From 9eeb0710992f76a91b2bab934186b8c85040936c Mon Sep 17 00:00:00 2001 From: inman Date: Wed, 2 Sep 2026 15:25:16 +0800 Subject: [PATCH] docs: reconcile AgentBus and dashboard integration --- ...H-001-fixed-scope-account-authorization.md | 18 ++++-- .project-docs/10-decisions/decision-index.md | 2 +- .project-docs/20-architecture/data-flow.md | 10 +-- .../20-architecture/system-overview.md | 12 ++-- .project-docs/30-worklog/current-state.md | 21 +++++-- .project-docs/30-worklog/task-history.md | 2 + .../20260902-integrate-all-push-c93a7f21.md | 63 +++++++++++++++++++ .project-docs/40-domain/business-rules.md | 6 +- .project-docs/50-evidence/evidence-index.md | 2 + .project-docs/80-commitments/commitments.md | 1 + 10 files changed, 115 insertions(+), 22 deletions(-) create mode 100644 .project-docs/30-worklog/tasks/20260902-integrate-all-push-c93a7f21.md diff --git a/.project-docs/10-decisions/AUTH-001-fixed-scope-account-authorization.md b/.project-docs/10-decisions/AUTH-001-fixed-scope-account-authorization.md index 3d19211..3ec9656 100644 --- a/.project-docs/10-decisions/AUTH-001-fixed-scope-account-authorization.md +++ b/.project-docs/10-decisions/AUTH-001-fixed-scope-account-authorization.md @@ -10,20 +10,24 @@ Accepted ## Context -The platform already required login but treated the fixed deployment scope as a shared administrator workspace. It needed administrator-maintained accounts, per-user task isolation, a team-lead oversight role, creator/original-input audit, and explicit task-type eligibility without introducing tenant or organization administration. +The platform already required login but treated the fixed deployment scope as a shared administrator workspace. It needed administrator-maintained accounts, per-user task isolation, a team-lead oversight role, creator/original-input audit, explicit task-type eligibility, and a deterministic employee-to-AgentBus-to-ERP execution binding without introducing tenant or organization administration. ## Decision - Keep one internal `organization_id` deployment scope and do not expose organization selection or tenant administration. - Use three roles: `admin`, `team_lead`, and `user`. -- Administrators manage account lifecycle, passwords, sessions, global settings/audit, AgentBus/system tasks, and all manual tasks. They always hold all 18 registered manual business routes. +- Administrators manage account lifecycle, passwords, sessions, global settings/audit, AgentBus channels, and all manual/AgentBus task visibility. They always hold all 18 registered manual business routes, but their inspection authority does not grant ERP execution authority over work assigned to another account. - Password entry points require a non-empty value but impose no application-level minimum or maximum length. The platform does not force a password change on first login or after an administrator reset; voluntary self-service change, administrator reset, and session revocation remain supported. The historical `must_change_password` column is compatibility-only and is cleared on password writes. - Team leads and ordinary users use normal business APIs only for their own manual tasks. New non-administrator accounts start with no task-type grants and may invoke only routes explicitly granted by an administrator. - Re-read route authorization before intake and relevant task state transitions. Known denied routes and unknown/non-unique routes fail closed before parsing, plugin dispatch, or ERP execution. - Give team leads a dedicated read-only platform-operations dashboard over all manual account tasks. It is an aggregate-first leadership view across task, person, original input, final output, time, task type, and completion state; every aggregate may drill into the same bounded business-facing task projection. - Keep the leadership dashboard separate from audit and engineering diagnostics. It never renders parser/executor payloads, internal identifiers, codes, machine-shaped historical input, or technical failure text; those values are replaced by a concise business explanation without changing the underlying audit evidence. +- Keep leadership summary cards display-only. Status changes are explicit filter-form actions, default to all results, and retain the business-facing merge of internal attention states into “进行中”. - Preserve creator and input-turn attribution with encrypted input at rest. Routine removal is archive/restore; irreversible purge is not exposed. -- Keep AgentBus authorization as a separate administrator-controlled channel boundary. +- Bind each enabled AgentBus channel to exactly one active `user` or `team_lead` account with a configured, case-insensitively unique expected ERP account. Administrator accounts remain unbound from employee channels. +- Execute inbound AgentBus work under the bound employee identity and that account's route allowlist. Persist one immutable task assignee for both manual and AgentBus work; confirmation, browser claim/result, reconciliation, and resume require the assignee even when the caller is an administrator. +- Allow only one fresh browser execution worker per account. Heartbeats must match the account's expected ERP identity; a second fresh worker or mismatched ERP session fails closed, and automatic failover begins only after the prior worker is stale. +- Preserve organization-wide ERP FIFO serialization. Employee worker binding chooses who may execute; it does not authorize parallel ERP writes. ## Rationale @@ -31,12 +35,14 @@ This model fits a single-organization deployment while enforcing least privilege ## Consequences -- Migrations 015–017 must be applied before the updated control plane starts. +- Migrations 015–018 must be applied before the updated control plane starts. - Existing accounts migrate as administrators; newly created team leads and users require explicit task grants. - Existing historical `must_change_password=true` values do not restrict login, reads, or mutations; no destructive migration is required to retire the forced-change flow. - Permission revocation can block an existing task at confirmation or browser claim even when an administrator attempts the transition. +- Existing unbound AgentBus channels and historical unassigned AgentBus tasks remain non-executable until an administrator completes an explicit employee binding; no assignee is inferred from whichever browser is online. +- Extension `0.5.164` is the first release carrying the expected-ERP identity probe required by this worker contract. - Cross-user operational visibility is intentionally separated from normal task mutation and technical debugging surfaces. -- Dashboard acceptance is based on leadership questions and business-readable drill-through, not on reproducing task history or technical audit records. +- Dashboard acceptance is based on leadership questions, explicit filters, and business-readable drill-through, not on reproducing task history or technical audit records. ## Supersedes @@ -47,5 +53,7 @@ This model fits a single-organization deployment while enforcing least privilege - `control-plane/migrations/015_account_roles_and_task_audit.sql` - `control-plane/migrations/016_team_lead_operations_dashboard.sql` - `control-plane/migrations/017_user_business_route_authorizations.sql` +- `control-plane/migrations/018_agentbus_account_workers.sql` - `.project-docs/30-worklog/tasks/20260901-account-system-impl-d4e7a2.md` - `.project-docs/30-worklog/tasks/20260901-leadership-dashboard-c4b9e1.md` +- `.project-docs/30-worklog/tasks/20260902-integrate-all-push-c93a7f21.md` diff --git a/.project-docs/10-decisions/decision-index.md b/.project-docs/10-decisions/decision-index.md index 28cd4c5..10948a1 100644 --- a/.project-docs/10-decisions/decision-index.md +++ b/.project-docs/10-decisions/decision-index.md @@ -10,7 +10,7 @@ | RELEASE-001 | Current artifacts, filenames, versions, and SHA-256 values are defined only by `dist/release-manifest.json`. | Active | 2026-08-28 | Release and delivery | [Release manifest](../../dist/release-manifest.json) | | SAFETY-001 | Real ERP access/write, task mutation, extension reload, service restart, deployment, and external delivery require explicit task-scoped authorization. | Active | 2026-08-28 | Operations and maintenance | [Governance](../../AGENTS.md) | | NETWORK-001 | In the trusted internal deployment, AgentBus roster attachment URLs may resolve to internal/private addresses; HTTPS, credential rejection, DNS pinning, redirect validation, bounds, and digest checks remain. | Active | 2026-08-31 | AgentBus attachment ingress | [Reply contract](../../agent设计规范/agentbus-reply-contract.md) | -| AUTH-001 | The fixed deployment scope uses administrator-managed `admin`, `team_lead`, and `user` accounts, owner-isolated normal tasks, an aggregate-first read-only leadership dashboard, explicit non-admin task-route allowlists, and no first-login forced-password-change workflow. | Active | 2026-09-01 | Authentication, authorization, audit, and operations oversight | [ADR](AUTH-001-fixed-scope-account-authorization.md) | +| AUTH-001 | The fixed deployment scope uses administrator-managed `admin`, `team_lead`, and `user` accounts, owner-isolated normal tasks, display-only leadership metrics with explicit filtering, explicit non-admin route grants, and assignee-bound AgentBus/browser/ERP execution. | Active | 2026-09-01 | Authentication, authorization, audit, AgentBus workers, and operations oversight | [ADR](AUTH-001-fixed-scope-account-authorization.md) | ## Superseded Decisions diff --git a/.project-docs/20-architecture/data-flow.md b/.project-docs/20-architecture/data-flow.md index beb0418..188fa66 100644 --- a/.project-docs/20-architecture/data-flow.md +++ b/.project-docs/20-architecture/data-flow.md @@ -4,23 +4,25 @@ | Flow | Source | Destination | Notes | |---|---|---|---| -| Business directive | Manual workbench or AgentBus | Route orchestrator | Source changes input/reply adaptation, not parser or confirmation policy | +| Business directive | Manual workbench or AgentBus | Route orchestrator | Manual input uses the signed-in account; AgentBus input uses the channel's bound employee account and its route allowlist. | +| AgentBus execution ownership | Enabled channel | Employee account → immutable task assignee → executable feed | One account owns at most one channel; unbound channels and unassigned historical tasks stay non-executable. | | Manual account authorization | Signed-in account plus resolved business route | Intake and task-transition gates | Administrators hold all routes; team leads/users require explicit grants and unresolved routes fail closed | | Parsing | Route orchestrator | AI Skill or deterministic Program parser | AI/Shadow/Auto/Program mode is frozen per task | | Operation | Parser | Control-plane task and confirmation | Must validate against the same final contract | | ERP execution | Confirmed task | Chrome extension and logged-in ERP page | Requires unique object, page identity, ownership, and write preflight | | Completion evidence | ERP response/requery | Control-plane receipt and business reply | Evidence is action-specific; uncertain writes fail closed | -| Passenger workbook | Single `.xls/.xlsx` attachment | Deterministic encrypted canonical TSV | First row ignored, second