ubiquitous-invention/plans/Plan-multitenant-cursor-sync/Epic-multitenancy/Task-tenant-scoped-cursor-connections.md
Randall Stillwell 663bc77afe feat: ECHODO app shell, Coolify deploy, Authentik + Umami
Bundles in-flight ECHODO work with the Coolify deployment configuration:

App
- New routes: ai, forms, planner, settings (templates/types), teams,
  doc detail, whiteboard detail
- New components: app shell rework (icon-rail, top-header), forms
  builder/renderer/responses, types manager, objects creation dialog,
  card primitive, form + overview views
- New tRPC routers: favorites, forms, types, workspaces; updates to
  health and objects routers
- Markdown backlog sync (packages/database) + cursor-sync schema/migrations
- Schema additions: forms, types, favorites, markdown_backlog, cursor_sync
- Initial Drizzle migrations checked in

Deployment
- docker/docker-compose.coolify.yml: drops bundled Postgres/Redis
  (uses CT 102 shared services), removes host port mappings, adds
  Coolify SERVICE_FQDN_* magic vars for web + collab
- .env.example rewritten as the full ECHODO/Coolify variable manifest
- NextAuth gains an Authentik OIDC provider (gated on env presence)
- Root layout injects Umami tracking script when configured;
  metadata title flipped to ECHODO

Security
- .gitignore expanded to exclude AGENT-DEPLOY.md, .env.*, secrets/,
  credentials.*, *.key, *.crt, *.pem, ssh keys

Made-with: Cursor
2026-04-26 14:34:34 -05:00

49 lines
1 KiB
Markdown

---
kind: task
slug: tenant-scoped-cursor-connections
title: Store per-tenant Cursor tokens and default sync mode
plan_slug: multitenant-cursor-sync
epic_slug: multitenancy
status: ready
priority: P1
tenant_id: global
owner: unassigned
cursor_todo_id: null
updated_at: "2026-04-26"
---
# Task summary
Add tenant-level settings: **encrypted** Cursor token (or OAuth refresh), default `markdown_authoritative` vs `app_authoritative` mode from `config/CursorSync.md`.
## Description
Never commit secrets to markdown. Admin UI or env-injected secrets for dev only.
## Subtasks
- [ ] Settings table or reuse workspace settings JSON
- [ ] Rotation path documented
- [ ] E2E test with two fake tenants
## Owner or assignee
Unassigned
## Status
ready
## Estimation
L
## Acceptance criteria
- [ ] Token at rest encrypted or stored in vault integration stub.
- [ ] Sync job loads credentials only for the tenant id on the job payload.
## Links to related Epic / Plan
- Epic: `./Epic-multitenancy.md`
- Plan: `../Plan-multitenant-cursor-sync.md`