to improve error handling and tag retrieval.
- Integrate `NoteRepository` into `ItemTagUseCase`.
- Add mock repository for notes in tests.
- Adjust `NoteView` and `NoteSummary` DTO fields for consistency.
- Add unit tests for note use cases.

* feat(backend-go): add NoteHandler for managing notes with full CRUD operations

- Implement `NoteHandler` for handling notes within project context.
- Add router mappings and integrate `NoteHandler` into the API.
- Update test helpers and add extensive tests for note routes and handler logic.

* feat(api-docs): add OpenAPI documentation for notes management

- Document CRUD operations for notes: create, read (single and paginated), update, and delete.
- Add schemas for `Note`, `NoteSummary`, `NoteSummaryPage`, `CreateNoteCommand`, and `UpdateNoteCommand`.
- Extend `ItemType` enum with `NOTE`.
- Define paths for `/projects/{project_id}/notes` and `/projects/{project_id}/notes/{note_id}`.

* fix(backend-go): improve error logging in NoteHandler and update OpenAPI docs for NOTE item type

- Log detailed error information in `NoteHandler.Create` on internal server errors.
- Extend OpenAPI `ItemType` descriptions to include support for `NOTE` in tag association endpoints.

* feat:  Vault Security Engine & AppSettings (#37)

* feat(backend-go): implement secure vault use case and key management

- Add VaultUseCase to manage master password setup, unlocking, and session status.
- Introduce MasterKeySession and Argon2KeyDeriver adapters for secure key handling.
- Add DTOs for handling API interactions related to the vault and app settings.
- Implement unit tests for VaultUseCase methods.
- Upgrade dependencies in go.mod and go.sum for crypto and security improvements.

* feat(backend-go): add SecurityHandler and integrate Vault APIs

- Introduce SecurityHandler to manage master password setup, unlocking, session status, and vault locking.
- Extend Gin router with security-related routes.
- Update DTO validation for master password constraints.
- Add OpenAPI documentation for security endpoints.
- Implement unit tests for SecurityHandler functions.
- Refactor memory hygiene guide to align with backend-go security standards.

* refactor(backend-go): improve memory handling and add comprehensive security tests

- Enhance memory hygiene in SecurityHandler by ensuring proper password reference clearing.
- Add extensive unit tests for Argon2KeyDeriver and MasterKeySessionHolder for key derivation, salt generation, and session management.
- Simplify VaultUseCase by consolidating app setting save operations with `SaveMasterPasswordSettings`.
- Improve synchronization and defensive copying in MasterKeySessionHolder.
- Introduce transaction handling and constraints for saving master password settings in AppSettingRepository.

* Feat: Credentials Module Implementation & AES-256-GCM Security Integration (#38)

* feat(backend-go): implement AES-GCM crypto adapter and related DTOs

- Add AES-GCM encryption/decryption implementation (`AESGCMCryptoAdapter`)
- Create Crypto port interface for encryption abstraction
- Include tests for AES-GCM encryption/decryption scenarios
- Add credential-related DTOs for command and view models
- Update `CredentialRepositoryAdapter` to refine query for credential retrieval

* **feat(backend-go): add credential use case with unit tests and repository enhancements**

- Implement `CredentialUseCase` for CRUD operations, including:
  - `Create`, `GetById`, `GetAllByProjectID`, `Update`, and `Delete`.
- Add corresponding unit tests to ensure robustness.
- Extend `CredentialRepository` interface for project-scoped queries.
- Update `CredentialRepositoryAdapter` with project-specific operations for `FindByID` and `DeleteByID`.

* **feat(backend-go): add CredentialHandler and API routes for credential management**

- Introduced `CredentialHandler` with CRUD operations (`Create`, `GetAll`, `GetById`, `Update`, `Delete`).
- Mapped routes under `/projects/:project_id/credentials`.
- Updated dependency injection for `CredentialHandler` in `main.go`.
- Enhanced test coverage with integration tests for credential APIs.

* **feat(backend-go): add VaultAutoLock scheduler to purge expired sessions**

- Introduced `VaultAutoLock` in the `scheduler` package to handle automatic session purging.
- Integrated the scheduler into `main.go` for periodic cleanup of expired sessions.
- Refactored `MasterKeySession` field casing for consistency across the codebase.

* **feat: extend OpenAPI spec to include credential management and secret payload handling**

- Added schemas for `CredentialSecretType`, `CreateCredentialCommand`, `UpdateCredentialCommand`, `CredentialView`, and paginated responses.
- Documented new endpoints under `/projects/{project_id}/credentials` for CRUD operations.
- Updated handling for item types to support `CREDENTIAL`.
- Improved sensitive data marshaling using `SecretBytes` for enhanced memory hygiene.

* **refactor(backend-go): improve test memory hygiene and update credential update logic**

- Refactored unit tests to ensure zeroing of sensitive `masterKey` during runtime.
- Updated `UpdateCredential` to handle partial updates with secret payload merging.
- Improved error messages for decryption failure scenarios.
- Adjusted OpenAPI spec error description for clarity on UUID validation.

* Feature/adapt frontend to golang (#39)

* feat(frontend): adapt REST API client to Go backend

- Update internal security token header to DEVAULTY_INTERNAL_TOKEN
- Adapt error interceptor to handle Go backend error payload format ({ error: string })
- Align MasterPassword setup check response with MasterPasswordSetupRequiredView schema
- Update tag search query parameter to tag_name
- Add tag badges rendering and tag search filtering to Snippets list view

* feat(tauri): integrate native Go backend and optimize memory usage

- Replace Java JRE integration in Tauri Rust shell with native Go sidecar execution
- Implement secure IPC using CSPRNG UUID token and stdout stream handshake
- Embed SQL migrations inside Go binary via go:embed for a self-contained executable
- Reduce Go backend RAM footprint down to 19MB via Gin ReleaseMode and GOGC tuning
- Implement 3-phase app startup (handshake, HTTP health check, minimum 2s splash screen)
- Update cross-platform build scripts and purge all remaining Java/Spring dependencies

* refactor: migrate backend from Gradle/Java to Go and update CI/CD pipelines to build installers via Tauri

* fix: improve backend data directory resolution, clean build artifacts, and normalize application versioning for Tauri compatibility.

* refactor!: replace Java backend with native Go backend and update Tauri v2 pipeline
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Backend Backend feature or modification documentation Improvements or additions to documentation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant