chore: finalize integrated release baseline

This commit is contained in:
inman committed 2026-09-07 21:24:15 +08:00
1 parent fd39347603
commit d5465e9c0d
36 files changed
+324 -92

No files matched your search

+8 -8
View File
@@ -4,9 +4,9 @@
| Flow | Source | Destination | Notes |
|---|---|---|---|
| Business directive | Manual workbench or AgentBus | Route orchestrator | Manual input uses the signed-in account; AgentBus input uses the channel's bound employee account and its route allowlist. |
| Business directive | Employee manual workbench or AgentBus | Route orchestrator | Manual input uses a signed-in team lead/user; AgentBus input uses the channel's bound employee account and its route allowlist. Administrators cannot enter this flow. |
| AgentBus execution ownership | Enabled channel | Employee account → immutable task assignee → executable feed | One account owns at most one channel; unbound channels and unassigned historical tasks stay non-executable. |
| Manual account authorization | Signed-in account plus resolved business route | Intake and task-transition gates | Administrators hold all routes; team leads/users require explicit grants and unresolved routes fail closed |
| Manual account authorization | Signed-in employee plus resolved business route | Intake and task-transition gates | Team leads/users require explicit grants; administrators manage grants but hold none, and denied or unresolved routes fail closed. |
| Parsing | Route orchestrator | AI Skill or deterministic Program parser | AI/Shadow/Auto/Program mode is frozen per task |
| Operation | Parser | Control-plane task and confirmation | Must validate against the same final contract |
| ERP execution | Confirmed task | Chrome extension and logged-in ERP page | Requires unique object, page identity, ownership, and write preflight |
@@ -15,25 +15,25 @@
| WeChat roster attachment | Strict transport envelope plus one structured `payload.attachments[]` entry | Existing `awaiting_attachment` task | Explicit conversation ID wins; otherwise strict `Conversation:` supplies the fallback. Placeholder text alone never creates a task. |
| Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. |
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Display-only summaries plus explicit filters drive an aggregate-first task/person/input/output/time/type/completion view; list reads are bounded to one read-only connection and hydrate full details only for the current page. |
| Platform operations oversight | Durably assigned manual/AgentBus task, encrypted instruction history, and readable outcome | Team-lead-only leadership projection | Immutable assignee is the employee dimension; unassigned historical AgentBus rows are excluded. Display-only summaries plus explicit filters drive an aggregate-first task/person/input/output/time/type/completion view, with bounded list reads and page-only detail hydration. |
| Team-lead task summary | Future stable manual/AgentBus task outcome for another non-admin employee | Role/channel reconciler → current-owner encrypted route → separate durable outbox → leader-owned AgentBus channel → WeChat | Automatic for active team leads with a usable route; employee replies are sent first, summary frames use stable IDs and explicit routing with no `reply_to`, and delivery failure never changes task state. |
| Browser worker selection | Immutable task assignee | One fresh account-bound browser connection | The heartbeat must match the account's expected ERP identity; a second fresh worker or identity mismatch is non-executable, with failover only after staleness. |
| Browser worker selection | Immutable task assignee | One fresh account-bound browser connection | The heartbeat must prove the expected ERP identity from one unique login node by normalized exact equality; missing, duplicate, blank, substring-only, or mismatched identity is non-executable, with failover only after staleness. |
| Account-scoped ERP queue | Confirmed task assignee | Assigned account's browser worker | Organization-plus-account advisory locking preserves FIFO and at most one active execution for that account; another account's active, queued, stale, or uncertain work is outside this queue. |
| Executable event and result routing | Immutable task assignee | Matching authenticated platform page and plugin | SSE history/live events, claims, plugin results, and browser cleanup commands never use administrator-wide visibility and fail closed when the authenticated account is not the assignee. |
| Task removal | Authorized operator | Archive/restore or permanent force delete | Archive/restore remains reversible and state-gated. Explicit force delete has no lifecycle-state gate, removes task-owned platform records atomically, retains a minimal deletion audit marker, and performs post-commit artifact/plugin cleanup best effort. |
| Executable event and result routing | Immutable task assignee | Matching authenticated employee page and plugin | Task APIs, SSE history/live events, claims, plugin results, and browser cleanup commands require a team-lead/user session matching the assignee; administrators are rejected before task handling. |
| Task removal | Owning employee | Archive/restore or permanent force delete | Archive/restore remains reversible and state-gated. Explicit owner force delete has no lifecycle-state gate, removes task-owned platform records atomically, retains a minimal deletion audit marker, and performs post-commit artifact/plugin cleanup best effort. Administrators cannot invoke either path. |
| Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF |
| Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames |
## State Ownership
- PostgreSQL owns durable control-plane account, role, expected ERP identity, task-route grant, AgentBus channel owner, immutable task assignee, account-scoped queue/lease state, browser worker, session, confirmation, audit, archive, outcome state, and revisioned team-lead notification subscriptions/deliveries. Notification destinations and payloads remain encrypted at rest. A force-deleted task no longer exists in task state; only its minimal non-content deletion audit marker remains, while an already delivered external message cannot be retracted.
