19 Commits

Author SHA1 Message Date
6baa34dec3 update and nug fixes 2026-07-11 19:24:28 +03:00
5dc61c8e30 update on the px-actions 2026-07-05 14:49:45 +03:00
e5705a1b1c fix: 3 cross-hospital data isolation violations (0 violations after fix)
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m8s
Isolation test: HH-N admin vs E2E-HOSP data across 5 scenarios.
Found + fixed 3 real isolation gaps:

1. observation_list LEAKED unassigned observations across hospitals —
   the filter Q(assigned_department__hospital=X) | Q(assigned_department__isnull=True)
   showed ALL unassigned observations globally. Fixed: add hospital= filter
   to the isnull branch.

2. complaint_add_note allowed cross-hospital note creation —
   ComplaintService.add_note had no hospital check. Any authenticated user
   from any hospital could add notes to any complaint. Fixed: added hospital
   isolation check (same hospital or px_admin).

3. observation_detail accessible cross-hospital when assigned_department is null —
   the RBAC check only ran if observation.assigned_department was set.
   Fixed: added fallback hospital check for observations with no department.

Result: 16 PASS, 0 FAIL, 0 isolation violations.
Tested: list isolation (8 modules), detail isolation (3), write isolation (2),
px_admin hospital switching, observation no-dept edge case.
2026-06-18 21:17:37 +03:00
2089730344 test: onboarding flow — activation, wizard, checklist, completion (12 PASS, 3 WARN)
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m15s
Tests the full onboarding flow: token activation (auto-login) → welcome → wizard
content steps → checklist → activation (password) → completion → invalid token
→ admin provisional list.

Key finding: the wizard UI renders but the onboarding flow doesn't actually
COMPLETE — after walking all steps + submitting the password form, the user is
still is_provisional=True with no password set. The activation step lacks a
POST handler to finalize onboarding. Details in the test observations.

Harness: seed_e2e_provisional + get_e2e_onboarding_state CLI + spec.
2026-06-17 18:23:27 +03:00
badb6a9ebf feat: QI Projects — team-member task management + My Tasks + notifications
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m41s
Fixed 3 gaps in the QI Projects module:

Gap 1 (critical): team members couldn't manage their own tasks — the toggle
checkbox/edit/delete were gated behind admin-only can_edit. Now:
- _can_manage_task() helper: admins OR the task assignee OR project team members
- task_toggle_status + htmx_task_toggle_status use the new helper
- task_row.html shows the toggle for assignees (task.assigned_to.user_id check)

Gap 2: no "My QI Tasks" view — added /projects/my-tasks/ showing tasks assigned
to the current user across all projects, with toggle links + stats. Sidebar link.

Gap 3: no notification on task assignment — added apps/projects/signals.py
(post_save on QIProjectTask → create_in_app_notification). apps.py ready() wired.

Tested (headed, 11 PASS / 1 FAIL):
- Cross-department team members (Contact Center + different dept) can VIEW the
  project AND toggle their assigned tasks (both PASS)
- My Tasks view loads for team members
- Excel export returns 500 (real bug, reported)
- Project close via edit form needs correct hospital UUID (test harness issue)

Also bundles accumulated in-progress work across complaints, observations,
organizations, templates, and other modules.

Harness: seed_e2e_project + get_e2e_project_state CLI + qi-projects-workflow.spec.ts
2026-06-16 23:55:58 +03:00
1ee9ae807b test: complaint full lifecycle (create -> resolve) + fix public_submit NameError
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m11s
One continuous E2E test from public-form creation through resolution:
1. CREATE (public form POST) -> captures CMP- reference
2. ACTIVATE (open -> in_progress)
3. SEND TO DEPARTMENT (creates ComplaintInvolvedDepartment)
4. CHAMPION RESPONDS (department response)
5. MANAGER APPROVES
6. PX ACCEPTS
7. RESOLVE

Fix: NameError in public_complaint_submit (reference_number was undefined after
removing the legacy CMP- generator). Also fixed the same in the inquiry public
submit path (ui_views.py). Both now read complaint.reference_number /
inquiry.reference_number after save().

Harness: get_e2e_complaint_id CLI + seed_e2e_complaint other_dept_id output.
2026-06-15 16:20:55 +03:00
553364b82c test: send-to-person workflow (assign + reassign) across complaint/inquiry/observation
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m21s
Covers the recipient_type=person branch of the unified send-to endpoint for all
3 modules: assign to px_employee, verify the assignee can open the item detail,
then reassign to a different user. 3/3 pass, 0 FAIL.

