docs: reconcile batch and webhook integration
This commit is contained in:
1 parent
295409bff0
commit
a6abd32618
17 files changed
+185
-43
No files matched your search
@@ -4,6 +4,9 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
|
||||
## Integrated Through
|
||||
|
||||
- Source commit `be17f6c` from feature task `20260908-leader-webhook-api-7c4e9a12`, integrated as merge commit `295409b`, for organization-level external Webhook delivery of privacy-bounded leader summaries, migration `023_leader_summary_webhook_delivery`, and AUTH-005's one-attempt accepted-versus-delivered boundary.
|
||||
- Source commit `6ac90f8` from feature task `20260908-shared-child-batch-create-4e7c2a91`, integrated as merge commit `0d20544`, for Program-only `shared_child_order_batch_create`, parser `v1.0.7`, migration `022_shared_child_order_batch_create`, complete pre-write target enumeration, deterministic stop-on-first-non-success execution, and extension `0.5.170`.
|
||||
- Commit `bb115a3` from integration task `20260908-remove-maintain-project-docs-requirement-6d8a31f2` removed the deleted external project-document Skill/task-registry dependency and retained repository-local worktree and project-memory gates.
|
||||
- Source commit `a2378c8` from feature task `20260907-admin-task-data-plane-isolation-c3a7e91b`, integrated as `fd39347`, for the management-plane-only administrator role, task-data-plane denial at UI/HTTP/service/database boundaries, team-lead-only operations dashboard, and migration `021_admin_task_data_plane_isolation`; integration task `20260907-integrate-all-changes-9d2e7c41` accepted AUTH-004 and reconciled the administrator boundary.
|
||||
- Source commit `9043ad6eda0deb2a620e1303467d1c3bd80374ed` from feature task `20260907-leader-kanban-all-members-73c9e1a4`, integrated as `03d0131`, for the assignee-based team-lead dashboard over all durably assigned manual and AgentBus tasks.
|
||||
- Source commit `af9c90a3142e197493e80d74333af876c3bb947a` from feature task `20260907-ignore-extra-roster-fields-a6e4c9f2`, integrated as `9d1a6b4`, for required-field-only passenger-workbook normalization `v1.4.0`, ignored non-import columns, and synchronized Skill/business-instruction release `0.5.126`.
|
||||
@@ -39,7 +42,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
|
||||
## Current Focus
|
||||
|
||||
Operate the repository's current extension `0.5.169`, Skill/business-instruction `0.5.126`, roster normalizer `v1.4.0`, and migration-021 fixed-scope account model safely. Administrators manage accounts, channels, employee grants, parser routing, automation settings, and audit but never enter the task data plane. Team leads/users own normal task operations through immutable assignment; same-account work remains FIFO and single-active while distinct accounts are independent. Team leads alone receive the read-only assignee-based dashboard over assigned manual and AgentBus work and automatic future privacy-bounded summaries through usable owned AgentBus routes. Migration 021, manual extension reload, guarded product-search retry, service rollout, and any live AgentBus/WeChat canary remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
|
||||
Operate the repository's current extension `0.5.170`, Program parser `v1.0.7`, Skill/business-instruction `0.5.126`, roster normalizer `v1.4.0`, and migrations through `023_leader_summary_webhook_delivery` safely. The machine registry contains 19 routes; the external Agent remains limited to its original 18 and the two passenger-list routes plus shared-child batch creation are Program-only. Administrators manage accounts, channels, employee grants, parser routing, automation settings, and audit but never enter the task data plane. Team leads/users own normal task operations through immutable assignment; same-account work remains FIFO and single-active while distinct accounts are independent. Team leads alone receive the read-only assignee-based dashboard. Future privacy-bounded organization summaries use one protected external Webhook and a separate encrypted one-attempt outbox, not a leader AgentBus route. Database migration, extension reload, route grants, service rollout, live ERP validation, and any external Webhook canary remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
|
||||
|
||||
## Recently Completed
|
||||
|
||||
@@ -71,32 +74,37 @@ Operate the repository's current extension `0.5.169`, Skill/business-instruction
|
||||
- 2026-09-07: Advanced passenger-workbook normalization to `v1.4.0` and the five Skills plus operator instruction DOCX to `0.5.126`. Only required ERP source semantics participate in extraction; ordinary non-import columns are ignored and excluded from canonical TSV while active-content safety remains workbook-wide.
|
||||
- 2026-09-07: Expanded the team-lead operations dashboard to every durably assigned manual and AgentBus task using immutable assignment as the employee dimension; unassigned historical AgentBus rows remain excluded.
|
||||
- 2026-09-07: Accepted AUTH-004 and migration 021. Administrators are management-plane-only, cannot access task APIs, browser workers, task routes, dashboards, summaries, or task principals, and role promotion removes legacy executable bindings.
