docs: start server diagnostics integration
This commit is contained in:
1 parent
14aa6402d6
commit
48f63ccf68
1 file changed
+44
@@ -0,0 +1,44 @@
|
||||
# Task: Integrate server diagnostics into main
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260831-integrate-server-diagnostics-8b42c6d1
|
||||
- Mode: Integration
|
||||
- Branch: main
|
||||
- Worktree: /Users/inmanx/Documents/lwltAPI
|
||||
- Base commit: 14aa6402d6cff52ccf7abb373eb1896e16f6ae98
|
||||
- Owner: codex
|
||||
- Status: In progress
|
||||
|
||||
## Scope
|
||||
|
||||
- Merge the independently advanced `origin/main`, local project-governance/diagnosis commits, and the published WeChat attachment-correlation/diagnostics branch into `main`.
|
||||
- Preserve the remote deployment adaptations and Chrome extension `0.5.163` release while retaining the accepted `.project-docs`-only governance boundary.
|
||||
- Add production support for attachment URLs that intentionally resolve inside the server environment through an exact, configuration-driven private-host allowlist.
|
||||
- Preserve HTTPS, credential rejection, redirect revalidation, DNS pinning, byte limits, declared size, and SHA-256 verification; do not globally permit private/reserved networks.
|
||||
- Reconcile accepted promotion candidates into canonical data-flow, business-rule, architecture/current-state, evidence, and deployment documentation where supported.
|
||||
- Run all repository gates, commit the integrated result on `main`, and push it to `origin/main`.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- The user explicitly authorized merging all current work into `main` and pushing a new revision, and explicitly confirmed that the attachment source is expected to use a private address in the server environment.
|
||||
- Private-network compatibility must be opt-in per exact hostname or IP. Empty configuration preserves the existing fail-closed SSRF behavior; wildcards, URL prefixes, paths, credentials, and CIDR-wide bypasses are not accepted.
|
||||
- Every initial URL and redirect target must be evaluated independently against the same exact allowlist; logging may record only allowlist presence/count and a boolean match, never the configured host values or attachment URL.
|
||||
- Resolve the root planning-file merge according to accepted decision `DOC-001`: remote implementation/release facts and immutable archives are retained, but retired root planning files are not restored as active sources.
|
||||
- Do not deploy, restart services, mutate Kubernetes, read secrets, access ERP, retry live tasks, or send external messages.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Not completed.
|
||||
|
||||
## Verification
|
||||
|
||||
- Not run.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- None recorded.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None recorded.
|
||||
Reference in new issue
Block a user