Previously priority sorting was alphabetical (high < low < medium < urgent)
instead of by importance. Now uses Django Case/When to map priority strings
to numeric values: urgent=4, high=3, medium=2, low=1.
Fixes both queryset sorting and list sorting for overdue filter.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Adds automatic creation of next task instance when recurring tasks are completed.
- Add calculate_next_due_date() and create_next_recurrence() methods to Task model
- Update task completion handlers in views and sync API to create next recurrence
- Add hourly Celery task to process any missed recurring tasks
- Support daily, weekly, biweekly, monthly, yearly recurrence patterns
- Respect recurrence_end_date limits
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Added validation for status, priority, and recurrence fields in web forms to prevent invalid database values.
Changes:
TaskUpdateView.post() (line 419):
- Validate status against Task.STATUS_CHOICES before setting
- Validate priority against Task.PRIORITY_CHOICES before setting
- Validate recurrence against Task.RECURRENCE_CHOICES before setting
- Only update fields if value is in allowed choices
- Default to 'none' for invalid recurrence values
TaskCreateView.post() (line 481):
- Validate status, default to 'pending' if invalid
- Validate priority, default to 'medium' if invalid
- Validate recurrence, default to 'none' if invalid
- Prevents creation with invalid choice values
Allowed Choices:
- Status: pending, in_progress, completed, cancelled
- Priority: low, medium, high, urgent
- Recurrence: none, daily, weekly, biweekly, monthly
Security impact:
- Prevents invalid database values from user input
- Maintains data integrity
- Blocks potential business logic bypasses
- Prevents database constraint violations
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Fixed open redirect vulnerability in 9 locations throughout tasks/views.py.
Changes:
- Added url_has_allowed_host_and_scheme import from django.utils.http
- Created safe_redirect() helper function to validate redirect URLs
- Only allows relative URLs or URLs to the same host
- Prevents attackers from redirecting users to phishing/malicious sites
Fixed locations:
- Line 447: TaskUpdateView - task update redirect
- Line 501: task_quick_add - quick add redirect
- Line 521: subtask_create - subtask creation redirect
- Line 537: task_toggle_status - status toggle redirect
- Line 549: task_delete - task deletion redirect
- Line 601: web_timer_start - timer start redirect
- Line 626: web_timer_stop - timer stop redirect
- Line 672: TagUpdateView - tag update redirect
- Line 684: tag_delete - tag deletion redirect
Security impact:
- Prevents phishing attacks via malicious redirect URLs
- Blocks cache poisoning attacks
- Ensures users stay within the application domain
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Added comprehensive authorization checks to prevent users from:
1. Sharing tasks/tags they don't own
2. Modifying tasks/tags that are only shared with them (read-only access)
Changes:
tasks/serializers.py (TaskShareSerializer):
- Added validation in validate() method to verify task/tag ownership
- Users can only share their own tasks and tags
- Prevents malicious users from sharing other people's resources
tasks/permissions.py (NEW):
- Created IsOwnerOrReadOnlyIfShared permission class
- Owners: full access (read, update, delete)
- Shared users: read-only access
- Prevents privilege escalation via shared access
tasks/views.py:
- Applied IsOwnerOrReadOnlyIfShared to TaskDetailAPIView
- Applied IsOwnerOrReadOnlyIfShared to TagDetailAPIView
- Enforces object-level permissions on all update/delete operations
Security impact:
- Prevents users from modifying or deleting resources they don't own
- Prevents users from sharing resources they don't own
- Maintains proper separation between owner and shared access levels
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Features:
- Django-based REST API with web interface
- Task management with tags, priorities, and due dates
- Time tracking with start/stop timers
- Subtasks support
- Task filtering (all, today, upcoming, overdue, completed)
- Tag-based organization with color coding
- Sorting by due date and priority
- Auto-assign tags when filtering
- Responsive 3-pane layout (sidebar, task list, detail panel)
- Task sharing between users
- Mobile-responsive design with dark mode support
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>