Baseline md2vk: docs, audit log, docker 8420, openspec, deploy

This commit is contained in:
estorozhenko
2026-09-18 22:05:01 +00:00
commit 09e960a3a9
39 changed files with 3716 additions and 0 deletions
+20
View File
@@ -0,0 +1,20 @@
# md2vk configuration
HOST=0.0.0.0
PORT=8000
# Путь к файлу с ключом Fernet-шифрования VK-токенов
# Файл должен содержать 32-байтовый base64-ключ, сгенерированный:
# python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
# В Docker — /run/secrets/token_encryption_key
# При локальном запуске — /opt/md2vk/secrets/token_encryption_key
TOKEN_ENCRYPTION_KEY_FILE=/opt/md2vk/secrets/token_encryption_key
# База данных (SQLite = один файл, не требует отдельного сервера)
DATABASE_URL=sqlite+aiosqlite:///data/md2vk.db
# Версия VK API
VK_API_VERSION=5.199
# Rate limiting: макс. запросов в минуту на один VK-аккаунт
RATE_LIMIT_PER_MINUTE=10
+41
View File
@@ -0,0 +1,41 @@
# Python
__pycache__/
*.py[cod]
*.egg-info/
venv/
.venv/
*.egg
# IDE
.vscode/
.idea/
# Secrets (НИКОГДА не коммитить)
secrets/token_encryption_key
secrets/*.key
secrets/estorozhenko_api_key.txt
.env
# Database
/data/
*.db
# Logs (аудит)
/logs/
# OS
.DS_Store
Thumbs.db
# Tests
.pytest_cache/
.coverage
htmlcov/
# Build
dist/
build/
# OpenSpec
openspec/.openspec/
openspec/changes/archive/
@@ -0,0 +1,188 @@
---
name: openspec-apply-change
description: Implement tasks from an OpenSpec change. Use when the user wants to start implementing, continue implementation, or work through tasks.
allowed-tools: Bash(openspec:*)
license: MIT
compatibility: Requires openspec CLI.
metadata:
author: openspec
version: "1.0"
generatedBy: "1.12.0"
---
Implement tasks from an OpenSpec change.
**Store selection:** If the user names a store (a store is a standalone OpenSpec repo registered on this machine) or the work lives in one, run `openspec store list --json` to discover registered store ids, then pass `--store <id>` on the commands that read or write specs and changes (`new change`, `status`, `instructions`, `list`, `show`, `validate`, `archive`, `doctor`, `context`, `schemas`, `view`). Once selected, treat `--store <id>` as sticky for the rest of the workflow. Every unscoped example of those commands below is shorthand: before running it, append the flag. For example, run `openspec status --change "<name>" --json --store "<id>"`, not the unscoped form shown below. Other commands do not take the flag. Hints printed by commands already carry the flag; keep it on follow-ups. Without a store, commands act on the nearest local `openspec/` root.
**Input**: Optionally specify a change name (e.g., `/openspec-apply-change add-auth`). If omitted, check if it can be inferred from conversation context. If vague or ambiguous you MUST prompt for available changes.
**Steps**
1. **Select the change**
If a name is provided, use it. Otherwise:
- Infer from conversation context if the user mentioned a change
- Auto-select if only one active change exists
- If ambiguous, run `openspec list --json` to get available changes and ask the user to select one
Always announce: "Using change: <name>" and how to override (e.g., `/openspec-apply-change <other>`).
2. **Check status to understand the schema**
```bash
openspec status --change "<name>" --json
```
Parse the JSON to understand:
- `schemaName`: The workflow being used (e.g., "spec-driven")
- `planningHome`, `changeRoot`, and `actionContext`: planning scope and edit constraints
- Which artifact contains the tasks (typically "tasks" for spec-driven, check status for others)
3. **Get apply instructions**
```bash
openspec instructions apply --change "<name>" --json
```
This returns:
- `contextFiles`: artifact ID -> array of concrete file paths (varies by schema - could be proposal/specs/design/tasks or spec/tests/implementation/docs)
- Progress (total, complete, remaining)
- Task list with status
- Dynamic instruction based on current state
- Optional `context`: current required project instruction input from the selected root
- Optional `operationGuidance`: current advisory guidance for apply
**Handle states:**
- If `state: "blocked"` (missing artifacts): show message, suggest using `/openspec-continue-change` (if it is not installed, run `openspec status --change "<name>" --json` to see the next artifact and `openspec instructions <artifact-id> --change "<name>" --json` for how to create it)
- If `state: "all_done"`: congratulate, suggest archive
- Otherwise: proceed to implementation
Treat `context` as a required prompt-level input. Read and consider it, and
apply relevant project facts, conventions, and constraints while implementing.
Treat `operationGuidance` as optional additive advice. Read and consider every
entry, and follow entries that are applicable and compatible with the built-in
workflow.
Keep both fields separate from CLI-returned state, missing artifacts, tasks,
progress, `contextFiles`, and the built-in `instruction`. They are not
evidence of task completion, do not replace the built-in instruction, and do
not permit bypassing a blocked state. If context conflicts with the built-in
instruction, an explicit user choice, or a CLI-controlled value, report the
conflict and preserve the controlling value. If guidance is inapplicable or
conflicts with those controlling inputs, do not follow it and explain why.
These are prompt-level behavior contracts, not enforceable checks.
4. **Read context files**
Read every file path listed under `contextFiles` from the apply instructions output.
The files depend on the schema being used:
- **spec-driven**: proposal, specs, design, tasks
- Other schemas: follow the contextFiles from CLI output
Do not copy `context` or `operationGuidance` verbatim into implementation
files or planning artifacts unless the user separately asks for that content.
5. **Show current progress**
Display:
- Schema being used
- Progress: "N/M tasks complete"
- Remaining tasks overview
- Dynamic instruction from CLI
6. **Implement tasks (loop until done or blocked)**
For each pending task:
- Show which task is being worked on
- Make the code changes required
- Keep changes minimal and focused
- Mark task complete in the tasks file: `- [ ]` → `- [x]`
- Continue to next task
**Pause if:**
- Task is unclear → ask for clarification
- Implementation reveals a design issue → suggest updating artifacts
- A task needs work beyond what the spec and tasks describe, or you are tempted to drop, narrow, defer, or accept exceptions to specified behavior to make it fit → surface the added scope and ask; do not absorb it silently
- Error or blocker encountered → report and wait for guidance
- User interrupts
7. **On completion or pause, show status**
Display:
- Tasks completed this session
- Overall progress: "N/M tasks complete"
- If all done: suggest archive
- If paused: explain why and wait for guidance
**Output During Implementation**
```
## Implementing: <change-name> (schema: <schema-name>)
Working on task 3/7: <task description>
[...implementation happening...]
✓ Task complete
Working on task 4/7: <task description>
[...implementation happening...]
✓ Task complete
```
**Output On Completion**
```
## Implementation Complete
**Change:** <change-name>
**Schema:** <schema-name>
**Progress:** 7/7 tasks complete ✓
### Completed This Session
- [x] Task 1
- [x] Task 2
...
All tasks complete! You can archive this change with `/openspec-archive-change`.
```
**Output On Pause (Issue Encountered)**
```
## Implementation Paused
**Change:** <change-name>
**Schema:** <schema-name>
**Progress:** 4/7 tasks complete
### Issue Encountered
<description of the issue>
**Options:**
1. <option 1>
2. <option 2>
3. Other approach
What would you like to do?
```
**Guardrails**
- Keep going through tasks until done or blocked
- Always read context files before starting (from the apply instructions output)
- If task is ambiguous, pause and ask before implementing
- If implementation reveals issues, pause and suggest artifact updates
- Keep code changes minimal and scoped to each task
- Update task checkbox immediately after completing each task
- Pause on errors, blockers, or unclear requirements - don't guess
- When a task needs work beyond what the spec describes, surface the added scope and pause - never silently narrow, defer, or simplify away specified behavior
- Only mark a task `- [x]` when its specified behavior is fully implemented, not when it is partially done or deferred
- Use contextFiles from CLI output, don't assume specific file names
- Do not use context or operation guidance as proof that a task is complete
- Apply relevant project context; report conflicts with controlling workflow inputs
- Consider every guidance entry; explain any inapplicable or conflicting advice
- Do not copy runtime context or operation guidance into implementation files or planning artifacts
- Preserve CLI-controlled blocked/ready/all-done behavior and completion criteria
**Fluid Workflow Integration**
This skill supports the "actions on a change" model:
- **Can be invoked anytime**: Before all artifacts are done (if tasks exist), after partial implementation, interleaved with other actions
- **Allows artifact updates**: If implementation reveals design issues, suggest updating artifacts - not phase-locked, work fluidly
@@ -0,0 +1,182 @@
---
name: openspec-archive-change
description: Archive a completed change in the experimental workflow. Use when the user wants to finalize and archive a change after implementation is complete.
allowed-tools: Bash(openspec:*)
license: MIT
compatibility: Requires openspec CLI.
metadata:
author: openspec
version: "1.0"
generatedBy: "1.12.0"
---
Archive a completed change in the experimental workflow.
**Store selection:** If the user names a store (a store is a standalone OpenSpec repo registered on this machine) or the work lives in one, run `openspec store list --json` to discover registered store ids, then pass `--store <id>` on the commands that read or write specs and changes (`new change`, `status`, `instructions`, `list`, `show`, `validate`, `archive`, `doctor`, `context`, `schemas`, `view`). Once selected, treat `--store <id>` as sticky for the rest of the workflow. Every unscoped example of those commands below is shorthand: before running it, append the flag. For example, run `openspec status --change "<name>" --json --store "<id>"`, not the unscoped form shown below. Other commands do not take the flag. Hints printed by commands already carry the flag; keep it on follow-ups. Without a store, commands act on the nearest local `openspec/` root.
`<capability-path>` is the spec directory relative to `specs/` (for example, `user-auth` or `identity/user-auth`). Preserve the full path from each delta spec when resolving its main spec.
**Input**: Optionally specify a change name. If omitted, check if it can be inferred from conversation context. If vague or ambiguous you MUST prompt for available changes.
**Steps**
1. **Select the change**
If a name is provided, use it. Otherwise:
- Infer from conversation context if the user mentioned a change
- Auto-select if only one active change exists
- If ambiguous, run `openspec list --json` to get available changes and ask the user to select one
When prompting, show only active changes (not already archived).
Include the schema used for each change if available.
Always announce: "Using change: <name>" and how to override (e.g., `/openspec-archive-change <other>`).
**Load current archive inputs before the existing archive checks:**
After resolving the selected change and planning root, run:
```bash
openspec instructions archive --change "<name>" --json
```
Keep the same selected-root flags on this command. This lookup is advisory and
optional: it only supplies extra prompt inputs, so it must never block archiving.
If it exits non-zero or returns invalid JSON — for example on an older CLI that
does not support this command yet — continue the archive workflow with no
context and no operation guidance. Do not report an error and do not stop.
A successful response may omit both optional fields. Treat `context` as a
required prompt-level input: read and consider it, and apply relevant project
facts, conventions, and constraints. Treat `operationGuidance` as optional
additive advice: read and consider every entry, and follow entries that are
applicable and compatible with the built-in archive workflow.
Keep both fields separate from built-in steps, explicit user choices, resolved
paths, CLI checks, and command contracts. If context conflicts with one of those
controlling inputs, report the conflict and preserve the controlling value. If
guidance is inapplicable or conflicts with a controlling input, do not follow it
and explain why. Do not infer replacement paths, skipped prompts, or flags from
either field, and do not copy their text verbatim into specs, change artifacts,
or archive summaries unless the user separately asks for it. These are
prompt-level behavior contracts, not enforceable checks.
2. **Check artifact completion status**
Run `openspec status --change "<name>" --json` to check artifact completion.
Parse the JSON to understand:
- `schemaName`: The workflow being used
- `planningHome`, `changeRoot`, `artifactPaths`, and `actionContext`: path and scope context
- `artifacts`: List of artifacts with their status (`done`, `skipped`, or other)
**If any artifacts are neither `done` nor `skipped`** (skipped artifacts satisfy the requirement - the change declares skip_specs):
- Display warning listing incomplete artifacts
- Ask the user to confirm they want to proceed
- Proceed if user confirms
3. **Check task completion status**
Read the tasks file (typically `tasks.md`) to check for incomplete tasks.
Count tasks marked with `- [ ]` (incomplete) vs `- [x]` (complete).
**If incomplete tasks found:**
- Display warning showing count of incomplete tasks
- Ask the user to confirm they want to proceed
- Proceed if user confirms
**If no tasks file exists:** Proceed without task-related warning.
4. **Assess delta spec sync state**
Use `artifactPaths.specs.existingOutputPaths` from status JSON as the only
delta-spec source. If the `specs` entry is missing or
`existingOutputPaths` is empty, proceed without a sync prompt and do not infer
delta specs from other artifacts.
**If delta specs exist:**
- Compare each delta spec with its corresponding main spec at `<planningHome.root>/openspec/specs/<capability-path>/spec.md` (use the store-aware `planningHome.root` from step 2, not a hardcoded repo path)
- Determine what changes would be applied (adds, modifications, removals, renames)
- Show a combined summary before prompting
**Prompt options:**
- If changes needed: "Sync now (recommended)", "Archive without syncing"
- If already synced: "Archive now", "Sync anyway", "Cancel"
Route on the answer:
- "Cancel" — stop, do not archive
- "Archive without syncing" or "Archive now" — proceed to archive
- "Sync now" or "Sync anyway" — sync, then verify (below)
- Anything else — ask again rather than archiving
Before a selected sync writes any main spec, run
`openspec instructions specs --change "<name>" --json` once with the same
selected-root flags. Require a zero exit status and valid artifact-instruction
JSON. If the lookup fails or returns invalid JSON, report the error and stop
before writing any main spec or moving the change. A valid response with omitted
`rules` is the no-rules case. Apply returned `rules` only to the content and
form of main specs produced by this merge; do not use them as archive guidance,
change CLI behavior, or copy the rule text into any output file.
Then run the `openspec-sync-specs` workflow inline (agent-driven intelligent merge) for change '<name>', passing the delta spec analysis and the fetched specs-rule snapshot from above, and wait for it to finish. The inline sync must reuse that snapshot without fetching `specs` instructions again. Do not delegate it to a background task — step 5 would move `changeRoot` out from under a sync that is still reading it, leaving the change archived and the main specs never updated. If your agent can only run it by delegation, delegate synchronously and wait for the result.
Then re-run the comparison from the top of this step against every capability that has a delta spec in `artifactPaths.specs.existingOutputPaths` — not only the ones the sync reports it touched. A successful sync leaves nothing left to apply, so each capability must now read as already synced:
- ADDED requirements present
- MODIFIED requirements carrying the scenario and description changes named in the delta, with their other scenarios intact
- REMOVED requirements gone — and where this sync retired a capability (removed its last requirement, leaving `## Requirements` empty), its main spec deleted rather than left empty; a spec the sync deliberately kept and reported is also a match
- RENAMED requirements present under the new name and absent under the old one
If the sync failed, or any capability does not match, report what differs and stop — do not archive. Nothing has moved and `changeRoot` is intact, so the user can fix the mismatch or re-run the sync and start the archive again.
5. **Perform the archive**
Create an `archive` directory under `planningHome.changesDir` if it doesn't exist:
```bash
mkdir -p "<planningHome.changesDir>/archive"
```
Generate the target name: use the change name as-is when it already starts with a `YYYY-MM-DD-` prefix; otherwise prepend the current date as `YYYY-MM-DD-<change-name>`. Never stack a second date (same rule as `openspec archive`).
**Check if target already exists:**
- If yes: Fail with error, suggest renaming existing archive or using different date
- If no: Move `changeRoot` to the archive directory
```bash
mv "<changeRoot>" "<planningHome.changesDir>/archive/<target-name>"
```
6. **Display summary**
Show archive completion summary including:
- Change name
- Schema that was used
- Archive location
- Whether specs were synced (if applicable)
- Note about any warnings (incomplete artifacts/tasks)
**Output On Success**
```markdown
## Archive Complete
**Change:** <change-name>
**Schema:** <schema-name>
**Archived to:** the archive path derived from `planningHome.changesDir`/<target-name>/
**Specs:** <"✓ Synced to main specs" only if the step 4 verification passed; otherwise "No delta specs" or "Sync skipped">
<"All artifacts complete. All tasks complete." — or, if archived with warnings, list them instead (e.g. "Archived with 2 incomplete tasks")>
```
**Guardrails**
- Announce the selected change; prompt for selection when it is ambiguous
- Use artifact graph (openspec status --json) for completion checking
- Don't block archive on warnings - just inform and confirm
- Preserve .openspec.yaml when moving to archive (it moves with the directory)
- Show clear summary of what happened
- If sync is requested, run the `openspec-sync-specs` workflow inline (agent-driven)
- Never archive while a spec sync is still in flight — run the sync inline and verify the main specs before moving `changeRoot`
- If delta specs exist, always run the sync assessment and show the combined summary before prompting
- Apply relevant runtime context and report conflicts; operation guidance remains advisory
- Consider every guidance entry and explain any inapplicable or conflicting advice
- Existing CLI checks, resolved paths, prompts, and command contracts are unchanged
- Artifact rules constrain only the specs being written and are never operation guidance
- Never copy runtime context, operation guidance, or artifact-rule text verbatim into output files
+335
View File
@@ -0,0 +1,335 @@
---
name: openspec-explore
description: Enter explore mode - a thinking partner for exploring ideas, investigating problems, and clarifying requirements. Use when the user wants to think through something before or during a change.
allowed-tools: Bash(openspec:*)
license: MIT
compatibility: Requires openspec CLI.
metadata:
author: openspec
version: "1.0"
generatedBy: "1.12.0"
---
Enter explore mode. Think deeply. Visualize freely. Follow the conversation wherever it goes.
