Commit graph

7 commits

Author SHA1 Message Date
Randall Stillwell
dab939bcd5 feat(mcp): agent-pipeline bridge — 6 lifecycle tools + convoy_events + L1/L3 scaffolding
Implements the Phase 2a Echodo bridge described in agent-pipeline's
v0.4 plan (.cursor/plans/pipeline_v0.4_design_+_echodo_54a3bdb7). Echodo
becomes the projection layer over the local .convoys/ tree; local files
remain source of truth per the local-first contract.

MCP lifecycle tools (apps/mcp-server/src/tools/):
- create-convoy.ts: registers create_convoy. Creates a Drizzle `project`
  object with status="draft" + appends initial "## Status log" to the
  description. Takes workspace_slug + slug + title + classification +
  skip_flags + success_metric + idea_markdown + repo.
- create-brief.ts: registers create_brief. Creates a `task` child of the
  convoy project. Takes convoyId + briefNumber + title + files_allowlist
  + depends_on + acceptance_criteria + brief_markdown.
- transition-convoy-status.ts: registers transition_convoy_status. Enforces
  the 9-status state machine from plan §7.3 with valid transitions +
  actor-permission gates. Appends an audit entry to the description's
  ## Status log per transition.
- log-convoy-event.ts: registers log_convoy_event. Inserts events into the
  new convoy_events table (one row per role hand-off, with classification,
  skip-flags, duration, stack-class, outcome, multitask-group metadata).
- query-manifest-status.ts: registers query_manifest_status (stub —
  depends on the Phase 4 pipeline_drift_reports table; documented).
- reconcile-from-files.ts: registers reconcile_from_files implementing the
  local-first recovery path. Reads .convoys/.pending-mcp-sync.jsonl from
  the given repoPath, replays queued log_convoy_event + transition_convoy_status
  calls, updates the outbox file on success/failure. Resolves the SPOF risk:
  failed MCP calls during offline windows reconcile when the bridge returns.

Database (packages/database/):
- src/schema/convoy_events.ts: new Drizzle schema. Columns: id, workspaceId,
  convoyId, convoySlug, role, brief, classification, skipFlags, durationS,
  stackClass, repo, outcome, multitaskGroup, metadata, ts. 4 indexes for
  per-workspace + per-convoy + role-filtered reads.
- src/schema/index.ts: re-exports the new table.
- migrations/0010_wandering_the_professor.sql + meta snapshot: generated
  via drizzle-kit generate. Pure-additive (CREATE TABLE + indexes + FKs).
- package.json: db:migrate / db:push / db:studio now use node --env-file
  to load ../../.env (consistent with the existing mcp-server tsx pattern).
  db:generate stays as-is (offline operation, no env needed).

L1 + L3 agent-pipeline scaffolding installed per
agent-pipeline/skills/bootstrap-agent-context v0.5.0:
- .agent-context-manifest.yml: tracks 17 artifacts at pipeline version
  0.5.0 with sha256 hashes. 4 artifacts flagged customized:true (no-go-zones,
  CODEOWNERS, pr-health-rollup.yml, echodo.config.json) — adapted from
  templates for Echodo's monorepo + Drizzle + Coolify + workspace_slug.
- .convoys/README.md: explains convoy file convention.
- .cursor/agents/echodo.config.json: workspace_slug=convoys-tasks (the
  workspace created in Echodo UI). Fallback policy: local-only.
- .cursor/rules/no-go-zones.mdc: adapted for Drizzle migrations, Coolify
  deploy infra, mcp-server boundaries.
- .github/CODEOWNERS: @rstillw as sole maintainer; targeted rules for
  apps/, packages/, auth, deploy infra, DB schema, MCP server, agent
  context.
- .github/PULL_REQUEST_TEMPLATE.md: pipeline PR template.
- .github/workflows/agent-context-drift.yml: drift monitor against upstream
  agent-pipeline.
- .github/workflows/pr-health-rollup.yml: adapted for tasks' pnpm monorepo
  + Coolify deploy (no per-PR preview by default).
- scripts/log-convoy-event.sh: convoy event logger shim.
- scripts/wt.sh: worktree helper stub (deprecated — points at Cursor 3.2
  native worktrees).
- .gitignore: excludes .convoys/.metrics.jsonl + .convoys/.pending-mcp-sync.jsonl
  (local agent analytics + MCP outbox).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 20:59:45 -05:00
Randall Stillwell
56b697b81c feat(markdown-backlog): close the sync loop with DB → frontmatter export
Until now the markdown importer was one-way (plans/*.md → DB). Any
agent-driven status flip via claim_task / complete_task would be
clobbered on the next importer sweep. This change closes the loop: the
DB now projects status, priority, agent_prompt, and updated_at back
into the file's frontmatter, preserving body bytes, key order, and
every other frontmatter key.

