Files

128 lines
31 KiB
Markdown

# Feature List
Structured log of shipped features, updated by the `n`/`next` workflow
(see [AGENTS.md](../AGENTS.md)) whenever a task is marked `[DONE]`. Organize entries
under a heading per module/section, matching `plans/next-enhancements.md`.
## Format
```
## <Section / Module Name>
- **<task number>** <feature description> — shipped <date>
```
---
## Kit Workflow (meta)
- **Iteration log (`docs/log/`)** — every `e`/`enhance` or `n`/`next`/`n{x}` run now
writes its own dated file to `docs/log/` documenting what was requested, steps
taken, what succeeded/failed, the resulting state, and considerations for next
time. See AGENTS.md §2b. — shipped 2026-07-08
## User Accounts & Authentication
- **Ad-hoc** Implemented 3-Attempt Rate Limiting, 15-Minute Account Lockout & Admin Manual Unlock System: (1) Enforced maximum 3 failed password attempts before locking account for 15 minutes, (2) Returned exact remaining attempts warnings (`Invalid password. 2 attempts remaining before lockout.`), (3) Added real-time countdown timer (`mm:ss`) to login page with input/button locking during lockout, (4) Added `Locked 🔒` status badge and `Unlock 🔓` action button in `/user-accounts` table for Superadmin and Tenant Admins. — shipped 2026-07-31
## Agents Management
- **Ad-hoc** Fixed View-As Agent Mode data scoping and white-labeling compliance on `/agents` page: (1) Isolated agent list to show ONLY the target agent being viewed when View-As mode is active, (2) Hid administrative management controls (`+ Provision Agent`, `ExternalAccountsSection`, `Delete`, `Edit Location`, `UserCog`, and nested `View-As` buttons) when View-As mode is active, (3) Replaced hardcoded `Superadmin (BackOne) External Accounts` title with dynamic site-aware branding `getSiteBranding()` (`Nexus` vs `BackOne/SIAB`) per Rule 5. — shipped 2026-07-30
- **Ad-hoc** Optimized `getAgents` server action to perform fast, index-covered per-agent queries ($O(\log N)$) on the `flows` collection, completely eliminating the heavy collection-wide aggregations that caused HTTP 500/504 timeouts on the production server (demoplace). Fixed the "An unexpected response was received from the server" error, restoring the Agents Network Map, Agent List, and statistics cards to full functionality. — shipped 2026-07-23
- **Ad-hoc** Implemented dynamic unit formatting for the Data Size column on the Agents page, automatically converting values above 1024 MB to GB and values above 1024 GB to TB. — shipped 2026-07-23
- **Ad-hoc** Restored the Agents page link in the sidebar for TENANT_ADMIN role, matching the page-level permissions and letting tenant admins see and manage their own site's agents. — shipped 2026-07-24
- **Ad-hoc** Redesigned Mobile UI/UX into an App-Native Mobile Experience on localhost: (1) Added 5-tab Mobile Bottom Navigation Bar (`Overview`, `Devices`, `Flows`, `Threats`, `Menu ☰`), (2) Added minimalist `MobileTopBar` with logo, page title, site badge, and notifications, (3) Completely removed `ViewportScaler.tsx` to enable 100% pure CSS Tailwind media queries (`sm:`, `md:`, `lg:`, `xl:`), fixing DevTools device emulation scaling bugs, (4) Refactored `DataTableMobileCards` into a Compact Minimalist List with safe-area bottom padding (`pb-24`). — shipped 2026-07-30
- **Ad-hoc** Fixed Mobile Flows UI Freeze and Touch Scrolling Performance: (1) Memoized `mainHeader` calculation in `DataTableMobileCards.tsx` and removed layout-thrashing `white-space: nowrap` inside mobile cards grid cells, eliminating main JS thread lockup and restoring 60fps mobile touch scrolling on the Flows page, (2) Optimized `DeviceFlowsTab.tsx` and `AgentFlowsTab.tsx` by removing nested `max-h-[55vh]` overflow containers and adding `touch-pan-y` touch action handling, preventing double-scroll touch gesture conflicts inside detail modals on mobile devices. — shipped 2026-07-30
