docs: integrate account authorization model
This commit is contained in:
1 parent
191c1a1aad
commit
ffda0d5f3f
6 files changed
+108
-6
No files matched your search
@@ -5,6 +5,7 @@
|
||||
| Flow | Source | Destination | Notes |
|
||||
|---|---|---|---|
|
||||
| Business directive | Manual workbench or AgentBus | Route orchestrator | Source changes input/reply adaptation, not parser or confirmation policy |
|
||||
| Manual account authorization | Signed-in account plus resolved business route | Intake and task-transition gates | Administrators hold all routes; team leads/users require explicit grants and unresolved routes fail closed |
|
||||
| Parsing | Route orchestrator | AI Skill or deterministic Program parser | AI/Shadow/Auto/Program mode is frozen per task |
|
||||
| Operation | Parser | Control-plane task and confirmation | Must validate against the same final contract |
|
||||
| ERP execution | Confirmed task | Chrome extension and logged-in ERP page | Requires unique object, page identity, ownership, and write preflight |
|
||||
@@ -13,12 +14,13 @@
|
||||
| WeChat roster attachment | Strict transport envelope plus one structured `payload.attachments[]` entry | Existing `awaiting_attachment` task | Explicit conversation ID wins; otherwise strict `Conversation:` supplies the fallback. Placeholder text alone never creates a task. |
|
||||
| Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. |
|
||||
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
|
||||
| Operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator dashboard projection | Read-only who/instruction/result view; no parser/executor payloads or task mutation authority |
|
||||
| Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF |
|
||||
| Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames |
|
||||
|
||||
## State Ownership
|
||||
|
||||
- PostgreSQL owns durable control-plane task, session, confirmation, channel, audit, and outcome state.
|
||||
- PostgreSQL owns durable control-plane account, role, task-route grant, task, session, confirmation, channel, audit, archive, and outcome state.
|
||||
- Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted.
|
||||
- Chrome extension local state is bounded execution/reconciliation support, not canonical business history.
|
||||
- `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection.
|
||||
@@ -32,4 +34,4 @@
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-08-31
|
||||
2026-09-01
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
## Current Architecture
|
||||
|
||||
Manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns task/session/confirmation/audit state, and the Chrome extension resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
|
||||
Authenticated manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns account, task, session, task-type authorization, confirmation, audit, and archive state, and the Chrome extension resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
|
||||
|
||||
## Main Components
|
||||
|
||||
@@ -20,7 +20,10 @@ Manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program or
|
||||
## Important Boundaries
|
||||
|
||||
- AI/Program parsing and ERP resolution/execution share the final operation contract but do not share authority.
|
||||
- Platform envelope fields such as task ID, session, parser decision, confirmation, transport, and audit never enter the business operation.
|
||||
- Platform envelope fields such as task ID, account identity, authorization revision, session, parser decision, confirmation, transport, and audit never enter the business operation.
|
||||
- The product is one fixed internal organization scope with three roles. Administrators manage accounts and all 18 manual routes; team leads and users are owner-scoped for normal tasks and require explicit per-route grants. Team leads additionally receive a dedicated read-only, manual-task-only operations dashboard.
|
||||
- Authorization is enforced in server and service paths, not by navigation visibility. A denied or unresolved non-admin business route stops before parsing, plugin dispatch, and ERP execution; creator authorization is rechecked at confirmation and browser claim.
|
||||
- Creator and manual input-turn attribution remain durable while business input stays encrypted at rest. Routine removal is reversible archive/restore; physical purge is not an operator capability.
|
||||
- Unknown, ambiguous, unverified, or post-write-uncertain states fail closed; automatic retries must not create duplicate writes.
|
||||
- PostgreSQL is the sole required durable database/state middleware, and the production artifact provider is OSS. Redis, message queues, MongoDB, and search services are not runtime dependencies.
|
||||
- Migrations must complete before the application starts. The current ACK topology starts with one application replica because AgentBus listeners and SSE emission are process-local; horizontal scale requires explicit coordination first.
|
||||
@@ -36,7 +39,8 @@ Manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program or
|
||||
- RELEASE-001
|
||||
- SAFETY-001
|
||||
- NETWORK-001
|
||||
- AUTH-001
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-08-31
|
||||
2026-09-01
|
||||
Reference in new issue
Block a user