# Leader summaries with original input text ## Scope and authorization - User requested removing the public task ID from the notification body and adding input. Latest correction explicitly selects the original input text, superseding the earlier Chinese business-field preference. - Feature task: owns this record, leader-summary formatter/input projection, dedicated notification worker reads, and relevant tests. Shared canonical documents remain unchanged; contract updates are promotion candidates. - Local implementation and validation only. No deployment, service restart, ERP access, or external message sending. - No subagents: repository instructions require explicit user consent, which has not been provided. ## Worktree safety - Branch: `main` - Worktree: `/Users/andy/IdeaProjects/LWLT-AIBOT` - Base commit: `7ea7c211cc8e543a4089b1efd212aca2a838e1b7` - Existing changes: untracked `.idea/`, unrelated and preserved. - Other worktrees: none. Overlap result: Clear for notification source/tests. ## Implementation plan - Remove task-number text while retaining internal task association, deduplication and diagnostic IDs. - Render the task's original submitted text from `original_text_ciphertext`, preserving multiline content. No parsed-field extraction or attachment expansion. - Bound the entire message to an internal 4,000-byte UTF-8 display budget, visibly abbreviating only excessive input while retaining the result. This is a local display safeguard, not an assertion about the external provider's documented limit. - Missing/invalid encrypted input must not prevent other task notifications; show an unavailable-input message instead. - Cover exact input preservation, all stable outcomes, missing/invalid ciphertext, result updates, multibyte boundaries and worker data plumbing with local regression tests. - Run repository-required checks and build; document unrelated local hygiene limitations separately. ## Status - Complete locally; production deployment and actual WeChat delivery remain for the user. - Notification body now shows employee, business, status, submission time, original input and result. The generated task-number line is removed; task IDs still link internal delivery records, logs and deduplication. - Input is the first submitted text stored in `tasks.original_text_ciphertext`, shared by manual and AgentBus intake. Later conversational supplements and attachment contents are not fetched. Parse failures can therefore still show original input without a parsed operation. - Original punctuation, tabs and line layout are retained; line endings are normalized and nonprinting controls/outer whitespace removed. Only excessive original input is abbreviated with a visible notice under the 4,000-byte total display budget; the outcome remains complete. - Missing or undecryptable original text displays `原始输入暂不可用,请在平台查看。` and does not abort the projection batch. No input plaintext, ciphertext or response body is newly logged. - Existing encrypted outbox, future-only scope, one-attempt sends, fixed recipient configuration, task execution and database schema are unchanged. Previously materialized delivery text is not rewritten or resent. - Deployment requires a new server image/restart, with no extension update or SQL migration for this change. ## Validation and final review - Targeted summary/transport contract checks: 20/20 PASS, including 9 new behavioral regressions for exact multiline text, failed parsing, result updates, unavailable input, UTF-8 length boundaries and decryption failure isolation. - `node --run check`: PASS; `node --run build`: PASS in the original checkout. - `node --run check:repo` in the original checkout: 8/10 PASS, with only pre-existing `.idea/`, root `.DS_Store` and `chrome-extension/.DS_Store` hygiene violations. All existing local files preserved. - Clean validation snapshot `/private/tmp/ltjt-leader-original-input-verify-w90er9zg` contains tracked files with current edits plus this task record, excludes local secrets and unrelated untracked/Finder files, and reuses installed dependencies through a symlink. Repository checks 10/10 PASS; full control-plane tests 192/192 PASS. - Full legacy suite in that snapshot: 285/287 PASS under the sandbox; two existing localhost HTTP tests failed solely on `listen EPERM: 127.0.0.1`. Both were rerun with the required localhost permission and PASS 2/2. They use mock parsers and no external services. No other test failures remain. - Final local read-only review: PASS. Worker selects the original encrypted column and decrypts only for summary rendering; formatter has no generated task ID; dispatcher still validates encrypted payload fingerprints and retains internal IDs. Scope is two production TypeScript files, two tests and this record. - `git diff --check`: PASS. No deployment, restart, ERP action or external notification was performed. ## Promotion candidates - Update `agent设计规范/leader-summary-webhook-contract.md` and AUTH-005/canonical notification documentation during integration: task ID no longer appears as a generated message field, and original submitted text is included. Internal IDs, deduplication, delivery scope and one-attempt transport are unchanged. - The explicit request to display raw input supersedes the old body's exclusion of raw instructions and any content the user puts in them. No additional customer/passenger records, attachments, credentials or technical internals are fetched or appended. Notification text/ciphertext is not written to logs.