P2: Complete account, admin, AI and background-work CLI ceremony and discovery #843

Open
opened 2026-10-02 13:23:17 +00:00 by kayg · 0 comments
Owner

Research follow-up under #484. Source snapshot: c4a61e8cf090170f35b1bed3350d9de20c83ecd5.

Raw adapters cover account, admin, AI and remote jobs, but calling an operation ID does not finish its credential ceremony.

Evidence:

  • CLI has login/logout/whoami and local Sync commands, but no named account/admin/AI/remote-jobs areas.
  • Account authority changes require a recent assertion, and some operations require a passkey or sign-in flow. A raw challenge call is not complete User parity.
  • MCP/WebMCP admin discovery checks authority; App Passwords remain denied on account/admin routes even for an admin User.
  • Local Sync pairs control the current Installation, not a remote server job. Do not expose its local paths as a remote data action.

Acceptance:

  1. Provide registry-derived discovery for profile/sessions/App Passwords, admin configuration/Users/invites/backups, AI turn history/stop/Undo and remote job state/cancel.
  2. Guide a User through existing browser approval/fresh assertion where required; give non-interactive callers a typed actionable failure.
  3. Preserve scoped Installation credentials, Role/freshness checks and App Password denial. No adapter may mint stronger authority.
  4. Test successful authorized calls and denied member/data-only/read-only/revoked/disabled-surface cases across all surfaces.
  5. Keep local daemon controls separate from server background-work actions and preserve their existing safety guard.

Matrix U1–U7/D1–D3/I1–I2; #484 and #483. This is workflow and verification work; no bypass is asserted.

Full evidence and decisions: docs/research/agent-surfaces.md on branch job/research-surfaces. No runtime change was made by the research job.

Research follow-up under #484. Source snapshot: `c4a61e8cf090170f35b1bed3350d9de20c83ecd5`. Raw adapters cover account, admin, AI and remote jobs, but calling an operation ID does not finish its credential ceremony. Evidence: - CLI has login/logout/whoami and local Sync commands, but no named account/admin/AI/remote-jobs areas. - Account authority changes require a recent assertion, and some operations require a passkey or sign-in flow. A raw challenge call is not complete User parity. - MCP/WebMCP admin discovery checks authority; App Passwords remain denied on account/admin routes even for an admin User. - Local Sync pairs control the current Installation, not a remote server job. Do not expose its local paths as a remote data action. Acceptance: 1. Provide registry-derived discovery for profile/sessions/App Passwords, admin configuration/Users/invites/backups, AI turn history/stop/Undo and remote job state/cancel. 2. Guide a User through existing browser approval/fresh assertion where required; give non-interactive callers a typed actionable failure. 3. Preserve scoped Installation credentials, Role/freshness checks and App Password denial. No adapter may mint stronger authority. 4. Test successful authorized calls and denied member/data-only/read-only/revoked/disabled-surface cases across all surfaces. 5. Keep local daemon controls separate from server background-work actions and preserve their existing safety guard. Matrix U1–U7/D1–D3/I1–I2; #484 and #483. This is workflow and verification work; no bypass is asserted. Full evidence and decisions: `docs/research/agent-surfaces.md` on branch `job/research-surfaces`. No runtime change was made by the research job.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#843
No description provided.