# Project Status Report **Updated:** 2026-07-22 **Branch:** main **Last Commit:** 09f51d1 - Add queued email notifications for collaboration events ## Quick Stats | Metric | Value | |--------|-------| | Total Tracked Files | 201 | | Go Files | 63 | | Swift Files | 15 (macOS app and package manifest) | | Go Test Files | 18 | | Aggregate Go Test Coverage | 52.4% | | Milestones Complete | 3/6 (50%) | ## Verification - `go test -coverpkg=./... -coverprofile=... ./...` passes with 52.4% aggregate statement coverage. - `swift build` passes for the macOS app and CLI. - Focused race tests pass for email, collaboration, and HTTP packages. A full `go test -race ./...` exceeds the current five-minute local timeout. - `govulncheck` currently fails because Go 1.24.2 has 31 reachable standard-library vulnerabilities; the pinned Go toolchain must be upgraded before production sign-off. - Highest package coverage: Markdown 87.0%, email 77.9%, store 70.0%, config 67.9%, auth 54.9%, and sync 54.2%. - Collaboration, configuration, email-provider, and collaboration HTTP integration tests are present; database, logging, and realtime still lack direct suites. ## Recent Activity Recent work has moved the project beyond the previous 2026-06-24 report: - Durable email queue with retry/backoff and failed-delivery inspection. - Postmark outbound sender with API-level tests. - Cloudflare Email Service REST sender with retry/permanent-error classification and API-level tests. - File-change and comment notifications now enqueue email delivery. - Notification bell/list/read UI is active. - Document watch/unwatch controls are active, watcher subscriptions are deduplicated, and ancestor-folder matching is fixed. - Nested comment replies, whole-thread resolution, and resolved-history UI are active. - Notification dispatch rechecks the watcher's current document permission. - Existing users can add another passkey from their account page. - Resource permission UI and private-by-default filtering cover documents, folders, navigation, search, API document lists, and native sync snapshots. - CodeMirror editor, wiki-link autocomplete, keyboard navigation, mobile drawers, archive UI, and tag pages are present. - The macOS menu-bar app and CLI compile successfully. ## Milestone Progress - [x] Milestone 1: Foundation - [x] Milestone 2: Sync Protocol - [x] Milestone 3: Authentication - [ ] Milestone 4: Collaboration (threaded comments, notification bell, watch controls, and queued Postmark/Cloudflare/SMTP delivery shipped; preferences, digest, inbound replies, mention/conflict triggers, and live-provider tests remain) - [ ] Milestone 5: Search & UI (server FTS5, tags, keyboard navigation, and responsive foundations shipped; offline client search, `/design`, performance, and accessibility validation remain) - [ ] Milestone 6: Production (health/readiness endpoints, CI, deployment scaffolding, and some integration tests exist; hardening acceptance criteria remain open) ## Current Focus Milestone 4 collaboration completion: - Add notification preferences and digest delivery. - Add inbound email replies through a verified webhook flow. - Add mention and conflict notification triggers. - Test watcher-to-email delivery against live Postmark and Cloudflare accounts. ## Known Gaps Requiring Human Review - Go 1.24.2 is below the patched versions reported by `govulncheck`, including fixes for `html/template`, `crypto/tls`, `net/http`, and `crypto/x509` vulnerabilities. - WebSocket broadcasts are authenticated but not filtered by per-document permissions. - Content-hash downloads are not tied back to effective document permission. - Browser caches are not cleared on logout. - Raw HTML is enabled in authored Markdown while the security specification says it should be disabled. - Folder/collection permission administration is only fully discoverable for documents. - The implementation uses JSON for SimpleSync while protocol documentation still leaves JSON versus protobuf unresolved. - Backup documentation does not match the named data volume in Compose. --- *This report is maintained from the implementation and verification results, not milestone checkbox state alone.*