2.4 KiB
2.4 KiB
Task: Integrate server diagnostics into main
Identity
- Task ID: 20260831-integrate-server-diagnostics-8b42c6d1
- Mode: Integration
- Branch: main
- Worktree: /Users/inmanx/Documents/lwltAPI
- Base commit:
14aa6402d6 - Owner: codex
- Status: In progress
Scope
- Merge the independently advanced
origin/main, local project-governance/diagnosis commits, and the published WeChat attachment-correlation/diagnostics branch intomain. - Preserve the remote deployment adaptations and Chrome extension
0.5.163release while retaining the accepted.project-docs-only governance boundary. - Add production support for attachment URLs that intentionally resolve inside the server environment through an exact, configuration-driven private-host allowlist.
- Preserve HTTPS, credential rejection, redirect revalidation, DNS pinning, byte limits, declared size, and SHA-256 verification; do not globally permit private/reserved networks.
- Reconcile accepted promotion candidates into canonical data-flow, business-rule, architecture/current-state, evidence, and deployment documentation where supported.
- Run all repository gates, commit the integrated result on
main, and push it toorigin/main.
Intent And Constraints
- The user explicitly authorized merging all current work into
mainand pushing a new revision, and explicitly confirmed that the attachment source is expected to use a private address in the server environment. - Private-network compatibility must be opt-in per exact hostname or IP. Empty configuration preserves the existing fail-closed SSRF behavior; wildcards, URL prefixes, paths, credentials, and CIDR-wide bypasses are not accepted.
- Every initial URL and redirect target must be evaluated independently against the same exact allowlist; logging may record only allowlist presence/count and a boolean match, never the configured host values or attachment URL.
- Resolve the root planning-file merge according to accepted decision
DOC-001: remote implementation/release facts and immutable archives are retained, but retired root planning files are not restored as active sources. - Do not deploy, restart services, mutate Kubernetes, read secrets, access ERP, retry live tasks, or send external messages.
Outcome
- Not completed.
Verification
- Not run.
Follow-ups
- None recorded.
Promotion Candidates
- None recorded.