**IMPORTANT: Explore mode is for thinking, not implementing.** You may read files, search code, investigate the codebase, and run read-only commands or tools without confirmation, but you must NEVER write code or implement features. If the user asks you to implement something, remind them to exit explore mode first and create a change proposal. You MAY create or update OpenSpec change artifacts (proposals, designs, specs) within a confirmed scope—that's capturing thinking, not implementing. Answering design or clarifying questions is never consent to write. Before the first write-capable action, name the artifacts or files you would change and what you would do, ask a direct yes/no question, and wait for the user's confirmation in a separate message. Confirmation covers only the scope you described; ask again before expanding it. For a new change, scaffold it first as described below.
**This is a stance, not a workflow.** There are no fixed steps, no required sequence, no mandatory outputs. You're a thinking partner helping the user explore.
**Store selection:** If the user names a store (a store is a standalone OpenSpec repo registered on this machine) or the work lives in one, run `openspec store list --json` to discover registered store ids, then pass `--store <id>` on the commands that read or write specs and changes (`new change`, `status`, `instructions`, `list`, `show`, `validate`, `archive`, `doctor`, `context`, `schemas`, `view`). Once selected, treat `--store <id>` as sticky for the rest of the workflow. Every unscoped example of those commands below is shorthand: before running it, append the flag. For example, run `openspec status --change "<name>" --json --store "<id>"`, not the unscoped form shown below. Other commands do not take the flag. Hints printed by commands already carry the flag; keep it on follow-ups. Without a store, commands act on the nearest local `openspec/` root.
---
## The Stance
- **Curious, not prescriptive** - Ask questions that emerge naturally, don't follow a script
- **Open threads, not interrogations** - Surface multiple interesting directions and let the user follow what resonates. Don't funnel them through a single path of questions.
- **Visual** - Use ASCII diagrams liberally when they'd help clarify thinking
- **Adaptive** - Follow interesting threads, pivot when new information emerges
- **Patient** - Don't rush to conclusions, let the shape of the problem emerge
- **Grounded** - Explore the actual codebase when relevant, don't just theorize
---
## Planning a Change
When the user is planning a change, guide them toward shared understanding with focused discovery questions. For open-ended discussion, follow the conversation without imposing an interview or a required output.
Before asking a factual question, follow the context discovery below and inspect relevant OpenSpec artifacts, source, tests, docs, and configuration. Do not ask the user to repeat facts you can verify. Summarize relevant findings without reproducing private context or rules. If evidence is missing, conflicting, or inaccessible, state that limitation and ask only for the clarification needed to proceed.
- **Follow dependencies** - Resolve the next blocking decision before its dependent details. For example, clarify the user's outcome and scope before choosing an API or data model. Revisit downstream assumptions when an earlier answer changes. Skip branches that do not matter to this goal.
- **Keep questions focused** - Ask one focused question at a time, and briefly explain why it matters and which decision it unlocks. Batch questions only if the user asks for a batch; keep them small and group related decisions.
- **Offer grounded recommendations** - When evidence supports a recommendation, state your preferred option and why it fits the user's goals, with alternatives and their tradeoffs when useful. Do not invent intent, priorities, or external constraints: ask the user when only they can answer. Avoid a fixed question format.
- **Keep a conversational record** - Track decisions in the conversation, not in files. Separate confirmed decisions from proposed defaults and unresolved questions. Silence is not acceptance. Accepting an answer or a batch of recommendations is not permission to write. Keep file-write confirmation separate from discovery questions and follow the guardrails below.
Stop asking when the user has enough clarity. Let them pause, pivot, or defer a decision; do not exhaust every branch or force a proposal.
For example, after inspecting the relevant code:
```text
The CLI already uses SQLite and has no remote service. Is sharing state
across devices in scope? That determines whether local storage is enough.
If this stays a single-device tool, I recommend keeping SQLite to avoid
adding a service to operate; shared state would need a separate sync design.
```
---
## What You Might Do
Depending on what the user brings, you might:
**Explore the problem space**
- Ask clarifying questions that emerge from what they said
- Challenge assumptions
- Reframe the problem
- Find analogies
**Investigate the codebase**
- Map existing architecture relevant to the discussion
- Find integration points
- Identify patterns already in use
- Surface hidden complexity
**Compare options**
- Brainstorm multiple approaches
- Build comparison tables
- Sketch tradeoffs
- Recommend a path (if asked)
**Visualize**
```
+------------------------------------------+
| Use ASCII diagrams liberally |
+------------------------------------------+
| |
| [State A] -------> [State B] |
| | |
| v |
| [State C] |
| |
| System diagrams, state machines, |
| data flows, architecture sketches, |
| dependency graphs, comparison tables |
| |
+------------------------------------------+
```
**Draw with plain ASCII only** — borders `+` `-` `|`, arrows `-->` `<--` `^` `v`, markers `*` `x`.
Unicode diagram glyphs can render at different widths across terminals, fonts, and locales, so padded boxes and aligned tables can drift. Keep every diagram character ASCII.
**Surface risks and unknowns**
- Identify what could go wrong
- Find gaps in understanding
- Suggest spikes or investigations
---
## OpenSpec Awareness
You have full context of the OpenSpec system. Use it naturally, don't force it.
### Check for context
At the start, quickly check what exists:
```bash
openspec list --json
```
This tells you:
- If there are active changes
- Their names, schemas, and status
- What the user might be working on
Then read the project's own context from the resolved root - `<root.path>/openspec/config.yaml` (or `config.yml`). Use the `root.path` returned above, and skip this if neither file exists:
- `context`: project background - tech stack, conventions, constraints
- `rules`: keyed by artifact id - the entries for an artifact apply only when you write that artifact
Ground your thinking in these. They are constraints for you to follow, not content to reproduce: do NOT copy them into the conversation or into any artifact you create.
### When no change exists
Think freely. When insights crystallize, you might offer:
- "This feels solid enough to start a change. Want me to create a proposal?"
- Or keep exploring - no pressure to formalize
If the user asks you to capture the exploration as a new change, transition seamlessly into the requested capture:
1. Run `openspec new change "<name>"` (with `--store <id>` when applicable) before creating any artifacts. Never create a new change directory under `openspec/changes/` by hand; the CLI scaffold creates required metadata such as `.openspec.yaml`. Keep the selected `--store <id>` on every applicable follow-up `status` and `instructions` command.
2. Run `openspec status --change "<name>" --json` (append the confirmed `--store "<id>"` only for a registered standalone store), then process the requested artifacts in dependency order. For each requested artifact that is `ready`, run `openspec instructions "<artifact-id>" --change "<name>" --json` (append the confirmed `--store "<id>"` only for a registered standalone store). Before creating a requested artifact, evaluate any condition in its own `instruction` against the explored change; record a deliberate skip instead when the condition does not apply. If a requested artifact is blocked by a direct prerequisite the user did not request, run `openspec instructions "<prerequisite-id>" --change "<name>" --json` (append the confirmed `--store "<id>"` only for a registered standalone store) for that prerequisite whether it is `ready` or `blocked`. If its own `instruction` states a condition, evaluate that condition against the explored change and record a deliberate skip only when the condition does not apply. If the condition applies, or the prerequisite is not conditional, treat it as a normal prerequisite and ask before expanding the capture. Do not create an unrequested prerequisite unless the user approves.
3. Follow the returned `template` and `instruction` fields. Read completed dependency files listed in `dependencies`, and apply `context` and `rules` as constraints without copying them into the artifact. If the instruction delegates creation to a specific skill or command, invoke it; otherwise write the artifact to `resolvedOutputPath`, using the instruction to choose a concrete path when it is a glob. Verify that the selected concrete output exists.
4. After creating each artifact, re-run `openspec status --change "<name>" --json` (append the confirmed `--store "<id>"` only for a registered standalone store) and continue until every requested artifact is `done`, `skipped`, or was deliberately skipped because its own `instruction` stated a condition that did not apply. Tell the user about a deliberate conditional skip, remember it, and do not reconsider it. Dependencies are enablers, not gates: if a requested artifact is still `blocked` only because you deliberately skipped a conditional prerequisite, run `openspec instructions "<artifact-id>" --change "<name>" --json` (append the confirmed `--store "<id>"` only for a registered standalone store) despite the blocked status, then create it using step 3 only when those recorded conditional skips are its sole missing dependencies. If a requested artifact is blocked by a prerequisite the user did not ask to capture and cannot be conditionally skipped, explain that dependency and ask before expanding the capture.
Capture the artifact(s) the user requested without asking them to invoke another workflow command. If they asked only to start a change, stop after scaffolding and show its status.
### When a change exists
If the user mentions a change or you detect one is relevant:
1. **Resolve and read existing artifacts for context**
- Run `openspec status --change "<name>" --json`.
- Use `changeRoot`, `artifactPaths`, and `actionContext` from the status JSON.
- Read existing files from `artifactPaths.<artifact>.existingOutputPaths`.
2. **Reference them naturally in conversation**
- "Your design mentions using Redis, but we just realized SQLite fits better..."
- "The proposal scopes this to premium users, but we're now thinking everyone..."
3. **Offer to capture when decisions are made**
`<capability-path>` is the spec directory relative to `specs/` (for example, `user-auth` or `identity/user-auth`). Preserve an existing capability's full path and follow the project's established organization for new capabilities.
| Insight Type | Where to Capture |
|----------------------------|-------------------------------------|
| New requirement discovered | `specs/<capability-path>/spec.md` |
| Requirement changed | `specs/<capability-path>/spec.md` |
| Design decision made | `design.md` |
| Scope changed | `proposal.md` |
| New work identified | `tasks.md` |
| Assumption invalidated | Relevant artifact |
Example offers:
- "That's a design decision. Capture it in design.md?"
- "This is a new requirement. Add it to specs?"
- "This changes scope. Update the proposal?"
4. **The user decides** - Offer and move on. Don't pressure. Don't auto-capture.
---
## What You Don't Have To Do
- Follow a script
- Ask the same questions every time
- Produce a specific artifact
- Reach a conclusion
- Stay on topic if a tangent is valuable
- Be brief (this is thinking time)
---
## Handling Different Entry Points
**User brings a vague idea:**
```
User: I'm thinking about adding real-time collaboration
You: Real-time collab is a big space. Let me think about this...
COLLABORATION SPECTRUM
============================================
Awareness Coordination Sync
| | |
v v v
+--------+ +--------+ +--------+
|Presence| |Cursors | | CRDT |
| "3 | | Multi | |Conflict|
|online" | | select | | free |
+--------+ +--------+ +--------+
| | |
trivial moderate complex
Where's your head at?
```
**User brings a specific problem:**
```
User: The auth system is a mess
You: [reads codebase]
+---------------------------------------------+
| CURRENT AUTH FLOW |
+---------------------------------------------+
|
+-------------+-------------+
v v v
+---------+ +---------+ +---------+
| Google | | GitHub | | Email |
| OAuth | | OAuth | | Magic |
+----+----+ +----+----+ +----+----+
| | |
+-------------+-------------+
v
+-----------+
| Session |
+-----+-----+
|
v
+-----------+
| Perms |
+-----------+
I see three tangles. Which one's burning?
```
**User is stuck mid-implementation:**
```
User: /openspec-explore add-auth-system
The OAuth integration is more complex than expected
You: [reads change artifacts]
You're on task 4: "Implement OAuth flow"
Let me trace what's involved...
[draws diagram, explores options, suggests paths]
Want to update the design to reflect this?
Or add a spike task to investigate?
```
**User wants to compare options:**
```
User: Should we use Postgres or SQLite?
You: Generic answer is boring. What's the context?
User: A CLI tool that tracks local dev environments
You: That changes everything.
+-------------------------------------------------+
| CLI TOOL DATA STORAGE |
+-------------------------------------------------+
Key constraints:
- No daemon running
- Must work offline
- Single user
SQLite Postgres
Deployment embedded needs server
Offline yes no
Single file yes no
SQLite. Not even close.
Unless... is there a sync component?
```
---
## Ending Discovery
There's no required ending. Discovery might:
- **Flow into a proposal**: "Ready to start? I can create a change proposal."
- **Result in artifact updates**: "Updated design.md with these decisions"
- **Just provide clarity**: User has what they need, moves on
- **Continue later**: "We can pick this up anytime"
When it feels like things are crystallizing, you might summarize:
```
## What We Figured Out
**The problem**: [crystallized understanding]
**The approach**: [if one emerged]
**Open questions**: [if any remain]
**Next steps** (if ready):
- Create a change proposal
- Keep exploring: just keep talking
```
But this summary is optional. Sometimes the thinking IS the value.
---
## Guardrails
- **Don't implement** - Never write code or implement features. Workflow configuration counts too: creating or editing schemas, templates, or `openspec/config.yaml` is a change, not thinking. Creating or updating OpenSpec change artifacts within the confirmed scope is fine, writing anything else is not.
- **Don't fake understanding** - If something is unclear, dig deeper
- **Don't rush** - Discovery is thinking time, not task time
- **Don't force structure** - Let patterns emerge naturally
- **Don't auto-capture** - Offer to save insights, don't just do it. Read-only commands and tools need no confirmation. Before the first write-capable action—including `openspec new change` or another command that writes files—name the artifacts or files and proposed changes, ask a direct yes/no question, and wait for explicit confirmation in a separate user message. That confirmation covers only the described scope; ask again before expanding it. Answers to design or clarifying questions are never consent to write.
- **Don't manually scaffold changes** - Never create a new change directory under `openspec/changes/` by hand. Always use `openspec new change "<name>"` (with `--store <id>` when applicable) so required metadata such as `.openspec.yaml` is created before writing artifacts.
- **Do visualize** - A good diagram is worth many paragraphs
- **Do explore the codebase** - Ground discussions in reality
- **Do question assumptions** - Including the user's and your own
+153
View File
@@ -0,0 +1,153 @@
---
name: openspec-propose
description: Propose a new change with all artifacts generated in one step. Use when the user wants to quickly describe what they want to build and get a complete proposal with design, specs, and tasks ready for implementation.
allowed-tools: Bash(openspec:*)
license: MIT
compatibility: Requires openspec CLI.
metadata:
author: openspec
version: "1.0"
generatedBy: "1.12.0"
---
Propose a new change - create the change and generate all artifacts in one step.
**Planning boundary**: This workflow creates planning artifacts only. The user request that selected or triggered this workflow authorizes planning only, even if it asks to build or fix something. Do not edit project code. After the planning artifacts are complete, stop. Do not start implementation in the same response, even if the initial request asks for it. Wait for a new user request after the artifacts are presented; then start the apply workflow.
I'll create a change with the artifacts your schema defines. With the default spec-driven schema that is:
- proposal.md (what & why)
- `specs/<capability-path>/spec.md` (what the system must do - a delta, not the main spec)
- design.md (how)
- tasks.md (implementation steps)
`<capability-path>` is the spec directory relative to `specs/` (for example, `user-auth` or `identity/user-auth`). Preserve an existing capability's full path and follow the project's established organization for new capabilities.
When the user is ready to implement, they must start the apply workflow explicitly.
---
**Store selection:** If the user names a store (a store is a standalone OpenSpec repo registered on this machine) or the work lives in one, run `openspec store list --json` to discover registered store ids, then pass `--store <id>` on the commands that read or write specs and changes (`new change`, `status`, `instructions`, `list`, `show`, `validate`, `archive`, `doctor`, `context`, `schemas`, `view`). Once selected, treat `--store <id>` as sticky for the rest of the workflow. Every unscoped example of those commands below is shorthand: before running it, append the flag. For example, run `openspec status --change "<name>" --json --store "<id>"`, not the unscoped form shown below. Other commands do not take the flag. Hints printed by commands already carry the flag; keep it on follow-ups. Without a store, commands act on the nearest local `openspec/` root.
**Input**: The user's request should include a change name (kebab-case) OR a description of what they want to build.
**Steps**
1. **Understand the request and clarify material ambiguity**
If no clear input is provided, ask the user (open-ended, no preset options):
> "What change do you want to work on? Describe what you want to build or fix."
From their description, derive a kebab-case name (e.g., "add user authentication" → `add-user-auth`).
**IMPORTANT**: Do NOT proceed without understanding what the user wants to build.
If the request contains ambiguity that would materially affect scope, externally observable behavior, compatibility, or acceptance criteria, ask the user before creating the change. For minor details, make a reasonable assumption and record it in the planning artifacts.
2. **Determine the workflow schema**
Use the configured default schema unless the user explicitly requests a different workflow.
**Use a different schema only if the user:**
- Explicitly requests a specific schema by name → use `--schema <schema-name>`
- Asks to "show workflows" or asks "what workflows" exist → resolve the authoritative root by running `openspec context --json` from the current working directory. If the user explicitly selected a registered store, use `openspec context --json --store "<store-id>"`. Then run `openspec schemas --json` with its working directory set to the returned `root.path` and let them choose. This preserves roots selected by a local `store:` pointer or the global `defaultStore`; when a registered store was explicitly selected, append `--store "<store-id>"` to `openspec schemas --json` as well. If context reports only `no_openspec_root`, run `openspec schemas --json` from the current working directory instead. Do not use this fallback for invalid or unavailable stores.
Otherwise, omit `--schema` to preserve the configured default.
3. **Create the change directory**
Choose one schema form below. If a registered store is selected, append `--store "<store-id>"` to that command and each later OpenSpec command shown below that accepts `--store`.
Using the configured default:
```bash
openspec new change "<name>"
```
Using an explicitly requested schema:
```bash
openspec new change "<name>" --schema "<schema-name>"
```
This creates a scaffolded change in the planning home resolved by the CLI with `.openspec.yaml`.
4. **Get the artifact build order**
```bash
openspec status --change "<name>" --json
```
Parse the JSON to get:
- `applyRequires`: array of artifact IDs needed before implementation (e.g., `["tasks"]`)
- `artifacts`: list of all artifacts, each with its `status` and its `requires` edges (the artifact IDs it directly depends on)
- `planningHome`, `changeRoot`, `artifactPaths`, and `actionContext`: path and scope context. Use these instead of assuming repo-local paths.
5. **Create every artifact in the required set**
Use a todo list to track progress through the artifacts.
Loop through artifacts in dependency order (artifacts with no pending dependencies first):
a. **For each artifact that is `ready` (dependencies satisfied)**:
- Get instructions:
```bash
openspec instructions <artifact-id> --change "<name>" --json
```
- The instructions JSON includes:
- `context`: Project background (constraints for you - do NOT include in output)
- `rules`: Artifact-specific rules (constraints for you - do NOT include in output)
- `template`: The structure to use for your output file
- `instruction`: Schema-specific guidance for this artifact type
- `skipped`/`warning`: present when the change declares skip_specs and this artifact must NOT be created - stop and pick another artifact
- `resolvedOutputPath`: Resolved path or pattern to write the artifact
- `dependencies`: Completed artifacts to read for context
- Read any completed dependency files for context - always re-read them from disk, even if you saw them earlier in the conversation (the user may have edited them)
- **Inspect the relevant project before drafting**: Read `context` and `rules` first, then inspect relevant implementation, nearby tests, configuration, and documentation outside `openspec/`. Keep inspection read-only and proportional to the change; reuse findings for later artifacts and inspect more only as needed.
- Identify the target project from the request and project context; the planning home may be separate from the code. If the target is unclear, ask. For greenfield or non-code changes, inspect the available structure and relevant documents. If source is unavailable, state the limitation and ask when it materially affects the plan.
- Ground scope, approach, and tasks in what you find. Distinguish observed behavior from assumptions and proposed additions; surface conflicts with existing specs instead of silently deciding which is correct.
- Do this discovery now, rather than leaving generic "explore the codebase" or "make a plan" tasks for implementation. Keep any necessary follow-up investigation specific to an unresolved question.
- If the `instruction` field delegates creation to a specific skill or command, invoke it to produce the artifact instead of writing the file yourself, then verify the artifact file exists at `resolvedOutputPath`
- Otherwise create the artifact file using `template` as the structure and write it to `resolvedOutputPath`. If `resolvedOutputPath` is a glob, follow `instruction` to choose the concrete file path
- Apply `context` and `rules` as constraints - but do NOT copy them into the file
- Show brief progress: "Created <artifact-id>"
b. **Continue until every artifact in the required set exists (not just `apply.requires`)**
- After creating each artifact, re-run `openspec status --change "<name>" --json`
- The required set is `applyRequires` plus every artifact reachable from those by following the `requires` edges in `status --json` - walk them transitively (spec-driven closes over proposal, specs, design, tasks). Leave artifacts outside that set alone
- `status` is file-existence only, so an `applyRequires` artifact reading `done` does NOT mean its dependencies exist - writing `tasks.md` early marks `tasks` done while `specs` was never written. Use each artifact's `requires` edges, not its `status`, to build the required set: a `done` artifact still lists what it depends on
- An artifact already reading `status: "skipped"` is satisfied: the change declares `skip_specs` in `.openspec.yaml`, so its files must NOT exist. Never try to create one
- Create every artifact in the required set that is missing, then re-check - creating one can unblock others
- Skip one only when `status` already reports it `skipped`, or when its own `instruction` says it is conditional: run `openspec instructions <artifact-id> --change "<name>" --json` and skip only if its `instruction` field marks it optional (e.g. "create only if..."). Spec-driven's `design.md` qualifies; `specs` qualifies only via the `skipped` status above, never by your own judgment. Tell the user, and do not reconsider it
- Dependencies are enablers, not gates: if a required artifact is still `blocked` only because you skipped a conditional dependency, write it anyway
- Stop when every artifact in the required set is `done`, `skipped`, or was deliberately skipped
c. **If an artifact requires user input** (unclear context):
- Ask the user to clarify
- Then continue with creation
6. **Show final status**
```bash
openspec status --change "<name>"
```
**Output**
After completing all artifacts, summarize:
- Change name and location
- List of artifacts created with brief descriptions, plus any conditional artifact you skipped and why
- What's ready: "All artifacts needed for implementation are ready."
- Prompt: "The artifacts are ready for review. When you are ready, run `/openspec-apply-change` or ask me to apply this change."
**Artifact Creation Guidelines**
- Follow the `instruction` field from `openspec instructions` for each artifact type - it is the authoritative guidance, even for familiar artifact names
- If the `instruction` field directs you to use a specific skill or command to create the artifact, invoke it instead of writing the artifact directly
- The schema defines what each artifact should contain - follow it
- Read dependency artifacts for context before creating new ones
- Use `template` as the structure for your output file - fill in its sections
- **IMPORTANT**: `context` and `rules` are constraints for YOU, not content for the file
- Do NOT copy `<context>`, `<rules>`, `<project_context>` blocks into the artifact
- These guide what you write, but should never appear in the output
**Guardrails**
- The request that invoked this workflow authorizes planning only. Any implementation or apply instruction in that request does not carry forward. Do NOT implement the change, start the apply workflow, or edit project code during this workflow. After presenting the artifacts, stop and wait for a new user request to start the apply workflow
- Create every artifact the apply phase transitively depends on, not just the ids listed in `apply.requires`
- Always read dependency artifacts before creating a new one - re-read from disk, not from conversation memory (files may have changed since you last saw them)
- Ask about ambiguities that would materially change scope, externally observable behavior, compatibility, or acceptance criteria; for minor details, make reasonable assumptions and record them
- If a change with that name already exists, ask if user wants to continue it or create a new one
- Verify each artifact file exists after writing before proceeding to next
+262
View File
@@ -0,0 +1,262 @@
---
name: openspec-sync-specs
description: Sync delta specs from a change to main specs. Use when the user wants to update main specs with changes from a delta spec, without archiving the change.
allowed-tools: Bash(openspec:*)
license: MIT
compatibility: Requires openspec CLI.
metadata:
author: openspec
version: "1.0"
generatedBy: "1.12.0"
---
Sync delta specs from a change to main specs.
This is an **agent-driven** operation - you will read delta specs and directly edit main specs to apply the changes. This allows intelligent merging (e.g., adding a scenario without copying the entire requirement).
**Store selection:** If the user names a store (a store is a standalone OpenSpec repo registered on this machine) or the work lives in one, run `openspec store list --json` to discover registered store ids, then pass `--store <id>` on the commands that read or write specs and changes (`new change`, `status`, `instructions`, `list`, `show`, `validate`, `archive`, `doctor`, `context`, `schemas`, `view`). Once selected, treat `--store <id>` as sticky for the rest of the workflow. Every unscoped example of those commands below is shorthand: before running it, append the flag. For example, run `openspec status --change "<name>" --json --store "<id>"`, not the unscoped form shown below. Other commands do not take the flag. Hints printed by commands already carry the flag; keep it on follow-ups. Without a store, commands act on the nearest local `openspec/` root.
`<capability-path>` is the spec directory relative to `specs/` (for example, `user-auth` or `identity/user-auth`). Preserve the full path from each delta spec when resolving its main spec.
**Input**: Optionally specify a change name. If omitted, check if it can be inferred from conversation context. If vague or ambiguous you MUST prompt for available changes.
**Steps**
1. **Select the change**
If a name is provided, use it. Otherwise:
- Infer from conversation context if the user mentioned a change
- Auto-select if only one active change exists
- If ambiguous, run `openspec list --json` to get available changes and ask the user to select one
When prompting, show changes that have delta specs (under `specs/` directory).
Always announce: "Using change: <name>" and how to override (e.g., `/openspec-sync-specs <other>`).
2. **Resolve change context**
Run:
```bash
openspec status --change "<name>" --json
```
The JSON includes `planningHome.root`. Main specs live under `<planningHome.root>/openspec/specs/` — use that (store-aware) root for every main-spec path below, not a hardcoded repo path. When a store is selected it points at the store, not the current repository.
3. **Find delta specs**
Use `artifactPaths.specs.existingOutputPaths` from the status JSON as the
only source of delta spec paths. If the `specs` entry is missing or
`existingOutputPaths` is empty, report that there are no delta specs to sync,
do not infer them from other artifacts, and stop without requesting artifact
instructions or writing a main spec.
Sync every path in `existingOutputPaths` unless the caller narrowed the set.
A caller narrows it by naming an explicit list of complete entries from
`existingOutputPaths` — copy those absolute values verbatim. Archive does
this inline, and a user can too (for example, by selecting the entry ending
in `/specs/billing/invoices/spec.md`).
Then sync only the named paths and leave the remaining delta specs untouched:
bulk archive excludes a delta whose implementation it could not find, and
syncing it anyway would write a main spec the caller deliberately withheld.
Carry that narrowed selection through step 4; never widen it back to the full
list. If a named path is not in `existingOutputPaths`, do not sync it —
report it and stop, rather than dropping it silently. If the named list is
empty, report that there is nothing to sync and stop without writing a main
spec.
Each delta spec file contains sections like:
- `## ADDED Requirements` - New requirements to add
- `## MODIFIED Requirements` - Changes to existing requirements
- `## REMOVED Requirements` - Requirements to remove
- `## RENAMED Requirements` - Requirements to rename (FROM:/TO: format)
If no delta specs found, inform user and stop.
4. **For each delta spec, apply changes to main specs**
Before the first main-spec write, obtain one current specs-rule snapshot:
- If archive invoked this workflow inline and supplied a valid snapshot from
`openspec instructions specs --change "<name>" --json`, reuse it and do not
fetch the same instructions again.
- Otherwise run that command once now with the same selected-root flags.
- If the direct lookup exits non-zero or returns invalid artifact-instruction
JSON, report the error and stop before writing any main spec. Do not treat the
failure as an absent rule set.
- A valid response with omitted `rules` means no artifact rules are configured
and the existing semantic merge continues.
Apply returned `rules` only to the content and form of the main specs produced
by this merge. Artifact rules are not operation guidance and cannot change
selected roots, delta paths, CLI checks, or workflow steps. Use their text as
constraints without copying it verbatim into a main spec or summary.
For each capability delta spec path selected in step 3 — the full `existingOutputPaths` list, or the narrowed subset when a caller supplied one (these may belong to a selected store, not the repo):
a. **Read the delta spec** to understand the intended changes
b. **Read the main spec** at `<planningHome.root>/openspec/specs/<capability-path>/spec.md` (may not exist yet)
c. **Apply changes intelligently**:
**ADDED Requirements:**
- If requirement doesn't exist in main spec → add it
- If requirement already exists → update it to match (treat as implicit MODIFIED)
**MODIFIED Requirements:**
- Find the requirement in main spec
- Apply the changes - this can be:
- Adding new scenarios the main spec does not have yet
- Modifying existing scenarios
- Changing the requirement description
- Preserve scenarios/content not mentioned in the delta
**REMOVED Requirements:**
- Remove the entire requirement block from main spec
- Retiring the capability. Delete the whole `spec.md` - and the directory once
nothing else is left in it - only when ALL of these hold:
1. removing the requirements *this run* left no requirement blocks;
2. the rest of the spec is well-formed (it still has a `## Purpose`);
3. the main spec was not already empty before this sync - if you removed
nothing, change nothing;
4. every other nonblank line in the whole file is accounted for as the
title, Purpose, Requirements header, or a canonical requirement's
statement, scenarios, or fenced examples;
5. the change's `.openspec.yaml` declares `retire_capabilities: true`;
6. the `spec.md` resolves inside the real specs root (do not follow a
capability-directory symlink to delete an external file).
If removing the selected requirements would leave no requirement blocks and
any retirement condition is not satisfied, do not modify the main spec. Stop
the sync for that capability, report the blocking condition, and tell the user
how to resolve it. Never write or leave an empty `## Requirements` section.
When only the marker is missing, say that too - it is the one thing the user
can add to make the retirement go through.
- Deleting the file also deletes its `## Purpose`; any other section blocks
retirement. Name Purpose when you report the retirement. Include a pasteable
`git checkout` only when the spec lived in the caller's checkout;
otherwise give checkout-scoped recovery guidance.
**RENAMED Requirements:**
- Find the FROM requirement, rename to TO
**`## Purpose` in the delta:**
- The main spec already has one and it is authoritative - leave it alone
(this is what `openspec archive` does; it warns and moves on)
d. **Create new main spec** if capability doesn't exist yet:
- Create `<planningHome.root>/openspec/specs/<capability-path>/spec.md`
- Add Purpose section: copy the delta's `## Purpose` body verbatim when it has one
(this is what `openspec archive` does); only write a brief TBD placeholder when it does not
- Add Requirements section with the ADDED requirements
- Follow the **Main Spec Format Reference** below
5. **Validate updated main specs**
Run `openspec validate --specs` with the same selected-root flags used earlier.
If validation fails, report the problems and do not claim the sync succeeded.
6. **Show summary**
After applying all changes, summarize:
- Which capabilities were updated
- What changes were made (requirements added/modified/removed/renamed)
- Any new main spec left with a TBD Purpose placeholder, so it gets written
now rather than lingering
- Any capability retired, naming the deleted `spec.md`, its Purpose, and
either a pasteable `git checkout` or checkout-scoped recovery guidance
**Delta Spec Format Reference**
```markdown
## Purpose
Only on a delta that introduces a brand-new capability. Seeds the new main spec.
## ADDED Requirements
### Requirement: New Feature
The system SHALL do something new.
#### Scenario: Basic case
- **WHEN** user does X
- **THEN** system does Y
## MODIFIED Requirements
### Requirement: Existing Feature
The system SHALL keep doing the existing thing, now also handling A.
#### Scenario: Scenario the main spec already has
- **WHEN** user does X
- **THEN** system does Y
#### Scenario: New scenario to add
- **WHEN** user does A
- **THEN** system does B
## REMOVED Requirements
### Requirement: Deprecated Feature
## RENAMED Requirements
- FROM: `### Requirement: Old Name`
- TO: `### Requirement: New Name`
```
**Main Spec Format Reference**
Main specs are what the delta merges INTO. They must never contain delta operation headers (`## ADDED/MODIFIED/REMOVED/RENAMED Requirements`) - after syncing, every requirement lives under a single `## Requirements` section:
```markdown
# <capability> Specification
## Purpose
Short description of what this capability does and why it exists.
## Requirements
### Requirement: New Feature
The system SHALL do something new.
#### Scenario: Basic case
- **WHEN** user does X
- **THEN** system does Y
```
**Key Principle: Intelligent Merging**
Unlike programmatic merging, you merge rather than overwrite:
- A MODIFIED block carries the whole requirement - body plus every scenario that survives the change. `openspec validate` and `openspec archive` both reject one that drops a scenario the main spec still has.
- Keep anything the delta does not mention, in the main spec's existing order
- Use your judgment to merge changes sensibly
**Output On Success**
```markdown
## Specs Synced: <change-name>
Updated main specs:
**<capability-1>**:
- Added requirement: "New Feature"
- Modified requirement: "Existing Feature" (added 1 scenario)
**<capability-2>**:
- Created new spec file
- Added requirement: "Another Feature"
Main specs are now updated. The change remains active - archive when implementation is complete.
```
**Guardrails**
- Read both delta and main specs before making changes
- Preserve existing content not mentioned in delta
- Never copy a delta file into a main spec as-is - merge its content so the main spec keeps the Main Spec Format Reference structure, with no delta operation headers
- If something is unclear, ask for clarification
- Show what you're changing as you go
- The operation should be idempotent - running twice should give same result
- Use only `artifactPaths.specs.existingOutputPaths`; never infer delta specs from unrelated artifacts
- Honor a caller-supplied subset of `existingOutputPaths`; never widen it back to the full list
- Fetch specs instructions once for direct sync, or reuse the archive-supplied snapshot inline
- Stop before every main-spec write on a non-zero or invalid JSON specs-instruction response
- Artifact rules constrain only the specs being written and are never copied into output files
@@ -0,0 +1,91 @@
---
name: openspec-update-change
description: Update an OpenSpec change by revising its existing planning artifacts and keeping them coherent with one another. Use when the user wants to revise a change's plan, fold new decisions into it, or reconcile its artifacts after an edit. Never edits code.
allowed-tools: Bash(openspec:*)
license: MIT
compatibility: Requires openspec CLI.
metadata:
author: openspec
version: "1.0"
generatedBy: "1.12.0"
---
Revise a change's existing planning artifacts and keep them coherent. Never edit code.
**Store selection:** If the user names a store (a store is a standalone OpenSpec repo registered on this machine) or the work lives in one, run `openspec store list --json` to discover registered store ids, then pass `--store <id>` on the commands that read or write specs and changes (`new change`, `status`, `instructions`, `list`, `show`, `validate`, `archive`, `doctor`, `context`, `schemas`, `view`). Once selected, treat `--store <id>` as sticky for the rest of the workflow. Every unscoped example of those commands below is shorthand: before running it, append the flag. For example, run `openspec status --change "<name>" --json --store "<id>"`, not the unscoped form shown below. Other commands do not take the flag. Hints printed by commands already carry the flag; keep it on follow-ups. Without a store, commands act on the nearest local `openspec/` root.
**Input**: Optionally specify a change name. If omitted, check if it can be inferred from conversation context. If vague or ambiguous you MUST prompt for available changes.
`/openspec-continue-change` is an optional workflow and may not be installed. Before suggesting it anywhere below, verify that it is available. If it is unavailable, `openspec status --change "<name>" --json` shows the next artifact and `openspec instructions "<artifact-id>" --change "<name>" --json` explains how to create it.
**Steps**
1. **Select the change**
If a name is provided, use it. Otherwise:
- Infer from conversation context if the user mentioned a change
- Auto-select if only one active change exists
- If ambiguous, run `openspec list --json` to get available changes sorted by most recently modified, and ask the user to select one
When prompting, present the top 3-4 most recently modified changes as options, showing:
- Change name
- Schema (from `schema` field if present, otherwise "spec-driven")
- Status (e.g., "0/5 tasks", "complete", "no tasks")
- How recently it was modified (from `lastModified` field)
Mark the most recently modified change as "(Recommended)" since it's likely what the user wants to update.
Always announce: "Using change: <name>" and how to override (e.g., `/openspec-update-change <other>`).
2. **Get the change's artifacts**
```bash
openspec status --change "<name>" --json
```
Parse the JSON to understand current state. The response includes:
- `schemaName`: The workflow schema being used (e.g., "spec-driven")
- `artifacts`: Array of artifacts with their status ("done", "skipped", "ready", "blocked")
- `isPlanningComplete`: Boolean indicating if all planning artifacts are complete. Older CLI versions expose the same value as `isComplete`.
