31 KiB
Feature List
Structured log of shipped features, updated by the n/next workflow
(see AGENTS.md) whenever a task is marked [DONE]. Organize entries
under a heading per module/section, matching plans/next-enhancements.md.
Format
## <Section / Module Name>
- **<task number>** <feature description> — shipped <date>
Kit Workflow (meta)
- Iteration log (
docs/log/) — everye/enhanceorn/next/n{x}run now writes its own dated file todocs/log/documenting what was requested, steps taken, what succeeded/failed, the resulting state, and considerations for next time. See AGENTS.md §2b. — shipped 2026-07-08
User Accounts & Authentication
- Ad-hoc Implemented 3-Attempt Rate Limiting, 15-Minute Account Lockout & Admin Manual Unlock System: (1) Enforced maximum 3 failed password attempts before locking account for 15 minutes, (2) Returned exact remaining attempts warnings (
Invalid password. 2 attempts remaining before lockout.), (3) Added real-time countdown timer (mm:ss) to login page with input/button locking during lockout, (4) AddedLocked 🔒status badge andUnlock 🔓action button in/user-accountstable for Superadmin and Tenant Admins. — shipped 2026-07-31
Agents Management
-
Ad-hoc Fixed View-As Agent Mode data scoping and white-labeling compliance on
/agentspage: (1) Isolated agent list to show ONLY the target agent being viewed when View-As mode is active, (2) Hid administrative management controls (+ Provision Agent,ExternalAccountsSection,Delete,Edit Location,UserCog, and nestedView-Asbuttons) when View-As mode is active, (3) Replaced hardcodedSuperadmin (BackOne) External Accountstitle with dynamic site-aware brandinggetSiteBranding()(NexusvsBackOne/SIAB) per Rule 5. — shipped 2026-07-30 -
Ad-hoc Optimized
getAgentsserver action to perform fast, index-covered per-agent queries (O(\log N)) on theflowscollection, completely eliminating the heavy collection-wide aggregations that caused HTTP 500/504 timeouts on the production server (demoplace). Fixed the "An unexpected response was received from the server" error, restoring the Agents Network Map, Agent List, and statistics cards to full functionality. — shipped 2026-07-23 -
Ad-hoc Implemented dynamic unit formatting for the Data Size column on the Agents page, automatically converting values above 1024 MB to GB and values above 1024 GB to TB. — shipped 2026-07-23
-
Ad-hoc Restored the Agents page link in the sidebar for TENANT_ADMIN role, matching the page-level permissions and letting tenant admins see and manage their own site's agents. — shipped 2026-07-24
-
Ad-hoc Redesigned Mobile UI/UX into an App-Native Mobile Experience on localhost: (1) Added 5-tab Mobile Bottom Navigation Bar (
Overview,Devices,Flows,Threats,Menu ☰), (2) Added minimalistMobileTopBarwith logo, page title, site badge, and notifications, (3) Completely removedViewportScaler.tsxto enable 100% pure CSS Tailwind media queries (sm:,md:,lg:,xl:), fixing DevTools device emulation scaling bugs, (4) RefactoredDataTableMobileCardsinto a Compact Minimalist List with safe-area bottom padding (pb-24). — shipped 2026-07-30 -
Ad-hoc Fixed Mobile Flows UI Freeze and Touch Scrolling Performance: (1) Memoized
mainHeadercalculation inDataTableMobileCards.tsxand removed layout-thrashingwhite-space: nowrapinside mobile cards grid cells, eliminating main JS thread lockup and restoring 60fps mobile touch scrolling on the Flows page, (2) OptimizedDeviceFlowsTab.tsxandAgentFlowsTab.tsxby removing nestedmax-h-[55vh]overflow containers and addingtouch-pan-ytouch action handling, preventing double-scroll touch gesture conflicts inside detail modals on mobile devices. — shipped 2026-07-30 -
Ad-hoc Separated the "Learn This Page" guides for the Threat Intelligence and Detected Threats pages into separate, custom guides showing unique instructions for each, and split the guides file into
threats.tsto respect the 256-line threshold. — shipped 2026-07-27 -
Ad-hoc Removed the route/slug path pill (e.g.
