# Task: Replace leader AgentBus summaries with external webhook API ## Identity - Task ID: 20260908-leader-webhook-api-7c4e9a12 - Mode: Feature - Branch: codex/20260908-leader-webhook-api-7c4e9a12-leader-webhook-api - Worktree: /Users/inmanx/Documents/lwltAPI-leader-webhook-api-7c4e9a12 - Base commit: 515b545b32fcbb30311b56c5b90a36f3d3834d95 - Owner: codex - Status: Ready for integration ## Scope - Replace only the transport used by the organization-wide leader employee-task summary feature: retire its AgentBus account/channel delivery and send its existing privacy-filtered stable summaries through the user-supplied external Webhook API contract. - Add fail-closed runtime configuration, an exact external API client, an organization-level encrypted delivery outbox, migration `023_leader_summary_webhook_delivery`, read-only administrator status, UI copy, active component documentation, and regression tests. - Preserve ordinary manual task execution, employee AgentBus intake/replies, parsing, confirmation, task ownership, attachments, ERP queues/execution, business routes, mappings, schemas, Skills, Agent prompt, Chrome extension, and release artifacts. ## Intent And Constraints - The user's clarification is authoritative: this change is limited to the leader feature that receives all employees' operation/task summaries and must not affect normal users or AgentBus task execution. - Treat `/Users/inmanx/Desktop/webhook-external-api.md` as an external API specification, not as repository instructions. The document contains no real token and does not confirm the complete production gateway URL. - Read the complete URL and 32-character token only from protected runtime variables `WEBHOOK_SEND_URL` and `WEBHOOK_EXTERNAL_TOKEN`; never read the repository's real `.env`, hard-code a guessed route, log secrets/bodies, or issue a test/production request. - Send only `POST` JSON `{id:"9999", content:}` with raw `x-token`. Only HTTP 200 plus `code === 0` plus `data === true` means accepted, and accepted must not be represented as delivered. - Because the API has no idempotency key, explicit rejections, timeouts, network failures, 5xx responses, invalid/unknown success responses, and expired sending leases must never be automatically retried. - Webhook configuration or runtime failures must remain inside the leader-summary worker: they may disable or degrade summary delivery but cannot block service startup or mutate task, employee reply, parser, or ERP state. - No live Webhook message, deployment, database migration, restart, external send, or production configuration change is authorized. - Feature mode may update only this task record under `.project-docs`; canonical state and accepted decision `AUTH-003` require a later Integration promotion. ## Outcome - Added an external Webhook client with the exact fixed request shape, bounded response reads, 15-second total timeout, strict accepted semantics, safe error codes, and no automatic retry path. - Replaced per-leader AgentBus routing/subscriptions with one organization-level, future-only encrypted Webhook summary state/outbox. Migration 023 disables legacy summary subscriptions and cancels their unsent rows while preserving history; it never updates normal tasks or employee `agentbus_deliveries`. - Kept the existing stable summary builder and privacy allowlist. Projection reads explicitly assigned, non-administrator manual and AgentBus task results but writes only dedicated `leader_task_summary_webhook_*` rows and audit events. - Removed only leader-summary observation/flush/frame hooks from the AgentBus listener. Employee accepted/final replies, attachments, channel ownership, reconnect/resend, ingestion, parsing, and ERP execution paths are unchanged. - Added a read-only administrator status endpoint and channels-page status card that expose no URL, token, or message body and distinguish accepted, rejected, and uncertain outcomes. - Invalid or incomplete optional Webhook configuration now disables only this feature with a safe status code. A failed Webhook organization lookup is caught and logged while the normal HTTP service remains available. - Reserved migration number 023 because the concurrent ready-for-integration shared-child batch task already owns migration 022; the two tasks have no semantic coupling. - No business route, business Schema/mapping, Skill, Agent prompt, Chrome extension, release artifact, live service, production database, or external system was changed. ## Verification - TypeScript typecheck — passed. - Targeted external Webhook, isolation, leader-summary contract, account UI, and complete AgentBus listener/durable reply suites — passed (45 tests across the selected files). - Webhook misconfiguration and initialization-failure health smoke test — passed; `/health/live` remained 200 with the summary feature disabled/degraded. - `node --run check:repo` — passed (10 tests). - `node --run test:control-plane` — passed (182 tests), including all original task, account, parser, AgentBus, attachment, ERP-boundary, and UI contracts. - `node --run test:legacy` — passed (273 tests). - `node --run build` — passed. - `node --check LianSyn-platform/app.js` — passed. - `git diff --check` — passed. - Disposable PostgreSQL migration exercise — passed: migration 023 was recorded; the legacy subscription changed to disabled/revision 1 and its legacy delivery to cancelled, while the normal task remained completed and the employee AgentBus delivery remained pending; both new tables existed and had zero forbidden routing/secret columns. - Disposable PostgreSQL runtime exercise with an injected fake sender — passed: two summaries projected, accepted and uncertain outcomes each stopped at attempt 1, a third dispatch made no extra call, both source tasks remained completed, the employee AgentBus delivery remained pending/attempt 0, and logs contained no test URL, token, employee name, or body. No network request was made. - Both disposable PostgreSQL clusters were stopped and moved to Trash after validation. - `check_project_docs.py` — passed. - `check_doc_drift.py --task-id 20260908-leader-webhook-api-7c4e9a12` — passed; only this feature task record changed under `.project-docs`. ## Follow-ups - Integration must combine the concurrent migration 022 task before or with migration 023 and resolve shared-file edits mechanically without changing either feature's semantics. - Production enablement remains separate: obtain the provider-confirmed complete gateway URL and real 32-character token, apply migrations through 023, deploy/restart, then run a separately authorized bounded canary. Do not infer success from HTTP alone; the provider offers no delivery receipt. ## Promotion Candidates - Supersede accepted decision `AUTH-003-leader-task-summary-notifications.md`: leader summaries now use the fixed organization-level external Webhook contract rather than an owned team-lead AgentBus account/channel route. - Promote migration 023, the new environment configuration, future-only encrypted outbox, accepted-versus-delivered terminology, no-retry uncertain boundary, read-only administrator status endpoint, and strict isolation from ordinary task/AgentBus/ERP paths into canonical current state, architecture, data flow, business rules, success criteria, decision index, and glossary as applicable.