- `planningHome`, `changeRoot`, `artifactPaths`, and `actionContext`: path and scope context. Use these instead of assuming repo-local paths.
The artifact ids and paths come from the active schema - do NOT assume them, and do NOT branch on hardcoded artifact names. Custom schemas must work unchanged.
The files to edit are `artifactPaths.<id>.existingOutputPaths` - the concrete files that exist on disk, already glob-expanded for glob artifacts (e.g. `specs/**/*.md`). Do NOT write to `resolvedOutputPath`: for a glob artifact it is still the glob pattern, not a real file.
3. **Understand the request**
- If the user asked for a specific revision ("the design now uses X"), that is the starting edit.
- If they only said "update" / "make this coherent", treat it as a coherence review: read the existing artifacts and check them against each other for contradictions, gaps, and duplication.
4. **Read and reconcile**
- Read the artifact(s) the request touches and the change's other existing artifacts.
- Apply the requested edit. Then check every other existing artifact against it - in ANY direction: an edit to a later artifact may require revising an earlier one, not only the other way around. Build order is a useful reading order, not a constraint on which artifacts may be revised.
- Note everything that is now inconsistent, missing, or contradictory.
- Revise only files that already exist (`existingOutputPaths`). Do NOT create artifacts that don't exist yet, and do NOT invent new files under a glob artifact - note them and point the user to `/openspec-continue-change` to create them.
- If the change is already coherent, say so and make no edits.
5. **Confirm and apply, one artifact at a time**
- Show each proposed revision and why. Write only after the user confirms.
- If the user rejects a revision, do not write it - leave that artifact unchanged.
- When a substantial rewrite is needed, get that artifact's rules and template first:
```bash
openspec instructions "<artifact-id>" --change "<name>" --json
```
6. **Point to the next step (guidance only - NEVER act on it)**
- Artifacts still missing -> suggest `/openspec-continue-change` to create them.
- Change already implemented (tasks checked off / already applied) -> the code may no longer match the revised plan; suggest `/openspec-apply-change` to carry the delta into code.
- Everything done and implemented -> suggest `/openspec-archive-change`.
**Output**
After each invocation, show:
- Which artifacts were revised (and which proposed revisions were rejected)
- Anything deferred to `/openspec-continue-change` (not-yet-created artifacts or files)
- Where the change stands and the recommended next command
**Guardrails**
- Planning artifacts only - NEVER edit implementation code. If the revised plan implies code changes, stop and point to `/openspec-apply-change`.
- Use the artifact ids and paths reported by `openspec status`; never branch on hardcoded artifact names.
- Edit only the concrete files in `existingOutputPaths`; never write to a glob `resolvedOutputPath`.
- Do not advance the build frontier: no new artifacts, no new files under glob artifacts - that is `/openspec-continue-change`'s job.
- Confirm every edit with the user before writing.
- If the request changes the change's *intent* rather than refining it, first verify whether the optional `/openspec-new-change` workflow is available. If it is, recommend starting fresh with `/openspec-new-change` (the "Update vs. Start Fresh" heuristic). If it is unavailable, ask for a distinct unused change name and recommend `openspec new change "<new-change-name>"` instead.
+32
View File
@@ -0,0 +1,32 @@
FROM python:3.12-slim AS builder
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
FROM python:3.12-slim
WORKDIR /app
# Только бинарники и зависимости — без сборщика
COPY --from=builder /usr/local/lib/python3.12/site-packages /usr/local/lib/python3.12/site-packages
COPY --from=builder /usr/local/bin /usr/local/bin
COPY app/ app/
COPY .env.example .env
# Read-only rootfs — только /data для БД и /logs для аудита
RUN mkdir -p /data /logs && chmod 755 /data /logs
# Не root
RUN useradd -m -u 1000 md2vk && chown -R md2vk:md2vk /app /data /logs
USER md2vk
EXPOSE 8420
# Ключ шифрования — через Docker secret /run/secrets/token_encryption_key
ENV TOKEN_ENCRYPTION_KEY_FILE=/run/secrets/token_encryption_key
ENV DATABASE_URL=sqlite+aiosqlite:////data/md2vk.db
ENV AUDIT_LOG_DIR=/logs
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8420"]
+53
View File
@@ -0,0 +1,53 @@
.PHONY: dev install run clean test
dev: install
TOKEN_ENCRYPTION_KEY_FILE=secrets/token_encryption_key \
uvicorn app.main:app --host 0.0.0.0 --port 8000 --reload
install:
python3 -m venv venv && \
. venv/bin/activate && \
pip install -r requirements.txt
run:
TOKEN_ENCRYPTION_KEY_FILE=secrets/token_encryption_key \
uvicorn app.main:app --host 0.0.0.0 --port 8000
test:
. venv/bin/activate && \
TOKEN_ENCRYPTION_KEY_FILE=secrets/token_encryption_key \
python3 -m pytest tests/ -v
clean:
rm -rf venv/ __pycache__ .pytest_cache
find . -name '*.pyc' -delete
docker-build:
docker compose build
docker-up:
docker compose up -d
docker-down:
docker compose down
key:
python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
user:
TOKEN_ENCRYPTION_KEY_FILE=secrets/token_encryption_key \
python3 -c "
import asyncio
from app.database import init_db, async_session_factory
from app.models import User
from app.security import generate_api_key
async def create():
await init_db()
async with async_session_factory() as session:
key, h = generate_api_key()
u = User(api_key_hash=h, display_name='admin')
session.add(u)
await session.commit()
print(f'User created. API key: {key}')
asyncio.run(create())
"
+64
View File
@@ -0,0 +1,64 @@
# md2vk
Сервис публикации Markdown на стене VK через официальный VK API (wall.post + format_data).
```
┌─────────────┐ ┌─────────────┐ ┌──────────────┐
│ Hermes │────▶│ md2vk │────▶│ VK API │
│ Agent │ │ :8420 │ │ wall.post │
│ (skill) │◀────│ FastAPI │ │ vk.com │
└─────────────┘ └─────────────┘ └──────────────┘
```
**Прод:** https://md2vk.nixg.ru (basic auth — см. `docs/security.md`; Swagger `/docs`).
## Документация
Вся документация — в [`docs/`](docs/index.md):
- [docs/index.md](docs/index.md) — указатель, обзор
- [docs/access.md](docs/access.md) — **реквизиты и доступы** (vps02, Caddy, gitverse, gitea, DNS, VK API)
- [docs/architecture.md](docs/architecture.md) — архитектура, порты, схема
- [docs/vk-api.md](docs/vk-api.md) — порядок взаимодействия с VK API (OAuth, wall.post, лонгриды)
- [docs/security.md](docs/security.md) — безопасность (basic auth, fail2ban, Fernet, API-ключ)
- [docs/deploy.md](docs/deploy.md) — деплой (docker, Caddy, fail2ban)
- [docs/status.md](docs/status.md) — статус/история
Инструкции для агентов (Hermes и др.): [`AGENTS.md`](AGENTS.md).
## Возможности
- Публикация Markdown на стене VK с сохранением форматирования
- Конвертация Markdown → VK format_data (JSON) без публикации
- Управление VK-аккаунтами — несколько страниц через один сервис
- Отложенные посты — запись `scheduled` (планировщик — открытая задача)
- Архив публикаций с фильтрацией по статусу
- Аудит-лог запросов API (JSONL, ротация по дням)
## API
| Метод | Путь | Описание |
|-------|------|----------|
| `GET` | `/api/v1/health` | Проверка работоспособности |
| `GET` | `/api/v1/accounts` | Список VK-аккаунтов |
| `POST` | `/api/v1/accounts` | Добавить VK-аккаунт |
| `DELETE` | `/api/v1/accounts/{id}` | Удалить VK-аккаунт |
| `POST` | `/api/v1/publish` | Опубликовать пост на стене |
| `POST` | `/api/v1/convert` | Конвертировать Markdown (без публикации) |
| `POST` | `/api/v1/publications` | Архив публикаций |
Swagger UI: `http://127.0.0.1:8420/docs` (прод — за basic auth).
## Быстрый старт
```bash
cd /opt/md2vk
make docker-up # docker compose up -d --build
curl -s http://127.0.0.1:8420/api/v1/health # {"status":"ok"}
```
Детали деплоя и проверки — [docs/deploy.md](docs/deploy.md).
## Технологии
Python 3.12+, FastAPI, SQLAlchemy 2.0 (async), SQLite (aiosqlite), httpx, cryptography (Fernet), Docker, Caddy, fail2ban.
+28
View File
@@ -0,0 +1,28 @@
# md2vk — Статус проекта
> История изменений — в [docs/status.md](docs/status.md). Структура и реквизиты — в [docs/](docs/index.md).
## Текущее состояние
**Phase 1 (ядро) — DONE.** Плюс: документация docs/, аудит-лог, docker-деплой :8420,
подключены openspec, git (gitverse → gitea mirror), Caddy + fail2ban на vps02.
Актуальный статус: [docs/status.md](docs/status.md) · Задачи в OpenSpec: `openspec/`
## Открытые задачи (кратко)
- Планировщик отложенных постов (status=scheduled → wall.post)
- OAuth-флоу VK ID (нужны client_id/secret)
- Web UI, Telegram-бот
- Unit/integration тесты (pytest)
- Rate limiting, retry, graceful shutdown
- Hermes skill md2vk
## Как запустить (кратко)
```bash
make docker-up # docker compose up -d --build
curl -s http://127.0.0.1:8420/api/v1/health # {"status":"ok"}
```
Подробно: [docs/deploy.md](docs/deploy.md).
View File
View File
+121
View File
@@ -0,0 +1,121 @@
"""Аудит-лог авторизации и запросов API (JSONL, ротация по дням).
Пишет строку JSON на каждый запрос /api/v1/*:
ts, ip, method, path, api_key_prefix, user_id, status, success, latency_ms, error.
Параметры из env:
- AUDIT_LOG_DIR — каталог для логов (по умолчанию "logs").
"""
from __future__ import annotations
import json
import logging
import os
import time
from datetime import date, datetime, timezone
from pathlib import Path
from starlette.middleware.base import BaseHTTPMiddleware
from starlette.requests import Request
logger = logging.getLogger("md2vk.audit")
class AuditMiddleware(BaseHTTPMiddleware):
"""Логирует каждый запрос /api/v1/* в JSONL с ротацией по дням."""
def __init__(self, app, log_dir: str | None = None):
super().__init__(app)
self.log_dir = Path(log_dir or os.getenv("AUDIT_LOG_DIR", "logs"))
self.log_dir.mkdir(parents=True, exist_ok=True)
self._fh = None
self._fh_date: date | None = None
def _ensure_file(self) -> None:
today = date.today()
if self._fh is None or self._fh_date != today:
if self._fh is not None:
try:
self._fh.close()
except Exception:
pass
path = self.log_dir / f"access.{today.isoformat()}.log"
self._fh = open(path, "a", encoding="utf-8")
self._fh_date = today
def _write(self, record: dict) -> None:
try:
self._ensure_file()
self._fh.write(json.dumps(record, ensure_ascii=False, default=str) + "\n")
self._fh.flush()
except Exception:
# Логгер не должен ронять API
logger.exception("audit write failed")
async def dispatch(self, request: Request, call_next):
start = time.monotonic()
response = None
error = None
try:
response = await call_next(request)
return response
except Exception as exc: # noqa: BLE001
error = str(exc)
raise
finally:
path = request.url.path
if path.startswith("/api/v1"):
try:
latency_ms = round((time.monotonic() - start) * 1000, 1)
status = response.status_code if response is not None else 500
auth = request.headers.get("authorization", "")
# api_key может быть в теле (POST) — пытаемся достать
api_key_prefix = ""
api_key_hash_short = ""
user_id = None
if auth.startswith("Bearer "):
api_key_prefix = auth[len("Bearer "):][:12]
elif request.method == "POST":
api_key_prefix = self._api_key_from_body(request)
if "md2vk_" in api_key_prefix:
# вычислим короткий хэш для привязки к user (без хранения ключа)
import hashlib
api_key_hash_short = hashlib.sha256(
api_key_prefix.encode()
).hexdigest()[:12]
record = {
"ts": datetime.now(timezone.utc).isoformat(timespec="seconds"),
"ip": (request.client.host if request.client else ""),
"method": request.method,
"path": path,
"query": str(request.url.query) or "",
"api_key_prefix": api_key_prefix,
"api_key_hash_short": api_key_hash_short,
"user_id": user_id,
"status": status,
"success": status < 400,
"latency_ms": latency_ms,
"error": error,
}
self._write(record)
except Exception: # noqa: BLE001
logger.exception("audit dispatch failed")
@staticmethod
def _api_key_from_body(request: Request) -> str:
"""Достаёт api_key из JSON-тела, не ломая повторное чтение."""
try:
# starlette кэширует _body — повторное чтение в роутере безопасно
body = getattr(request, "_body", None)
if body is None:
body = request.body() if hasattr(request, "body") else b""
if isinstance(body, bytes) and body:
data = json.loads(body)
key = data.get("api_key", "")
return str(key)[:12]
except Exception:
return ""
return ""
+64
View File
@@ -0,0 +1,64 @@
"""FastAPI-зависимости: аутентификация по API-ключу."""
from __future__ import annotations
import hashlib
from fastapi import Depends, HTTPException, status
from fastapi.security import HTTPAuthorizationCredentials, HTTPBearer
from sqlalchemy import select
from sqlalchemy.ext.asyncio import AsyncSession
from app.database import get_db
from app.models import User
security_scheme = HTTPBearer(auto_error=False)
def hash_api_key(api_key: str) -> str:
return hashlib.sha256(api_key.encode()).hexdigest()
async def get_current_user_from_header(
credentials: HTTPAuthorizationCredentials | None = Depends(security_scheme),
db: AsyncSession = Depends(get_db),
) -> User:
"""Аутентификация по заголовку Authorization: Bearer <api_key>."""
if credentials is None:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Missing Authorization header. Use: Authorization: Bearer <api_key>",
)
api_key = credentials.credentials
if not api_key.startswith("md2vk_"):
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Invalid API key format",
)
api_key_hash = hash_api_key(api_key)
result = await db.execute(
select(User).where(User.api_key_hash == api_key_hash, User.is_active == True)
)
user = result.scalar_one_or_none()
if user is None:
raise HTTPException(status_code=status.HTTP_401_UNAUTHORIZED, detail="Invalid API key")
return user
async def get_user_by_api_key(api_key: str, db: AsyncSession) -> User:
"""Проверяет API-ключ из тела запроса. Используется в POST-эндпоинтах."""
if not api_key.startswith("md2vk_"):
raise HTTPException(status_code=401, detail="Invalid API key format")
api_key_hash = hash_api_key(api_key)
result = await db.execute(
select(User).where(User.api_key_hash == api_key_hash, User.is_active == True)
)
user = result.scalar_one_or_none()
if user is None:
raise HTTPException(status_code=401, detail="Invalid API key")
return user
+110
View File
@@ -0,0 +1,110 @@
"""Pydantic-схемы для API-запросов и ответов."""
from __future__ import annotations
from datetime import datetime
from typing import Optional
from pydantic import BaseModel, Field
# ─── Аутентификация ────────────────────────────────────────────────────────
class ApiKeyRequest(BaseModel):
api_key: str = Field(..., description="API-ключ пользователя")
# ─── Аккаунты ──────────────────────────────────────────────────────────────
class AccountCreateRequest(BaseModel):
api_key: str
vk_user_id: int = Field(..., description="VK owner_id (положительный — пользователь, отрицательный — сообщество)")
display_name: str = Field(..., max_length=255, description="Отображаемое имя аккаунта")
access_token: str = Field(..., description="VK OAuth-токен с правами wall")
token_type: str = Field(default="user", pattern="^(user|group)$", description="user | group")
class AccountResponse(BaseModel):
id: int
vk_user_id: int
display_name: str
token_type: str
is_active: bool
created_at: datetime
class AccountListResponse(BaseModel):
accounts: list[AccountResponse]
# ─── Публикация ────────────────────────────────────────────────────────────
class PublishRequest(BaseModel):
api_key: str
vk_account_id: int = Field(..., description="ID VK-аккаунта из /api/v1/accounts")
message_md: str = Field(..., min_length=1, description="Текст поста в Markdown")
publish_date: Optional[datetime] = Field(None, description="ISO datetime для отложенной публикации")
friends_only: bool = False
attachments: Optional[str] = Field(None, description="VK-вложения через запятую (photo123_456, ...)")
signed: Optional[bool] = Field(None, description="Подпись автора (для групп)")
class PublishResponse(BaseModel):
success: bool
publication_id: int
vk_post_id: Optional[int] = None
vk_owner_id: Optional[int] = None
url: Optional[str] = None
error: Optional[str] = None
# ─── Конвертация ───────────────────────────────────────────────────────────
class ConvertRequest(BaseModel):
message_md: str = Field(..., min_length=1, description="Markdown-текст для конвертации")
class FormatItemResponse(BaseModel):
type: str
offset: int
length: int
url: Optional[str] = None
class ConvertResponse(BaseModel):
text: str
format_data: Optional[dict] = None
# ─── Публикации (архив) ────────────────────────────────────────────────────
class PublicationFilterRequest(BaseModel):
api_key: str
vk_account_id: Optional[int] = None
status: Optional[str] = Field(None, pattern="^(draft|scheduled|published|error)$")
limit: int = Field(default=20, ge=1, le=100)
offset: int = Field(default=0, ge=0)
class PublicationItem(BaseModel):
id: int
vk_account_id: int
status: str
markdown_original: str
vk_post_id: Optional[int] = None
vk_owner_id: Optional[int] = None
scheduled_at: Optional[datetime] = None
published_at: Optional[datetime] = None
error_message: Optional[str] = None
created_at: datetime
class PublicationListResponse(BaseModel):
publications: list[PublicationItem]
total: int
# ─── Ошибки ────────────────────────────────────────────────────────────────
class ErrorResponse(BaseModel):
detail: str
+325
View File
@@ -0,0 +1,325 @@
"""API v1: эндпоинты публикации, конвертации, управления аккаунтами."""
