chore: finalize integrated release baseline

This commit is contained in:
inman committed 2026-09-07 21:24:15 +08:00
1 parent fd39347603
commit d5465e9c0d
36 files changed
+324 -92

No files matched your search

+23 -12
View File
@@ -4,10 +4,14 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Source commit `a2378c8` from feature task `20260907-admin-task-data-plane-isolation-c3a7e91b`, integrated as `fd39347`, for the management-plane-only administrator role, task-data-plane denial at UI/HTTP/service/database boundaries, team-lead-only operations dashboard, and migration `021_admin_task_data_plane_isolation`; integration task `20260907-integrate-all-changes-9d2e7c41` accepted AUTH-004 and reconciled the administrator boundary.
- Source commit `9043ad6eda0deb2a620e1303467d1c3bd80374ed` from feature task `20260907-leader-kanban-all-members-73c9e1a4`, integrated as `03d0131`, for the assignee-based team-lead dashboard over all durably assigned manual and AgentBus tasks.
- Source commit `af9c90a3142e197493e80d74333af876c3bb947a` from feature task `20260907-ignore-extra-roster-fields-a6e4c9f2`, integrated as `9d1a6b4`, for required-field-only passenger-workbook normalization `v1.4.0`, ignored non-import columns, and synchronized Skill/business-instruction release `0.5.126`.
- Source commit `5b57df0e10fc6c6c0b2f9eeef300e36508055acc` from feature task `20260907-fix-erp-account-verification-4d8c2a71`, integrated as `8f70cba`, for unique-login-node exact ERP identity verification and synchronized extension `0.5.168`.
- Source commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` from feature task `20260907-auto-leader-summary-routing-5e8c1a73` for automatic role-driven team-lead summaries, current-owner AgentBus route learning/fallback, read-only status UI, stale-route cancellation, and removal of the manual mutation endpoint; integration task `20260907-integrate-auto-leader-summary-9a4d2c61` revised AUTH-003 and canonical notification behavior.
- Source commit `1a3ab63` from feature task `20260907-implement-leader-agentbus-copy-b7e31a94` for default-off team-lead task summaries over future manual and AgentBus outcomes, a separate encrypted/revisioned outbox, verified proactive AgentBus routing, administrator configuration/health UI, and migration 020; integration task `20260907-integrate-leader-summaries-84c1d7ea` accepted AUTH-003 and canonical notification boundaries.
- Correction commit `fe1cc2cddc29e4dead81e53c16d31bb71493602d` from integration task `20260903-backup-revert-extension-update-c71a4e92` preserved the complete former `0.5.167`/migration-019 stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed the central private-OSS/ECS automatic-update service architecture without rewriting history, and retained the exact Chrome extension `0.5.167` source/package on the active main line with migration 018.
- Merge commit `3224758` and integration task `20260903-finalize-extension-update-a6c4e192` remain historical records of the full-stack extension-update design. Only the plugin `0.5.167` release, adaptive entry readiness, and dormant plugin-side idle/reload safeguards remain active; the server orchestration is preserved on the backup branch only.
- Correction commit `fe1cc2cddc29e4dead81e53c16d31bb71493602d` from integration task `20260903-backup-revert-extension-update-c71a4e92` preserved the complete former `0.5.167`/migration-019 stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed the central private-OSS/ECS automatic-update service architecture without rewriting history, and retained exact extension `0.5.167` with migration 018 at that correction point.
- Merge commit `3224758` and integration task `20260903-finalize-extension-update-a6c4e192` remain historical records of the full-stack extension-update design. Adaptive entry readiness and dormant plugin-side idle/reload safeguards remain in the later `0.5.169` release; server orchestration is preserved on the backup branch only.
- Commit `c4c469f4441d744627af2d34abe693b6783e833c` for the independently advanced remote deployment/extension line.
- Commit `cd45ce17d0fcd25f7fa89ab9f8a391d3e904ecdf` for WeChat attachment correlation and privacy-safe server diagnostics.
- Commit `161f90d09d6ad1368973b1a85d51059059495223` for trusted-intranet attachment compatibility and canonical reconciliation.
@@ -35,7 +39,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Current Focus
Operate the repository's current `0.5.167` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator or team-lead visibility never enters another account's executable event/result path. Active team leads with usable owned AgentBus routes automatically receive future privacy-bounded summaries; migration 020, manual extension reload, guarded product-search retry, service rollout, and any live AgentBus/WeChat canary remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
Operate the repository's current extension `0.5.169`, Skill/business-instruction `0.5.126`, roster normalizer `v1.4.0`, and migration-021 fixed-scope account model safely. Administrators manage accounts, channels, employee grants, parser routing, automation settings, and audit but never enter the task data plane. Team leads/users own normal task operations through immutable assignment; same-account work remains FIFO and single-active while distinct accounts are independent. Team leads alone receive the read-only assignee-based dashboard over assigned manual and AgentBus work and automatic future privacy-bounded summaries through usable owned AgentBus routes. Migration 021, manual extension reload, guarded product-search retry, service rollout, and any live AgentBus/WeChat canary remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
## Recently Completed
@@ -59,20 +63,25 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- 2026-09-02: Integrated extension `0.5.165`: scatter-plan creation and independent batch-order creation now try loaded product candidates, then the form's native non-empty `S_chanpinming` search, and finally one bounded empty-query compatibility reload. A user-authorized search-only ERP check returned exactly one target row in both forms without selecting or saving it; zero or multiple local matches continue to fail closed.
- 2026-09-03: Accepted AUTH-002 and integrated account-scoped ERP queues. Each immutable assignee now owns one FIFO/single-active claim partition, different accounts no longer block one another, and executable SSE/results/cleanup commands are owner-only even when an administrator is signed in.
- 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back.
- 2026-09-03: Backed up the complete adaptive-readiness and central extension-update stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, then removed the central OSS/ECS update service and migration 019 from `main` with normal history-preserving commits. After correcting an initially over-broad rollback, the active repository retains the exact extension `0.5.167` source/package and uses migration 018; the removed server architecture was never deployed by these tasks.
- 2026-09-03: Backed up the complete adaptive-readiness and central extension-update stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, then removed the central OSS/ECS update service and migration 019 from `main` with normal history-preserving commits. At that rollback point the repository retained exact extension `0.5.167` with migration 018; the plugin and schema later advanced independently without restoring the removed server architecture.
- 2026-09-07: Integrated AUTH-003 and migration 020 for administrator-managed team-lead task summaries. Future stable manual/AgentBus outcomes for other non-admin employees project into a separate encrypted outbox and use the leader's verified AgentBus/WeChat target without changing task ownership, employee reply priority, or ERP execution authority.
- 2026-09-07: Revised AUTH-003 so active team-lead identity plus an enabled owned AgentBus channel automatically activates both-source summaries. Routing uses only the current owner's latest valid inbound route or the channel external-user reference; channel rebind clears stale identity data, the settings API/UI is read-only, and all prior privacy, future-only, revision, priority, and no-ERP-authority boundaries remain.
- 2026-09-07: Advanced the synchronized Chrome extension to `0.5.168`; expected ERP identity is accepted only from one unique login account node with normalized exact equality, never from whole-page substring matching.
- 2026-09-07: Advanced the synchronized Chrome extension to `0.5.169`; uncertain ERP writes now direct manual read-only verification to the immutable task owner instead of an administrator who has no task-data-plane access.
- 2026-09-07: Advanced passenger-workbook normalization to `v1.4.0` and the five Skills plus operator instruction DOCX to `0.5.126`. Only required ERP source semantics participate in extraction; ordinary non-import columns are ignored and excluded from canonical TSV while active-content safety remains workbook-wide.