/intelligence) from the header of the "Learn This Page" contextual help modals globally across all pages. — shipped 2026-07-27 -
Ad-hoc Replaced the custom document title descriptor in
Sidebar.tsxwith a standard React-nativeMutationObservertitle sync, ensuring the browser tab title dynamically switches to "Nexus" or "BackOne" in real-time depending on the logged-in user's site context. — shipped 2026-07-27 -
Ad-hoc Updated the SIAB branding configurations in seeding files and database migrations to rename the footer copyright from "PT. SIAB Indonesia" to "PT. Data Bisnis Solusi", and successfully redeployed the updated build and configuration to the demoplace production domain. — shipped 2026-07-27
-
Ad-hoc Fixed multitenant branding bug in
getSiteBrandingto correctly prioritize explicit site UUID checks (e.g. SIAB site'6681452d_9cae_4ff4_8ae8_0d504774265e') over hostname fallbacks, and updated SIAB site branding to return the BackOne logo and BackOne brand name. This replaces the incorrect Nexus logo with the BackOne logo for SIAB accounts and removes "Nexus" from the App Lookup browser tab title and description. — shipped 2026-07-24 -
Ad-hoc Localhost sidebar menu, branding logo, status pill, dropdown selectors, and page document titles matched 100% with domain. Distinct Lucide icons added to Flows, Traffic Categories, DPI MetaData, Network Topology, and Geo Traffic. Dynamic browser tab titles implemented for all dashboard pages. — shipped 2026-07-22
-
Ad-hoc Redesigned the Active Site and Time Filter selectors in the sidebar to match a premium double-row card design, featuring standalone naked line icons (Activity and Calendar) in blue, clean uppercase tracking labels, bold white sans-serif text values, and clean borders with dropdown indicators. — shipped 2026-07-22
-
Ad-hoc Aligned the entire sidebar font style and font sizes with the demoplace production domain by applying a Times New Roman serif font stack to the entire sidebar container, menu links (
text-xs), selector labels (text-[10.5px]), and values (text-sm). — shipped 2026-07-22 -
Ad-hoc Restored the "Learn This Page" HelpTrigger button to all 14 dashboard pages (Overview, Agents, Apps, Devices, DNS, Events, Flows, Geography, Intelligence, Lookup, Network Infrastructure, Network Intelligence, Security Audit, Threats). Previously only dpi-analytics and threats had the button. TypeScript compilation verified: 0 errors. — shipped 2026-07-22
-
Ad-hoc Implemented Agent Network Map on Agents page with: (1) interactive world map showing all agents as colored pins (green=online/pulse, red=offline) using react-simple-maps, (2) hover tooltips showing agent label, UUID, coordinates, and uptime %, (3) zoom/pan controls + reset to Indonesia center, (4) MapPin 📍 action button per agent row to open the coordinate input modal (AgentLocationModal), (5) status badge showing how many agents have locations configured vs. total. TypeScript: 0 errors. — shipped 2026-07-22
App Database / Lookup
- Ad-hoc Fixed missing application logos, favicons, and full names in the App Lookup catalog database. Configured the proxy synchronizer (
proxy/netifyClientStats.js) to parse and populatelogo,favicon,icon, andfull_namefields from Netify API payloads into MongoDB. — shipped 2026-07-22 - Ad-hoc Restored the Blacklist Configuration tab within the App Lookup page, implementing a tabbed layout (
App CatalogandBlacklist Configuration) to enable admins/analysts (in Agent View mode) to manage domain and category blacklist rules. — shipped 2026-07-22 - Ad-hoc Transitioned telemetry ingestion pipeline to use 5-minute incremental deltas, refactoring backend aggregations (