|
||||
- 2026-09-08: Added Program-only shared-child batch creation across an inclusive departure-date range. Every product-matching parent is enumerated and validated before the first write; execution is ordered by date/tid, stops at the first blocked/failed/uncertain result, and never retries a write automatically. Parser `v1.0.7`, migration 022, and extension `0.5.170` are synchronized.
|
||||
- 2026-09-08: Replaced only the leader-summary AgentBus transport with an organization-level external Webhook. AUTH-005 and migration 023 retain future-only encrypted/privacy-bounded projection, mark only strict gateway success as accepted rather than delivered, and terminate rejected or uncertain attempts without automatic retry.
|
||||
- 2026-09-08: Removed the deleted external project-document Skill and task-registry requirement; repository-local Git worktree checks and `.project-docs/` remain the active collaboration and memory boundary.
|
||||
|
||||
## In Progress
|
||||
|
||||
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
|
||||
- Required migrations through `021_admin_task_data_plane_isolation`, employee ERP identities/channel bindings, extension `0.5.169`, account-scoped queue/routing changes, owner force-delete behavior, roster `v1.4.0`, and the merged dashboard/automatic-notification/administrator-isolation runtime changes have not been applied to or restarted on the standard service in this integration task. No live automatic team-lead delivery canary was performed.
|
||||
- Required migrations through `023_leader_summary_webhook_delivery`, employee ERP identities/channel bindings, extension `0.5.170`, account-scoped queue/routing changes, owner force-delete behavior, roster `v1.4.0`, shared-child batch creation, and the merged dashboard/Webhook/administrator-isolation runtime changes have not been applied to or restarted on the standard service in this integration task. No live batch ERP write or external Webhook canary was performed.
|
||||
|
||||
## Next Recommended Steps
|
||||
|
||||
1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply all migrations through 021, deploy the control plane and platform assets together, restart the service, manually load extension `0.5.169`, and verify readiness plus the exact-account handshake.
|
||||
2. Through the administrator management UI, create representative team-lead and ordinary accounts, assign narrow task grants and channels, and verify that administrator task pages/APIs/workers fail closed while employee routes remain usable.
|
||||
1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply all migrations through 023 in order, deploy the control plane and platform assets together, restart the service, manually load extension `0.5.170`, and verify readiness plus the exact-account handshake.
|
||||
2. Through the administrator management UI, create representative team-lead and ordinary accounts, assign narrow task grants and channels, explicitly grant the new shared-child batch route only where intended, and verify that administrator task pages/APIs/workers fail closed while employee routes remain usable.
|
||||
3. With separate team-lead and employee sessions, verify owner isolation, both-source leadership-dashboard reads, same-account FIFO, cross-account independence, mismatched ERP identity, worker conflict/failover, and owner-performed waiting/active force deletion without unintended ERP writes.
|
||||
4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
|
||||
5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
|
||||
6. With explicit external-send authorization, use one controlled team-lead channel to verify automatic current-owner route resolution, proactive `task.summary` handling, and stable-frame deduplication through AgentBus/WeChat, then observe one manual and one AgentBus task before wider assurance.
|
||||
6. With explicit ERP-write authorization, run one bounded shared-child batch acceptance task after validating the full target set, then compare every per-parent receipt and stop behavior before wider use.
|
||||
7. With explicit external-send authorization and provider-confirmed protected configuration, send one controlled leader-summary Webhook canary, record only strict gateway acceptance, and independently verify downstream group delivery without automatically retrying any uncertain attempt.
|
||||
|
||||
## Open Questions / Blockers
|
||||
|
||||
- Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
|
||||
- Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
|
||||
- The standard service was last restarted before commits `3062ed5`, `b5f5847`, `cc09506`, `336ca6e`, `e4fd916`, `d09b303`, and the 2026-09-07 integration commits; its runtime schema, extension, account UI, queue/routing, owner force-delete, roster normalization, administrator isolation, and dashboard behavior must not be represented as the newly integrated repository state until an authorized rollout.
|
||||
- The standard service was last restarted before commits `3062ed5`, `b5f5847`, `cc09506`, `336ca6e`, `e4fd916`, `d09b303`, the 2026-09-07 integration commits, and migrations 022–023; its runtime schema, extension, account UI, queue/routing, owner force-delete, roster normalization, shared-child batch route, administrator isolation, dashboard, and Webhook behavior must not be represented as the newly integrated repository state until an authorized rollout.
|
||||
- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering unique-node exact ERP identity, mismatched login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator task-data-plane denial, and both manual and automatic channel work.
|
||||
- Administrator migration 021 and the team-lead dashboard's assigned manual/AgentBus scope have repository and disposable-database evidence but no deployed multi-role browser canary.
|
||||
- The exact user-supplied workbook could not be replayed after the roster `v1.4.0` fix because its temporary shared-pasteboard file expired; synthetic regressions cover ignored populated identity-card and ordinary extra columns without preserving passenger data.
|
||||
- Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
|
||||
- A live internal AgentBus attachment verification remains separately unperformed.
|
||||
- Proactive team-lead `task.summary` delivery has repository, mock-WebSocket, and disposable-PostgreSQL evidence but no deployed AgentBus/WeChat canary; automatic current-owner route resolution remains unverified in the live bridge.
|
||||
- Shared-child batch creation has parser/browser/static regression evidence but no authorized current-version ERP write verification.
|
||||
- External leader-summary delivery has repository, fake-sender, and disposable-PostgreSQL evidence but no deployed gateway/WeChat canary; an uncertain live attempt must not be retried automatically.
|
||||
|
||||
## Risky Areas
|
||||
|
||||
@@ -106,9 +114,10 @@ Operate the repository's current extension `0.5.169`, Skill/business-instruction
|
||||
- Account role changes, migration-021 principal cleanup/triggers, administrator task-plane denial, session revocation, creator-based task-route revocation, cross-source assignee-based dashboard projection, and encrypted input audit are security-sensitive boundaries.
|
||||
- AgentBus channel ownership, immutable task assignment, unique-node exact expected ERP identity, browser-worker freshness/failover, and administrator management/task-plane separation are security- and write-safety-sensitive boundaries.
|
||||
- Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
|
||||
- Team-lead automatic route derivation, stale-owner invalidation, encrypted projection/delivery rows, at-least-once stable-frame deduplication, privacy allowlisting, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
|
||||
- Shared-child complete target enumeration, exact parent binding, ordered multi-write execution, per-parent receipts, stop-on-first-non-success behavior, and write uncertainty are duplicate-write-sensitive boundaries.
|
||||
- External Webhook configuration secrecy, future-only revisions, encrypted projection/delivery rows, one-attempt lease handling, privacy allowlisting, accepted-versus-delivered wording, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
|
||||
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-09-07
|
||||
2026-09-09
|
||||
@@ -14,3 +14,6 @@ This is integrated history. Feature tasks write only their task-scoped records;
|
||||
| 2026-09-07 | Team-lead AgentBus task summaries | Integrated default-off future-only summaries for other non-admin employees' manual/AgentBus outcomes through a separate encrypted outbox and verified proactive target, without changing task or ERP authority. | [Integration task](tasks/20260907-integrate-leader-summaries-84c1d7ea.md) |
|
||||
| 2026-09-07 | Automatic leader-summary routing correction | Replaced the duplicate administrator subscription form with role-driven activation and current-owner AgentBus route resolution while retaining future-only privacy and delivery boundaries. | [Integration task](tasks/20260907-integrate-auto-leader-summary-9a4d2c61.md) |
|
||||
| 2026-09-07 | Exact identity, roster selection, leader oversight, and administrator isolation | Integrated extension `0.5.169`, roster normalizer `v1.4.0`/Skill `0.5.126`, assigned manual+AgentBus leadership reporting, AUTH-004, and migration 021; repository/runtime rollout remains separate. | [Integration task](tasks/20260907-integrate-all-changes-9d2e7c41.md) |
|
||||
| 2026-09-08 | Shared-child batch creation | Added the nineteenth machine route as Program-only, complete pre-write parent enumeration, ordered stop-on-first-non-success execution, parser `v1.0.7`, migration 022, and extension `0.5.170`. | [Feature task](tasks/20260908-shared-child-batch-create-4e7c2a91.md) |
|
||||
| 2026-09-08 | Leader-summary external Webhook | Replaced only the AgentBus summary transport with an organization-level encrypted one-attempt Webhook outbox, migration 023, strict accepted-versus-delivered semantics, and AUTH-005. | [Feature task](tasks/20260908-leader-webhook-api-7c4e9a12.md) |
|
||||
| 2026-09-08 | Repository-local project-document governance | Removed the deleted external Skill/task-registry dependency while preserving Git worktree safety checks and `.project-docs/` as canonical memory. | [Integration task](tasks/20260908-remove-maintain-project-docs-requirement-6d8a31f2.md) |
|
||||
@@ -0,0 +1,61 @@
|
||||
# Task: Integrate pending changes, push main, and provide migration SQL
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260909-integrate-pending-push-sql-4c8e2a71
|
||||
- Mode: Integration
|
||||
- Branch: main
|
||||
- Worktree: /Users/inmanx/Documents/lwltAPI
|
||||
- Base commit: 515b545b32fcbb30311b56c5b90a36f3d3834d95
|
||||
- Owner: codex
|
||||
- Status: Ready for push verification
|
||||
|
||||
## Scope
|
||||
|
||||
- Preserve and commit the known completed repository-governance changes already present on `main`.
