Commit graph

8 commits

Author SHA1 Message Date
5d311d900a Remediate Fable round-2: BLOCK-1 credential mechanism + residual fixes
- BLOCK-1: invert the token-layer trifecta layering — per-app-client AllowedOAuthScopes
  is the PRIMARY vendor-supported boundary (Cognito won't issue out-of-tier scopes
  regardless of group union); pre-token suppression is a fail-closed backstop; the
  aud/authorizer mechanism is flagged unverified-load-bearing and added to the §6 verify
  gate (#8); fix the design.md §2.3 misattribution + add the amendment to §4.
- FIX-1: §1f notion-sync dual-feeds via S3 (was 'repointed instead of').
- FIX-2: split Phase 0a exit gate into fatal vs decision-input (Testing-Center identity).
- FIX-3: remove stale 'boundary stays in infrastructure' phrasing (server is the boundary).
- FIX-4: bound parallel-run double-spend (G9 + Phases 1-3 time-box).
- FIX-5: specify minimal throwaway 0a kit + Slack-plan dependency.
- FIX-6: remove dangling (O3); D3 recorded as accepted.
- NITs: severity arithmetic, Ops welcome no longer oversells tasks, wrong-audience alarm
  named, flip-point clarified. Q1 fallback scope + Q2 freshness-bound documented.
2026-06-26 12:45:06 -04:00
04322f6cb8 Fold in cross_reviewer (GPT-4.1) auth/trifecta findings
Cross-family review caught defense-in-depth gaps:
- CR-1: validate aud at edge AND server-side (per-tier authorizer doesn't replace
  design.md §2.5 server enforcement); alarm on wrong-audience tokens.
- CR-6: finance-audience token must not reach Gmail/Calendar even with a Google token.
- CR-2: verify+enforce received sub is the Google Workspace sub, not a Salesforce id.
- CR-3: pre-token Lambda fails closed on cross-audience scope.
- CR-5: pre-token + group-sync are the auth SPOF — alarms + group-claim freshness bound.
- CR-4/CR-7: restrict per-client Cognito scopes; WAF is defense-in-depth only.
Reflected in §0.1 B3/B4, §1h tests, §4 monitoring, §5 cross-review log.
2026-06-26 12:45:06 -04:00
8c768f0495 Remediate sh-plan-review findings (B1-B5, F1-F7, NITs, Qs)
Address the Fable plan-review gate (REQUEST CHANGES):
- B1: move ALL teardown to Phase 4 + shared-consumer audit; notion-sync dual-feeds;
  rollback never targets a deleted/starved resource.
- B2: propagate the §0.1 resolutions through D5/D11/§1d/§2.x/§3/G6/G9/§6 (model,
  guardrail, dropped ~30% claim, Phase-0 'verify' not 'decide').
- B3: pin D12 to one facade per trust tier (per-server Cognito audience at the edge);
  reconcile the §1h list_tools test (deferred with MCP adapter).
- B4: specify per-agent External Credential + Cognito app client minting only its tier's
  scopes; add the token-layer trifecta test.
- B5: split Phase 0 (0a auth spike gates 0b); add custom-Bolt fallback; relabel G1 as
  mitigation-chosen/unverified.
- F1-F7: Testing-Center identity (G12); design.md amendments reframed (F2); sh-agentforce
  new-repo checklist + cd-sfdx JWT-key auth (F3); platform-build phase (F4); Salesforce
  data-processor gap (G13/F5); memory+README obligations (F6); per-user visibility
  degradation (G14/F7).
- NITs: S3->Data Cloud ingestion pinned; facade+notion-sync ALARM monitoring; DevName
  naming boundary. Qs Q1-Q3 registered as G15 + verify items.
- §0.3 remediation log + gap count 11->15.
2026-06-26 12:45:06 -04:00
5cde27da80 Add D12: OpenAPI-first, MCP-ready transport-agnostic core
Tool handlers + shared auth/scope/PII/audit guard built independent of wire
protocol; OpenAPI adapter shipped now (Agentforce External Service actions, Apex
only for shaping); MCP adapter deferred to a named trigger (real IDE/Claude Code
workflow, or native remote-MCP per-user GA). Update decision log, §0.1 transport
architecture block, §1h test split (OpenAPI contract now, MCP conformance deferred),
and §4 deliverables (annotate design.md §4; transport-agnostic core story).
2026-06-26 12:45:06 -04:00
764b6725c3 Resolve open decisions: per-user auth pattern + reasoning model
Fold Adam's decisions and deep-research (wf_1bf9e142) outcomes into the plan:
- D4: ES/Apex actions + Per-User OAuth Browser Flow External Credential -> Cognito;
  native remote-MCP connector off the per-user hop (Beta, per-user binding unconfirmed).
- D5: AWS-Hosted Claude as the planner; BYOLLM ruled out (custom-action-only, routes
  through SF Models API/Trust Layer). Guardrail moves to the MCP/action layer (revises D11).
- D1 accepted; D3 accepted; G8 corpus authoring deferred (fund when needed).
- Resolve gaps G1/G2/G6; add §0.1 resolutions and a Phase-0 verify-in-org gate.
2026-06-26 12:45:06 -04:00
Claude
eaec749fc2 Add Agentforce migration & architecture plan
Decision document mapping the sh-mcp design.md substrate onto Agentforce:
3-agent roster (Ops/Finance/Lauren Exec) on trust-tiered MCP servers,
per-user OAuth via Cognito, Data Library/retriever design replacing the
Bedrock KB, model/DX/Testing-Center plans, cutover phasing, and an
11-item capability-gap register.