New: packages/database/src/markdown-backlog/export.ts
  - `rewriteFrontmatter()` — pure function, covered by 10 Vitest cases
    (round-trip identity, status flip, priority flip, agent_prompt
    null/block-scalar/single-line variants, body preservation,
    trailing-newline preservation, idempotent re-application).
  - `exportBacklogItemToMarkdown()` — DB-loading wrapper with atomic
    write (tmp + rename) and tenant fencing. Returns a structured
    result so callers can surface what happened in their response.

Wired into:
  - `claim_task` MCP tool — exports on the ready → in_progress flip.
  - `complete_task` MCP tool — exports on any finalStatus transition.
  - `backlog.updateWorkflowPrompt` tRPC mutation — exports on prompt
    edits made through the app UI.

Robust repo-root resolution (`apps/{mcp-server,web}/src/lib/repo-root.ts`,
plus a copy in `import-markdown-backlog.ts`): walk up from the source
file looking for `pnpm-workspace.yaml`, falling back to env var or cwd.
This fixes a class of bug where `pnpm --filter <pkg>` cd's into the
package directory and breaks naive cwd-based path resolution — the
importer was deleting all 44 rows during smoke testing before this fix
because it found zero files in `packages/database/plans/`.

`config/CursorSync.md`: documents the new two-way contract, the
DB-wins-on-allow-list conflict policy, and the
MARKDOWN_BACKLOG_REPO_ROOT=off escape hatch for production deployments
where `plans/` isn't checked out.

Smoke verified end-to-end against the homelab DB: claim flips file
status to in_progress, complete flips it back to ready, importer
round-trips with stable content_hash (true no-op), agent identity
preserved throughout.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-03 10:21:22 -05:00
Randall Stillwell
fc2235a346 feat(agent-runs): capture client + model identity on claim/complete
Adds level-B agent attribution: every MCP tool call can identify itself
with a `client` (e.g. cursor-ide, codex, echodo-orchestrator) and `model`
(e.g. claude-4.6-sonnet) string. Both optional, both stored in
agent_runs.metadata as JSONB so the schema doesn't move.

- claim_task: new optional `client` + `model` args. Written into the
  inserted agent_runs row's metadata, and mirrored into the audit log
  entry. On idempotent re-claim, incoming values are merged into
  existing metadata (existing keys override only when explicit), so a
  mid-session model switch updates attribution without losing earlier
  context.
- complete_task: same optional args, with merge-on-close semantics —
  late-bound values override the earlier claim's values so the run row
  reflects whichever model actually closed the session. Audit row also
  carries the merged identity.
- /settings/runs UI: stack the client/model under the actor name in the
  table so attribution is visible at a glance without adding a column.

Smoke-tested: claim with {cursor-ide, claude-4.6-sonnet} then complete
with only model={claude-4.6-sonnet-medium-thinking} yields final
metadata {client: cursor-ide, model: claude-4.6-sonnet-medium-thinking}
on both the run row and the task.completed audit entry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-03 10:11:35 -05:00
Randall Stillwell
b2aff2045b feat(mcp): claim_task tool + register claim/complete pair
Pairs with the parallel complete_task commit. claim_task opens an
agent_runs row, flips status to in_progress only when it's safe
(ready/draft → in_progress, never overwriting a deliberate
blocked/done/in_progress), and returns the resolved workflow prompt
+ source level. Idempotent re-claim by the same actor returns the
existing run with reused=true and refreshes notes only — started_at
is sacred. Different-actor re-claim errors with ALREADY_CLAIMED
naming the existing actor and run id.

