Files
LWLT-AIBOT/.project-docs/30-worklog/tasks/20260831-integrate-server-diagnostics-8b42c6d1.md
T

2.4 KiB

Task: Integrate server diagnostics into main

Identity

  • Task ID: 20260831-integrate-server-diagnostics-8b42c6d1
  • Mode: Integration
  • Branch: main
  • Worktree: /Users/inmanx/Documents/lwltAPI
  • Base commit: 14aa6402d6
  • Owner: codex
  • Status: In progress

Scope

  • Merge the independently advanced origin/main, local project-governance/diagnosis commits, and the published WeChat attachment-correlation/diagnostics branch into main.
  • Preserve the remote deployment adaptations and Chrome extension 0.5.163 release while retaining the accepted .project-docs-only governance boundary.
  • Add production support for attachment URLs that intentionally resolve inside the server environment through an exact, configuration-driven private-host allowlist.
  • Preserve HTTPS, credential rejection, redirect revalidation, DNS pinning, byte limits, declared size, and SHA-256 verification; do not globally permit private/reserved networks.
  • Reconcile accepted promotion candidates into canonical data-flow, business-rule, architecture/current-state, evidence, and deployment documentation where supported.
  • Run all repository gates, commit the integrated result on main, and push it to origin/main.

Intent And Constraints

  • The user explicitly authorized merging all current work into main and pushing a new revision, and explicitly confirmed that the attachment source is expected to use a private address in the server environment.
  • Private-network compatibility must be opt-in per exact hostname or IP. Empty configuration preserves the existing fail-closed SSRF behavior; wildcards, URL prefixes, paths, credentials, and CIDR-wide bypasses are not accepted.
  • Every initial URL and redirect target must be evaluated independently against the same exact allowlist; logging may record only allowlist presence/count and a boolean match, never the configured host values or attachment URL.
  • Resolve the root planning-file merge according to accepted decision DOC-001: remote implementation/release facts and immutable archives are retained, but retired root planning files are not restored as active sources.
  • Do not deploy, restart services, mutate Kubernetes, read secrets, access ERP, retry live tasks, or send external messages.

Outcome

  • Not completed.

Verification

  • Not run.

Follow-ups

  • None recorded.

Promotion Candidates

  • None recorded.