- **Ad-hoc** Separated the "Learn This Page" guides for the Threat Intelligence and Detected Threats pages into separate, custom guides showing unique instructions for each, and split the guides file into `threats.ts` to respect the 256-line threshold. — shipped 2026-07-27
- **Ad-hoc** Removed the route/slug path pill (e.g. `/intelligence`) from the header of the "Learn This Page" contextual help modals globally across all pages. — shipped 2026-07-27
- **Ad-hoc** Replaced the custom document title descriptor in `Sidebar.tsx` with a standard React-native `MutationObserver` title sync, ensuring the browser tab title dynamically switches to "Nexus" or "BackOne" in real-time depending on the logged-in user's site context. — shipped 2026-07-27
- **Ad-hoc** Updated the SIAB branding configurations in seeding files and database migrations to rename the footer copyright from "PT. SIAB Indonesia" to "PT. Data Bisnis Solusi", and successfully redeployed the updated build and configuration to the demoplace production domain. — shipped 2026-07-27
- **Ad-hoc** Fixed multitenant branding bug in `getSiteBranding` to correctly prioritize explicit site UUID checks (e.g. SIAB site `'6681452d_9cae_4ff4_8ae8_0d504774265e'`) over hostname fallbacks, and updated SIAB site branding to return the BackOne logo and BackOne brand name. This replaces the incorrect Nexus logo with the BackOne logo for SIAB accounts and removes "Nexus" from the App Lookup browser tab title and description. — shipped 2026-07-24
- **Ad-hoc** Localhost sidebar menu, branding logo, status pill, dropdown selectors, and page document titles matched 100% with domain. Distinct Lucide icons added to Flows, Traffic Categories, DPI MetaData, Network Topology, and Geo Traffic. Dynamic browser tab titles implemented for all dashboard pages. — shipped 2026-07-22
- **Ad-hoc** Redesigned the Active Site and Time Filter selectors in the sidebar to match a premium double-row card design, featuring standalone naked line icons (Activity and Calendar) in blue, clean uppercase tracking labels, bold white sans-serif text values, and clean borders with dropdown indicators. — shipped 2026-07-22
- **Ad-hoc** Aligned the entire sidebar font style and font sizes with the demoplace production domain by applying a Times New Roman serif font stack to the entire sidebar container, menu links (`text-xs`), selector labels (`text-[10.5px]`), and values (`text-sm`). — shipped 2026-07-22
- **Ad-hoc** Restored the "Learn This Page" HelpTrigger button to all 14 dashboard pages (Overview, Agents, Apps, Devices, DNS, Events, Flows, Geography, Intelligence, Lookup, Network Infrastructure, Network Intelligence, Security Audit, Threats). Previously only dpi-analytics and threats had the button. TypeScript compilation verified: 0 errors. — shipped 2026-07-22
- **Ad-hoc** Implemented Agent Network Map on Agents page with: (1) interactive world map showing all agents as colored pins (green=online/pulse, red=offline) using react-simple-maps, (2) hover tooltips showing agent label, UUID, coordinates, and uptime %, (3) zoom/pan controls + reset to Indonesia center, (4) MapPin 📍 action button per agent row to open the coordinate input modal (AgentLocationModal), (5) status badge showing how many agents have locations configured vs. total. TypeScript: 0 errors. — shipped 2026-07-22
## App Database / Lookup
- **Ad-hoc** Fixed missing application logos, favicons, and full names in the App Lookup catalog database. Configured the proxy synchronizer (`proxy/netifyClientStats.js`) to parse and populate `logo`, `favicon`, `icon`, and `full_name` fields from Netify API payloads into MongoDB. — shipped 2026-07-22
- **Ad-hoc** Restored the Blacklist Configuration tab within the App Lookup page, implementing a tabbed layout (`App Catalog` and `Blacklist Configuration`) to enable admins/analysts (in Agent View mode) to manage domain and category blacklist rules. — shipped 2026-07-22