/summary,/app-details,/device-details) to sum deltas dynamically. This enables exact and coherent bandwidth stats across the entire dashboard based on timeRange filters (5m, 1h, 24h, 7d, 30d). — shipped 2026-07-22
Telemetry & DPI Analytics
- Ad-hoc Full Integration of Custom MAC Owner Labels in All PDF Export Reports: (1) Updated
DevicePdfDocument.tsxto displayOwner / Custom Labelin the Device Identification grid, (2) UpdatedAgentPdfDocument.tsxto includeOwner / Device Labelcolumn in the Monitored Devices table, (3) CreatedDeviceLabelingPdfDocument.tsxand enabled PDF Export on the/device-labelingpage to export the complete Device Asset Directory with owner labels, (4) CreatedDeviceMacPdfDocument.tsxand added anExport PDFbutton toDeviceMacDetailsModal.tsxto export individual MAC details and Associated IP Address history. — shipped 2026-07-31 - Ad-hoc Fixed device detail pop-up modal errors and visual focus locking across all dashboard pages: (1) Corrected invalid TypeScript syntax in backend
deviceDetailsHandler.js(line 111) that caused 500 Internal Server Error when opening device details, (2) RefactoredDeviceDetailModal,AppDetailModal,AgentDetailModal, andModalto usecreatePortal(..., document.body)withz-[9999], mounting overlays at root DOM level to lock user interaction focus to the modal and prevent background tab switching, (3) Enhanced backdrop blur withbg-slate-950/80 backdrop-blur-mdandbackdropFilter: blur(12px)for full-screen frosted glass effect covering both main content and sidebar, (4) Enforceddocument.body.style.overflow = "hidden"while modals are open. — shipped 2026-07-30 - Ad-hoc Optimized device telemetry detail handler (
deviceDetailsHandler.js) and Server ActiongetAgents: (1) Added compound indexes onFlowSchemafor(agent_uuid, src_ip, timestamp)and(agent_uuid, dst_ip, timestamp), (2) Replaced heavy 5,000-record un-indexed$orflow table scans with indexed parallel queries viaPromise.all(reducing detail lookup from 4s to 20ms), (3) ParallelizedgetAgentsstatus checks withPromise.all(speeding up page navigation from 13s to ~150ms), (4) UpgradedDeviceDetailModaloverlay backdrop blur with explicitbackdropFilter: blur(12px)for consistent frosted-glass visual effect across all browsers. — shipped 2026-07-30
Visual & Typography
- Ad-hoc Overhauled Mobile Pop-Up Modals Spacing, Layout & Table Cell Alignment: (1) Fixed overlapping text issue in
DeviceMacDetailsModal.tsx("Associated IP Addresses" table) by removing invaliddisplay: flexapplied directly to<td>elements, formatting timestamps into stacked 2-line date/time cells (DateCell), adding truncation withtitlehover tooltips on IP addresses, and settingmin-w-[520px]table width with clean horizontal scrolling, (2) Transformed stacked 1-column Total Download & Upload stat cards into compact 2-column side-by-side cards (grid-cols-2,p-3.5 sm:p-6,text-xl sm:text-4xl) insideDeviceDetailModalandRemoteIpDetailModal, reducing vertical modal height on mobile by over 50% and eliminating crampness, (3) Optimized modal padding (p-2.5 sm:p-4), header paddings (px-3.5 py-3 sm:px-6 sm:py-5), tab bars (px-2.5 py-1.5scrollable horizontal tab bar), and identity cards (DeviceIdentityCard,p-3.5 sm:p-6,gap-3 sm:gap-6) acrossDeviceDetailModal,AgentDetailModal,AppDetailModal,RemoteIpDetailModal, andModal.tsxfor a spacious, elegant, and comfortable mobile user experience. — shipped 2026-07-31 - Ad-hoc Complete 100% Dashboard Coverage for Pop-up Filter Button & Modal Drawers: (1) Overhauled
ThreatFilters.tsxfrom an inline expanded card into a compact trigger button bar (Filter Threat Data) with Pop-Up Filter Modal Drawer (z-[99999]), matchingUniversalFilters.tsx, (2) Verified all 16 pages and tab modals (/devices,/geography,/flows,/apps,/dns,/events,/security-audit,/network-intelligence,/threats,DeviceDetailModaltabs,AgentDetailModaltabs, andRemoteIpDetailModaltabs) now 100% use compact Pop-Up Filter Buttons on mobile viewports. — shipped 2026-07-30 - Ad-hoc React Portal Modal Mounting, FAB Auto-Hiding & Page Header Layout Redesign: (1) Mounted
ContextualHelpModaldirectly to rootdocument.bodyviacreatePortal, breaking out of all parent DOM stacking contexts, (2) Added DOM mutation listener inHelpCenterFAB.tsx(document.body.style.overflow === "hidden") to automatically hide the floating FAB?icon whenever any modal is active, eliminating 100% of button overlaps, (3) Redesigned page headers across all 15 dashboard pages into a clean 2-row layout: Row 1 aligns<h1>Title</h1>and<HelpTrigger />badge, Row 2 renders subtitle descriptions at full width underneath. — shipped 2026-07-30 - Ad-hoc Contextual Help Modal Mobile Responsiveness & Layering Overhaul: (1) Raised
ContextualHelpModalz-index toz-[99999], preventing the floatingHelpCenterFAB(?icon) from obscuring modal buttons or cluttering mobile viewports, (2) Refactored modal footer to responsive layout (px-4 py-3.5 flex-col sm:flex-row), expandingClose GuideandOpen Full Guidebuttons to full mobile width (flex-1 sm:flex-none) to eliminate all button text wrapping and button collision. — shipped 2026-07-30 - Ad-hoc Mobile Layout, Help Button, Card Header & Byte Formatting Polish: (1) Refactored
HelpTrigger.tsxto render a responsive[📖 Learn]badge on mobile screens, preventing multi-line button text crowding on header rows, (2) RefactoredDataTableMobileCards.tsxto group index badge[#1]and primary IP address172.16.60.1together on the top-left of the card header, completely removing the awkward wide gap, (3) AdjustedGlobeMap.tsxcamera altitude (2.4) and container height (h-[360px] sm:h-[400px]) on mobile viewports so 100% of the full 3D sphere is centered and visible without cropping (matching Gambar 2), (4) AddedfmtBytesformatter to Recharts PieChart tooltip inTopWidgets.tsx, automatically converting raw numbers likeUDP : 9567431into clean human-readable units (e.g.UDP : 9.12 MB). — shipped 2026-07-30 - Ad-hoc Comprehensive Mobile UI/UX Overhaul (Pop-Up Filter Modal, Heatmap Resizing & Card List Refactoring): (1) Converted
UniversalFilters.tsxfrom an inline expanded block into a compact trigger button bar with active filter chip badges and a Pop-up Filter Modal Drawer (z-[9999]) containing all dropdowns, date picker, reset, and apply controls, freeing up ~100% of mobile viewport space for data display, (2) Repositioned and resized the "Heatmap Intensity" legend inWorldMap.tsxfrom a large top-left card into a sleek bottom-left pill (bottom-3 left-3 px-3 py-1.5 rounded-full) so 100% of the world map is uncovered, (3) RefactoredDataTableMobileCards.tsxto skip column 0 (#index) in the grid body, eliminating duplicate index printing (#1) and cleaning up font sizes, grid spacing, and label alignment across all mobile data lists. — shipped 2026-07-30 - Ad-hoc Total Theme Architecture Cleanup & Pure Dark Mode Hard-Lock: (1) Completely removed
.lighttheme CSS selectors and@media (prefers-color-scheme: light)rules fromvariables.css,globals.css, andIndonesiaAgentMapHelpers.ts, (2) Hard-lockedcolor-scheme: darkat:rootinvariables.cssand as inline style on<html>inlayout.tsx, (3) Refactored dual Tailwind classes (such asbg-slate-50/50 dark:bg-white/[0.02]) inDeviceIdentityCard.tsx,DeviceOverviewTab.tsx,DeviceAppsTab.tsx,DeviceDomainsTab.tsx,DeviceFlowsTab.tsx,DeviceProtocolsTab.tsx,RemoteIpDetailModal.tsx,RemoteIpLocalDevicesTab.tsx, andDeviceDetailModal.tsxinto solid, single Dark Mode classes. Eliminates all light gray background fallbacks when devices are set to Light Mode. — shipped 2026-07-30 - Ad-hoc Complete Mobile UI & UX Responsiveness Overhaul on localhost: (1) Added explicit Next.js Viewport export (
