This file tracks the implementation progress of features and tasks in devRAG.
- Added
AGENTS.mdto define global architecture rules. - Created
.agents/rules/for Go and Python. - Created
.agents/skills/add-new-api-endpoint/with multi-step endpoint guidelines. - Added a rule to ensure
README.mdandimplementation.mdare updated after every task.
- Executed tasks in
01-monorepo-setup.md. - Initialized Go, Python, and React workspaces.
- Configured base linters.
- Created strict Go (yaml.v3) and Python (Pydantic) parsers.
- Bound them to
conf/service_conf.yaml. - Verified 1:1 cross-language matching via automated CLI test suites.
- Dual-ORM (GORM + Peewee) setup mapped identically to the same tables (
tenant,user,user_tenant). - Enforced multi-tenancy foundation and cross-language compatibility.
- Established API Gateway using Gin.
- Implemented middlewares: CORS, Logger, Recovery.
- Added health handler at
/api/v1/health.
- Built the Python ASGI gateway (Quart/Hypercorn).
- Scoped ML and Agents blueprints.
- Ensured independent testability alongside the unified configuration ecosystem.
- Completed Go authentication boundary using bcrypt, jwt-go, and go-redis.
- Achieved complete
go testintegration coverage.
- Centralized auth boundaries ensuring secure mapping of
User↔Tenantnatively exposingtenant_id. - Replicated logic gracefully in Python
api/apps/auth_decorator.py.
- Fully established safe RBAC parsing through the
UserTenantdatabase layer seamlessly into both API gateway and Python worker loop contexts. - Integrated spoofing protection avoiding payload overrides safely terminating any injection attempt.
- Enforced complete API isolation where queries actively map to DB states matching authenticated bounds avoiding untrusted IDs!
- Executed Runtime and Integration verification proving cross-tenant deletion failures!
- Implemented transactional logic cleaning up MinIO objects if DB insertion fails minimizing orphaned objects.
- Integration tests verified cross-tenant upload denial natively asserting
404 Not Foundfor mismatched datasets.