# Current State This file is the integrated default-branch snapshot. Feature tasks record progress in `30-worklog/tasks/{task_id}.md` and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode. ## Integrated Through - Source commit `5cbd8f1` from feature task `20260903-dashboard-refresh-no-data-b4e82f1a`, integrated as merge commit `b11dc7b`, for lightweight leadership-dashboard candidate reads that exclude full `operation` JSON, hydrate only the compact `action`/`kind`/`mode` shape needed by unresolved legacy classification, and retain complete payloads only for keyword search and current-page detail. - Integration task `20260909-business-instruction-batch-child-7e3c1a94` synchronized operator input catalog/DOCX `0.5.127` with all 19 system routes, adding the copyable `散拼团多个新增子单` entry while keeping that route Program-only and leaving the five Skills at `0.5.126`. - Source commit `be17f6c` from feature task `20260908-leader-webhook-api-7c4e9a12`, integrated as merge commit `295409b`, for organization-level external Webhook delivery of privacy-bounded leader summaries, migration `023_leader_summary_webhook_delivery`, and AUTH-005's one-attempt accepted-versus-delivered boundary. - Source commit `6ac90f8` from feature task `20260908-shared-child-batch-create-4e7c2a91`, integrated as merge commit `0d20544`, for Program-only `shared_child_order_batch_create`, parser `v1.0.7`, migration `022_shared_child_order_batch_create`, complete pre-write target enumeration, deterministic stop-on-first-non-success execution, and extension `0.5.170`. - Commit `bb115a3` from integration task `20260908-remove-maintain-project-docs-requirement-6d8a31f2` removed the deleted external project-document Skill/task-registry dependency and retained repository-local worktree and project-memory gates. - Source commit `a2378c8` from feature task `20260907-admin-task-data-plane-isolation-c3a7e91b`, integrated as `fd39347`, for the management-plane-only administrator role, task-data-plane denial at UI/HTTP/service/database boundaries, team-lead-only operations dashboard, and migration `021_admin_task_data_plane_isolation`; integration task `20260907-integrate-all-changes-9d2e7c41` accepted AUTH-004 and reconciled the administrator boundary. - Source commit `9043ad6eda0deb2a620e1303467d1c3bd80374ed` from feature task `20260907-leader-kanban-all-members-73c9e1a4`, integrated as `03d0131`, for the assignee-based team-lead dashboard over all durably assigned manual and AgentBus tasks. - Source commit `af9c90a3142e197493e80d74333af876c3bb947a` from feature task `20260907-ignore-extra-roster-fields-a6e4c9f2`, integrated as `9d1a6b4`, for required-field-only passenger-workbook normalization `v1.4.0`, ignored non-import columns, and synchronized Skill/business-instruction release `0.5.126`. - Source commit `5b57df0e10fc6c6c0b2f9eeef300e36508055acc` from feature task `20260907-fix-erp-account-verification-4d8c2a71`, integrated as `8f70cba`, for unique-login-node exact ERP identity verification and synchronized extension `0.5.168`. - Source commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` from feature task `20260907-auto-leader-summary-routing-5e8c1a73` for automatic role-driven team-lead summaries, current-owner AgentBus route learning/fallback, read-only status UI, stale-route cancellation, and removal of the manual mutation endpoint; integration task `20260907-integrate-auto-leader-summary-9a4d2c61` revised AUTH-003 and canonical notification behavior. - Source commit `1a3ab63` from feature task `20260907-implement-leader-agentbus-copy-b7e31a94` for default-off team-lead task summaries over future manual and AgentBus outcomes, a separate encrypted/revisioned outbox, verified proactive AgentBus routing, administrator configuration/health UI, and migration 020; integration task `20260907-integrate-leader-summaries-84c1d7ea` accepted AUTH-003 and canonical notification boundaries. - Correction commit `fe1cc2cddc29e4dead81e53c16d31bb71493602d` from integration task `20260903-backup-revert-extension-update-c71a4e92` preserved the complete former `0.5.167`/migration-019 stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed the central private-OSS/ECS automatic-update service architecture without rewriting history, and retained exact extension `0.5.167` with migration 018 at that correction point. - Merge commit `3224758` and integration task `20260903-finalize-extension-update-a6c4e192` remain historical records of the full-stack extension-update design. Adaptive entry readiness and dormant plugin-side idle/reload safeguards remain in the later `0.5.169` release; server orchestration is preserved on the backup branch only. - Commit `c4c469f4441d744627af2d34abe693b6783e833c` for the independently advanced remote deployment/extension line. - Commit `cd45ce17d0fcd25f7fa89ab9f8a391d3e904ecdf` for WeChat