Skip to content

Reach teammates' terminals through the gateway #11

Description

@iamnbutler

Terminals are owner-only and don't reach peers' or hosted channels' workspaces through another gateway. The owner already gets terminals by connecting directly to the host that runs a channel's workspace, including a hosted channel's workspace host. What's missing is forwarding through another gateway to that workspace, plus terminal session discovery and rights for teammates (scope audit).

Tracked by #58. Migrated from TODO.md — During dogfooding.

Activity

  1. iamnbutler commented on Oct 6, 2026

    @iamnbutler
    ContributorAuthor

    Read-only scope audit at main 6dc0f1c, linked to dogfooding #5 and distributed-work meta #58. These are code-path findings, not new runtime acceptance.

    Missing path: all four terminal operations are owner-only (gateway.ts); terminal open requires a local catalog record and has no peer/workspace forwarding (handler). The existing code does permit the owner's direct tailnet browser and hosted channels opened on their workspace host. Another gateway reaching that workspace remains unsupported; the hosted cell itself has no shell.

    Design required before implementation:

    • Creating a new shell in a teammate's checkout differs from discovering/attaching to their existing terminal. IDs currently live in client layouts; there is no session-discovery protocol.
    • Direct PTY access runs as the host OS user. Read, input, resize, and close rights are not defined by the existing switch, which controls only new agent invocations (team semantics). Preserve the tailnet trust model; don't silently broaden that flag.
    • Reattach and continuation operations currently trust terminal IDs. Peer exposure needs channel/participant binding and explicit existing-session semantics (terminal manager).
    • Define output/exit forwarding, reconnect/replay, simultaneous input/resize, close versus detach, orphan timeout, and kill/archive/delete behavior.

    Recommendation: no straight-proxy patch. An owner-only route through their other machines is a smaller possible first slice; teammate session access needs the decisions above. Validate the owner route on two machines and teammate rights with two people. #159 addresses transcript watches, while #53 addresses agent jobs; neither implements this terminal feature.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions