Commit Graph
6 Commits
Author SHA1 Message Date
Keith SmithandClaude Sonnet 4.5 1d6b07bfed Implement recurring tasks functionality
Adds automatic creation of next task instance when recurring tasks are completed.

- Add calculate_next_due_date() and create_next_recurrence() methods to Task model
- Update task completion handlers in views and sync API to create next recurrence
- Add hourly Celery task to process any missed recurring tasks
- Support daily, weekly, biweekly, monthly, yearly recurrence patterns
- Respect recurrence_end_date limits

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-04 10:00:34 -07:00
Keith SmithandClaude Sonnet 4.5 84d9b4704a Fix MEDIUM-HIGH Security Issue: Add input validation for choice fields
Added validation for status, priority, and recurrence fields in web forms to prevent invalid database values.

Changes:

TaskUpdateView.post() (line 419):
- Validate status against Task.STATUS_CHOICES before setting
- Validate priority against Task.PRIORITY_CHOICES before setting
- Validate recurrence against Task.RECURRENCE_CHOICES before setting
- Only update fields if value is in allowed choices
- Default to 'none' for invalid recurrence values

TaskCreateView.post() (line 481):
- Validate status, default to 'pending' if invalid
- Validate priority, default to 'medium' if invalid
- Validate recurrence, default to 'none' if invalid
- Prevents creation with invalid choice values

Allowed Choices:
- Status: pending, in_progress, completed, cancelled
- Priority: low, medium, high, urgent
- Recurrence: none, daily, weekly, biweekly, monthly

Security impact:
- Prevents invalid database values from user input
- Maintains data integrity
- Blocks potential business logic bypasses
- Prevents database constraint violations

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-23 06:25:22 -07:00
Keith SmithandClaude Sonnet 4.5 e5b15c7193 Fix HIGH Security Issue: Open Redirect Vulnerability
Fixed open redirect vulnerability in 9 locations throughout tasks/views.py.

Changes:
- Added url_has_allowed_host_and_scheme import from django.utils.http
- Created safe_redirect() helper function to validate redirect URLs
- Only allows relative URLs or URLs to the same host
- Prevents attackers from redirecting users to phishing/malicious sites

Fixed locations:
- Line 447: TaskUpdateView - task update redirect
- Line 501: task_quick_add - quick add redirect
- Line 521: subtask_create - subtask creation redirect
- Line 537: task_toggle_status - status toggle redirect
- Line 549: task_delete - task deletion redirect
- Line 601: web_timer_start - timer start redirect
- Line 626: web_timer_stop - timer stop redirect
- Line 672: TagUpdateView - tag update redirect
- Line 684: tag_delete - tag deletion redirect

Security impact:
- Prevents phishing attacks via malicious redirect URLs
- Blocks cache poisoning attacks
- Ensures users stay within the application domain

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-23 06:21:44 -07:00
Keith SmithandClaude Sonnet 4.5 c50aaa2d81 Fix Critical Security Issue: Authorization bypass on shared tasks
Added comprehensive authorization checks to prevent users from:
1. Sharing tasks/tags they don't own
2. Modifying tasks/tags that are only shared with them (read-only access)

Changes:

tasks/serializers.py (TaskShareSerializer):
- Added validation in validate() method to verify task/tag ownership
- Users can only share their own tasks and tags
- Prevents malicious users from sharing other people's resources

tasks/permissions.py (NEW):
- Created IsOwnerOrReadOnlyIfShared permission class
- Owners: full access (read, update, delete)
- Shared users: read-only access
- Prevents privilege escalation via shared access

tasks/views.py:
- Applied IsOwnerOrReadOnlyIfShared to TaskDetailAPIView
- Applied IsOwnerOrReadOnlyIfShared to TagDetailAPIView
- Enforces object-level permissions on all update/delete operations

Security impact:
- Prevents users from modifying or deleting resources they don't own
- Prevents users from sharing resources they don't own
- Maintains proper separation between owner and shared access levels

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-22 22:38:43 -07:00
Keith SmithandClaude Sonnet 4.5 b57321e1e4 Fix Critical Security Issue: Replace print() with proper logging
Replaced all debug print() statements with proper logging framework:
- tasks/views.py: 5 print statements → logger.debug()
- sync/views.py: 15 print statements → logger.debug()
- config/celery.py: 1 print statement → logger.debug()
- notifications/tasks.py: 2 print statements → logger.error()

Retained print() in settings files (development.py, selfhosted.py) as they are appropriate warnings to stderr for configuration issues.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-22 22:34:57 -07:00
Keith SmithandClaude Sonnet 4.5 6a0b35c39c Initial commit: KeepItGoing task management server
Features:
- Django-based REST API with web interface
- Task management with tags, priorities, and due dates
- Time tracking with start/stop timers
- Subtasks support
- Task filtering (all, today, upcoming, overdue, completed)
- Tag-based organization with color coding
- Sorting by due date and priority
- Auto-assign tags when filtering
- Responsive 3-pane layout (sidebar, task list, detail panel)
- Task sharing between users
- Mobile-responsive design with dark mode support

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2025-12-18 17:41:29 -07:00