Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Document session sharing

未关闭
#562 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
60/100
Issue 类型
文档
描述清晰度
基本清楚
活跃度
活跃
技术栈
grpc

调研方向

Create 1.x/agents/share-a-session.md (weight 60, placed after Human in the loop), cross-referencing the Session definition in 1.x/about/core-concepts.md. The issue's surface table already lists what to document: the CreateSessionShare/ListSessionShares/RevokeSessionShare RPCs, READ_ONLY/READ_WRITE scopes, ttl vs expiresAt, and the controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL cap. Settle the auth framing (capability model plus the KAGENT_AUTH_MODE insecure caveat) with the team first, then verify the page against a live 1.0 alpha cluster and check off the Done-when list.

由索引模型根据 Issue 内容生成。

描述

documentation kagent

Session sharing has no page in the 1.x docs. alpha8 added a TTL to it (kagent#2987), which is a field on a page that does not exist.

Surface

Element Detail
RPCs CreateSessionShare, ListSessionShares, RevokeSessionShare
Permissions READ_ONLY (A2A get, list, subscribe), READ_WRITE (also send, cancel)
ttl on create Optional duration, must be positive. Omitted takes the controller cap.
expiresAt on the share Unset means never.
Controller cap controller.sessionShareMaxTTL / KAGENT_SESSION_SHARE_MAX_TTL, default 0, which leaves shares unbounded. A ttl above the cap is rejected.
Spending a share The X-Share-Token header.

What the API does not announce

A share is a capability, not a grant to a named user. The backend resolves the token to the conversation's owner and answers as though the owner had asked, keeping the caller's own identity only for the record. Anyone holding the link acts with the owner's read or write access.

READ_ONLY is not a security boundary in a default install. KAGENT_AUTH_MODE defaults to insecure, where the caller supplies its own identity in x-user-id. A caller can claim the owner's identity and reach the session without a share token at all. The page must not present READ_ONLY as an access control: it is a scope on what the share link can do, and the boundary exists only under trusted-proxy with a credential-validating proxy in front.

There is no CLI verb. Sharing is gRPC and UI only, so the task is a UI procedure. No page in the 1.x tree currently carries screenshots.

Where it goes

1.x/agents/share-a-session.md, weight 60, after Human in the loop. Open question: whether sharing belongs under agents/ at all, given Session is defined in about/core-concepts.md and nothing else under agents/ is a conversation-level task.

Before starting

  • Settle the auth framing above with the team. It sets the page's whole register and is not a writer's call to make alone.
  • Decide whether the page ships screenshots. If it does, the screenshot harness comes first.

Done when

  • The page states the capability model and the insecure-mode caveat without overclaiming
  • ttl, expiresAt, and sessionShareMaxTTL are documented, including the cap and the rejection
  • Revoking a share is covered
  • Verified against a live cluster at the current 1.0 alpha
主要语言
TypeScript
星标
20
派生
66
平均合并
1 天 3 小时
30 天内合并 PR
52

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

kagent-dev/website 的其他 Issue

查看 kagent-dev/website 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。