Desktop could not create an attachment at all, and a removed attachment or
dismissed preview came back on the next pull. Now:
- core: add_attachment keeps the bytes in the blob store and queues the row
(schema v10: attachments.uploaded / upload_error). Push uploads it once its
note has landed. A refusal that retrying won't fix (too large, id clash, hash
mismatch) is recorded on the file and not re-sent every cycle; the editor
shows it.
- core: removing a synced attachment or dismissing a preview leaves a tombstone
in pending_deletes; push sends it as an `attachment`/`preview` delete, and a
pull while it waits doesn't put the row back. A pull also keeps files still
waiting to upload instead of replacing them wholesale.
- server: PUT /api/sync/attachments/<id> (raw body, sha256-checked, idempotent,
size-capped) and child deletes in push, which apply regardless of LWW and
answer noop for rows the caller can't see. One store_attachment helper for
the upload route, the importer and sync. Protocol 5, feature attachment_sync;
the client sends neither to a server without it.
- server: migration 0031 makes a link preview's insert/delete bump its note, so
background-fetched previews and web dismissals reach linked devices.
- desktop: Attach and paste-image work offline (raw-bytes IPC command).
- SVG is served as a download by the desktop blob scheme too (as #1981 did for
the web), and drawn as a file chip on both.
- autosync: drop the catch_unwind; release builds abort on panic, so it only
ever worked in debug builds.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Both notes-store uploads (uploadAttachment, importNotes) hand-rolled the
same fetch + resp.json() + !ok error parsing that api.client already does.
Add `api.postForm<T>(path, form)`: request() now detects a FormData body
and lets the browser set the multipart Content-Type (skipping the JSON
header + stringify), reusing the shared error handling — so the two
uploads gain network-error handling and the 5xx infra toast they lacked.
A too-large import returns 413 (< 500), so it still throws for inline
display rather than toasting.
DRY: net -13 lines; no raw fetch() remains in the stores.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
The api client now catches network failures and non-JSON bodies robustly,
and routes unexpected errors (offline / 5xx) to a global toast — 4xx stay
with the caller so forms keep their inline messages. Toast actions are now
optional (undo toasts keep their button; error toasts are message-only), and
ToastHost moved from AppShell to the app root so toasts show everywhere,
including the login screen.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
- AppShell: persistent left sidebar (Notes · labels · Archive · Trash) + top bar
(site name, admin Settings, sign out); BoardView now renders inside it.
- labels store (list/create/rename/delete); Note gains labels[]; notes store
gains setLabels + label-aware reconcile + /api/notes?label= loading.
- /label/:id route → label-filtered board.
- LabelPicker (tag a note, create-on-the-fly) in the editor; label chips shown
on cards and in the editor; LabelsModal to create/rename/delete labels.
- api client PUT; new icons (note/tag/pencil/plus/check); nav-link styles.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
- Vite + Vue 3.5 + Pinia + vue-router + Tailwind (brand accent #F5C518),
dark-mode aware, deterministic package-lock.json for `npm ci`.
- Session store (fetchMe/login/register/logout) over a credentials:'include'
fetch client; router guards (requiresAuth / guestOnly) with lazy /me resolve.
- BaseButton + BaseInput primitives (focus rings, loading, error states).
- LoginView, RegisterView, and an authed BoardView shell with an empty state
for the M1 masonry board — all at v1 polish (rule 24).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm