23 KiB
Feature List
Structured log of shipped features, updated by the n/next workflow
(see AGENTS.md) whenever a task is marked [DONE]. Organize entries
under a heading per module/section, matching plans/next-enhancements.md.
Format
## <Section / Module Name>
- **<task number>** <feature description> — shipped <date>
Kit Workflow (meta)
- Iteration log (
docs/log/) — everye/enhanceorn/next/n{x}run now writes its own dated file todocs/log/documenting what was requested, steps taken, what succeeded/failed, the resulting state, and considerations for next time. See AGENTS.md §2b. — shipped 2026-07-08
Agents Management
- Ad-hoc Optimized
getAgentsserver action to perform fast, index-covered per-agent queries (O(\log N)) on theflowscollection, completely eliminating the heavy collection-wide aggregations that caused HTTP 500/504 timeouts on the production server (demoplace). Fixed the "An unexpected response was received from the server" error, restoring the Agents Network Map, Agent List, and statistics cards to full functionality. — shipped 2026-07-23 - Ad-hoc Implemented dynamic unit formatting for the Data Size column on the Agents page, automatically converting values above 1024 MB to GB and values above 1024 GB to TB. — shipped 2026-07-23
- Ad-hoc Restored the Agents page link in the sidebar for TENANT_ADMIN role, matching the page-level permissions and letting tenant admins see and manage their own site's agents. — shipped 2026-07-24
Sidebar & Brand Alignment
- Ad-hoc Swapped and aligned the site UUID mapping logic between SIAB (site
1959bb55_045b_47c7_bbdd_f33b7db197b9with agent23-TE-6L-I2) and Office (site6681452d_9cae_4ff4_8ae8_0d504774265ewith agent8A-V3-PB-85) in the frontend, backend, and central MongoDB database. This aligns the client dashboard display with the authoritative dataset from the BackOne API (https://api0.dev.backone.cloud/api/v1), resolving swapped coordinates and mismatching agent lists. — shipped 2026-08-04 - Ad-hoc Separated the "Learn This Page" guides for the Threat Intelligence and Detected Threats pages into separate, custom guides showing unique instructions for each, and split the guides file into
threats.tsto respect the 256-line threshold. — shipped 2026-07-27 - Ad-hoc Removed the route/slug path pill (e.g.
/intelligence) from the header of the "Learn This Page" contextual help modals globally across all pages. — shipped 2026-07-27 - Ad-hoc Replaced the custom document title descriptor in
Sidebar.tsxwith a standard React-nativeMutationObservertitle sync, ensuring the browser tab title dynamically switches to "Nexus" or "BackOne" in real-time depending on the logged-in user's site context. — shipped 2026-07-27 - Ad-hoc Updated the SIAB branding configurations in seeding files and database migrations to rename the footer copyright from "PT. SIAB Indonesia" to "PT. Data Bisnis Solusi", and successfully redeployed the updated build and configuration to the demoplace production domain. — shipped 2026-07-27
- Ad-hoc Fixed multitenant branding bug in
getSiteBrandingto correctly prioritize explicit site UUID checks (e.g. SIAB site'6681452d_9cae_4ff4_8ae8_0d504774265e') over hostname fallbacks, and updated SIAB site branding to return the BackOne logo and BackOne brand name. This replaces the incorrect Nexus logo with the BackOne logo for SIAB accounts and removes "Nexus" from the App Lookup browser tab title and description. — shipped 2026-07-24 - Ad-hoc Localhost sidebar menu, branding logo, status pill, dropdown selectors, and page document titles matched 100% with domain. Distinct Lucide icons added to Flows, Traffic Categories, DPI MetaData, Network Topology, and Geo Traffic. Dynamic browser tab titles implemented for all dashboard pages. — shipped 2026-07-22
- Ad-hoc Redesigned the Active Site and Time Filter selectors in the sidebar to match a premium double-row card design, featuring standalone naked line icons (Activity and Calendar) in blue, clean uppercase tracking labels, bold white sans-serif text values, and clean borders with dropdown indicators. — shipped 2026-07-22
- Ad-hoc Aligned the entire sidebar font style and font sizes with the demoplace production domain by applying a Times New Roman serif font stack to the entire sidebar container, menu links (
text-xs), selector labels (text-[10.5px]), and values (text-sm). — shipped 2026-07-22 - Ad-hoc Restored the "Learn This Page" HelpTrigger button to all 14 dashboard pages (Overview, Agents, Apps, Devices, DNS, Events, Flows, Geography, Intelligence, Lookup, Network Infrastructure, Network Intelligence, Security Audit, Threats). Previously only dpi-analytics and threats had the button. TypeScript compilation verified: 0 errors. — shipped 2026-07-22
- Ad-hoc Implemented Agent Network Map on Agents page with: (1) interactive world map showing all agents as colored pins (green=online/pulse, red=offline) using react-simple-maps, (2) hover tooltips showing agent label, UUID, coordinates, and uptime %, (3) zoom/pan controls + reset to Indonesia center, (4) MapPin 📍 action button per agent row to open the coordinate input modal (AgentLocationModal), (5) status badge showing how many agents have locations configured vs. total. TypeScript: 0 errors. — shipped 2026-07-22
App Database / Lookup
- Ad-hoc Fixed missing application logos, favicons, and full names in the App Lookup catalog database. Configured the proxy synchronizer (
proxy/netifyClientStats.js) to parse and populatelogo,favicon,icon, andfull_namefields from Netify API payloads into MongoDB. — shipped 2026-07-22 - Ad-hoc Restored the Blacklist Configuration tab within the App Lookup page, implementing a tabbed layout (
App CatalogandBlacklist Configuration) to enable admins/analysts (in Agent View mode) to manage domain and category blacklist rules. — shipped 2026-07-22 - Ad-hoc Transitioned telemetry ingestion pipeline to use 5-minute incremental deltas, refactoring backend aggregations (
/summary,/app-details,/device-details) to sum deltas dynamically. This enables exact and coherent bandwidth stats across the entire dashboard based on timeRange filters (5m, 1h, 24h, 7d, 30d). — shipped 2026-07-22
Visual & Typography
- Ad-hoc Fixed font readability issues on Agents page: reduced
font-bold→font-mediumon Historical Uptime column andfont-semibold→font-normalon Data Size column. Addedtext-xs tracking-wideto numeric values for cleaner rendering. Updated--font-monoCSS variable to use Inter font first (matching demoplace:--default-mono-font-family: var(--font-inter)) so all monospace numeric values render with Inter's clean tabular numerals instead of heavy system monospace. — shipped 2026-07-22 - Ad-hoc Applied Georgia font stack globally (
Georgia, serif, var(--font-sans)) to body and configured Tailwind@themereplacement to map--font-sansto Georgia. Splitglobals.cssinto modularglobals.css,theme.css, andvariables.cssfiles to comply with the 256-line threshold. — shipped 2026-07-23 - Ad-hoc Redesigned Active Site and Time Filter selectors in the sidebar to be semi-transparent using
bg-white/[0.03]with hover adjustments,backdrop-blur-md(frosted glass), and muted slate text/icons for harmonious integration. — shipped 2026-07-23 - Ad-hoc Resolved dynamic layout shifting on Overview KPI cards by optimizing card padding to
p-4, applyingwhitespace-nowrapto prevent values from wrapping, adjusting value font sizes totext-[22px], and rendering invisible layout alignment placeholders to ensure perfectly aligned heights and baselines across all time filters. — shipped 2026-07-23
Security & Session Management
- Ad-hoc Implemented a hybrid Tab-Aware 1-hour session security inactivity timeout using Page Visibility API. The timer runs silently when the user switches tabs, prevents immediate logouts or alerts during short tab-away periods (3-5 minutes), and displays the premium "Session Security Alert" warning modal only during the final 2 minutes. Resets to 1-hour automatically upon user interactions (clicks, keyboard inputs, mouse movements) while the tab is active/visible. Verified with unit tests. — shipped 2026-07-23
- Ad-hoc Configured the auth token cookie as session-only (by removing the
maxAgeoption). This ensures the cookie is cleared immediately when the user closes their browser, preventing direct dashboard access on browser restart. — shipped 2026-07-24 - Ad-hoc Restricted the View As History logs visible to a TENANT_ADMIN to only include logs for agents within their own site and exclude all logs performed by SUPER_ADMIN (username "admin"). — shipped 2026-07-24
- Ad-hoc Restored Next.js middleware file
src/middleware.ts(with functionmiddleware) from the deprecated and non-functionalsrc/proxy.tssetup. This fixes the server-side authentication routing and page-load crashes on the production server by properly registering the middleware manifest. — shipped 2026-07-24 - Ad-hoc Replaced client-side