attachment correlation and privacy-safe server diagnostics. - Commit `161f90d09d6ad1368973b1a85d51059059495223` for trusted-intranet attachment compatibility and canonical reconciliation. - Integration task `20260831-finalize-main-push-4e1c7a9b` for verified non-force synchronization to `origin/main`. - Commit `b08f2960fa4db09c807b6fb61dfba33dc524a274` for the read-only list-attachment behavior inspection record; no product behavior changed. - Commit `191c1a1aad6f4bb1651143df3e0c1dc98dcd09e0` for the fixed-scope account system, three-role authorization, owner isolation, operations dashboard, audit/archive behavior, and per-account task-route grants. - Integration task `20260901-integrate-account-system-7b2f4d` for canonical authorization reconciliation, migrations 015–017, and the authorized standard-panel restart. - Commit `823d1cb6305077e1743f8783176d2cae3b5aec39` for the aggregate-first leadership platform-operations dashboard and business-safe input/result projections. - Integration task `20260901-integrate-leadership-dashboard-9e2b6c` for the leadership-dashboard product-definition correction. - Merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` from feature task `20260902-registration-invalid-params-59f94692`, with canonical promotion by integration task `20260902-promote-password-flow-c81d42`, for non-empty-only password validation and removal of the first-login forced-password-change workflow. - Commit `63b387f` integrating feature commit `6e212b3` from task `20260902-dashboard-nice-scale-d8c31a` for independent dynamic ranking scales with readable headroom above each leading bar. - Commit `8dddd21` integrating feature commit `1ee89da` from task `20260902-dashboard-mobile-share-4e91c7` for the focused leadership shell, responsive phone/tablet layout, unified dashboard cards, and the business-facing merge of follow-up work into in-progress. - Integration task `20260902-dashboard-mobile-integration-e28c` for canonical reconciliation of the mobile leadership-dashboard behavior. - Merge commit `a1b2d2f` integrating source commit `e68fcc1` from task `20260901-roster-header-error-a4f7` for exact ERP-semantic passenger-workbook header detection across rows 1–100, approved aliases, arbitrary column order, and the synchronized `0.5.125` lifecycle Skill and business-instruction DOCX. - Integration task `20260902-merge-all-restart-b7e3c91f` for local-branch/worktree reconciliation, canonical roster-contract promotion, full repository/release verification, and the authorized standard-panel restart. - Commit `3062ed5` from task `20260902-kanban-filter-7e3a91c4` for bounded single-connection leadership-dashboard queries, SQL business prefiltering, selective search hydration, 20-row pages, cancellation propagation, and timeout feedback. - Merge commit `b5f5847` integrating source commit `6f9fd0f` from task `20260902-agentbus-account-routing-b62f19e4` for employee-owned AgentBus channels, immutable task assignees, matching single-browser ERP workers, migration 018, and extension `0.5.164`. - Merge commit `cc09506` integrating source commit `b1fe533` from task `20260902-dashboard-metrics-static-a91c` for display-only dashboard metric cards and explicit status filtering. - Integration task `20260902-integrate-all-push-c93a7f21` for all-worktree reconciliation, semantic merge resolution, canonical promotion, full verification, and synchronization of `main` to `origin/main`. - Merge commit `336ca6e` integrating source commit `b26001e` from task `20260902-account-permission-ui-6c9e21ad` for a scroll-safe account task-permission editor layout and focused regression coverage. - Merge commit `e4fd916` integrating source commit `b5c727b` from task `20260902-diagnose-parse-error-7f3a9c2d` for native non-empty ERP product search in scatter-plan creation and independent batch-order creation, synchronized as extension `0.5.165`. - Integration task `20260902-integrate-product-search-3b7f6a20` for canonical product-search promotion, full release verification, and normal non-force synchronization to `origin/main`. - Commit `d09b303` from task `20260902-per-account-queue-hard-delete-a6d9f2c1` for account-scoped ERP FIFO, strict assignee-only executable routing, and explicit lifecycle-independent physical force deletion. - Integration task `20260903-finalize-account-routing-7c4e2a91` for AUTH-002 acceptance, canonical queue/removal reconciliation, full repository verification, and normal non-force synchronization to `origin/main`. ## Current Focus Operate the repository's current extension `0.5.170`, Program parser `v1.0.7`, Skills `0.5.126`, business-instruction `0.5.127`, roster normalizer `v1.4.0`, and migrations through `023_leader_summary_webhook_delivery` safely. The machine registry and operator input catalog contain 19 routes; the external Agent remains limited to its original 18 and the