Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Document session sharing

Ouverte
#562 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
60/100
Type d'issue
Documentation
Clarté
Plutôt claire
Activité
Active
Stack technique
grpc

Piste de recherche

Create 1.x/agents/share-a-session.md (weight 60, placed after Human in the loop), cross-referencing the Session definition in 1.x/about/core-concepts.md. The issue's surface table already lists what to document: the CreateSessionShare/ListSessionShares/RevokeSessionShare RPCs, READ_ONLY/READ_WRITE scopes, ttl vs expiresAt, and the controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL cap. Settle the auth framing (capability model plus the KAGENT_AUTH_MODE insecure caveat) with the team first, then verify the page against a live 1.0 alpha cluster and check off the Done-when list.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

documentation kagent

Session sharing has no page in the 1.x docs. alpha8 added a TTL to it (kagent#2987), which is a field on a page that does not exist.

Surface

Element Detail
RPCs CreateSessionShare, ListSessionShares, RevokeSessionShare
Permissions READ_ONLY (A2A get, list, subscribe), READ_WRITE (also send, cancel)
ttl on create Optional duration, must be positive. Omitted takes the controller cap.
expiresAt on the share Unset means never.
Controller cap controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL, default 0, which leaves shares unbounded. A ttl above the cap is rejected.
Spending a share The X-Share-Token header.

What the API does not announce

A share is a capability, not a grant to a named user. The backend resolves the token to the conversation's owner and answers as though the owner had asked, keeping the caller's own identity only for the record. Anyone holding the link acts with the owner's read or write access.

READ_ONLY is not a security boundary in a default install. KAGENT_AUTH_MODE defaults to insecure, where the caller supplies its own identity in x-user-id. A caller can claim the owner's identity and reach the session without a share token at all. The page must not present READ_ONLY as an access control: it is a scope on what the share link can do, and the boundary exists only under trusted-proxy with a credential-validating proxy in front.

There is no CLI verb. Sharing is gRPC and UI only, so the task is a UI procedure. No page in the 1.x tree currently carries screenshots.

Where it goes

1.x/agents/share-a-session.md, weight 60, after Human in the loop. Open question: whether sharing belongs under agents/ at all, given Session is defined in about/core-concepts.md and nothing else under agents/ is a conversation-level task.

Before starting

  • Settle the auth framing above with the team. It sets the page's whole register and is not a writer's call to make alone.
  • Decide whether the page ships screenshots. If it does, the screenshot harness comes first.

Done when

  • The page states the capability model and the insecure-mode caveat without overclaiming
  • ttl, expiresAt, and sessionShareMaxTTL are documented, including the cap and the rejection
  • Revoking a share is covered
  • Verified against a live cluster at the current 1.0 alpha
Langage dominant
TypeScript
Étoiles
20
Forks
66
Merge moyen
1 j 3 h
PR mergées (30 j)
52

Préparer son environnement

Ce projet ne fournit ni conteneur de développement, ni Dockerfile, ni guide de contribution : l'installation est à votre charge. Commencez par son README, et consultez notre guide de la première contribution pour les étapes générales.

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de kagent-dev/website

Toutes les issues de kagent-dev/website

Issues similaires

Plus d'issues TypeScript

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.