feat: add leader AgentBus task summaries
This commit is contained in:
1 parent
f4664997a8
commit
1a3ab63700
18 files changed
+2158
-19
No files matched your search
@@ -0,0 +1,64 @@
|
||||
# Task: Implement leader task summaries via AgentBus
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260907-implement-leader-agentbus-copy-b7e31a94
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260907-implement-leader-agentbus-copy-b7e31a94-implement-leader-agentbus-copy
|
||||
- Worktree: /Users/inmanx/Documents/lwltAPI-implement-leader-agentbus-copy-b7e31a94
|
||||
- Base commit: f4664997a81722459f8d3e14acfbbf44cc6bbbe1
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Implement administrator-managed, default-off organization-wide subscriptions that copy deterministic summaries of other non-administrator employees' manual and AgentBus tasks to a bound team-lead AgentBus/WeChat route.
|
||||
- Add a separate encrypted durable notification outbox, idempotent projection from existing `task.updated` outbox events, lower-priority AgentBus proactive delivery, retry/release behavior, health projection, and explicit administration UI.
|
||||
- Cover stable completed, failed, cancelled, uncertain, and uncertain-then-resolved outcomes without copying transient progress, historical outcomes, raw instructions, attachments, passenger/customer details, technical payloads, or ERP execution authority.
|
||||
- Update the active AgentBus/control-plane contract and focused regressions. Do not modify business Skills, ERP schemas/mappings, Chrome extension source/releases, task queues, confirmation, execution, deployment, runtime database, channels, or live external messages.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Base implementation on current `origin/main` commit `f4664997a81722459f8d3e14acfbbf44cc6bbbe1` in this isolated worktree; preserve the occupied dirty `main` worktree.
|
||||
- Preserve AUTH-002 immutable assignee, per-account FIFO, assignee-only executable feeds/results, and the separation between organization-wide read projections and ERP mutation authority.
|
||||
- The user confirmed fixed-organization scope, both `manual` and `agentbus` sources, and implementation. Exclude administrator, system/unassigned, and recipient-owned tasks; do not invent team membership.
|
||||
- Do not reuse `agentbus_deliveries` or fabricate `reply_to`. Proactive frames use a separately verified recipient/conversation route and `task.summary` contract with stable frame IDs.
|
||||
- Destination and payload remain encrypted at rest; operational logs expose only bounded identifiers and fingerprints. Delivery failure must never change task state.
|
||||
- No historical backfill. A new or materially changed subscription starts at the change time, and target/channel/role invalidation cancels or blocks pending delivery without automatic rerouting.
|
||||
- Feature mode changes only implementation files, active component documentation, this task record, and any task-prefixed supporting record; canonical project memory remains an Integration Gate promotion candidate.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added migration `020_leader_task_summary_notifications` with a default-off, organization-scoped team-lead subscription and a dedicated durable delivery outbox. Recipient address, conversation ID, and summary payload are encrypted at rest; only SHA-256 fingerprints are exposed to administration and diagnostics. Composite organization foreign keys, bounded projection/claim indexes, revisioned deduplication, and no data backfill keep the feature isolated from existing employee reply rows.
|
||||
- Added `LeaderNotificationService` as a read-only projection over existing `task.updated` outbox events. It includes future manual and AgentBus tasks assigned to other non-administrator employees, excludes recipient-owned/admin/system tasks, projects only stable outcome milestones, uses transaction advisory locks plus `SKIP LOCKED`, cancels obsolete subscription revisions, and retries delivery failures without changing task state.
|
||||
- Added deterministic privacy-safe summary generation for completed, failed, cancelled, uncertain, and uncertain-then-resolved outcomes. Messages contain only employee username, registered business label, public task ID, submission time, generic status/result wording, and allowlisted group/order identifiers; raw instructions, attachments, customer/traveller fields, URLs, and technical errors are not copied.
