Files
LWLT-AIBOT/.project-docs/30-worklog/current-state.md
2026-09-09 18:56:41 +08:00

128 lines
26 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Current State
This file is the integrated default-branch snapshot. Feature tasks record progress in `30-worklog/tasks/{task_id}.md` and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode.
## Integrated Through
- Source commit `5cbd8f1` from feature task `20260903-dashboard-refresh-no-data-b4e82f1a`, integrated as merge commit `b11dc7b`, for lightweight leadership-dashboard candidate reads that exclude full `operation` JSON, hydrate only the compact `action`/`kind`/`mode` shape needed by unresolved legacy classification, and retain complete payloads only for keyword search and current-page detail.
- Integration task `20260909-business-instruction-batch-child-7e3c1a94` synchronized operator input catalog/DOCX `0.5.127` with all 19 system routes, adding the copyable `散拼团多个新增子单` entry while keeping that route Program-only and leaving the five Skills at `0.5.126`.
- Source commit `be17f6c` from feature task `20260908-leader-webhook-api-7c4e9a12`, integrated as merge commit `295409b`, for organization-level external Webhook delivery of privacy-bounded leader summaries, migration `023_leader_summary_webhook_delivery`, and AUTH-005's one-attempt accepted-versus-delivered boundary.
- Source commit `6ac90f8` from feature task `20260908-shared-child-batch-create-4e7c2a91`, integrated as merge commit `0d20544`, for Program-only `shared_child_order_batch_create`, parser `v1.0.7`, migration `022_shared_child_order_batch_create`, complete pre-write target enumeration, deterministic stop-on-first-non-success execution, and extension `0.5.170`.
- Commit `bb115a3` from integration task `20260908-remove-maintain-project-docs-requirement-6d8a31f2` removed the deleted external project-document Skill/task-registry dependency and retained repository-local worktree and project-memory gates.
- Source commit `a2378c8` from feature task `20260907-admin-task-data-plane-isolation-c3a7e91b`, integrated as `fd39347`, for the management-plane-only administrator role, task-data-plane denial at UI/HTTP/service/database boundaries, team-lead-only operations dashboard, and migration `021_admin_task_data_plane_isolation`; integration task `20260907-integrate-all-changes-9d2e7c41` accepted AUTH-004 and reconciled the administrator boundary.
- Source commit `9043ad6eda0deb2a620e1303467d1c3bd80374ed` from feature task `20260907-leader-kanban-all-members-73c9e1a4`, integrated as `03d0131`, for the assignee-based team-lead dashboard over all durably assigned manual and AgentBus tasks.
- Source commit `af9c90a3142e197493e80d74333af876c3bb947a` from feature task `20260907-ignore-extra-roster-fields-a6e4c9f2`, integrated as `9d1a6b4`, for required-field-only passenger-workbook normalization `v1.4.0`, ignored non-import columns, and synchronized Skill/business-instruction release `0.5.126`.
- Source commit `5b57df0e10fc6c6c0b2f9eeef300e36508055acc` from feature task `20260907-fix-erp-account-verification-4d8c2a71`, integrated as `8f70cba`, for unique-login-node exact ERP identity verification and synchronized extension `0.5.168`.
- Source commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` from feature task `20260907-auto-leader-summary-routing-5e8c1a73` for automatic role-driven team-lead summaries, current-owner AgentBus route learning/fallback, read-only status UI, stale-route cancellation, and removal of the manual mutation endpoint; integration task `20260907-integrate-auto-leader-summary-9a4d2c61` revised AUTH-003 and canonical notification behavior.
- Source commit `1a3ab63` from feature task `20260907-implement-leader-agentbus-copy-b7e31a94` for default-off team-lead task summaries over future manual and AgentBus outcomes, a separate encrypted/revisioned outbox, verified proactive AgentBus routing, administrator configuration/health UI, and migration 020; integration task `20260907-integrate-leader-summaries-84c1d7ea` accepted AUTH-003 and canonical notification boundaries.
- Correction commit `fe1cc2cddc29e4dead81e53c16d31bb71493602d` from integration task `20260903-backup-revert-extension-update-c71a4e92` preserved the complete former `0.5.167`/migration-019 stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed the central private-OSS/ECS automatic-update service architecture without rewriting history, and retained exact extension `0.5.167` with migration 018 at that correction point.