from __future__ import annotations
import json
from datetime import datetime
from fastapi import APIRouter, Depends, HTTPException, status
from sqlalchemy import select, func
from sqlalchemy.ext.asyncio import AsyncSession
from app.database import get_db
from app.models import User, VkAccount, Publication
from app.security import decrypt_token, encrypt_token
from app.vk_client import VkClient, VkApiError
from app.converters.markdown_to_vk import markdown_to_vk, format_data_json
from app.api.schemas import (
AccountCreateRequest,
AccountResponse,
AccountListResponse,
PublishRequest,
PublishResponse,
ConvertRequest,
ConvertResponse,
PublicationFilterRequest,
PublicationItem,
PublicationListResponse,
)
from app.api.deps import get_current_user_from_header, get_user_by_api_key
router = APIRouter(prefix="/api/v1", tags=["v1"])
# ─── Health ─────────────────────────────────────────────────────────────────
@router.get("/health")
async def health():
return {"status": "ok"}
# ─── Аккаунты ──────────────────────────────────────────────────────────────
@router.post("/accounts", response_model=AccountResponse)
async def create_account(
req: AccountCreateRequest,
db: AsyncSession = Depends(get_db),
):
"""Добавить VK-аккаунт. Проверяет токен через VK API перед сохранением."""
user = await get_user_by_api_key(req.api_key, db)
# Проверяем токен через VK API
vk = VkClient(req.access_token)
try:
is_valid, display_name = await vk.check_token()
if not is_valid:
raise HTTPException(status_code=400, detail=f"VK token invalid: {display_name}")
except VkApiError as e:
raise HTTPException(status_code=400, detail=f"VK API error: {e}")
finally:
await vk.close()
# Шифруем токен перед сохранением
encrypted = encrypt_token(req.access_token)
name = req.display_name or display_name or f"VK-{req.vk_user_id}"
# Проверяем, нет ли уже такого VK-аккаунта у пользователя
existing = await db.execute(
select(VkAccount).where(
VkAccount.user_id == user.id,
VkAccount.vk_user_id == req.vk_user_id,
VkAccount.is_active == True,
)
)
if existing.scalar_one_or_none():
raise HTTPException(status_code=409, detail="This VK account is already registered")
account = VkAccount(
user_id=user.id,
vk_user_id=req.vk_user_id,
display_name=name,
access_token_enc=encrypted,
token_type=req.token_type,
)
db.add(account)
await db.flush()
await db.refresh(account)
return AccountResponse(
id=account.id,
vk_user_id=account.vk_user_id,
display_name=account.display_name,
token_type=account.token_type,
is_active=account.is_active,
created_at=account.created_at,
)
@router.get("/accounts", response_model=AccountListResponse)
async def list_accounts(
user: User = Depends(get_current_user_from_header),
db: AsyncSession = Depends(get_db),
):
"""Список VK-аккаунтов текущего пользователя."""
result = await db.execute(
select(VkAccount).where(VkAccount.user_id == user.id, VkAccount.is_active == True)
)
accounts = result.scalars().all()
return AccountListResponse(
accounts=[
AccountResponse(
id=a.id,
vk_user_id=a.vk_user_id,
display_name=a.display_name,
token_type=a.token_type,
is_active=a.is_active,
created_at=a.created_at,
)
for a in accounts
]
)
@router.delete("/accounts/{account_id}", status_code=204)
async def delete_account(
account_id: int,
user: User = Depends(get_current_user_from_header),
db: AsyncSession = Depends(get_db),
):
"""Удалить VK-аккаунт (soft delete)."""
result = await db.execute(
select(VkAccount).where(
VkAccount.id == account_id,
VkAccount.user_id == user.id,
)
)
account = result.scalar_one_or_none()
if account is None:
raise HTTPException(status_code=404, detail="Account not found")
account.is_active = False
await db.flush()
# ─── Публикация ────────────────────────────────────────────────────────────
@router.post("/publish", response_model=PublishResponse)
async def publish(
req: PublishRequest,
db: AsyncSession = Depends(get_db),
):
"""Опубликовать пост на стене VK."""
# Аутентификация по api_key из тела запроса
user = await get_user_by_api_key(req.api_key, db)
# Получаем VK-аккаунт
result = await db.execute(
select(VkAccount).where(
VkAccount.id == req.vk_account_id,
VkAccount.user_id == user.id,
VkAccount.is_active == True,
)
)
account = result.scalar_one_or_none()
if account is None:
raise HTTPException(status_code=404, detail="VK account not found")
# Расшифровываем токен (только в памяти!)
token = decrypt_token(account.access_token_enc)
if token is None:
raise HTTPException(status_code=500, detail="Failed to decrypt VK token (key mismatch?)")
# Конвертируем Markdown
chunks = markdown_to_vk(req.message_md)
if not chunks or not chunks[0].text.strip():
raise HTTPException(status_code=400, detail="Empty message after markdown conversion")
chunk = chunks[0]
fd_json = format_data_json(chunk.items) if chunk.items else None
# Создаём запись о публикации
publication = Publication(
vk_account_id=account.id,
status="draft",
markdown_original=req.message_md,
vk_text=chunk.text,
vk_format_data=fd_json,
scheduled_at=req.publish_date,
)
db.add(publication)
await db.flush()
# Если отложенная — сохраняем и выходим
if req.publish_date:
publication.status = "scheduled"
await db.flush()
return PublishResponse(
success=True,
publication_id=publication.id,
)
# Публикуем через VK API
vk = VkClient(token)
try:
result = await vk.wall_post(
message=chunk.text,
owner_id=account.vk_user_id if account.token_type == "group" else None,
from_group=(account.token_type == "group"),
friends_only=req.friends_only,
publish_date=int(req.publish_date.timestamp()) if req.publish_date else None,
attachments=req.attachments,
signed=req.signed,
format_data=chunk.items if chunk.items else None,
)
post_id = result.get("post_id")
owner_id = result.get("owner_id") or account.vk_user_id
publication.status = "published"
publication.vk_post_id = post_id
publication.vk_owner_id = owner_id
publication.published_at = datetime.utcnow()
await db.flush()
url = f"https://vk.com/wall{owner_id}_{post_id}"
return PublishResponse(
success=True,
publication_id=publication.id,
vk_post_id=post_id,
vk_owner_id=owner_id,
url=url,
)
except VkApiError as e:
publication.status = "error"
publication.error_message = str(e)
await db.flush()
return PublishResponse(
success=False,
publication_id=publication.id,
error=str(e),
)
finally:
await vk.close()
@router.post("/convert", response_model=ConvertResponse)
async def convert(req: ConvertRequest):
"""Конвертировать Markdown в VK format_data (без публикации)."""
chunks = markdown_to_vk(req.message_md)
if not chunks:
return ConvertResponse(text="", format_data={"version": 1, "items": []})
chunk = chunks[0]
items = []
for i in chunk.items:
items.append({"type": i.type, "offset": i.offset, "length": i.length, "url": i.url})
return ConvertResponse(
text=chunk.text,
format_data={"version": 1, "items": items},
)
# ─── Архив публикаций ──────────────────────────────────────────────────────
@router.post("/publications", response_model=PublicationListResponse)
async def list_publications(
req: PublicationFilterRequest,
db: AsyncSession = Depends(get_db),
):
"""Архив публикаций с фильтрацией."""
user = await get_user_by_api_key(req.api_key, db)
# Базовый запрос — только публикации пользователя
base_filter = VkAccount.user_id == user.id
query = (
select(Publication)
.join(VkAccount)
.where(base_filter)
)
count_query = (
select(func.count(Publication.id))
.join(VkAccount)
.where(base_filter)
)
if req.vk_account_id is not None:
query = query.where(Publication.vk_account_id == req.vk_account_id)
count_query = count_query.where(Publication.vk_account_id == req.vk_account_id)
if req.status is not None:
query = query.where(Publication.status == req.status)
count_query = count_query.where(Publication.status == req.status)
total_result = await db.execute(count_query)
total = total_result.scalar() or 0
query = query.order_by(Publication.created_at.desc()).offset(req.offset).limit(req.limit)
result = await db.execute(query)
publications = result.scalars().all()
return PublicationListResponse(
publications=[
PublicationItem(
id=p.id,
vk_account_id=p.vk_account_id,
status=p.status,
markdown_original=p.markdown_original,
vk_post_id=p.vk_post_id,
vk_owner_id=p.vk_owner_id,
scheduled_at=p.scheduled_at,
published_at=p.published_at,
error_message=p.error_message,
created_at=p.created_at,
)
for p in publications
],
total=total,
)
+42
View File
@@ -0,0 +1,42 @@
"""Конфигурация md2vk из переменных окружения."""
from __future__ import annotations
from pathlib import Path
from pydantic_settings import BaseSettings
class Settings(BaseSettings):
# HTTP
host: str = "0.0.0.0"
port: int = 8000
# Файл с Fernet-ключом (Docker secret / файл на диске)
token_encryption_key_file: str = "/run/secrets/token_encryption_key"
# База данных
database_url: str = "sqlite+aiosqlite:///data/md2vk.db"
# VK API
vk_api_version: str = "5.199"
# Rate limiting (запросов в минуту на VK-аккаунт)
rate_limit_per_minute: int = 10
model_config = {"env_file": ".env", "env_prefix": ""}
@property
def fernet_key(self) -> bytes:
"""Читает и возвращает Fernet-ключ из файла."""
key_path = Path(self.token_encryption_key_file)
if not key_path.exists():
raise RuntimeError(
f"Файл с Fernet-ключом не найден: {key_path}. "
f"Сгенерируйте: python3 -c \"from cryptography.fernet import Fernet; "
f"print(Fernet.generate_key().decode())\" > {key_path}"
)
return key_path.read_bytes().strip()
settings = Settings()
View File
+422
View File
@@ -0,0 +1,422 @@
"""Конвертер Markdown → VK format_data.
Поддерживает: **жирный**, *курсив*, `код`, [ссылки], #заголовки, > цитаты, ```блоки кода```, ---.
Разбивает длинные тексты на чанки (VK лимит ~4096 символов).
"""
from __future__ import annotations
import re
from dataclasses import dataclass, field
from typing import Optional
@dataclass
class FormatItem:
type: str # bold | italic | link | inline_code
offset: int
length: int
url: Optional[str] = None
@dataclass
class Chunk:
text: str
items: list[FormatItem] = field(default_factory=list)
# ─── AST-узлы для промежуточного представления ───────────────────────────
@dataclass
class TextNode:
text: str
@dataclass
class BoldNode:
children: list = field(default_factory=list)
@dataclass
class ItalicNode:
children: list = field(default_factory=list)
@dataclass
class BoldItalicNode:
children: list = field(default_factory=list)
@dataclass
class CodeNode:
text: str
@dataclass
class LinkNode:
text: str
url: str
@dataclass
class HeaderNode:
level: int
text: str
@dataclass
class BlockquoteNode:
text: str
@dataclass
class CodeBlockNode:
text: str
@dataclass
class HrNode:
pass
@dataclass
class ParagraphNode:
children: list = field(default_factory=list)
@dataclass
class DocumentNode:
children: list = field(default_factory=list)
# ─── Парсер Markdown (блочный + строчный) ─────────────────────────────────
def parse_block(text: str) -> list:
"""Разбивает текст на блочные элементы."""
lines = text.split("\n")
blocks = []
i = 0
while i < len(lines):
line = lines[i]
# Горизонтальная линия
if re.match(r"^-{3,}$", line.strip()):
blocks.append(HrNode())
i += 1
continue
# Заголовок
hm = re.match(r"^(#{1,6})\s+(.+)$", line)
if hm:
blocks.append(HeaderNode(level=len(hm.group(1)), text=hm.group(2)))
i += 1
continue
# Цитата
if line.startswith("> "):
quote_lines = []
while i < len(lines) and lines[i].startswith("> "):
quote_lines.append(lines[i][2:])
i += 1
blocks.append(BlockquoteNode(text="\n".join(quote_lines)))
continue
# Блок кода
if line.startswith("```"):
code_lines = []
i += 1
while i < len(lines) and not lines[i].startswith("```"):
code_lines.append(lines[i])
i += 1
i += 1 # пропускаем закрывающие ```
blocks.append(CodeBlockNode(text="\n".join(code_lines)))
continue
# Пустая строка — разделитель параграфов
if line.strip() == "":
i += 1
continue
# Обычный параграф
para_lines = []
while i < len(lines) and lines[i].strip() != "" and not lines[i].startswith("```") and not re.match(r"^-{3,}$", lines[i].strip()):
# Проверка на заголовок внутри — не разрываем параграф
if re.match(r"^#{1,6}\s+", lines[i]) and len(para_lines) > 0:
break
para_lines.append(lines[i])
i += 1
blocks.append(ParagraphNode(children=parse_inline("\n".join(para_lines))))
# Не инкрементим i, т.к. цикл while уже продвинул
return blocks
def parse_inline(text: str) -> list:
"""Парсит строчные элементы: **жирный**, *курсив*, `код`, [ссылки], ***жирный+курсив***."""
result = []
pos = 0
while pos < len(text):
# ***жирный+курсив***
m = re.match(r"\*\*\*(.+?)\*\*\*", text[pos:])
if m:
result.append(BoldItalicNode(children=[TextNode(text=m.group(1))]))
pos += len(m.group(0))
continue
# **жирный**
m = re.match(r"\*\*(.+?)\*\*", text[pos:])
if m:
result.append(BoldNode(children=[TextNode(text=m.group(1))]))
pos += len(m.group(0))
continue
# __жирный__
m = re.match(r"__(.+?)__", text[pos:])
if m:
result.append(BoldNode(children=[TextNode(text=m.group(1))]))
pos += len(m.group(0))
continue
# *курсив*
m = re.match(r"\*(.+?)\*", text[pos:])
if m:
# Убедимся, что это не **
if not text[pos:].startswith("**"):
result.append(ItalicNode(children=[TextNode(text=m.group(1))]))
pos += len(m.group(0))
continue
# _курсив_
m = re.match(r"_(.+?)_", text[pos:])
if m:
if not text[pos:].startswith("__"):
result.append(ItalicNode(children=[TextNode(text=m.group(1))]))
pos += len(m.group(0))
continue
# `код`
m = re.match(r"`([^`]+)`", text[pos:])
if m:
result.append(CodeNode(text=m.group(1)))
pos += len(m.group(0))
continue
# [ссылка](url)
m = re.match(r"\[([^\]]+)\]\(([^)]+)\)", text[pos:])
if m:
result.append(LinkNode(text=m.group(1), url=m.group(2)))
pos += len(m.group(0))
continue
# Обычный текст
m = re.match(r"[^*_`\[<]+", text[pos:])
if m:
result.append(TextNode(text=m.group(0)))
pos += len(m.group(0))
continue
# Одиночный символ (если не подошло ни одно правило)
result.append(TextNode(text=text[pos]))
pos += 1
return result
# ─── Генерация VK-формата ─────────────────────────────────────────────────
def _render_node(node, plain_text: list[str], format_items: list[FormatItem], base_offset: int) -> int:
"""Рендерит AST-узел в plain_text и format_items. Возвращает новый offset."""
if isinstance(node, TextNode):
plain_text.append(node.text)
return base_offset + len(node.text)
elif isinstance(node, BoldNode):
inner_start = base_offset
offset = inner_start
for child in node.children:
offset = _render_node(child, plain_text, format_items, offset)
if offset > inner_start:
format_items.append(FormatItem(type="bold", offset=inner_start, length=offset - inner_start))
return offset
elif isinstance(node, ItalicNode):
inner_start = base_offset
offset = inner_start
for child in node.children:
offset = _render_node(child, plain_text, format_items, offset)
if offset > inner_start:
format_items.append(FormatItem(type="italic", offset=inner_start, length=offset - inner_start))
return offset
elif isinstance(node, BoldItalicNode):
inner_start = base_offset
offset = inner_start
for child in node.children:
offset = _render_node(child, plain_text, format_items, offset)
if offset > inner_start:
format_items.append(FormatItem(type="bold", offset=inner_start, length=offset - inner_start))
format_items.append(FormatItem(type="italic", offset=inner_start, length=offset - inner_start))
return offset
elif isinstance(node, CodeNode):
plain_text.append(node.text)
length = len(node.text)
format_items.append(FormatItem(type="inline_code", offset=base_offset, length=length))
return base_offset + length
elif isinstance(node, LinkNode):
offset = base_offset
for child in parse_inline(node.text):
offset = _render_node(child, plain_text, format_items, offset)
length = offset - base_offset
format_items.append(FormatItem(type="link", offset=base_offset, length=length, url=node.url))
return offset
elif isinstance(node, HeaderNode):
# Заголовки → жирный + uppercase
text = node.text.upper()
plain_text.append(text)
format_items.append(FormatItem(type="bold", offset=base_offset, length=len(text)))
return base_offset + len(text)
elif isinstance(node, BlockquoteNode):
# Цитата → italic
text = node.text
plain_text.append(text)
format_items.append(FormatItem(type="italic", offset=base_offset, length=len(text)))
return base_offset + len(text)
elif isinstance(node, CodeBlockNode):
text = node.text
plain_text.append(text)
return base_offset + len(text)
elif isinstance(node, HrNode):
plain_text.append("───")
return base_offset + 3
elif isinstance(node, ParagraphNode):
offset = base_offset
for child in node.children:
offset = _render_node(child, plain_text, format_items, offset)
return offset
return base_offset
def render_document(blocks: list) -> tuple[str, list[FormatItem]]:
"""Рендерит список блоков в плоский текст + format_items."""
plain_text: list[str] = []
format_items: list[FormatItem] = []
offset = 0
for i, block in enumerate(blocks):
if i > 0:
plain_text.append("\n\n")
offset += 2
offset = _render_node(block, plain_text, format_items, offset)
return "".join(plain_text), format_items
# ─── Разбиение на чанки ────────────────────────────────────────────────────
def _vk_char_len(text: str) -> int:
"""VK считает @ за 2 символа. Учитываем это при подсчёте длины."""
count = 0
for ch in text:
count += 2 if ch == "@" else 1
return count
def _split_into_chunks(text: str, items: list[FormatItem], chunk_size: int = 4096) -> list[Chunk]:
"""Разбивает текст на чанки, корректируя format_items на границах."""
if not text:
return [Chunk(text="", items=[])]
# Определяем границы разбиения по \n\n (абзацы)
# Если текст влезает целиком — один чанк
if _vk_char_len(text) <= chunk_size:
return [Chunk(text=text, items=_adjust_items(items, 0, len(text)))]
chunks: list[Chunk] = []
start = 0
while start < len(text):
# Ищем границу: \n\n в пределах chunk_size
end = start + int(chunk_size * 0.9) # 90% от лимита — запас
if end >= len(text):
end = len(text)
# Ищем \n\n назад от end
split_pos = text.rfind("\n\n", start, end)
if split_pos == -1 or split_pos <= start:
# Если нет \n\n — ищем последний пробел
split_pos = text.rfind(" ", start, end)
if split_pos == -1 or split_pos <= start:
split_pos = end
chunk_text = text[start:split_pos].strip()
if chunk_text:
chunk_items = _adjust_items(items, start, split_pos)
chunks.append(Chunk(text=chunk_text, items=chunk_items))
start = split_pos + 1 # пропускаем разделитель
return chunks if chunks else [Chunk(text=text, items=[])]
def _adjust_items(items: list[FormatItem], start: int, end: int) -> list[FormatItem]:
"""Обрезает format_items для диапазона [start, end) и сдвигает offset."""
result = []
for item in items:
item_end = item.offset + item.length
# Проверяем пересечение
if item_end <= start or item.offset >= end:
continue
new_offset = max(item.offset, start) - start
new_length = min(item_end, end) - max(item.offset, start)
result.append(FormatItem(
type=item.type,
offset=new_offset,
length=new_length,
url=item.url,
))
return result
# ─── Публичный API ─────────────────────────────────────────────────────────
def markdown_to_vk(text: str, chunk_size: int = 4096) -> list[Chunk]:
"""Конвертирует Markdown в список чанков, готовых к отправке в VK API.
