docs: record repository publication

This commit is contained in:
Wyndham ARR
2026-07-29 16:45:57 +08:00
parent a701de9f0e
commit 12881be17e
3 changed files with 5 additions and 3 deletions

View File

@@ -2,10 +2,11 @@
## Current Focus ## Current Focus
A controlled public-deployment source snapshot is prepared for the empty self-hosted `wyndham-ARR` repository. Its Compose Web entry explicitly enables `--enable-processing --secure-cookies`; Caddy is the only public listener and adds HTTPS plus Web Basic Auth, while MCP retains its independent bearer and exact Host allowlist. Local application defaults remain fail-closed. The snapshot passes 259 tests with 2 environment skips plus contract, checksum, candidate-file and secret scans. No public server deployment has been performed from this workspace. The controlled public-deployment source snapshot is published on `main` at `https://git.nianxx.cn/shiyuyun/wyndham-ARR.git`; initial deployment commit `a701de9` contains the verified source snapshot. Its Compose Web entry explicitly enables `--enable-processing --secure-cookies`; Caddy is the only public listener and adds HTTPS plus Web Basic Auth, while MCP retains its independent bearer and exact Host allowlist. Local application defaults remain fail-closed. The snapshot passes 259 tests with 2 environment skips plus contract, checksum, candidate-file and secret scans. No public server deployment has been performed from this workspace.
## Recently Completed ## Recently Completed
- 2026-07-29: Published the deployment-ready snapshot to the empty self-hosted repository as `main`, established upstream tracking and verified that the remote branch contains initial commit `a701de9`.
- 2026-07-29: Added a Linux Dockerfile, Compose, Caddy TLS boundary, production env example and deployment runbook. The Web health gate requires both `database_ready` and `processing_ready`; the production command opens XML processing without changing the source default. - 2026-07-29: Added a Linux Dockerfile, Compose, Caddy TLS boundary, production env example and deployment runbook. The Web health gate requires both `database_ready` and `processing_ready`; the production command opens XML processing without changing the source default.
- 2026-07-29: Added opt-in HTTPS `Secure` session cookies, made the booking fixture root portable, removed local paths/test endpoints/temporary tunnel names from the publishable snapshot, and verified 271 final candidate files (about 2.0 MiB) contain no detected secrets, symlinks or files larger than 1 MiB. - 2026-07-29: Added opt-in HTTPS `Secure` session cookies, made the booking fixture root portable, removed local paths/test endpoints/temporary tunnel names from the publishable snapshot, and verified 271 final candidate files (about 2.0 MiB) contain no detected secrets, symlinks or files larger than 1 MiB.
- 2026-07-29: Ran the complete Python suite in a dependency-complete Python 3.12 environment: 259 tests passed and 2 were skipped. Compose YAML, JSON contracts and controlled package checksums also passed static validation. - 2026-07-29: Ran the complete Python suite in a dependency-complete Python 3.12 environment: 259 tests passed and 2 were skipped. Compose YAML, JSON contracts and controlled package checksums also passed static validation.
@@ -21,7 +22,7 @@ A controlled public-deployment source snapshot is prepared for the empty self-ho
## In Progress ## In Progress
- Repository publication is the remaining local handoff step. Runtime deployment, DNS/Secret injection and SuperAgent stable-domain rebinding belong to the user's public server environment. - No local repository publication work remains. Runtime deployment, DNS/Secret injection and SuperAgent stable-domain rebinding belong to the user's public server environment.
## Next Recommended Steps ## Next Recommended Steps