Tenancy fence: if the backlog item exists but in a different workspace
than the resolved handle, we refuse with "doesn't belong to workspace"
rather than 404. Prevents cross-tenant existence fishing.

All three writes (run insert + status flip + audit insert) happen in
one db.transaction() so a partial claim is unreachable.

tools/index.ts now registers both claim_task and complete_task.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-02 22:23:05 -05:00
Randall Stillwell
93b6398c76 feat(mcp): complete_task tool — close agent_runs row + finalize status
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-02 22:21:26 -05:00
Randall Stillwell
c582d621ce multi-tenancy: promote workspaces to top-level table
Block A of the EchoDo plan. Workspaces used to live as `objects(type='workspace')`,
which made it impossible to put a real RLS-friendly tenant boundary on the schema
or to give each workspace a stable URL slug. This commit:

- Adds a top-level `workspaces` table (slug unique, owner FK, plan_tier hook).
- Migrates the 8 anchor tables (objects, workspace_members, object_type_defs,
  property_definitions, templates, forms, markdown_backlog_items,
  cursor_sync_mappings) to FK into `workspaces.id` instead of `objects.id`,
  with a hand-augmented data-copy migration that preserves IDs and slug-collision-
  proofs on backfill.
- Introduces a `workspaceProcedure` tRPC middleware + `resolveWorkspace` helper
  that take a UUID-or-slug `workspace` handle and expose `ctx.workspace`. All
  tenant-scoped routers (objects, types, properties, templates, forms, search,
  ai, relations, favorites) now flow through it.
- Updates the web app to pass `workspace` slugs from the URL (or store) instead
  of the old `workspaceId`, including a workspace-sync layer that rewrites
  /<UUID>/... links to /<slug>/...
- Updates the MCP tools (list_objects, create_object, search_objects) and the
  workspace://{handle}/tree resource to accept either a slug or UUID so existing
  agents keep working.
- Adds a Create Workspace dialog and a Workspace Settings page (rename + slug
  rename with redirect, owner-only archive).

Verified locally against a fresh Postgres: migration applies cleanly, slug
uniqueness holds, tenant data is isolated by workspace_id, slug↔UUID resolution
works in both directions, and ON DELETE CASCADE cleans up child rows in the
correct workspace only.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-06 23:02:55 -05:00
Randall Stillwell
a508ece6e7 feat: Full project management application scaffold
Complete architecture for a ClickUp/Notion/Miro-class project management app:

- Turborepo monorepo with Next.js 15, TypeScript, PostgreSQL (Drizzle ORM)
- Object-centered database schema (everything is an Object: tasks, projects, docs, whiteboards)
- NextAuth v5 authentication with credentials + OAuth providers
- tRPC v11 API layer with full CRUD for objects, properties, relations, templates, search
- Three-panel UI: collapsible sidebar, center content area, push-in right panel
- Purple/teal theme with light/dark mode via Shadcn/ui + Tailwind CSS
- Multiple views: List, Kanban board (dnd-kit), Table (spreadsheet), Embedded iframe
- TipTap rich text editor with slash commands, custom blocks (callout, toggle, mention, embed, divider), AI block
- Real-time collaboration via Yjs + Hocuspocus with presence/cursors
- tldraw whiteboard with custom shape cards (task, document, project)
- MCP server exposing all app data/tools for AI agents
- AI chat panel, editor AI slash commands, Cmd+K command palette
- Template system with built-in templates (Bug Report, Meeting Notes, Sprint)
- Full-text search with result highlighting
- Docker Compose for full-stack deployment (web + collab + postgres + redis)

Made-with: Cursor
2026-03-26 22:39:16 -05:00