Commit graph

1 commit

Author SHA1 Message Date
Randall Stillwell
a8bab93270 convoy: scope fix-auth-bypass (P0 #1, #2, #4, #5, #6 partial)
Conductor output for the first real convoy after the agent-pipeline
bootstrap. Closes P0 ship-blockers #1, #2, #4, #5 and the auth-route
slice of #6 from .convoys/ship-readiness.md.

Classification: server-only
Skip: ia, ux, visual, a11y, design
Next role: role-architect

The convoy is unflagged (auth fixes don't ship behind a feature flag).
Architect produces a slice plan with explicit slice_dependencies so
implementers can /multitask the disjoint briefs (dev-endpoint delete +
CORS tighten + rate-limit wiring) once the central JWT secret helper
lands.

Out of scope here (own convoys):
- P0 #3 default admin creds + README   → drop-public-setup
- P0 #7 Layout default-prop email leak → fix-layout-default-user
- P0 #6 full (search/import/upload)    → add-rate-limiting

Convoy file: .convoys/fix-auth-bypass.md
Analytics: emitted via scripts/log-convoy-event.sh

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 23:27:25 -05:00