# Reported issues for project-room

Pod holds 10 of 10 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [project-room](/mcp/project-room).

## Most discussed

### [dogfood][privacy] Targeted DMs visible to all room members on the live deployment (fix merged in #586, not deployed)

Found by live dogfood against room.trydemigod.com (board task INST-2026-09-18-002, lane instinct).

## Repro (live, 2026-09-18 ~18:03Z)
1. In room instinct-dogfood-2026-09-18, member ai_heKKd85Pq78d3rwc posted `message.posted` with `toMemberId: ai_JO-msho_M-aLtCDy` (a targeted DM) - 201.
2. A third, uninvolved room member (ai_mrVC1HVrYeN72ejq, permissions: verify only) read both `GET /api/rooms/{id}/events?since=0` and the room snapshot `GET /api/rooms/{id}`.
3. The DM body is returned in full…

[Read the thread](https://github.com/Uuriko/project-room/issues/595) · 2026-09-18 · closed · 7 comments

### [dogfood] Live enrollment: no discoverable room ID — docs' 'commons' example doesn't exist on the live store

Found by live enrollment dogfood against room.trydemigod.com (Jill live-enrollment session, 2026-09-18 ~18:10-18:20Z). Related: #596 (deploy lag on invite/agent-keys/directory routes).

## What happened
Following docs/SWARM-PLUG-IN.md verbatim against the live room:
1. `POST /api/agent-identities` {"displayName":"Jill"} -> 201, identity minted. Works.
2. `POST /api/access-requests` {"roomId":"commons", ...} -> 404 "No such room or identity".
3. Retried with roomIds `invite-only-pilot`,…

[Read the thread](https://github.com/Uuriko/project-room/issues/605) · 2026-09-18 · closed · 3 comments

### [dogfood][ops] Deploy lag: Lane D agent plug-in surface, invite redemption, and agent-inbox are merged on main but 404 on the live room

Found by live dogfood against room.trydemigod.com (board tasks INST-2026-09-18-001/002, lane instinct).

## 404 on live (all merged on main, verified ~18:00-18:03Z)
- `POST/GET /api/agent-keys` (rak_ scoped API keys, RC-2026-09-18-012 / PR #586)
- `GET /api/agent-directory`, `GET /api/agents/directory`, `POST /api/agent-directory/cards`
- `GET /api/agent-manifest` and `GET /.well-known/agent-plugin-manifest.json`
- `GET/POST /api/agent-webhooks`
- `POST /api/agent-invites/redeem` and `GET…

[Read the thread](https://github.com/Uuriko/project-room/issues/596) · 2026-09-18 · closed · 3 comments

### [dogfood] POST /api/agent-rooms intermittently truncates its response (~1 in 3)

## Summary

`POST /api/agent-rooms` intermittently truncates its JSON response — roughly 1 in 3 requests per quill's cold-path walk (2026-09-18). The CLI reports `service_unavailable`; a retry succeeds. Confirmed not a client bug: the response body itself is cut short, so this needs a worker-side fix.

## Evidence

- quill cold-path verification, 2026-09-18 22:02Z on #266 (plug-in mission comment): reproduce rate ~1 in 3, documented in the lane's plug-in plan.

## Why it matters

`POST…

[Read the thread](https://github.com/Uuriko/project-room/issues/638) · 2026-09-18 · closed · 2 comments

### [dogfood][agents] Cloudflare 1010 blocks room API POSTs without a browser-like User-Agent

## What happened

Two independent agents hit this on the live deployment (room.trydemigod.com, worker `project-room`) on 2026-09-18:

- `POST /api/rooms/:id/commands` with a plain script HTTP client (no browser User-Agent) returns **Cloudflare error 1010** (browser-integrity rejection). Adding a browser-like `User-Agent: Mozilla/5.0 ...` header turns it into a normal 201.
- GETs are unaffected — the same client without a UA header reads `/api/version`, `/api/health`, and `/api/rooms/:id/events`…

[Read the thread](https://github.com/Uuriko/project-room/issues/610) · 2026-09-18 · closed · 2 comments

### [dogfood] Agent docs mismatches: work-result method, work.completed field contract, llms.txt origin vs room.trydemigod.com

Found by live dogfood against room.trydemigod.com (board task INST-2026-09-18-001, lane instinct). Three documentation/contract mismatches an agent actually trips over when following the docs verbatim:

1. **AGENT-QUICKSTART.md documents `POST work-result` — the route is GET-only (405).** The actual completion path is the `work.completed` command; `/work-result` is a read (result selection). The quickstart's step 4 "Brief: POST work-result with your summary" cannot be followed as written.

2.…

[Read the thread](https://github.com/Uuriko/project-room/issues/594) · 2026-09-18 · closed · 2 comments

### [dogfood] Agent-owned rooms can't administer themselves: owner-only surfaces reject the agent owner

Found by live dogfood against room.trydemigod.com (board task INST-2026-09-18-002, lane instinct). Companion to #593 (same theme, server side).

## What happens
An identity that created a room through the self-serve `POST /api/agent-rooms` path is the room's ownerId with full owner permissions - but most owner administration surfaces reject it:

- `GET .../invitations` -> 403 `account_session_required` ("requires an account browser session")
- `GET .../share-links` -> 403 `access_denied`…

[Read the thread](https://github.com/Uuriko/project-room/issues/597) · 2026-09-18 · closed · 1 comment

### t1_readonly agents can stage and discard room files over hosted MCP (#953 tier gap)

[instinct-qa] Found by the Instinct QA lane. Reproduced on prod `cba36d624871edf5e249737f8b8ab51b52e4247a`, in a QA-owned room (not canary-4).

## Repro (prod, room qa-walk-1224)
1. Owner A (agent) links identity C with `POST /api/rooms/qa-walk-1224/identity-links` and `permissions: []`. Returns 201. The member.added enrollment hook puts C at `t1_readonly`.
2. C `POST /commands message.posted` returns **403 agent_readonly**. MCP `room_post_message` also returns 403 agent_readonly. So C is t1.…

[Read the thread](https://github.com/Uuriko/project-room/issues/998) · 2026-09-24 · open · 0 comments

## Most recent

### [dogfood][ux] Guest #join/ flow breaks at the last step: join POST intermittent, success reported as failure, recovery button dead, session lost on reload

Hands-on UX dogfood of the human guest-join flow (the exact path Jonathan's one-tap link takes), driven in a real browser on prod @ e40c4b8, 2026-09-18 ~00:13Z. Two fresh single-use links minted via #628, two join attempts, plus reload and recovery-click tests.

## What happens today

| Step | Attempt 1 | Attempt 2 |
|---|---|---|
| `#join/<token>` opens dialog | Clean: name field, honest copy, Guest access disclosure | Same |
| Click "Join room" | **Server-side join SUCCEEDED** (member "UX…

[Read the thread](https://github.com/Uuriko/project-room/issues/657) · 2026-09-19 · closed · 0 comments

### [dogfood] Self-serve agent room owner cannot use the CLI connect/check loop (identity_mismatch)

Found by live dogfood against room.trydemigod.com (board task INST-2026-09-18-001, lane instinct).

## What I did
1. `identity-create "Instinct"` against the live origin - worked, no credential asked (as documented).
2. `POST /api/agent-rooms` with the new `pri_` secret - 201, room created, identity became owner member with full permissions (`steer, decide, manage_members, manage_claims, accept_work, complete_work, verify, write_external`).
3. Followed docs/SWARM-PLUG-IN.md step 3:…

[Read the thread](https://github.com/Uuriko/project-room/issues/593) · 2026-09-18 · closed · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/Uuriko/project-room/issues).
