Add the COSS Pagination primitive and page the patients list at 10 rows/page
(search resets to page 1; the page is clamped at render so a shrinking list
never strands you past the last page). Replace the flat "secondary" status
badge with semantic colours: active → success, inpatient → info, discharged →
outline. Includes the i18n keys for pagination, the AI setup notice, and the
patient record-history / PDF export features.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
/api/network reported the container's bridge IP (172.x) when running in
Docker, which surfaced as a broken/"Error" value in Settings → About &
updates. Skip container-internal interfaces (detected via /.dockerenv) so the
endpoint returns no address inside a container, and guard the panel against an
unexpected response shape — both paths fall back to the helpful
"open via the server's IP" hint.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Give previewImport a concrete object schema (was z.array(z.unknown())) so
Google Gemini can emit a real function call — an array-of-unknown serializes
to an empty JSON schema, which made Gemini print the call as a `tool_code`
text block instead of invoking the tool. Validation stays lenient in
execute() via patientInputSchema. Also strengthen the system prompt: never
print tool calls/JSON or re-list record fields; keep prose to one sentence.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Retarget the release workflow, docker-compose image refs, and docs from the
placeholder temetro namespace to khalidxv (GitHub repo refs unchanged).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Reference prebuilt temetro/temetro-{backend,frontend} images in docker-compose
(with a build fallback) and stop baking the frontend API URL. Add a
tag-triggered GitHub Actions release workflow that pushes both images and cuts
a GitHub Release, plus RELEASING.md, CHANGELOG.md, and a root version. Overhaul
the root and frontend READMEs (screenshot, features, prebuilt-image quickstart,
LAN access, updating).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Resolve the backend URL from the current host at runtime (lib/backend-url.ts)
so one build works on localhost and any clinic LAN IP without a rebuild; used
by the API client, auth client, and socket. Wire the AI-chat mic to the Web
Speech API with graceful fallback. Add a Settings "About & updates" panel
(current/latest version, update command, shareable network address) and an
optional dismissible update banner.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add public GET /api/version (current version + GitHub-release update check,
cached, fail-soft) and GET /api/network (detected LAN addresses). Accept
localhost/private-LAN origins in CORS and Better Auth trusted origins via a
shared isAllowedOrigin helper, so staff can reach the app over the clinic
network. The seed-demo.ts fake test data is removed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The sibling patient wallet app was redesigned to build its UI with HeroUI
Native (Uniwind/Tailwind); only the tab bar stays expo-router NativeTabs.
Update the "Patient wallet app" note to match.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Two changes so off-network wallet scanning actually works:
- Force the cloudflared edge connection over http2 (TCP/443) instead of
QUIC (UDP/7844) in both the Docker tunnel and the dev-tunnel script.
QUIC is blocked on many networks/Docker setups, which left the tunnel
stuck "Failed to dial a quic connection" and the QR pointing at a dead
URL — the root cause of "must be on the same network" failures.
- Gate the discovered quick-tunnel URL on real end-to-end reachability:
poll the tunnel's own /health until it answers (Cloudflare 1033 clears
in ~30s) before publishing it, and have /pair await that discovery so
the QR never carries a not-yet-live URL.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add `npm run docker:tunnel` (docker-compose.tunnel.yml overlay): a
cloudflared sidecar opens a public quick tunnel to the backend, and the
backend auto-discovers its https://…trycloudflare.com URL from cloudflared's
metrics endpoint (services/relay-url.ts) and bakes it into the wallet-import
QR — so a phone on any network can scan, with no install/account/PUBLIC_RELAY_URL.
PUBLIC_RELAY_URL still wins when set. Verified end-to-end: the backend logs
the discovered tunnel URL on startup.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Scan-to-connect only worked on the same Wi-Fi because the QR carried a LAN
relay URL. Give the relay a public address two ways:
- `npm run dev:tunnel` (scripts/dev-tunnel.mjs) opens a cloudflared tunnel
to localhost:4000 and starts the backend with PUBLIC_RELAY_URL set to the
public https URL, so the QR carries it and a phone on any network connects.
- Deploy configs for Fly.io (fly.toml), Render (render.yaml), and Railway
(railway.json), all building the existing Dockerfile.
