- GET /jobs/export (jobs.export): styled .xlsx via openpyxl — branded
banner, dark-green frozen header with auto-filter, zebra rows, color-
coded status, bulleted requirements/nice-to-have, date formatting.
Honors the same filters as /jobs/fetch.
- Export button on the Jobs screen now downloads the file through the
authenticated downloadFile helper, carrying the active UI filters,
with an Exporting... busy state (was a fake success toast).
- openpyxl pinned in backend requirements.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Deploy to S3 / deploy (push) Successful in 33sDetails
- New POST /job/assist-field (job_board.create OR jobs.edit): per-field
AI fix/suggest via backend/job_assist package on the shared llm_call.
Suggest is gated on title + experience anchors; decisive typo repair;
provider failures return a generic 503.
- AiFieldAssist component: sparkle button per field with fix/suggest,
loading, preview-before-apply, abort on close; wired into JobForm and
EditJobForm with per-field suggest hints.
- Create Job no longer requires a Buffer channel: without channel_id or
platform the backend saves an internal-only requisition (platform
internal) and never calls Buffer; publishing stays on the Job Board.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Assignees restricted to recruiter-role users (role id resolved from the
roles table per request, not hardcoded); server 422s any other role on
create and update
- New GET /tasks/assignees/fetch: active recruiter users for the picker,
separate from /users/fetch so assigning never needs rbac_users.view
- Creation gated to system_administrator / hr_administrator / recruiter:
allowed role ids searched from the DB and compared to the callers
role_id, on top of the tasks.create permission tag
- manual/005_tasks_rbac_restrict.sql: permission DB follows suit -
hiring_manager / department_head / ceo swap tasks_management for a
view-only tasks_viewer bundle (idempotent, auto-applies at boot)
- UI: assignee dropdown lists recruiters from the new endpoint with
required-field validation; recruiters get an assign-to-me default; the
New Task button honours the creator roles
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- New backend/tasks/ package (offer/ house style): tasks table
(title/status/priority/due_date/assignee_id -> users.id, optional
inbox_id/job_post_id links, soft delete), routes /tasks/fetch|create|
update|delete guarded by new tasks.* permission tags
- Assignees validated against users+roles: must exist, not deleted, not
candidate-role; omitted assignee defaults to the caller; responses carry
assignee_name/assignee_role from one batched join
- TASKS permission module (104 -> 112 tags); manual/004_tasks_rbac.sql
seeds the tags + tasks_management bundle onto 6 staff roles (auto-applies
at startup)
- Tasks.jsx cut over from seed to live: real create/complete/reopen with
optimistic flip, two-click delete in the detail modal, assignee picker
listing real users with roles; live sidebar badge (open-task total);
route now requires tasks.view
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- inbox_messages.ats_score/ats_band written on every completed inbox score;
inbox.ats_id always points at the current ats_results row
- ats_results now holds the supersede-chained history for BOTH inbox and
upload scores (new candidate_id link, inbox_id nullable for uploads)
- migrations/manual/*.sql apply automatically at startup, tracked once per
database in manual_migrations - developers just pull and boot
- 002_backfill_inbox_ats.sql backfills pre-existing scores
- Add Candidate modal: Matching-style role picker above the CV dropzone,
and the CV is scored via /candidate/score after creation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>