row fixed header, exact leader-contact rules | +| Passenger workbook | Single `.xls/.xlsx` attachment | Deterministic encrypted canonical TSV | Exactly one complete ERP-semantic header is detected in rows 1–100 through finite aliases and arbitrary column order; exact leader-contact rules remain. | | WeChat roster attachment | Strict transport envelope plus one structured `payload.attachments[]` entry | Existing `awaiting_attachment` task | Explicit conversation ID wins; otherwise strict `Conversation:` supplies the fallback. Placeholder text alone never creates a task. | | Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. | | Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. | -| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Aggregate-first task/person/input/output/time/type/completion view with clickable business drill-through; no machine payloads, technical failure text, internal identifiers, or task mutation authority | +| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Display-only summaries plus explicit filters drive an aggregate-first task/person/input/output/time/type/completion view; list reads are bounded to one read-only connection and hydrate full details only for the current page. | +| Browser worker selection | Immutable task assignee | One fresh account-bound browser connection | The heartbeat must match the account's expected ERP identity; a second fresh worker or identity mismatch is non-executable, with failover only after staleness. | | Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF | | Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames | ## State Ownership -- PostgreSQL owns durable control-plane account, role, task-route grant, task, session, confirmation, channel, audit, archive, and outcome state. +- PostgreSQL owns durable control-plane account, role, expected ERP identity, task-route grant, AgentBus channel owner, immutable task assignee, browser worker, session, confirmation, audit, archive, and outcome state. - Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted. - Chrome extension local state is bounded execution/reconciliation support, not canonical business history. - `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection. diff --git a/.project-docs/20-architecture/system-overview.md b/.project-docs/20-architecture/system-overview.md index 984e7b7..98192c4 100644 --- a/.project-docs/20-architecture/system-overview.md +++ b/.project-docs/20-architecture/system-overview.md @@ -2,7 +2,7 @@ ## Current Architecture -Authenticated manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns account, task, session, task-type authorization, confirmation, audit, and archive state, and the Chrome extension resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence. +Authenticated manual or account-bound AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns account, channel owner, immutable task assignee, browser worker, session, task-type authorization, confirmation, audit, and archive state. The Chrome extension verifies the expected ERP account, resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence. ## Main Components @@ -10,7 +10,7 @@ Authenticated manual or AgentBus input is routed through task-scoped AI/Shadow/A |---|---|---| | `agent设计规范/` | Agent Prompt, five parsing Skills, business templates, business registry, and stable fixtures | Editable source for business semantics; not runtime evidence | | `schemas/` and `mappings/` | Parse-state, execution-state, ERP form, field, and lifecycle contracts | Current contracts only | -| `control-plane/` | Task/session persistence, parser orchestration, confirmation, audit, AgentBus, attachments, receipts, and structured diagnostics | TypeScript source; build output goes to `.build/` | +| `control-plane/` | Task/session persistence, parser orchestration, confirmation, audit, AgentBus channel ownership, task assignment, browser workers, attachments, receipts, and structured diagnostics | TypeScript source; build output goes to `.build/` | | `LianSyn-platform/` | Operator workbench and external parser adapter | Source and UI, not local task output | | `chrome-extension/ltjt-order-assistant/` | Logged-in ERP resolution, preflight, native execution, response handling, and requery | Any code change requires synchronized versioned release updates | | `dist/` | Versioned current deliverables and machine-readable release manifest | Not a compilation directory | @@ -21,14 +21,16 @@ Authenticated manual or AgentBus input is routed through task-scoped AI/Shadow/A - AI/Program parsing and ERP resolution/execution share the final operation contract but do not share authority. - Platform envelope fields such as task ID, account identity, authorization revision, session, parser decision, confirmation, transport, and audit never enter the business operation. -- The product is one fixed internal organization scope with three roles. Administrators manage accounts and all 18 manual routes; team leads and users are owner-scoped for normal tasks and require explicit per-route grants. Team leads additionally receive a dedicated read-only, manual-task-only platform-operations dashboard. +- The product is one fixed internal organization scope with three roles. Administrators manage accounts, channels, and all 18 manual routes; team leads and users are owner-scoped for normal tasks and require explicit per-route grants. Team leads additionally receive a dedicated read-only, manual-task-only platform-operations dashboard. Administrator-wide visibility does not permit executing another account's assigned ERP work. - Account passwords are accepted when