convoy: scope fix-auth-bypass (P0 #1, #2, #4, #5, #6 partial) #2

Closed
varutasu wants to merge 9 commits from convoy/fix-auth-bypass into bootstrap/agent-pipeline-v0.5.0
varutasu commented 2026-05-23 00:19:39 -04:00 (Migrated from github.com)

Summary

  • Conductor output: scopes the first real convoy after the agent-pipeline bootstrap.
  • Closes P0 ship-blockers #1 (admin bypass), #2 (JWT secret fallback), #4 (dev-only endpoints), #5 (CORS *), and the auth-route slice of #6 (rate limiting) from .convoys/ship-readiness.md.
  • Adds zero production code. The Architect is the next role to run — produces briefs under .convoys/fix-auth-bypass/brief-N-*.md.

Base branch is bootstrap/agent-pipeline-v0.5.0, not main, because the L2 role files only exist on the bootstrap branch right now. Will rebase onto main after PR #1 lands.

Convoy + Brief

  • Convoy: .convoys/fix-auth-bypass.md (this PR)
  • Brief: N/A (Conductor produces no briefs; Architect does)
  • Classification: server-only
  • Skip: ia, ux, visual, a11y, design
  • Next role: role-architect

Acceptance criteria

  • One file added: .convoys/fix-auth-bypass.md
  • Frontmatter follows .cursor/agents/role-conductor.md schema
  • Four required sections present: Why / Scope / Roles invoked / Todos
  • Out-of-scope items explicitly listed and routed to their own convoys
  • Hand-off message ready to paste into a new chat for role-architect
  • Analytics event emitted (.convoys/.metrics.jsonl — gitignored)

Test plan

  • This PR ships only a markdown file. CI lint should pass.
  • Validate the convoy file structure against .cursor/agents/role-conductor.md anti-patterns:
    • Single file written ✓
    • No code changes ✓
    • No skip: pr-merge or prod-promote
    • No automatic role invocation (hand-off is by message) ✓

Pipeline gates

  • CI: lint
  • Visual diff — N/A
  • A11y audit — N/A
  • Design-system audit — N/A
  • Reviewer report — light; this is documentation
  • Smoke on staging — N/A

Notes for reviewer

  • The Conductor brought vitest into scope on Brief 6 (provisional), one slot ahead of the proposed adopt-vitest convoy. Rationale: the blast radius of getUserFromRequest plus the JWT helper centralization warrants a safety net. Architect has discretion to push it back out — note the recommendation explicitly.
  • Multitask dispatch is gated by Architect's slice_dependencies:. Until that block exists, all briefs run serial.
  • After landing this convoy, the next two should run in quick succession: drop-public-setup and fix-layout-default-user. Both are trivial; both touch P0 items.

Made with Cursor

<!-- pipeline: convoy=fix-auth-bypass, brief=0 skip: ia, ux, visual, a11y, design --> ## Summary - Conductor output: scopes the first real convoy after the agent-pipeline bootstrap. - Closes P0 ship-blockers **#1 (admin bypass)**, **#2 (JWT secret fallback)**, **#4 (dev-only endpoints)**, **#5 (CORS *)**, and the auth-route slice of **#6 (rate limiting)** from `.convoys/ship-readiness.md`. - Adds zero production code. The Architect is the next role to run — produces briefs under `.convoys/fix-auth-bypass/brief-N-*.md`. **Base branch is `bootstrap/agent-pipeline-v0.5.0`, not `main`**, because the L2 role files only exist on the bootstrap branch right now. Will rebase onto `main` after PR #1 lands. ## Convoy + Brief - Convoy: `.convoys/fix-auth-bypass.md` (this PR) - Brief: N/A (Conductor produces no briefs; Architect does) - Classification: `server-only` - Skip: `ia, ux, visual, a11y, design` - Next role: `role-architect` ## Acceptance criteria - [x] One file added: `.convoys/fix-auth-bypass.md` - [x] Frontmatter follows `.cursor/agents/role-conductor.md` schema - [x] Four required sections present: Why / Scope / Roles invoked / Todos - [x] Out-of-scope items explicitly listed and routed to their own convoys - [x] Hand-off message ready to paste into a new chat for `role-architect` - [x] Analytics event emitted (`.convoys/.metrics.jsonl` — gitignored) ## Test plan - This PR ships only a markdown file. CI lint should pass. - Validate the convoy file structure against `.cursor/agents/role-conductor.md` anti-patterns: - Single file written ✓ - No code changes ✓ - No `skip: pr-merge` or `prod-promote` ✓ - No automatic role invocation (hand-off is by message) ✓ ## Pipeline gates - [ ] CI: lint - [x] Visual diff — N/A - [x] A11y audit — N/A - [x] Design-system audit — N/A - [ ] Reviewer report — light; this is documentation - [x] Smoke on staging — N/A ## Notes for reviewer - The Conductor brought `vitest` into scope on Brief 6 (provisional), one slot ahead of the proposed `adopt-vitest` convoy. Rationale: the blast radius of `getUserFromRequest` plus the JWT helper centralization warrants a safety net. Architect has discretion to push it back out — note the recommendation explicitly. - Multitask dispatch is gated by Architect's `slice_dependencies:`. Until that block exists, all briefs run serial. - After landing this convoy, the next two should run in quick succession: `drop-public-setup` and `fix-layout-default-user`. Both are trivial; both touch P0 items. Made with [Cursor](https://cursor.com)
vercel[bot] commented 2026-05-23 00:19:44 -04:00 (Migrated from github.com)