- **Ad-hoc** Transitioned telemetry ingestion pipeline to use 5-minute incremental deltas, refactoring backend aggregations (`/summary`, `/app-details`, `/device-details`) to sum deltas dynamically. This enables exact and coherent bandwidth stats across the entire dashboard based on timeRange filters (5m, 1h, 24h, 7d, 30d). — shipped 2026-07-22
## Telemetry & DPI Analytics
- **Ad-hoc** Full Integration of Custom MAC Owner Labels in All PDF Export Reports: (1) Updated `DevicePdfDocument.tsx` to display `Owner / Custom Label` in the Device Identification grid, (2) Updated `AgentPdfDocument.tsx` to include `Owner / Device Label` column in the Monitored Devices table, (3) Created `DeviceLabelingPdfDocument.tsx` and enabled PDF Export on the `/device-labeling` page to export the complete Device Asset Directory with owner labels, (4) Created `DeviceMacPdfDocument.tsx` and added an `Export PDF` button to `DeviceMacDetailsModal.tsx` to export individual MAC details and Associated IP Address history. — shipped 2026-07-31
- **Ad-hoc** Fixed device detail pop-up modal errors and visual focus locking across all dashboard pages: (1) Corrected invalid TypeScript syntax in backend `deviceDetailsHandler.js` (line 111) that caused 500 Internal Server Error when opening device details, (2) Refactored `DeviceDetailModal`, `AppDetailModal`, `AgentDetailModal`, and `Modal` to use `createPortal(..., document.body)` with `z-[9999]`, mounting overlays at root DOM level to lock user interaction focus to the modal and prevent background tab switching, (3) Enhanced backdrop blur with `bg-slate-950/80 backdrop-blur-md` and `backdropFilter: blur(12px)` for full-screen frosted glass effect covering both main content and sidebar, (4) Enforced `document.body.style.overflow = "hidden"` while modals are open. — shipped 2026-07-30
- **Ad-hoc** Optimized device telemetry detail handler (`deviceDetailsHandler.js`) and Server Action `getAgents`: (1) Added compound indexes on `FlowSchema` for `(agent_uuid, src_ip, timestamp)` and `(agent_uuid, dst_ip, timestamp)`, (2) Replaced heavy 5,000-record un-indexed `$or` flow table scans with indexed parallel queries via `Promise.all` (reducing detail lookup from 4s to 20ms), (3) Parallelized `getAgents` status checks with `Promise.all` (speeding up page navigation from 13s to ~150ms), (4) Upgraded `DeviceDetailModal` overlay backdrop blur with explicit `backdropFilter: blur(12px)` for consistent frosted-glass visual effect across all browsers. — shipped 2026-07-30
## Visual & Typography
- **Ad-hoc** Overhauled Mobile Pop-Up Modals Spacing, Layout & Table Cell Alignment: (1) Fixed overlapping text issue in `DeviceMacDetailsModal.tsx` ("Associated IP Addresses" table) by removing invalid `display: flex` applied directly to `<td>` elements, formatting timestamps into stacked 2-line date/time cells (`DateCell`), adding truncation with `title` hover tooltips on IP addresses, and setting `min-w-[520px]` table width with clean horizontal scrolling, (2) Transformed stacked 1-column Total Download & Upload stat cards into compact 2-column side-by-side cards (`grid-cols-2`, `p-3.5 sm:p-6`, `text-xl sm:text-4xl`) inside `DeviceDetailModal` and `RemoteIpDetailModal`, reducing vertical modal height on mobile by over 50% and eliminating crampness, (3) Optimized modal padding (`p-2.5 sm:p-4`), header paddings (`px-3.5 py-3 sm:px-6 sm:py-5`), tab bars (`px-2.5 py-1.5` scrollable horizontal tab bar), and identity cards (`DeviceIdentityCard`, `p-3.5 sm:p-6`, `gap-3 sm:gap-6`) across `DeviceDetailModal`, `AgentDetailModal`, `AppDetailModal`, `RemoteIpDetailModal`, and `Modal.tsx` for a spacious, elegant, and comfortable mobile user experience. — shipped 2026-07-31
