Commit Graph
67 Commits
Author SHA1 Message Date
chenchenandClaude Opus 4.8 0fe1d20d67 feat(agent): unify agnet→agent and implement client/runtime unification spec v0.1 core
按桌面客户端统一方案 v0.1 + agent_management Sub Mode Runtime 对接,强制全量统一,不留兼容。

命名统一(强制,无兼容):
- 全仓 agnet/Agnet/AGNET → agent/Agent/AGENT:后端 Go(路由 /api/agent/*、env AGENT_*、
  结构体/函数、19 个文件改名)、前端(agent-console/agent-hub、/api/agent 调用、i18n)、
  DB(表 agent_*、列 agent_id)、compose/.env、文档、脚本。
- DB 加幂等迁移 renameAgnetTablesToAgent():启动时 rename 老 agnet_* 表/列,保住生产数据。

统一方案核心(10 项):
- callback 统一 /api/agent/callbacks/runtime-events(路由/广播URL/函数名)。
- artifact 兜底判定改用 Runtime 权威信号 metadata.synthesized(§7.2)+ 结构化 artifact_type。
- Manager→Runtime 路径对齐 /api/agent/sub-agile/deployments(§2.2),{deployment_id} 回退 swarm_id。
- 状态裁决 display_status:Manager 唯一裁判,completed 无有效产物→needs_codegen/
  completed_without_deliverable(§10.6),接入 detail/timeline/workflow。
- GET /api/heicode/capabilities 能力发现(§6)。
- 模型策略 per_role(role_models)+ 收集 allowed_model_ids(§9)。
- resource_binding_id→secret_ref 服务端解析,客户端不再 inline secret_ref(§17.6)。
- 客户端统一路由层 /api/heicode/sub-agile|swarm/*(task≡deployment,复用控制面)+ workflow 投影。
- 日志分层 user_logs/debug_logs(§13)。

验证:go build ./... + go test(controller/router/model/middleware)全绿;前端 tsc -b + rsbuild build 通过。
待部署:VM .env 的 AGNET_*→AGENT_*;启动迁移自动 rename 表;其他三仓库需同步切到 /api/agent。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-01 23:45:10 +08:00
chenchenandClaude Opus 4.8 12602ebcd6 fix(agnet): structured deliverable judgment, secret_ref validation, single default model
代码评审(2026-06-01 全链路报告)中 Manager 侧自主可修项:

- P2 交付物判定: runtimeArtifactsAreSummaryOnly 改为优先读结构化字段
  (artifact_type + files_modified 信号),修复 Runtime 新 uri scheme 与
  artifact_type=document 被旧 /artifacts/summary 字符串启发式漏判的回归。
- P6a: Resource CRUD(normalizeResourcePayload)强制 secret_ref 必须 azkv://,
  与 agnet 部署/审批路径一致,堵住直写任意 secret_ref 的旁路。
- P6b: 明文密钥检测从仅按字段名升级为同时扫字符串值(sk-/ghp_/AKIA/JWT/PEM
  等高置信模式),containsPlaintextSecret 与 containsSensitiveGrantField 均覆盖。
- P5 默认模型收敛: 新增单一来源 defaultAgnetModelID()(env AGNET_DEFAULT_MODEL_ID,
  默认生产已验证的 gpt-5.4);移除 draft 构造器两处 agnet-model-<role> 占位回退
  (生产 NewAPI "No available channel" 根因)与角色模板硬编码 claude-* 默认。
- P3 文档: 对接文档状态枚举补 completed 终态、runtime_state 镜像说明与未知值兜底;
  role-templates 示例占位名改为 gpt-5.4。

新增 controller/agnet_deliverable_secret_test.go 覆盖以上行为。
go build ./... 与 go test ./controller/ 全绿。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-01 17:33:32 +08:00
gongzhiyong be5b9996d9 docs: clarify desktop sub artifact handling
Document how the desktop client should classify and display sub-mode artifacts, including summary-only outputs and markdown code documents.

Constraint: Keep interface paths stable; update display and validation rules only

Confidence: high

Scope-risk: narrow

Not-tested: Documentation-only change; git diff --check passed
2026-06-01 01:48:27 +08:00
gongzhiyong 1d5bc81b38 docs: refresh sub runtime verification
Record the 2026-05-31 production Manager smoke result for ordinary sub mode after the Agent Manager Runtime image update.

Constraint: Keep ordinary sub mode separate from swarm mode and document real production ids only

Confidence: high

Scope-risk: narrow

Not-tested: Documentation-only change; git diff --check passed
2026-05-31 22:50:24 +08:00
gongzhiyong 8e56284baa fix: polish manager account pages 2026-05-30 15:37:28 +08:00
gongzhiyong 8a43018cf5 docs: update desktop sub agile integration guide 2026-05-30 14:39:26 +08:00
gongzhiyong 8c1d9461f4 fix: use valid default agnet runtime models 2026-05-30 14:15:01 +08:00
gongzhiyong edf7aeaf8a feat: add agnet artifact content proxy 2026-05-30 12:55:04 +08:00
gongzhiyong 70663f47ee fix: separate swarm runtime integration
Add separate Runtime mode selection for ordinary sub and swarm flows, including Swarm-specific create payload shaping and Azure VM env wiring. Document the ordinary sub artifact callback gap, swarm runtime findings, PayPal billing boundaries, deployment migration requirements, and desktop/API progress.

Constraint: Keep ordinary sub and HeiCode-Swarm Runtime deployments separate

Confidence: high

Scope-risk: moderate

Tests: go test ./...
2026-05-29 17:31:24 +08:00
gongzhiyong ed9136d29d docs: list remaining agent manager sub requirements 2026-05-28 21:56:17 +08:00
gongzhiyong fecb365e87 fix: complete sub callback agent state 2026-05-28 21:30:53 +08:00
gongzhiyong 8e7bdc6388 fix: sync sub runtime callback state 2026-05-28 21:24:02 +08:00
gongzhiyong 704579f03e fix: normalize agnet runtime callbacks 2026-05-28 20:33:38 +08:00
gongzhiyong 61e060909d fix: localize agnet detail copy 2026-05-28 19:15:41 +08:00
gongzhiyong 7d7c163f37 fix: localize agnet form field labels 2026-05-28 19:03:51 +08:00
gongzhiyong 53cc1a5e63 fix: localize agnet role and resource labels 2026-05-28 18:51:43 +08:00
gongzhiyong 587746db90 fix: localize agnet create run sheet 2026-05-28 18:43:08 +08:00
gongzhiyong 72cbf43dec fix: localize agnet drawer status text 2026-05-28 18:24:07 +08:00
gongzhiyong fd02edcd52 fix: localize simulated agnet status 2026-05-28 18:16:06 +08:00
gongzhiyong efaac446ab fix: localize agnet console copy 2026-05-28 18:08:18 +08:00
gongzhiyong d2f7ab7333 fix: enable encrypted swarm requests 2026-05-28 16:58:27 +08:00
gongzhiyong 7f9f70b1dc docs: add agent manager sub integration requirements 2026-05-28 16:06:52 +08:00
gongzhiyong 8075891770 feat: document and expose swarm runtime contract 2026-05-28 11:57:58 +08:00
gongzhiyong ee5342c404 docs: rename agent manager action lists 2026-05-28 01:30:09 +08:00
gongzhiyong 6848f1a101 docs: add agent manager integration action lists 2026-05-28 01:28:05 +08:00
gongzhiyong 10fc64e172 feat: complete sub task flow callbacks 2026-05-27 23:31:57 +08:00
gongzhiyong 4ccf7b1062 feat: complete swarm manager callback loop 2026-05-27 21:17:32 +08:00
gongzhiyong 741cc0d254 docs: update desktop sub encrypted request flow 2026-05-27 18:46:32 +08:00
gongzhiyong 9f5b4ba777 feat: encrypt desktop sub requests 2026-05-27 18:15:29 +08:00
gongzhiyong f466c40545 docs: update desktop sub agile integration flow 2026-05-27 17:53:04 +08:00
gongzhiyong 5fc0532ec1 fix: propagate agnet runtime stop 2026-05-27 15:19:57 +08:00
gongzhiyong beaf1e6611 fix: align runtime create payload with agnet 2026-05-27 15:03:48 +08:00
gongzhiyong 50b76dd4e6 feat: align agnet runtime v2.1 integration 2026-05-27 11:04:08 +08:00
gongzhiyong 8a6fea235e fix: restrict agnet simulation controls 2026-05-26 18:41:26 +08:00
gongzhiyong 2cc5e667df feat: complete manager agnet callback timeline 2026-05-26 18:38:24 +08:00
gongzhiyong 0abd761d66 feat: add manager sub deployment bridge 2026-05-26 18:23:23 +08:00
gongzhiyong 6562acaa62 docs: add manager standalone execution plan 2026-05-26 18:02:40 +08:00
gongzhiyong 99776d18af docs: refine sub swarm progress checklist 2026-05-26 17:54:37 +08:00
gongzhiyong cc148b15c3 docs: add sub swarm progress checklist 2026-05-26 17:46:51 +08:00
gongzhiyong d16b2ca1d5 fix: correct admin sidebar model links 2026-05-26 16:51:36 +08:00
gongzhiyong d02685dd5e fix: correct admin sidebar model links 2026-05-26 16:42:29 +08:00
gongzhiyong a80c3e0c35 feat: release manager 1.4.4 agnet persistence 2026-05-26 16:01:49 +08:00
gongzhiyong 1ebaa1ccce fix: move signup email hint below email field 2026-05-25 18:08:17 +08:00
gongzhiyong 07b307c094 fix: place signup email hint under email field 2026-05-25 17:57:09 +08:00
gongzhiyong e1b9de2a49 feat: add azure key vault resource discovery 2026-05-25 17:41:43 +08:00
chenchen 23ec354eb5 更新 2026-05-25 16:03:00 +08:00
chenchenandClaude Opus 4.7 da81c57db2 feat(cloud): Azure subscription binding via Service Principal (M2 phase 1)
Sprint 13. Lifts the resource-binding wizard's "Connect cloud account"
step from a disabled "Coming soon" button to a real binding flow,
scoped to Azure for now (AWS / GCP coming soon).