two passenger-list routes plus shared-child batch creation are Program-only. Administrators manage accounts, channels, employee grants, parser routing, automation settings, and audit but never enter the task data plane. Team leads/users own normal task operations through immutable assignment; same-account work remains FIFO and single-active while distinct accounts are independent. Team leads alone receive the read-only assignee-based dashboard, whose range-wide candidate pass stays lightweight and reserves full operation/result hydration for search and the current page. Future privacy-bounded organization summaries use one protected external Webhook and a separate encrypted one-attempt outbox, not a leader AgentBus route. Database migration, extension reload, route grants, service rollout, live ERP validation, and any external Webhook canary remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line. ## Recently Completed - 2026-08-28: Initialized `.project-docs/`, migrated durable project memory, and retired the root Planning with Files system into date-scoped history. - 2026-08-30: Advanced the synchronized Chrome extension/runtime release to `0.5.163`; Program parser remains `v1.0.6`, input contract/DOCX `0.5.123`, and five business Skills `0.5.125`. - 2026-08-28: Added narrow shared-mother-plan whole-visitor export using `shared_plan + visitor-list + tid-only` while preserving child/independent `did+tid` behavior. - 2026-08-28: Restarted the standard 8786 control plane under authorization and observed AgentBus 4/4 channels ready across repeated samples. - 2026-08-31: Integrated strict WeChat envelope conversation fallback, placeholder-only attachment rejection before task ingestion, and safe attachment error summaries while preserving the original `awaiting_attachment` task. - 2026-08-31: Integrated structured privacy-safe diagnostics across service, HTTP, task/audit, parser, AgentBus, attachment, database, and cleanup stages, with bounded Docker stdout retention and a read-only server diagnostic command. - 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls. - 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015–017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator. - 2026-09-01: Reframed the leadership dashboard from instruction-history/audit presentation to a platform-running view across tasks, people, input, output, time, type, and completion, with clickable drill-through and no visible technical payload language. - 2026-09-02: Removed application-level password length limits and the first-login forced-password-change flow while preserving voluntary password changes, administrator resets, session revocation, roles, task ownership, and route authorization. - 2026-09-02: Changed the task-type and employee ranking bars from max-item normalization to independent readable dynamic scales, so the leading bar retains visible headroom while operation counts remain the only encoded length. - 2026-09-02: Adapted the authenticated leadership dashboard for direct phone and portrait-tablet use, retained the desktop overview, unified the first metric card with the remaining cards, and removed the separate visible “待跟进” category by presenting those internal states as “进行中”. - 2026-09-02: Integrated passenger-workbook normalizer `v1.3.0`; one unique complete ERP-semantic header may appear on row 1 through 100 with arbitrary column order and finite approved aliases, while unknown columns, duplicate semantics, multiple candidates, unsafe formulas, and non-passport data continue to fail closed. - 2026-09-02: Restarted the standard `127.0.0.1:8786` control plane from current local `main` after the roster integration; liveness, database readiness, schema migration 017, and repeated listener stability checks passed. AgentBus remained enabled but disconnected, matching the pre-restart observation. - 2026-09-02: Integrated migration 018 and extension `0.5.164` so each enabled AgentBus channel binds one non-admin employee, each task keeps an immutable execution assignee, administrators cannot execute another assignee's work, and only one fresh browser with the matching ERP account is execution-ready. - 2026-09-02: Reworked leadership-dashboard reads into a bounded one-connection transaction with business SQL prefiltering, selective message hydration, page-only detail hydration, request/database deadlines, and 20-row pages; metric cards are now display-only and explicit filters default to all results. - 2026-09-02: Corrected the account-management task-permission editor so opening it expands a dedicated five-row layout, keeps the account list below the editor, and allows vertical page scrolling on desktop and narrow screens without changing authorization semantics. - 2026-09-02: Integrated extension `0.5.165`: scatter-plan creation and independent batch-order creation now try