Files
LWLT-AIBOT/.project-docs/30-worklog/current-state.md
2026-09-03 17:33:27 +08:00

16 KiB
Raw Blame History

Current State

This file is the integrated default-branch snapshot. Feature tasks record progress in 30-worklog/tasks/{task_id}.md and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode.

Integrated Through

  • Correction commit fe1cc2cddc29e4dead81e53c16d31bb71493602d from integration task 20260903-backup-revert-extension-update-c71a4e92 preserved the complete former 0.5.167/migration-019 stack at remote branch codex/backup-extension-update-20260903-b2e33e2, removed the central private-OSS/ECS automatic-update service architecture without rewriting history, and retained the exact Chrome extension 0.5.167 source/package on the active main line with migration 018.
  • Merge commit 3224758 and integration task 20260903-finalize-extension-update-a6c4e192 remain historical records of the full-stack extension-update design. Only the plugin 0.5.167 release, adaptive entry readiness, and dormant plugin-side idle/reload safeguards remain active; the server orchestration is preserved on the backup branch only.
  • Commit c4c469f4441d744627af2d34abe693b6783e833c for the independently advanced remote deployment/extension line.
  • Commit cd45ce17d0fcd25f7fa89ab9f8a391d3e904ecdf for WeChat attachment correlation and privacy-safe server diagnostics.
  • Commit 161f90d09d6ad1368973b1a85d51059059495223 for trusted-intranet attachment compatibility and canonical reconciliation.
  • Integration task 20260831-finalize-main-push-4e1c7a9b for verified non-force synchronization to origin/main.
  • Commit b08f2960fa4db09c807b6fb61dfba33dc524a274 for the read-only list-attachment behavior inspection record; no product behavior changed.
  • Commit 191c1a1aad6f4bb1651143df3e0c1dc98dcd09e0 for the fixed-scope account system, three-role authorization, owner isolation, operations dashboard, audit/archive behavior, and per-account task-route grants.
  • Integration task 20260901-integrate-account-system-7b2f4d for canonical authorization reconciliation, migrations 015017, and the authorized standard-panel restart.
  • Commit 823d1cb6305077e1743f8783176d2cae3b5aec39 for the aggregate-first leadership platform-operations dashboard and business-safe input/result projections.
  • Integration task 20260901-integrate-leadership-dashboard-9e2b6c for the leadership-dashboard product-definition correction.
  • Merge commit 029c8c6a59215cb6c3f8d7f126c4313730b2abb2 from feature task 20260902-registration-invalid-params-59f94692, with canonical promotion by integration task 20260902-promote-password-flow-c81d42, for non-empty-only password validation and removal of the first-login forced-password-change workflow.
  • Commit 63b387f integrating feature commit 6e212b3 from task 20260902-dashboard-nice-scale-d8c31a for independent dynamic ranking scales with readable headroom above each leading bar.
  • Commit 8dddd21 integrating feature commit 1ee89da from task 20260902-dashboard-mobile-share-4e91c7 for the focused leadership shell, responsive phone/tablet layout, unified dashboard cards, and the business-facing merge of follow-up work into in-progress.
  • Integration task 20260902-dashboard-mobile-integration-e28c for canonical reconciliation of the mobile leadership-dashboard behavior.
  • Merge commit a1b2d2f integrating source commit e68fcc1 from task 20260901-roster-header-error-a4f7 for exact ERP-semantic passenger-workbook header detection across rows 1100, approved aliases, arbitrary column order, and the synchronized 0.5.125 lifecycle Skill and business-instruction DOCX.
  • Integration task 20260902-merge-all-restart-b7e3c91f for local-branch/worktree reconciliation, canonical roster-contract promotion, full repository/release verification, and the authorized standard-panel restart.
  • Commit 3062ed5 from task 20260902-kanban-filter-7e3a91c4 for bounded single-connection leadership-dashboard queries, SQL business prefiltering, selective search hydration, 20-row pages, cancellation propagation, and timeout feedback.
  • Merge commit b5f5847 integrating source commit 6f9fd0f from task 20260902-agentbus-account-routing-b62f19e4 for employee-owned AgentBus channels, immutable task assignees, matching single-browser ERP workers, migration 018, and extension 0.5.164.
  • Merge commit cc09506 integrating source commit b1fe533 from task 20260902-dashboard-metrics-static-a91c for display-only dashboard metric cards and explicit status filtering.
  • Integration task 20260902-integrate-all-push-c93a7f21 for all-worktree reconciliation, semantic merge resolution, canonical promotion, full verification, and synchronization of main to origin/main.
  • Merge commit 336ca6e integrating source commit b26001e from task 20260902-account-permission-ui-6c9e21ad for a scroll-safe account task-permission editor layout and focused regression coverage.
  • Merge commit e4fd916 integrating source commit b5c727b from task 20260902-diagnose-parse-error-7f3a9c2d for native non-empty ERP product search in scatter-plan creation and independent batch-order creation, synchronized as extension 0.5.165.
  • Integration task 20260902-integrate-product-search-3b7f6a20 for canonical product-search promotion, full release verification, and normal non-force synchronization to origin/main.
  • Commit d09b303 from task 20260902-per-account-queue-hard-delete-a6d9f2c1 for account-scoped ERP FIFO, strict assignee-only executable routing, and explicit lifecycle-independent physical force deletion.
  • Integration task 20260903-finalize-account-routing-7c4e2a91 for AUTH-002 acceptance, canonical queue/removal reconciliation, full repository verification, and normal non-force synchronization to origin/main.

Current Focus

Operate the repository's current 0.5.167 extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator visibility never enters another account's executable event/result path. Migration 018, manual extension reload, guarded product-search retry, and service rollout remain separately authorized runtime work; server-side automatic extension updating is not part of the active main line.

