Files
LWLT-AIBOT/.project-docs/30-worklog/current-state.md
2026-09-03 09:58:33 +08:00

14 KiB
Raw Blame History

Current State

This file is the integrated default-branch snapshot. Feature tasks record progress in 30-worklog/tasks/{task_id}.md and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode.

Integrated Through

  • Commit c4c469f4441d744627af2d34abe693b6783e833c for the independently advanced remote deployment/extension line.
  • Commit cd45ce17d0fcd25f7fa89ab9f8a391d3e904ecdf for WeChat attachment correlation and privacy-safe server diagnostics.
  • Commit 161f90d09d6ad1368973b1a85d51059059495223 for trusted-intranet attachment compatibility and canonical reconciliation.
  • Integration task 20260831-finalize-main-push-4e1c7a9b for verified non-force synchronization to origin/main.
  • Commit b08f2960fa4db09c807b6fb61dfba33dc524a274 for the read-only list-attachment behavior inspection record; no product behavior changed.
  • Commit 191c1a1aad6f4bb1651143df3e0c1dc98dcd09e0 for the fixed-scope account system, three-role authorization, owner isolation, operations dashboard, audit/archive behavior, and per-account task-route grants.
  • Integration task 20260901-integrate-account-system-7b2f4d for canonical authorization reconciliation, migrations 015–017, and the authorized standard-panel restart.
  • Commit 823d1cb6305077e1743f8783176d2cae3b5aec39 for the aggregate-first leadership platform-operations dashboard and business-safe input/result projections.
  • Integration task 20260901-integrate-leadership-dashboard-9e2b6c for the leadership-dashboard product-definition correction.
  • Merge commit 029c8c6a59215cb6c3f8d7f126c4313730b2abb2 from feature task 20260902-registration-invalid-params-59f94692, with canonical promotion by integration task 20260902-promote-password-flow-c81d42, for non-empty-only password validation and removal of the first-login forced-password-change workflow.
  • Commit 63b387f integrating feature commit 6e212b3 from task 20260902-dashboard-nice-scale-d8c31a for independent dynamic ranking scales with readable headroom above each leading bar.
  • Commit 8dddd21 integrating feature commit 1ee89da from task 20260902-dashboard-mobile-share-4e91c7 for the focused leadership shell, responsive phone/tablet layout, unified dashboard cards, and the business-facing merge of follow-up work into in-progress.
  • Integration task 20260902-dashboard-mobile-integration-e28c for canonical reconciliation of the mobile leadership-dashboard behavior.
  • Merge commit a1b2d2f integrating source commit e68fcc1 from task 20260901-roster-header-error-a4f7 for exact ERP-semantic passenger-workbook header detection across rows 1–100, approved aliases, arbitrary column order, and the synchronized 0.5.125 lifecycle Skill and business-instruction DOCX.
  • Integration task 20260902-merge-all-restart-b7e3c91f for local-branch/worktree reconciliation, canonical roster-contract promotion, full repository/release verification, and the authorized standard-panel restart.
  • Commit 3062ed5 from task 20260902-kanban-filter-7e3a91c4 for bounded single-connection leadership-dashboard queries, SQL business prefiltering, selective search hydration, 20-row pages, cancellation propagation, and timeout feedback.
  • Merge commit b5f5847 integrating source commit 6f9fd0f from task 20260902-agentbus-account-routing-b62f19e4 for employee-owned AgentBus channels, immutable task assignees, matching single-browser ERP workers, migration 018, and extension 0.5.164.
  • Merge commit cc09506 integrating source commit b1fe533 from task 20260902-dashboard-metrics-static-a91c for display-only dashboard metric cards and explicit status filtering.
  • Integration task 20260902-integrate-all-push-c93a7f21 for all-worktree reconciliation, semantic merge resolution, canonical promotion, full verification, and synchronization of main to origin/main.
  • Merge commit 336ca6e integrating source commit b26001e from task 20260902-account-permission-ui-6c9e21ad for a scroll-safe account task-permission editor layout and focused regression coverage.
  • Merge commit e4fd916 integrating source commit b5c727b from task 20260902-diagnose-parse-error-7f3a9c2d for native non-empty ERP product search in scatter-plan creation and independent batch-order creation, synchronized as extension 0.5.165.
  • Integration task 20260902-integrate-product-search-3b7f6a20 for canonical product-search promotion, full release verification, and normal non-force synchronization to origin/main.
  • Commit d09b303 from task 20260902-per-account-queue-hard-delete-a6d9f2c1 for account-scoped ERP FIFO, strict assignee-only executable routing, and explicit lifecycle-independent physical force deletion.
  • Integration task 20260903-finalize-account-routing-7c4e2a91 for AUTH-002 acceptance, canonical queue/removal reconciliation, full repository verification, and normal non-force synchronization to origin/main.

Current Focus

Operate the repository's current 0.5.165 extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator visibility never enters another account's executable event/result path. Migration 018, extension reload, guarded product-search retry, and service rollout remain separately authorized runtime work.

Recently Completed

  • 2026-08-28: Initialized .project-docs/, migrated durable project memory, and retired the root Planning with Files system into date-scoped history.
  • 2026-08-30: Advanced the synchronized Chrome extension/runtime release to 0.5.163; Program parser remains v1.0.6, input contract/DOCX 0.5.123, and five business Skills 0.5.125.
  • 2026-08-28: Added narrow shared-mother-plan whole-visitor export using shared_plan + visitor-list + tid-only while preserving child/independent did+tid behavior.
  • 2026-08-28: Restarted the standard 8786 control plane under authorization and observed AgentBus 4/4 channels ready across repeated samples.
  • 2026-08-31: Integrated strict WeChat envelope conversation fallback, placeholder-only attachment rejection before task ingestion, and safe attachment error summaries while preserving the original awaiting_attachment task.
  • 2026-08-31: Integrated structured privacy-safe diagnostics across service, HTTP, task/audit, parser, AgentBus, attachment, database, and cleanup stages, with bounded Docker stdout retention and a read-only server diagnostic command.
  • 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
  • 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015–017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator.
  • 2026-09-01: Reframed the leadership dashboard from instruction-history/audit presentation to a platform-running view across tasks, people, input, output, time, type, and completion, with clickable drill-through and no visible technical payload language.
  • 2026-09-02: Removed application-level password length limits and the first-login forced-password-change flow while preserving voluntary password changes, administrator resets, session revocation, roles, task ownership, and route authorization.
  • 2026-09-02: Changed the task-type and employee ranking bars from max-item normalization to independent readable dynamic scales, so the leading bar retains visible headroom while operation counts remain the only encoded length.
  • 2026-09-02: Adapted the authenticated leadership dashboard for direct phone and portrait-tablet use, retained the desktop overview, unified the first metric card with the remaining cards, and removed the separate visible “待跟进” category by presenting those internal states as “进行中”.
  • 2026-09-02: Integrated passenger-workbook normalizer v1.3.0; one unique complete ERP-semantic header may appear on row 1 through 100 with arbitrary column order and finite approved aliases, while unknown columns, duplicate semantics, multiple candidates, unsafe formulas, and non-passport data continue to fail closed.
  • 2026-09-02: Restarted the standard 127.0.0.1:8786 control plane from current local main after the roster integration; liveness, database readiness, schema migration 017, and repeated listener stability checks passed. AgentBus remained enabled but disconnected, matching the pre-restart observation.
  • 2026-09-02: Integrated migration 018 and extension 0.5.164 so each enabled AgentBus channel binds one non-admin employee, each task keeps an immutable execution assignee, administrators cannot execute another assignee's work, and only one fresh browser with the matching ERP account is execution-ready.
  • 2026-09-02: Reworked leadership-dashboard reads into a bounded one-connection transaction with business SQL prefiltering, selective message hydration, page-only detail hydration, request/database deadlines, and 20-row pages; metric cards are now display-only and explicit filters default to all results.
  • 2026-09-02: Corrected the account-management task-permission editor so opening it expands a dedicated five-row layout, keeps the account list below the editor, and allows vertical page scrolling on desktop and narrow screens without changing authorization semantics.
  • 2026-09-02: Integrated extension 0.5.165: scatter-plan creation and independent batch-order creation now try loaded product candidates, then the form's native non-empty S_chanpinming search, and finally one bounded empty-query compatibility reload. A user-authorized search-only ERP check returned exactly one target row in both forms without selecting or saving it; zero or multiple local matches continue to fail closed.
  • 2026-09-03: Accepted AUTH-002 and integrated account-scoped ERP queues. Each immutable assignee now owns one FIFO/single-active claim partition, different accounts no longer block one another, and executable SSE/results/cleanup commands are owner-only even when an administrator is signed in.
  • 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back.

In Progress

  • The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
  • Migration 018_agentbus_account_workers, employee ERP identities/channel bindings, extension 0.5.165, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/runtime changes have not been applied to or restarted on the standard service in this integration task.
  1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply migration 018, restart the control plane, load extension 0.5.165, verify its runtime handshake, configure employee ERP identities and channel bindings, and run the multi-cloud-PC/identity/failover plus account-queue matrix before production assurance.
  2. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes.
  3. In the same authorized staging window, verify that an administrator receives no employee executable events/results, then force-delete disposable waiting and active employee tasks and confirm database absence plus cleanup only in the owning employee plugin.
  4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan tid-only whole-visitor export path.
  5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.

Open Questions / Blockers

  • Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
  • Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
  • The standard service was last restarted before commits 3062ed5, b5f5847, cc09506, 336ca6e, e4fd916, and d09b303; its runtime schema, extension, account UI, queue/routing, force-delete, and dashboard behavior must not be represented as the newly integrated repository state until an authorized rollout.
  • AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering mismatched ERP login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator executable-feed isolation, and both manual and automatic channel work.
  • Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
  • A live internal AgentBus attachment verification remains separately unperformed.

Risky Areas

  • Any ERP write, uncertain post-write state, automatic retry, or scope widening.
  • Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity.
  • AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts.
  • Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
  • AgentBus channel ownership, immutable task assignment, expected ERP identity, browser-worker freshness/failover, and administrator non-execution are security- and write-safety-sensitive boundaries.
  • Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
  • Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and dist/release-manifest.json.

Last Updated

2026-09-03