329 lines
11 KiB
Markdown
329 lines
11 KiB
Markdown
# TASKS
|
||
|
||
## Current
|
||
|
||
### `feat/community-agent-key-cutover`
|
||
|
||
Status: in_progress
|
||
|
||
Goal:
|
||
- довести открытую редакцию до продуктово завершенного машинного доступа через ключ AI-агента.
|
||
|
||
Main code areas:
|
||
- `crates/crank-core/src/agent.rs`
|
||
- `crates/crank-core/src/auth.rs`
|
||
- `crates/crank-registry/src/postgres/agent.rs`
|
||
- `crates/crank-registry/src/postgres/api_key.rs`
|
||
- `apps/admin-api/src/service.rs`
|
||
- `apps/admin-api/src/app.rs`
|
||
- `apps/mcp-server/src/app.rs`
|
||
- `apps/ui/js/agents.js`
|
||
- `apps/ui/js/api-keys.js`
|
||
- `apps/ui/html/agents.html`
|
||
- `apps/ui/html/api-keys.html`
|
||
- `apps/ui/js/i18n.js`
|
||
|
||
Implementation slices:
|
||
1. Закрыть remaining workspace/platform-key assumptions в `admin-api` и `mcp-server`.
|
||
2. Нормализовать list/create/revoke/delete flow для agent keys.
|
||
3. Привести UI страницы `Agents` и `API Keys` к одной модели agent-scoped machine access.
|
||
4. Явно ограничить `Community` на `security_level = standard`.
|
||
|
||
Progress:
|
||
- done: `mcp-server` принимает ключ только по `(workspace_slug, agent_slug, secret_hash)`;
|
||
- done: `admin-api` уже отдает и принимает agent-scoped key routes;
|
||
- done: UI `API Keys` переведен на agent-scoped machine access;
|
||
- done: removed legacy workspace-key routes, demo/bootstrap assumptions, and per-agent key count bug.
|
||
|
||
DoD:
|
||
- ключ создается и принадлежит конкретному AI-агенту;
|
||
- UI объясняет назначение ключа без ссылок на старую workspace-key модель;
|
||
- `mcp-server` принимает Community machine access только по agent key;
|
||
- Community flow не требует short-lived token service.
|
||
|
||
Verification:
|
||
- backend unit and integration tests for key lifecycle;
|
||
- MCP tool-call tests through agent endpoint;
|
||
- e2e smoke for agent key create/reveal/revoke.
|
||
|
||
## Next
|
||
|
||
### `feat/edition-capability-model`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- ввести capability model по редакциям и перестать смешивать Community и premium surface.
|
||
|
||
Main code areas:
|
||
- `crates/crank-core/src/*`
|
||
- `apps/admin-api/src/service.rs`
|
||
- `apps/admin-api/src/app.rs`
|
||
- `apps/ui/js/*`
|
||
- `apps/ui/html/*`
|
||
- `docs/product-editions.md`
|
||
- `docs/frontend-roadmap.md`
|
||
|
||
Implementation slices:
|
||
1. Ввести серверную модель capabilities:
|
||
- protocols
|
||
- auth modes
|
||
- security levels
|
||
- workspace/user/agent limits
|
||
2. Отдавать capability flags в `admin-api`.
|
||
3. Привести UI к capability gating вместо скрытых продуктовых допущений.
|
||
4. Зафиксировать Community defaults в docs и runtime config.
|
||
|
||
DoD:
|
||
- UI знает, какие функции входят в текущую редакцию;
|
||
- Community не показывает рабочие controls для premium-only features;
|
||
- capability checks существуют не только в UI, но и на сервере.
|
||
|
||
Verification:
|
||
- API tests for capability payloads;
|
||
- frontend smoke for hidden/locked states;
|
||
- manual verification on Community build.
|
||
|
||
### `feat/private-token-service-seam`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- подготовить public codebase к private реализации короткоживущих и одноразовых токенов.
