Document session sharing
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 60/100
- Type d'issue
- Documentation
- Clarté
- Plutôt claire
- Activité
- Active
- Stack technique
- grpc
- Domaine
- documentation, security
Piste de recherche
Create 1.x/agents/share-a-session.md (weight 60, placed after Human in the loop), cross-referencing the Session definition in 1.x/about/core-concepts.md. The issue's surface table already lists what to document: the CreateSessionShare/ListSessionShares/RevokeSessionShare RPCs, READ_ONLY/READ_WRITE scopes, ttl vs expiresAt, and the controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL cap. Settle the auth framing (capability model plus the KAGENT_AUTH_MODE insecure caveat) with the team first, then verify the page against a live 1.0 alpha cluster and check off the Done-when list.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Session sharing has no page in the 1.x docs. alpha8 added a TTL to it (kagent#2987), which is a field on a page that does not exist.
Surface
| Element | Detail |
|---|---|
| RPCs | CreateSessionShare, ListSessionShares, RevokeSessionShare |
| Permissions | READ_ONLY (A2A get, list, subscribe), READ_WRITE (also send, cancel) |
ttl on create |
Optional duration, must be positive. Omitted takes the controller cap. |
expiresAt on the share |
Unset means never. |
| Controller cap | controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL, default 0, which leaves shares unbounded. A ttl above the cap is rejected. |
| Spending a share | The X-Share-Token header. |
What the API does not announce
A share is a capability, not a grant to a named user. The backend resolves the token to the conversation's owner and answers as though the owner had asked, keeping the caller's own identity only for the record. Anyone holding the link acts with the owner's read or write access.
READ_ONLY is not a security boundary in a default install. KAGENT_AUTH_MODE defaults to insecure, where the caller supplies its own identity in x-user-id. A caller can claim the owner's identity and reach the session without a share token at all. The page must not present READ_ONLY as an access control: it is a scope on what the share link can do, and the boundary exists only under trusted-proxy with a credential-validating proxy in front.
There is no CLI verb. Sharing is gRPC and UI only, so the task is a UI procedure. No page in the 1.x tree currently carries screenshots.
Where it goes
1.x/agents/share-a-session.md, weight 60, after Human in the loop. Open question: whether sharing belongs under agents/ at all, given Session is defined in about/core-concepts.md and nothing else under agents/ is a conversation-level task.
Before starting
- Settle the auth framing above with the team. It sets the page's whole register and is not a writer's call to make alone.
- Decide whether the page ships screenshots. If it does, the screenshot harness comes first.
Done when
- The page states the capability model and the
insecure-mode caveat without overclaiming -
ttl,expiresAt, andsessionShareMaxTTLare documented, including the cap and the rejection - Revoking a share is covered
- Verified against a live cluster at the current 1.0 alpha
- Langage dominant
- TypeScript
- Étoiles
- 20
- Forks
- 66
- Merge moyen
- 1 j 3 h
- PR mergées (30 j)
- 52
Préparer son environnement
Ce projet ne fournit ni conteneur de développement, ni Dockerfile, ni guide de contribution : l'installation est à votre charge. Commencez par son README, et consultez notre guide de la première contribution pour les étapes générales.
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de kagent-dev/website
-
Hold until GA: repoint kagent.dev navigation from 0.x to 1.xPeut-être pris @Rachael-Graham l’a pris il y a 9 jours. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
kagent-dev/website#521 · 1 personne assignée ·
Les mainteneurs répondent en général sous 1 jour
-
help wanted
Difficulté 3/5 1-2 jours Accessibilité débutants 72/100
kagent-dev/website#539 ·
Les mainteneurs répondent en général sous 1 jour
-
help wanted
Difficulté 4/5 3-5 jours Accessibilité débutants 45/100
kagent-dev/website#538 ·
Les mainteneurs répondent en général sous 1 jour
-
Docs: cover microvm sandbox support for kagent 1.xPeut-être pris Une pull request liée à cette issue est ouverte ou déjà fusionnée. Ouvertehelp wanted
Difficulté 4/5 3-5 jours Accessibilité débutants 45/100
kagent-dev/website#537 ·
Les mainteneurs répondent en général sous 1 jour
-
Docs: add Codex and Claude Harness examples, and a codex runtime-image conrefPeut-être pris @chinmaychahar l’a pris il y a 2 jours. Ouvertehelp wanted
Difficulté 3/5 1-2 jours Accessibilité débutants 65/100
kagent-dev/website#530 · 5 commentaires · 1 personne assignée ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de kagent-dev/website
Issues similaires
-
First unknown-user login after boot is one scrypt run slower than a real user's wrong passwordOuvertearea: backend bug priority: low
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
snapotter-hq/SnapOtter#2254 ·
Les mainteneurs répondent en général sous 1 jour
-
bug ticket
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
cratestack/cratestack#1154 ·
Les mainteneurs répondent en général sous 1 jour
-
server 消息处理器 cmd 分支补显式错误回报——竞态非法命令现走未处理拒绝Peut-être pris @openaddr l’a pris aujourd’hui. Ouverteready-for-agent refactor wayfinder:task
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
openaddr/dafung-web#428 ·
Les mainteneurs répondent en général sous 1 jour
-
Flaky: mongodb-memory-server 'Port already in use' when another process starts a mongod concurrentlyOuvertearea:testing bug effort:S priority:P2
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
Les mainteneurs répondent en général sous 1 jour
-
lens:agent lens:process process
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
thebristolsound/birdbrain#1772 ·
Les mainteneurs répondent en général sous 1 jour