docs: record account system deployment

This commit is contained in:
inman committed 2026-09-01 19:23:14 +08:00
1 parent ffda0d5f3f
commit 08725b2de9
3 files changed
+38 -10

No files matched your search

+9 -5
View File
@@ -9,10 +9,12 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
- Commit `161f90d09d6ad1368973b1a85d51059059495223` for trusted-intranet attachment compatibility and canonical reconciliation.
- Integration task `20260831-finalize-main-push-4e1c7a9b` for verified non-force synchronization to `origin/main`.
- Commit `b08f2960fa4db09c807b6fb61dfba33dc524a274` for the read-only list-attachment behavior inspection record; no product behavior changed.
- Commit `191c1a1aad6f4bb1651143df3e0c1dc98dcd09e0` for the fixed-scope account system, three-role authorization, owner isolation, operations dashboard, audit/archive behavior, and per-account task-route grants.
- Integration task `20260901-integrate-account-system-7b2f4d` for canonical authorization reconciliation, migrations 015–017, and the authorized standard-panel restart.
## Current Focus
Operate the current `0.5.163` extension release baseline safely, keep Program/AI routing and ERP execution boundaries synchronized, and prepare the integrated control-plane revision for a separately authorized deployment.
Operate the current `0.5.163` extension baseline and the deployed fixed-scope account model safely, provision roles and task grants through administrator workflows, and preserve Program/AI plus ERP execution boundaries.
## Recently Completed
@@ -23,30 +25,32 @@ Operate the current `0.5.163` extension release baseline safely, keep Program/AI
- 2026-08-31: Integrated strict WeChat envelope conversation fallback, placeholder-only attachment rejection before task ingestion, and safe attachment error summaries while preserving the original `awaiting_attachment` task.
- 2026-08-31: Integrated structured privacy-safe diagnostics across service, HTTP, task/audit, parser, AgentBus, attachment, database, and cleanup stages, with bounded Docker stdout retention and a read-only server diagnostic command.
- 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
- 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015–017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator.
## In Progress
- No separate repository feature task is recorded at this integration snapshot; deployment and restart remain unperformed.
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
## Next Recommended Steps
1. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
2. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
3. Under separate deployment authorization, publish the integrated control-plane image with `DEPLOYMENT_REVISION` set and verify one real internal AgentBus roster attachment through the new diagnostic stages.
3. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes.
## Open Questions / Blockers
- Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
- Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
- The repository fix for internal attachment URLs is not active on the server until a separately authorized image build/deployment/restart occurs.
- The restarted service now runs current local `main`; a live internal AgentBus attachment verification remains separately unperformed.
## Risky Areas
- Any ERP write, uncertain post-write state, automatic retry, or scope widening.
- Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity.
- AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts.
- Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
## Last Updated
2026-08-31
2026-09-01