diff --git a/README.md b/README.md index f1beafe..95041e9 100644 --- a/README.md +++ b/README.md @@ -47,6 +47,7 @@ Crank - платформа для публикации внешних API в в - `docs/runtime-config.md` - конфигурация окружения. - `docs/deployment.md` - деплой, reverse proxy и CI/CD. - `docs/deploy-and-staging-smoke.md` - канонический post-deploy smoke pass для staging/production-like окружения. +- `docs/authenticated-staging-pass.md` - browser-authenticated pass для UI flows, secrets, wizard и protocol smoke на стенде. - `docs/staging-regression-notes.md` - журнал реальных замечаний и результатов post-deploy проверок на стенде. - `docs/demo-runbook.md` - демонстрационный сценарий. - `docs/public-smoke-targets.md` - готовые публичные upstream-сервисы и payload-ы для smoke-проверки MCP. diff --git a/TASKS.md b/TASKS.md index 983c2db..6a3d324 100644 --- a/TASKS.md +++ b/TASKS.md @@ -2,18 +2,18 @@ ## Current -### `feat/live-staging-run` +### `feat/authenticated-staging-pass` Status: completed DoD: -- first real staging regression entry exists -- public routes, auth session JSON, MCP health and legacy redirects are recorded against the live domain -- follow-up for the next authenticated staging pass is captured +- authenticated staging pass template exists +- deploy smoke and staging notes docs link to the authenticated pass +- README exposes the authenticated pass doc as the canonical next step after helper smoke ## Next -- `feat/authenticated-staging-pass` +- `feat/live-authenticated-staging-entry` ## Backlog diff --git a/docs/authenticated-staging-pass.md b/docs/authenticated-staging-pass.md new file mode 100644 index 0000000..17e2f29 --- /dev/null +++ b/docs/authenticated-staging-pass.md @@ -0,0 +1,204 @@ +# Authenticated Staging Pass + +## 1. Назначение + +Этот документ описывает именно тот кусок staging smoke, который нельзя честно закрыть одними `curl` и unauthenticated route checks. + +Он покрывает: + +- login/logout; +- UI shell после входа; +- `Secrets -> Auth Profiles -> Wizard -> Test run`; +- protocol smoke через UI и MCP; +- streaming pages после реальных вызовов. + +Использовать вместе с: + +- [deploy-and-staging-smoke.md](/home/a.tolmachev/code/rust/mcpaas/docs/deploy-and-staging-smoke.md) +- [staging-regression-notes.md](/home/a.tolmachev/code/rust/mcpaas/docs/staging-regression-notes.md) +- [manual-regression-checklist.md](/home/a.tolmachev/code/rust/mcpaas/docs/manual-regression-checklist.md) + +## 2. Что нужно заранее + +- свежий deploy уже прошел helper smoke: + - `just staging-smoke https://` +- известны bootstrap admin credentials; +- на стенде есть demo data или подготовленный disposable workspace; +- браузер открыт с devtools, чтобы фиксировать network/console findings. + +## 3. Канонический проход + +### 3.1. Login and shell + +1. Открыть `/login` +2. Проверить: + - invalid login -> корректная ошибка; + - valid login -> redirect на `/`; + - нет redirect loop; + - password-only note видна; + - planned actions на login не выглядят рабочими. +3. После входа проверить: + - current workspace в navbar; + - user identity; + - language switch; + - logout. + +### 3.2. Core UI pages + +После повторного входа открыть: + +- `/` +- `/agents` +- `/api-keys` +- `/secrets` +- `/logs` +- `/usage` +- `/workspace-setup` +- `/settings` +- `/stream-sessions` +- `/async-jobs` +- `/wizard/` + +Для каждой страницы зафиксировать: + +- `status: passed | partial | failed` +- есть ли console errors; +- есть ли failing XHR/fetch; +- есть ли broken layout. + +### 3.3. Secrets and auth profiles + +1. Открыть `/secrets` +2. Создать disposable `token` secret +3. При необходимости создать еще: + - `header` + - `username_password` +4. Проверить: + - list/update timestamps; + - rotate; + - delete; + - usage references + +### 3.4. Wizard auth flow + +1. Открыть `/wizard/` +2. На шаге 2: + - выбрать `No auth`; + - выбрать existing auth profile; + - создать quick secret; + - создать quick auth profile; +3. Сохранить upstream +4. Дойти до `Test run` +5. Подтвердить, что: + - нет `${secrets.