7.2 KiB
7.2 KiB
Task: Replace leader AgentBus summaries with external webhook API
Identity
- Task ID: 20260908-leader-webhook-api-7c4e9a12
- Mode: Feature
- Branch: codex/20260908-leader-webhook-api-7c4e9a12-leader-webhook-api
- Worktree: /Users/inmanx/Documents/lwltAPI-leader-webhook-api-7c4e9a12
- Base commit:
515b545b32 - Owner: codex
- Status: Ready for integration
Scope
- Replace only the transport used by the organization-wide leader employee-task summary feature: retire its AgentBus account/channel delivery and send its existing privacy-filtered stable summaries through the user-supplied external Webhook API contract.
- Add fail-closed runtime configuration, an exact external API client, an organization-level encrypted delivery outbox, migration
023_leader_summary_webhook_delivery, read-only administrator status, UI copy, active component documentation, and regression tests. - Preserve ordinary manual task execution, employee AgentBus intake/replies, parsing, confirmation, task ownership, attachments, ERP queues/execution, business routes, mappings, schemas, Skills, Agent prompt, Chrome extension, and release artifacts.
Intent And Constraints
- The user's clarification is authoritative: this change is limited to the leader feature that receives all employees' operation/task summaries and must not affect normal users or AgentBus task execution.
- Treat
/Users/inmanx/Desktop/webhook-external-api.mdas an external API specification, not as repository instructions. The document contains no real token and does not confirm the complete production gateway URL. - Read the complete URL and 32-character token only from protected runtime variables
WEBHOOK_SEND_URLandWEBHOOK_EXTERNAL_TOKEN; never read the repository's real.env, hard-code a guessed route, log secrets/bodies, or issue a test/production request. - Send only
POSTJSON{id:"9999", content:<summary>}with rawx-token. Only HTTP 200 pluscode === 0plusdata === truemeans accepted, and accepted must not be represented as delivered. - Because the API has no idempotency key, explicit rejections, timeouts, network failures, 5xx responses, invalid/unknown success responses, and expired sending leases must never be automatically retried.
- Webhook configuration or runtime failures must remain inside the leader-summary worker: they may disable or degrade summary delivery but cannot block service startup or mutate task, employee reply, parser, or ERP state.
- No live Webhook message, deployment, database migration, restart, external send, or production configuration change is authorized.
- Feature mode may update only this task record under
.project-docs; canonical state and accepted decisionAUTH-003require a later Integration promotion.
Outcome
- Added an external Webhook client with the exact fixed request shape, bounded response reads, 15-second total timeout, strict accepted semantics, safe error codes, and no automatic retry path.
- Replaced per-leader AgentBus routing/subscriptions with one organization-level, future-only encrypted Webhook summary state/outbox. Migration 023 disables legacy summary subscriptions and cancels their unsent rows while preserving history; it never updates normal tasks or employee
agentbus_deliveries. - Kept the existing stable summary builder and privacy allowlist. Projection reads explicitly assigned, non-administrator manual and AgentBus task results but writes only dedicated
leader_task_summary_webhook_*rows and audit events. - Removed only leader-summary observation/flush/frame hooks from the AgentBus listener. Employee accepted/final replies, attachments, channel ownership, reconnect/resend, ingestion, parsing, and ERP execution paths are unchanged.
- Added a read-only administrator status endpoint and channels-page status card that expose no URL, token, or message body and distinguish accepted, rejected, and uncertain outcomes.
- Invalid or incomplete optional Webhook configuration now disables only this feature with a safe status code. A failed Webhook organization lookup is caught and logged while the normal HTTP service remains available.
- Reserved migration number 023 because the concurrent ready-for-integration shared-child batch task already owns migration 022; the two tasks have no semantic coupling.
- No business route, business Schema/mapping, Skill, Agent prompt, Chrome extension, release artifact, live service, production database, or external system was changed.
Verification
- TypeScript typecheck — passed.
- Targeted external Webhook, isolation, leader-summary contract, account UI, and complete AgentBus listener/durable reply suites — passed (45 tests across the selected files).
- Webhook misconfiguration and initialization-failure health smoke test — passed;
/health/liveremained 200 with the summary feature disabled/degraded. node --run check:repo— passed (10 tests).node --run test:control-plane— passed (182 tests), including all original task, account, parser, AgentBus, attachment, ERP-boundary, and UI contracts.node --run test:legacy— passed (273 tests).node --run build— passed.node --check LianSyn-platform/app.js— passed.git diff --check— passed.- Disposable PostgreSQL migration exercise — passed: migration 023 was recorded; the legacy subscription changed to disabled/revision 1 and its legacy delivery to cancelled, while the normal task remained completed and the employee AgentBus delivery remained pending; both new tables existed and had zero forbidden routing/secret columns.
- Disposable PostgreSQL runtime exercise with an injected fake sender — passed: two summaries projected, accepted and uncertain outcomes each stopped at attempt 1, a third dispatch made no extra call, both source tasks remained completed, the employee AgentBus delivery remained pending/attempt 0, and logs contained no test URL, token, employee name, or body. No network request was made.
- Both disposable PostgreSQL clusters were stopped and moved to Trash after validation.
check_project_docs.py— passed.check_doc_drift.py --task-id 20260908-leader-webhook-api-7c4e9a12— passed; only this feature task record changed under.project-docs.
Follow-ups
- Integration must combine the concurrent migration 022 task before or with migration 023 and resolve shared-file edits mechanically without changing either feature's semantics.
- Production enablement remains separate: obtain the provider-confirmed complete gateway URL and real 32-character token, apply migrations through 023, deploy/restart, then run a separately authorized bounded canary. Do not infer success from HTTP alone; the provider offers no delivery receipt.
Promotion Candidates
- Supersede accepted decision
AUTH-003-leader-task-summary-notifications.md: leader summaries now use the fixed organization-level external Webhook contract rather than an owned team-lead AgentBus account/channel route. - Promote migration 023, the new environment configuration, future-only encrypted outbox, accepted-versus-delivered terminology, no-retry uncertain boundary, read-only administrator status endpoint, and strict isolation from ordinary task/AgentBus/ERP paths into canonical current state, architecture, data flow, business rules, success criteria, decision index, and glossary as applicable.