Also harden resolveRelayUrl to honor x-forwarded-proto so the derived QR URL
is https behind a TLS proxy (iOS ATS requires wss).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The "Import from a patient app → QR" code baked the web app's own
API_BASE_URL (typically http://localhost:4000) into the pairing URI, so a
real phone could never reach the relay and "Scan to connect" silently
stalled. Use the backend's server-resolved, device-reachable relay URL
instead (PUBLIC_RELAY_URL, else the request host), surface it on the
WalletPairing type, and document PUBLIC_RELAY_URL in .env.example.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Backend: nullable wallet_number on wallet_share_requests (migration 0029);
createPairingRequest + POST /api/patients/wallet/pair; applyShareResponse
binds the authenticated wallet on QR (pairing) requests
- Frontend: Import dialog gains a "Show QR" mode rendering a temetro-pair QR
(react-qr-code) the patient scans; requestWalletPairing helper; i18n keys
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- auth: forgot-password now has Email/Username tabs; new public
/api/auth-helpers/reset-by-username resolves a username and hands off to the
existing reset flow (real email or admin-notify fallback)
- messages: conversations expose isSystem; System notices are read-only (no
composer, no call button) and styled distinctly (shield icon + badge)
- meetings: compact, larger control bar; self tile shows real initials and an
avatar (not black) when the camera is off; delete-room UI with confirm
- sidebar: username-only accounts show @username instead of a synthetic email
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Chat: history pill now shows a History icon + a Start-new-chat (SquarePen)
button; removed the duplicate chat-history list from the sidebar.
Email: deployment-wide email provider config (Resend/Postmark/SendGrid/SMTP) in
Settings → Developers, with encrypted API key and a Send-test action. sendEmail
dispatches via the chosen provider (REST via fetch; SMTP via nodemailer).
Forgot password with no provider: alert the clinic admin(s) via a "System"
message card in Messages + a bell notification (seeded system user + per-clinic
System conversation); clicking deep-links to /settings?tab=careTeam&member=<id>.
Admins can set a member's password directly from the employee dialog
(PATCH /api/staff/:id/password via Better Auth's internal context — no admin
plugin needed).
Patient Portal: "New patient" booking path registers a demographics-only patient
then books; bookings reject double-booked slots (409).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New chrome-less (portal) route group with /portal/[clinic], a card-style choice
of "Book an appointment" vs "View my results", and step flows wired to a new
public backend router (src/routes/portal.ts):
- GET /api/portal/:clinic -> clinic name
- POST /api/portal/:clinic/appointments (verifies name+file#, books a confirmed
appointment that appears on the doctor's Appointments page)
- GET /api/portal/:clinic/results (minimal, safe status — no clinical values)
Excluded /portal from the auth proxy redirect so the kiosk loads without a
session. PHI exposure is intentionally minimal (see docs).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Backend: GET /api/settings/records/export downloads the clinic's full patient
archive as JSON; POST /api/settings/records/import creates new patients (skips
existing file numbers, drops cross-clinic provider links). Both admin-gated.
Frontend: Records settings now has a working Export button and an Import flow
(choose file -> preview count -> apply) wired to the new endpoints.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Backend: add tasks.assignee_user_id (nullable, fk user) + migration; persist
it through create/update and surface tasks to the assigned person in listTasks.
Frontend: New Task dialog gains a three-way Assignee control
(Myself / Department / Person) with a provider picker from /api/staff/providers;
task card + detail show the assignee's name when set.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- settings: keep tab nav on its own row so "Developers" no longer wraps
- chat: show the "Veil active" chip once per conversation, not every turn
- chat: record cards only offer "Click for more" when they have detail
- chat: chat-history panel (pill + sheet) top-left of the AI chat with
"Start new chat"; rename sidebar "New chat" -> "Ask temetro" (Sparkles)
- meetings: disable past dates, add an Upcoming Meetings list, and use the
Empty component for empty days; scheduler can be pre-targeted via ?with
- messages: add a call button left of each inbox row -> Meetings (?with)
- toast: add a dismiss (x) button; call invites now ring 30s with "Accept"
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Live invite: ring a clinic member into a room (socket call:invite + a bell
notification); the invitee gets a toast with a Join action. Notifications of
type "meeting" deep-link to /messages/meetings?room=, which auto-joins.
- Scheduling: new scheduled_meetings table + /api/meetings/events (list mine,
create, delete); a Calendar tab on the Meetings page with a month picker
(meeting-day dots), the day's agenda, and a Schedule-meeting dialog
(title/date/time/participants).
