docs: accept leader summary notification architecture
This commit is contained in:
1 parent
1a3ab63700
commit
a2888db243
15 files changed
+157
-18
No files matched your search
@@ -4,6 +4,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
|
||||
## Integrated Through
|
||||
|
||||
- Source commit `1a3ab63` from feature task `20260907-implement-leader-agentbus-copy-b7e31a94` for default-off team-lead task summaries over future manual and AgentBus outcomes, a separate encrypted/revisioned outbox, verified proactive AgentBus routing, administrator configuration/health UI, and migration 020; integration task `20260907-integrate-leader-summaries-84c1d7ea` accepted AUTH-003 and canonical notification boundaries.
|
||||
- Correction commit `fe1cc2cddc29e4dead81e53c16d31bb71493602d` from integration task `20260903-backup-revert-extension-update-c71a4e92` preserved the complete former `0.5.167`/migration-019 stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed the central private-OSS/ECS automatic-update service architecture without rewriting history, and retained the exact Chrome extension `0.5.167` source/package on the active main line with migration 018.
|
||||
- Merge commit `3224758` and integration task `20260903-finalize-extension-update-a6c4e192` remain historical records of the full-stack extension-update design. Only the plugin `0.5.167` release, adaptive entry readiness, and dormant plugin-side idle/reload safeguards remain active; the server orchestration is preserved on the backup branch only.
|
||||
- Commit `c4c469f4441d744627af2d34abe693b6783e833c` for the independently advanced remote deployment/extension line.
|
||||
@@ -33,7 +34,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
|
||||
## Current Focus
|
||||
|
||||
Operate the repository's current `0.5.167` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator visibility never enters another account's executable event/result path. Migration 018, manual extension reload, guarded product-search retry, and service rollout remain separately authorized runtime work; server-side automatic extension updating is not part of the active main line.
|
||||
Operate the repository's current `0.5.167` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator or team-lead visibility never enters another account's executable event/result path. Team-lead task summaries remain default-off until an administrator verifies the exact proactive route; migration 020, manual extension reload, guarded product-search retry, and service rollout remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
|
||||
|
||||
## Recently Completed
|
||||
|
||||
@@ -58,19 +59,21 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
|
||||
- 2026-09-03: Accepted AUTH-002 and integrated account-scoped ERP queues. Each immutable assignee now owns one FIFO/single-active claim partition, different accounts no longer block one another, and executable SSE/results/cleanup commands are owner-only even when an administrator is signed in.
|
||||
- 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back.
|
||||
- 2026-09-03: Backed up the complete adaptive-readiness and central extension-update stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, then removed the central OSS/ECS update service and migration 019 from `main` with normal history-preserving commits. After correcting an initially over-broad rollback, the active repository retains the exact extension `0.5.167` source/package and uses migration 018; the removed server architecture was never deployed by these tasks.
|
||||
- 2026-09-07: Integrated AUTH-003 and migration 020 for administrator-managed team-lead task summaries. Future stable manual/AgentBus outcomes for other non-admin employees project into a separate encrypted outbox and use the leader's verified AgentBus/WeChat target without changing task ownership, employee reply priority, or ERP execution authority.
|
||||
|
||||
## In Progress
|
||||
|
||||
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
|
||||
- Migration `018_agentbus_account_workers`, employee ERP identities/channel bindings, extension `0.5.167`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/runtime changes have not been applied to or restarted on the standard service in this integration task.
|
||||
- Required migrations through `020_leader_task_summary_notifications`, employee ERP identities/channel bindings, extension `0.5.167`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/notification runtime changes have not been applied to or restarted on the standard service in this integration task. No production team-lead target is configured or enabled.
|
||||
|
||||
## Next Recommended Steps
|
||||
|
||||
1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply migration 018, restart the control plane, manually load extension `0.5.167`, verify its runtime handshake, configure employee ERP identities and channel bindings, and run the multi-cloud-PC/identity/failover plus account-queue matrix before production assurance.
|
||||
1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply all migrations through 020, restart the control plane, manually load extension `0.5.167`, verify its runtime handshake, configure employee ERP identities and channel bindings, and run the multi-cloud-PC/identity/failover plus account-queue matrix before production assurance.
|
||||
2. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes.
|
||||
3. In the same authorized staging window, verify that an administrator receives no employee executable events/results, then force-delete disposable waiting and active employee tasks and confirm database absence plus cleanup only in the owning employee plugin.
|
||||
4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
|
||||
5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
|
||||
6. With explicit external-send authorization, configure one controlled team-lead route, verify proactive `task.summary` handling and stable-frame deduplication through AgentBus/WeChat, then observe one manual and one AgentBus task before wider enablement.
|
||||
|
||||
## Open Questions / Blockers
|
||||
|
||||
@@ -80,6 +83,7 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
|
||||
- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering mismatched ERP login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator executable-feed isolation, and both manual and automatic channel work.
|
||||
- Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
|
||||
- A live internal AgentBus attachment verification remains separately unperformed.
|
||||
- Proactive team-lead `task.summary` delivery has repository, mock-WebSocket, and disposable-PostgreSQL evidence but no deployed AgentBus/WeChat canary; exact production target verification and enablement remain pending authorization.
|
||||
|
||||
## Risky Areas
|
||||
|
||||
@@ -89,8 +93,9 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
|
||||
- Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
|
||||
- AgentBus channel ownership, immutable task assignment, expected ERP identity, browser-worker freshness/failover, and administrator non-execution are security- and write-safety-sensitive boundaries.
