docs: integrate automatic leader summary routing

This commit is contained in:
inman committed 2026-09-07 16:20:02 +08:00
1 parent 0b3aa5c42d
commit 6bdaa2a6e6
9 files changed
+76 -16

No files matched your search

+7 -5
View File
@@ -4,6 +4,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Source commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` from feature task `20260907-auto-leader-summary-routing-5e8c1a73` for automatic role-driven team-lead summaries, current-owner AgentBus route learning/fallback, read-only status UI, stale-route cancellation, and removal of the manual mutation endpoint; integration task `20260907-integrate-auto-leader-summary-9a4d2c61` revised AUTH-003 and canonical notification behavior.
- Source commit `1a3ab63` from feature task `20260907-implement-leader-agentbus-copy-b7e31a94` for default-off team-lead task summaries over future manual and AgentBus outcomes, a separate encrypted/revisioned outbox, verified proactive AgentBus routing, administrator configuration/health UI, and migration 020; integration task `20260907-integrate-leader-summaries-84c1d7ea` accepted AUTH-003 and canonical notification boundaries.
- Correction commit `fe1cc2cddc29e4dead81e53c16d31bb71493602d` from integration task `20260903-backup-revert-extension-update-c71a4e92` preserved the complete former `0.5.167`/migration-019 stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed the central private-OSS/ECS automatic-update service architecture without rewriting history, and retained the exact Chrome extension `0.5.167` source/package on the active main line with migration 018.
- Merge commit `3224758` and integration task `20260903-finalize-extension-update-a6c4e192` remain historical records of the full-stack extension-update design. Only the plugin `0.5.167` release, adaptive entry readiness, and dormant plugin-side idle/reload safeguards remain active; the server orchestration is preserved on the backup branch only.
@@ -34,7 +35,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Current Focus
Operate the repository's current `0.5.167` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator or team-lead visibility never enters another account's executable event/result path. Team-lead task summaries remain default-off until an administrator verifies the exact proactive route; migration 020, manual extension reload, guarded product-search retry, and service rollout remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
Operate the repository's current `0.5.167` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator or team-lead visibility never enters another account's executable event/result path. Active team leads with usable owned AgentBus routes automatically receive future privacy-bounded summaries; migration 020, manual extension reload, guarded product-search retry, service rollout, and any live AgentBus/WeChat canary remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
## Recently Completed
@@ -60,11 +61,12 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back.
- 2026-09-03: Backed up the complete adaptive-readiness and central extension-update stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, then removed the central OSS/ECS update service and migration 019 from `main` with normal history-preserving commits. After correcting an initially over-broad rollback, the active repository retains the exact extension `0.5.167` source/package and uses migration 018; the removed server architecture was never deployed by these tasks.
- 2026-09-07: Integrated AUTH-003 and migration 020 for administrator-managed team-lead task summaries. Future stable manual/AgentBus outcomes for other non-admin employees project into a separate encrypted outbox and use the leader's verified AgentBus/WeChat target without changing task ownership, employee reply priority, or ERP execution authority.
- 2026-09-07: Revised AUTH-003 so active team-lead identity plus an enabled owned AgentBus channel automatically activates both-source summaries. Routing uses only the current owner's latest valid inbound route or the channel external-user reference; channel rebind clears stale identity data, the settings API/UI is read-only, and all prior privacy, future-only, revision, priority, and no-ERP-authority boundaries remain.
## In Progress
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
- Required migrations through `020_leader_task_summary_notifications`, employee ERP identities/channel bindings, extension `0.5.167`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/notification runtime changes have not been applied to or restarted on the standard service in this integration task. No production team-lead target is configured or enabled.
- Required migrations through `020_leader_task_summary_notifications`, employee ERP identities/channel bindings, extension `0.5.167`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/automatic-notification runtime changes have not been applied to or restarted on the standard service in this integration task. No live automatic team-lead delivery canary was performed.
## Next Recommended Steps
@@ -73,7 +75,7 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
3. In the same authorized staging window, verify that an administrator receives no employee executable events/results, then force-delete disposable waiting and active employee tasks and confirm database absence plus cleanup only in the owning employee plugin.
4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
6. With explicit external-send authorization, configure one controlled team-lead route, verify proactive `task.summary` handling and stable-frame deduplication through AgentBus/WeChat, then observe one manual and one AgentBus task before wider enablement.
6. With explicit external-send authorization, use one controlled team-lead channel to verify automatic current-owner route resolution, proactive `task.summary` handling, and stable-frame deduplication through AgentBus/WeChat, then observe one manual and one AgentBus task before wider assurance.
## Open Questions / Blockers
@@ -83,7 +85,7 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering mismatched ERP login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator executable-feed isolation, and both manual and automatic channel work.
- Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
- A live internal AgentBus attachment verification remains separately unperformed.
- Proactive team-lead `task.summary` delivery has repository, mock-WebSocket, and disposable-PostgreSQL evidence but no deployed AgentBus/WeChat canary; exact production target verification and enablement remain pending authorization.
- Proactive team-lead `task.summary` delivery has repository, mock-WebSocket, and disposable-PostgreSQL evidence but no deployed AgentBus/WeChat canary; automatic current-owner route resolution remains unverified in the live bridge.
## Risky Areas
@@ -93,7 +95,7 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
- AgentBus channel ownership, immutable task assignment, expected ERP identity, browser-worker freshness/failover, and administrator non-execution are security- and write-safety-sensitive boundaries.
- Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
- Team-lead summary target verification, encrypted projection/delivery rows, at-least-once stable-frame deduplication, privacy allowlisting, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
- Team-lead automatic route derivation, stale-owner invalidation, encrypted projection/delivery rows, at-least-once stable-frame deduplication, privacy allowlisting, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
## Last Updated
+1
View File
@@ -12,3 +12,4 @@ This is integrated history. Feature tasks write only their task-scoped records;
| 2026-09-03 | Adaptive ERP readiness and extension host updates | Integrated immediate-first scatter-plan readiness plus private OSS/ECS host updating as extension `0.5.167`; the server-update architecture was later reverted before deployment while the plugin release was retained. | [Original integration task](tasks/20260903-finalize-extension-update-a6c4e192.md) |
| 2026-09-03 | Extension-update iteration backup and scoped rollback | Preserved exact commit `b2e33e2` on remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed migration 019 and server-side automatic updating, and retained extension `0.5.167` plus migration 018 through non-force commits. | [Rollback task](tasks/20260903-backup-revert-extension-update-c71a4e92.md) |
| 2026-09-07 | Team-lead AgentBus task summaries | Integrated default-off future-only summaries for other non-admin employees' manual/AgentBus outcomes through a separate encrypted outbox and verified proactive target, without changing task or ERP authority. | [Integration task](tasks/20260907-integrate-leader-summaries-84c1d7ea.md) |
| 2026-09-07 | Automatic leader-summary routing correction | Replaced the duplicate administrator subscription form with role-driven activation and current-owner AgentBus route resolution while retaining future-only privacy and delivery boundaries. | [Integration task](tasks/20260907-integrate-auto-leader-summary-9a4d2c61.md) |
@@ -0,0 +1,51 @@
# Task: Integrate automatic leader summary routing
## Identity
- Task ID: 20260907-integrate-auto-leader-summary-9a4d2c61
- Mode: Integration
- Branch: codex/20260907-integrate-auto-leader-summary-9a4d2c61-integrate-auto-leader-summary
- Worktree: /Users/inmanx/Documents/lwltAPI-integrate-auto-leader-summary-9a4d2c61
- Base commit: 0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00
- Owner: codex
- Status: Ready for Integration
## Scope
- Integrate source commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` from feature task `20260907-auto-leader-summary-routing-5e8c1a73` onto the current `origin/main` ancestry.
- Promote the user-approved role-driven automatic leader-summary behavior into AUTH-003, architecture, domain rules, success criteria, current state, and integrated history.
- Re-run repository, type, control-plane, legacy, build, and documentation gates before a normal non-force push to `origin/main`.
## Intent And Constraints
- The user explicitly replaced the earlier administrator-configured/default-off workflow with automatic activation for active team leads using their AgentBus channel routing.
- Preserve all privacy, future-only, durable-outbox, employee-first, role/channel fail-closed, and no-ERP-authority-expansion guarantees from AUTH-003.
- Do not apply migrations, restart services, deploy, mutate production data, or send a real AgentBus/WeChat message.
- Preserve the dirty local `main` worktree and its unrelated untracked task record; integrate only from this isolated worktree.
## Outcome
- Promoted feature commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` as the canonical implementation of role-driven automatic leader-summary routing.
- Updated AUTH-003, its decision index entry, success criteria, system overview, data flow, business rules, current state, and integrated task history to remove the obsolete administrator-configured/default-off product model.
- Recorded that active team leads are reconciled automatically against an enabled, bound, owned AgentBus channel; the current observed route is preferred and the bound external recipient is the fallback.
- Preserved fail-closed invalidation, encrypted route snapshots, durable outbox delivery, future-only semantics, employee-first scheduling, and both manual and AgentBus task sources.
- No migration, production-data mutation, deployment, service restart, or real AgentBus/WeChat send was performed. Migration 020 remains the current schema requirement.
## Verification
- `node --run check:repo` — passed (10/10).
- `node --run check` — passed.
- `node --run test:control-plane` — passed (176/176).
- `node --run test:legacy` — passed (270/270).
- `node --run build` — passed.
- `node --check LianSyn-platform/app.js` — passed.
- Disposable PostgreSQL 16.14 verification from the source feature task applied migrations 001–020 and confirmed idempotent reconciliation, learned-route delivery, both task sources, and role-revocation cancellation.
- `check_project_docs.py` and `check_doc_drift.py --task-id 20260907-integrate-auto-leader-summary-9a4d2c61` — passed after canonical promotion.
## Follow-ups
- A real WeChat canary requires separate deployment/runtime authorization and should use a non-sensitive test summary.
## Promotion Candidates
- None; the accepted behavior was promoted directly into canonical project memory by this Integration task.