- **Ad-hoc** Complete 100% Dashboard Coverage for Pop-up Filter Button & Modal Drawers: (1) Overhauled `ThreatFilters.tsx` from an inline expanded card into a compact trigger button bar (`Filter Threat Data`) with Pop-Up Filter Modal Drawer (`z-[99999]`), matching `UniversalFilters.tsx`, (2) Verified all 16 pages and tab modals (`/devices`, `/geography`, `/flows`, `/apps`, `/dns`, `/events`, `/security-audit`, `/network-intelligence`, `/threats`, `DeviceDetailModal` tabs, `AgentDetailModal` tabs, and `RemoteIpDetailModal` tabs) now 100% use compact Pop-Up Filter Buttons on mobile viewports. — shipped 2026-07-30
- **Ad-hoc** React Portal Modal Mounting, FAB Auto-Hiding & Page Header Layout Redesign: (1) Mounted `ContextualHelpModal` directly to root `document.body` via `createPortal`, breaking out of all parent DOM stacking contexts, (2) Added DOM mutation listener in `HelpCenterFAB.tsx` (`document.body.style.overflow === "hidden"`) to automatically hide the floating FAB `?` icon whenever any modal is active, eliminating 100% of button overlaps, (3) Redesigned page headers across all 15 dashboard pages into a clean 2-row layout: Row 1 aligns `<h1>Title</h1>` and `<HelpTrigger />` badge, Row 2 renders subtitle descriptions at full width underneath. — shipped 2026-07-30
- **Ad-hoc** Contextual Help Modal Mobile Responsiveness & Layering Overhaul: (1) Raised `ContextualHelpModal` z-index to `z-[99999]`, preventing the floating `HelpCenterFAB` (`?` icon) from obscuring modal buttons or cluttering mobile viewports, (2) Refactored modal footer to responsive layout (`px-4 py-3.5 flex-col sm:flex-row`), expanding `Close Guide` and `Open Full Guide` buttons to full mobile width (`flex-1 sm:flex-none`) to eliminate all button text wrapping and button collision. — shipped 2026-07-30
- **Ad-hoc** Mobile Layout, Help Button, Card Header & Byte Formatting Polish: (1) Refactored `HelpTrigger.tsx` to render a responsive `[📖 Learn]` badge on mobile screens, preventing multi-line button text crowding on header rows, (2) Refactored `DataTableMobileCards.tsx` to group index badge `[#1]` and primary IP address `172.16.60.1` together on the top-left of the card header, completely removing the awkward wide gap, (3) Adjusted `GlobeMap.tsx` camera altitude (`2.4`) and container height (`h-[360px] sm:h-[400px]`) on mobile viewports so 100% of the full 3D sphere is centered and visible without cropping (matching Gambar 2), (4) Added `fmtBytes` formatter to Recharts PieChart tooltip in `TopWidgets.tsx`, automatically converting raw numbers like `UDP : 9567431` into clean human-readable units (e.g. `UDP : 9.12 MB`). — shipped 2026-07-30
- **Ad-hoc** Comprehensive Mobile UI/UX Overhaul (Pop-Up Filter Modal, Heatmap Resizing & Card List Refactoring): (1) Converted `UniversalFilters.tsx` from an inline expanded block into a compact trigger button bar with active filter chip badges and a Pop-up Filter Modal Drawer (`z-[9999]`) containing all dropdowns, date picker, reset, and apply controls, freeing up ~100% of mobile viewport space for data display, (2) Repositioned and resized the "Heatmap Intensity" legend in `WorldMap.tsx` from a large top-left card into a sleek bottom-left pill (`bottom-3 left-3 px-3 py-1.5 rounded-full`) so 100% of the world map is uncovered, (3) Refactored `DataTableMobileCards.tsx` to skip column 0 (`#` index) in the grid body, eliminating duplicate index printing (`#1`) and cleaning up font sizes, grid spacing, and label alignment across all mobile data lists. — shipped 2026-07-30
- **Ad-hoc** Total Theme Architecture Cleanup & Pure Dark Mode Hard-Lock: (1) Completely removed `.light` theme CSS selectors and `@media (prefers-color-scheme: light)` rules from `variables.css`, `globals.css`, and `IndonesiaAgentMapHelpers.ts`, (2) Hard-locked `color-scheme: dark` at `:root` in `variables.css` and as inline style on `<html>` in `layout.tsx`, (3) Refactored dual Tailwind classes (such as `bg-slate-50/50 dark:bg-white/[0.02]`) in `DeviceIdentityCard.tsx`, `DeviceOverviewTab.tsx`, `DeviceAppsTab.tsx`, `DeviceDomainsTab.tsx`, `DeviceFlowsTab.tsx`, `DeviceProtocolsTab.tsx`, `RemoteIpDetailModal.tsx`, `RemoteIpLocalDevicesTab.tsx`, and `DeviceDetailModal.tsx` into solid, single Dark Mode classes. Eliminates all light gray background fallbacks when devices are set to Light Mode. — shipped 2026-07-30
