Initial commit: VoIdeaAI - voice-first AI idea assistant
This commit is contained in:
@@ -0,0 +1,33 @@
|
||||
# Changelog v1.0
|
||||
|
||||
## [1.0.0] - 2026-05-11
|
||||
|
||||
### Added
|
||||
- Project rename: VoIdea → VoIdeaAI (config, main.py, .env.example, PWA)
|
||||
- Phase 0: Database models and initial Alembic migration (8 tables)
|
||||
- Phase 1: Chat sessions with auto-title (LLM), sidebar, history
|
||||
- Phase 6: Rate limiting (slowapi) on all auth endpoints
|
||||
- Phase 7: Security hardening — security headers middleware, brute force protection (5 attempts),
|
||||
refresh token rotation, separate JWT reset secret
|
||||
- 26 agents: 1 Conductor + 13 role agents + 12 dev/ops agents
|
||||
- Voice pipeline: Web Speech API → Whisper API, SpeechSynthesis TTS
|
||||
- Yandex OAuth + Disk integration (7 scopes)
|
||||
- Password reset via email (JWT token, 1h expiry)
|
||||
- AES-256 encryption service (Fernet, PBKDF2 600k)
|
||||
- Email service with Jinja2 templates and SMTP fallback logging
|
||||
- Google/Apple OAuth stubs with Drive client interfaces
|
||||
- Full PWA support: manifest, favicons, service worker
|
||||
- docs/full.md — comprehensive project specification (19 sections)
|
||||
|
||||
### Changed
|
||||
- Static files moved from `/assets` to proper StaticFiles mount in main.py
|
||||
- Conductor agent accepts session_id, auto-creates sessions
|
||||
- VoiceChat UI: sidebar with session list, text input alongside mic
|
||||
- .env: updated to unified DATABASE_URL format, new OAuth fields
|
||||
|
||||
### Security
|
||||
- All auth endpoints rate-limited (10/min login, 5/min register, 3/min forgot-password)
|
||||
- SecurityHeadersMiddleware: CSP, HSTS, X-Frame-Options, X-Content-Type-Options
|
||||
- Brute force: 5 failed login attempts → 15 minute block
|
||||
- Refresh token rotation on every refresh call
|
||||
- Password reset uses separate JWT secret key
|
||||
Reference in New Issue
Block a user