Document session sharing
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 60/100
- Tipo de issue
- Documentación
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- grpc
- Área
- documentation, security
Línea de trabajo
Create 1.x/agents/share-a-session.md (weight 60, placed after Human in the loop), cross-referencing the Session definition in 1.x/about/core-concepts.md. The issue's surface table already lists what to document: the CreateSessionShare/ListSessionShares/RevokeSessionShare RPCs, READ_ONLY/READ_WRITE scopes, ttl vs expiresAt, and the controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL cap. Settle the auth framing (capability model plus the KAGENT_AUTH_MODE insecure caveat) with the team first, then verify the page against a live 1.0 alpha cluster and check off the Done-when list.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Session sharing has no page in the 1.x docs. alpha8 added a TTL to it (kagent#2987), which is a field on a page that does not exist.
Surface
| Element | Detail |
|---|---|
| RPCs | CreateSessionShare, ListSessionShares, RevokeSessionShare |
| Permissions | READ_ONLY (A2A get, list, subscribe), READ_WRITE (also send, cancel) |
ttl on create |
Optional duration, must be positive. Omitted takes the controller cap. |
expiresAt on the share |
Unset means never. |
| Controller cap | controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL, default 0, which leaves shares unbounded. A ttl above the cap is rejected. |
| Spending a share | The X-Share-Token header. |
What the API does not announce
A share is a capability, not a grant to a named user. The backend resolves the token to the conversation's owner and answers as though the owner had asked, keeping the caller's own identity only for the record. Anyone holding the link acts with the owner's read or write access.
READ_ONLY is not a security boundary in a default install. KAGENT_AUTH_MODE defaults to insecure, where the caller supplies its own identity in x-user-id. A caller can claim the owner's identity and reach the session without a share token at all. The page must not present READ_ONLY as an access control: it is a scope on what the share link can do, and the boundary exists only under trusted-proxy with a credential-validating proxy in front.
There is no CLI verb. Sharing is gRPC and UI only, so the task is a UI procedure. No page in the 1.x tree currently carries screenshots.
Where it goes
1.x/agents/share-a-session.md, weight 60, after Human in the loop. Open question: whether sharing belongs under agents/ at all, given Session is defined in about/core-concepts.md and nothing else under agents/ is a conversation-level task.
Before starting
- Settle the auth framing above with the team. It sets the page's whole register and is not a writer's call to make alone.
- Decide whether the page ships screenshots. If it does, the screenshot harness comes first.
Done when
- The page states the capability model and the
insecure-mode caveat without overclaiming -
ttl,expiresAt, andsessionShareMaxTTLare documented, including the cap and the rejection - Revoking a share is covered
- Verified against a live cluster at the current 1.0 alpha
- Lenguaje dominante
- TypeScript
- Estrellas
- 20
- Forks
- 66
- Merge medio
- 1 d 3 h
- PR fusionados (30 d)
- 52
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de kagent-dev/website
-
Hold until GA: repoint kagent.dev navigation from 0.x to 1.xPosiblemente ocupada @Rachael-Graham la tomó hace 9 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
kagent-dev/website#521 · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
help wanted
Dificultad 3/5 1-2 días Aptitud para principiantes 72/100
kagent-dev/website#539 ·
Los mantenedores suelen responder en 1 día
-
help wanted
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
kagent-dev/website#538 ·
Los mantenedores suelen responder en 1 día
-
Docs: cover microvm sandbox support for kagent 1.xPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertohelp wanted
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
kagent-dev/website#537 ·
Los mantenedores suelen responder en 1 día
-
Docs: add Codex and Claude Harness examples, and a codex runtime-image conrefPosiblemente ocupada @chinmaychahar la tomó hace 2 días. Abiertohelp wanted
Dificultad 3/5 1-2 días Aptitud para principiantes 65/100
kagent-dev/website#530 · 5 comentarios · 1 asignado ·
Los mantenedores suelen responder en 1 día
Todos los issues de kagent-dev/website
Issues similares
-
Flaky: mongodb-memory-server 'Port already in use' when another process starts a mongod concurrentlyAbiertoarea:testing bug effort:S priority:P2
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 1 día
-
lens:agent lens:process process
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
thebristolsound/birdbrain#1772 ·
Los mantenedores suelen responder en 1 día
-
bug priority:low ready-for-dev
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Automattic/data-liberation-agent#685 ·
Los mantenedores suelen responder en 1 día
-
Business
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
Los mantenedores suelen responder en 1 día