|
||
|
||
Main code areas:
|
||
- `crates/crank-core/src/auth.rs`
|
||
- `crates/crank-core/src/agent.rs`
|
||
- `apps/admin-api/src/app.rs`
|
||
- `apps/admin-api/src/service.rs`
|
||
- `apps/mcp-server/src/app.rs`
|
||
- `docs/agent-auth-model.md`
|
||
- `docs/admin-api.md`
|
||
- `docs/mcp-interface.md`
|
||
|
||
Implementation slices:
|
||
1. Определить stable contracts для:
|
||
- `POST /mcp-auth/v1/token`
|
||
- `POST /mcp-auth/v1/token/one-time`
|
||
2. Ввести abstraction для token verification в `mcp-server`.
|
||
3. Подготовить capability-gated UI/API surface без private implementation в Community.
|
||
4. Отделить Community `standard` flow от commercial `elevated/strict`.
|
||
|
||
DoD:
|
||
- public contracts зафиксированы и тестируемы;
|
||
- Community продолжает работать без private token service;
|
||
- premium auth paths не размазываются по Community logic.
|
||
|
||
Verification:
|
||
- contract tests for auth payload shapes;
|
||
- unit tests for credential-kind enforcement;
|
||
- docs sync check.
|
||
|
||
### `feat/community-surface-trim`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- привести открытую редакцию к честному product surface и убрать расхождение между текущим кодом и edition policy.
|
||
|
||
Main code areas:
|
||
- `apps/ui/js/wizard.js`
|
||
- `apps/ui/js/wizard-model.js`
|
||
- `apps/ui/js/agents.js`
|
||
- `apps/ui/js/settings.js`
|
||
- `apps/ui/js/i18n.js`
|
||
- `docs/product-editions.md`
|
||
- `docs/architecture.md`
|
||
- `docs/mcp-interface.md`
|
||
|
||
Implementation slices:
|
||
1. Скрыть или честно заблокировать:
|
||
- `WebSocket`
|
||
- `SOAP`
|
||
- `gRPC streaming`
|
||
- streaming execution modes
|
||
- `elevated/strict` security levels
|
||
в Community.
|
||
2. Привести copy и feature affordances к open-core границе.
|
||
3. Добавить edition-aware explanation в wizard и agents UI.
|
||
|
||
DoD:
|
||
- Community UX не создает ложного ожидания наличия premium functionality;
|
||
- protocol set и security levels совпадают в docs, UI и runtime contracts.
|
||
|
||
Verification:
|
||
- e2e checks for wizard protocol list;
|
||
- manual Community smoke;
|
||
- localized copy review.
|
||
|
||
## Planned
|
||
|
||
### `feat/frontend-commercial-polish`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- закрыть оставшиеся UI/UX дефекты, мешающие коммерческой демонстрации и продажной версии продукта.
|
||
|
||
Main code areas:
|
||
- `apps/ui/js/api-keys.js`
|
||
- `apps/ui/js/agents.js`
|
||
- `apps/ui/js/secrets.js`
|
||
- `apps/ui/js/usage.js`
|
||
- `apps/ui/js/settings.js`
|
||
- `apps/ui/js/workspace-setup.js`
|
||
- `apps/ui/js/auth.js`
|
||
- `apps/ui/css/*`
|
||
- `docs/frontend-roadmap.md`
|
||
|
||
Implementation slices:
|
||
1. Перевести mobile tables в card layouts для:
|
||
- `API Keys`
|
||
- `Secrets`
|
||
- `Usage`
|
||
2. Доделать `Agents` page и modal:
|
||
- объяснение отдельных agent endpoints
|
||
- empty states
|
||
- slug hints
|
||
3. Добить `Settings` and workspace flows:
|
||
- terminology cleanup
|
||
- navigation spacing
|
||
- notifications honesty
|
||
- mobile sticky bug
|
||
4. Довести agent-key UX на `API Keys` page.
|
||
|
||
DoD:
|
||
- mobile UI не требует обязательного горизонтального скролла для primary actions;
|
||
- terminology и product copy согласованы;
|
||
- коммерческая демонстрация проходит без UI contradictions.
|
||
|
||
Verification:
|
||
- targeted Playwright coverage;
|
||
- manual mobile checks at 375px width;
|
||
- EN/RU copy audit.