- Merge commit `3224758` and integration task `20260903-finalize-extension-update-a6c4e192` remain historical records of the full-stack extension-update design. Adaptive entry readiness and dormant plugin-side idle/reload safeguards remain in the later `0.5.169` release; server orchestration is preserved on the backup branch only.
- Commit `c4c469f4441d744627af2d34abe693b6783e833c` for the independently advanced remote deployment/extension line.
- Commit `cd45ce17d0fcd25f7fa89ab9f8a391d3e904ecdf` for WeChat attachment correlation and privacy-safe server diagnostics.
- Commit `161f90d09d6ad1368973b1a85d51059059495223` for trusted-intranet attachment compatibility and canonical reconciliation.
- Integration task `20260831-finalize-main-push-4e1c7a9b` for verified non-force synchronization to `origin/main`.
- Commit `b08f2960fa4db09c807b6fb61dfba33dc524a274` for the read-only list-attachment behavior inspection record; no product behavior changed.
- Commit `191c1a1aad6f4bb1651143df3e0c1dc98dcd09e0` for the fixed-scope account system, three-role authorization, owner isolation, operations dashboard, audit/archive behavior, and per-account task-route grants.
- Integration task `20260901-integrate-account-system-7b2f4d` for canonical authorization reconciliation, migrations 015–017, and the authorized standard-panel restart.
- Commit `823d1cb6305077e1743f8783176d2cae3b5aec39` for the aggregate-first leadership platform-operations dashboard and business-safe input/result projections.
- Integration task `20260901-integrate-leadership-dashboard-9e2b6c` for the leadership-dashboard product-definition correction.
- Merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` from feature task `20260902-registration-invalid-params-59f94692`, with canonical promotion by integration task `20260902-promote-password-flow-c81d42`, for non-empty-only password validation and removal of the first-login forced-password-change workflow.
- Commit `63b387f` integrating feature commit `6e212b3` from task `20260902-dashboard-nice-scale-d8c31a` for independent dynamic ranking scales with readable headroom above each leading bar.
- Commit `8dddd21` integrating feature commit `1ee89da` from task `20260902-dashboard-mobile-share-4e91c7` for the focused leadership shell, responsive phone/tablet layout, unified dashboard cards, and the business-facing merge of follow-up work into in-progress.
- Integration task `20260902-dashboard-mobile-integration-e28c` for canonical reconciliation of the mobile leadership-dashboard behavior.
- Merge commit `a1b2d2f` integrating source commit `e68fcc1` from task `20260901-roster-header-error-a4f7` for exact ERP-semantic passenger-workbook header detection across rows 1–100, approved aliases, arbitrary column order, and the synchronized `0.5.125` lifecycle Skill and business-instruction DOCX.
- Integration task `20260902-merge-all-restart-b7e3c91f` for local-branch/worktree reconciliation, canonical roster-contract promotion, full repository/release verification, and the authorized standard-panel restart.
- Commit `3062ed5` from task `20260902-kanban-filter-7e3a91c4` for bounded single-connection leadership-dashboard queries, SQL business prefiltering, selective search hydration, 20-row pages, cancellation propagation, and timeout feedback.
- Merge commit `b5f5847` integrating source commit `6f9fd0f` from task `20260902-agentbus-account-routing-b62f19e4` for employee-owned AgentBus channels, immutable task assignees, matching single-browser ERP workers, migration 018, and extension `0.5.164`.
- Merge commit `cc09506` integrating source commit `b1fe533` from task `20260902-dashboard-metrics-static-a91c` for display-only dashboard metric cards and explicit status filtering.
- Integration task `20260902-integrate-all-push-c93a7f21` for all-worktree reconciliation, semantic merge resolution, canonical promotion, full verification, and synchronization of `main` to `origin/main`.
- Merge commit `336ca6e` integrating source commit `b26001e` from task `20260902-account-permission-ui-6c9e21ad` for a scroll-safe account task-permission editor layout and focused regression coverage.
