| #100 |
FTX-100: last_used_at is never written — the API reports a permanently-null field operators use to triage keys
EARS SPEC:
- When an API key successfully authenticates a request, Futex shall record the time of us...
|
closed |
medium |
2026-07-31 18:29 |
- |
|
| #88 |
FTX-88: Restyle landing page with Rodmena brand theme
EARS SPEC:\n- LX-1: The Futex landing page shall use the Rodmena design system: dark theme with viol...
|
closed |
medium |
2026-07-28 21:41 |
- |
|
| #83 |
FTX-83: Repo docs — README + docs/ (architecture, sequence, flow) + CONTRIBUTING
EARS SPEC:
- The repository shall provide a short, effective README.md that states what Futex is, li...
|
closed |
medium |
2026-07-25 13:24 |
- |
|
| #79 |
FTX-79: Retention worker (P2)
Daily via Redis SET NX marker; terminal decisions past RETENTION_DAYS=365 (tenant override clamped >...
|
closed |
medium |
2026-07-23 15:08 |
- |
|
| #78 |
FTX-78: DLQ admin APIs (P2)
GET /v1/webhooks/deliveries?state= , GET .../{id}, POST .../{id}/requeue (atomic UPDATE WHERE state=...
|
closed |
medium |
2026-07-23 15:08 |
- |
|
| #75 |
FTX-75: Richer Action Web (P2)
review.html branches per snapshot: request_changes reason+change-request rows, amend inputs from all...
|
open |
medium |
2026-07-23 15:08 |
- |
|
| #74 |
FTX-74: escalate + delegate_task actions (P2)
domain/escalation.py execute_escalation_step shared by SLA worker + escalate action (escalated<->in_...
|
closed |
medium |
2026-07-23 15:08 |
- |
|
| #73 |
FTX-73: amend_and_approve (P2)
Policy amendments{allowed,fields[json-pointers],schema}; validate allowlist + resulting doc (jsonsch...
|
closed |
medium |
2026-07-23 15:08 |
- |
|
| #64 |
FTX-64: Review page conformance
UB-AW-4 fields (tenant name, title, step+policy version, expiry/SLA, submitter, proposed_action, con...
|
open |
medium |
2026-07-23 15:08 |
- |
|
| #61 |
FTX-61: Audit coverage sweep
Every UB-AUD-2 event type written: decision lifecycle, actions, delegation changes, escalation hops,...
|
closed |
medium |
2026-07-23 15:08 |
- |
|
| #60 |
FTX-60: /readyz + Prometheus metrics
/readyz probes DB+Redis+circuit states (UB-REST-1); /metrics: request rate/errors/queue depths/webho...
|
closed |
medium |
2026-07-23 15:08 |
- |
|
| #59 |
FTX-59: Cursor pagination + audit filters + missing routes
Cursor pagination default 25 max 100 (UB-API-7) on inbox/audit/policies/delegations/webhooks; /v1/au...
|
closed |
medium |
2026-07-23 15:08 |
- |
|
| #31 |
TEST-1: Contract & Isolation Tests
Write tests mocking Auth, Mail, RunFlow with circuit-open behavior. Prove cross-tenant isolation and...
|
closed |
medium |
2026-07-22 21:59 |
- |
|
| #30 |
INT-1: RunFlow Binding Sync
Implement /v1/runflow/bindings CRUD. Map stage completions to RunFlow node_ref. Call RunFlow approve...
|
wont-do |
medium |
2026-07-22 21:59 |
- |
|
| #29 |
SEC-1: Redis Rate Limiting & API Security
Enforce per-tenant and per-key rate limits via Redis. Enforce 1MB max JSON body. Protect Webhooks ag...
|
closed |
medium |
2026-07-22 21:59 |
- |
|
| #28 |
API-7: Audit REST API & Event Logging
Implement /v1/audit read endpoint. Trigger audit events for decision lifecycle, actions, delegations...
|
closed |
medium |
2026-07-22 21:59 |
- |
|
| #18 |
AUDIT-1: Audit Logs & Quality Check
Ensure all state mutations correctly log to audit_events. Expose /v1/audit API. Final quality checks...
|
closed |
medium |
2026-07-22 21:09 |
- |
|
| #17 |
MCP-2: Reviewer MCP Server
Expose SSE MCP server with tools hitl_list_inbox, hitl_act_on_task.
Development Workflow:
1. Read t...
|
closed |
medium |
2026-07-22 21:09 |
- |
|
| #16 |
MCP-1: Submitter MCP Server
Expose SSE MCP server with tools hitl_request_decision, hitl_list_policies.
Development Workflow:
1...
|
closed |
medium |
2026-07-22 21:09 |
- |
|
| #15 |
RUNFLOW-1: RunFlow Adapter
Implement RunFlow bindings to call RunFlow approve/reject upon Decision terminal state.
Development...
|
wont-do |
medium |
2026-07-22 21:09 |
- |
|