Bundles in-flight ECHODO work with the Coolify deployment configuration: App - New routes: ai, forms, planner, settings (templates/types), teams, doc detail, whiteboard detail - New components: app shell rework (icon-rail, top-header), forms builder/renderer/responses, types manager, objects creation dialog, card primitive, form + overview views - New tRPC routers: favorites, forms, types, workspaces; updates to health and objects routers - Markdown backlog sync (packages/database) + cursor-sync schema/migrations - Schema additions: forms, types, favorites, markdown_backlog, cursor_sync - Initial Drizzle migrations checked in Deployment - docker/docker-compose.coolify.yml: drops bundled Postgres/Redis (uses CT 102 shared services), removes host port mappings, adds Coolify SERVICE_FQDN_* magic vars for web + collab - .env.example rewritten as the full ECHODO/Coolify variable manifest - NextAuth gains an Authentik OIDC provider (gated on env presence) - Root layout injects Umami tracking script when configured; metadata title flipped to ECHODO Security - .gitignore expanded to exclude AGENT-DEPLOY.md, .env.*, secrets/, credentials.*, *.key, *.crt, *.pem, ssh keys Made-with: Cursor
1.2 KiB
1.2 KiB
| kind | slug | title | plan_slug | status | priority | tenant_id | cursor_epic_id | updated_at |
|---|---|---|---|---|---|---|---|---|
| epic | multitenancy | Tenant isolation for backlog and Cursor connections | multitenant-cursor-sync | ready | P0 | global | null | 2026-04-26 |
Epic objective
Ensure every plan, epic, task, markdown path, and Cursor credential set is scoped to a tenant, with authorization enforced on all sync and CRUD paths.
In scope / out of scope
In scope
- Tenant id on all backlog entities and mappings
- Router guards: user ∈ tenant before read/write
- Documentation of isolation guarantees in
docs/Glossary.md
Out of scope
- Billing per tenant
- Cross-tenant reporting
Related tasks
| Task | Link |
|---|---|
| Tenant-scoped Cursor connections | ./Task-tenant-scoped-cursor-connections.md |
Dependencies
- Depends on: existing workspace / membership model in app DB
- Blocks: Cursor sync layer (production)
Acceptance criteria
- Impossible for tenant A’s job to read tenant B’s
plans/prefix or mapping rows (test with two tenants).
Proposed timeline
| Phase | Window | Notes |
|---|---|---|
| Audit | Week 1 | List all routers touching objects/search |
| Enforce | Week 2+ | Add membership checks |