71 lines
8.4 KiB
Markdown
71 lines
8.4 KiB
Markdown
# Current State
|
||
|
||
This file is the integrated default-branch snapshot. Feature tasks record progress in `30-worklog/tasks/{task_id}.md` and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode.
|
||
|
||
## Integrated Through
|
||
|
||
- Commit `c4c469f4441d744627af2d34abe693b6783e833c` for the independently advanced remote deployment/extension line.
|
||
- Commit `cd45ce17d0fcd25f7fa89ab9f8a391d3e904ecdf` for WeChat attachment correlation and privacy-safe server diagnostics.
|
||
- Commit `161f90d09d6ad1368973b1a85d51059059495223` for trusted-intranet attachment compatibility and canonical reconciliation.
|
||
- Integration task `20260831-finalize-main-push-4e1c7a9b` for verified non-force synchronization to `origin/main`.
|
||
- Commit `b08f2960fa4db09c807b6fb61dfba33dc524a274` for the read-only list-attachment behavior inspection record; no product behavior changed.
|
||
- Commit `191c1a1aad6f4bb1651143df3e0c1dc98dcd09e0` for the fixed-scope account system, three-role authorization, owner isolation, operations dashboard, audit/archive behavior, and per-account task-route grants.
|
||
- Integration task `20260901-integrate-account-system-7b2f4d` for canonical authorization reconciliation, migrations 015–017, and the authorized standard-panel restart.
|
||
- Commit `823d1cb6305077e1743f8783176d2cae3b5aec39` for the aggregate-first leadership platform-operations dashboard and business-safe input/result projections.
|
||
- Integration task `20260901-integrate-leadership-dashboard-9e2b6c` for the leadership-dashboard product-definition correction.
|
||
- Merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` from feature task `20260902-registration-invalid-params-59f94692`, with canonical promotion by integration task `20260902-promote-password-flow-c81d42`, for non-empty-only password validation and removal of the first-login forced-password-change workflow.
|
||
- Commit `63b387f` integrating feature commit `6e212b3` from task `20260902-dashboard-nice-scale-d8c31a` for independent dynamic ranking scales with readable headroom above each leading bar.
|
||
- Commit `8dddd21` integrating feature commit `1ee89da` from task `20260902-dashboard-mobile-share-4e91c7` for the focused leadership shell, responsive phone/tablet layout, unified dashboard cards, and the business-facing merge of follow-up work into in-progress.
|
||
- Integration task `20260902-dashboard-mobile-integration-e28c` for canonical reconciliation of the mobile leadership-dashboard behavior.
|
||
- Merge commit `a1b2d2f` integrating source commit `e68fcc1` from task `20260901-roster-header-error-a4f7` for exact ERP-semantic passenger-workbook header detection across rows 1–100, approved aliases, arbitrary column order, and the synchronized `0.5.125` lifecycle Skill and business-instruction DOCX.
|
||
- Integration task `20260902-merge-all-restart-b7e3c91f` for local-branch/worktree reconciliation, canonical roster-contract promotion, full repository/release verification, and the authorized standard-panel restart.
|
||
|
||
## Current Focus
|
||
|
||
Operate the current `0.5.163` extension baseline and the deployed fixed-scope account model safely, provision roles and task grants through administrator workflows, use the aggregate-first leadership dashboard for business oversight, and preserve Program/AI plus ERP execution boundaries.
|
||
|
||
## Recently Completed
|
||
|
||
- 2026-08-28: Initialized `.project-docs/`, migrated durable project memory, and retired the root Planning with Files system into date-scoped history.
|
||
- 2026-08-30: Advanced the synchronized Chrome extension/runtime release to `0.5.163`; Program parser remains `v1.0.6`, input contract/DOCX `0.5.123`, and five business Skills `0.5.125`.
|
||
- 2026-08-28: Added narrow shared-mother-plan whole-visitor export using `shared_plan + visitor-list + tid-only` while preserving child/independent `did+tid` behavior.
|
||
- 2026-08-28: Restarted the standard 8786 control plane under authorization and observed AgentBus 4/4 channels ready across repeated samples.
|
||
- 2026-08-31: Integrated strict WeChat envelope conversation fallback, placeholder-only attachment rejection before task ingestion, and safe attachment error summaries while preserving the original `awaiting_attachment` task.
|
||
- 2026-08-31: Integrated structured privacy-safe diagnostics across service, HTTP, task/audit, parser, AgentBus, attachment, database, and cleanup stages, with bounded Docker stdout retention and a read-only server diagnostic command.
|
||
- 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
|
||
- 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015–017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator.
|
||
- 2026-09-01: Reframed the leadership dashboard from instruction-history/audit presentation to a platform-running view across tasks, people, input, output, time, type, and completion, with clickable drill-through and no visible technical payload language.
|
||
- 2026-09-02: Removed application-level password length limits and the first-login forced-password-change flow while preserving voluntary password changes, administrator resets, session revocation, roles, task ownership, and route authorization.
|
||
- 2026-09-02: Changed the task-type and employee ranking bars from max-item normalization to independent readable dynamic scales, so the leading bar retains visible headroom while operation counts remain the only encoded length.
|
||
- 2026-09-02: Adapted the authenticated leadership dashboard for direct phone and portrait-tablet use, retained the desktop overview, unified the first metric card with the remaining cards, and removed the separate visible “待跟进” category by presenting those internal states as “进行中”.
|
||
- 2026-09-02: Integrated passenger-workbook normalizer `v1.3.0`; one unique complete ERP-semantic header may appear on row 1 through 100 with arbitrary column order and finite approved aliases, while unknown columns, duplicate semantics, multiple candidates, unsafe formulas, and non-passport data continue to fail closed.
|
||
- 2026-09-02: Restarted the standard `127.0.0.1:8786` control plane from current local `main` after the roster integration; liveness, database readiness, schema migration 017, and repeated listener stability checks passed. AgentBus remained enabled but disconnected, matching the pre-restart observation.
|
||
|
||
## In Progress
|
||
|
||
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
|
||
|
||
## Next Recommended Steps
|
||
|
||
1. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
|
||
2. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
|
||
3. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes.
|
||
|
||
## Open Questions / Blockers
|
||
|
||
- Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
|
||
- Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
|
||
- The restarted service now runs current local `main`; a live internal AgentBus attachment verification remains separately unperformed.
|
||
|
||
## Risky Areas
|
||
|
||
- Any ERP write, uncertain post-write state, automatic retry, or scope widening.
|
||
- Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity.
|
||
- AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts.
|
||
- Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
|
||
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
|
||
|
||
## Last Updated
|
||
|
||
2026-09-02
|