width: "device-width", initialScale: 1) tolayout.tsx, (2) OverhauledGlobeMap.tsxwith dynamic camera distance and responsive height (h-[320px] sm:h-[400px] md:h-[480px]) andoverflow-hiddencontainer to fix cut-off WebGL globe canvas, (3) RedesignedKPICards.tsxinto a 2-column mobile grid with compact padding and text sizes, (4) ImprovedTopWidgets.tsxchart layout and legends for narrow screens, (5) AdjustedHelpCenterFAB.tsxpositioning tobottom-20 lg:bottom-6and increased main bottom padding topb-28 lg:pb-8to prevent bottom bar obscuration, (6) RefactoredDataTable.tsxto extractDataTableDesktopView.tsxcomplying with Rule 3 (256-line threshold rule), (7) EnhancedDeviceDetailModal.tsxfor mobile screen height and horizontal scrollable tabs (overflow-x-auto whitespace-nowrap). — shipped 2026-07-30 - Ad-hoc Fixed font readability issues on Agents page: reduced
font-bold→font-mediumon Historical Uptime column andfont-semibold→font-normalon Data Size column. Addedtext-xs tracking-wideto numeric values for cleaner rendering. Updated--font-monoCSS variable to use Inter font first (matching demoplace:--default-mono-font-family: var(--font-inter)) so all monospace numeric values render with Inter's clean tabular numerals instead of heavy system monospace. — shipped 2026-07-22 - Ad-hoc Applied Georgia font stack globally (
Georgia, serif, var(--font-sans)) to body and configured Tailwind@themereplacement to map--font-sansto Georgia. Splitglobals.cssinto modularglobals.css,theme.css, andvariables.cssfiles to comply with the 256-line threshold. — shipped 2026-07-23 - Ad-hoc Redesigned Active Site and Time Filter selectors in the sidebar to be semi-transparent using
bg-white/[0.03]with hover adjustments,backdrop-blur-md(frosted glass), and muted slate text/icons for harmonious integration. — shipped 2026-07-23 - Ad-hoc Resolved dynamic layout shifting on Overview KPI cards by optimizing card padding to
p-4, applyingwhitespace-nowrapto prevent values from wrapping, adjusting value font sizes totext-[22px], and rendering invisible layout alignment placeholders to ensure perfectly aligned heights and baselines across all time filters. — shipped 2026-07-23
Security & Session Management
- Ad-hoc Implemented a hybrid Tab-Aware 1-hour session security inactivity timeout using Page Visibility API. The timer runs silently when the user switches tabs, prevents immediate logouts or alerts during short tab-away periods (3-5 minutes), and displays the premium "Session Security Alert" warning modal only during the final 2 minutes. Resets to 1-hour automatically upon user interactions (clicks, keyboard inputs, mouse movements) while the tab is active/visible. Verified with unit tests. — shipped 2026-07-23
- Ad-hoc Configured the auth token cookie as session-only (by removing the
maxAgeoption). This ensures the cookie is cleared immediately when the user closes their browser, preventing direct dashboard access on browser restart. — shipped 2026-07-24 - Ad-hoc Restricted the View As History logs visible to a TENANT_ADMIN to only include logs for agents within their own site and exclude all logs performed by SUPER_ADMIN (username "admin"). — shipped 2026-07-24
- Ad-hoc Restored Next.js middleware file
src/middleware.ts(with functionmiddleware) from the deprecated and non-functionalsrc/proxy.tssetup. This fixes the server-side authentication routing and page-load crashes on the production server by properly registering the middleware manifest. — shipped 2026-07-24 - Ad-hoc Replaced client-side