non-empty without an application-level length rule. First-login forced password changes are disabled; voluntary changes and administrator resets still revoke the relevant sessions, while the historical `must_change_password` column remains compatibility-only storage. -- The leadership dashboard is an aggregate-first projection across task, person, original input, final output, time, task type, and completion state. Its drill-through stays business-facing; technical payloads, internal identifiers, machine-shaped historical input, and technical failure text remain in separate authorized audit/engineering surfaces. +- The leadership dashboard is an aggregate-first projection across task, person, original input, final output, time, task type, and completion state. Summary cards are display-only; filtering is explicit and defaults to all results. List reads use one bounded read-only database transaction, SQL prefiltering, selective historical-message hydration, and full detail projection only for the current 20-row page. Its drill-through stays business-facing; technical payloads, internal identifiers, machine-shaped historical input, and technical failure text remain in separate authorized audit/engineering surfaces. - Authorization is enforced in server and service paths, not by navigation visibility. A denied or unresolved non-admin business route stops before parsing, plugin dispatch, and ERP execution; creator authorization is rechecked at confirmation and browser claim. +- Each enabled AgentBus channel owns one active non-admin employee account. Inbound work uses that account and route allowlist, persists the same account as immutable task assignee, and is returned only to that account's executable feed. +- Each employee account has one expected ERP identity and at most one fresh browser execution worker. Mismatched ERP identity, concurrent fresh workers, unbound channels, or unassigned tasks fail closed; stale-worker failover does not weaken organization-wide ERP FIFO serialization. - Creator and manual input-turn attribution remain durable while business input stays encrypted at rest. Routine removal is reversible archive/restore; physical purge is not an operator capability. - Unknown, ambiguous, unverified, or post-write-uncertain states fail closed; automatic retries must not create duplicate writes. - PostgreSQL is the sole required durable database/state middleware, and the production artifact provider is OSS. Redis, message queues, MongoDB, and search services are not runtime dependencies. -- Migrations must complete before the application starts. The current ACK topology starts with one application replica because AgentBus listeners and SSE emission are process-local; horizontal scale requires explicit coordination first. +- Migrations through `018_agentbus_account_workers` must complete before the updated application starts. The current ACK topology starts with one application replica because AgentBus listeners and SSE emission are process-local; horizontal scale requires explicit coordination first. - Operational diagnostics are privacy-safe structured JSON on stdout/stderr. Docker owns bounded rotation; repository files and a second mutable log database are not log sinks. - In the trusted internal deployment, AgentBus roster attachment downloads may resolve to private/reserved addresses. Credential-free HTTPS, DNS resolution/pinning, redirect revalidation, size, timeout, and digest checks remain mandatory, and trusted channels/bridges own the network-input boundary. - Canonical project memory is updated only under Integration Gate; feature tasks write only their task-scoped records. diff --git a/.project-docs/30-worklog/current-state.md b/.project-docs/30-worklog/current-state.md index 3109ca1..1feb210 100644 --- a/.project-docs/30-worklog/current-state.md +++ b/.project-docs/30-worklog/current-state.md @@ -19,10 +19,14 @@ This file is the integrated default-branch snapshot. Feature tasks record progre - Integration task `20260902-dashboard-mobile-integration-e28c` for canonical reconciliation of the mobile leadership-dashboard behavior. - Merge commit `a1b2d2f` integrating source commit `e68fcc1` from task `20260901-roster-header-error-a4f7` for exact ERP-semantic passenger-workbook header detection across rows 1–100, approved aliases, arbitrary column order, and the synchronized `0.5.125` lifecycle Skill and business-instruction DOCX. - Integration task `20260902-merge-all-restart-b7e3c91f` for local-branch/worktree reconciliation, canonical roster-contract promotion, full repository/release verification, and the authorized standard-panel restart. +- Commit `3062ed5` from task `20260902-kanban-filter-7e3a91c4` for bounded single-connection leadership-dashboard queries, SQL business prefiltering, selective search hydration, 20-row pages, cancellation propagation, and timeout feedback. +- Merge commit `b5f5847` integrating source commit `6f9fd0f` from task `20260902-agentbus-account-routing-b62f19e4` for employee-owned AgentBus channels, immutable task assignees, matching single-browser ERP workers, migration 018, and extension `0.5.164`. +- Merge commit `cc09506` integrating source commit `b1fe533` from task `20260902-dashboard-metrics-static-a91c` for display-only dashboard metric cards and explicit status filtering. +- Integration task `20260902-integrate-all-push-c93a7f21` for all-worktree reconciliation, semantic merge resolution, canonical promotion, full verification, and synchronization of `main` to `origin/main`. ## Current Focus -Operate the current `0.5.163` extension baseline and the deployed fixed-scope account model safely, provision