Recently Completed

  • 2026-08-28: Initialized .project-docs/, migrated durable project memory, and retired the root Planning with Files system into date-scoped history.
  • 2026-08-30: Advanced the synchronized Chrome extension/runtime release to 0.5.163; Program parser remains v1.0.6, input contract/DOCX 0.5.123, and five business Skills 0.5.125.
  • 2026-08-28: Added narrow shared-mother-plan whole-visitor export using shared_plan + visitor-list + tid-only while preserving child/independent did+tid behavior.
  • 2026-08-28: Restarted the standard 8786 control plane under authorization and observed AgentBus 4/4 channels ready across repeated samples.
  • 2026-08-31: Integrated strict WeChat envelope conversation fallback, placeholder-only attachment rejection before task ingestion, and safe attachment error summaries while preserving the original awaiting_attachment task.
  • 2026-08-31: Integrated structured privacy-safe diagnostics across service, HTTP, task/audit, parser, AgentBus, attachment, database, and cleanup stages, with bounded Docker stdout retention and a read-only server diagnostic command.
  • 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
  • 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator.
  • 2026-09-01: Reframed the leadership dashboard from instruction-history/audit presentation to a platform-running view across tasks, people, input, output, time, type, and completion, with clickable drill-through and no visible technical payload language.
  • 2026-09-02: Removed application-level password length limits and the first-login forced-password-change flow while preserving voluntary password changes, administrator resets, session revocation, roles, task ownership, and route authorization.
  • 2026-09-02: Changed the task-type and employee ranking bars from max-item normalization to independent readable dynamic scales, so the leading bar retains visible headroom while operation counts remain the only encoded length.
  • 2026-09-02: Adapted the authenticated leadership dashboard for direct phone and portrait-tablet use, retained the desktop overview, unified the first metric card with the remaining cards, and removed the separate visible “待跟进” category by presenting those internal states as “进行中”.
  • 2026-09-02: Integrated passenger-workbook normalizer v1.3.0; one unique complete ERP-semantic header may appear on row 1 through 100 with arbitrary column order and finite approved aliases, while unknown columns, duplicate semantics, multiple candidates, unsafe formulas, and non-passport data continue to fail closed.
  • 2026-09-02: Restarted the standard 127.0.0.1:8786 control plane from current local main after the roster integration; liveness, database readiness, schema migration 017, and repeated listener stability checks passed. AgentBus remained enabled but disconnected, matching the pre-restart observation.
  • 2026-09-02: Integrated migration 018 and extension 0.5.164 so each enabled AgentBus channel binds one non-admin employee, each task keeps an immutable execution assignee, administrators cannot execute another assignee's work, and only one fresh browser with the matching ERP account is execution-ready.
  • 2026-09-02: Reworked leadership-dashboard reads into a bounded one-connection transaction with business SQL prefiltering, selective message hydration, page-only detail hydration, request/database deadlines, and 20-row pages; metric cards are now display-only and explicit filters default to all results.
  • 2026-09-02: Corrected the account-management task-permission editor so opening it expands a dedicated five-row layout, keeps the account list below the editor, and allows vertical page scrolling on desktop and narrow screens without changing authorization semantics.
  • 2026-09-02: Integrated extension 0.5.165: scatter-plan creation and independent batch-order creation now try loaded product candidates, then the form's native non-empty S_chanpinming search, and finally one bounded empty-query compatibility reload. A user-authorized search-only ERP check returned exactly one target row in both forms without selecting or saving it; zero or multiple local matches continue to fail closed.
  • 2026-09-03: Accepted AUTH-002 and integrated account-scoped ERP queues. Each immutable assignee now owns one FIFO/single-active claim partition, different accounts no longer block one another, and executable SSE/results/cleanup commands are owner-only even when an administrator is signed in.
  • 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back.
  • 2026-09-03: Backed up the complete adaptive-readiness and central extension-update stack at remote branch codex/backup-extension-update-20260903-b2e33e2, then removed the central OSS/ECS update service and migration 019 from main with normal history-preserving commits. After correcting an initially over-broad rollback, the active repository retains the exact extension 0.5.167 source/package and uses migration 018; the removed server architecture was never deployed by these tasks.

In Progress

  • The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
  • Migration 018_agentbus_account_workers, employee ERP identities/channel bindings, extension 0.5.167, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/runtime changes have not been applied to or restarted on the standard service in this integration task.
  1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply migration 018, restart the control plane, manually load extension 0.5.167, verify its runtime handshake, configure employee ERP identities and channel bindings, and run the multi-cloud-PC/identity/failover plus account-queue matrix before production assurance.
  2. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes.
  3. In the same authorized staging window, verify that an administrator receives no employee executable events/results, then force-delete disposable waiting and active employee tasks and confirm database absence plus cleanup only in the owning employee plugin.
  4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan tid-only whole-visitor export path.
  5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.

Open Questions / Blockers

  • Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
  • Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
  • The standard service was last restarted before commits 3062ed5, b5f5847, cc09506, 336ca6e, e4fd916, and d09b303; its runtime schema, extension, account UI, queue/routing, force-delete, and dashboard behavior must not be represented as the newly integrated repository state until an authorized rollout.
  • AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering mismatched ERP login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator executable-feed isolation, and both manual and automatic channel work.
  • Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
  • A live internal AgentBus attachment verification remains separately unperformed.

Risky Areas

  • Any ERP write, uncertain post-write state, automatic retry, or scope widening.
  • Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity.
  • AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts.
  • Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
  • AgentBus channel ownership, immutable task assignment, expected ERP identity, browser-worker freshness/failover, and administrator non-execution are security- and write-safety-sensitive boundaries.
  • Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
  • Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and dist/release-manifest.json.

Last Updated

2026-09-03