feat: per-board activity log
Adds an audit trail per board, visible from a new clock-icon button on the toolbar. Useful for review-style work where someone wants to see who contributed which references and when. Logged events (high-signal only — canvas-edit noise intentionally skipped): - image / video / pdf added (whether dropped, pasted, or pulled from a URL) - board created / renamed / deleted - thread started, resolved, reopened - comment posted on a thread Backend: - new activity_logs table (id, board_id, user_id, denormalised actor name + email, action, target_type/id/label, metadata JSON, created_at) with an index on (board_id, created_at DESC). - logActivity helper resolves the user once at log time and stores their display name + email so entries survive deactivation/rename. - recordActivity wraps logActivity + a Socket.IO emit to the board's room so the panel updates live without polling. - GET /api/boards/:id/activity?limit=&before= for pagination (collection-membership gated, viewer+). Frontend: - ActivityPanel side-drawer: time-grouped feed (Today / Yesterday / older), per-action icons + tone colours (add/remove/edit/comment), pagination via "Load older", live append on Socket.IO 'activity:new'. - Relative timestamps refresh every 30s. - Wired into Editor + Toolbar. README updated; roadmap entry checked off.
This commit is contained in:
@@ -0,0 +1,55 @@
|
||||
/**
|
||||
* activity.js — single helper used by route handlers to append an entry to
|
||||
* the per-board audit log AND broadcast it over Socket.IO to anyone in the
|
||||
* room so live activity panels update without polling.
|
||||
*/
|
||||
|
||||
const { logActivity } = require('./db');
|
||||
const { getRoomName } = require('./socket/board-room');
|
||||
|
||||
/**
|
||||
* Record + broadcast a board activity event.
|
||||
*
|
||||
* @param {object} req — Express req (used for app.get('io') and req.user)
|
||||
* @param {object} entry — { boardId, action, targetType?, targetId?, targetLabel?, metadata? }
|
||||
* userId is taken from req.user.id automatically.
|
||||
*/
|
||||
function recordActivity(req, entry) {
|
||||
try {
|
||||
const userId = entry.userId !== undefined ? entry.userId : req?.user?.id || null;
|
||||
const row = logActivity({ ...entry, userId });
|
||||
if (!row) return null;
|
||||
|
||||
const io = req?.app?.get?.('io');
|
||||
if (io && entry.boardId) {
|
||||
io.to(getRoomName(entry.boardId)).emit('activity:new', formatRow(row));
|
||||
}
|
||||
return row;
|
||||
} catch (err) {
|
||||
// Never let activity logging break a mutation. Just log + swallow.
|
||||
console.error('[activity] failed:', err.message);
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
function formatRow(row) {
|
||||
return {
|
||||
id: row.id,
|
||||
board_id: row.board_id,
|
||||
user_id: row.user_id,
|
||||
actor_name: row.actor_name,
|
||||
actor_email: row.actor_email,
|
||||
action: row.action,
|
||||
target_type: row.target_type,
|
||||
target_id: row.target_id,
|
||||
target_label: row.target_label,
|
||||
metadata: row.metadata ? safeParse(row.metadata) : null,
|
||||
created_at: row.created_at,
|
||||
};
|
||||
}
|
||||
|
||||
function safeParse(s) {
|
||||
try { return JSON.parse(s); } catch { return null; }
|
||||
}
|
||||
|
||||
module.exports = { recordActivity, formatRow };
|
||||
@@ -207,6 +207,82 @@ catch { db.exec('ALTER TABLE images ADD COLUMN page_count INTEGER'); }
|
||||
try { db.prepare('SELECT priority FROM media_jobs LIMIT 0').get(); }
|
||||
catch { db.exec('ALTER TABLE media_jobs ADD COLUMN priority INTEGER DEFAULT 0'); }
|
||||
|
||||
// ---------------------
|
||||
// Activity log (per-board audit trail)
|
||||
// ---------------------
|
||||
db.exec(`
|
||||
CREATE TABLE IF NOT EXISTS activity_logs (
|
||||
id TEXT PRIMARY KEY,
|
||||
board_id TEXT NOT NULL,
|
||||
user_id TEXT,
|
||||
actor_name TEXT,
|
||||
actor_email TEXT,
|
||||
action TEXT NOT NULL,
|
||||
target_type TEXT,
|
||||
target_id TEXT,
|
||||
target_label TEXT,
|
||||
metadata TEXT,
|
||||
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||
);
|
||||
|
||||
CREATE INDEX IF NOT EXISTS idx_activity_board_time
|
||||
ON activity_logs(board_id, created_at DESC);
|
||||
`);
|
||||
|
||||
const { v4: _activityUuid } = require('uuid');
|
||||
|
||||
/**
|
||||
* Append a single activity entry. Resolves user → denormalised actor fields
|
||||
* at log time so the entry survives user rename / deactivation.
