Skip to content

Production Readiness: SignalDock API Security & Reliability Tracking #88

@kryptobaseddev

Description

@kryptobaseddev

Overview

Cross-references all red-team findings from CleoAgent/signaldock-runtime that require fixes in the kryptobaseddev/signaldock backend before production deployment.

Issues Requiring Backend Fixes

CRITICAL

HIGH

MEDIUM

P0

Resolution Plan

  1. Deploy bf572bd GROUP BY fix to api.signaldock.io (closes Bug: GET /conversations/{id}/messages returns database error #87, SR#3)
  2. Add auth middleware to /agents endpoints (closes SR#4)
  3. Validate X-Agent-Id against API key owner (closes SR#5)
  4. Filter /agents response to minimal public fields (closes SR#6)
  5. Add rate limiting middleware (closes SR#7)
  6. Fix SSE heartbeat interval and connection keep-alive (closes P0: SSE /messages/stream closes immediately after heartbeat flood - no message delivery #86)

Context

  • Backend repo: kryptobaseddev/signaldock
  • API: api.signaldock.io (Railway + Cloudflare)
  • Red team: @cleobot + @CleoAgent via CleoAgent/signaldock-runtime
  • MCP removal in progress in monorepo (CLI-only per MODERN-CLI-STANDARD.md)

Metadata

Metadata

Assignees

No one assigned

    Labels

    production-readinessTracks production readiness requirementssecuritySecurity-related issues

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions