docs: reconcile batch and webhook integration

This commit is contained in:
inman committed 2026-09-09 17:33:19 +08:00
1 parent 295409bff0
commit a6abd32618
17 files changed
+185 -43

No files matched your search

+7 -5
View File
@@ -7,7 +7,7 @@
| Business directive | Employee manual workbench or AgentBus | Route orchestrator | Manual input uses a signed-in team lead/user; AgentBus input uses the channel's bound employee account and its route allowlist. Administrators cannot enter this flow. |
| AgentBus execution ownership | Enabled channel | Employee account → immutable task assignee → executable feed | One account owns at most one channel; unbound channels and unassigned historical tasks stay non-executable. |
| Manual account authorization | Signed-in employee plus resolved business route | Intake and task-transition gates | Team leads/users require explicit grants; administrators manage grants but hold none, and denied or unresolved routes fail closed. |
| Parsing | Route orchestrator | AI Skill or deterministic Program parser | AI/Shadow/Auto/Program mode is frozen per task |
| Parsing | 19-route orchestrator | AI Skill or deterministic Program parser | AI/Shadow/Auto/Program mode is frozen per task; the external Agent exposes 18 routes and three routes are Program-only |
| Operation | Parser | Control-plane task and confirmation | Must validate against the same final contract |
| ERP execution | Confirmed task | Chrome extension and logged-in ERP page | Requires unique object, page identity, ownership, and write preflight |
| Completion evidence | ERP response/requery | Control-plane receipt and business reply | Evidence is action-specific; uncertain writes fail closed |
@@ -16,7 +16,8 @@
| Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. |
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
| Platform operations oversight | Durably assigned manual/AgentBus task, encrypted instruction history, and readable outcome | Team-lead-only leadership projection | Immutable assignee is the employee dimension; unassigned historical AgentBus rows are excluded. Display-only summaries plus explicit filters drive an aggregate-first task/person/input/output/time/type/completion view, with bounded list reads and page-only detail hydration. |
| Team-lead task summary | Future stable manual/AgentBus task outcome for another non-admin employee | Role/channel reconciler → current-owner encrypted route → separate durable outbox → leader-owned AgentBus channel → WeChat | Automatic for active team leads with a usable route; employee replies are sent first, summary frames use stable IDs and explicit routing with no `reply_to`, and delivery failure never changes task state. |
| Leader task summary | Future stable manual/AgentBus task outcome for a durably assigned non-admin employee | Privacy projection → encrypted organization/revision outbox → fixed external Webhook → leader group | Independent from AgentBus task replies and ERP execution; strict success means accepted, not delivered, and rejected/uncertain attempts terminate without automatic retry. |
| Shared-child batch creation | Inclusive departure range plus exact product/customer/counts | Complete read-only parent enumeration → validated date/tid target list → sequential single-child adapter reuse | All targets are known before the first write; execution is deterministic and stops at the first blocked, failed, or uncertain result with remaining targets not started. |
| Browser worker selection | Immutable task assignee | One fresh account-bound browser connection | The heartbeat must prove the expected ERP identity from one unique login node by normalized exact equality; missing, duplicate, blank, substring-only, or mismatched identity is non-executable, with failover only after staleness. |
| Account-scoped ERP queue | Confirmed task assignee | Assigned account's browser worker | Organization-plus-account advisory locking preserves FIFO and at most one active execution for that account; another account's active, queued, stale, or uncertain work is outside this queue. |
| Executable event and result routing | Immutable task assignee | Matching authenticated employee page and plugin | Task APIs, SSE history/live events, claims, plugin results, and browser cleanup commands require a team-lead/user session matching the assignee; administrators are rejected before task handling. |
@@ -26,7 +27,7 @@
## State Ownership
- PostgreSQL owns durable control-plane account, management/task-plane role constraints, exact expected ERP identity, employee task-route grant, AgentBus channel owner, immutable task assignee, account-scoped queue/lease state, browser worker, session, confirmation, audit, archive, outcome state, and revisioned team-lead notification subscriptions/deliveries. Migration 021 removes and rejects administrator task principals. Notification destinations and payloads remain encrypted at rest. A force-deleted task no longer exists in task state; only its minimal non-content deletion audit marker remains, while an already delivered external message cannot be retracted.
- PostgreSQL owns durable control-plane account, management/task-plane role constraints, exact expected ERP identity, employee task-route grant, AgentBus channel owner, immutable task assignee, account-scoped queue/lease state, browser worker, session, confirmation, audit, archive, outcome state, and revisioned leader-summary Webhook state/deliveries. Migration 021 removes and rejects administrator task principals, migration 022 admits the new route without granting it, and migration 023 retires unsent legacy AgentBus summaries. Webhook payloads remain encrypted at rest while the URL/token remain runtime-only. A force-deleted task no longer exists in task state; only its minimal non-content deletion audit marker remains, while an externally accepted summary cannot be retracted.
- Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted.
- Chrome extension local state is bounded execution/reconciliation support, not canonical business history.
- `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection.
@@ -34,10 +35,11 @@
## External Interfaces
- Employee task workbench and separate administrator management pages at the control-plane service.
- AgentBus WebSocket channels and attachment delivery.
- AgentBus WebSocket channels and attachment delivery for normal employee task traffic.
- Fixed external Webhook for organization-level leader-summary delivery.
- Logged-in ERP browser pages under the Chrome extension host permissions.
- PostgreSQL, OSS, deployment gateway, and authenticated artifact download.
## Last Updated
2026-09-07
2026-09-09