router.pushredirects with robustwindow.location.hreffull page reloads on login and logout flows. This completely prevents chunk load failures ("This page couldn't load" screen) caused by stale JavaScript compiler hashes in active client browser sessions. — shipped 2026-07-24 - Ad-hoc Fixed deployment upload omissions in
scripts/deploy-sftp.jsby adding the.next/staticandpublicdirectories to the SFTPUPLOAD_MANIFEST. This guarantees all compilation chunk files are successfully uploaded, eliminating the 404 chunk load errors that broke the login redirects. — shipped 2026-07-24 - Ad-hoc Implemented dynamic branding detection and logo rendering on the Sidebar component. Integrated
document.titlesetter interceptor to dynamically rewrite tab titles matching active site names (e.g. Nexus vs. BackOne). Fixed React hydration mismatch in the sidebar logo image src using a mounted state wrapper. — shipped 2026-07-24 - Ad-hoc Secured
getAgentsNext.js server action and/api/dashboard/agents/*backend Express routes by decoding JWT and enforcing strict tenant site-isolation filters for non-global user roles (TENANT_ADMIN,AGENT_VIEWER). — shipped 2026-07-24 - Ad-hoc Reverted the Login page layout to the original BackOne logo and title as requested, keeping login branding standard. — shipped 2026-07-24
- Ad-hoc Rebranded the App Lookup description dynamically to match active site context (Nexus's vs. BackOne's) and implemented a dynamic rebranding middleware in the backend dashboard router to rewrite Netify/BackOne database content to Nexus on the fly. — shipped 2026-07-24
Overview Dashboard & KPI Alignment
- Ad-hoc Implemented robust database fallback aggregation for Overview Dashboard KPIs (Download, Upload, Devices, Top Apps, Top Protocols) across all time filters. If pre-aggregated summary collections are empty (due to sensor data gap or offline status), the API dynamically calculates the metrics by fallback aggregation from raw
FlowandAppCategoryStatlogs. — shipped 2026-07-27 - Ad-hoc Aligned the Flows KPI count on the Overview Dashboard with the Flows list page count by querying the number of documents in the
Flowcollection directly, replacing the 5-minute stats delta sum. — shipped 2026-07-23 - Ad-hoc Aligned the Threats KPI count on the Overview Dashboard with the Detected Threats list page by implementing the same cybersecurity-events-to-threats fallback query when no primary threats exist. — shipped 2026-07-23
Device Labeling & Flows Integration
- Ad-hoc Optimized
/api/dashboard/devices/labelingbackend query by replacing the heavyFlow.aggregatewith an index-coveredFlow.distinctscan followed by parallelFlow.findOnequeries. This cut the API response duration from 7.7 seconds to 91 milliseconds (an 84x speedup) and resolved Next.js dev server memory depletion restarts. — shipped 2026-07-28 - Ad-hoc Enforced a strictly vertical-scroll-only layout by eliminating all horizontal scrollbars across the application. Converted rigid pixel-based column dimensions to percentage-based widths on the Detected Threats, Network Flows, Recent Events, and Traffic Categories tables, allowing them to shrink to fit smaller screens. Removed
whitespace-nowrapfrom theDataTableheaders to allow headers to wrap, locked container overflow tooverflow-hidden, and refactoredDataTable.tsxto extract pagination controls into a modular sub-component to stay under the 256-line threshold limit. — shipped 2026-07-28
Viewport Auto-Scaling & Cross-Laptop Consistency
- Ad-hoc Implemented Viewport Auto-Scaling (
ViewportScaler.tsx) using CSStransform: scale(outerWidth / 1536)withtransform-origin: top left, mounted globally inlayout.tsx. The entire dashboard now renders at the 1536px reference design width and is proportionally scaled down to fit any laptop screen size. Removed themax-w-7xlcontent container limit fromDashboardLayout.tsxand addedhtml/body { overflow-x: hidden }enforcement inglobals.css. Also removedwhitespace-nowrapfromDataTable<td>cells and the "View Mitigation" action button inthreatColumns.tsxto eliminate the last source of forced horizontal overflow. TypeScript: 0 errors. — shipped 2026-07-28
User Accounts & Company Management
- Ad-hoc Implemented a Hierarchical Company-Based User Model and Multi-Agent delegation. Introduced 3 customer-tier roles (