- 2026-09-07: Expanded the team-lead operations dashboard to every durably assigned manual and AgentBus task using immutable assignment as the employee dimension; unassigned historical AgentBus rows remain excluded.
- 2026-09-07: Accepted AUTH-004 and migration 021. Administrators are management-plane-only, cannot access task APIs, browser workers, task routes, dashboards, summaries, or task principals, and role promotion removes legacy executable bindings.
## In Progress
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
- Required migrations through `020_leader_task_summary_notifications`, employee ERP identities/channel bindings, extension `0.5.167`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/automatic-notification runtime changes have not been applied to or restarted on the standard service in this integration task. No live automatic team-lead delivery canary was performed.
- Required migrations through `021_admin_task_data_plane_isolation`, employee ERP identities/channel bindings, extension `0.5.169`, account-scoped queue/routing changes, owner force-delete behavior, roster `v1.4.0`, and the merged dashboard/automatic-notification/administrator-isolation runtime changes have not been applied to or restarted on the standard service in this integration task. No live automatic team-lead delivery canary was performed.
## Next Recommended Steps
1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply all migrations through 020, restart the control plane, manually load extension `0.5.167`, verify its runtime handshake, configure employee ERP identities and channel bindings, and run the multi-cloud-PC/identity/failover plus account-queue matrix before production assurance.
2. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes.
3. In the same authorized staging window, verify that an administrator receives no employee executable events/results, then force-delete disposable waiting and active employee tasks and confirm database absence plus cleanup only in the owning employee plugin.
1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply all migrations through 021, deploy the control plane and platform assets together, restart the service, manually load extension `0.5.169`, and verify readiness plus the exact-account handshake.
2. Through the administrator management UI, create representative team-lead and ordinary accounts, assign narrow task grants and channels, and verify that administrator task pages/APIs/workers fail closed while employee routes remain usable.
3. With separate team-lead and employee sessions, verify owner isolation, both-source leadership-dashboard reads, same-account FIFO, cross-account independence, mismatched ERP identity, worker conflict/failover, and owner-performed waiting/active force deletion without unintended ERP writes.
4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
6. With explicit external-send authorization, use one controlled team-lead channel to verify automatic current-owner route resolution, proactive `task.summary` handling, and stable-frame deduplication through AgentBus/WeChat, then observe one manual and one AgentBus task before wider assurance.
@@ -81,8 +90,10 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
- Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
- The standard service was last restarted before commits `3062ed5`, `b5f5847`, `cc09506`, `336ca6e`, `e4fd916`, and `d09b303`; its runtime schema, extension, account UI, queue/routing, force-delete, and dashboard behavior must not be represented as the newly integrated repository state until an authorized rollout.
- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering mismatched ERP login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator executable-feed isolation, and both manual and automatic channel work.
- The standard service was last restarted before commits `3062ed5`, `b5f5847`, `cc09506`, `336ca6e`, `e4fd916`, `d09b303`, and the 2026-09-07 integration commits; its runtime schema, extension, account UI, queue/routing, owner force-delete, roster normalization, administrator isolation, and dashboard behavior must not be represented as the newly integrated repository state until an authorized rollout.
- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering unique-node exact ERP identity, mismatched login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator task-data-plane denial, and both manual and automatic channel work.
- Administrator migration 021 and the team-lead dashboard's assigned manual/AgentBus scope have repository and disposable-database evidence but no deployed multi-role browser canary.
- The exact user-supplied workbook could not be replayed after the roster `v1.4.0` fix because its temporary shared-pasteboard file expired; synthetic regressions cover ignored populated identity-card and ordinary extra columns without preserving passenger data.
- Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
- A live internal AgentBus attachment verification remains separately unperformed.
- Proactive team-lead `task.summary` delivery has repository, mock-WebSocket, and disposable-PostgreSQL evidence but no deployed AgentBus/WeChat canary; automatic current-owner route resolution remains unverified in the live bridge.
@@ -92,8 +103,8 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- Any ERP write, uncertain post-write state, automatic retry, or scope widening.
- Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity.
- AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts.
- Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
- AgentBus channel ownership, immutable task assignment, expected ERP identity, browser-worker freshness/failover, and administrator non-execution are security- and write-safety-sensitive boundaries.
- Account role changes, migration-021 principal cleanup/triggers, administrator task-plane denial, session revocation, creator-based task-route revocation, cross-source assignee-based dashboard projection, and encrypted input audit are security-sensitive boundaries.
- AgentBus channel ownership, immutable task assignment, unique-node exact expected ERP identity, browser-worker freshness/failover, and administrator management/task-plane separation are security- and write-safety-sensitive boundaries.
- Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
- Team-lead automatic route derivation, stale-owner invalidation, encrypted projection/delivery rows, at-least-once stable-frame deduplication, privacy allowlisting, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
+1
View File
@@ -13,3 +13,4 @@ This is integrated history. Feature tasks write only their task-scoped records;
| 2026-09-03 | Extension-update iteration backup and scoped rollback | Preserved exact commit `b2e33e2` on remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed migration 019 and server-side automatic updating, and retained extension `0.5.167` plus migration 018 through non-force commits. | [Rollback task](tasks/20260903-backup-revert-extension-update-c71a4e92.md) |
| 2026-09-07 | Team-lead AgentBus task summaries | Integrated default-off future-only summaries for other non-admin employees' manual/AgentBus outcomes through a separate encrypted outbox and verified proactive target, without changing task or ERP authority. | [Integration task](tasks/20260907-integrate-leader-summaries-84c1d7ea.md) |
| 2026-09-07 | Automatic leader-summary routing correction | Replaced the duplicate administrator subscription form with role-driven activation and current-owner AgentBus route resolution while retaining future-only privacy and delivery boundaries. | [Integration task](tasks/20260907-integrate-auto-leader-summary-9a4d2c61.md) |
| 2026-09-07 | Exact identity, roster selection, leader oversight, and administrator isolation | Integrated extension `0.5.169`, roster normalizer `v1.4.0`/Skill `0.5.126`, assigned manual+AgentBus leadership reporting, AUTH-004, and migration 021; repository/runtime rollout remains separate. | [Integration task](tasks/20260907-integrate-all-changes-9d2e7c41.md) |
@@ -0,0 +1,61 @@
# Task: Integrate all pending changes and push main
## Identity
- Task ID: 20260907-integrate-all-changes-9d2e7c41
- Mode: Integration
- Branch: codex/20260907-integrate-all-changes-9d2e7c41-integrate-all-changes
- Worktree: /Users/inmanx/Documents/lwltAPI-integrate-all-changes-9d2e7c41
- Base commit: 6bdaa2a6e6b6006241ee324ad0e8736f79bae7fd
- Owner: codex
- Status: In Progress
## Scope
- Audit every local branch and linked worktree against current `main` and `origin/main`, preserving occupied or unrelated dirty worktrees.
- Integrate source commits `5b57df0`, `af9c90a`, `9043ad6`, and `a2378c8` for exact ERP identity, required-field-only roster normalization, cross-source leader dashboard visibility, and administrator task-data-plane isolation.
- Resolve overlapping control-plane documentation, dashboard query, authorization, release, and test changes semantically.
- Promote the accepted source outcomes into canonical project memory, run repository and artifact verification, then push the integrated tree to `origin/main` without force.
## Intent And Constraints
- The user explicitly authorized integrating all pending repository changes into the main branch and pushing the result.
- Preserve `AUTH-002` account-scoped execution and `AUTH-003` leader-summary privacy while applying the user-confirmed replacement of administrator task visibility with a management-plane-only administrator role.
- Keep the leadership dashboard read-only and team-lead-only, but include every durably assigned `manual` and `agentbus` task and use immutable assignment as the employee dimension.