router.pushredirects with robustwindow.location.hreffull page reloads on login and logout flows. This completely prevents chunk load failures ("This page couldn't load" screen) caused by stale JavaScript compiler hashes in active client browser sessions. — shipped 2026-07-24 - Ad-hoc Fixed deployment upload omissions in
scripts/deploy-sftp.jsby adding the.next/staticandpublicdirectories to the SFTPUPLOAD_MANIFEST. This guarantees all compilation chunk files are successfully uploaded, eliminating the 404 chunk load errors that broke the login redirects. — shipped 2026-07-24 - Ad-hoc Implemented dynamic branding detection and logo rendering on the Sidebar component. Integrated
document.titlesetter interceptor to dynamically rewrite tab titles matching active site names (e.g. Nexus vs. BackOne). Fixed React hydration mismatch in the sidebar logo image src using a mounted state wrapper. — shipped 2026-07-24 - Ad-hoc Secured
getAgentsNext.js server action and/api/dashboard/agents/*backend Express routes by decoding JWT and enforcing strict tenant site-isolation filters for non-global user roles (TENANT_ADMIN,AGENT_VIEWER). — shipped 2026-07-24 - Ad-hoc Reverted the Login page layout to the original BackOne logo and title as requested, keeping login branding standard. — shipped 2026-07-24
- Ad-hoc Rebranded the App Lookup description dynamically to match active site context (Nexus's vs. BackOne's) and implemented a dynamic rebranding middleware in the backend dashboard router to rewrite Netify/BackOne database content to Nexus on the fly. — shipped 2026-07-24
Overview Dashboard & KPI Alignment
- Ad-hoc Implemented robust database fallback aggregation for Overview Dashboard KPIs (Download, Upload, Devices, Top Apps, Top Protocols) across all time filters. If pre-aggregated summary collections are empty (due to sensor data gap or offline status), the API dynamically calculates the metrics by fallback aggregation from raw
FlowandAppCategoryStatlogs. — shipped 2026-07-27 - Ad-hoc Aligned the Flows KPI count on the Overview Dashboard with the Flows list page count by querying the number of documents in the
Flowcollection directly, replacing the 5-minute stats delta sum. — shipped 2026-07-23 - Ad-hoc Aligned the Threats KPI count on the Overview Dashboard with the Detected Threats list page by implementing the same cybersecurity-events-to-threats fallback query when no primary threats exist. — shipped 2026-07-23
Device Labeling & Flows Integration
- Ad-hoc Optimized
/api/dashboard/devices/labelingbackend query by replacing the heavyFlow.aggregatewith an index-coveredFlow.distinctscan followed by parallelFlow.findOnequeries. This cut the API response duration from 7.7 seconds to 91 milliseconds (an 84x speedup) and resolved Next.js dev server memory depletion restarts. — shipped 2026-07-28 - Ad-hoc Enforced a strictly vertical-scroll-only layout by eliminating all horizontal scrollbars across the application. Converted rigid pixel-based column dimensions to percentage-based widths on the Detected Threats, Network Flows, Recent Events, and Traffic Categories tables, allowing them to shrink to fit smaller screens. Removed
whitespace-nowrapfrom theDataTableheaders to allow headers to wrap, locked container overflow tooverflow-hidden, and refactoredDataTable.tsxto extract pagination controls into a modular sub-component to stay under the 256-line threshold limit. — shipped 2026-07-28 - Ad-hoc Created backend batch random device label seeder (
backend/scripts/seed_device_labels.js) that automatically scans MongoDB for unlabelled MAC addresses acrossDeviceStatandFlowcollections and populatesCustomDeviceLabelwith realistic random device labels while preserving existing manual custom labels. Executed seeder to label 151 unlabelled MAC addresses. — shipped 2026-07-30 - Ad-hoc Implemented Full Target User Account Impersonation for the "View-As" feature (