roles and task grants through administrator workflows, use the aggregate-first leadership dashboard for business oversight, and preserve Program/AI plus ERP execution boundaries. +Operate the repository's current `0.5.164` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus organization-wide ERP execution boundaries. Migration 018, extension reload, and service rollout remain separately authorized runtime work. ## Recently Completed @@ -40,22 +44,28 @@ Operate the current `0.5.163` extension baseline and the deployed fixed-scope ac - 2026-09-02: Adapted the authenticated leadership dashboard for direct phone and portrait-tablet use, retained the desktop overview, unified the first metric card with the remaining cards, and removed the separate visible “待跟进” category by presenting those internal states as “进行中”. - 2026-09-02: Integrated passenger-workbook normalizer `v1.3.0`; one unique complete ERP-semantic header may appear on row 1 through 100 with arbitrary column order and finite approved aliases, while unknown columns, duplicate semantics, multiple candidates, unsafe formulas, and non-passport data continue to fail closed. - 2026-09-02: Restarted the standard `127.0.0.1:8786` control plane from current local `main` after the roster integration; liveness, database readiness, schema migration 017, and repeated listener stability checks passed. AgentBus remained enabled but disconnected, matching the pre-restart observation. +- 2026-09-02: Integrated migration 018 and extension `0.5.164` so each enabled AgentBus channel binds one non-admin employee, each task keeps an immutable execution assignee, administrators cannot execute another assignee's work, and only one fresh browser with the matching ERP account is execution-ready. +- 2026-09-02: Reworked leadership-dashboard reads into a bounded one-connection transaction with business SQL prefiltering, selective message hydration, page-only detail hydration, request/database deadlines, and 20-row pages; metric cards are now display-only and explicit filters default to all results. ## In Progress - The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window. +- Migration `018_agentbus_account_workers`, employee ERP identities/channel bindings, extension `0.5.164`, and the merged dashboard runtime have not been applied to or restarted on the standard service in this integration task. ## Next Recommended Steps -1. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path. -2. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings. -3. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes. +1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply migration 018, restart the control plane, load extension `0.5.164`, configure employee ERP identities and channel bindings, and run the multi-cloud-PC/identity/failover matrix before production assurance. +2. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes. +3. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path. +4. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings. ## Open Questions / Blockers - Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification. - Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence. -- The restarted service now runs current local `main`; a live internal AgentBus attachment verification remains separately unperformed. +- The standard service was last restarted before commits `3062ed5`, `b5f5847`, and `cc09506`; its runtime schema/extension/dashboard behavior must not be represented as the newly integrated repository state until an authorized rollout. +- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering mismatched ERP login, same-account device conflict, 90-second stale failover, and both manual and automatic channel work. +- A live internal AgentBus attachment verification remains separately unperformed. ## Risky Areas @@ -63,6 +73,7 @@ Operate the current `0.5.163` extension baseline and the deployed fixed-scope ac - Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity. - AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts. - Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries. +- AgentBus channel ownership, immutable task assignment, expected ERP identity, browser-worker freshness/failover, and administrator non-execution are security- and write-safety-sensitive boundaries. - Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`. ## Last Updated diff --git a/.project-docs/30-worklog/task-history.md b/.project-docs/30-worklog/task-history.md index 3d014a8..f47ad8a 100644 --- a/.project-docs/30-worklog/task-history.md +++ b/.project-docs/30-worklog/task-history.md @@ -7,3 +7,5 @@ This is integrated history. Feature tasks write only their task-scoped records; | 2026-08-28 | Project documentation migration | `.project-docs/` became the sole active project-memory system; legacy root planning files were preserved in date-scoped history. | [Integration task](tasks/20260828-migrate-project-docs-6f1a9c2d.md) | | 2026-08-28 | AgentBus reconnect | Authorized control-plane restart completed; database, migration 014, and 4/4 channels were repeatedly ready. | [Archived legacy progress](../../archive/project-history/2026-08-28/legacy-planning-with-files-progress-final.md) | | 2026-08-28 | Shared mother-plan whole-visitor export | Released strict `shared_plan + visitor-list + tid-only` routing and execution boundaries in extension `0.5.157`. | [Release gate](../../agent设计规范/test-fixtures/lwlt-lifecycle/release-gate.md) | +| 2026-09-02 | AgentBus account workers | Integrated one-to-one employee channel ownership, immutable task assignment, expected ERP identity, single-fresh-worker