- Preserve exact-account behavior from extension `0.5.168`, then publish synchronized extension `0.5.169` so uncertain-write recovery names the immutable task owner; preserve Skill/business-instruction `0.5.126`, roster normalizer `v1.4.0`, and required migration `021` as current baselines.
- Do not merge historical diagnosis, recovery, rollback, superseded, or patch-equivalent branches merely because their tips are not ancestors of `main`.
- Do not modify source task records. The source diffs are applied without their task-owned records; integration progress is recorded only in this task record and canonical documents.
- Do not read `.env`, run production migrations, deploy or restart services, reload extensions, access or write ERP, mutate runtime tasks/accounts/channels, or send external messages.
## Outcome
- Audited every local branch and linked worktree against `main`/`origin/main`. Integrated the four distinct pending product changes and left patch-equivalent, superseded, diagnostic, recovery, and rollback branches out of the mainline.
- Recovered the known administrator-isolation dirty worktree under formal task ownership, committed it as source commit `a2378c8`, and preserved the unrelated occupied local `main` worktree without stashing, resetting, cleaning, or modifying it.
- Applied the source outcomes as integration commits `8f70cba` (exact ERP identity), `9d1a6b4` (required-field-only roster import), `03d0131` (all durably assigned team-lead dashboard tasks), and `fd39347` (administrator management-plane isolation). The overlapping `control-plane/README.md` conflict was resolved semantically.
- Accepted `AUTH-004` and reconciled authorization, architecture, business rules, evidence, commitments, and current-state memory around management-plane-only administrators, immutable task ownership, and team-lead-only read access.
- Advanced the synchronized Chrome extension baseline to `0.5.169`, changed uncertain-write guidance to require the task-owning account, archived the superseded `0.5.168` release, and created `dist/ltjt-order-assistant-0.5.169.zip` with SHA-256 `00ad06a1640d36cfe7df8c9e52d677131793c70d493392b551b7ecbd965c854b`.
- Preserved Skill/business-instruction version `0.5.126`, roster normalizer `ltjt-passenger-roster-workbook-v1.4.0`, and required schema migration `021_admin_task_data_plane_isolation`.
- Source task records remained untouched; all integration-specific decisions and verification are recorded here. The prepared integration tree still requires its final non-force push and remote-head verification.
## Verification
- Passed focused source regressions: exact ERP identity `3/3`, account authorization plus roster normalization `27/27`, and team-lead dashboard `5/5`.
- Passed `node --run check:repo` (`10/10`) and `node --run check`.
- Passed `node --run test:control-plane` (`180/180`) and `node --run test:legacy` (`273/273`). The legacy suite was rerun successfully after correcting its expected synchronized extension version.
- Passed `node --run build` and direct JavaScript syntax checks for the changed extension/runtime files.
- Passed final focused static regressions for control-plane authorization and owner-confirmation wording (`55/55`) and lifecycle/release contracts (`59/59`).
- Passed all five official Skill validators.
- Passed extension ZIP integrity, manifest SHA-256 verification, and exact package/source file-set comparison for `0.5.169`.
- Rendered all 12 pages of `dist/老挝联泰AI指令表-0.5.126.docx` with the bundled document renderer and configured Chinese fonts; visual inspection found no missing glyphs, clipping, overlap, or broken layout.
- Passed `git diff --check`, JSON parsing, conflict-marker scanning, and the final active-tree scan for stale administrator-confirmation wording; the only matches are negative regression assertions.
- Passed final `check_project_docs.py` and task-scoped `check_doc_drift.py`; remote push verification remains pending the closing task-record update.
## Follow-ups
- Apply migration `021_admin_task_data_plane_isolation`, deploy/restart services, distribute/reload extension `0.5.169`, and perform live ERP/runtime verification only in a separately authorized rollout.
- Exact customer-workbook validation remains unavailable in this repository; required-field-only behavior is covered by synthetic workbook regressions.
- No additional distinct merge candidate remained after the branch/worktree audit.
## Promotion Candidates
- None recorded.