Commit Graph

3 Commits

Author SHA1 Message Date
gsxdsm
52facd1461 FN-9000: scope runtime records to their projects
Scope runtime data access to the owning project while preserving explicit unbound compatibility.

- Thread optional project identifiers through project-table reads and mutations.
- Isolate chat, approvals, artifacts, secrets, audit, branch groups, plugin analytics, and verification cache records.
- Add PostgreSQL coverage and a patch changeset documenting multi-project isolation.

Files changed:
 .../fn-9000-project-ownership-runtime-scope.md     |   7 +
 docs/storage.md                                    |   3 +-
 .../project-ownership-runtime-scope.pg.test.ts     | 155 +++++++++++++++++++++
 packages/core/src/agents/approval-request-store.ts |  20 ++-
 .../async-stores/async-approval-request-store.ts   |  30 ++--
 packages/core/src/async-stores/async-chat-store.ts | 105 +++++++++++---
 .../core/src/async-stores/async-secrets-store.ts   |  58 +++++---
 packages/core/src/chat/chat-store.ts               |  22 +--
 .../src/plugins/plugin-activation-analytics.ts     |  12 +-
 packages/core/src/secrets/secrets-store.ts         |  12 +-
 packages/core/src/store.ts                         |   6 +-
 .../src/task-store/async/async-archive-lineage.ts  |  16 ++-
 packages/core/src/task-store/async/async-audit.ts  |  18 ++-
 .../src/task-store/async/async-branch-groups.ts    |  50 ++++---
 .../task-store/async/async-comments-attachments.ts |  35 +++--
 .../core/src/task-store/branch-and-pr-entities.ts  |  15 +-
 packages/core/src/task-store/branch-group-ops.ts   |   2 +-
 packages/core/src/task-store/task-artifacts-ops.ts |   2 +-
 packages/core/src/task-store/task-id-integrity.ts  |   2 +-
 packages/core/src/task-store/task-mutation-ops.ts  |  14 +-
 .../core/src/task-store/workflow-definitions.ts    |   7 +
 packages/dashboard/src/server.ts                   |   2 +-
 22 files changed, 472 insertions(+), 121 deletions(-)

Fusion-Task-Id: FN-9000

Fusion-Task-Lineage: 9842e9e9-ec50-4459-8534-dfdaa2cdf35e

Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>
2026-08-12 07:43:29 -07:00
gsxdsm
9c5176f55e FN-8997: enforce project ownership for project tables
Enforce project-scoped ownership for chat and workflow records.

- Add project ownership columns, migration backfill, and schema validation.
- Scope chat-room and workflow CRUD operations to the active project.
- Add PostgreSQL regression coverage, storage documentation, and a release changeset.

Files changed: .../fn-8997-project-ownership-declaration-drift.md |   7 ++
 docs/storage.md                                    |   1 +
 .../project-ownership-declaration-drift.pg.test.ts |  42 +++++++++
 .../src/__tests__/postgres/schema-applier.test.ts  |   9 +-
 packages/core/src/async-stores/async-chat-store.ts | 100 ++++++++++++---------
 packages/core/src/chat/chat-store.ts               |  38 ++++----
 ...fn_8997_project_ownership_declaration_drift.sql |  17 ++++
 packages/core/src/postgres/schema-applier.ts       |  12 ++-
 packages/core/src/postgres/schema/project.ts       |  43 +++++++--
 packages/core/src/task-store/project-store-ops.ts  |   7 +-
 .../core/src/task-store/workflow-definitions.ts    |   4 +-
 packages/core/src/task-store/workflow-ops.ts       |  13 +--
 .../src/task-store/workflow-task-create-ops.ts     |   2 +-
 13 files changed, 210 insertions(+), 85 deletions(-)

Fusion-Task-Id: FN-8997

Fusion-Task-Lineage: 01cd71b1-8f86-41e5-abdb-5ab00ff91c83

Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>
2026-08-11 19:34:01 -07:00
gsxdsm
cb57093d03 refactor: domain folder layout (types, API, core, engine) (#2398)
## Summary

Wave 17 organizes Fusion into **domain folders** (stacks on #2397).

### Layout
- **core/types/** — board, task, agents, settings, merge, workflow,
mesh, …
- **core/src/** — agents, ai, async-stores, workflows, tasks, config,
db, …
- **dashboard/app/api/** — client, tasks, agents, git, missions,
planning, …
- **engine/src/** — agents, auth, execution, merge, missions, overseer,
worktree, …

Root keepers retained for large entrypoints (`store.ts`, `executor.ts`,
`merger.ts`, …).

Public barrels (`@fusion/core`, `@fusion/engine`, `app/api.ts` → legacy)
stay stable.

## Test plan
- [x] `@fusion/core` typecheck
- [x] `@fusion/engine` typecheck (pre-existing playwright-core noise
only)
- [ ] CI merge gate

**Stack:** #2394 → #2397 → **this PR**
2026-08-03 00:20:53 -07:00