*}`; + - upstream сохраняется; + - test run отрабатывает с `auth_profile_ref`. + +### 3.5. Protocol smoke + +Использовать: + +- [public-smoke-targets.md](/home/a.tolmachev/code/rust/mcpaas/docs/public-smoke-targets.md) + +Обязательные кейсы: + +- `REST` +- `GraphQL` +- `gRPC` + +Для каждого: + +1. создать или открыть operation; +2. выполнить `Test run`; +3. publish; +4. привязать к agent; +5. выполнить MCP smoke: + - `tools/list` + - `tools/call` + +### 3.6. Streaming smoke + +Проверить: + +- `window` tool; +- `session` tool; +- `async_job` tool; +- `/stream-sessions`; +- `/async-jobs`. + +Если WebSocket/SOAP upstream на стенде отсутствуют: + +- явно записать `not exercised`, а не оставлять пустым. + +## 4. Что нужно занести в staging notes + +По итогам authenticated pass в [staging-regression-notes.md](/home/a.tolmachev/code/rust/mcpaas/docs/staging-regression-notes.md) обязательно добавить: + +- deploy commit; +- кто проходил smoke; +- что именно проверено; +- что прошло; +- findings с severity; +- infra notes; +- explicit status для: + - auth; + - secrets/auth profiles; + - wizard; + - REST; + - GraphQL; + - gRPC; + - streaming; + - WebSocket; + - SOAP. + +## 5. Готовый блок для вставки + +```md +## YYYY-MM-DD HH:MM TZ — rmcp.itexp.me (authenticated pass) + +- deploy commit: `` +- checked by: `` +- smoke status: `passed | partial | failed` +- scope: + - auth + - ui shell + - operations + - wizard + - agents + - api keys + - secrets + - logs + - usage + - streaming + - mcp smoke + +### Passed + +- login/logout completed +- shell pages open after auth +- secrets/auth profile flow status: `` +- REST smoke: `` +- GraphQL smoke: `` +- gRPC smoke: `` +- streaming pages status: `` +- WebSocket: `` +- SOAP: `` + +### Findings + +- none + +### Infra notes + +- ... + +### Follow-up + +- ... +``` + +## 6. Практический статус + +На текущий момент этот документ подготовлен как operational template. + +Он не заменяет реальный authenticated browser pass и не должен отмечаться как `passed`, пока результаты не занесены в [staging-regression-notes.md](/home/a.tolmachev/code/rust/mcpaas/docs/staging-regression-notes.md). diff --git a/docs/deploy-and-staging-smoke.md b/docs/deploy-and-staging-smoke.md index e5cb054..3253678 100644 --- a/docs/deploy-and-staging-smoke.md +++ b/docs/deploy-and-staging-smoke.md @@ -11,6 +11,10 @@ Результаты прохождения этого checklist нужно заносить в [staging-regression-notes.md](/home/a.tolmachev/code/rust/mcpaas/docs/staging-regression-notes.md). +Для полного browser-authenticated прохода использовать отдельный документ: + +- [authenticated-staging-pass.md](/home/a.tolmachev/code/rust/mcpaas/docs/authenticated-staging-pass.md) + ## 2. Когда использовать Запускать после: diff --git a/docs/staging-regression-notes.md b/docs/staging-regression-notes.md index 916ba0c..c568588 100644 --- a/docs/staging-regression-notes.md +++ b/docs/staging-regression-notes.md @@ -58,6 +58,7 @@ - [deploy-and-staging-smoke.md](/home/a.tolmachev/code/rust/mcpaas/docs/deploy-and-staging-smoke.md) - [manual-regression-checklist.md](/home/a.tolmachev/code/rust/mcpaas/docs/manual-regression-checklist.md) +- [authenticated-staging-pass.md](/home/a.tolmachev/code/rust/mcpaas/docs/authenticated-staging-pass.md) ## 2. Как вести записи