loaded product candidates, then the form's native non-empty `S_chanpinming` search, and finally one bounded empty-query compatibility reload. A user-authorized search-only ERP check returned exactly one target row in both forms without selecting or saving it; zero or multiple local matches continue to fail closed. - 2026-09-03: Accepted AUTH-002 and integrated account-scoped ERP queues. Each immutable assignee now owns one FIFO/single-active claim partition, different accounts no longer block one another, and executable SSE/results/cleanup commands are owner-only even when an administrator is signed in. - 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back. - 2026-09-03: Backed up the complete adaptive-readiness and central extension-update stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, then removed the central OSS/ECS update service and migration 019 from `main` with normal history-preserving commits. At that rollback point the repository retained exact extension `0.5.167` with migration 018; the plugin and schema later advanced independently without restoring the removed server architecture. - 2026-09-07: Integrated AUTH-003 and migration 020 for administrator-managed team-lead task summaries. Future stable manual/AgentBus outcomes for other non-admin employees project into a separate encrypted outbox and use the leader's verified AgentBus/WeChat target without changing task ownership, employee reply priority, or ERP execution authority. - 2026-09-07: Revised AUTH-003 so active team-lead identity plus an enabled owned AgentBus channel automatically activates both-source summaries. Routing uses only the current owner's latest valid inbound route or the channel external-user reference; channel rebind clears stale identity data, the settings API/UI is read-only, and all prior privacy, future-only, revision, priority, and no-ERP-authority boundaries remain. - 2026-09-07: Advanced the synchronized Chrome extension to `0.5.168`; expected ERP identity is accepted only from one unique login account node with normalized exact equality, never from whole-page substring matching. - 2026-09-07: Advanced the synchronized Chrome extension to `0.5.169`; uncertain ERP writes now direct manual read-only verification to the immutable task owner instead of an administrator who has no task-data-plane access. - 2026-09-07: Advanced passenger-workbook normalization to `v1.4.0` and the five Skills plus operator instruction DOCX to `0.5.126`. Only required ERP source semantics participate in extraction; ordinary non-import columns are ignored and excluded from canonical TSV while active-content safety remains workbook-wide. - 2026-09-07: Expanded the team-lead operations dashboard to every durably assigned manual and AgentBus task using immutable assignment as the employee dimension; unassigned historical AgentBus rows remain excluded. - 2026-09-07: Accepted AUTH-004 and migration 021. Administrators are management-plane-only, cannot access task APIs, browser workers, task routes, dashboards, summaries, or task principals, and role promotion removes legacy executable bindings. - 2026-09-08: Added Program-only shared-child batch creation across an inclusive departure-date range. Every product-matching parent is enumerated and validated before the first write; execution is ordered by date/tid, stops at the first blocked/failed/uncertain result, and never retries a write automatically. Parser `v1.0.7`, migration 022, and extension `0.5.170` are synchronized. - 2026-09-08: Replaced only the leader-summary AgentBus transport with an organization-level external Webhook. AUTH-005 and migration 023 retain future-only encrypted/privacy-bounded projection, mark only strict gateway success as accepted rather than delivered, and terminate rejected or uncertain attempts without automatic retry. - 2026-09-08: Removed the deleted external project-document Skill and task-registry requirement; repository-local Git worktree checks and `.project-docs/` remain the active collaboration and memory boundary. - 2026-09-09: Advanced the operator input catalog and generated DOCX to `0.5.127`, covering all 19 routes with a new copyable Program-only `散拼团多个新增子单` section while leaving Agent Prompt and Skill packages unchanged. - 2026-09-09: Integrated the missed dashboard candidate-query correction so normal date-range reads no longer load complete operation JSON before pagination; unresolved legacy classification receives only its compact required fields, while keyword search and current-page detail keep their existing fidelity. ## In Progress - The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window. - Required migrations through `023_leader_summary_webhook_delivery`, employee ERP identities/channel bindings, extension `0.5.170`, account-scoped queue/routing changes, owner force-delete behavior, roster `v1.4.0`, shared-child batch creation, and the merged dashboard/Webhook/administrator-isolation runtime changes have not been applied to or restarted on the standard service in this integration task. No live batch ERP write or external Webhook canary was performed. ## Next Recommended Steps 1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply all migrations through 023 in order, deploy the control plane and platform assets together, restart the service, manually load extension `0.5.170`, and verify readiness plus the exact-account handshake. 