Bundles in-flight ECHODO work with the Coolify deployment configuration: App - New routes: ai, forms, planner, settings (templates/types), teams, doc detail, whiteboard detail - New components: app shell rework (icon-rail, top-header), forms builder/renderer/responses, types manager, objects creation dialog, card primitive, form + overview views - New tRPC routers: favorites, forms, types, workspaces; updates to health and objects routers - Markdown backlog sync (packages/database) + cursor-sync schema/migrations - Schema additions: forms, types, favorites, markdown_backlog, cursor_sync - Initial Drizzle migrations checked in Deployment - docker/docker-compose.coolify.yml: drops bundled Postgres/Redis (uses CT 102 shared services), removes host port mappings, adds Coolify SERVICE_FQDN_* magic vars for web + collab - .env.example rewritten as the full ECHODO/Coolify variable manifest - NextAuth gains an Authentik OIDC provider (gated on env presence) - Root layout injects Umami tracking script when configured; metadata title flipped to ECHODO Security - .gitignore expanded to exclude AGENT-DEPLOY.md, .env.*, secrets/, credentials.*, *.key, *.crt, *.pem, ssh keys Made-with: Cursor
1 KiB
1 KiB
| kind | slug | title | plan_slug | epic_slug | status | priority | tenant_id | owner | cursor_todo_id | updated_at |
|---|---|---|---|---|---|---|---|---|---|---|
| task | tenant-scoped-cursor-connections | Store per-tenant Cursor tokens and default sync mode | multitenant-cursor-sync | multitenancy | ready | P1 | global | unassigned | null | 2026-04-26 |
Task summary
Add tenant-level settings: encrypted Cursor token (or OAuth refresh), default markdown_authoritative vs app_authoritative mode from config/CursorSync.md.
Description
Never commit secrets to markdown. Admin UI or env-injected secrets for dev only.
Subtasks
- Settings table or reuse workspace settings JSON
- Rotation path documented
- E2E test with two fake tenants
Owner or assignee
Unassigned
Status
ready
Estimation
L
Acceptance criteria
- Token at rest encrypted or stored in vault integration stub.
- Sync job loads credentials only for the tenant id on the job payload.
Links to related Epic / Plan
- Epic:
./Epic-multitenancy.md - Plan:
../Plan-multitenant-cursor-sync.md