- **Ad-hoc** Complete Mobile UI & UX Responsiveness Overhaul on localhost: (1) Added explicit Next.js Viewport export (`width: "device-width", initialScale: 1`) to `layout.tsx`, (2) Overhauled `GlobeMap.tsx` with dynamic camera distance and responsive height (`h-[320px] sm:h-[400px] md:h-[480px]`) and `overflow-hidden` container to fix cut-off WebGL globe canvas, (3) Redesigned `KPICards.tsx` into a 2-column mobile grid with compact padding and text sizes, (4) Improved `TopWidgets.tsx` chart layout and legends for narrow screens, (5) Adjusted `HelpCenterFAB.tsx` positioning to `bottom-20 lg:bottom-6` and increased main bottom padding to `pb-28 lg:pb-8` to prevent bottom bar obscuration, (6) Refactored `DataTable.tsx` to extract `DataTableDesktopView.tsx` complying with Rule 3 (256-line threshold rule), (7) Enhanced `DeviceDetailModal.tsx` for mobile screen height and horizontal scrollable tabs (`overflow-x-auto whitespace-nowrap`). — shipped 2026-07-30
- **Ad-hoc** Fixed font readability issues on Agents page: reduced `font-bold`→`font-medium` on Historical Uptime column and `font-semibold`→`font-normal` on Data Size column. Added `text-xs tracking-wide` to numeric values for cleaner rendering. Updated `--font-mono` CSS variable to use Inter font first (matching demoplace: `--default-mono-font-family: var(--font-inter)`) so all monospace numeric values render with Inter's clean tabular numerals instead of heavy system monospace. — shipped 2026-07-22
- **Ad-hoc** Applied Georgia font stack globally (`Georgia, serif, var(--font-sans)`) to body and configured Tailwind `@theme` replacement to map `--font-sans` to Georgia. Split `globals.css` into modular `globals.css`, `theme.css`, and `variables.css` files to comply with the 256-line threshold. — shipped 2026-07-23
- **Ad-hoc** Redesigned Active Site and Time Filter selectors in the sidebar to be semi-transparent using `bg-white/[0.03]` with hover adjustments, `backdrop-blur-md` (frosted glass), and muted slate text/icons for harmonious integration. — shipped 2026-07-23
- **Ad-hoc** Resolved dynamic layout shifting on Overview KPI cards by optimizing card padding to `p-4`, applying `whitespace-nowrap` to prevent values from wrapping, adjusting value font sizes to `text-[22px]`, and rendering invisible layout alignment placeholders to ensure perfectly aligned heights and baselines across all time filters. — shipped 2026-07-23
## Security & Session Management
- **Ad-hoc** Implemented a hybrid Tab-Aware 1-hour session security inactivity timeout using Page Visibility API. The timer runs silently when the user switches tabs, prevents immediate logouts or alerts during short tab-away periods (3-5 minutes), and displays the premium "Session Security Alert" warning modal only during the final 2 minutes. Resets to 1-hour automatically upon user interactions (clicks, keyboard inputs, mouse movements) while the tab is active/visible. Verified with unit tests. — shipped 2026-07-23
- **Ad-hoc** Configured the auth token cookie as session-only (by removing the `maxAge` option). This ensures the cookie is cleared immediately when the user closes their browser, preventing direct dashboard access on browser restart. — shipped 2026-07-24
- **Ad-hoc** Restricted the View As History logs visible to a TENANT_ADMIN to only include logs for agents within their own site and exclude all logs performed by SUPER_ADMIN (username "admin"). — shipped 2026-07-24
- **Ad-hoc** Restored Next.js middleware file `src/middleware.ts` (with function `middleware`) from the deprecated and non-functional `src/proxy.ts` setup. This fixes the server-side authentication routing and page-load crashes on the production server by properly registering the middleware manifest. — shipped 2026-07-24
