docs: lead decision 68, a service account owns the Vikunja bots (sage)
Darkwing's row 38 labels probe on the pinned 2.7.0 image: a bot created from the owner's account reads and attaches every label that account created, in any project (upstream #3592). Bots owned by svc-<business>, an account with no labels and no shares, see only labels on the shared project's tasks. The runbook now creates the bots and mints and revokes their tokens as svc-$BIZ; the owner keeps the project and the shares. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -1196,3 +1196,37 @@ which stay with him. Each item names who decided it and what happened.
|
||||
proposed Sage as PM and Darkwing as Lead (the PRD's CTO role).
|
||||
That is the slice 1 brief's staffing already: PM held by Sage,
|
||||
CTO by Darkwing. No row changes.
|
||||
68. **A per-business service account owns the Vikunja bots
|
||||
(2026-10-08).** Source: Darkwing's row 38 probe record,
|
||||
`agents/darkwing/work/slice1-s3/probes.md` section L, on the
|
||||
pinned 2.7.0 image in a scratch container. Decision 66 made the
|
||||
labels probe a precondition for the estate instance, and it failed
|
||||
with the runbook as written.
|
||||
- In 2.7.0 a bot reads and attaches every label its owning account
|
||||
created, in any project. Upstream treats that as intended
|
||||
(`pkg/models/label_test.go`, #3592). A PM bot created from the
|
||||
owner's account and shared only into mosaic-stack listed the
|
||||
owner's Launchpad, personal and unattached labels, and attached
|
||||
two of them to a mosaic-stack task (201). On the estate instance,
|
||||
bots under Jason's account would see every Launchpad, personal
|
||||
and system label.
|
||||
- Control: the same bot owned by `svc-mosaic-stack`, an account
|
||||
with no labels and no shares, saw only labels on mosaic-stack
|
||||
tasks and got 403 on the others. The project owner can share a
|
||||
bot that another account owns. Only the owning account can mint
|
||||
its token (the owner got 404, code 1005).
|
||||
- Ruling: each business gets a service account `svc-<business>`,
|
||||
not Jason's. It creates that business's five bots and mints and
|
||||
revokes their tokens. It owns no labels, projects or other bots,
|
||||
and nobody shares a project with it. Jason's account still owns
|
||||
the project and makes the shares. The runbook's sections 2 to 5
|
||||
say this now.
|
||||
- S3's broker also attaches only the label ids the business file
|
||||
lists, so a label that later becomes visible can't be attached.
|
||||
This is a second guard and doesn't replace the first.
|
||||
- Still to probe before Jason runs section 3: whether `svc` can
|
||||
revoke a bot's token with `DELETE /tokens/{id}`, as the rotation
|
||||
step now says. Darkwing adds it to the record.
|
||||
- T236 has to provide `svc-mosaic-stack` on the estate instance.
|
||||
Its operator creates it with `vikunja user create`, unless the
|
||||
instance allows registration. Sent to Mos.
|
||||
|
||||
Reference in New Issue
Block a user