Каждый чанк содержит:
- text: plain text для поля message
- items: список FormatItem для format_data
VK принимает format_data через поле format_data в wall.post,
которое должно быть JSON-строкой вида:
{"version": 1, "items": [{"type": "bold", "offset": 0, "length": 5}]}
"""
if not text or not text.strip():
return [Chunk(text="", items=[])]
blocks = parse_block(text)
plain_text, items = render_document(blocks)
return _split_into_chunks(plain_text, items, chunk_size)
def format_data_json(items: list[FormatItem]) -> str:
"""Сериализует format_items в JSON для VK API."""
import json
vk_items = []
for item in items:
d = {"type": item.type, "offset": item.offset, "length": item.length}
if item.url:
d["url"] = item.url
vk_items.append(d)
return json.dumps({"version": 1, "items": vk_items}, ensure_ascii=False)
+37
View File
@@ -0,0 +1,37 @@
"""База данных: async engine, сессии, инициализация."""
from __future__ import annotations
from pathlib import Path
from sqlalchemy.ext.asyncio import AsyncSession, async_sessionmaker, create_async_engine
from app.config import settings
# Создаём каталог для БД, если SQLite
_db_path = settings.database_url.replace("sqlite+aiosqlite:///", "")
if _db_path != settings.database_url:
Path(_db_path).parent.mkdir(parents=True, exist_ok=True)
engine = create_async_engine(settings.database_url, echo=False)
async_session_factory = async_sessionmaker(engine, class_=AsyncSession, expire_on_commit=False)
async def get_db() -> AsyncSession:
"""FastAPI-зависимость: сессия БД."""
async with async_session_factory() as session:
try:
yield session
await session.commit()
except Exception:
await session.rollback()
raise
finally:
await session.close()
async def init_db():
"""Создаёт таблицы при старте."""
from app.models import Base # noqa: F401 — импорт моделей для регистрации
async with engine.begin() as conn:
await conn.run_sync(Base.metadata.create_all)
+48
View File
@@ -0,0 +1,48 @@
"""md2vk — FastAPI приложение."""
from __future__ import annotations
import logging
from contextlib import asynccontextmanager
from fastapi import FastAPI, Request
from fastapi.responses import JSONResponse
from app.database import init_db
from app.api.v1 import router as api_v1_router
from app.api.audit import AuditMiddleware
logging.basicConfig(level=logging.INFO, format="%(asctime)s [%(levelname)s] %(name)s: %(message)s")
logger = logging.getLogger("md2vk")
@asynccontextmanager
async def lifespan(app: FastAPI):
"""Инициализация при старте."""
logger.info("Initializing database...")
await init_db()
logger.info("Database ready. Starting md2vk...")
yield
logger.info("Shutting down...")
app = FastAPI(
title="md2vk",
description="Сервис публикации Markdown на стене VK",
version="0.1.0",
lifespan=lifespan,
)
# Аудит-лог авторизации/запросов API (JSONL, ротация по дням)
app.add_middleware(AuditMiddleware)
app.include_router(api_v1_router)
@app.exception_handler(Exception)
async def global_exception_handler(request: Request, exc: Exception):
logger.error(f"Unhandled error: {exc}", exc_info=True)
return JSONResponse(
status_code=500,
content={"detail": f"Internal server error: {str(exc)}"},
)
+92
View File
@@ -0,0 +1,92 @@
"""ORM-модели: User, VkAccount, Publication."""
from __future__ import annotations
import datetime
from typing import Optional
from sqlalchemy import (
Boolean,
DateTime,
ForeignKey,
Integer,
String,
Text,
func,
)
from sqlalchemy.orm import DeclarativeBase, Mapped, mapped_column, relationship
class Base(DeclarativeBase):
pass
class User(Base):
__tablename__ = "users"
id: Mapped[int] = mapped_column(Integer, primary_key=True, autoincrement=True)
name: Mapped[str] = mapped_column(String(255), nullable=False)
email: Mapped[Optional[str]] = mapped_column(String(255), nullable=True, unique=True)
api_key_hash: Mapped[str] = mapped_column(String(64), nullable=False, unique=True)
api_key_prefix: Mapped[str] = mapped_column(String(12), nullable=False, comment="Первые ~10 символов ключа для идентификации")
is_active: Mapped[bool] = mapped_column(Boolean, default=True, nullable=False)
created_at: Mapped[datetime.datetime] = mapped_column(DateTime, server_default=func.now(), nullable=False)
updated_at: Mapped[datetime.datetime] = mapped_column(DateTime, server_default=func.now(), onupdate=func.now(), nullable=False)
vk_accounts: Mapped[list[VkAccount]] = relationship(back_populates="user", cascade="all, delete-orphan")
class VkAccount(Base):
__tablename__ = "vk_accounts"
id: Mapped[int] = mapped_column(Integer, primary_key=True, autoincrement=True)
user_id: Mapped[int] = mapped_column(ForeignKey("users.id"), nullable=False, index=True)
vk_user_id: Mapped[int] = mapped_column(Integer, nullable=False, comment="VK owner_id (положительный — пользователь, отрицательный — сообщество)")
display_name: Mapped[str] = mapped_column(String(255), nullable=False, comment="Отображаемое имя (например, 'Моя стена')")
access_token_enc: Mapped[str] = mapped_column(Text, nullable=False, comment="Зашифрованный VK-токен")
token_type: Mapped[str] = mapped_column(String(10), default="user", nullable=False, comment="user | group")
is_active: Mapped[bool] = mapped_column(Boolean, default=True, nullable=False)
expires_at: Mapped[Optional[datetime.datetime]] = mapped_column(DateTime, nullable=True)
last_used_at: Mapped[Optional[datetime.datetime]] = mapped_column(DateTime, nullable=True)
created_at: Mapped[datetime.datetime] = mapped_column(DateTime, server_default=func.now(), nullable=False)
user: Mapped[User] = relationship(back_populates="vk_accounts")
publications: Mapped[list[Publication]] = relationship(back_populates="vk_account", cascade="all, delete-orphan")
class Publication(Base):
__tablename__ = "publications"
id: Mapped[int] = mapped_column(Integer, primary_key=True, autoincrement=True)
vk_account_id: Mapped[int] = mapped_column(ForeignKey("vk_accounts.id"), nullable=False, index=True)
status: Mapped[str] = mapped_column(
String(20),
default="draft",
nullable=False,
comment="draft | scheduled | published | error",
)
# Входные данные
markdown_original: Mapped[str] = mapped_column(Text, nullable=False, comment="Исходный Markdown")
# Результат конвертации
vk_text: Mapped[str] = mapped_column(Text, nullable=False, comment="Текст для VK")
vk_format_data: Mapped[Optional[str]] = mapped_column(Text, nullable=True, comment="JSON format_data")
# Результат публикации
vk_post_id: Mapped[Optional[int]] = mapped_column(Integer, nullable=True)
vk_owner_id: Mapped[Optional[int]] = mapped_column(Integer, nullable=True)
attachments: Mapped[Optional[str]] = mapped_column(Text, nullable=True, comment="JSON attachments")
# Отложенная публикация
scheduled_at: Mapped[Optional[datetime.datetime]] = mapped_column(DateTime, nullable=True)
published_at: Mapped[Optional[datetime.datetime]] = mapped_column(DateTime, nullable=True)
# Ошибки
error_message: Mapped[Optional[str]] = mapped_column(Text, nullable=True)
created_at: Mapped[datetime.datetime] = mapped_column(DateTime, server_default=func.now(), nullable=False)
updated_at: Mapped[datetime.datetime] = mapped_column(DateTime, server_default=func.now(), onupdate=func.now(), nullable=False)
vk_account: Mapped[VkAccount] = relationship(back_populates="publications")
+50
View File
@@ -0,0 +1,50 @@
"""Безопасность: шифрование токенов, генерация API-ключей."""
from __future__ import annotations
import hashlib
import hmac
import secrets
from typing import Optional
from cryptography.fernet import Fernet, InvalidToken
from app.config import settings
def get_fernet() -> Fernet:
"""Создаёт Fernet-инстанс из ключа в settings."""
return Fernet(settings.fernet_key)
def encrypt_token(token: str) -> str:
"""Шифрует VK-токен. Возвращает base64-строку."""
f = get_fernet()
return f.encrypt(token.encode()).decode()
def decrypt_token(encrypted: str) -> Optional[str]:
"""Расшифровывает VK-токен. Возвращает None при ошибке."""
try:
f = get_fernet()
return f.decrypt(encrypted.encode()).decode()
except (InvalidToken, Exception):
return None
def generate_api_key() -> tuple[str, str]:
"""Генерирует пару (api_key, api_key_hash).
api_key — то, что отдаётся пользователю (md2vk_xxx...)
api_key_hash — SHA-256 хеш, хранится в БД.
"""
raw = secrets.token_hex(32)
api_key = f"md2vk_{raw}"
api_key_hash = hashlib.sha256(api_key.encode()).hexdigest()
return api_key, api_key_hash
def verify_api_key(api_key: str, api_key_hash: str) -> bool:
"""Проверяет API-ключ по хранимому хешу (constant-time)."""
computed = hashlib.sha256(api_key.encode()).hexdigest()
return hmac.compare_digest(computed, api_key_hash)
+108
View File
@@ -0,0 +1,108 @@
"""VK API клиент — вызов wall.post с format_data."""
from __future__ import annotations
import json
from typing import Optional
import httpx
from app.config import settings
from app.converters.markdown_to_vk import FormatItem, format_data_json
class VkApiError(Exception):
"""Ошибка VK API. Содержит код ошибки и описание."""
def __init__(self, error_code: int, error_msg: str):
self.error_code = error_code
self.error_msg = error_msg
super().__init__(f"VK API error #{error_code}: {error_msg}")
class VkClient:
"""HTTP-клиент для VK API."""
BASE_URL = "https://api.vk.com/method"
def __init__(self, access_token: str):
self.access_token = access_token
self._client = httpx.AsyncClient(timeout=30.0)
async def close(self):
await self._client.aclose()
async def wall_post(
self,
message: str,
owner_id: Optional[int] = None,
from_group: bool = False,
friends_only: bool = False,
publish_date: Optional[int] = None,
attachments: Optional[str] = None,
signed: Optional[bool] = None,
format_data: Optional[list[FormatItem]] = None,
) -> dict:
"""Публикует запись на стене через wall.post.
Возвращает ответ VK API с полями post_id, owner_id.
"""
params = {
"access_token": self.access_token,
"v": settings.vk_api_version,
"message": message,
}
if owner_id is not None:
params["owner_id"] = owner_id
if from_group:
params["from_group"] = 1
if friends_only:
params["friends_only"] = 1
if publish_date is not None:
params["publish_date"] = publish_date
if attachments is not None:
params["attachments"] = attachments
if signed is not None:
params["signed"] = 1 if signed else 0
if format_data:
params["format_data"] = format_data_json(format_data)
response = await self._client.post(f"{self.BASE_URL}/wall.post", data=params)
data = response.json()
if "error" in data:
err = data["error"]
raise VkApiError(
error_code=err.get("error_code", 0),
error_msg=err.get("error_msg", "Unknown error"),
)
return data.get("response", {})
async def users_get(self, user_ids: str) -> list[dict]:
"""Получает информацию о пользователе (для проверки токена/имени)."""
params = {
"access_token": self.access_token,
"v": settings.vk_api_version,
"user_ids": user_ids,
}
response = await self._client.post(f"{self.BASE_URL}/users.get", data=params)
data = response.json()
if "error" in data:
err = data["error"]
raise VkApiError(
error_code=err.get("error_code", 0),
error_msg=err.get("error_msg", "Unknown error"),
)
return data.get("response", [])
async def check_token(self) -> tuple[bool, str]:
"""Проверяет валидность токена. Возвращает (is_valid, display_name)."""
try:
users = await self.users_get("")
if users:
name = f"{users[0].get('first_name', '')} {users[0].get('last_name', '')}".strip()
return True, name or "Unknown"
return False, "Token invalid"
except VkApiError:
return False, "Token invalid or expired"
+31
View File
@@ -0,0 +1,31 @@
services:
md2vk:
build: .
# Внутренний порт в контейнере — 8420; наружу слушает 127.0.0.1:8420
# (8000 на bigbox занят docker-search-api). Caddy на vps02 → 10.8.0.2:8420.
ports:
- "127.0.0.1:8420:8420"
volumes:
- ./data:/data
- ./logs:/logs
secrets:
- token_encryption_key
environment:
- TOKEN_ENCRYPTION_KEY_FILE=/run/secrets/token_encryption_key
- DATABASE_URL=sqlite+aiosqlite:////data/md2vk.db
- AUDIT_LOG_DIR=/logs
restart: unless-stopped
read_only: true
tmpfs:
- /tmp
healthcheck:
# curl в python:3.12-slim отсутствует — используем python
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8420/api/v1/health', timeout=5)"]
interval: 30s
timeout: 5s
retries: 3
start_period: 15s
secrets:
token_encryption_key:
file: ./secrets/token_encryption_key
+84
View File
@@ -0,0 +1,84 @@
# md2vk — Реквизиты и доступы
**Цель этого файла — собрать все реквизиты/доступы к смежным сервисам, чтобы не искать их потом.**
Секреты (токены, пароли) в git **не** помещаются — вместо них указывается файл-источник. Пароль
приложения хранится только как bcrypt-хэш (см. ниже).
## Схема продакшена
```
Внешний мир
│ https://md2vk.nixg.ru
▼
vps02 (87.242.100.206) ── Caddy (:443, basic auth + fail2ban)
│ reverse_proxy 10.8.0.2:8420 (WireGuard)
▼
bigbox (10.8.0.2) ── docker-контейнер md2vk ── 127.0.0.1:8420 ── SQLite /opt/md2vk/data/md2vk.db
│
▼ VK API: https://api.vk.com/method/wall.post
```
| Роль | Значение |
|------|----------|
| Прод-домен | `md2vk.nixg.ru` → A 87.242.100.206 (vps02) |
| bigbox | 10.8.0.2 (WireGuard), хост проекта `/opt/md2vk` |
| vps02 | 87.242.100.206, ssh-алиас `vps02` (estorozhenko, sudo по ключу) |
| Caddy | контейнер `caddy` на vps02, конфиг `/opt/caddy/Caddyfile`, reload: `docker exec caddy caddy reload` |
| Порт приложения | 127.0.0.1:8420 на bigbox (контейнер), извне не торчит |
| БД | SQLite `/opt/md2vk/data/md2vk.db` (в docker — `/data/md2vk.db`) |
## Git
| Forge | URL | Логин | Как авторизоваться |
|-------|-----|-------|--------------------|
| **gitverse.ru (истина)** | `git@gitverse.ru:kpa39l/md2vk.git` | **kpa39l** | SSH-ключ `/home/estorozhenko/.ssh/gitverse`; PAT — в `git-tokens.env` |
| gitea.nixg.ru (pull mirror) | `https://gitea.nixg.ru/estorozhenko/md2vk.git` | estorozhenko | токен `GITEA_NIXG_TOKEN` |
- Источник токенов: `/opt/hermes/.hermes/secrets/git-tokens.env` (`source` его, не искать токены по каталогам).
Переменные: `GITVERSE_LOGIN=kpa39l`, `GITVERSE_PAT`, `GITEA_NIXG_API`, `GITEA_NIXG_TOKEN`.
- Gitea локальный API (bigbox): `http://127.0.0.1:3000/api/v1`, токен `GITEA_TOKEN` (там же).
- Правила работы с зеркалами: см. skill `git-forge-management`, reference `gitea-pull-mirror-gitverse.md`
(migrate работает только по HTTPS+PAT: `https://oauth2:<PAT>@gitverse.ru/kpa39l/md2vk.git`).
- `tea` CLI: `~/.local/bin/tea`, логин `gitea.nixg-full` — для работы с gitea.nixg.ru.
