Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Document session sharing

オープン
#562 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
60/100
issue の種類
ドキュメント
明瞭さ
おおむね明確
活発さ
活発
技術スタック
grpc

調査の方向性

Create 1.x/agents/share-a-session.md (weight 60, placed after Human in the loop), cross-referencing the Session definition in 1.x/about/core-concepts.md. The issue's surface table already lists what to document: the CreateSessionShare/ListSessionShares/RevokeSessionShare RPCs, READ_ONLY/READ_WRITE scopes, ttl vs expiresAt, and the controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL cap. Settle the auth framing (capability model plus the KAGENT_AUTH_MODE insecure caveat) with the team first, then verify the page against a live 1.0 alpha cluster and check off the Done-when list.

索引モデルが issue の本文から書いたものです。

説明

documentation kagent

Session sharing has no page in the 1.x docs. alpha8 added a TTL to it (kagent#2987), which is a field on a page that does not exist.

Surface

Element Detail
RPCs CreateSessionShare, ListSessionShares, RevokeSessionShare
Permissions READ_ONLY (A2A get, list, subscribe), READ_WRITE (also send, cancel)
ttl on create Optional duration, must be positive. Omitted takes the controller cap.
expiresAt on the share Unset means never.
Controller cap controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL, default 0, which leaves shares unbounded. A ttl above the cap is rejected.
Spending a share The X-Share-Token header.

What the API does not announce

A share is a capability, not a grant to a named user. The backend resolves the token to the conversation's owner and answers as though the owner had asked, keeping the caller's own identity only for the record. Anyone holding the link acts with the owner's read or write access.

READ_ONLY is not a security boundary in a default install. KAGENT_AUTH_MODE defaults to insecure, where the caller supplies its own identity in x-user-id. A caller can claim the owner's identity and reach the session without a share token at all. The page must not present READ_ONLY as an access control: it is a scope on what the share link can do, and the boundary exists only under trusted-proxy with a credential-validating proxy in front.

There is no CLI verb. Sharing is gRPC and UI only, so the task is a UI procedure. No page in the 1.x tree currently carries screenshots.

Where it goes

1.x/agents/share-a-session.md, weight 60, after Human in the loop. Open question: whether sharing belongs under agents/ at all, given Session is defined in about/core-concepts.md and nothing else under agents/ is a conversation-level task.

Before starting

  • Settle the auth framing above with the team. It sets the page's whole register and is not a writer's call to make alone.
  • Decide whether the page ships screenshots. If it does, the screenshot harness comes first.

Done when

  • The page states the capability model and the insecure-mode caveat without overclaiming
  • ttl, expiresAt, and sessionShareMaxTTL are documented, including the cap and the rejection
  • Revoking a share is covered
  • Verified against a live cluster at the current 1.0 alpha
主要言語
TypeScript
スター
20
フォーク
66
平均マージ
1日 2時間
マージ済み PR(30日)
49

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

kagent-dev/website のほかの issue

kagent-dev/website の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。