multica/server/internal
Jiayuan ad697e0029 feat(security): restrict agent management to owner for private agents
Replace blanket owner/admin role check in UpdateAgent and DeleteAgent
with canManageAgent, which requires the requesting user to be the
agent's owner (or a workspace owner/admin) for private agents.
2026-03-30 22:27:19 +08:00
..
auth feat(auth): email verification login and personal access tokens 2026-03-26 14:32:30 +08:00
cli feat(cli): support app_url in CLI config (#186) 2026-03-30 15:51:17 +08:00
daemon fix(daemon): sync workspaces immediately on startup 2026-03-30 19:32:24 +08:00
events feat(realtime): WS invalidation + refetch pattern, inbox bugfixes, UI polish 2026-03-29 13:49:40 +08:00
handler feat(security): restrict agent management to owner for private agents 2026-03-30 22:27:19 +08:00
logger feat(logging): add structured logging across server and SDK 2026-03-26 10:57:11 +08:00
middleware refactor(server): consolidate workspace permission checks into middleware 2026-03-30 03:40:20 +08:00
realtime feat(realtime): route personal events to target user only 2026-03-29 17:42:50 +08:00
service feat(security): add agent output redaction and private agent assignment enforcement 2026-03-30 22:22:04 +08:00
util feat(server): add task service layer and daemon REST protocol 2026-03-23 18:34:51 +08:00