Module 2 Release Notes — Workspace Foundation + Dashboard UI
Commits: ddd0524 (backend), 6fa4c14 (frontend).
Full decision record: docs/adr/0002-workspace-foundation-module.md.
Features added
Backend — Workspace Foundation, the storage layer every future module (Recon, AI, Bug Bounty, Reports) will attach to:
- Workspaces (renamed from Organizations): settings, avatar upload, member listing.
- Projects: create/update/archive/restore/soft-delete/favorite, status, visibility, tags, members.
- Targets: 8 types (domain/subdomain/URL/IP/CIDR/API/mobile app/internal asset), environment, scope status, tags — no scanning or recon logic attached.
- Notes: markdown content, optional target linkage.
- Evidence: 6 types (screenshot/HTTP request/HTTP response/file/log/video), SHA-256 checksums on upload.
- Attachments: polymorphic file uploads across Workspace/Project/Target/Note/Evidence.
- Tags: workspace-scoped, applicable to Projects and Targets.
- Activity Timeline: event-driven, records every create/update/archive/delete/favorite/upload action.
- Search: cross-resource (Project/Target/Note/Evidence) query endpoint.
PATCH /users/me/preferences(theme/timezone/notifications) — small Module 1 extension.
Frontend — first real UI for the product:
- Full Auth flow: login, register, forgot/reset password, email verification, MFA challenge, OAuth (Google/GitHub).
- Dashboard shell: sidebar, header, workspace switcher, command palette (Cmd/Ctrl+K), keyboard shortcuts, mobile slide-in drawer.
- Dashboard home: stat cards, recent projects, recent activity, quick actions.
- Full CRUD UI for Projects (cards/table views), Targets, Notes (markdown split-pane editor with debounced auto-save), Evidence (with attachments panel).
- Workspace-wide Activity timeline.
- Settings: Profile, Security (password + MFA setup/disable), Sessions (list/revoke), API Keys (honest "coming soon"), Preferences, Workspace.
- Dark-mode-first, responsive, loading skeletons, empty/error states, toast notifications throughout.
Architectural improvements
- CQRS (
@nestjs/cqrs) established as the standing pattern for all future feature modules —CommandBus/QueryBus/EventBus, one command/query per file, no event-sourcing overhead. - Event-driven Activity Timeline: any future module can plug into activity recording just by publishing a domain event that implements
ActivityDomainEvent— no changes to theactivitymodule required. StorageService/SearchServicebehind swappable ports: both got their first real consumers this sprint (local-disk storage, Prisma ILIKE search); S3/R2/Meilisearch/etc. are new adapter classes later, not feature-module rewrites.- "No direct feature imports" rule proven out across 8 new modules — cross-module reads go through real DB foreign keys (caught and mapped to clean errors) or the CQRS bus, never direct repository imports.
packages/sharedgiven a real build step (compiles todist/) so one package can be safely consumed by both the NodeNext-resolution backend and the Turbopack-bundled frontend — a pattern any future shared code needs to follow.turbo.jsonordering fix:check-typesnow waits on the same package'sbuild— prevents a.next/race that only surfaces once a package has both tasks doing real work.
Breaking changes
Organization/OrganizationMember/OrgMemberRolerenamed toWorkspace/WorkspaceMember/WorkspaceMemberRole(schema + every Module 1 reference). No externally-facing API existed yet for these under the old name, so this is breaking only against local dev databases seeded before this module — re-runprisma db push(or apply the new baseline migration) and reseed.- None of Module 1's authentication endpoints or contracts changed.
Known limitations
- No workspace-wide "list all targets/notes/evidence" endpoint — these resources are project-scoped by design (matches how pentest engagements are actually organized); the frontend's top-level nav entries reflect this honestly via a project picker rather than faking a global list.
- API key issuance has no backend endpoints yet (Module 1 schema only) — Settings shows an honest "coming soon" state.
- Header notifications are a visual stub — no
Notificationmodel or delivery mechanism yet. - No automated browser/E2E test suite for the frontend this sprint (verified live via build + full HTTP-level flow testing instead); a Playwright suite is a reasonable future addition.
- Visual/interactive browser verification of the dashboard was not completed in the build environment (missing system libraries for headless Chromium, blocked on a
sudoinstall) — verification instead relied on a clean production build (all 27 routes), full lint/typecheck/test pass, and a live curl-driven flow against the real API.
Recommended next module
Recon Module (WHOIS/DNS/subdomain enumeration/tech fingerprinting), per the existing rollout order in PROJECT_SPEC.md. It's the first module that actually populates Targets with real data (via Target.customFields, reserved for exactly this) and will exercise the Activity Timeline and Attachments/Evidence pipeline under real usage for the first time.