26 lines
2.4 KiB
Markdown
26 lines
2.4 KiB
Markdown
# Business Rules
|
|
|
|
## Durable Rules
|
|
|
|
- `agent设计规范/business-adaptation-registry.md` is the cross-session business entry; each business maps user input, Skill/action, ERP flow, contracts, implementation, fixtures, and verification status.
|
|
- Manual and AgentBus tasks share the same 18 machine routes, task-scoped parser mode snapshot, and organization automation rules.
|
|
- The two passenger-list import routes are Program-only and wait for exactly one `.xls` or `.xlsx` attachment before deterministic normalization.
|
|
- A WeChat attachment card is transport placeholder text, not file content. Only a structured `payload.attachments[]` entry can resume a roster task; missing metadata fails before ingestion and leaves the original task in `awaiting_attachment` instead of creating a new task.
|
|
- The trusted internal deployment accepts credential-free HTTPS roster attachment URLs whose host is internal, private/reserved IPv4/IPv6, or localhost. DNS pinning, redirect revalidation, download timeout, byte limits, declared-size checks, and optional SHA-256 verification remain mandatory.
|
|
- AgentBus attachment diagnostics may record stage, address count/family, status, byte count, code, outcome, and duration, but never URL, hostname, IP, file name, bytes, message text, or roster values.
|
|
- Passenger overwrite requires confirmation when target ERP rows are occupied; after `full_replace + confirmed=true`, every attachment-specified sequence is written even when values are unchanged.
|
|
- A single strict `领队` row supplies leader contact; ambiguous, incomplete, duplicate, or structurally inconsistent leader data fails closed.
|
|
- Shared-mother-plan `整团游客信息` export is only `shared_plan + visitor-list + tid-only`; independent and concrete shared-child visitor lists remain `did+tid`.
|
|
- Real writes require unique resolution, exact page identity, ownership, write projection, explicit server response, and action-specific completion evidence.
|
|
- Current business capability and verification status come from active source/contracts and the lifecycle release gate, never from archive wording.
|
|
|
|
## Open Questions
|
|
|
|
- Fresh authorized runtime read verification remains for the shared-mother-plan whole-visitor export branch.
|
|
- Authorized current-version ERP write verification remains for SGL/TWN and four independent-order headcount categories.
|
|
- Deployment/restart and one live internal attachment verification still require separate authorization.
|
|
|
|
## Last Reviewed
|
|
|
|
2026-08-31
|