Harness: get_e2e_user_id + get_e2e_assignment_state CLI helpers.
2026-06-15 15:11:54 +03:00
32e2a3f996 fix: require activation before sending observation/inquiry to a department
Some checks failed
Build and Push Docker Image / build (push) Failing after 6m52s
An item could be sent to a department while still in its initial (open) state,
bypassing activation. Added a status guard to the 4 send entry points:
- observation_send_to_department / observation_send_to (AJAX)
- inquiry_transfer_to_department / inquiry_send_to (AJAX)
Rejects with "Activate this {observation/inquiry} before sending it to a
department." if status is open. Re-sends after a rejection still work (item
stays in_progress).

Also:
- seed_e2e_dept_response: observation status "new" -> "open" (valid initial;
  "new" isn't a valid ObservationStatus, which is why activate never moved it)
- spec: Flow A/B/C now activate before send
2026-06-14 21:27:39 +03:00
23b6e239b5 test: inquiry + observation dept-response workflow E2E
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m2s
Adds headed Playwright coverage for the simpler dept-response flow
(PX send -> champion responds -> PX accept/reject), 3 flows per module
(happy path, token response, reject loop). 6/6 pass; 50 PASS / 5 WARN / 0 FAIL.

Findings (documented in report):
- token-response form pages (inquiry + observation) render the dashboard
  chrome instead of the response form -> anonymous champions can't submit
  via the emailed link (backend POST still works)
- NameError get_email_header_html in inquiry_transfer_to_department (notif
  email silently fails)
- observation can't jump new->resolved (status machine needs intermediate steps)

Harness:
- seed_e2e_dept_response, get_e2e_dept_response_state CLI helpers
- E2E_MAXIMIZED=1 fullscreen mode in playwright.config.ts
- report: appended "Inquiry & Observation dept-response workflow" section
2026-06-14 16:55:54 +03:00
ef53f69833 test: champion/manager workflow E2E + fix investigation bugs
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m7s
Adds headed Playwright coverage for the full send-to-department lifecycle
(PX send -> champion investigates -> manager approves/rejects -> PX accepts ->
resolve), including the token investigation sub-flow and both reject loops.

Bugs fixed (found by the new test):
- champion_start_investigation: NameError - InvestigationAnswer not imported
  (complaints/views.py) -> the "create questions" POST was 500ing
- champion_start_investigation: staff_member.phone_number -> Staff.phone
  (would have AttributeError'd once the import was fixed)

Harness:
- create_e2e_isolated_env: bind dept-manager as department.manager + create
  e2e-staff Staff profile in the champion's department
- seed_e2e_complaint, get_e2e_workflow_state CLI helpers for setup/assertions
- champion-manager-workflow.spec.ts (flows A/B/C1/C2)

Report: appended "Champion/Manager Workflow Audit" section.
2026-06-14 15:23:14 +03:00
7369d08012 feat: unified reference numbers + feedback modules QA audit
All checks were successful
Build and Push Docker Image / build (push) Successful in 4m14s
Reference numbers (unified scheme PREFIX-YYYYMM-HOSP-NNNN, e.g. CMP-202606-HHN-0001):
- new ReferenceSequence model + generate_reference() helper (apps/core)
- Complaint/Inquiry/Observation/Appreciation/Suggestion emit unified refs via save()
- prefix-based auto-routing in public track API (CMP/INQ/OBS trackable; APR/SGT internal-only)
- removed legacy CMP-/INQ- generators in ui_views, integrations, px_sources
- migrations: core.0003_referencesequence, appreciation.0006, feedback.0008, observations.0012
- unit tests (format, sanitization, monthly reset, 40-thread concurrency)

QA audit:
- isolated E2E hospital sandbox mirroring HH-N + 10 role users (create_e2e_isolated_env)
- feedback-modules-audit.spec.ts + audit helper (headed, run-to-completion)
- reports/feedback-modules-qa-report.md

Also bundles accumulated in-progress work across complaints, observations,
organizations, templates, and other modules.
2026-06-14 14:29:23 +03:00
c5f76b3855 updates
Some checks are pending
Build and Push Docker Image / build (push) Waiting to run
2026-05-11 14:45:30 +03:00
e119312a9c clean up version 2026-04-19 10:53:12 +03:00
bcb9c86541 pre dep 2026-04-09 13:46:34 +03:00
177a7e0f5f updates 2026-04-08 17:13:35 +03:00
0fc06151eb data 2026-03-15 23:48:45 +03:00
c16e410fdd Remove hospital dropdowns from templates and fix JavaScript dependencies 2026-03-11 00:17:53 +03:00
ceae6c5009 update 2026-02-25 08:24:43 +03:00
d787d41bc9 export 2026-02-25 08:15:25 +03:00