enforcement, migration 018, and extension `0.5.164`. | [Integration task](tasks/20260902-integrate-all-push-c93a7f21.md) | +| 2026-09-02 | Leadership dashboard query and filter contract | Integrated bounded single-connection reads, 20-row paging, cancellation/timeout feedback, display-only metrics, and explicit result filtering. | [Integration task](tasks/20260902-integrate-all-push-c93a7f21.md) | diff --git a/.project-docs/30-worklog/tasks/20260902-integrate-all-push-c93a7f21.md b/.project-docs/30-worklog/tasks/20260902-integrate-all-push-c93a7f21.md new file mode 100644 index 0000000..a15d19c --- /dev/null +++ b/.project-docs/30-worklog/tasks/20260902-integrate-all-push-c93a7f21.md @@ -0,0 +1,63 @@ +# Task: Integrate all completed changes and push main + +## Identity + +- Task ID: 20260902-integrate-all-push-c93a7f21 +- Mode: Integration +- Branch: main +- Worktree: /Users/inmanx/Documents/lwltAPI +- Base commit: 3062ed5f0400d1b90319b58b79cd50445b94ad8e +- Owner: codex +- Status: In progress + +## Scope + +- Audit every local branch and linked worktree against current `main` and `origin/main`, preserving unknown or duplicate working-tree state. +- Integrate source commits `6f9fd0f` (AgentBus account workers) and `b1fe533` (display-only dashboard metrics) with current `main` commit `3062ed5` (bounded dashboard filtering). +- Resolve overlapping dashboard, authorization, AgentBus, release, and test changes semantically without regressing accepted mobile/dashboard behavior. +- Promote accepted AgentBus worker-routing, dashboard display/filter, and bounded-query facts into canonical project memory. +- Run repository, TypeScript, control-plane, legacy, build, extension/package, and project-doc checks; then push `main` to `origin` without force and verify the remote tip. + +## Intent And Constraints + +- The user explicitly authorized merging all current changes into the main branch and pushing the result to the repository. +- Keep the fixed single-organization authorization model, leadership-only read dashboard, business-facing projection, organization-wide ERP FIFO, and existing write-safety gates. +- Apply the source task's user-confirmed metric-card behavior: summary cards are display-only; explicit form controls own filtering and default to all results. +- Apply the source task's user-confirmed AgentBus model: one channel binds one non-admin employee account; tasks keep an immutable assignee; only one fresh matching browser/ERP worker may execute for that account; administrators manage and inspect but do not claim another assignee's work. +- Do not read `.env`, deploy or restart services, apply migration 018, reload the extension, access ERP, mutate runtime tasks/accounts/channels, or send external business data. +- Do not modify source task records or task-prefixed supporting records. Keep duplicate or already-integrated dirty worktrees untouched after proving their effective changes are represented by commits reachable from `main`. +- Use a normal non-force push only after all required checks pass and `origin/main` is confirmed not to have advanced unexpectedly. + +## Outcome + +- Audited all 13 linked worktrees and every local branch after fetching `origin`. The account-system, password, dashboard scale/mobile, roster, prior integration, and older branches are ancestors or patch-equivalent to changes already represented on `main`. +- Compared every dirty path in the roster source worktree against source commit `e68fcc1`; all 23 paths matched byte-for-byte or matched the recorded deletion, proving that no unique roster product/release change remained outside the already merged history. +- Kept source-task-only records and superseded/empty operational branches out of the integration tree. The older kanban selected-card commit was not replayed because its accepted status presentation was already carried by the mobile integration and its click-to-filter behavior is explicitly superseded by the display-only metric-card decision. +- Finalized and reverified AgentBus source task `20260902-agentbus-account-routing-b62f19e4` as commit `6f9fd0f`, then merged it through `b5f5847` while retaining the dashboard query changes already on `main`. +- Integrated display-only dashboard source commit `b1fe533` through merge commit `cc09506`, preserving the 20-row bounded query, abort/timeout feedback, mobile layout, rankings, business-facing attention-state merge, and explicit filter form. +- Resolved both merge rounds' static-asset conflicts with one combined cache token instead of choosing either side mechanically. Source task records remain unchanged in their source commits/worktrees as required by Integration Gate ownership. +- Advanced the synchronized Chrome extension release to `0.5.164`, archived `0.5.163`, added migration `018_agentbus_account_workers`, and retained manifest/source/ZIP consistency. +- Promoted the accepted channel-owner → employee account → immutable task assignee → one matching fresh browser/ERP worker chain into AUTH-001, architecture, data flow, domain rules, current state, evidence, commitments, and integrated history. +- Recorded the final dashboard contract: five summary cards are display-only, the explicit status filter defaults to all results, and dashboard reads use one bounded read-only transaction with selective hydration and page-only detail projection. +- No database migration, service restart, extension reload, ERP access/write, runtime task/account/channel mutation, deployment, or external business-data transmission was performed. + +## Verification + +- Before source commits, `check_project_docs.py`, task-aware drift checks, `git