- Enforce task ownership on PATCH/DELETE /api/tasks (was: any signed-in
user could edit or delete anyone's tasks)
- Validate all API request bodies with zod; escape user content and
restrict links to http(s) in the Drive export; block reverting a
SUBMITTED report
- Add @@unique([userId, date]) on Report with upsert to eliminate the
duplicate-daily-report race; switch startup from
`prisma db push --accept-data-loss` to `prisma migrate deploy` with
automatic baselining of existing databases (dedup migration merges
any pre-existing duplicates)
- Autosave: re-queue and retry failed task saves with a visible
saving/error indicator instead of silently dropping edits
- Paginate and filter GET /api/reports (?date, ?mine, ?q, ?take,
?cursor); report form fetches only today's report, admin dashboard
uses server-side search + Load more
- Type the frontend and lib layer (DTOs in src/types/api.ts); zero
eslint errors
- Update README and Unraid guide for migrations, upgrade path, and API
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The classic Docker builder (used by docker-build.yml on the host runner)
does not support heredoc COPY syntax, which caused 'COPY failed: no source
files were specified'. Replace the heredoc with a checked-in entrypoint.sh
copied normally.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>