docs: accept leader summary notification architecture

This commit is contained in:
inman committed 2026-09-07 13:25:14 +08:00
1 parent 1a3ab63700
commit a2888db243
15 files changed
+157 -18

No files matched your search

+3 -2
View File
@@ -16,6 +16,7 @@
| Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. |
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Display-only summaries plus explicit filters drive an aggregate-first task/person/input/output/time/type/completion view; list reads are bounded to one read-only connection and hydrate full details only for the current page. |
| Team-lead task summary | Future stable manual/AgentBus task outcome for another non-admin employee | Separate encrypted durable outbox → leader-owned AgentBus channel → verified WeChat conversation | Administrator-configured and default-off; employee replies are sent first, summary frames use stable IDs and explicit routing with no `reply_to`, and delivery failure never changes task state. |
| Browser worker selection | Immutable task assignee | One fresh account-bound browser connection | The heartbeat must match the account's expected ERP identity; a second fresh worker or identity mismatch is non-executable, with failover only after staleness. |
| Account-scoped ERP queue | Confirmed task assignee | Assigned account's browser worker | Organization-plus-account advisory locking preserves FIFO and at most one active execution for that account; another account's active, queued, stale, or uncertain work is outside this queue. |
| Executable event and result routing | Immutable task assignee | Matching authenticated platform page and plugin | SSE history/live events, claims, plugin results, and browser cleanup commands never use administrator-wide visibility and fail closed when the authenticated account is not the assignee. |
@@ -25,7 +26,7 @@
## State Ownership
- PostgreSQL owns durable control-plane account, role, expected ERP identity, task-route grant, AgentBus channel owner, immutable task assignee, account-scoped queue/lease state, browser worker, session, confirmation, audit, archive, and outcome state. A force-deleted task no longer exists in task state; only its minimal non-content deletion audit marker remains.
- PostgreSQL owns durable control-plane account, role, expected ERP identity, task-route grant, AgentBus channel owner, immutable task assignee, account-scoped queue/lease state, browser worker, session, confirmation, audit, archive, outcome state, and revisioned team-lead notification subscriptions/deliveries. Notification destinations and payloads remain encrypted at rest. A force-deleted task no longer exists in task state; only its minimal non-content deletion audit marker remains, while an already delivered external message cannot be retracted.
- Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted.
- Chrome extension local state is bounded execution/reconciliation support, not canonical business history.
- `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection.
@@ -39,4 +40,4 @@
## Last Updated
2026-09-03
2026-09-07