## Доступы к сервисам (смежные)
| Сервис | URL/адрес | Доступ |
|--------|-----------|--------|
| DNS nixg.ru | NS: ns1..ns4.jino.ru (Jino) | панель регистратора Jino (кто владеет доменом), A-записи |
| VK API | https://dev.vk.com/ru/reference | открытая документация |
| VK ID (приложение) | https://id.vk.ru/about/business/go/docs/ru/vkid/latest/vk-id/connection/create-application | нужен аккаунт VK для client_id/secret |
| Caddy vps02 | /opt/caddy/Caddyfile | ssh vps02, sudo |
| fail2ban vps02 | jail local, `/etc/fail2ban/` | ssh vps02, sudo |
## Пароль приложения (basic auth на Caddy)
- Пользователь: **estorozhenko**
- Пароль: задан пользователем (md2vk!Ghjcgtrn73 — в менеджере паролей пользователя; в git не хранится).
- В Caddyfile: bcrypt-хэш: `$2a$14$T5gAji7gmg1t3Ifxw0CJy.jat9vpFfOiJIE8j5bnHynEVH1q.QTPS` (генерируется заново при создании записи).
- Генерация: `docker exec caddy caddy hash-password --plaintext '<пароль>'`.
- Блокировка: fail2ban ban IP после 5 неудачных попыток подряд, ручной unban:
`fail2ban-client -c /etc/fail2ban unban <ip>` (на vps02). Детали — [security.md](security.md).
## VK OAuth (для OAuth-флоу VK ID)
- Ссылка авторизации: `https://oauth.vk.com/authorize?client_id=...&scope=wall,offline&redirect_uri=...&response_type=token`
- API: `https://api.vk.com/method/wall.post?access_token=...&owner_id=...&message=...&v=5.199`
- Версия API в конфиге: `VK_API_VERSION=5.199`
- Требуется пользовательский токен (не токен сообщества из настроек группы); для стены группы — токен администратора с `wall`, `photos`, публикация через `from_group=1`.
- Ограничение VK: создать статью (лонгрид) через API нельзя; через `wall.post` можно прикрепить уже опубликованную: `attachments=articleXXX_YYY`. Подробности — [vk-api.md](vk-api.md).
## Файлы секретов проекта (не в git)
| Файл | Что это |
|------|---------|
| `/opt/md2vk/secrets/token_encryption_key` | Fernet-ключ шифрования VK-токенов (генерируется `python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"`) |
| `/opt/md2vk/secrets/estorozhenko_api_key.txt` | API-ключ пользователя estorozhenko (md2vk_...) для вызова API |
| `/opt/hermes/.hermes/secrets/git-tokens.env` | токены gitverse/gitea |
## Наблюдаемость
- Лог авторизации/запросов API: `/opt/md2vk/logs/access.log` (JSONL) и `access.{YYYY-MM-DD}.log` (ротация по дням).
В docker: каталог монтируется как `/logs`. Поля: `ts, ip, method, path, api_key_prefix, user_id, status, success, latency_ms, error`.
- Health: `GET /api/v1/health` → `{"status":"ok"}`.
- Метрики доступности/успешности/активной сессии — собираются из лога (см. deploy.md).
+84
View File
@@ -0,0 +1,84 @@
# md2vk — Архитектура
## Обзор
FastAPI-сервис, публикует Markdown на стену VK через `wall.post` с `format_data`.
Полный стек: Python 3.12, FastAPI, SQLAlchemy 2.0 async, SQLite, httpx, cryptography (Fernet), Docker.
## Компоненты
```
┌─────────────────────────────── /opt/md2vk (bigbox) ───────────────────────────────┐
│ │
│ docker (контейнер md2vk, порт 127.0.0.1:8420) │
│ ┌────────────────────────────────────────────────────────────────────┐ │
│ │ app/main.py FastAPI entrypoint, lifespan → init_db │ │
│ │ app/config.py Settings из env (pydantic-settings) │ │
│ │ app/database.py async engine (aiosqlite), get_db │ │
│ │ app/models.py ORM: User, VkAccount, Publication │ │
│ │ app/security.py Fernet encrypt/decrypt, API-key gen/verify │ │
│ │ app/vk_client.py httpx-клиент: wall.post, users.get │ │
│ │ app/converters/markdown_to_vk.py MD → VK format_data + чанки │ │
│ │ app/api/v1.py эндпоинты /api/v1/* │ │
│ │ app/api/deps.py auth по API-ключу (Bearer / тело) │ │
│ └────────────────────────────────────────────────────────────────────┘ │
│ │
│ /data (volume) → SQLite /data/md2vk.db │
│ /logs → access.{date}.log (JSONL аудит) │
│ /run/secrets/token_encryption_key (Docker secret) │
└───────────────────────────────────────────────────────────────────────────────────┘
```
## Поток публикации
1. Клиент (Hermes/skill) `POST /api/v1/publish` c `api_key`, `vk_account_id`, `message_md`
2. Auth: hash api_key → User.is_active
3. Load VkAccount → decrypt_token (Fernet, только в памяти)
4. `markdown_to_vk(message_md)` → chunks (VK-лимит ~4096 симв., режет по абзацам; `@` = 2 симв.)
5. Publication (status=draft|scheduled)
6. Если `publish_date` задан → status=scheduled (планировщик — TODO)
7. Иначе `vk.wall_post(message, owner_id, from_group, ..., format_data=items)`
8. Ответ: post_id, owner_id, url `https://vk.com/wall{owner}_{post}`; ошибки → status=error + error_message
## Порт/интерфейсы
| Интерфейс | Адрес | Назначение |
|-----------|-------|------------|
| Локальный | 127.0.0.1:8420 | внутренний (Caddy на vps02 → 10.8.0.2:8420) |
| VK API | https://api.vk.com/method | исходящий (wall.post, users.get) |
| Swagger | /docs | openapi, за basic auth |
## База данных (SQLite)
| Таблица | Ключевые поля |
|---------|---------------|
| users | id, name, email, api_key_hash, api_key_prefix, is_active, created_at, updated_at |
| vk_accounts | id, user_id→users, vk_user_id (owner_id, `-` = сообщество), display_name, access_token_enc (Fernet), token_type (user\|group), is_active, expires_at, last_used_at |
| publications | id, vk_account_id→vk_accounts, status (draft\|scheduled\|published\|error), markdown_original, vk_text, vk_format_data, vk_post_id, vk_owner_id, attachments, scheduled_at, published_at, error_message |
## Отложенные посты
Модель поддерживает `scheduled_at`, `/publish` с `publish_date` создаёт запись `scheduled`.
**Планировщика нет** — открытая задача (worker-процесс/cron, выбирающий `status=scheduled AND scheduled_at<=now`).
## Ошибки VK API
Код | Смысл
----|------
`VkApiError` | обёртка: `error_code` + `error_msg` из ответа VK; пишется в `publications.error_message`
## Конвертер Markdown
| Markdown | VK format |
|----------|-----------|
| `**bold**`, `__bold__` | `bold` |
| `*italic*`, `_italic_` | `italic` |
| `***bold italic***` | `bold` + `italic` |
| `` `code` `` | `inline_code` |
| `[text](url)` | `link` (+url) |
| `# H1..H6` | `bold` (uppercase) |
| `> quote` | `italic` |
| ```` ```code```` | `code` (без format) |
| `---` | `───` |
Длинный текст режется на чанки по `\n\n` (абзацы), запас 10% от лимита 4096.
+127
View File
@@ -0,0 +1,127 @@
# md2vk — Деплой
## Топология
```
https://md2vk.nixg.ru (Caddy на vps02, basic auth)
└─ reverse_proxy 10.8.0.2:8420 (WireGuard: vps02 .4 → bigbox .1)
└─ docker-контейнер md2vk на bigbox, 127.0.0.1:8420
```
- Порт приложения **8420** (8000 занят docker-search-api на bigbox).
- Контейнер слушает на 127.0.0.1:8420 (снаружи bigbox не открыт).
## bigbox (10.8.0.2) — приложение
```bash
cd /opt/md2vk
make docker-up # docker compose up -d --build
docker ps | grep md2vk # статус
curl -s http://127.0.0.1:8420/api/v1/health # {"status":"ok"}
```
- Данные: named volume `md2vk_data` → `/data/md2vk.db` (SQLite).
- Секрет: `./secrets/token_encryption_key` → `/run/secrets/token_encryption_key`.
- Логи аудита: `./logs/` монтируется в `/logs`.
- Health: `/api/v1/health`, проверяется Docker healthcheck.
- Восстановление после перезагрузки: `restart: unless-stopped`.
- Если надо пересоздать БД — удалить том (только по явной команде, данные!):
`docker compose down -v && make docker-up` (НЕ делать без подтверждения).
## Создание пользователя и API-ключа
```bash
cd /opt/md2vk
source venv/bin/activate
TOKEN_ENCRYPTION_KEY_FILE=/opt/md2vk/secrets/token_encryption_key ./scripts/create_user.py \
--name estorozhenko --api-key-out secrets/estorozhenko_api_key.txt
# вывод: API key сохранён в secrets/estorozhenko_api_key.txt (md2vk_...)
```
Источник: `scripts/create_user.py` (добавляет User с сгенерированным ключом; ключ отображается один раз).
## vps02 (87.242.100.206) — Caddy
Файл `/opt/caddy/Caddyfile` на vps02, секция:
```
md2vk.nixg.ru {
basic_auth /* {
estorozhenko $2a$14$T5gAji7gmg1t3Ifxw0CJy.jat9vpFfOiJIE8j5bnHynEVH1q.QTPS
}
reverse_proxy 10.8.0.2:8420
}
```
Применить (контейнер caddy, монтирует Caddyfile):
```bash
ssh vps02
docker exec caddy caddy validate --config /etc/caddy/Caddyfile # проверить синтаксис
docker exec caddy caddy reload --config /etc/caddy/Caddyfile # перезагрузить
# если нужно: docker restart caddy
```
- TLS: Caddy автоматически выпускает Let's Encrypt сертификат для md2vk.nixg.ru (acme в Caddyfile: `email kpa39l@yandex.ru`).
- Сертификат на caddy_data (volume), переживает рестарты.
## vps02 — fail2ban (блокировка после 5 попыток)
Пакет ставится на vps02 (Debian/Ubuntu):
```bash
ssh vps02
sudo apt-get update && sudo apt-get install -y fail2ban
```
Конфиг jail (`/etc/fail2ban/jail.local`) и фильтр (`/etc/fail2ban/filter.d/md2vk.conf`):
```ini
# /etc/fail2ban/filter.d/md2vk.conf
[Definition]
failregex = ^.*"status":401.*
ignoreregex =
```
```ini
# /etc/fail2ban/jail.local
[md2vk]
enabled = true
port = http,https
filter = md2vk
logpath = /var/log/caddy/access.log
maxretry = 5
findtime = 600
bantime = -1
action = iptables-allports
```
- Лог Caddy в JSON: настроить в Caddyfile `log { output file /var/log/caddy/access.log format json }` (глобальный блок).
- Перезапуск: `sudo systemctl restart fail2ban`.
- Проверка: `sudo fail2ban-client status md2vk`.
- Ручной unban: `sudo fail2ban-client -c /etc/fail2ban unban <ip>`.
## Сквозная проверка
```bash
# 1. health через Caddy (без auth → 401)
curl -s -o /dev/null -w "%{http_code}\n" https://md2vk.nixg.ru/api/v1/health # 401
# 2. health c auth → 200
curl -s -u 'estorozhenko:<пароль>' https://md2vk.nixg.ru/api/v1/health # {"status":"ok"}
# 3. публикация не требует VK-токена? нет — конвертация:
curl -s -u 'estorozhenko:<пароль>' -H 'Authorization: Bearer <api_key>' \
-X POST https://md2vk.nixg.ru/api/v1/convert \
-H 'Content-Type: application/json' \
-d '{"message_md":"**test** *curl*"}' # format_data
# 4. баним проверкой: 5 раз неверный пароль → fail2ban ban IP
for i in 1 2 3 4 5 6; do curl -s -o /dev/null -w "%{http_code}\n" -u 'estorozhenko:wrong' https://md2vk.nixg.ru/api/v1/health; done
# → 401 ×6, затем соединение DROP (curl timeout)
sudo fail2ban-client status md2vk # IP в banned
sudo fail2ban-client unban <ваш-ip>
```
## Восстановление после аварии
- Приложение: `docker compose up -d --force-recreate` на bigbox.
- Caddy: `docker restart caddy` на vps02 (volume caddy_data хранит сертификаты).
- БД: том `md2vk_data`; бэкап = копия `/opt/md2vk/data/md2vk.db` (вне контейнера) — включена в homelab-backup (/opt/backup).
+65
View File
@@ -0,0 +1,65 @@
# md2vk — Документация
Указатель документации проекта. Все реквизиты и доступы — в [access.md](access.md).
## Разделы
| Файл | Содержание |
|------|------------|
| [index.md](index.md) | Этот указатель, обзор проекта |
| [access.md](access.md) | **Все реквизиты и доступы к смежным сервисам** (vps02, Caddy, gitverse, gitea, DNS, VK API, fail2ban) |
| [architecture.md](architecture.md) | Архитектура, компоненты, порты, схема |
| [vk-api.md](vk-api.md) | Порядок взаимодействия с VK API: OAuth-флоу, wall.post, format_data, ограничения (лонгриды) |
| [security.md](security.md) | Безопасность: пароль, basic auth, блокировка после 5 попыток, Fernet, API-ключ |
| [deploy.md](deploy.md) | Деплой: docker на bigbox, Caddy на vps02, fail2ban |
| [status.md](status.md) | Статус реализации по фазам (в т.ч. история) |
## Обзор
Сервис публикации Markdown-текста на стене VK через официальный VK API (`wall.post`).
```
┌─────────────┐ ┌─────────────┐ ┌──────────────┐
│ Hermes │────▶│ md2vk │────▶│ VK API │
│ Agent │ │ :8420 │ │ wall.post │
│ (skill) │◀────│ FastAPI │ │ vk.com │
└─────────────┘ └─────────────┘ └──────────────┘
```
- Публикация Markdown → VK wall.post с `format_data` (жирный, курсив, код, ссылки, заголовки, цитаты)
- Конвертация Markdown → VK format_data без публикации (preview)
- Управление VK-аккаунтами (несколько страниц), шифрование токенов (Fernet)
- Архив публикаций с фильтрацией по статусу
- Отложенные посты (статус `scheduled`; планировщик — открытая задача)
## Внешние точки
| Что | Адрес |
|-----|-------|
| Прод | https://md2vk.nixg.ru (basic auth, см. [security.md](security.md)) |
| Swagger | https://md2vk.nixg.ru/docs (за basic auth) |
| Локально | http://127.0.0.1:8420 (bigbox), Swagger http://127.0.0.1:8420/docs |
## Быстрый старт (dev)
```bash
cd /opt/md2vk
source venv/bin/activate
pip install -r requirements.txt
# ключ шифрования уже есть: secrets/token_encryption_key (не в git)
make dev # uvicorn :8000 --reload (для dev; прод-порт 8420 в docker)
```
## Git
Схема: **gitverse.ru (истина) → gitea.nixg.ru (pull mirror)**. Подробности в [access.md](access.md).
## Открытые задачи (см. [status.md](status.md) и openspec/)
- Планировщик отложенных постов (worker + cron)
- Web UI (форма поста + превью), сейчас только API
- OAuth-флоу VK VK ID (кнопка «Прикрепить аккаунт») — сейчас токен вводится вручную
- Unit/integration тесты (pytest)
- Rate limiting (in-memory bucket)
- Retry при сетевых ошибках VK API
- Read-only rootfs в Docker (частично: `read_only: true` в compose)
+71
View File
@@ -0,0 +1,71 @@
# md2vk — Безопасность
## Два уровня доступа
### 1. Внешний — Caddy basic_auth (на vps02)
- Весь https://md2vk.nixg.ru закрыт HTTP Basic Auth.
- Пользователь: **estorozhenko**; пароль — у пользователя, в конфиге только bcrypt-хэш.
- Хэш в Caddyfile: `admin $2a$14$T5gAji7gmg1t3Ifxw0CJy.jat9vpFfOiJIE8j5bnHynEVH1q.QTPS`
(генерируется `docker exec caddy caddy hash-password --plaintext '<пароль>'`).
- Без basic auth сервис наружу не отдаётся.
### 2. Внутренний — API-ключ (FastAPI)
- Все эндпоинты `/api/v1/*` (кроме `/health`) требуют API-ключ `md2vk_...`:
- в заголовке `Authorization: Bearer <api_key>` (GET) или в теле `{"api_key": ...}` (POST);
- API-ключ даёт право публиковать, но **не позволяет прочитать VK-токен** (raw токен не возвращается ни одним эндпоинтом).
- Хранится только SHA-256 хэш (`api_key_hash`), сравнение constant-time (`hmac.compare_digest`).
- Пользователь estorozhenko + API-ключ: создаётся скриптом, ключ кладётся в `secrets/estorozhenko_api_key.txt` (не в git).
## Блокировка после 5 неудачных попыток (fail2ban на vps02)
- На vps02 установлен fail2ban, jail `md2vk`:
- следит за логами Caddy (JSON: `/var/log/caddy/access.log`),
- фильтр: basic auth failure (`401` с `"err"`, absence of `"user_id"`):
```
^.*"status":401.*
```
- правило: ban IP после **5 неудачных попыток подряд** (`maxretry=5`, `findtime=600`),
- наказание: **ban до ручного снятия** (`bantime = -1`),
- действие: `iptables-allports` (ban на уровне ядра, DROP).
- **Ручная разблокировка** (на vps02, sudo):
```bash
fail2ban-client -c /etc/fail2ban unban <ip>
fail2ban-client -c /etc/fail2ban status md2vk # проверить
```
- Логи fail2ban: `journalctl -u fail2ban -e` или `/var/log/fail2ban.log`.
## Шифрование VK-токенов
- VK OAuth-токены в БД только в шифрованном виде: **Fernet (AES-128-CBC + HMAC-SHA256)**.
- Ключ — Docker secret `/run/secrets/token_encryption_key` (файл на bigbox: `secrets/token_encryption_key`, не в git).
- Расшифровка только в памяти при публикации.