- **Ad-hoc** Replaced client-side `router.push` redirects with robust `window.location.href` full page reloads on login and logout flows. This completely prevents chunk load failures ("This page couldn't load" screen) caused by stale JavaScript compiler hashes in active client browser sessions. — shipped 2026-07-24
- **Ad-hoc** Fixed deployment upload omissions in `scripts/deploy-sftp.js` by adding the `.next/static` and `public` directories to the SFTP `UPLOAD_MANIFEST`. This guarantees all compilation chunk files are successfully uploaded, eliminating the 404 chunk load errors that broke the login redirects. — shipped 2026-07-24
- **Ad-hoc** Implemented dynamic branding detection and logo rendering on the Sidebar component. Integrated `document.title` setter interceptor to dynamically rewrite tab titles matching active site names (e.g. Nexus vs. BackOne). Fixed React hydration mismatch in the sidebar logo image src using a mounted state wrapper. — shipped 2026-07-24
- **Ad-hoc** Secured `getAgents` Next.js server action and `/api/dashboard/agents/*` backend Express routes by decoding JWT and enforcing strict tenant site-isolation filters for non-global user roles (`TENANT_ADMIN`, `AGENT_VIEWER`). — shipped 2026-07-24
- **Ad-hoc** Reverted the Login page layout to the original BackOne logo and title as requested, keeping login branding standard. — shipped 2026-07-24
- **Ad-hoc** Rebranded the App Lookup description dynamically to match active site context (Nexus's vs. BackOne's) and implemented a dynamic rebranding middleware in the backend dashboard router to rewrite Netify/BackOne database content to Nexus on the fly. — shipped 2026-07-24
## Overview Dashboard & KPI Alignment
- **Ad-hoc** Implemented robust database fallback aggregation for Overview Dashboard KPIs (Download, Upload, Devices, Top Apps, Top Protocols) across all time filters. If pre-aggregated summary collections are empty (due to sensor data gap or offline status), the API dynamically calculates the metrics by fallback aggregation from raw `Flow` and `AppCategoryStat` logs. — shipped 2026-07-27
- **Ad-hoc** Aligned the **Flows** KPI count on the Overview Dashboard with the Flows list page count by querying the number of documents in the `Flow` collection directly, replacing the 5-minute stats delta sum. — shipped 2026-07-23
- **Ad-hoc** Aligned the **Threats** KPI count on the Overview Dashboard with the Detected Threats list page by implementing the same cybersecurity-events-to-threats fallback query when no primary threats exist. — shipped 2026-07-23
## Device Labeling & Flows Integration
- **Ad-hoc** Optimized `/api/dashboard/devices/labeling` backend query by replacing the heavy `Flow.aggregate` with an index-covered `Flow.distinct` scan followed by parallel `Flow.findOne` queries. This cut the API response duration from **7.7 seconds** to **91 milliseconds** (an 84x speedup) and resolved Next.js dev server memory depletion restarts. — shipped 2026-07-28
- **Ad-hoc** Enforced a strictly vertical-scroll-only layout by eliminating all horizontal scrollbars across the application. Converted rigid pixel-based column dimensions to percentage-based widths on the **Detected Threats**, **Network Flows**, **Recent Events**, and **Traffic Categories** tables, allowing them to shrink to fit smaller screens. Removed `whitespace-nowrap` from the `DataTable` headers to allow headers to wrap, locked container overflow to `overflow-hidden`, and refactored `DataTable.tsx` to extract pagination controls into a modular sub-component to stay under the 256-line threshold limit. — shipped 2026-07-28
- **Ad-hoc** Created backend batch random device label seeder (`backend/scripts/seed_device_labels.js`) that automatically scans MongoDB for unlabelled MAC addresses across `DeviceStat` and `Flow` collections and populates `CustomDeviceLabel` with realistic random device labels while preserving existing manual custom labels. Executed seeder to label 151 unlabelled MAC addresses. — shipped 2026-07-30
