diff options
| author | Somhairle H. Marisol <[email protected]> | 2026-09-17 14:32:37 +0800 |
|---|---|---|
| committer | Somhairle H. Marisol <[email protected]> | 2026-09-17 14:32:37 +0800 |
| commit | 5c0ba37eda80d39e6ceca59bb1d5f4942f858995 (patch) | |
| tree | 948723f9cedf7ccb0707fa6ee516bd30fe20fd10 /RELEASE_SCOPE.md | |
| download | strategy-lab-5c0ba37eda80d39e6ceca59bb1d5f4942f858995.tar.gz | |
chore: establish Strategy Lab source baseline (development, not release)
Diffstat (limited to 'RELEASE_SCOPE.md')
| -rw-r--r-- | RELEASE_SCOPE.md | 38 |
1 files changed, 38 insertions, 0 deletions
diff --git a/RELEASE_SCOPE.md b/RELEASE_SCOPE.md new file mode 100644 index 0000000..373d263 --- /dev/null +++ b/RELEASE_SCOPE.md @@ -0,0 +1,38 @@ +# Release scope amendment — supersedes conflicting SPEC.md clauses + +User explicitly authorized renewed full development and deployment after stop. Final target is https://fin.somhairle.bid (the supplied on-host Cloudflare guide confirms .bid; earlier .bin failed public DNS). Parent handles Tunnel edits only after QA. Do NOT touch Cloudflare, hosts, proxy, Docker daemon or unrelated services. Working directory MUST be /home/somhairle/projects/strategy-lab, use absolute file paths and explicit cwd for tool commands. Earlier jobs were interrupted; inspect partial files and continue. + +## Full user and permission model +Deliver real multi-user system; default invitation-based registration so code-running accounts are trusted during POC. No open self-signup in POC. Roles admin and member, explicit active/disabled account state. Object-owner checks apply to every project/draft/version/data request/manifest/run/result/AI conversation. Admin manages users and quotas; admin does NOT automatically access private strategy source or payloads. Admin may inspect aggregate ops/errors safely. Shared public market objects never imply shared project visibility. + +Add API (compatible with prior contract): +- POST /auth/register {invite_token,name,email,password}: consume single-use expiring invitation transactionally; Argon2 password; return user and session. Role assigned by invite/admin, never client role input. +- GET /auth/me user includes role,active; login checks disabled and throttled failed attempts. Secure cookie in production, HttpOnly, SameSite, hashed session storage and expiration. +- PATCH /auth/profile {name}; POST /auth/password {current_password,new_password}: verify current then revoke other sessions. +- GET /auth/sessions returns own sessions sanitized; DELETE /auth/sessions/:id revokes own session. Logout invalidates server token. +- GET /admin/users; PATCH /admin/users/:id {active?,role?,daily_run_limit?,ai_enabled?}; prevent last active admin demotion/disable; disable revokes sessions and blocks jobs/AI. +- POST /admin/invitations {email?,role:'member',expires_hours?} -> {token,expires_at} display token once; hash in DB. GET /admin/invitations sanitized list; DELETE /admin/invitations/:id revoke. +- POST /admin/users/:id/reset-password -> {reset_token,expires_at} single-use short-lived hash; POST /auth/reset-password {token,new_password}; reset revokes sessions. No fake email delivery; UI says admin-issued recovery link. Optional SMTP can be future configured, not prerequisite for honest recovery UI. +- GET /admin/audit => sanitized security audit events (actor/action/target/time/status; no password/key/code). +- AI permission is explicit per account, default admin-only internal POC until upstream third-party service permission. No payments/resale in this release; ledger is metering, not claim real charges. +- quotas enforced transactionally server-side for data requests/run concurrency/model request budget, not merely disabled frontend controls. + +## UI additions +Login/register-by-invite/password-reset routes. Account profile/security page, password change and own session management. Admin-only users/invitations/recovery/audit page. Consistent loading/empty/error states, no hidden dead ends. Allow invite token from URL, but never put passwords in URLs or logs. + +## API/worker contract clarifications +Cache share only exact canonical source/market/asset/symbol/frequency/adjustment/params/normalization version and immutable payload. Store interval coverage; exact duplicate reuse required; overlapping coverage reuse where API/data adapter supports it, limitations documented. New user dataset has own id but references same raw/normalized object. Dataset manifest hash stable content identity independent of request/user IDs and fetch timestamp if data content unchanged. Source revision changes create new objects. Previous runs pin existing objects. +Backend must transform worker relative object paths into immutable stored paths and mount only files selected for that run; prohibit symlinks/path traversal. Data worker and backtest worker differ in network permission. No fake catalog; data endpoint failures visible. Complete natural workflow with chosen instruments and fields, not a hardcoded demo. + +Store strategy source hash, source version, parameters, data manifest hash, engine/dependency versions, execution assumptions and seed where relevant. Re-run original MUST use same source/config/dataset, not current draft. Data warnings acknowledged explicitly. One run worker initially and separate bounded data fetch concurrency, to protect host. + +## Production delivery +Local service should bind loopback:8787 behind existing Tunnel HTTPS. Canonical origin env https://fin.somhairle.bid, secure cookies when set, enforce exact trusted origin for writes (no broad trust of arbitrary X-Forwarded headers). Health public contains no paths/secrets. Frontend built static served same origin. +Backtest isolation is defense-in-depth Docker for trusted invited accounts, not claim hostile public sandbox; no register-without-invite. Cannot mount host secrets, Docker socket, arbitrary paths, or network in user-code runner. CPU/memory/pids/runtime/output limits and cancel/restart cleanup tested. Do not run user code directly on host to pass tests. +Provide production build, install/run script and systemd --user service instructions (parent integrates). Runtime credentials outside repo mode0600, .env.example names only. Respect current service ports. Application startup cannot fail merely because provider API is temporarily unavailable; AI surfaces bounded errors. + +## Context efficiency +OpenCode uses model strategy-go/glm-5.3-flash, model context/input 1,000,000, automatic compaction reserve 744,000 (effective threshold 256,000). Use short build outputs, read relevant files only, keep docs/<area>.md handoff before long pauses. Parent may invoke /session/:id/summarize (same compaction as /compact) around 256K. No broad home scans. Do not install other agents or change model. + +## Evidence +TDD first; independently runnable tests per area. Full real browser check and real data/model call required before completion. No fake data except clearly labeled tests. Primary output must be WORKING CODE, not further plans. |
