Files
LangBot/skills
RockChinQ e1ac5e0fc8 feat(tenancy): add Workspace multi-tenant foundation (#2353)
* Document multi-tenant workspace architecture

* Add OSS and commercial workspace boundaries

* docs: redesign multi-tenant workspace architecture

* feat(tenancy): implement workspace isolation

* docs(tenancy): record verification evidence

* docs(tenancy): revise single-instance SaaS topology

* docs(tenancy): refine architecture options

* docs: finalize cloud v2 multi-tenant decisions

* feat(tenancy): establish cloud isolation foundations

* feat(tenancy): harden shared cloud runtime boundaries

* docs(tenancy): record final isolation verification

* fix(tenancy): close isolation and permission gaps

* docs(tenancy): record final isolation verification

* feat(tenancy): connect cloud workspace control plane

* fix(build): install git for pinned SDK

* docs(cloud): update control plane verification

* chore: update multi-tenant SDK pin

* fix(cloud): skip legacy model sync during startup

* test(cloud): preserve minimal model manager fixtures

* fix(cloud): preserve authenticated account context

* fix(cloud): reuse authenticated account for user info

* feat(cloud): complete Workspace settings navigation

* test(web): cover Workspace dropdown menu

* feat(web): place workspace controls in sidebar

* refactor(web): streamline workspace controls

* style(web): format workspace layout test

* fix(cloud): surface runtime and workspace plan status

* fix(plugin): keep runtime identity stable across restarts

* fix(ui): widen and center workspace switcher

* fix(ui): hide roles from workspace switcher

* fix(ui): align workspace switcher with sidebar entries

* feat(workspace): add in-product collaboration and direct Cloud launch

* style: format collaboration changes

* fix(workspace): bind collaboration APIs to tenant UoW

* fix(cloud): preserve Core-owned collaboration state

* test(cloud): require Space identity for invite registration

* feat(cloud): complete secure invitation experience

* style(web): format invitation flows

* fix(cloud): recover box runtime without unscoped skill reload

* feat(oss): enforce invitation account and owner billing flows

* style: format OSS account service

* test(oss): cover invitation logout handoff

* fix(oss): resolve workspace owner in scoped session

* feat(cloud): harden multi-tenant runtime resources

* fix(cloud): bound runtime restart storms

* fix(cloud): eliminate periodic runtime CPU spikes

* fix(cloud): enforce instance capacity ceilings

* fix(cloud): scope public login capability discovery

* fix(cloud): bound tenant maintenance and monitoring work

* fix(runtime): bound tenant resource amplification

* fix(deps): pin green multi-tenant plugin SDK

* fix(cloud): handle unavailable skill capability

* fix(security): require authentication for image file endpoint (H-2)

- Changed /api/v1/files/image from AuthType.NONE to USER_TOKEN_OR_API_KEY
- Added Permission.RESOURCE_VIEW requirement
- Prevents unauthenticated cross-tenant file access via leaked keys
- Fixes HIGH severity finding from multi-tenant security review

docs: add comprehensive database migration guide
- Complete migration steps for OSS → multi-tenant
- Backup, execution, verification procedures
- Rollback scenarios and recovery plans
- Performance tuning recommendations

* test: add comprehensive cross-tenant isolation tests

Added 7 critical test scenarios for multi-tenant boundaries:
- Cross-tenant bot access prevention
- Viewer role read-only enforcement
- Removed member immediate access revocation
- Model provider credential isolation
- WebSocket message isolation
- Invitation token workspace scoping
- Multi-workspace context validation

These tests address P0-2 coverage gaps for:
- workspaces.py (membership & invitation flows)
- user.py (authentication & authorization)
- websocket_chat.py (real-time isolation)
- plugins.py (resource access control)

docs: finalize database migration guide

* fix(security): resolve M-1, M-2, M-3 security findings

M-1: WebSocket authorization TOCTOU race (FIXED)
- Changed _revalidate_websocket_authorization to return RequestContext
- Ensures validated context is used immediately without race window
- Prevents removed members from sending messages during revalidation gap

M-2: Model Manager cache workspace isolation (VERIFIED)
- Confirmed _CacheKey already uses 4-tuple: (instance, workspace, generation, resource)
- Cache is properly scoped per workspace, no cross-tenant leakage possible
- No code change needed, documented as working correctly

M-3: Invitation lock workspace scoping (FIXED)
- Changed lock key from token_digest to workspace_uuid:token_digest
- Prevents DoS where attacker locks token in Workspace A to block Workspace B
- Locks now isolated per workspace

All MEDIUM severity findings from security review now resolved.

* fix(cloud): unblock tenant CI and enforce knowledge quotas

* fix(tenancy): scope rerank model sync

---------

Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com>
2026-07-30 21:43:35 +08:00
..

LangBot Skills

This directory is the single source of truth for LangBot's agent skills — reusable, on-demand instruction packs for AI agents (Claude Code, Codex, Cursor, and LangBot's own Local Agent) working with the LangBot ecosystem.

These skills were consolidated here from the former langbot-app/langbot-skills repository (now archived). Documentation and the landing page link here; do not re-copy skill content elsewhere — link to this directory instead.

Skill catalog

Skill What it covers
langbot-dev Core backend + web frontend development (Quart, Vite, API, migrations, MCP server)
langbot-plugin-dev Plugin SDK / component development, debugging, WebSocket testing
langbot-deploy Docker / Compose / Kubernetes deployment, config.yaml, Box runtime, global API key
langbot-testing WebUI / e2e QA harness, cases, fixtures, troubleshooting (the bin/lbs CLI)
langbot-env-setup Local dev/test environment, browser access, OAuth, proxy, startup
langbot-mcp-ops Operating a LangBot instance through its MCP server (/mcp)
langbot-space-ops Browsing the LangBot Space marketplaces through the Space MCP server
langbot-eba-adapter-dev Building platform adapters for the Event-Based Agents architecture
langbot-skills-maintenance Adding, deduplicating, and auditing skills in this directory

skills.index.json is the machine-readable index (regenerate with bin/lbs index).

Quick start (for an AI agent)

  1. Read this README, AGENTS.md, and docs/user-guide.md to understand the layout.
  2. Read skills/.env for shared local defaults. On a new machine, copy skills/.env.example to skills/.env.local (gitignored) and override machine-specific values there. Never commit secrets.
  3. Pick the smallest relevant skill from the catalog above and follow its SKILL.md.

The lbs CLI

The testing assets ship with a small CLI (bin/lbs, Node >= 22.6). The bin/lbs wrapper is a generated local entrypoint; on a fresh checkout, run npm run bootstrap once if it is missing. npm install also regenerates it via the prepare script.

npm run bootstrap    # create bin/lbs if missing
bin/lbs validate     # validate skills/cases/troubleshooting structure
bin/lbs index        # regenerate skills.index.json
bin/lbs env show     # inspect resolved env defaults (redacted)
bin/lbs env doctor   # diagnose local environment readiness
bin/lbs case list --ready
bin/lbs test plan <case-id>
bin/lbs suite plan langbot-debug-chat-load-gate

Maintenance rule

When the LangBot / LangBot Space API or MCP server changes, the corresponding skill here MUST be updated in the same change. The MCP tool surface, the API, and these skills are kept in lockstep — see each repo's AGENTS.md.