## Rate limiting
- В конфиге `RATE_LIMIT_PER_MINUTE=10` (запросов/мин на VK-аккаунт).
- In-memory bucket — НЕ реализован (открытая задача).
## Аудит-лог
- Пишется JSONL в `/opt/md2vk/logs/access.{YYYY-MM-DD}.log` (вне контейнера — `logs/` на bigbox).
- Событие на каждый запрос `/api/v1/*`: `ts, ip, method, path, api_key_prefix, user_id, status, success, latency_ms, error`.
- Используется для мониторинга (доступность, успешность, активная сессия) и расследований.
- Caddy на vps02 пишет свой access-лог (используется fail2ban).
## Матрица рисков
| Сценарий | Последствия | Защита |
|---|---|---|
| Утечка .db | Токены зашифрованы | Fernet + Docker secret |
| Утечка API-ключа | Можно постить, но не украсть токен | API-ключ ≠ VK-токен |
| Брутфорс basic auth | Полный доступ к веб-интерфейсу API | fail2ban ban после 5 попыток, ручной unban |
| Перехват HTTP | — | HTTPS (Caddy/Let's Encrypt) |
| Компрометация контейнера | Полный доступ к токенам | read-only rootfs, audit log |
| Отзыв токена VK | Пост не выйдет | VK вернёт ошибку → error_message |
## Правило пользователя
> Никогда не удалять файлы пользователя без явного подтверждения. Пароли и токены не сохранять в коде —
> только через переменные окружения, Docker secrets или файлы, исключённые из git (.gitignore).
+59
View File
@@ -0,0 +1,59 @@
# md2vk — Статус (история изменений)
> Актуальный статус работ — в `openspec/` и `todo`-файлах; здесь хроника и границы.
## 2026-09: Документация, деплой, git, openspec
**Сделано:**
- [x] Аудит проекта (FastAPI ядро, Phase 1)
- [x] Документация в `docs/` (index, access, architecture, vk-api, security, deploy, status) + `AGENTS.md`
- [x] Аудит-лог авторизации (JSONL, ротация по дням) — см. `app/api/audit.py` + middleware
- [x] Docker: порт 8420 (8000 занят), bind `./data`→`/data`, `./logs`→`/logs`, HEALTHCHECK через python (curl в slim-образе нет)
- [x] openspec инициализирован (specs/ baseline)
- [x] git init, push на gitverse.ru (kpa39l/md2vk), pull mirror в gitea.nixg.ru (estorozhenko/md2vk)
- [x] Caddy на vps02: md2vk.nixg.ru + basic_auth estorozhenko (bcrypt), reverse_proxy 10.8.0.2:8420
- [x] fail2ban на vps02: jail md2vk, ban после 5 попыток, ручной unban
- [x] Сквозная проверка: https + auth + блокировка + unban
## Phase 1 — Ядро (DONE, из STATUS.md)
- Каркас проекта, структура директорий
- Config из env (pydantic-settings)
- Async SQLAlchemy + SQLite, инициализация БД
- ORM-модели (User, VkAccount, Publication)
- Fernet-шифрование/дешифрование токенов
- Генерация и верификация API-ключей
- Конвертер Markdown → VK format_data
- VK API клиент (wall.post, users.get, check_token)
- Pydantic-схемы запросов/ответов
- API: /health, /accounts (CRUD), /publish, /convert, /publications
- Аутентификация по API-ключу (заголовок + тело)
- Генерация ключа шифрования
- Проверка импортов и запуск
- Тест конвертации через API (curl)
## Открытые задачи
- [ ] Планировщик отложенных постов (status=scheduled → wall.post). Модель готова, worker нет.
- [ ] OAuth-флоу VK ID (кнопка «Прикрепить аккаунт»); нужны client_id/secret VK-приложения
- [ ] Web UI (форма поста + превью)
- [ ] Unit-тесты конвертера (pytest)
- [ ] Integration-тесты API (pytest + httpx)
- [ ] Rate limiting (in-memory bucket, RATE_LIMIT_PER_MINUTE)
- [ ] Retry при сетевых ошибках VK API
- [ ] Graceful shutdown
- [ ] Read-only rootfs (уже `read_only: true` в compose, но /logs мешает; пересмотреть)
- [ ] CORS (ограничение по origin)
- [ ] Обработка длинных постов (multipart: пост + комментарии)
- [ ] Hermes skill md2vk (проверка сервиса, публикация, добавление аккаунта)
## Границы Phase 1
- Конвертация Markdown → VK format_data (жирный, курсив, код, ссылки, заголовки, цитаты, блоки кода)
- Публикация поста на стене VK
- Шифрование токенов (Fernet + Docker secret)
- Аутентификация по API-ключу
- Управление VK-аккаунтами (добавить, список, удалить)
- Архив публикаций с фильтрацией
- Конвертация без публикации (preview)
- Отложенные посты: только запись `scheduled` (без планировщика)
+83
View File
@@ -0,0 +1,83 @@
# md2vk — Взаимодействие с VK API
> Источник: официальная документация VK (dev.vk.com / id.vk.ru), проверено 2026-09.
> Услуга работает через официальный протокол OAuth 2.0 и VK API — никакого «взлома».
## Как это работает
1. **OAuth-авторизация.** Пользователь нажимает «Прикрепить аккаунт» → редирект на VK.
Пользователь подтверждает вход и выдаёт приложению права (scopes, обязателен `wall`).
Сервис не получает пароль — только временный код/токен.
2. **Access Token.** VK возвращает сервису access token — цифровой ключ с ограниченными правами
(например, только публикация записей).
3. **Публикация через API.** Сервис вызывает `wall.post` с текстом/вложениями, `owner_id`, `from_group`.
Авторизация — `access_token` в параметрах запроса.
## Ссылки на официальную документацию
| Что | Ссылка |
|-----|--------|
| Создание и настройка приложения (VK ID, Standalone) | https://id.vk.com/about/business/go/docs/ru/vkid/latest/vk-id/connection/create-application |
| Общая документация по API | https://dev.vk.com/ru/reference |
| Авторизация (OAuth 2.0/2.1) | https://id.vk.com/about/business/go/docs/ru/vkid/latest/vk-id/connection/start-integration/auth-without-sdk/auth-without-sdk-web |
| Метод wall.post | https://dev.vk.com/ru/method/wall.post |
| Создать приложение (dev.vk.com) | https://dev.vk.com |
## OAuth-флоу (ссылка для получения токена)
```
https://oauth.vk.com/authorize?client_id=<client_id>&scope=wall,offline&redirect_uri=<redirect>&response_type=token
```
- `client_id` — ID приложения VK (см. VK ID).
- `scope` — обязателен `wall`; `offline` — долгоживущий токен.
- `response_type=token` — токен приходит в фрагменте редиректа.
- После ответа: `access_token`, `user_id`, `expires_in` (0 = бессрочно).
## Публикация (wall.post)
```
https://api.vk.com/method/wall.post
POST data: access_token, v=5.199, owner_id, message, from_group, attachments, publish_date, format_data
```
Параметры в нашем клиенте (`app/vk_client.py`):
| Параметр | Когда | Значение |
|----------|-------|----------|
| `owner_id` | группа | отрицательный ID сообщества (`-123`), для пользователя не передаём |
| `from_group` | группа | `1` — пост от имени группы |
| `friends_only` | опц. | только друзьям |
| `publish_date` | отложка | Unix timestamp |
| `attachments` | опц. | `photo123_456,...` |
| `signed` | группа | подпись автора |
| `format_data` | всегда | JSON `{"version":1,"items":[...]}` |
Ответ: `{"response":{"post_id":N,"owner_id":M}}` → URL `https://vk.com/wall{M}_{N}`.
### Важно про токены
- Для **личной стены** — токен пользователя.
- Для **стены сообщества** — токен **администратора группы** с правами `wall` и `photos`.
- Токены сообщества из настроек группы («Работа с API») для `wall.post` **не подходят** —
нужен именно пользовательский токен.
## Лонгриды (статьи) — ограничение
- **Создавать статьи через официальный VK API нельзя.** В FAQ VK: «методов для работы с лонгридами пока что нет».
- Можно **опубликовать на стене существующую статью** через `wall.post`:
`attachments=articleXXX_YYY`, где `XXX` — ID автора (для сообщества — с минусом), `YYY` — ID статьи.
Статья должна быть уже опубликована (черновик прикрепить нельзя).
- Значит, полный автоматический дубликат блога (генерация лонгридов «из коробки») невозможен.
Варианты: посты+фото+ссылки через API, статьи вручную, гибрид.
## Версия API
- В конфиге `VK_API_VERSION=5.199` (`app/config.py`).
- Проверка токена: `users.get` (пустой user_ids → текущий пользователь).
## Ошибки
Формат ошибки VK: `{"error":{"error_code":N,"error_msg":"..."}}`.
Наш клиент бросает `VkApiError(error_code, error_msg)`; в API публикации ошибка пишется в
`publications.error_message`, ответ `success=false`.
+32
View File
@@ -0,0 +1,32 @@
schema: spec-driven
# Project context (optional)
# This is shown to AI when creating artifacts.
# Add your tech stack, conventions, style guides, domain knowledge, etc.
# Example:
# context: |
# Tech stack: TypeScript, React, Node.js
# We use conventional commits
# Domain: e-commerce platform
# Per-artifact rules (optional)
# Add custom rules for specific artifacts.
# Example:
# rules:
# proposal:
# - Keep proposals under 500 words
# - Always include a "Non-goals" section
# tasks:
# - Break tasks into chunks of max 2 hours
# Per-operation guidance (optional)
# Add advisory guidance for how apply and archive work should be conducted.
# This is separate from artifact rules above.
# Example:
# operations:
# apply:
# guidance:
# - Keep test summaries concise
# archive:
# guidance:
# - Summarize the archive outcome before finishing
View File
+133
View File
@@ -0,0 +1,133 @@
# publishing/markdown Specification
## Purpose
Перечень требований к сервису md2vk — публикация Markdown на стену VK через официальный VK API,
с защитой доступа, аудитом и инфраструктурой деплоя.
## Requirements
### Requirement: Конвертация Markdown в формат VK
Сервис MUST конвертировать Markdown-текст в VK format_data (bold, italic, link, inline_code) и
разбивать длинные посты на чанки (лимит ~4096 символов, учёт `@` = 2 символа).
#### Scenario: конвертация без публикации
- **WHEN** клиент вызывает `POST /api/v1/convert` с валидным `message_md` и API-ключом
- **THEN** сервис возвращает `{text, format_data:{version:1,items:[...]}}` без обращения к VK
### Requirement: Публикация поста на стене VK
Сервис MUST публиковать посты через официальный VK API `wall.post` (access_token, owner_id,
from_group, format_data), сохраняя запись в архив с статусом published/error.
#### Scenario: успешная публикация
- **WHEN** клиент вызывает `POST /api/v1/publish` с валидным API-ключом, vk_account_id и message_md
- **THEN** сервис вызывает VK API wall.post и возвращает `{success:true, vk_post_id, vk_owner_id, url}`,
а публикация получает статус `published`
#### Scenario: ошибка VK API
- **WHEN** VK API возвращает ошибку (невалидный/отозванный токен, лимиты)
- **THEN** сервис возвращает `{success:false, error}` и сохраняет публикацию со статусом `error`
и текстом ошибки в `error_message`
### Requirement: Управление VK-аккаунтами
Сервис MUST поддерживать несколько VK-аккаунтов на пользователя: добавление (с проверкой токена
через users.get), список, soft-delete; токены хранить только зашифрованными.
#### Scenario: добавление аккаунта с валидным токеном
- **WHEN** клиент вызывает `POST /api/v1/accounts` с api_key и корректным access_token (scope wall)
- **THEN** сервис проверяет токен через VK users.get, шифрует его Fernet и сохраняет аккаунт
#### Scenario: дубликат аккаунта
- **WHEN** клиент добавляет VK-аккаунт, который уже есть у пользователя (тот же vk_user_id)
- **THEN** сервис возвращает 409 и не создаёт дубликат
### Requirement: Аутентификация по API-ключу
Все эндпоинты `/api/v1/*` (кроме `/health`) MUST требовать API-ключ `md2vk_...` (Bearer-заголовок
или поле `api_key` в теле); в БД хранится только SHA-256 хэш; сравнение constant-time.
API-ключ SHOULD NOT позволять прочитать VK-токен.
#### Scenario: запрос без ключа
- **WHEN** клиент вызывает `/api/v1/accounts` без Authorization-заголовка
- **THEN** сервис возвращает 401 с сообщением об использовании Bearer
#### Scenario: неверный ключ
- **WHEN** клиент передаёт ключ, хэш которого не найден в БД
- **THEN** сервис возвращает 401
### Requirement: Шифрование VK-токенов
VK OAuth-токены MUST храниться в БД только в зашифрованном виде (Fernet: AES-128-CBC + HMAC-SHA256);
ключ шифрования — из Docker secret `/run/secrets/token_encryption_key`; расшифровка только в памяти.
#### Scenario: утечка файла БД
- **WHEN** файл `data/md2vk.db` попадает в чужие руки без ключа шифрования
- **THEN** VK-токены не могут быть расшифрованы
### Requirement: Внешний контроль доступа (basic auth + fail2ban)
Прод-домен https://md2vk.nixg.ru MUST быть закрыт HTTP Basic Auth (пользователь estorozhenko,
bcrypt-хэш в Caddyfile). Сервис MUST блокировать IP после 5 неудачных попыток подряд (fail2ban,
jail `md2vk`), с ручной разблокировкой (fail2ban-client unban).
#### Scenario: неверный пароль 5 раз подряд
- **WHEN** клиент 5 раз подряд отправляет запросы с неверным паролем basic auth
- **THEN** fail2ban банит IP (bantime=-1), последующие запросы получают отказ соединения
#### Scenario: ручная разблокировка
- **WHEN** администратор выполняет `fail2ban-client unban <ip>` на vps02
- **THEN** IP снова может обращаться к сервису
### Requirement: Аудит-лог запросов API
Сервис MUST логировать каждый запрос `/api/v1/*` в JSONL (ts, ip, method, path, api_key_prefix,
user_id, status, success, latency_ms, error) с ротацией по дням.
#### Scenario: запрос к API
- **WHEN** любой запрос к `/api/v1/*` завершается
- **THEN** в каталоге логов (AUDIT_LOG_DIR, по умолчанию ./logs) появляется строка JSON
с полями ts, status, latency_ms и др.
### Requirement: Деплой через docker и Caddy
Приложение MUST запускаться docker-контейнером на bigbox, слушать 127.0.0.1:8420, монтировать
./data → /data (SQLite), ./logs → /logs, секрет token_encryption_key; Caddy на vps02 MUST
проксировать md2vk.nixg.ru → 10.8.0.2:8420 с basic auth и TLS (Let's Encrypt).
#### Scenario: проверка здоровья через Caddy
- **WHEN** выполняется `curl https://md2vk.nixg.ru/api/v1/health` с верными учётными данными
- **THEN** возвращается `{"status":"ok"}`
### Requirement: Git-зеркала
Репозиторий MUST иметь истину на gitverse.ru (kpa39l/md2vk) и pull mirror на gitea.nixg.ru
(estorozhenko/md2vk); секреты и данные не коммитятся (.gitignore).
#### Scenario: синхронизация зеркала
- **WHEN** в gitverse появляется новый коммит в main
- **THEN** gitea.nixg.ru подтягивает его по расписанию (mirror interval)
### Requirement: Отложенные посты
Сервис MUST сохранять посты с `publish_date` в статусе `scheduled`. Планировщик (worker,
выполняющий wall.post для scheduled-постов) — открытая задача (SHOULD в будущем).
#### Scenario: отложенная публикация
- **WHEN** клиент вызывает `/api/v1/publish` с publish_date в будущем
- **THEN** публикация сохраняется со статусом `scheduled` и не отправляется в VK сразу
+9
View File
@@ -0,0 +1,9 @@
fastapi>=0.115.0
uvicorn[standard]>=0.30.0
pydantic>=2.0.0
pydantic-settings>=2.0.0
httpx>=0.27.0
sqlalchemy[asyncio]>=2.0.0
aiosqlite>=0.20.0
cryptography>=42.0.0
python-multipart>=0.0.9
+70
View File
@@ -0,0 +1,70 @@
#!/usr/bin/env python3
"""Создание пользователя и API-ключа md2vk.
Пример:
TOKEN_ENCRYPTION_KEY_FILE=secrets/token_encryption_key \
./scripts/create_user.py --name estorozhenko \
--api-key-out secrets/estorozhenko_api_key.txt
Ключ показывается один раз и (опционально) сохраняется в файл (не в git!).
"""
from __future__ import annotations
import argparse
import asyncio
import sys
from pathlib import Path
# Даём импортировать app при запуске из любой директории
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
from app.database import init_db, async_session_factory # noqa: E402
from app.models import User # noqa: E402
from app.security import generate_api_key # noqa: E402
def main() -> int:
parser = argparse.ArgumentParser(description="Create md2vk user")
parser.add_argument("--name", required=True, help="display name")
parser.add_argument("--email", default=None, help="optional email")
parser.add_argument(
"--api-key-out",
default=None,
help="save API key to this file (NOT committed to git)",
)
args = parser.parse_args()
async def create() -> None:
await init_db()
async with async_session_factory() as session:
key, key_hash = generate_api_key()
user = User(
name=args.name,
email=args.email,
api_key_hash=key_hash,
api_key_prefix=key[:12],
is_active=True,
)
session.add(user)
await session.commit()
print(f"User created: id={user.id} name={user.name}")
print(f"API key: {key}")
print(f"prefix: {key[:12]}")
if args.api_key_out:
out = Path(args.api_key_out)
out.parent.mkdir(parents=True, exist_ok=True)
out.write_text(key + "\n", encoding="utf-8")
out.chmod(0o600)
print(f"API key saved to {out}")
try:
asyncio.run(create())
except Exception as exc: # noqa: BLE001
print(f"ERROR: {exc}", file=sys.stderr)
return 1
return 0
if __name__ == "__main__":
raise SystemExit(main())