- Redesign: rounded control bar with tooltips (mic/cam/screen/invite + separated
red Leave), speaking ring on tiles (Web Audio), and live room-occupancy counts
via call:presence broadcasts. Migration 0025.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Chat patient cards are now compact previews (header + key stat + "Click for
more"); cards size to content (items-start) instead of stretching to the tallest;
Edit record moved into the summary detail dialog
- AI citations render once per source per message (collapses per-word spam) and the
prompt now asks the model to cite sparingly (once per paragraph, not per list item)
- Sidebar sub-items use exact-match active state so Meetings no longer lights Inbox
- Analysis defaults to All Time, drops the 12m option, and clamps the chart window
to >=2 points so 30d/Today render instead of collapsing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Backend: meeting_rooms table + /api/meetings (list/create/delete, org-scoped),
and WebRTC mesh signaling over the existing authed Socket.io (call:join with a
≤4 cap and org authorization, call:signal relay, peer-joined/left, disconnect
cleanup). Migration 0024.
Frontend: Messages nav is now expandable (Inbox + Meetings); new
/messages/meetings page with a room list and a Discord-style call UI — a
useWebRtcMesh hook (camera/mic, screen share via replaceTrack, ≤4 mesh) and a
tile grid with a mic/camera/screen/leave control bar. New lib/meetings + i18n.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Retrieval tools now register a PHI-free sourceId per record/list and stream a
data-source part with the real clinician-facing title; the system prompt asks
the model to cite facts inline as [[src:id]]. The chat renders those markers as
numbered inline citation chips (PreviewCard hover) via a Streamdown link
override, with a Sources footer fallback when the model omits markers.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New staff_profile table (org + user, unique) holding a clinician's clinical
specialty. GET /api/staff and /api/staff/providers now include specialty; new
PATCH /api/staff/:userId (member:update) upserts it. Migration 0023.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Fix clinic onboarding loop: refresh session after setActive before navigating,
surface setActive errors, and guard AppAuthGuard's onboarding redirect race (#1)
- Add a mobile-only floating top-right SidebarTrigger so the sidebar is reachable
when the offcanvas sidebar is closed on phones (#5)
- Make notifications clickable: navigate to the source (conversation/patient) and
mark read; MessagesView/PatientsView honor ?conversation= / ?file= deep links (#6)
- Analysis page: add an Overview header with a time-range segmented control and a
Customize popover that shows/hides sections; range slices month-based charts (#10)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Hover state fed the nodes/edges useMemos, so every hover recreated both
arrays — React Flow re-measured the dimensionless nodes and the hovered
node's scale transform shifted it out from under the pointer, causing a
rapid dark↔light flicker. Drive hover focus through React context instead
so the nodes/edges props stay referentially stable (custom memoized node +
edge read the hovered id), and drop the scale transform. Theme the React
Flow controls via colorMode from next-themes so the zoom box matches the
active theme instead of rendering white.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
In Graph mode, a natural-language request ("graph for John Smith") went
through the getPatient tool, which always emitted record cards — so the
clinician got Summary/Vitals cards instead of a graph (the mode prompt
even wrongly claimed the graph rendered automatically). Thread the
composer mode into the chat tools and have getPatient emit
data-recordGraph in graph mode (matching the client-side /patient
fast-path), with the cards kept for chat/analysis modes.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Approval state lived only in each card's local React state, so after
committing (or after reloading a saved conversation) the Add / Review &
add / Import buttons reappeared active and the same records could be
added again. Persist the resolution onto the message data part via a
chat-panel handler (setMessages), and initialize each card's status from
data.resolved so committed/discarded proposals stay locked across
re-render and history reload.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The import preview only showed counts + skipped-row errors with no way to
fix anything. Now every parsed record is editable before import:
- backend: shared validatePatientImport() (used by the previewImport tool)
+ POST /api/ai/import/validate for dry-run re-validation; the import
preview payload now carries the original records (and the source record on
each invalid row) so the UI can edit them.
- frontend: the import card gets a "Review & edit" dialog listing every
record with a ready / needs-fixing badge; opening one reuses the full
PatientFormDialog in a new non-persisting review mode (editable file
number) and re-validates on save, so skipped rows can be fixed and
included.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Migration prompt now tells the agent to map/normalize an uploaded export
into temetro's shape itself (gender words, non-numeric IDs, delimited
allergy/med/problem lists, per-visit encounters) and to fix-and-re-preview
skipped rows rather than telling the clinician to reformat the file.