- Merge commit `e4fd916` integrating source commit `b5c727b` from task `20260902-diagnose-parse-error-7f3a9c2d` for native non-empty ERP product search in scatter-plan creation and independent batch-order creation, synchronized as extension `0.5.165`.
- Integration task `20260902-integrate-product-search-3b7f6a20` for canonical product-search promotion, full release verification, and normal non-force synchronization to `origin/main`.
- Commit `d09b303` from task `20260902-per-account-queue-hard-delete-a6d9f2c1` for account-scoped ERP FIFO, strict assignee-only executable routing, and explicit lifecycle-independent physical force deletion.
- Integration task `20260903-finalize-account-routing-7c4e2a91` for AUTH-002 acceptance, canonical queue/removal reconciliation, full repository verification, and normal non-force synchronization to `origin/main`.
## Current Focus
Operate the repository's current extension `0.5.170`, Program parser `v1.0.7`, Skills `0.5.126`, business-instruction `0.5.127`, roster normalizer `v1.4.0`, and migrations through `023_leader_summary_webhook_delivery` safely. The machine registry and operator input catalog contain 19 routes; the external Agent remains limited to its original 18 and the two passenger-list routes plus shared-child batch creation are Program-only. Administrators manage accounts, channels, employee grants, parser routing, automation settings, and audit but never enter the task data plane. Team leads/users own normal task operations through immutable assignment; same-account work remains FIFO and single-active while distinct accounts are independent. Team leads alone receive the read-only assignee-based dashboard, whose range-wide candidate pass stays lightweight and reserves full operation/result hydration for search and the current page. Future privacy-bounded organization summaries use one protected external Webhook and a separate encrypted one-attempt outbox, not a leader AgentBus route. Database migration, extension reload, route grants, service rollout, live ERP validation, and any external Webhook canary remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
## Recently Completed
- 2026-08-28: Initialized `.project-docs/`, migrated durable project memory, and retired the root Planning with Files system into date-scoped history.
- 2026-08-30: Advanced the synchronized Chrome extension/runtime release to `0.5.163`; Program parser remains `v1.0.6`, input contract/DOCX `0.5.123`, and five business Skills `0.5.125`.
- 2026-08-28: Added narrow shared-mother-plan whole-visitor export using `shared_plan + visitor-list + tid-only` while preserving child/independent `did+tid` behavior.
- 2026-08-28: Restarted the standard 8786 control plane under authorization and observed AgentBus 4/4 channels ready across repeated samples.
- 2026-08-31: Integrated strict WeChat envelope conversation fallback, placeholder-only attachment rejection before task ingestion, and safe attachment error summaries while preserving the original `awaiting_attachment` task.
- 2026-08-31: Integrated structured privacy-safe diagnostics across service, HTTP, task/audit, parser, AgentBus, attachment, database, and cleanup stages, with bounded Docker stdout retention and a read-only server diagnostic command.
- 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
- 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015–017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator.
- 2026-09-01: Reframed the leadership dashboard from instruction-history/audit presentation to a platform-running view across tasks, people, input, output, time, type, and completion, with clickable drill-through and no visible technical payload language.
- 2026-09-02: Removed application-level password length limits and the first-login forced-password-change flow while preserving voluntary password changes, administrator resets, session revocation, roles, task ownership, and route authorization.
- 2026-09-02: Changed the task-type and employee ranking bars from max-item normalization to independent readable dynamic scales, so the leading bar retains visible headroom while operation counts remain the only encoded length.
- 2026-09-02: Adapted the authenticated leadership dashboard for direct phone and portrait-tablet use, retained the desktop overview, unified the first metric card with the remaining cards, and removed the separate visible “待跟进” category by presenting those internal states as “进行中”.
- 2026-09-02: Integrated passenger-workbook normalizer `v1.3.0`; one unique complete ERP-semantic header may appear on row 1 through 100 with arbitrary column order and finite approved aliases, while unknown columns, duplicate semantics, multiple candidates, unsafe formulas, and non-passport data continue to fail closed.
- 2026-09-02: Restarted the standard `127.0.0.1:8786` control plane from current local `main` after the roster integration; liveness, database readiness, schema migration 017, and repeated listener stability checks passed. AgentBus remained enabled but disconnected, matching the pre-restart observation.