COMPANY_ADMIN[Tingkat 1],COMPANY_OPERATOR[Tingkat 2], andCOMPANY_VIEWER[Tingkat 3]) to strictly isolate data queries per company. Created a dedicated User Account sidebar page grouping user lists into visual Cards per company, featuring an account quota tracker (Max 5 accounts per company) enforced at both backend API validations and frontend UI controls. Refactored the single-agent select dropdown on user registration modal into a checkbox checklist to assign multiple agents to operator accounts. — shipped 2026-07-28 - Ad-hoc Replaced the native browser role select dropdown in the external account registration modal with a custom DOM-based select element, ensuring the list options scale down proportionally with the page viewport. Removed parenthesized access suffixes from the "Executive" role, ordered roles from highest to lowest rank, and split the modal file to adhere to the 256-line threshold limit. — shipped 2026-07-28
- Ad-hoc Implemented a Device details pop-up modal and relational IP tracking history in the Device Labeling page, allowing administrators to click any MAC Address to view all unique associated IP addresses, activity dates, and traffic usage metrics resolved from Flow logs. Optimized the backend database query by indexing the
src_macfield in FlowSchema and adding a compound index to support fast pagination scans. — shipped 2026-07-28 - Ad-hoc Fixed the critical "Unexpected end of form" error on the Create Technical Account form by creating dedicated Next.js API Routes for
/api/auth/admin/create-external-userand/api/auth/admin/update-agent-userto proxy multipart/form-data requests reliably to the Express backend. — shipped 2026-08-04 - Ad-hoc Resolved the critical "Unexpected end of form" error globally across all proxy API routes by implementing transparent request stream forwarding (
req.body) with directContent-Typeboundary preservation in the global Next.js gateway. This successfully restores profile picture uploads and account updates/resets to a 100% operational state. — shipped 2026-08-04 - Ad-hoc Expanded the User Guide (Learn This Page) for the
/user-accountspage from 3 generic sections to 6 comprehensive sections: Company Tenant Cards overview, Account Table Column Reference (explaining each column: #, Account Name, Username, Role, Assigned Devices, Actions with color-coded role badges), Role Hierarchies with full permission descriptions, step-by-step guide to adding a new account (7 steps), step-by-step guide to editing or deleting an account (4 steps), and 5-Account Quota Limit explanation. — shipped 2026-07-28 - Ad-hoc Fixed critical
SyntaxError: Unexpected token '<', "<!DOCTYPE"on/user-accountspage by correcting two bugs inuseExternalAccountForm.ts: (1) wrong endpoint/api/auth/users→/api/auth/admin/users, (2) wrong response shape checkdata.users→data.datamatching actual backend{ok:true, data:[...]}. Addedif (!res.ok) return nullsafety guard. Fixed port conflict by moving backend to port 3002 and addingNEXT_PUBLIC_API_URL=http://127.0.0.1:3002. FixedViewportScaler.tsxto usewindow.outerWidthinstead ofwindow.innerWidthfor correct split-screen scaling. — shipped 2026-07-28 - Ad-hoc Expanded the User Guide (Learn This Page) consistently across ALL major pages —
/user-accounts(6 sections incl. column reference, add/edit/delete steps, quota) and/agents(8 sections incl. column reference, GPS setup steps, View As Agent workflow, Device Labeling MAC pop-up, monitoring tips). Splitagents.tsguide into its own file to comply with the 256-line threshold; updatedhelpContent.tsto import from bothinfrastructure.tsandagents.ts. TypeScript: 0 errors. — shipped 2026-07-28
Refactoring & Rebranding (Netify to BackOne)
- Ad-hoc Refactored name references from "Netify" to "BackOne" across environment variables, file names, import references, and parameters. Cleaned up over 5,500 lines of unused legacy backend files (
backone.js,scheduler.js,database.js,ingestionService.js,backoneDeviceFetcher.js), satisfying the 256-line threshold compliance (Rule 3) and ensuring optimal workspace structure. Verified 100% success on Next.js build compile, arsitektur tests, and branding unit tests. — shipped 2026-08-03 - Ad-hoc Synchronized and fully integrated mobile responsive design including floating
MobileBottomBar,MobileTopBar, drawer layouts for filters, and full compliance with Tailwind CSS. — shipped 2026-08-03 - Ad-hoc Integrated PDF print layout exports for both the Device Asset Listing directory and individual MAC Address details history modal. — shipped 2026-08-03
