45 lines
2.4 KiB
Markdown
45 lines
2.4 KiB
Markdown
# Task: Integrate server diagnostics into main
|
|
|
|
## Identity
|
|
|
|
- Task ID: 20260831-integrate-server-diagnostics-8b42c6d1
|
|
- Mode: Integration
|
|
- Branch: main
|
|
- Worktree: /Users/inmanx/Documents/lwltAPI
|
|
- Base commit: 14aa6402d6cff52ccf7abb373eb1896e16f6ae98
|
|
- Owner: codex
|
|
- Status: In progress
|
|
|
|
## Scope
|
|
|
|
- Merge the independently advanced `origin/main`, local project-governance/diagnosis commits, and the published WeChat attachment-correlation/diagnostics branch into `main`.
|
|
- Preserve the remote deployment adaptations and Chrome extension `0.5.163` release while retaining the accepted `.project-docs`-only governance boundary.
|
|
- Add production support for attachment URLs that intentionally resolve inside the server environment through an exact, configuration-driven private-host allowlist.
|
|
- Preserve HTTPS, credential rejection, redirect revalidation, DNS pinning, byte limits, declared size, and SHA-256 verification; do not globally permit private/reserved networks.
|
|
- Reconcile accepted promotion candidates into canonical data-flow, business-rule, architecture/current-state, evidence, and deployment documentation where supported.
|
|
- Run all repository gates, commit the integrated result on `main`, and push it to `origin/main`.
|
|
|
|
## Intent And Constraints
|
|
|
|
- The user explicitly authorized merging all current work into `main` and pushing a new revision, and explicitly confirmed that the attachment source is expected to use a private address in the server environment.
|
|
- Private-network compatibility must be opt-in per exact hostname or IP. Empty configuration preserves the existing fail-closed SSRF behavior; wildcards, URL prefixes, paths, credentials, and CIDR-wide bypasses are not accepted.
|
|
- Every initial URL and redirect target must be evaluated independently against the same exact allowlist; logging may record only allowlist presence/count and a boolean match, never the configured host values or attachment URL.
|
|
- Resolve the root planning-file merge according to accepted decision `DOC-001`: remote implementation/release facts and immutable archives are retained, but retired root planning files are not restored as active sources.
|
|
- Do not deploy, restart services, mutate Kubernetes, read secrets, access ERP, retry live tasks, or send external messages.
|
|
|
|
## Outcome
|
|
|
|
- Not completed.
|
|
|
|
## Verification
|
|
|
|
- Not run.
|
|
|
|
## Follow-ups
|
|
|
|
- None recorded.
|
|
|
|
## Promotion Candidates
|
|
|
|
- None recorded.
|