- PostgreSQL owns durable control-plane account, management/task-plane role constraints, exact expected ERP identity, employee task-route grant, AgentBus channel owner, immutable task assignee, account-scoped queue/lease state, browser worker, session, confirmation, audit, archive, outcome state, and revisioned team-lead notification subscriptions/deliveries. Migration 021 removes and rejects administrator task principals. Notification destinations and payloads remain encrypted at rest. A force-deleted task no longer exists in task state; only its minimal non-content deletion audit marker remains, while an already delivered external message cannot be retracted.
- Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted.
- Chrome extension local state is bounded execution/reconciliation support, not canonical business history.
- `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection.
## External Interfaces
- Operator workbench at the control-plane service.
- Employee task workbench and separate administrator management pages at the control-plane service.
- AgentBus WebSocket channels and attachment delivery.
- Logged-in ERP browser pages under the Chrome extension host permissions.
- PostgreSQL, OSS, deployment gateway, and authenticated artifact download.
@@ -2,7 +2,7 @@
## Current Architecture
Authenticated manual or account-bound AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns account, channel owner, immutable task assignee, account-scoped execution queue, browser worker, session, task-type authorization, confirmation, audit, reversible archive, explicit force-delete behavior, and role-driven automatic team-lead task-summary projection. The Chrome extension verifies the expected ERP account, resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
Authenticated employee manual or account-bound AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane separates the administrator management plane from the employee task data plane and owns account, channel owner, immutable task assignee, account-scoped execution queue, browser worker, session, task-type authorization, confirmation, audit, reversible archive, explicit owner force-delete behavior, and role-driven automatic team-lead task-summary projection. The Chrome extension verifies the expected ERP account from one unique login identity node by normalized exact equality, resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
## Main Components
@@ -10,7 +10,7 @@ Authenticated manual or account-bound AgentBus input is routed through task-scop
|---|---|---|
| `agent设计规范/` | Agent Prompt, five parsing Skills, business templates, business registry, and stable fixtures | Editable source for business semantics; not runtime evidence |
| `schemas/` and `mappings/` | Parse-state, execution-state, ERP form, field, and lifecycle contracts | Current contracts only |
| `control-plane/` | Task/session persistence, parser orchestration, confirmation, audit, AgentBus channel ownership, task assignment, browser workers, attachments, receipts, encrypted leader-summary projection/outbox, and structured diagnostics | TypeScript source; build output goes to `.build/` |
| `control-plane/` | Management/task-plane authorization, task/session persistence, parser orchestration, confirmation, audit, AgentBus channel ownership, task assignment, browser workers, attachments, receipts, encrypted leader-summary projection/outbox, and structured diagnostics | TypeScript source; build output goes to `.build/`; migration 021 enforces administrator isolation |
| `LianSyn-platform/` | Operator workbench and external parser adapter | Source and UI, not local task output |
| `chrome-extension/ltjt-order-assistant/` | Logged-in ERP resolution, preflight, native execution, response handling, requery, and dormant idle/reload safety handlers | Current server/platform does not trigger automatic updates; any code change requires synchronized versioned release updates |
| `dist/` | Versioned current deliverables and machine-readable release manifest | Not a compilation directory |
@@ -21,19 +21,19 @@ Authenticated manual or account-bound AgentBus input is routed through task-scop
- AI/Program parsing and ERP resolution/execution share the final operation contract but do not share authority.