|
||||
- Integrated the separate summary queue into each team lead's existing AgentBus channel after the employee reply queue. Proactive `task.summary` frames use a stable delivery-derived ID plus explicit recipient/conversation routing and never fabricate `reply_to`; inbound `task.summary` events are reserved and ignored so an echo cannot create another task. Operational logs contain delivery/task/channel IDs and route fingerprints, not the frame or destination plaintext.
|
||||
- Added administrator-only list/update APIs and a `/channels` management panel. The panel requires explicit target verification and a second enable confirmation, explains default-off/future-only/at-least-once/non-retractable behavior, preserves encrypted routes when their fields are left blank, and shows eligibility plus pending/failed/sent health counts. There is deliberately no live test-send endpoint.
|
||||
- Updated the active AgentBus reply contract and control-plane README for proactive leader summaries and required schema `020`. Existing task ownership, executable feeds, ERP confirmation/execution, business Skills, schemas/mappings, and Chrome extension sources/releases were not changed.
|
||||
- No runtime database was migrated, service deployed/restarted, AgentBus channel changed, or real AgentBus/WeChat message sent.
|
||||
|
||||
## Verification
|
||||
|
||||
- `npm run check:repo`: passed (10/10).
|
||||
- `npm run check`: passed.
|
||||
- `npm run test:control-plane`: passed (174/174), including summary privacy/status projection, migration/authorization/UI contracts, proactive no-`reply_to` framing, echo rejection, employee-first queue ordering, redacted logging, retry gateway behavior, and existing control-plane regressions.
|
||||
- `npm run test:legacy`: passed (270/270).
|
||||
- `npm run build`: passed.
|
||||
- `node --check LianSyn-platform/app.js`: passed.
|
||||
- `git diff --check`: passed.
|
||||
- Fresh disposable PostgreSQL 16 integration: applied all 19 repository migrations through `020`; confirmed zero default subscription rows, administrator-created verified configuration without plaintext route exposure, no historical backfill, encrypted projection/claim, and a pending uncertainty reminder being cancelled when the task resolved so only one final `completed` summary was claimed. The temporary cluster was stopped and moved to Trash afterward.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Integration/deployment remains separately authorized: merge this Feature branch, back up and apply migration `020`, then restart the control plane. None of those live actions occurred here.
|
||||
- Before production enablement, choose the exact team-lead channel and controlled WeChat conversation, validate that the deployed AgentBus bridge accepts the proactive `task.summary` envelope and routes its explicit `to`/`conversation_id` without echoing it as inbound work, then manually mark that target verified and enable the subscription.
|
||||
- Observe one controlled manual task and one controlled AgentBus task end to end before widening use. Delivery is intentionally at-least-once, so downstream deduplication must honor the stable `leader-summary-<delivery-id>` frame ID and operators must understand that a message already accepted by AgentBus/WeChat cannot be retracted by deleting platform data.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- Target documents: canonical system architecture, authorization/data-isolation memory, current-state snapshot, and production operations guidance.
|
||||
- Proposed durable fact: team-lead WeChat summaries are a default-off organization-wide read projection, not task ownership or ERP authority. They use revisioned subscriptions and their own encrypted outbox; existing employee AgentBus replies remain the higher-priority queue and are never repurposed.
|
||||
- Proposed safety invariant: only future stable outcomes for other non-admin employees may be projected; route or role invalidation cancels unsent work without rerouting, stale uncertainty reminders are superseded before send, and delivery failures never mutate task state.
|
||||
- Proposed protocol fact: proactive frames use event `task.summary`, stable ID `leader-summary-<delivery-id>`, explicit `to` and `conversation_id`, and no `reply_to`; echoed `task.summary` frames are ignored inbound.
|
||||
- Evidence: migration `020`, leader notification/projector sources, AgentBus integration, administration UI/API, focused tests, full regression results, and the disposable PostgreSQL integration recorded by this task.
|
||||
- Human confirmation required: exact production team-lead recipient/channel binding, controlled external AgentBus/WeChat canary result, and authorization to integrate, migrate, restart, and enable.
|
||||
Reference in new issue
Block a user