https://claude.ai/code/session_01BvKGBQ4ek6JRZVkFicZuw6
2026-06-26 12:45:06 -04:00
Adam Moussa
0d1fefb326
Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2)
Some checks are pending
deploy / deploy (push) Waiting to run
* Phase 0b slice: monorepo scaffold + shared core + integration packages

The 0a-INDEPENDENT code slice (one-shot via af-0b-package-slice workflow: Haiku
scaffold + Sonnet packages, Sonnet fix-to-green). Nothing deploys; no CDK/servers.

- Monorepo scaffold: npm workspaces, strict TS (NodeNext), vitest (80% gate),
  eslint 9 flat config, prettier; ci.yaml/deploy.yaml callers (Node 24, enable-qemu).
- @sh-mcp/shared: transport-agnostic core — Scope/AuthContext/ToolDef, ToolRegistry,
  redact()+maskValue() (PII), OpenAPI 3.1 generator. AUTH STUBBED behind an AuthProvider
  interface (TODO auth-layer-0a); JWT/aud/client_id/JWKS/deny-list deferred per design.md §2.
- 9 integration packages (qbo, google-maps, internal-data, payments, knowledge-base,
  gmail, calendar, tasks, reminders): tools against shared, external deps mocked behind
  injected client interfaces; finance handlers call redact().

Verified green: tsc -b clean, vitest 245/245, eslint 0 errors. Auth mechanism intentionally
deferred until the 0a spike resolves it (G16/§0.4).

* Complete Cognito auth provider + Phase 1 build brief

Finish the WIP CognitoAuthProvider (client_id allow-list as audience
boundary, finance TTL ceiling, deny-list, scope-prefix stripping) with
its test suite, and check in docs/build-plan-phase-1.md so the Phase 1
work has its governing brief in-tree (design.md §2.5).

* ci: disable cdk synth for Phase 0b (no CDK app yet)

The reusable ci-typescript-cdk workflow defaults run-cdk-synth: true, but
the Phase 0b package scaffold has no cdk.json or stacks, so cdk synth fails
with '--app is required'. Disable it here; Phase 1 re-enables it with the
server CDK stubs.
2026-06-26 12:42:17 -04:00
3e2d99a1eb Initial commit: sh-mcp design and plan
Design doc for the Sea Haven MCP platform that replaces seahaven-slack-bot
and exec-aide: trust-tiered MCP servers, Google-SSO via a Cognito broker,
TypeScript monorepo. Cross-review (cross_reviewer/GPT-4.1) folded in.

Status: planning only, nothing built.
2026-06-09 19:25:24 -04:00