ubiquitous-invention/plans/Plan-multitenant-cursor-sync/Epic-multitenancy/Epic-multitenancy.md
Randall Stillwell 663bc77afe feat: ECHODO app shell, Coolify deploy, Authentik + Umami
Bundles in-flight ECHODO work with the Coolify deployment configuration:

App
- New routes: ai, forms, planner, settings (templates/types), teams,
  doc detail, whiteboard detail
- New components: app shell rework (icon-rail, top-header), forms
  builder/renderer/responses, types manager, objects creation dialog,
  card primitive, form + overview views
- New tRPC routers: favorites, forms, types, workspaces; updates to
  health and objects routers
- Markdown backlog sync (packages/database) + cursor-sync schema/migrations
- Schema additions: forms, types, favorites, markdown_backlog, cursor_sync
- Initial Drizzle migrations checked in

Deployment
- docker/docker-compose.coolify.yml: drops bundled Postgres/Redis
  (uses CT 102 shared services), removes host port mappings, adds
  Coolify SERVICE_FQDN_* magic vars for web + collab
- .env.example rewritten as the full ECHODO/Coolify variable manifest
- NextAuth gains an Authentik OIDC provider (gated on env presence)
- Root layout injects Umami tracking script when configured;
  metadata title flipped to ECHODO

Security
- .gitignore expanded to exclude AGENT-DEPLOY.md, .env.*, secrets/,
  credentials.*, *.key, *.crt, *.pem, ssh keys

Made-with: Cursor
2026-04-26 14:34:34 -05:00

50 lines
1.2 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
kind: epic
slug: multitenancy
title: Tenant isolation for backlog and Cursor connections
plan_slug: multitenant-cursor-sync
status: ready
priority: P0
tenant_id: global
cursor_epic_id: null
updated_at: "2026-04-26"
---
# Epic objective
Ensure every **plan, epic, task**, markdown path, and Cursor credential set is **scoped to a tenant**, with authorization enforced on all sync and CRUD paths.
## In scope / out of scope
**In scope**
- Tenant id on all backlog entities and mappings
- Router guards: user ∈ tenant before read/write
- Documentation of isolation guarantees in `docs/Glossary.md`
**Out of scope**
- Billing per tenant
- Cross-tenant reporting
## Related tasks
| Task | Link |
|------|------|
| Tenant-scoped Cursor connections | `./Task-tenant-scoped-cursor-connections.md` |
## Dependencies
- Depends on: existing workspace / membership model in app DB
- Blocks: Cursor sync layer (production)
## Acceptance criteria
- [ ] Impossible for tenant As job to read tenant Bs `plans/` prefix or mapping rows (test with two tenants).
## Proposed timeline
| Phase | Window | Notes |
|-------|--------|-------|
| Audit | Week 1 | List all routers touching objects/search |
| Enforce | Week 2+ | Add membership checks |