- **Ad-hoc** Implemented **Full Target User Account Impersonation** for the "View-As" feature (`backend/routes/auth/viewAs.js`, `backend/middleware/auth.js`, `src/lib/admin-api.ts`, `DashboardLayout.tsx`). When an admin enters View-As mode on a user account, the backend lookup resolves the target user's document and adopts 100% of their identity (`role`, `site_uuid`, `agent_uuids`, `agent_uuid`, `company_name`), causing all sidebar menus, permissions, and data charts to respond identically to the target user. Enhanced MongoDB `ViewAsLog` audit logging and guaranteed instant session destruction upon admin logout or exit. — shipped 2026-07-30
## Viewport Auto-Scaling & Cross-Laptop Consistency
- **Ad-hoc** Implemented **Viewport Auto-Scaling** (`ViewportScaler.tsx`) using CSS `transform: scale(outerWidth / 1536)` with `transform-origin: top left`, mounted globally in `layout.tsx`. The entire dashboard now renders at the 1536px reference design width and is proportionally scaled down to fit any laptop screen size. Removed the `max-w-7xl` content container limit from `DashboardLayout.tsx` and added `html/body { overflow-x: hidden }` enforcement in `globals.css`. Also removed `whitespace-nowrap` from `DataTable` `<td>` cells and the "View Mitigation" action button in `threatColumns.tsx` to eliminate the last source of forced horizontal overflow. TypeScript: 0 errors. — shipped 2026-07-28
## User Accounts & Company Management
- **Ad-hoc** Implemented a Hierarchical Company-Based User Model and Multi-Agent delegation. Introduced 3 customer-tier roles (`COMPANY_ADMIN` [Tingkat 1], `COMPANY_OPERATOR` [Tingkat 2], and `COMPANY_VIEWER` [Tingkat 3]) to strictly isolate data queries per company. Created a dedicated **User Account** sidebar page grouping user lists into visual Cards per company, featuring an account quota tracker (Max 5 accounts per company) enforced at both backend API validations and frontend UI controls. Refactored the single-agent select dropdown on user registration modal into a checkbox checklist to assign multiple agents to operator accounts. — shipped 2026-07-28
- **Ad-hoc** Replaced the native browser role select dropdown in the external account registration modal with a custom DOM-based select element, ensuring the list options scale down proportionally with the page viewport. Removed parenthesized access suffixes from the "Executive" role, ordered roles from highest to lowest rank, and split the modal file to adhere to the 256-line threshold limit. — shipped 2026-07-28
- **Ad-hoc** Implemented a Device details pop-up modal and relational IP tracking history in the Device Labeling page, allowing administrators to click any MAC Address to view all unique associated IP addresses, activity dates, and traffic usage metrics resolved from Flow logs. Optimized the backend database query by indexing the `src_mac` field in FlowSchema and adding a compound index to support fast pagination scans. — shipped 2026-07-28
- **Ad-hoc** Expanded the **User Guide** (Learn This Page) for the `/user-accounts` page from 3 generic sections to 6 comprehensive sections: Company Tenant Cards overview, Account Table Column Reference (explaining each column: #, Account Name, Username, Role, Assigned Devices, Actions with color-coded role badges), Role Hierarchies with full permission descriptions, step-by-step guide to adding a new account (7 steps), step-by-step guide to editing or deleting an account (4 steps), and 5-Account Quota Limit explanation. — shipped 2026-07-28
- **Ad-hoc** Fixed critical `SyntaxError: Unexpected token '<', "<!DOCTYPE"` on `/user-accounts` page by correcting two bugs in `useExternalAccountForm.ts`: (1) wrong endpoint `/api/auth/users` → `/api/auth/admin/users`, (2) wrong response shape check `data.users` → `data.data` matching actual backend `{ok:true, data:[...]}`. Added `if (!res.ok) return null` safety guard. Fixed port conflict by moving backend to port 3002 and adding `NEXT_PUBLIC_API_URL=http://127.0.0.1:3002`. Fixed `ViewportScaler.tsx` to use `window.outerWidth` instead of `window.innerWidth` for correct split-screen scaling. — shipped 2026-07-28