|
||
|
||
### `feat/open-core-repo-boundary`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- закрепить техническую границу между public Community repo и private commercial delivery.
|
||
|
||
Main code areas:
|
||
- `docs/commercial-boundaries.md`
|
||
- `docs/module-decomposition.md`
|
||
- `docs/development-rules.md`
|
||
- `docs/implementation-plan.md`
|
||
- release scripts / Docker manifests / future packaging files
|
||
|
||
Implementation slices:
|
||
1. Определить extension seams в public code.
|
||
2. Подготовить отдельные delivery manifests для Community.
|
||
3. Убрать из public repo assumptions о размещении private code рядом с Community logic.
|
||
4. Подготовить naming и packaging strategy для private repositories.
|
||
|
||
DoD:
|
||
- можно объяснить, что именно публикуется как OSS, а что уходит в private delivery;
|
||
- Community release path отделен от commercial release path;
|
||
- документация не ссылается на удаленные review files.
|
||
|
||
Verification:
|
||
- docs consistency pass;
|
||
- release checklist review.
|
||
|
||
### `feat/enterprise-access-governance`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- реализовать enterprise access layer вне Community scope.
|
||
|
||
Main code areas:
|
||
- private `enterprise` services and crates
|
||
- public contracts in:
|
||
- `docs/admin-api.md`
|
||
- `docs/agent-auth-model.md`
|
||
- `docs/product-editions.md`
|
||
|
||
Implementation slices:
|
||
1. `SSO`
|
||
2. `2FA`
|
||
3. extended `RBAC`
|
||
4. `audit log`
|
||
5. enterprise admin flows in UI through capability gating
|
||
|
||
DoD:
|
||
- governance features не живут как полумеры в Community;
|
||
- enterprise access model согласован с public contracts.
|
||
|
||
### `feat/cloud-metering-control-plane`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- подготовить hosted-редакцию как отдельный продуктовый контур.
|
||
|
||
Main code areas:
|
||
- private cloud services
|
||
- usage/metering integration points
|
||
- `docs/product-editions.md`
|
||
- `docs/commercial-boundaries.md`
|
||
|
||
Implementation slices:
|
||
1. usage metering by workspace / agent / token;
|
||
2. billing integration;
|
||
3. hosted tenant controls;
|
||
4. cloud operational tooling.
|
||
|
||
DoD:
|
||
- Cloud edition не зависит от ручного учета usage;
|
||
- hosted product surface согласован с feature matrix.
|
||
|
||
### `feat/release-protection-distribution`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- подготовить безопасную поставку Community и коммерческих редакций.
|
||
|
||
Main code areas:
|
||
- CI workflows
|
||
- Dockerfiles
|
||
- deployment manifests
|
||
- release docs
|
||
|
||
Implementation slices:
|
||
1. public GitHub release flow for Community;
|
||
2. private registry flow for Enterprise;
|
||
3. signed artifacts and provenance;
|
||
4. release checklist for edition-specific packaging.
|
||
|
||
DoD:
|
||
- Community публикуется из public repo;
|
||
- Enterprise и Cloud используют private delivery path;
|
||
- коммерческий код не требуется публиковать в open source ради поставки.
|
||
|
||
### `feat/live-authenticated-staging-entry`
|
||
|
||
Status: ready
|
||
|
||
Goal:
|
||
- держать реальный staging/demo контур в состоянии, пригодном для демонстрации и регрессии.
|
||
|
||
Main code areas:
|
||
- `docs/demo-runbook.md`
|
||
- `docs/deploy-and-staging-smoke.md`
|
||
- `docs/authenticated-staging-pass.md`
|
||
- deployment workflows
|
||
|
||
Implementation slices:
|
||
1. актуализировать demo user flow;
|
||
2. прогнать authenticated staging pass;
|
||
3. зафиксировать regressions и manual checks;
|
||
4. синхронизировать deploy docs с реальным окружением.
|
||
|
||
DoD:
|
||
- staging validation не зависит от локальных фикстур;
|
||
- documentation matches deployed behavior;
|
||
- demo flow reproducible on real environment.
|