Persistent stores grow and change over time. svelte-persisted-store deep-merges old localStorage values with new defaults, so stale values (e.g. hash_prefix_length: 1) silently survive schema changes and cause subtle bugs. - src/lib/stores/store_versions.ts: Single source of truth for AE_LOC_VERSION / AE_EVENTS_LOC_VERSION. Side-effect on import: reads raw localStorage and wipes if __version mismatches. Must be imported first in ae_stores.ts and ae_events_stores.ts so the wipe happens before persisted() hydrates from localStorage. - ae_stores.ts + ae_events_stores.ts: Import store_versions as first import; add __version to persisted store defaults. - documentation/TODO__Agents.md: Added stores refactor task — both store files need a cleanup pass. Bump AE_LOC_VERSION or AE_EVENTS_LOC_VERSION by 1 on breaking schema changes. Non-breaking changes (new optional fields, default value tweaks) do not need a bump. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
7.4 KiB
Frontend Agent Task List
Use this file to track steps for complex features or bug fixes. Status: <20> Stable — ongoing development.
📋 Open: Security
- PUBLIC_AE_API_SECRET_KEY Audit: Completed 2026-03-11. Key is
PUBLIC_*by design (always in client bundle). Highest-risk anonymous path now uses limited-permissionPUBLIC_AE_BOOTSTRAP_KEY. Full server-side migration would require a major API proxy refactor — not justified given JWT + account_id auth layers.manifest.webmanifest/+server.tsis a minor cleanup candidate (could use bootstrap key instead), but no security urgency. Current state is acceptable.
🚧 Upcoming High Priority
[Stores] Refactor — ae_stores.ts and ae_events_stores.ts cleanup
Both files have grown organically and are messy. Refactor goals:
- Split into focused files per domain (core, user/auth, files, module-specific)
- Remove dead/commented-out code and stale
ver/ver_idbconstants from data structs (replaced by__versionin store_versions.ts) - Standardize field naming conventions
- Move sponsorships/stripe Stripe button IDs out of session store and into config
- Keep
ae_stores.tsandae_events_stores.tsas barrel re-exports for backwards compatibility Related:src/lib/stores/store_versions.tsis the new home for version constants.
[Launcher] Active features (identified 2026-03-06)
-
Font size cycler (Launcher sidebar): Font size cycler and light/dark toggle added to new
menu_launcher_controls.sveltecomponent; wired intolauncher_menu.svelte. Visibility toggles (All Files / All Sessions) moved to same component and restyled topreset-tonal-tertiary. (2026-03-11) -
Minor Svelte warning:
slct_event_location_idprop inmenu_location_list.svelteis not$bindable()butbind:value={slct_event_location_id}is used. Functionally fine sinceonchangewrites directly to$events_slct.event_location_id.
[Svelte] State reference warnings
- 42
state_referenced_locallywarnings remain inrecovery_meetings/ae_idaa_comp__event_obj_id_edit.svelteand..._v2.svelte. Same pattern as the 10 fixed on 2026-03-09 — move reactive reads intoonMount.
[Badges] Remaining badge work before first live event
- Badge print controls UX polish: Scott has improvements in mind — TBD next session.
File:
ae_comp__badge_print_controls.svelte.
[Leads] Exhibitor Lead Scanning — NEXT MAJOR FEATURE
QR code scan at exhibitor booth → capture attendee badge data. Gated by allow_tracking on
the badge. Check if documentation/MODULE__AE_Events_Leads.md exists for full spec.
Key questions before starting: which routes, does the Electron app scan, what does the
lead record look like in the DB?