diff --check`, repository hygiene, type checking, full control-plane/legacy suites, builds, extension JavaScript syntax, and package/source/hash checks passed for both the dashboard-filter and AgentBus worktrees. +- AgentBus source verification passed repository hygiene 10/10, control-plane 158/158, legacy 264/264, TypeScript no-emit/build, extension/platform syntax, and release consistency. +- The AgentBus merge passed TypeScript, repository hygiene 10/10, and focused account/AgentBus regression 29/29. +- The combined dashboard merge passed focused dashboard regression 5/5, authorization regression 10/10, JavaScript syntax, and staged-diff checks. +- Final integrated-tree verification passed: `node --run check:repo` 10/10, `node --run check`, `node --run test:control-plane` 158/158, `node --run test:legacy` 265/265, and `node --run build`. +- `check_project_docs.py`, `check_doc_drift.py --task-id 20260902-integrate-all-push-c93a7f21`, conflict-marker scanning, and `git diff --check` passed on the reconciled tree. +- Final `git cherry main ` audit found only three patch-equivalent source commits and standalone `53a38f2`; that older selected-card patch is intentionally superseded as documented above. No unintegrated product/release commit remains. +- After the initial fetch, `origin/main...main` reported `0 28`: the remote had no commits absent locally, and local `main` was 28 commits ahead before the documentation commit and push. +- Remote push verification remains to be recorded before completion. + +## Follow-ups + +- Migration 018, service restart, extension `0.5.164` rollout, employee ERP/channel configuration, and the two-cloud-PC staging matrix require a separate explicitly authorized runtime task. +- A live internal AgentBus attachment retry and the already recorded ERP read/write verification gaps remain separately authorized work. + +## Promotion Candidates + +- None recorded. diff --git a/.project-docs/40-domain/business-rules.md b/.project-docs/40-domain/business-rules.md index 6e478da..06c1b92 100644 --- a/.project-docs/40-domain/business-rules.md +++ b/.project-docs/40-domain/business-rules.md @@ -3,13 +3,15 @@ ## Durable Rules - `agent设计规范/business-adaptation-registry.md` is the cross-session business entry; each business maps user input, Skill/action, ERP flow, contracts, implementation, fixtures, and verification status. -- Manual and AgentBus tasks share the same 18 machine routes, task-scoped parser mode snapshot, and organization automation rules. +- Manual and AgentBus tasks share the same 18 machine routes, task-scoped parser mode snapshot, and organization automation rules. AgentBus intake evaluates the bound employee account's route grants rather than an administrator or whichever browser is online. - The platform exposes one fixed deployment scope, not an organization-management product. Accounts use `admin`, `team_lead`, and `user` roles. - Passwords must be non-empty but have no application-level length restriction. First login and administrator password reset do not force a subsequent password change; users may still change passwords voluntarily, administrators may reset them, and password changes revoke existing sessions according to the account lifecycle contract. - Administrators always hold all 18 manual business routes. Team leads and ordinary users start with no task grants, require explicit administrator allowlists, and may use normal task APIs only for their own manual tasks. - A known ungranted route or a non-unique/unresolved route for a non-administrator fails before parsing, plugin dispatch, or ERP execution. Authorization is rechecked for supplemental input, attachments, confirmation, automatic confirmation, and browser claim. -- Team leads may read all manual account work only through the platform-operations dashboard. The dashboard is aggregate-first across task, person, original input, final output, time, task type, and completion state, with business-facing drill-through. Internal attention or waiting-for-input states remain unchanged in task storage but are presented and filtered as “进行中”; the leadership view exposes no separate “待跟进” category. It is not an audit log and never renders technical payloads, internal identifiers, machine-shaped historical input, or technical failure text; this visibility does not grant cross-user task mutation, artifacts, SSE, global settings, audit administration, or AgentBus access. +- Team leads may read all manual account work only through the platform-operations dashboard. The dashboard is aggregate-first across task, person, original input, final output, time, task type, and completion state, with business-facing drill-through. Its five summary cards are display-only; the explicit task-result filter defaults to all results. Internal attention or waiting-for-input states remain unchanged in task storage but are presented and filtered as “进行中”; the leadership view exposes no separate “待跟进” category. It is not an audit log and never renders technical payloads, internal identifiers, machine-shaped historical input, or technical failure text; this visibility does not grant cross-user task mutation, artifacts, SSE, global settings, audit administration, or AgentBus access. - Creator and input-turn attribution are durable, business inputs remain encrypted at rest, denial audit excludes plaintext, and routine task removal uses archive/restore rather than physical purge. +- Each non-admin employee may carry one case-insensitively unique expected ERP account and one AgentBus channel. New manual and AgentBus tasks persist an immutable assignee; only that account may