- Guarantee a non-empty reply: when the model ends on a tool call with no
text, ask it to summarize (external+Veil path) and fall back to a generic
line; the streaming path appends the same fallback. Raise the step cap to 8.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Real-world exports were rejected wholesale (file number must be digits,
sex must be M/F, every allergy/med/problem/encounter a full object), so
AI imports skipped everything. Normalize at the schema edge instead:
strip non-digits from the file number, map gender words to M/F, accept a
bare string for allergies/medications/problems (filling sensible
defaults), and default missing encounter fields (type → "Visit"). The
manual patient form shares this schema and benefits too.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a real file-storage layer to the backend and wire upload UI into the
frontend.
backend:
- new `attachments` table (org-scoped, links to a patient file number and
optionally a lab result) + Drizzle migration
- `/api/attachments` route: upload (multer → disk under UPLOAD_DIR),
list, stream/download, delete; gated by patient:write OR lab:write via
a new requireAnyPermission helper so lab staff can attach analyses
- UPLOAD_DIR env (default ./uploads) + a persistent docker volume
frontend:
- lib/attachments.ts client (multipart upload, list, delete, preview URL)
- staged file picker in the patient Add/Edit dialog (uploaded after save)
and the lab Add-result dialog (linked to the result)
- a Files section in the patient sheet that lists attachments and opens
them in a preview dialog (images inline, others via download)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The "Enable AI assistant" toggle already disabled the AI for everyone
(including owners/admins) at the policy layer, but the copy read as an
employee-only control and the Analysis surface stayed visible. Clarify
that the master switch covers admins too, and close the gaps: hide the
Analysis nav/command entry and redirect /analysis (alongside the chat
home) to /patients when AI is disabled. The employee-only toggle remains
the secondary option that keeps AI for owners/admins.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The single proposal card crammed every proposed record into comma-joined
summary lines — an inventory import became an unreadable wall of text.
Render inventory/invoice records as a compact scrollable item list, and
add an Edit button (single card + per-row in the batch review) that opens
a per-kind edit dialog so the clinician can adjust the data — whole record
or individual items — before it is committed.
New RecordEditDialog is schema-driven (EDIT_SCHEMAS) per action kind,
including add/remove rows for invoice line items and inventory items.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The record graph was a cramped React Flow box wedged inside a sheet
section. Redesign it Obsidian-style — round nodes with the label
underneath, a soft glow, and a hover-focus that highlights a node plus
its neighbours while dimming the rest.
Move it out of the inline section: the sheet now shows an "Open graph"
button (closes the sheet, opens the graph in a large dialog) and a
clickable list of the patient's records (problems + visits); clicking a
record opens a detail dialog.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
CLINICAL_RESOURCES includes "lab" but the employee detail dialog only
mapped patient/appointment/prescription/task, so the lab row rendered as
the raw i18n key with no icon. Add a FlaskConical icon and a
"Lab results" label.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The composer's SELECT is now a clinician-facing mode picker instead of a list
of LLM vendors (the model still comes from Settings → AI and continues to drive
the Veil consent gate). The mode travels with each send:
- backend appends an Analysis/Graph directive to the agent's system prompt
- Graph mode renders an Obsidian-style RecordGraph for the /patient fast-path
(new data-recordGraph message part reusing the shared graph component)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The marketing landing page is not a separate "temetro-landing" GitHub repo and
is not in the monorepo — it lives in the sibling ~/Desktop/temetro/landing-page
folder (next to the docs site), its own git repo. Fix both the root and
frontend CLAUDE.md notes.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- replace the attach "+" menu (whose programmatic fileInput.click() was dropped
by user-activation gating, so files never attached and no chip appeared) with
a native <label> paperclip + a direct appointment button
- shared-appointment cards are now clickable for both parties, opening an
AppointmentDetailDialog with the full snapshot (when/type/provider/patient/status)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- "Mark paid" button (settles invoice + all installments) when not paid/void
- per-installment Pay button + Paid badge; auto-marks invoice paid when the
last installment clears
- overdue badge on past-due unpaid installments; due-through timeframe hint
- installments + split control hidden once the invoice is paid
All via the existing PUT /api/invoices/:id (no backend change).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The realtime "Live" hospital card is dropped in favour of a six-month patient
visits area chart, aggregated client-side from real appointments. Renames the
analysis.live.* i18n block to analysis.area.* and removes the dead
live-hospital-chart component.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- deletePatient() lib fn (DELETE /api/patients/:fileNumber already existed)
- confirmed delete button in the patient sheet (full-clinician only)
- aggregate appointments/prescriptions/invoices into the sheet (by file #)
- new shared RecordGraph (@xyflow/react + d3-force) linking problems↔visits,
added as a "Record graph" section + reusable by AI Graph mode
- i18n keys for delete + new sheet sections
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The file pickers read event.target.files but reset event.target.value = ""
before the file was actually used: in the AI composer the value reset ran
before React's deferred setState updater read the (now-empty) live FileList,
so no chip appeared; in Messages the reset ran before the length check, so it
returned early. Snapshot the files into a plain array synchronously, before the
reset. This is why attaching seemed to fail (no badge) — especially while typing.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>