|
||||
*/
|
||||
function logActivity({ boardId, userId, action, targetType, targetId, targetLabel, metadata }) {
|
||||
if (!boardId || !action) return null;
|
||||
let actorName = null;
|
||||
let actorEmail = null;
|
||||
if (userId) {
|
||||
const user = db.prepare('SELECT display_name, email FROM users WHERE id = ?').get(userId);
|
||||
if (user) {
|
||||
actorName = user.display_name;
|
||||
actorEmail = user.email;
|
||||
}
|
||||
}
|
||||
const id = _activityUuid();
|
||||
db.prepare(`
|
||||
INSERT INTO activity_logs (id, board_id, user_id, actor_name, actor_email, action, target_type, target_id, target_label, metadata)
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
|
||||
`).run(
|
||||
id,
|
||||
boardId,
|
||||
userId || null,
|
||||
actorName,
|
||||
actorEmail,
|
||||
action,
|
||||
targetType || null,
|
||||
targetId || null,
|
||||
targetLabel || null,
|
||||
metadata ? JSON.stringify(metadata) : null,
|
||||
);
|
||||
return db.prepare('SELECT * FROM activity_logs WHERE id = ?').get(id);
|
||||
}
|
||||
|
||||
function getBoardActivity(boardId, { limit = 50, before = null } = {}) {
|
||||
const lim = Math.max(1, Math.min(parseInt(limit, 10) || 50, 200));
|
||||
if (before) {
|
||||
return db.prepare(`
|
||||
SELECT * FROM activity_logs
|
||||
WHERE board_id = ? AND created_at < ?
|
||||
ORDER BY created_at DESC
|
||||
LIMIT ?
|
||||
`).all(boardId, before, lim);
|
||||
}
|
||||
return db.prepare(`
|
||||
SELECT * FROM activity_logs
|
||||
WHERE board_id = ?
|
||||
ORDER BY created_at DESC
|
||||
LIMIT ?
|
||||
`).all(boardId, lim);
|
||||
}
|
||||
|
||||
// ---------------------
|
||||
// Settings (runtime-tunable key/value pairs)
|
||||
// ---------------------
|
||||
@@ -747,6 +823,8 @@ module.exports = {
|
||||
getCommentsByThread, getCommentsByBoard, getComment, createComment, updateComment, deleteComment,
|
||||
// Settings
|
||||
getSetting, setSetting, getAllSettings, getBoolSetting,
|
||||
// Activity log
|
||||
logActivity, getBoardActivity,
|
||||
// Bootstrap
|
||||
seedAdminFromEnv,
|
||||
};
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
const { Router } = require('express');
|
||||
const { authMiddleware } = require('../auth');
|
||||
const { getBoardActivity } = require('../db');
|
||||
const { resolveBoard } = require('./board-access');
|
||||
const { formatRow } = require('../activity');
|
||||
|
||||
const router = Router();
|
||||
router.use(authMiddleware);
|
||||
|
||||
/**
|
||||
* GET /api/boards/:boardId/activity
|
||||
* Returns recent activity entries for a board, newest first.