backend/routes/auth/viewAs.js,backend/middleware/auth.js,src/lib/admin-api.ts,DashboardLayout.tsx). When an admin enters View-As mode on a user account, the backend lookup resolves the target user's document and adopts 100% of their identity (role,site_uuid,agent_uuids,agent_uuid,company_name), causing all sidebar menus, permissions, and data charts to respond identically to the target user. Enhanced MongoDBViewAsLogaudit logging and guaranteed instant session destruction upon admin logout or exit. — shipped 2026-07-30
Viewport Auto-Scaling & Cross-Laptop Consistency
- Ad-hoc Implemented Viewport Auto-Scaling (
ViewportScaler.tsx) using CSStransform: scale(outerWidth / 1536)withtransform-origin: top left, mounted globally inlayout.tsx. The entire dashboard now renders at the 1536px reference design width and is proportionally scaled down to fit any laptop screen size. Removed themax-w-7xlcontent container limit fromDashboardLayout.tsxand addedhtml/body { overflow-x: hidden }enforcement inglobals.css. Also removedwhitespace-nowrapfromDataTable<td>cells and the "View Mitigation" action button inthreatColumns.tsxto eliminate the last source of forced horizontal overflow. TypeScript: 0 errors. — shipped 2026-07-28
User Accounts & Company Management
- Ad-hoc Implemented a Hierarchical Company-Based User Model and Multi-Agent delegation. Introduced 3 customer-tier roles (
COMPANY_ADMIN[Tingkat 1],COMPANY_OPERATOR[Tingkat 2], andCOMPANY_VIEWER[Tingkat 3]) to strictly isolate data queries per company. Created a dedicated User Account sidebar page grouping user lists into visual Cards per company, featuring an account quota tracker (Max 5 accounts per company) enforced at both backend API validations and frontend UI controls. Refactored the single-agent select dropdown on user registration modal into a checkbox checklist to assign multiple agents to operator accounts. — shipped 2026-07-28 - Ad-hoc Replaced the native browser role select dropdown in the external account registration modal with a custom DOM-based select element, ensuring the list options scale down proportionally with the page viewport. Removed parenthesized access suffixes from the "Executive" role, ordered roles from highest to lowest rank, and split the modal file to adhere to the 256-line threshold limit. — shipped 2026-07-28
- Ad-hoc Implemented a Device details pop-up modal and relational IP tracking history in the Device Labeling page, allowing administrators to click any MAC Address to view all unique associated IP addresses, activity dates, and traffic usage metrics resolved from Flow logs. Optimized the backend database query by indexing the
src_macfield in FlowSchema and adding a compound index to support fast pagination scans. — shipped 2026-07-28 - Ad-hoc Expanded the User Guide (Learn This Page) for the
/user-accountspage from 3 generic sections to 6 comprehensive sections: Company Tenant Cards overview, Account Table Column Reference (explaining each column: #, Account Name, Username, Role, Assigned Devices, Actions with color-coded role badges), Role Hierarchies with full permission descriptions, step-by-step guide to adding a new account (7 steps), step-by-step guide to editing or deleting an account (4 steps), and 5-Account Quota Limit explanation. — shipped 2026-07-28 - Ad-hoc Fixed critical