[DevOps] Remaining deployment items
- Wire AE_APP_REPLICAS:
docker-compose.ymlline 147 already hasscale: ${AE_APP_REPLICAS:-1}. (verified 2026-03-11) - Archive ae_env_node_app: Archived as tar.gz under
~/OSIT_dev/backups/; old history/docs moved to~/OSIT_dev/for_reference_only/. (2026-03-11) - Build Optimization: Current state finalized. Local Gitea instance stood up at
git.dgrzone.com(Docker, home server) — future: migrate repos from Bitbucket, verify Backblaze/restic backups cover Gitea data. (2026-03-11)
[General]
- Temp Cleanup: Auto-removal of native
.tmpfiles older than 24h. window.print()for badge print button: Wire the existinghandle_print_badge()to triggerwindow.print(). Browser print works well across Chrome/Chromium/Firefox — no Electron needed.- Input Field Audit: Several input fields are missing
name/idattributes ordata-testid. Known examples: badge override fields inae_comp__badge_obj_view.svelte; template name input inae_comp__badge_template_form.svelte. Matters for: accessibility, autofill, label associations, and test targeting. (For tests, usegetByLabel()rather thaninput[value*=...]which only checks the HTML attribute, not the Svelte-bound DOM property.)
[UX] Session Expired & Access Denied (identified 2026-03-10)
Two related UX gaps to handle together:
1. Session Expired banner (API 401/403 mid-session):
flag_expiredin root+layout.svelteis declared but never set — it was always intended for this- Add a small writable store or custom event (e.g.,
ae_auth_errorinae_stores) that API helpers (api_get_object.ts,api_post_object.ts,api_patch_object.ts) can fire when they get a 401 or 403 - Root layout watches the store and sets
flag_expired = true - Render a non-blocking dismissible banner (not full-screen): "Session expired. Please sign in again." with a link to the sign-in control
- Especially relevant for Launcher (event staff on tablets may not notice silent failures)
2. Standardize Access Denied UI (non-IDAA routes only — IDAA layout is intentionally custom):
- Currently inconsistent across the app:
- Root layout: full-screen
flag_denied(site access key gate — keep this, it's correct) /corelayout: silent redirect to home — should show a brief message instead/events/[event_id]/settings: inline raw text string — should use a consistent banner component/events/.../badges/.../review: inline<h3>Access Denied</h3>with no context or action
- Root layout: full-screen
- Create a reusable
element_access_denied.sveltecomponent (small: icon + message + optional action button) - Swap the ad-hoc patterns to use it consistently
✅ Completed (2026-03)
- [DevOps] Frontend + Backend unified into single
aether_container_envDocker Compose.ae_appservice live with healthcheck, single exposed port (AE_APP_NODE_PORT), internalae_apinetworking. Deploy scripts inpackage.jsonboth target../aether_container_env/docker-compose.yml. (2026-03-10) - [DevOps]
/healthendpoint live atsrc/routes/health/+server.ts. DockerHEALTHCHECKuses it. (2026-03-10) - [UI] Dark mode
color-schemefix —html.dark/light { color-scheme }inapp.css; all native browser controls now sync to app dark mode. (2026-03-10) - [Launcher] Location select → session auto-load bug fixed via
$derived.by()liveQuery pattern. (2026-03-10) - [Svelte]
state_referenced_locallywarning fixes — 10 warnings resolved in IDAA archives/BB. (2026-03-09) - [TypeScript] Sign In/Out TS errors fixed —
user_id/person_idtyped asstring | null. (2026-03-09) - [Tests] All badge data integrity and attendee workflow Playwright tests passing. Root causes documented in
tests/README.md. (2026-03) - [Badges] Badge print controls panel, QR code, duplex wiring, review form, print button, multi-word fulltext search,
data-testidattributes. (2026-03) - [UI] Firefly Theme + Pres Mgmt Visual Redesign (5 files). (2026-03-06)
- [Docs] UI Style Guidelines + Component Patterns docs created. (2026-03-06)
- [API] V3 Lookup system integration; Event File V3 mapping;
event_sessionsearch 400-error fix. (2026-02/03) - [API] All CRUD helpers on V3
/v3/crud/...paths. (2026-02) - [Security] Purged
x-aether-api-token; fixed misplaced CORS headers; Account ID Scavenging. (2026-02) - [Security] Playwright integration tests replace
verify_jwt_logic.jssimulation tests. (2026-03) - [Framework]
AE_Obj_Field_Editor_V3with Svelte 5 Runes. CRUD v2 fully retired. (2026-03-05) - [IDAA] Bulletin Board and Recovery Meetings functionality verified. (2026-02)