|
||||
*
|
||||
* Query params:
|
||||
* limit — max entries to return (1-200, default 50)
|
||||
* before — ISO timestamp; only entries created strictly before this
|
||||
*/
|
||||
router.get('/:boardId/activity', (req, res) => {
|
||||
try {
|
||||
const result = resolveBoard(req, res, 'viewer');
|
||||
if (!result) return;
|
||||
|
||||
const { limit, before } = req.query;
|
||||
const rows = getBoardActivity(result.board.id, { limit, before });
|
||||
return res.json({
|
||||
activity: rows.map(formatRow),
|
||||
hasMore: rows.length === Math.max(1, Math.min(parseInt(limit, 10) || 50, 200)),
|
||||
});
|
||||
} catch (err) {
|
||||
console.error('[activity] list error:', err);
|
||||
return res.status(500).json({ error: 'Internal server error' });
|
||||
}
|
||||
});
|
||||
|
||||
module.exports = router;
|
||||
@@ -12,6 +12,7 @@ const {
|
||||
getCollectionMember,
|
||||
} = require('../db');
|
||||
const { deleteBoardImages: deleteBoardMinioImages } = require('../minio');
|
||||
const { recordActivity } = require('../activity');
|
||||
|
||||
const router = Router();
|
||||
|
||||
@@ -81,6 +82,14 @@ router.post('/', (req, res) => {
|
||||
createdBy: req.user.id,
|
||||
});
|
||||
|
||||
recordActivity(req, {
|
||||
boardId: board.id,
|
||||
action: 'board.created',
|
||||
targetType: 'board',
|
||||
targetId: board.id,
|
||||
targetLabel: board.name,
|
||||
});
|
||||
|
||||
return res.status(201).json({ board });
|
||||
} catch (err) {
|
||||
console.error('[boards] create error:', err);
|
||||
@@ -171,8 +180,20 @@ router.put('/:boardId', (req, res) => {
|
||||
if (!result) return;
|
||||
|
||||
const { name, description } = req.body;
|
||||
const prevName = result.board.name;
|
||||
const updated = updateBoard(result.board.id, { name, description });
|
||||
|
||||
if (typeof name === 'string' && name.trim() && name.trim() !== prevName) {
|
||||
recordActivity(req, {
|
||||
boardId: updated.id,
|
||||
action: 'board.renamed',
|
||||
targetType: 'board',
|
||||
targetId: updated.id,
|
||||
targetLabel: updated.name,
|
||||
metadata: { from: prevName, to: updated.name },
|
||||
});
|
||||
}
|
||||
|
||||
return res.json({ board: updated });
|
||||
} catch (err) {
|
||||
console.error('[boards] update error:', err);
|
||||
@@ -195,6 +216,14 @@ router.delete('/:boardId', async (req, res) => {
|
||||
console.error('[boards] MinIO cleanup error:', e);
|
||||
}
|
||||
|
||||
recordActivity(req, {
|
||||
boardId: result.board.id,
|
||||
action: 'board.deleted',
|
||||
targetType: 'board',
|
||||
targetId: result.board.id,
|
||||
targetLabel: result.board.name,
|
||||
});
|
||||
|
||||
deleteBoard(result.board.id);
|
||||
|
||||
return res.json({ message: 'Board deleted' });
|
||||
|
||||
@@ -18,6 +18,7 @@ const {
|
||||
getUserById,
|
||||
} = require('../db');
|
||||
const { hasCollectionRole, resolveBoard } = require('./board-access');
|
||||
const { recordActivity } = require('../activity');
|
||||
|
||||
function resolveAuthorName(reqUser) {
|
||||
if (reqUser.display_name || reqUser.username) {
|
||||
@@ -108,6 +109,14 @@ router.post('/:boardId/threads', (req, res) => {
|
||||
});
|
||||
}
|
||||
|
||||
recordActivity(req, {
|
||||
boardId: req.params.boardId,
|
||||
action: 'thread.created',
|
||||
targetType: 'thread',
|
||||
targetId: threadId,
|
||||
targetLabel: content.trim().slice(0, 80),
|
||||
});
|
||||
|
||||
return res.status(201).json({ thread, comment });
|
||||
} catch (err) {
|
||||
console.error('[threads] create error:', err);
|
||||
@@ -144,6 +153,15 @@ router.patch('/:boardId/threads/:threadId', (req, res) => {
|
||||
});
|
||||
}
|
||||
|
||||
if (status === 'resolved' || status === 'open') {
|
||||
recordActivity(req, {
|
||||
boardId: req.params.boardId,
|
||||
action: status === 'resolved' ? 'thread.resolved' : 'thread.reopened',
|
||||
targetType: 'thread',
|
||||
targetId: req.params.threadId,
|
||||
});
|
||||
}
|
||||
|
||||
return res.json({ thread: updated });
|
