From 09e960a3a94bcbcb98f8dcad36173617a3ac8239 Mon Sep 17 00:00:00 2001 From: estorozhenko Date: Fri, 18 Sep 2026 22:05:01 +0000 Subject: [PATCH] Baseline md2vk: docs, audit log, docker 8420, openspec, deploy --- .env.example | 20 + .gitignore | 41 ++ .hermes/skills/openspec-apply-change/SKILL.md | 188 ++++++++ .../skills/openspec-archive-change/SKILL.md | 182 ++++++++ .hermes/skills/openspec-explore/SKILL.md | 335 ++++++++++++++ .hermes/skills/openspec-propose/SKILL.md | 153 +++++++ .hermes/skills/openspec-sync-specs/SKILL.md | 262 +++++++++++ .../skills/openspec-update-change/SKILL.md | 91 ++++ Dockerfile | 32 ++ Makefile | 53 +++ README.md | 64 +++ STATUS.md | 28 ++ app/__init__.py | 0 app/api/__init__.py | 0 app/api/audit.py | 121 +++++ app/api/deps.py | 64 +++ app/api/schemas.py | 110 +++++ app/api/v1.py | 325 ++++++++++++++ app/config.py | 42 ++ app/converters/__init__.py | 0 app/converters/markdown_to_vk.py | 422 ++++++++++++++++++ app/database.py | 37 ++ app/main.py | 48 ++ app/models.py | 92 ++++ app/security.py | 50 +++ app/vk_client.py | 108 +++++ docker-compose.yml | 31 ++ docs/access.md | 84 ++++ docs/architecture.md | 84 ++++ docs/deploy.md | 127 ++++++ docs/index.md | 65 +++ docs/security.md | 71 +++ docs/status.md | 59 +++ docs/vk-api.md | 83 ++++ openspec/config.yaml | 32 ++ openspec/specs/.gitkeep | 0 openspec/specs/publishing/markdown/spec.md | 133 ++++++ requirements.txt | 9 + scripts/create_user.py | 70 +++ 39 files changed, 3716 insertions(+) create mode 100644 .env.example create mode 100644 .gitignore create mode 100644 .hermes/skills/openspec-apply-change/SKILL.md create mode 100644 .hermes/skills/openspec-archive-change/SKILL.md create mode 100644 .hermes/skills/openspec-explore/SKILL.md create mode 100644 .hermes/skills/openspec-propose/SKILL.md create mode 100644 .hermes/skills/openspec-sync-specs/SKILL.md create mode 100644 .hermes/skills/openspec-update-change/SKILL.md create mode 100644 Dockerfile create mode 100644 Makefile create mode 100644 README.md create mode 100644 STATUS.md create mode 100644 app/__init__.py create mode 100644 app/api/__init__.py create mode 100644 app/api/audit.py create mode 100644 app/api/deps.py create mode 100644 app/api/schemas.py create mode 100644 app/api/v1.py create mode 100644 app/config.py create mode 100644 app/converters/__init__.py create mode 100644 app/converters/markdown_to_vk.py create mode 100644 app/database.py create mode 100644 app/main.py create mode 100644 app/models.py create mode 100644 app/security.py create mode 100644 app/vk_client.py create mode 100644 docker-compose.yml create mode 100644 docs/access.md create mode 100644 docs/architecture.md create mode 100644 docs/deploy.md create mode 100644 docs/index.md create mode 100644 docs/security.md create mode 100644 docs/status.md create mode 100644 docs/vk-api.md create mode 100644 openspec/config.yaml create mode 100644 openspec/specs/.gitkeep create mode 100644 openspec/specs/publishing/markdown/spec.md create mode 100644 requirements.txt create mode 100644 scripts/create_user.py diff --git a/.env.example b/.env.example new file mode 100644 index 0000000..be88b1a --- /dev/null +++ b/.env.example @@ -0,0 +1,20 @@ +# md2vk configuration + +HOST=0.0.0.0 +PORT=8000 + +# Путь к файлу с ключом Fernet-шифрования VK-токенов +# Файл должен содержать 32-байтовый base64-ключ, сгенерированный: +# python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())" +# В Docker — /run/secrets/token_encryption_key +# При локальном запуске — /opt/md2vk/secrets/token_encryption_key +TOKEN_ENCRYPTION_KEY_FILE=/opt/md2vk/secrets/token_encryption_key + +# База данных (SQLite = один файл, не требует отдельного сервера) +DATABASE_URL=sqlite+aiosqlite:///data/md2vk.db + +# Версия VK API +VK_API_VERSION=5.199 + +# Rate limiting: макс. запросов в минуту на один VK-аккаунт +RATE_LIMIT_PER_MINUTE=10 \ No newline at end of file diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..f7d3373 --- /dev/null +++ b/.gitignore @@ -0,0 +1,41 @@ +# Python +__pycache__/ +*.py[cod] +*.egg-info/ +venv/ +.venv/ +*.egg + +# IDE +.vscode/ +.idea/ + +# Secrets (НИКОГДА не коммитить) +secrets/token_encryption_key +secrets/*.key +secrets/estorozhenko_api_key.txt +.env + +# Database +/data/ +*.db + +# Logs (аудит) +/logs/ + +# OS +.DS_Store +Thumbs.db + +# Tests +.pytest_cache/ +.coverage +htmlcov/ + +# Build +dist/ +build/ + +# OpenSpec +openspec/.openspec/ +openspec/changes/archive/ \ No newline at end of file diff --git a/.hermes/skills/openspec-apply-change/SKILL.md b/.hermes/skills/openspec-apply-change/SKILL.md new file mode 100644 index 0000000..bc316f0 --- /dev/null +++ b/.hermes/skills/openspec-apply-change/SKILL.md @@ -0,0 +1,188 @@ +--- +name: openspec-apply-change +description: Implement tasks from an OpenSpec change. Use when the user wants to start implementing, continue implementation, or work through tasks. +allowed-tools: Bash(openspec:*) +license: MIT +compatibility: Requires openspec CLI. +metadata: + author: openspec + version: "1.0" + generatedBy: "1.12.0" +--- + +Implement tasks from an OpenSpec change. + +**Store selection:** If the user names a store (a store is a standalone OpenSpec repo registered on this machine) or the work lives in one, run `openspec store list --json` to discover registered store ids, then pass `--store ` on the commands that read or write specs and changes (`new change`, `status`, `instructions`, `list`, `show`, `validate`, `archive`, `doctor`, `context`, `schemas`, `view`). Once selected, treat `--store ` as sticky for the rest of the workflow. Every unscoped example of those commands below is shorthand: before running it, append the flag. For example, run `openspec status --change "" --json --store ""`, not the unscoped form shown below. Other commands do not take the flag. Hints printed by commands already carry the flag; keep it on follow-ups. Without a store, commands act on the nearest local `openspec/` root. + +**Input**: Optionally specify a change name (e.g., `/openspec-apply-change add-auth`). If omitted, check if it can be inferred from conversation context. If vague or ambiguous you MUST prompt for available changes. + +**Steps** + +1. **Select the change** + + If a name is provided, use it. Otherwise: + - Infer from conversation context if the user mentioned a change + - Auto-select if only one active change exists + - If ambiguous, run `openspec list --json` to get available changes and ask the user to select one + + Always announce: "Using change: " and how to override (e.g., `/openspec-apply-change `). + +2. **Check status to understand the schema** + ```bash + openspec status --change "" --json + ``` + Parse the JSON to understand: + - `schemaName`: The workflow being used (e.g., "spec-driven") + - `planningHome`, `changeRoot`, and `actionContext`: planning scope and edit constraints + - Which artifact contains the tasks (typically "tasks" for spec-driven, check status for others) + +3. **Get apply instructions** + + ```bash + openspec instructions apply --change "" --json + ``` + + This returns: + - `contextFiles`: artifact ID -> array of concrete file paths (varies by schema - could be proposal/specs/design/tasks or spec/tests/implementation/docs) + - Progress (total, complete, remaining) + - Task list with status + - Dynamic instruction based on current state + - Optional `context`: current required project instruction input from the selected root + - Optional `operationGuidance`: current advisory guidance for apply + + **Handle states:** + - If `state: "blocked"` (missing artifacts): show message, suggest using `/openspec-continue-change` (if it is not installed, run `openspec status --change "" --json` to see the next artifact and `openspec instructions --change "" --json` for how to create it) + - If `state: "all_done"`: congratulate, suggest archive + - Otherwise: proceed to implementation + + Treat `context` as a required prompt-level input. Read and consider it, and + apply relevant project facts, conventions, and constraints while implementing. + Treat `operationGuidance` as optional additive advice. Read and consider every + entry, and follow entries that are applicable and compatible with the built-in + workflow. + + Keep both fields separate from CLI-returned state, missing artifacts, tasks, + progress, `contextFiles`, and the built-in `instruction`. They are not + evidence of task completion, do not replace the built-in instruction, and do + not permit bypassing a blocked state. If context conflicts with the built-in + instruction, an explicit user choice, or a CLI-controlled value, report the + conflict and preserve the controlling value. If guidance is inapplicable or + conflicts with those controlling inputs, do not follow it and explain why. + These are prompt-level behavior contracts, not enforceable checks. + +4. **Read context files** + + Read every file path listed under `contextFiles` from the apply instructions output. + The files depend on the schema being used: + - **spec-driven**: proposal, specs, design, tasks + - Other schemas: follow the contextFiles from CLI output + + Do not copy `context` or `operationGuidance` verbatim into implementation + files or planning artifacts unless the user separately asks for that content. + +5. **Show current progress** + + Display: + - Schema being used + - Progress: "N/M tasks complete" + - Remaining tasks overview + - Dynamic instruction from CLI + +6. **Implement tasks (loop until done or blocked)** + + For each pending task: + - Show which task is being worked on + - Make the code changes required + - Keep changes minimal and focused + - Mark task complete in the tasks file: `- [ ]` → `- [x]` + - Continue to next task + + **Pause if:** + - Task is unclear → ask for clarification + - Implementation reveals a design issue → suggest updating artifacts + - A task needs work beyond what the spec and tasks describe, or you are tempted to drop, narrow, defer, or accept exceptions to specified behavior to make it fit → surface the added scope and ask; do not absorb it silently + - Error or blocker encountered → report and wait for guidance + - User interrupts + +7. **On completion or pause, show status** + + Display: + - Tasks completed this session + - Overall progress: "N/M tasks complete" + - If all done: suggest archive + - If paused: explain why and wait for guidance + +**Output During Implementation** + +``` +## Implementing: (schema: ) + +Working on task 3/7: +[...implementation happening...] +✓ Task complete + +Working on task 4/7: +[...implementation happening...] +✓ Task complete +``` + +**Output On Completion** + +``` +## Implementation Complete + +**Change:** +**Schema:** +**Progress:** 7/7 tasks complete ✓ + +### Completed This Session +- [x] Task 1 +- [x] Task 2 +... + +All tasks complete! You can archive this change with `/openspec-archive-change`. +``` + +**Output On Pause (Issue Encountered)** + +``` +## Implementation Paused + +**Change:** +**Schema:** +**Progress:** 4/7 tasks complete + +### Issue Encountered + + +**Options:** +1.