Document session sharing
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 60/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- grpc
- Lĩnh vực
- documentation, security
Hướng nghiên cứu
Create 1.x/agents/share-a-session.md (weight 60, placed after Human in the loop), cross-referencing the Session definition in 1.x/about/core-concepts.md. The issue's surface table already lists what to document: the CreateSessionShare/ListSessionShares/RevokeSessionShare RPCs, READ_ONLY/READ_WRITE scopes, ttl vs expiresAt, and the controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL cap. Settle the auth framing (capability model plus the KAGENT_AUTH_MODE insecure caveat) with the team first, then verify the page against a live 1.0 alpha cluster and check off the Done-when list.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Session sharing has no page in the 1.x docs. alpha8 added a TTL to it (kagent#2987), which is a field on a page that does not exist.
Surface
| Element | Detail |
|---|---|
| RPCs | CreateSessionShare, ListSessionShares, RevokeSessionShare |
| Permissions | READ_ONLY (A2A get, list, subscribe), READ_WRITE (also send, cancel) |
ttl on create |
Optional duration, must be positive. Omitted takes the controller cap. |
expiresAt on the share |
Unset means never. |
| Controller cap | controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL, default 0, which leaves shares unbounded. A ttl above the cap is rejected. |
| Spending a share | The X-Share-Token header. |
What the API does not announce
A share is a capability, not a grant to a named user. The backend resolves the token to the conversation's owner and answers as though the owner had asked, keeping the caller's own identity only for the record. Anyone holding the link acts with the owner's read or write access.
READ_ONLY is not a security boundary in a default install. KAGENT_AUTH_MODE defaults to insecure, where the caller supplies its own identity in x-user-id. A caller can claim the owner's identity and reach the session without a share token at all. The page must not present READ_ONLY as an access control: it is a scope on what the share link can do, and the boundary exists only under trusted-proxy with a credential-validating proxy in front.
There is no CLI verb. Sharing is gRPC and UI only, so the task is a UI procedure. No page in the 1.x tree currently carries screenshots.
Where it goes
1.x/agents/share-a-session.md, weight 60, after Human in the loop. Open question: whether sharing belongs under agents/ at all, given Session is defined in about/core-concepts.md and nothing else under agents/ is a conversation-level task.
Before starting
- Settle the auth framing above with the team. It sets the page's whole register and is not a writer's call to make alone.
- Decide whether the page ships screenshots. If it does, the screenshot harness comes first.
Done when
- The page states the capability model and the
insecure-mode caveat without overclaiming -
ttl,expiresAt, andsessionShareMaxTTLare documented, including the cap and the rejection - Revoking a share is covered
- Verified against a live cluster at the current 1.0 alpha
- Ngôn ngữ chính
- TypeScript
- Star
- 20
- Fork
- 66
- Merge trung bình
- 1 ngày 3 giờ
- Pull request đã merge (30 ngày)
- 52
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của kagent-dev/website
-
Hold until GA: repoint kagent.dev navigation from 0.x to 1.xCó thể đã có người làm @Rachael-Graham đã nhận 10 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
kagent-dev/website#521 · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
help wanted
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 72/100
kagent-dev/website#539 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
help wanted
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
kagent-dev/website#538 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Docs: cover microvm sandbox support for kagent 1.xCó thể đã có người làm @boxcee-interview đã nhận 1 ngày trước. Đang mởhelp wanted
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
kagent-dev/website#537 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Docs: add Codex and Claude Harness examples, and a codex runtime-image conrefCó thể đã có người làm @chinmaychahar đã nhận 3 ngày trước. Đang mởhelp wanted
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 65/100
kagent-dev/website#530 · 7 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của kagent-dev/website
Issue tương tự
-
[Feature]: [P3] engine-rs: the package source hash should ignore line endings and untracked filesĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
maniator/verticopolis#880 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
siyuan-note/siyuan#20353 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
black-forest-labs/skills#17 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Albert-Weasker/niubigeo#168 ·
Maintainer thường phản hồi trong vòng 1 ngày