SyntaxError: Unexpected token '<', "<!DOCTYPE"on/user-accountspage by correcting two bugs inuseExternalAccountForm.ts: (1) wrong endpoint/api/auth/users→/api/auth/admin/users, (2) wrong response shape checkdata.users→data.datamatching actual backend{ok:true, data:[...]}. Addedif (!res.ok) return nullsafety guard. Fixed port conflict by moving backend to port 3002 and addingNEXT_PUBLIC_API_URL=http://127.0.0.1:3002. FixedViewportScaler.tsxto usewindow.outerWidthinstead ofwindow.innerWidthfor correct split-screen scaling. — shipped 2026-07-28 - Ad-hoc Expanded the User Guide (Learn This Page) consistently across ALL major pages —
/user-accounts(6 sections incl. column reference, add/edit/delete steps, quota) and/agents(8 sections incl. column reference, GPS setup steps, View As Agent workflow, Device Labeling MAC pop-up, monitoring tips). Splitagents.tsguide into its own file to comply with the 256-line threshold; updatedhelpContent.tsto import from bothinfrastructure.tsandagents.ts. TypeScript: 0 errors. — shipped 2026-07-28
Production Deployments
- Ad-hoc Full Production Build & SFTP Deployment to
https://demoplace.my.id: Uploaded standalone Next.js build, static assets, backend/proxy services, and executed remote SSH zero-downtime PM2 process reload. Includes React Portal modals, FAB auto-hiding, 2-row page header redesign, and 100% Pop-up Filter Button coverage on mobile viewports. — shipped 2026-07-30 - Ad-hoc Fixed Mobile Top Header Notification Bell & Dropdown Truncation: Refactored
SidebarNotifications.tsxusingcreatePortal(..., document.body)withplacement="topbar"prop, responsive positioning (fixed top-14 right-3 w-[calc(100vw-24px)]), explicit close button, and unread count badge. Connected top header bell button inMobileTopBar.tsxto display notifications instead of toggling sidebar drawer. Deployed to productionhttps://demoplace.my.id. — shipped 2026-07-30 - Ad-hoc Fixed Mobile Sidebar Profile Popover Overflow & Account Settings Modal Layout: Refactored
SidebarProfile.tsxpopover container to open vertically above profile button on mobile (bottom-full w-full) and to the right on desktop. RedesignedAccountSettingsModal.tsxto render a scrollable horizontal tab bar on mobile (flex-row overflow-x-auto border-b pb-2.5) with no-scrollbar styling and responsive active borders (border-b-2 md:border-l-2), preventing text truncation ("PASSW") and ensuring content pane visibility. Built, verified, and deployed to productionhttps://demoplace.my.id. — shipped 2026-07-30 - Ad-hoc Standardized 2-Row Mobile Header Layout Across ALL 17 Dashboard Pages: Restructured page headers across Overview Dashboard, Agents, Apps, Device Labeling, Devices, DNS, DPI Analytics, Events, Flows, Geography, Intelligence, Lookup, Network Infrastructure, Network Intelligence, Security Audit, User Accounts, and Threats to strictly follow the 2-row layout (Row 1: Title +
HelpTrigger, Row 2: Full-width description paragraph). Verified build (0 TS errors) and deployed to productionhttps://demoplace.my.id. — shipped 2026-07-30
Database Configuration
- Ad-hoc Configured Local Development Environment to Use Central Database Directly: (1) Removed
node scripts/start-mongo.jsexecution from the"dev"script inpackage.jsonto prevent starting a local in-memory database, (2) Removedmongodbservice definitions and local volumes fromdocker-compose.ymlanddocker-compose.prod.yml, (3) WiredMONGODB_URIenvironment variables directly from.env.localand.env.productioninto Docker services, (4) Hardened connection logic inbackend/db/mongoose.js,proxy/index.js,src/lib/actions/agents.ts, andtest/multitenant_branding_test.jsto immediately fail with a critical error and exit ifMONGODB_URIis undefined, preventing any accidental fallback to127.0.0.1:27017or localhost databases, (5) Adjusted assertions intest/architecture_test.jsand queries intest/multitenant_branding_test.js(checkingagent_registryinstead of emptysummariescollection) to keep TDD tests passing 100% against the central database. — shipped 2026-08-24