- Platform envelope fields such as task ID, account identity, authorization revision, session, parser decision, confirmation, transport, and audit never enter the business operation.
- The product is one fixed internal organization scope with three roles. Administrators manage accounts, channels, and all 18 manual routes; team leads and users are owner-scoped for normal tasks and require explicit per-route grants. Team leads additionally receive a dedicated read-only, manual-task-only platform-operations dashboard. Administrator-wide visibility does not permit executing another account's assigned ERP work.
- The product is one fixed internal organization scope with three roles. Administrators are management-plane-only identities: they manage accounts, channels, employee route grants, parser routing, automation settings, and audit but cannot create, inspect, mutate, stream, claim, reconcile, delete, or execute business tasks. Team leads and users require explicit per-route grants and are owner-scoped for normal task operations. Team leads alone receive a dedicated organization-wide, read-only platform-operations dashboard over durably assigned manual and AgentBus tasks.
- Account passwords are accepted when non-empty without an application-level length rule. First-login forced password changes are disabled; voluntary changes and administrator resets still revoke the relevant sessions, while the historical `must_change_password` column remains compatibility-only storage.
- The leadership dashboard is an aggregate-first projection across task, person, original input, final output, time, task type, and completion state. Summary cards are display-only; filtering is explicit and defaults to all results. List reads use one bounded read-only database transaction, SQL prefiltering, selective historical-message hydration, and full detail projection only for the current 20-row page. Its drill-through stays business-facing; technical payloads, internal identifiers, machine-shaped historical input, and technical failure text remain in separate authorized audit/engineering surfaces.
- The leadership dashboard is an aggregate-first projection across assigned task, employee, original input, final output, time, task type, and completion state. It includes only durably assigned `manual` and `agentbus` work and uses immutable `assigned_user_id` for rankings, people filters, search, pagination, and detail; historical unassigned AgentBus rows are excluded. Summary cards are display-only; filtering is explicit and defaults to all results. List reads use one bounded read-only database transaction, SQL prefiltering, selective historical-message hydration, and full detail projection only for the current 20-row page. Its drill-through stays business-facing; technical payloads, internal identifiers, machine-shaped historical input, and technical failure text remain in separate authorized audit/engineering surfaces.
- Team-lead task summaries are a separate role-driven read projection, not an extension of dashboard, task, or ERP authority. An active leader with an enabled owned AgentBus channel is automatically subscribed to future stable manual and AgentBus outcomes for other non-admin employees. Routing comes from the current owner's latest valid inbound route or channel external-user reference, remains encrypted, fails closed when unavailable or stale, and never copies raw instructions, attachments, customer/traveller data, URLs, or technical errors.
- Authorization is enforced in server and service paths, not by navigation visibility. A denied or unresolved non-admin business route stops before parsing, plugin dispatch, and ERP execution; creator authorization is rechecked at confirmation and browser claim.
- Authorization is enforced in database, server, and service paths, not by navigation visibility. An administrator task-data-plane request fails before task storage or execution logic. A denied or unresolved employee business route stops before parsing, plugin dispatch, and ERP execution; assignee authorization is rechecked at confirmation and browser claim.
- Each enabled AgentBus channel owns one active non-admin employee account. Inbound work uses that account and route allowlist, persists the same account as immutable task assignee, and is returned only to that account's executable feed. A team-lead channel may additionally carry its leader's lower-priority proactive summary outbox; those rows use explicit destination/conversation routing and never become executable task traffic.