confirm, claim, reconcile, resume, or submit ERP execution results. Administrators manage and inspect but do not execute another assignee's work. +- A browser is execution-ready only when it is the account's sole fresh worker and the active ERP session matches the expected account. Concurrent fresh workers, identity mismatch, unbound channels, and historical unassigned AgentBus tasks fail closed; stale failover waits 90 seconds and organization-wide ERP FIFO remains. - The two passenger-list import routes are Program-only and wait for exactly one `.xls` or `.xlsx` attachment before deterministic normalization. - Passenger workbooks must contain exactly one complete ERP-semantic header within rows 1–100. The header may be on row 1 or follow metadata, column order is arbitrary, and only the finite approved source/ERP aliases—including `NAME`, `证件号码`, `签发日`, and `身份证`—are mapped. Unknown or unheaded data columns, duplicate semantic fields, multiple candidate headers, and non-passport identity data fail closed; the internal 13-column canonical TSV contract remains unchanged. - A WeChat attachment card is transport placeholder text, not file content. Only a structured `payload.attachments[]` entry can resume a roster task; missing metadata fails before ingestion and leaves the original task in `awaiting_attachment` instead of creating a new task. diff --git a/.project-docs/50-evidence/evidence-index.md b/.project-docs/50-evidence/evidence-index.md index 9547597..cf49000 100644 --- a/.project-docs/50-evidence/evidence-index.md +++ b/.project-docs/50-evidence/evidence-index.md @@ -16,6 +16,8 @@ Use this index for searchable, traceable evidence records. | 2026-09-01 | Leadership platform-operations dashboard | Repository and authenticated browser verified | [Feature task](../30-worklog/tasks/20260901-leadership-dashboard-c4b9e1.md) | Aggregate-first task/person/input/output/time/type/completion presentation, business-safe projections, clickable drill-through, and full regression passed against the standard 8786 runtime. | | 2026-09-02 | Account registration password rejection and simplified password lifecycle | Root cause and repository fix verified; runtime not restarted | [Evidence record](topics/20260902-registration-invalid-params-59f94692__account-registration-password-validation.md) | Privacy-safe diagnostics isolated the original rejection to `password`; the user then selected non-empty-only passwords and removal of first-login forced changes, with full regression coverage. | | 2026-09-02 | Passenger workbook header rejection and ERP-semantic compatibility | Root cause and repository fix verified; live attachment retry not performed | [Integration record](../30-worklog/tasks/20260902-merge-all-restart-b7e3c91f.md) | Source task `20260901-roster-header-error-a4f7` established that the approved workbook used the `身份证` alias and a safe reverse issue-date formula; normalizer `v1.3.0` accepts the exact mapped semantics without weakening workbook safety gates. | +| 2026-09-02 | AgentBus employee/account/browser/ERP routing | Repository, release, and regression verified; migration/restart/extension rollout not performed | [Integration record](../30-worklog/tasks/20260902-integrate-all-push-c93a7f21.md) | Migration 018, immutable task assignees, channel-owner/route gates, one fresh matching worker, administrator non-execution, extension `0.5.164`, and release hashes were integrated and verified. | +| 2026-09-02 | Leadership-dashboard filtering and summary interaction | Repository and focused regression verified; merged runtime not restarted | [Integration record](../30-worklog/tasks/20260902-integrate-all-push-c93a7f21.md) | Single-connection bounded reads, SQL prefiltering, selective hydration, 20-row paging, cancellation/timeout feedback, and display-only metric cards with explicit filters passed combined regression. | ## When To Add Evidence diff --git a/.project-docs/80-commitments/commitments.md b/.project-docs/80-commitments/commitments.md index 1731717..2ee3616 100644 --- a/.project-docs/80-commitments/commitments.md +++ b/.project-docs/80-commitments/commitments.md @@ -7,6 +7,7 @@ Track future-facing memory: promised follow-ups, unfinished loops, timed checks, | 2026-08-28 | Verify shared-mother-plan `tid-only` whole-visitor export against the current runtime ERP path. | Explicit user authorization for ERP read access | Future authorized task | Pending authorization | Run read-only source and artifact checks without external delivery. | | 2026-08-28 | Verify independent-order SGL/TWN and adult/child/leader headcount mappings with real ERP writes. | Explicit user authorization for controlled ERP writes | Future authorized task | Pending authorization | Use reversible values and action-specific requery evidence. | | 2026-08-28 | Resolve AgentBus OSS attachment rejection caused by private/reserved local DNS answers. | User scheduled integration and confirmed the environment is trusted internal networking | Integration task `20260831-integrate-server-diagnostics-8b42c6d1` | Completed in repository | Deploy/restart and run one live internal attachment verification only under separate authorization. | +| 2026-09-02 | Roll out and stage-test AgentBus account workers. | Explicit authorization for database backup/migration, service restart, extension reload, account/channel configuration, and staging traffic | Future authorized rollout task | Pending authorization | Apply migration 018 and extension `0.5.164`, then verify two employee accounts/cloud PCs, ERP identity mismatch, same-account worker conflict, 90-second failover, and manual/AgentBus execution routing. | ## Use