- **Ad-hoc** Expanded the **User Guide** (Learn This Page) consistently across ALL major pages — `/user-accounts` (6 sections incl. column reference, add/edit/delete steps, quota) and `/agents` (8 sections incl. column reference, GPS setup steps, View As Agent workflow, Device Labeling MAC pop-up, monitoring tips). Split `agents.ts` guide into its own file to comply with the 256-line threshold; updated `helpContent.ts` to import from both `infrastructure.ts` and `agents.ts`. TypeScript: 0 errors. — shipped 2026-07-28
## Production Deployments
- **Ad-hoc** Full Production Build & SFTP Deployment to `https://demoplace.my.id`: Uploaded standalone Next.js build, static assets, backend/proxy services, and executed remote SSH zero-downtime PM2 process reload. Includes React Portal modals, FAB auto-hiding, 2-row page header redesign, and 100% Pop-up Filter Button coverage on mobile viewports. — shipped 2026-07-30
- **Ad-hoc** Fixed Mobile Top Header Notification Bell & Dropdown Truncation: Refactored `SidebarNotifications.tsx` using `createPortal(..., document.body)` with `placement="topbar"` prop, responsive positioning (`fixed top-14 right-3 w-[calc(100vw-24px)]`), explicit close button, and unread count badge. Connected top header bell button in `MobileTopBar.tsx` to display notifications instead of toggling sidebar drawer. Deployed to production `https://demoplace.my.id`. — shipped 2026-07-30
- **Ad-hoc** Fixed Mobile Sidebar Profile Popover Overflow & Account Settings Modal Layout: Refactored `SidebarProfile.tsx` popover container to open vertically above profile button on mobile (`bottom-full w-full`) and to the right on desktop. Redesigned `AccountSettingsModal.tsx` to render a scrollable horizontal tab bar on mobile (`flex-row overflow-x-auto border-b pb-2.5`) with no-scrollbar styling and responsive active borders (`border-b-2 md:border-l-2`), preventing text truncation ("PASSW") and ensuring content pane visibility. Built, verified, and deployed to production `https://demoplace.my.id`. — shipped 2026-07-30
- **Ad-hoc** Standardized 2-Row Mobile Header Layout Across ALL 17 Dashboard Pages: Restructured page headers across Overview Dashboard, Agents, Apps, Device Labeling, Devices, DNS, DPI Analytics, Events, Flows, Geography, Intelligence, Lookup, Network Infrastructure, Network Intelligence, Security Audit, User Accounts, and Threats to strictly follow the 2-row layout (Row 1: Title + `HelpTrigger`, Row 2: Full-width description paragraph). Verified build (0 TS errors) and deployed to production `https://demoplace.my.id`. — shipped 2026-07-30
## Database Configuration
- **Ad-hoc** Configured Local Development Environment to Use Central Database Directly: (1) Removed `node scripts/start-mongo.js` execution from the `"dev"` script in `package.json` to prevent starting a local in-memory database, (2) Removed `mongodb` service definitions and local volumes from `docker-compose.yml` and `docker-compose.prod.yml`, (3) Wired `MONGODB_URI` environment variables directly from `.env.local` and `.env.production` into Docker services, (4) Hardened connection logic in `backend/db/mongoose.js`, `proxy/index.js`, `src/lib/actions/agents.ts`, and `test/multitenant_branding_test.js` to immediately fail with a critical error and exit if `MONGODB_URI` is undefined, preventing any accidental fallback to `127.0.0.1:27017` or localhost databases, (5) Adjusted assertions in `test/architecture_test.js` and queries in `test/multitenant_branding_test.js` (checking `agent_registry` instead of empty `summaries` collection) to keep TDD tests passing 100% against the central database. — shipped 2026-08-24