- 2026-09-02: Integrated migration 018 and extension `0.5.164` so each enabled AgentBus channel binds one non-admin employee, each task keeps an immutable execution assignee, administrators cannot execute another assignee's work, and only one fresh browser with the matching ERP account is execution-ready.
- 2026-09-02: Reworked leadership-dashboard reads into a bounded one-connection transaction with business SQL prefiltering, selective message hydration, page-only detail hydration, request/database deadlines, and 20-row pages; metric cards are now display-only and explicit filters default to all results.
- 2026-09-02: Corrected the account-management task-permission editor so opening it expands a dedicated five-row layout, keeps the account list below the editor, and allows vertical page scrolling on desktop and narrow screens without changing authorization semantics.
- 2026-09-02: Integrated extension `0.5.165`: scatter-plan creation and independent batch-order creation now try loaded product candidates, then the form's native non-empty `S_chanpinming` search, and finally one bounded empty-query compatibility reload. A user-authorized search-only ERP check returned exactly one target row in both forms without selecting or saving it; zero or multiple local matches continue to fail closed.
- 2026-09-03: Accepted AUTH-002 and integrated account-scoped ERP queues. Each immutable assignee now owns one FIFO/single-active claim partition, different accounts no longer block one another, and executable SSE/results/cleanup commands are owner-only even when an administrator is signed in.
- 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back.
- 2026-09-03: Backed up the complete adaptive-readiness and central extension-update stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, then removed the central OSS/ECS update service and migration 019 from `main` with normal history-preserving commits. At that rollback point the repository retained exact extension `0.5.167` with migration 018; the plugin and schema later advanced independently without restoring the removed server architecture.
- 2026-09-07: Integrated AUTH-003 and migration 020 for administrator-managed team-lead task summaries. Future stable manual/AgentBus outcomes for other non-admin employees project into a separate encrypted outbox and use the leader's verified AgentBus/WeChat target without changing task ownership, employee reply priority, or ERP execution authority.
- 2026-09-07: Revised AUTH-003 so active team-lead identity plus an enabled owned AgentBus channel automatically activates both-source summaries. Routing uses only the current owner's latest valid inbound route or the channel external-user reference; channel rebind clears stale identity data, the settings API/UI is read-only, and all prior privacy, future-only, revision, priority, and no-ERP-authority boundaries remain.
- 2026-09-07: Advanced the synchronized Chrome extension to `0.5.168`; expected ERP identity is accepted only from one unique login account node with normalized exact equality, never from whole-page substring matching.
- 2026-09-07: Advanced the synchronized Chrome extension to `0.5.169`; uncertain ERP writes now direct manual read-only verification to the immutable task owner instead of an administrator who has no task-data-plane access.
- 2026-09-07: Advanced passenger-workbook normalization to `v1.4.0` and the five Skills plus operator instruction DOCX to `0.5.126`. Only required ERP source semantics participate in extraction; ordinary non-import columns are ignored and excluded from canonical TSV while active-content safety remains workbook-wide.
- 2026-09-07: Expanded the team-lead operations dashboard to every durably assigned manual and AgentBus task using immutable assignment as the employee dimension; unassigned historical AgentBus rows remain excluded.
- 2026-09-07: Accepted AUTH-004 and migration 021. Administrators are management-plane-only, cannot access task APIs, browser workers, task routes, dashboards, summaries, or task principals, and role promotion removes legacy executable bindings.
- 2026-09-08: Added Program-only shared-child batch creation across an inclusive departure-date range. Every product-matching parent is enumerated and validated before the first write; execution is ordered by date/tid, stops at the first blocked/failed/uncertain result, and never retries a write automatically. Parser `v1.0.7`, migration 022, and extension `0.5.170` are synchronized.
- 2026-09-08: Replaced only the leader-summary AgentBus transport with an organization-level external Webhook. AUTH-005 and migration 023 retain future-only encrypted/privacy-bounded projection, mark only strict gateway success as accepted rather than delivered, and terminate rejected or uncertain attempts without automatic retry.
- 2026-09-08: Removed the deleted external project-document Skill and task-registry requirement; repository-local Git worktree checks and `.project-docs/` remain the active collaboration and memory boundary.
