| #37 |
FTX-37: API key issuance + member namespace provisioning
POST/GET/DELETE /v1/tenants/{id}/api-keys (raw key shown once); member add writes role/permissions/m...
|
closed |
high |
2026-07-23 15:08 |
- |
|
| #36 |
FTX-36: api_keys authn core + auth oracle client
api_keys table (hashed futex_sk_* secrets, UNIQUE key_hash, tenant+principal binding, policy_allowli...
|
closed |
critical |
2026-07-23 15:08 |
- |
|
| #35 |
FTX-35: Migration: delegation_rules
CREATE TABLE IF NOT EXISTS delegation_rules matching models.py + indexes. Fixes unreproducible fresh...
|
closed |
high |
2026-07-23 15:08 |
- |
|
| #34 |
FTX-34: config/db/errors/obs skeleton
app/config.py (all env in one place, one REDIS_URL, prod startup validation), app/db.py, app/errors....
|
closed |
high |
2026-07-23 15:08 |
- |
|
| #33 |
FTX-33: Test DB isolation (prod-wipe guard)
conftest.py hardwired to futex_test; assert dbname endswith _test before ANY truncate (current conft...
|
closed |
critical |
2026-07-23 15:08 |
- |
|
| #32 |
FTX-32: Packaging + pytest config
Add pyproject.toml with pinned deps + [tool.pytest.ini_options] (markers=[e2e], addopts='-m "not e2e...
|
closed |
high |
2026-07-23 15:08 |
- |
|
| #31 |
TEST-1: Contract & Isolation Tests
Write tests mocking Auth, Mail, RunFlow with circuit-open behavior. Prove cross-tenant isolation and...
|
closed |
medium |
2026-07-22 21:59 |
- |
|
| #29 |
SEC-1: Redis Rate Limiting & API Security
Enforce per-tenant and per-key rate limits via Redis. Enforce 1MB max JSON body. Protect Webhooks ag...
|
closed |
medium |
2026-07-22 21:59 |
- |
|
| #28 |
API-7: Audit REST API & Event Logging
Implement /v1/audit read endpoint. Trigger audit events for decision lifecycle, actions, delegations...
|
closed |
medium |
2026-07-22 21:59 |
- |
|
| #27 |
CORE-5: Delegation Resolution Engine
Resolve active delegation rules at task assignment time. Cap chain depth to 1. Skip non_delegable ta...
|
closed |
high |
2026-07-22 21:59 |
- |
|
| #26 |
API-6: Delegation REST API
Implement /v1/delegations CRUD. Require hitl:delegation:manage_self or manage_others. Rules must hav...
|
closed |
high |
2026-07-22 21:59 |
- |
|
| #25 |
CORE-4: Policy Engine - Clearance Profiles
Implement conditional further approval (clearance). Generate clearance tasks on approve, block RunFl...
|
closed |
high |
2026-07-22 21:59 |
- |
|
| #24 |
CORE-3: Policy Engine - Separation of Duties (SoD)
Implement SoD rules: submitter-cannot-act, mutually exclusive principals/roles. Reject task assignme...
|
closed |
high |
2026-07-22 21:59 |
- |
|
| #23 |
CORE-2: Complex Policy Engine - Quorums & Modes
Implement policy evaluation for step completion modes (all_of, any_of, n_of_m). Support parallel ste...
|
closed |
high |
2026-07-22 21:59 |
- |
|
| #22 |
MCP-3: MCP Reviewer Tools
Implement hitl_list_inbox, hitl_get_task, hitl_act_on_task. Require inbox/act permissions. (UB-MCP-4...
|
closed |
high |
2026-07-22 21:59 |
- |
|
| #21 |
MCP-2: MCP Submitter Tools
Implement hitl_list_policies, hitl_get_policy, hitl_request_decision, hitl_get_decision, hitl_cancel...
|
closed |
high |
2026-07-22 21:59 |
- |
|
| #20 |
MCP-1: MCP Server Core & Authentication
Implement /mcp endpoint. Support SSE or stdio (HTTP stream). Enforce Bearer API key authentication i...
|
closed |
high |
2026-07-22 21:59 |
- |
|
| #19 |
CORE-1: Decision Workflow Wiring
When a decision is created, instantiate initial tasks from policy and trigger webhooks.
|
closed |
high |
2026-07-22 21:41 |
- |
|
| #18 |
AUDIT-1: Audit Logs & Quality Check
Ensure all state mutations correctly log to audit_events. Expose /v1/audit API. Final quality checks...
|
closed |
medium |
2026-07-22 21:09 |
- |
|
| #17 |
MCP-2: Reviewer MCP Server
Expose SSE MCP server with tools hitl_list_inbox, hitl_act_on_task.
Development Workflow:
1. Read t...
|
closed |
medium |
2026-07-22 21:09 |
- |
|