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
tcg-vault Ready Ready Preview, Comment May 23, 2026 7:58am

Request Review

[vc]: #+RPYTjuX/QjiPQiTnE/382z2rLnx+pl9b1oFc4xf+Vs=:eyJpc01vbm9yZXBvIjp0cnVlLCJ0eXBlIjoiZ2l0aHViIiwicHJvamVjdHMiOlt7Im5hbWUiOiJ0Y2ctdmF1bHQiLCJwcm9qZWN0SWQiOiJwcmpfRjZXOEVvRkd3Y0g3aWVGcnRvRlNlOXdVVkFhNSIsImxpdmVGZWVkYmFjayI6eyJyZXNvbHZlZCI6MCwidW5yZXNvbHZlZCI6MCwidG90YWwiOjAsImxpbmsiOiJ0Y2ctdmF1bHQtZ2l0LWNvbnZveS1maXgtYXV0LTgxZWJmMy1yYW5kYWxsLXN0aWxsd2VsbHMtcHJvamVjdHMudmVyY2VsLmFwcCJ9LCJpbnNwZWN0b3JVcmwiOiJodHRwczovL3ZlcmNlbC5jb20vcmFuZGFsbC1zdGlsbHdlbGxzLXByb2plY3RzL3RjZy12YXVsdC9EVUhpNXV4cEZYZkt5dHc1eFVMaVBXQ0NGNUxrIiwicHJldmlld1VybCI6InRjZy12YXVsdC1naXQtY29udm95LWZpeC1hdXQtODFlYmYzLXJhbmRhbGwtc3RpbGx3ZWxscy1wcm9qZWN0cy52ZXJjZWwuYXBwIiwibmV4dENvbW1pdFN0YXR1cyI6IkRFUExPWUVEIiwicm9vdERpcmVjdG9yeSI6bnVsbH1dLCJyZXF1ZXN0UmV2aWV3VXJsIjoiaHR0cHM6Ly92ZXJjZWwuY29tL3ZlcmNlbC1hZ2VudC9yZXF1ZXN0LXJldmlldz9vd25lcj12YXJ1dGFzdSZyZXBvPXRjZy12YXVsdCZwcj0yIn0= The latest updates on your projects. Learn more about [Vercel for GitHub](https://vercel.link/github-learn-more). | Project | Deployment | Actions | Updated (UTC) | | :--- | :----- | :------ | :------ | | [tcg-vault](https://vercel.com/randall-stillwells-projects/tcg-vault) | ![Ready](https://vercel.com/static/status/ready.svg) [Ready](https://vercel.com/randall-stillwells-projects/tcg-vault/DUHi5uxpFXfKytw5xULiPWCCF5Lk) | [Preview](https://tcg-vault-git-convoy-fix-aut-81ebf3-randall-stillwells-projects.vercel.app), [Comment](https://vercel.live/open-feedback/tcg-vault-git-convoy-fix-aut-81ebf3-randall-stillwells-projects.vercel.app?via=pr-comment-feedback-link) | May 23, 2026 7:58am | <a href="https://vercel.com/vercel-agent/request-review?owner=varutasu&repo=tcg-vault&pr=2" rel="noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://agents-vade-review.vercel.sh/request-review-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://agents-vade-review.vercel.sh/request-review-light.svg"><img src="https://agents-vade-review.vercel.sh/request-review-light.svg" alt="Request Review"></picture></a>

Pull request closed

Sign in to join this conversation.
No description provided.