- Ad-hoc Implemented View-As impersonation mode for target operator/viewer accounts, with automated lockout recovery (Unlock action) in the user list and custom audit logging on impersonation startup. — shipped 2026-08-03
- Ad-hoc Fixed authentication loops in Next.js middleware by removing the automatic redirect from
/loginto/on invalid/stale session cookies. Configured the backendrequireAuthandrequireAdminmiddleware to clear thetokencookie immediately when verified as invalid. — shipped 2026-08-03 - Ad-hoc Positioned the profile account settings popover dynamically to open upwards (
bottom-full left-0 mb-2 w-full) on mobile viewports to prevent layout clipping. Shipped a premium 0.5s slide-in/slide-out transition for the mobile drawer menu. — shipped 2026-08-03 - Ad-hoc Refactored the
DeviceDetailModal.tsxcomponent to make it fully mobile-friendly. Replaced vertical tab stacking with a horizontal scrolling tab navigation and introducedDeviceKpiSectionto keep code under the 256-line threshold limit. — shipped 2026-08-03
Flows & Time Filter
- Ad-hoc Fixed Flows page filter not working: filter values with
'All'were still being sent to the backend as query params, causing the backend filter logic to be bypassed. Added!== 'All'guard for all filter params (protocol,src_ip,dst_ip,dst_port,app,domain,sort_download,sort_upload). — shipped 2026-08-07 - Ad-hoc Fixed
useCtxFetchstale data issue: when endpoint changes due to filter change, old data was displayed until new data arrived. Now resets todefaultValue+ shows loading on cache miss, preventing stale filter results from being shown. — shipped 2026-08-07
Overview Dashboard / Summary
-
Ad-hoc Fixed inflated Upload/Download values on Overview Dashboard Summary cards. Root cause:
summary.jswas summing ALLSummarydocuments within the 24h timeRange (288 snapshots × ~25MB = ~7GB incorrect). Fixed to use only the latest single document per site within the selected timeRange, which correctly represents current bandwidth. — shipped 2026-08-07 -
Ad-hoc Fixed Summary bandwidth/flows cards to correctly respond to Time Filter changes from the sidebar. Previously the query ignored
timeRangeand always returned the globally latest document. NowtimeRangeis applied tofindOnequeries for both site-level and agent-level summaries, so changing the sidebar to "Last 5 Minutes", "Last 1 Hour", "Last 7 Days", etc. returns bandwidth data scoped to that period. — shipped 2026-08-07 -
Ad-hoc Replaced the 3D rotating GlobeMap on the Overview Dashboard with an interactive, flat Leaflet-based world map (FlatWorldMap) using CartoDB Dark Matter tiles. Draws custom glowing markers (blue origin, severity-colored destinations) and animated flow dashed lines, showing real-time traffic connections with download/upload tooltips on hover. Commented out the GlobeMap code to preserve it as requested. — shipped 2026-08-20
-
Ad-hoc Implemented smart, collision-avoiding marker tooltips on the FlatWorldMap, shifting the origin tooltip (JAKARTA SITE) above the marker and adjusting destination labels dynamically based on location names (e.g. left for Tangerang/Balaraja, right for Bandung, bottom for Internal Network) to prevent label overlap. — shipped 2026-08-20
-
Ad-hoc Replaced the default
bodyfont family (which was Times New Roman / serif) inglobals.csswith a clean, modern sans-serif font stack (Inter, system-ui, etc.). This instantly updated all modal elements (download size badges, tab lists, network flows data table cells/headers, labels, and title texts) to use clean, modern, professional sans-serif typography. — shipped 2026-08-20 -
Ad-hoc Removed light-mode grey background fallback classes (
bg-slate-50/50,bg-slate-50,hover:bg-slate-100/50) and locked all device/IP details tab views (DeviceAppsTab,DeviceDomainsTab,DeviceProtocolsTab,RemoteIpDetailModal,DeviceFlowsTab,RemoteIpLocalDevicesTab) to dark theme transparent styles (bg-white/[0.02],bg-white/[0.03],hover:bg-white/[0.05]) permanently. — shipped 2026-08-20 -
Ad-hoc Injected the
font-sansclass and softened outer modal card borders toborder-border/50across all major detail modals (DeviceDetailModal,RemoteIpDetailModal,AppDetailModal,AgentDetailModal,CategoryDetailPanel,TlsCipherDetailModal,MetadataDetailPanel) to guarantee visual aesthetics remain clean, premium, and professional. — shipped 2026-08-20