View File

@@ -4,7 +4,7 @@
| Date | Task | Outcome | Docs Updated | | Date | Task | Outcome | Docs Updated |
|---|---|---|---| |---|---|---|---|
| 2026-07-29 | Prepare the project for controlled public-server deployment and repository publication | Added Docker/Compose/Caddy deployment with XML processing explicitly enabled, HTTPS Secure cookies, Basic Auth/Bearer boundaries and a Chinese runbook; sanitized publishable history; 259 tests passed (2 skipped), all contracts/checksums and a 271-file secret/size/symlink scan passed | Current state, architecture, deployment evidence/index, commitments, module map | | 2026-07-29 | Prepare and publish the project for controlled public-server deployment | Added Docker/Compose/Caddy deployment with XML processing explicitly enabled, HTTPS Secure cookies, Basic Auth/Bearer boundaries and a Chinese runbook; sanitized publishable history; 259 tests passed (2 skipped), all contracts/checksums and a 271-file secret/size/symlink scan passed; pushed `main` to the self-hosted repository and verified initial deployment commit `a701de9` | Current state, architecture, deployment evidence/index, commitments, module map |
| 2026-07-29 | Restart the controlled ARR MCP public path | Restarted loopback MCP and fixed ngrok host; corrected exact public Host allowlisting after a diagnostic 421; public unauthorized requests now return 401 and authenticated one-tool discovery returns 200. Main upload remains disabled | Current state, E2E evidence/index, commitment, active planning record | | 2026-07-29 | Restart the controlled ARR MCP public path | Restarted loopback MCP and fixed ngrok host; corrected exact public Host allowlisting after a diagnostic 421; public unauthorized requests now return 401 and authenticated one-tool discovery returns 200. Main upload remains disabled | Current state, E2E evidence/index, commitment, active planning record |
| 2026-07-29 | Diagnose persistent SuperAgent MCP `failed` status | Confirmed the temporary MCP and ngrok processes had exited; public `/mcp` returns `ERR_NGROK_3200 endpoint offline` despite valid DNS/TLS. The stale platform config version 33 remains a second-stage issue after reachability is restored | Current state, E2E evidence/index, commitment, active planning record | | 2026-07-29 | Diagnose persistent SuperAgent MCP `failed` status | Confirmed the temporary MCP and ngrok processes had exited; public `/mcp` returns `ERR_NGROK_3200 endpoint offline` despite valid DNS/TLS. The stale platform config version 33 remains a second-stage issue after reachability is restored | Current state, E2E evidence/index, commitment, active planning record |
| 2026-07-29 | Open XML upload in a controlled boundary and execute a real no-PII vertical slice | UI upload, OSS registration and SuperAgent dispatch passed; SuperAgent returned success without calling MCP because platform tool discovery remained at config version 33. Test run was failed safely, grant revoked, zero Finance writes verified, and temporary upload closed | Current state, evidence topic/index, commitments, planning record | | 2026-07-29 | Open XML upload in a controlled boundary and execute a real no-PII vertical slice | UI upload, OSS registration and SuperAgent dispatch passed; SuperAgent returned success without calling MCP because platform tool discovery remained at config version 33. Test run was failed safely, grant revoked, zero Finance writes verified, and temporary upload closed | Current state, evidence topic/index, commitments, planning record |

View File

@@ -17,6 +17,7 @@ Does the publishable source snapshot open XML processing through an explicit aut
## Evidence ## Evidence
- Files: `Dockerfile`, `compose.yaml`, `deploy/Caddyfile`, `deploy/.env.production.example`, `deploy/README.md`, `arr_web/app.py`, `arr_web/run.py`, `tests/test_arr_web.py`. - Files: `Dockerfile`, `compose.yaml`, `deploy/Caddyfile`, `deploy/.env.production.example`, `deploy/README.md`, `arr_web/app.py`, `arr_web/run.py`, `tests/test_arr_web.py`.
- Git: initial deployment snapshot commit `a701de9f0eff7402fe1785c3b35de5652576152a` was pushed to `origin/main`; an independent `ls-remote` check is required after the documentation closeout commit as the final publication proof.
- Deployment command inspection: Compose Web command contains `--enable-processing` and `--secure-cookies`; only Caddy maps host ports 80/443, Web and MCP use internal `expose` ports. - Deployment command inspection: Compose Web command contains `--enable-processing` and `--secure-cookies`; only Caddy maps host ports 80/443, Web and MCP use internal `expose` ports.
- Tests: Python 3.12 full discovery ran 259 tests successfully; 2 environment-dependent tests were skipped. - Tests: Python 3.12 full discovery ran 259 tests successfully; 2 environment-dependent tests were skipped.
- Integrity: every entry in `CHECKSUMS.sha256` passed and 10 JSON contracts parsed. - Integrity: every entry in `CHECKSUMS.sha256` passed and 10 JSON contracts parsed.