|
||||
- Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
|
||||
- Team-lead summary target verification, encrypted projection/delivery rows, at-least-once stable-frame deduplication, privacy allowlisting, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
|
||||
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-09-03
|
||||
2026-09-07
|
||||
@@ -11,3 +11,4 @@ This is integrated history. Feature tasks write only their task-scoped records;
|
||||
| 2026-09-02 | Leadership dashboard query and filter contract | Integrated bounded single-connection reads, 20-row paging, cancellation/timeout feedback, display-only metrics, and explicit result filtering. | [Integration task](tasks/20260902-integrate-all-push-c93a7f21.md) |
|
||||
| 2026-09-03 | Adaptive ERP readiness and extension host updates | Integrated immediate-first scatter-plan readiness plus private OSS/ECS host updating as extension `0.5.167`; the server-update architecture was later reverted before deployment while the plugin release was retained. | [Original integration task](tasks/20260903-finalize-extension-update-a6c4e192.md) |
|
||||
| 2026-09-03 | Extension-update iteration backup and scoped rollback | Preserved exact commit `b2e33e2` on remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed migration 019 and server-side automatic updating, and retained extension `0.5.167` plus migration 018 through non-force commits. | [Rollback task](tasks/20260903-backup-revert-extension-update-c71a4e92.md) |
|
||||
| 2026-09-07 | Team-lead AgentBus task summaries | Integrated default-off future-only summaries for other non-admin employees' manual/AgentBus outcomes through a separate encrypted outbox and verified proactive target, without changing task or ERP authority. | [Integration task](tasks/20260907-integrate-leader-summaries-84c1d7ea.md) |
|
||||
@@ -0,0 +1,55 @@
|
||||
# Task: Integrate leader AgentBus task summaries
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260907-integrate-leader-summaries-84c1d7ea
|
||||
- Mode: Integration
|
||||
- Branch: codex/20260907-integrate-leader-summaries-84c1d7ea-integrate-leader-summaries
|
||||
- Worktree: /Users/inmanx/Documents/lwltAPI-integrate-leader-summaries-6d42be91-v2
|
||||
- Base commit: 1a3ab6370071d80720f50efc64a97053ad3fe7fc
|
||||
- Owner: codex
|
||||
- Status: Integration in progress
|
||||
|
||||
## Scope
|
||||
|
||||
- Use completed feature commit `1a3ab63` as the Integration baseline for administrator-managed team-lead task-summary notifications.
|
||||
- Review and promote the source task's accepted durable notification, authorization, privacy, protocol, data-model, operational, and rollout facts into canonical project memory.
|
||||
- Run complete repository/document/test/build gates, then advance remote `main` through a normal non-force push without modifying the occupied local `main` worktree.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- The user explicitly authorized merging to `main` and pushing the repository. This authorizes Git integration/push, not a database migration, service restart/deployment, channel configuration, task mutation, ERP access, or a real external message.
|
||||
- Preserve AUTH-001/002 task ownership and account-scoped ERP execution. Accept the user-confirmed fixed-organization subscription and both manual/AgentBus sources as AUTH-003, while keeping the notification read-only, default-off, future-only, privacy-safe, and independent of employee AgentBus replies.
|
||||
- Source task records remain read-only. Integration owns only its task record and canonical reconciliation files in this exclusive worktree.
|
||||
- The local `main` checkout remains occupied by task `20260902-migrate-restart-confirmed-4f8c2a71` and contains its untracked record; do not modify, adopt, stash, reset, clean, or fast-forward that worktree.
|
||||
- The previous completed integration-lock owner was clean and recorded as integrated/pushed, so it was released normally without `--force` before this task acquired the lock.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Started from source commit `1a3ab63`, which directly descends from current `origin/main` `f466499` and already contains the immutable source task record required by the Integration drift gate.
|
||||
- Accepted AUTH-003 and reconciled decision index, system overview, data flow, business rules, success criteria, current state, task history, evidence index, and rollout commitments around the separate default-off encrypted leader-summary projection and proactive AgentBus contract.
|
||||
- Corrected three stale paths in the required read-before-planning entry so they point to the actual memory index, project positioning, and current-state files.
|
||||
- An initial unpushed integration worktree had been based on `origin/main`; its drift check correctly rejected the newly introduced source task record as foreign. That clean intermediate history was retained locally, its lock was normally released, and this final integration restarted from the source commit without force, reset, or lost changes.
|
||||
- Remote push pending final verification.
|
||||
|
||||
## Verification
|
||||
|
||||
- `npm run check:repo`: passed (10/10), including active Markdown links and repository/release hygiene.
|
||||
- `npm run check`: passed.
|
||||
- `npm run test:control-plane`: passed (174/174).
|
||||
- `npm run test:legacy`: passed (270/270).
|
||||
- `npm run build`: passed.
|
||||
- `node --check LianSyn-platform/app.js`: passed.
|
||||
- `git diff --check`: passed.
|
||||
- `check_project_docs.py`: passed.
|
||||
- `check_doc_drift.py --task-id 20260907-integrate-leader-summaries-84c1d7ea`: passed from the corrected source-commit baseline, with no foreign task-owned document changes.
|
||||
- `git merge-base --is-ancestor origin/main 1a3ab63`: passed before integration, proving the current remote main tip is contained in the source baseline.
|
||||
- The final Integration worktree reused the Feature worktree's byte-identical ignored `node_modules` through a temporary symlink; the link was removed after verification.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Production migration 020, service restart/deployment, exact leader target configuration, and controlled AgentBus/WeChat canary remain separately authorized rollout work.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None. Accepted source facts were promoted through AUTH-003 and the canonical architecture/domain/state/evidence/commitment documents in this Integration task.
|
||||
Reference in new issue
Block a user