Files
shopdb-flask/CHANGELOG.md
cproudlock 22e623c1f6 Plugin framework maturation, reports overhaul, theming, and USB frontend repair
Framework:
- Per-plugin Alembic migration chains (ADR-008): every bundled plugin
  carries its own chain with a stamp-only anchor at the ownership cutover;
  new plugin schema lands in plugins/<name>/migrations/, never the core
  chain. Deploys add flask plugin upgrade-all. Fixed a latent bug in the
  shared alembic template (engine URL resolution) and taught the metadata
  filter to include FK-referenced core tables.
- Frontend plugin route gating (ADR-009): plugin routes carry meta.plugin;
  a disabled plugin's pages redirect to the dashboard via a cached,
  fail-open check against the new public GET /api/plugins/enabled.
- get_reports() plugin hook (contract 0.5.0 -> 0.6.0): plugins contribute
  report cards; warranty and toner cards moved off the hardcoded list.

Reports:
- Hub grouped by category with search; inline reports render at the top,
  are URL-backed (?report=id, back-button and deep links work), expose
  their server-side filter params as controls, and export CSV. Warranty
  and Toner pages gained CSV export.
- Deleted the dead legacy Warranty Status report (always-zero buckets
  from a retired column).

Theming and fonts:
- Inter (variable) bundled locally via @fontsource, replacing the Google
  Fonts Roboto import - air-gapped installs now render correctly; tables
  use tabular numerals.
- Optional brand_primary_dark_color, brand_accent_color,
  brand_sidebar_color settings applied to CSS vars at bootstrap.

USB frontend repair (views were reading a dead legacy shape):
- List/detail/form and the employee profile USB panels remapped to the
  real API shape (device_id/device_desc/checkinoutlog); employee panels
  now use /usb/checkouts endpoints; external-mode /usb/checkouts/active
  honors the badge filter; dead client methods pruned.

Also: warranties list page no longer requires login (matches app
convention); collector doc rewritten with a GE-Enforce integration guide
and paste-ready PowerShell reporter; ADR index and CHANGELOG updated.

Verified: 323 tests pass, naming/style green, frontend builds, plugin
migration dry-run green on scratch MySQL.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-11 10:01:47 -04:00

5.8 KiB

Changelog

All notable changes to shopdb-flask are recorded here.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning. The product version (__version__) and the plugin-contract version (__contract_version__) are distinct series with independent bump rules; see ADR-007 and ADR-002.

Unreleased

Added

  • measuringtools plugin (ADR-005): gage-lab instruments as Asset extensions with type lookup (color-coded), calibration tracking (derived overdue/due-soon/current status), calibration report, and full frontend. Built as the framework exemplar; docs/PLUGIN-GUIDE.md walks through its construction step by step as the plugin-system tutorial.
  • CSV export on the Warranty and Toner report pages; per-report filter controls (business unit, asset type, location, application, limit) on the inline core reports; report open-state is URL-backed and deep-linkable.
  • Per-plugin Alembic migration chains (ADR-008): every bundled plugin now carries its own chain with a stamp-only anchor; new plugin schema changes land in plugins/<name>/migrations/, never the core chain. Deploys run flask plugin upgrade-all after flask db upgrade.
  • Frontend plugin route gating (ADR-009): a disabled backend plugin's pages redirect to the dashboard; new public GET /api/plugins/enabled.
  • get_reports() plugin hook (plugin contract 0.5.0 -> 0.6.0): plugins contribute their own report cards; warranty and toner cards moved off the hardcoded frontend list.
  • Reports hub grouped by category with a search filter.
  • Configurable QR label targets: qr_target_printer / qr_target_usb settings (blank = the asset's own page, else a URL template with placeholders) and a usb_label_style barcode/QR toggle for USB mini-labels. New Settings > Printing & Labels section.
  • Site palette theming: optional brand_primary_dark_color, brand_accent_color, brand_sidebar_color settings applied at bootstrap.
  • Collector integration guide rewrite: header-only auth reference and a paste-ready GE-Enforce PowerShell reporting function.

Changed

  • Inter (variable) replaces Roboto, bundled locally - no Google Fonts fetch, so air-gapped installs render correctly. Tables use tabular numerals.
  • ServiceNow defaults point at the current geaerospaceqa.service-now.com global search (search, incident, and change links).

Fixed

  • USB frontend remapped to the actual API shape (device_id / device_desc): device list, detail, form, label batch, and the employee profile's checked-out/history panels were all reading dead legacy fields.
  • External-mode GET /api/usb/checkouts/active now honors the badge filter.
  • Warranties list page no longer demands login (matches every other list page; reads were already public).
  • Removed the dead legacy Warranty Status report (always-zero buckets from a retired column); the warranty plugin's report is the real one.
  • Pruned dead usbApi client methods that had no backend routes.

0.5.0 - 2026-07-10

First release cut with a version, tag, changelog, and CI. Focused on letting other GE Aerospace sites stand up their own self-hosted instance (single-tenant per ADR-004).

Added

  • First-run setup wizard (/setup): creates the initial superadmin in-app, configures each plugin (create tables here vs connect your own database), uploads light/dark floor-map blueprints, and seeds starter reference data.
  • Self-hosted employee directory and USB plugins: in-app management plus CSV import, no external database required. Both ship default-disabled with an enable-time provisioning note.
  • Dell warranty plugin: real Dell provider, bulk warranty sync, add-warranty from asset pages, PC hero warranty badge, disk-cached Dell API token.
  • Custom fields, and a two-pane settings shell with tabbed, searchable System Settings and Settings index pages.
  • Dashboard defaults (visitor-IP to business-unit mapping) for kiosk displays; printer installer endpoint (data plus floor-map positions).
  • Global toast notifications replacing alert() calls.
  • Multi-stage Docker build that compiles the Vue frontend and ships frontend/dist, which Flask serves.
  • Documentation overhaul: new CONFIG, UPGRADE, and BACKUP-RESTORE guides; reconciled README, DEPLOY, CLAUDE, and ROADMAP.
  • ADR-007 (product versioning and releases), CHANGELOG, and best-effort Gitea Actions CI (backend tests, naming/style gate, frontend build).

Changed

  • Plugin contract (__contract_version__) settled at 0.5.0: full plugin import surface exposed via shopdb.api, dead search hook removed, and the dashboard-widgets hook wired to a real consumer.
  • Role-based access control now enforced on write routes, including admin-only guards on dashboard-defaults writes.
  • Branding, ServiceNow integration, employee-ID pattern, printer hostname template, and floor-plan blueprints are settings-driven and per-site configurable, with GE defaults preserved as shipped fallbacks (branding and floor-plan configurability landed in this release; some consumer wiring continues under Unreleased).

Security

  • Dashboard-defaults writes now require admin authorization instead of any authenticated user.
  • Collector error responses no longer leak exception detail; failures are logged server-side with generic client-facing messages.
  • Login rate limiting added (IP-based fixed window) on top of the existing account lockout.

BREAKING

  • Collector API key must now be sent in the X-API-Key header. The api-key-in-querystring fallback has been removed. Update any collector integration that passed the key as a query parameter. See docs/COLLECTOR-INTEGRATION.md.