- Each employee account has one expected ERP identity and at most one fresh browser execution worker. Mismatched ERP identity, concurrent fresh workers, unbound channels, or unassigned tasks fail closed. Browser claims, active-execution checks, and confirmed FIFO are serialized per immutable task assignee, so one account cannot block or occupy another account's queue.
- Administrator-wide task visibility is a read model, not an executable feed. Task SSE history/live events, browser claims, plugin-result ingestion, and browser cleanup commands are always scoped to the authenticated account matching `assigned_user_id`, including for administrators.
- Extension `0.5.167` is the current manually published/loaded plugin baseline. It retains an idle-proof and guarded-reload message protocol, but the active control plane has no extension-release tables, ECS host mapping, OSS publication endpoint, Cloud Assistant dispatcher, or platform trigger; required migration remains 018.
- Each employee account has one expected ERP identity and at most one fresh browser execution worker. The extension accepts ERP identity only from exactly one `#Lable_UserName` login node and normalized full equality; missing, duplicate, blank, substring-only, or unrelated body-text matches fail closed without returning the observed identity. Concurrent fresh workers, unbound channels, or unassigned tasks also fail closed. Browser claims, active-execution checks, and confirmed FIFO are serialized per immutable task assignee, so one account cannot block or occupy another account's queue.
- Administrators have no task read or execution model. Task lists/details, attachments, artifacts, lifecycle mutations, SSE history/live events, browser claims, plugin-result ingestion, and browser cleanup commands require a `team_lead` or `user` session matching `assigned_user_id`; the team-lead dashboard and notification outbox remain separate read projections.
- Extension `0.5.169` is the current manually published/loaded plugin baseline, and the five Skills plus operator instruction DOCX are at `0.5.126`. The extension retains an idle-proof and guarded-reload message protocol, but the active control plane has no extension-release tables, ECS host mapping, OSS publication endpoint, Cloud Assistant dispatcher, or platform trigger; required migration is 021.
- Creator and manual input-turn attribution remain durable while business input stays encrypted at rest. Routine removal is reversible archive/restore. Separately confirmed force delete physically removes an authorized task regardless of lifecycle state, retains only a minimal non-content deletion audit marker, and cannot undo an ERP write that already occurred.
- Unknown, ambiguous, unverified, or post-write-uncertain states fail closed; automatic retries must not create duplicate writes.
- PostgreSQL is the sole required durable database/state middleware, and the production artifact provider is OSS. Redis, message queues, MongoDB, and search services are not runtime dependencies.
- Migrations through `020_leader_task_summary_notifications` must complete before the updated application starts; migration 019 remains intentionally absent after the extension-updater rollback. The current ACK topology starts with one application replica because AgentBus listeners and SSE emission are process-local; horizontal scale requires explicit coordination first.
- Migrations through `021_admin_task_data_plane_isolation` must complete before the updated application starts; migration 019 remains intentionally absent after the extension-updater rollback. Migration 021 removes legacy administrator task principals and enforces future management/task-plane separation. The current ACK topology starts with one application replica because AgentBus listeners and SSE emission are process-local; horizontal scale requires explicit coordination first.
- Operational diagnostics are privacy-safe structured JSON on stdout/stderr. Docker owns bounded rotation; repository files and a second mutable log database are not log sinks.
- In the trusted internal deployment, AgentBus roster attachment downloads may resolve to private/reserved addresses. Credential-free HTTPS, DNS resolution/pinning, redirect revalidation, size, timeout, and digest checks remain mandatory, and trusted channels/bridges own the network-input boundary.
- Canonical project memory is updated only under Integration Gate; feature tasks write only their task-scoped records.
@@ -49,6 +49,7 @@ Authenticated manual or account-bound AgentBus input is routed through task-scop
- AUTH-001
- AUTH-002
- AUTH-003
- AUTH-004
## Last Updated