||||
} catch (err) {
|
||||
console.error('[threads] status error:', err);
|
||||
@@ -221,6 +239,14 @@ router.post('/:boardId/threads/:threadId/comments', (req, res) => {
|
||||
});
|
||||
}
|
||||
|
||||
recordActivity(req, {
|
||||
boardId: req.params.boardId,
|
||||
action: 'comment.added',
|
||||
targetType: 'thread',
|
||||
targetId: req.params.threadId,
|
||||
targetLabel: content.trim().slice(0, 80),
|
||||
});
|
||||
|
||||
return res.status(201).json({ comment });
|
||||
} catch (err) {
|
||||
console.error('[threads] add comment error:', err);
|
||||
|
||||
@@ -6,9 +6,10 @@ const https = require('https');
|
||||
const http = require('http');
|
||||
const { URL } = require('url');
|
||||
const { authMiddleware } = require('../auth');
|
||||
const { getBoard, getCollectionMember, createImage, createMediaJob, createPdfPage, updateImagePageCount } = require('../db');
|
||||
const { getBoard, getCollectionMember, createImage, getImage, createMediaJob, createPdfPage, updateImagePageCount } = require('../db');
|
||||
const { putBuffer, getImageUrl, MIME_TO_EXT, MAX_FILE_SIZE } = require('../minio');
|
||||
const { pdfInfo, bufferToTempFile } = require('../pdf-utils');
|
||||
const { recordActivity } = require('../activity');
|
||||
|
||||
const router = Router();
|
||||
|
||||
@@ -192,6 +193,15 @@ router.post('/boards/:boardId/images', upload.single('image'), async (req, res)
|
||||
});
|
||||
}
|
||||
|
||||
recordActivity(req, {
|
||||
boardId: board.id,
|
||||
action: 'pdf.added',
|
||||
targetType: 'pdf',
|
||||
targetId: imageId,
|
||||
targetLabel: originalname,
|
||||
metadata: { pageCount: info.pageCount, fileSize: size },
|
||||
});
|
||||
|
||||
return res.status(201).json({
|
||||
id: image.id,
|
||||
media_type: 'pdf',
|
||||
@@ -233,6 +243,15 @@ router.post('/boards/:boardId/images', upload.single('image'), async (req, res)
|
||||
createMediaJob({ id: jobId, imageId, boardId: board.id, type: 'poster' });
|
||||
}
|
||||
|
||||
recordActivity(req, {
|
||||
boardId: board.id,
|
||||
action: `${mediaType}.added`,
|
||||
targetType: mediaType,
|
||||
targetId: imageId,
|
||||
targetLabel: originalname,
|
||||
metadata: { fileSize: size, mimeType: mimetype, source: 'upload' },
|
||||
});
|
||||
|
||||
return res.status(201).json({
|
||||
id: image.id,
|
||||
url: publicUrl,
|
||||
@@ -354,6 +373,15 @@ router.post('/boards/:boardId/images/from-url', async (req, res) => {
|
||||
createMediaJob({ id: jobId, imageId, boardId: board.id, type: 'poster' });
|
||||
}
|
||||
|
||||
recordActivity(req, {
|
||||
boardId: board.id,
|
||||
action: `${mediaType}.added`,
|
||||
targetType: mediaType,
|
||||
targetId: imageId,
|
||||
targetLabel: filename,
|
||||
metadata: { fileSize: buffer.length, mimeType, source: 'url', sourceUrl: url },
|
||||
});
|
||||
|
||||
return res.status(201).json({
|
||||
id: image.id,
|
||||
url: publicUrl,
|
||||
|
||||
@@ -101,6 +101,7 @@ const uploadRoutes = require('./routes/upload');
|
||||
const adminRoutes = require('./routes/admin');
|
||||
const threadRoutes = require('./routes/threads');
|
||||
const pdfRoutes = require('./routes/pdf');
|
||||
const activityRoutes = require('./routes/activity');
|
||||
|
||||
app.use('/api/auth', authRoutes);
|
||||
app.use('/api/collections', collectionRoutes);
|
||||
@@ -109,6 +110,7 @@ app.use('/api/upload', uploadRoutes);
|
||||
app.use('/api/admin', adminRoutes);
|
||||
app.use('/api/boards', threadRoutes);
|
||||
app.use('/api/boards', pdfRoutes);
|
||||
app.use('/api/boards', activityRoutes);
|
||||
|
||||
// Public shared collection route (no auth required)
|
||||
app.get('/api/c/:shareToken', (req, res) => {
|
||||
|
||||
@@ -182,4 +182,4 @@ function leaveRoom(io, socket, roomName) {
|
||||
console.log(`[socket] ${socket.userDisplayName} left ${roomName}`);
|
||||
}
|
||||
|
||||
module.exports = { setupBoardRoom };
|
||||
module.exports = { setupBoardRoom, getRoomName };
|
||||
|
||||
Reference in New Issue
Block a user