|
||||
- Integrate ready feature tasks `20260908-shared-child-batch-create-4e7c2a91` and `20260908-leader-webhook-api-7c4e9a12`, including migrations 022 and 023.
|
||||
- Resolve shared-file conflicts semantically, promote accepted outcomes into canonical project memory, run repository/release verification, and push `main` to `origin/main` without force.
|
||||
- Provide the exact database migration SQL files needed for the integrated application.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- The user explicitly authorized merging all pending changes into the main branch and pushing the repository.
|
||||
- Treat completed, task-attributed work as merge candidates; do not merge historical diagnosis, rollback, superseded, or patch-equivalent branches merely because their tips are not ancestors of `main`.
|
||||
- Preserve the unrelated in-progress runtime record `20260902-migrate-restart-confirmed-4f8c2a71.md` and every unknown dirty worktree without resetting, cleaning, stashing, deleting, or rewriting it.
|
||||
- Keep the shared-child batch route Program-only and preserve its enumerate-before-write, deterministic ordering, stop-on-first-non-success, and no-automatic-retry boundaries.
|
||||
- Replace only leader-summary transport with the fixed organization-level external Webhook outbox; keep normal AgentBus task intake/replies and ERP execution isolated and unchanged.
|
||||
- Do not read `.env`, run production migrations, deploy/restart services, reload extensions, access ERP, mutate runtime tasks/accounts/channels, or send an external Webhook message.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Committed the completed repository-governance update as `bb115a3` and preserved the unrelated in-progress runtime/reload record as the separate documentation commit `301890d`.
|
||||
- Created source commits `6ac90f8` for shared-child batch creation and `be17f6c` for leader-summary Webhook delivery in their isolated feature worktrees.
|
||||
- Integrated the source branches into `main` as merge commits `0d20544` and `295409b`. The only conflicts were shared migration-version documentation and assertions; resolution retains migration 022 before 023, requires schema version 023, and preserves both feature semantics.
|
||||
- Promoted the integrated state to 19 total machine routes, 18 external-Agent routes, three Program-only routes, Program parser `v1.0.7`, extension `0.5.170`, and required migrations through `023_leader_summary_webhook_delivery`.
|
||||
- Accepted AUTH-005. Organization-level leader summaries now use protected external Webhook configuration, a separate future-only encrypted outbox, strict accepted-versus-delivered terminology, and terminal one-attempt rejection/uncertainty behavior without changing normal employee AgentBus/task/ERP paths.
|
||||
- Reconciled current state, decisions, architecture, data flow, business rules, glossary, evidence, commitments, task history, success criteria, and the Agent/Skill business-registry boundary.
|
||||
- Audited linked worktrees and branches. No other new ready-for-integration product task remained; historical diagnosis, rollback, superseded, patch-equivalent, and unrelated dirty worktrees were preserved without modification.
|
||||
- The exact new database migration SQL remains in `control-plane/migrations/022_shared_child_order_batch_create.sql` and `control-plane/migrations/023_leader_summary_webhook_delivery.sql`, in that required order.
|
||||
|
||||
## Verification
|
||||
|
||||
- Initial `git fetch origin` showed local `main` and `origin/main` both at `515b545b32fcbb30311b56c5b90a36f3d3834d95` before this integration.
|
||||
- `git diff --check` and active-tree conflict-marker scan passed.
|
||||
- Direct syntax checks passed for the platform application and changed extension JavaScript entrypoints.
|
||||
- `node --run check:repo` passed, 10/10, including exact release set, hashes, extension/source package equality, Markdown links, and repository governance.
|
||||
- `node --run check` passed.
|
||||
- `node --run test:control-plane` passed, 183/183.
|
||||
- `node --run test:legacy` passed, 277/277.
|
||||
- `node --run build` passed.
|
||||
- Source-task disposable PostgreSQL evidence was reviewed: migration 022 constraint expansion and migration 023 legacy-row retirement/new encrypted outbox both passed independently before integration; no production database or network endpoint was touched here.
|
||||
- Remote push and final remote-tip verification are pending the integration commit.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Back up the target database and run migrations through 023 before deploying the integrated control plane.
|
||||
- Configure the complete provider-confirmed Webhook URL and real token only in the protected runtime environment; a live send, deployment, restart, extension reload, route grant, or ERP write remains separately authorized.
|
||||
- Load extension `0.5.170` and grant the new Program-only shared-child batch route only to intended non-administrator accounts before a bounded live acceptance test.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None; this Integration task will reconcile accepted source outcomes directly.
|
||||
Reference in new issue
Block a user