- 2026-09-09: Advanced the operator input catalog and generated DOCX to `0.5.127`, covering all 19 routes with a new copyable Program-only `散拼团多个新增子单` section while leaving Agent Prompt and Skill packages unchanged.
- 2026-09-09: Integrated the missed dashboard candidate-query correction so normal date-range reads no longer load complete operation JSON before pagination; unresolved legacy classification receives only its compact required fields, while keyword search and current-page detail keep their existing fidelity.
## In Progress
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
- Required migrations through `023_leader_summary_webhook_delivery`, employee ERP identities/channel bindings, extension `0.5.170`, account-scoped queue/routing changes, owner force-delete behavior, roster `v1.4.0`, shared-child batch creation, and the merged dashboard/Webhook/administrator-isolation runtime changes have not been applied to or restarted on the standard service in this integration task. No live batch ERP write or external Webhook canary was performed.
## Next Recommended Steps
1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply all migrations through 023 in order, deploy the control plane and platform assets together, restart the service, manually load extension `0.5.170`, and verify readiness plus the exact-account handshake.
2. Through the administrator management UI, create representative team-lead and ordinary accounts, assign narrow task grants and channels, explicitly grant the new shared-child batch route only where intended, and verify that administrator task pages/APIs/workers fail closed while employee routes remain usable.
3. With separate team-lead and employee sessions, verify owner isolation, both-source leadership-dashboard reads, same-account FIFO, cross-account independence, mismatched ERP identity, worker conflict/failover, and owner-performed waiting/active force deletion without unintended ERP writes.
4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
6. With explicit ERP-write authorization, run one bounded shared-child batch acceptance task after validating the full target set, then compare every per-parent receipt and stop behavior before wider use.
7. With explicit external-send authorization and provider-confirmed protected configuration, send one controlled leader-summary Webhook canary, record only strict gateway acceptance, and independently verify downstream group delivery without automatically retrying any uncertain attempt.
## Open Questions / Blockers
- Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
- Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
- The standard service was last restarted before commits `3062ed5`, `b5f5847`, `cc09506`, `336ca6e`, `e4fd916`, `d09b303`, the 2026-09-07 integration commits, and migrations 022–023; its runtime schema, extension, account UI, queue/routing, owner force-delete, roster normalization, shared-child batch route, administrator isolation, dashboard, and Webhook behavior must not be represented as the newly integrated repository state until an authorized rollout.
- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering unique-node exact ERP identity, mismatched login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator task-data-plane denial, and both manual and automatic channel work.
- Administrator migration 021 and the team-lead dashboard's assigned manual/AgentBus scope have repository and disposable-database evidence but no deployed multi-role browser canary.
- The exact user-supplied workbook could not be replayed after the roster `v1.4.0` fix because its temporary shared-pasteboard file expired; synthetic regressions cover ignored populated identity-card and ordinary extra columns without preserving passenger data.
- Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
- A live internal AgentBus attachment verification remains separately unperformed.
- Shared-child batch creation has parser/browser/static regression evidence but no authorized current-version ERP write verification.
- External leader-summary delivery has repository, fake-sender, and disposable-PostgreSQL evidence but no deployed gateway/WeChat canary; an uncertain live attempt must not be retried automatically.
## Risky Areas
- Any ERP write, uncertain post-write state, automatic retry, or scope widening.
- Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity.
- AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts.
- Account role changes, migration-021 principal cleanup/triggers, administrator task-plane denial, session revocation, creator-based task-route revocation, cross-source assignee-based dashboard projection, and encrypted input audit are security-sensitive boundaries.
- AgentBus channel ownership, immutable task assignment, unique-node exact expected ERP identity, browser-worker freshness/failover, and administrator management/task-plane separation are security- and write-safety-sensitive boundaries.
- Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
- Shared-child complete target enumeration, exact parent binding, ordered multi-write execution, per-parent receipts, stop-on-first-non-success behavior, and write uncertainty are duplicate-write-sensitive boundaries.
- External Webhook configuration secrecy, future-only revisions, encrypted projection/delivery rows, one-attempt lease handling, privacy allowlisting, accepted-versus-delivered wording, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
## Last Updated
2026-09-09