2. Through the administrator management UI, create representative team-lead and ordinary accounts, assign narrow task grants and channels, explicitly grant the new shared-child batch route only where intended, and verify that administrator task pages/APIs/workers fail closed while employee routes remain usable. 3. With separate team-lead and employee sessions, verify owner isolation, both-source leadership-dashboard reads, same-account FIFO, cross-account independence, mismatched ERP identity, worker conflict/failover, and owner-performed waiting/active force deletion without unintended ERP writes. 4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path. 5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings. 6. With explicit ERP-write authorization, run one bounded shared-child batch acceptance task after validating the full target set, then compare every per-parent receipt and stop behavior before wider use. 7. With explicit external-send authorization and provider-confirmed protected configuration, send one controlled leader-summary Webhook canary, record only strict gateway acceptance, and independently verify downstream group delivery without automatically retrying any uncertain attempt. ## Open Questions / Blockers - Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification. - Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence. - The standard service was last restarted before commits `3062ed5`, `b5f5847`, `cc09506`, `336ca6e`, `e4fd916`, `d09b303`, the 2026-09-07 integration commits, and migrations 022–023; its runtime schema, extension, account UI, queue/routing, owner force-delete, roster normalization, shared-child batch route, administrator isolation, dashboard, and Webhook behavior must not be represented as the newly integrated repository state until an authorized rollout. - AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering unique-node exact ERP identity, mismatched login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator task-data-plane denial, and both manual and automatic channel work. - Administrator migration 021 and the team-lead dashboard's assigned manual/AgentBus scope have repository and disposable-database evidence but no deployed multi-role browser canary. - The exact user-supplied workbook could not be replayed after the roster `v1.4.0` fix because its temporary shared-pasteboard file expired; synthetic regressions cover ignored populated identity-card and ordinary extra columns without preserving passenger data. - Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup. - A live internal AgentBus attachment verification remains separately unperformed. - Shared-child batch creation has parser/browser/static regression evidence but no authorized current-version ERP write verification. - External leader-summary delivery has repository, fake-sender, and disposable-PostgreSQL evidence but no deployed gateway/WeChat canary; an uncertain live attempt must not be retried automatically. ## Risky Areas - Any ERP write, uncertain post-write state, automatic retry, or scope widening. - Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity. - AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts. - Account role changes, migration-021 principal cleanup/triggers, administrator task-plane denial, session revocation, creator-based task-route revocation, cross-source assignee-based dashboard projection, and encrypted input audit are security-sensitive boundaries. - AgentBus channel ownership, immutable task assignment, unique-node exact expected ERP identity, browser-worker freshness/failover, and administrator management/task-plane separation are security- and write-safety-sensitive boundaries. - Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries. - Shared-child complete target enumeration, exact parent binding, ordered multi-write execution, per-parent receipts, stop-on-first-non-success behavior, and write uncertainty are duplicate-write-sensitive boundaries. - External Webhook configuration secrecy, future-only revisions, encrypted projection/delivery rows, one-attempt lease handling, privacy allowlisting, accepted-versus-delivered wording, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries. - Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`. ## Last Updated 2026-09-09