What ships:
  - New AzureCloudBindingSheet — Service Principal credentials form
    (subscription_id / tenant_id / client_id / client_secret + display
    name)
  - Creates a mcp-server ResourceBinding of type 'cloud_account' with
    provider=azure metadata, permission_scope=['azure:read'], status
    flips between 'active' (vault configured) and 'pending' (vault
    not yet wired)
  - Sheet shows a yellow warning when OpenBao isn't configured,
    explaining that client_secret will NOT be persisted server-side
    until vault is online — operators re-enter or rotate the secret
    once vault is up
  - Explicit "what Heicode will / will not do" footer card per
    product docs §13.9 — read-only ARM, never modify without desktop
    approval, never log client_secret
  - Cloud step "Connect" button now opens this sheet (was disabled)
  - Wizard summary description updated: AWS/GCP labelled coming soon
    instead of implying all three providers ship today

Phase 2 (Azure OAuth code flow) + phase 3 (ARM auto-discovery) need
Azure App Registration + OpenBao online first — separate sprints.

i18n localized en + zh.

Verification:
  - tsc --noEmit clean
  - no backend change — leverages existing mcp-server ResourceBinding
    endpoint which already supports cloud_account type

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 14:53:34 +08:00
chenchenandClaude Opus 4.7 cdcc864298 feat(states): unified QueryState wrapper covers permission + network errors
Sprint 11 — closes M13 ("七态完整性") on the three highest-traffic
pages (Deployments, Events, Audit). Earlier behaviour was binary
(loading skeleton OR card list); 401/403 and offline both fell
through to a toast or a blank page.

New /components/query-state.tsx:
  - One wrapper that takes isLoading + error + isEmpty + retry
  - classifyError reads axios + fetch shapes; maps to 'permission'
    / 'network' / 'generic'
  - Permission state: ShieldOff icon, no retry button (admins must
    grant access; retry would just 401 again)
  - Network state: WifiOff icon, retry wired
  - Generic state: AlertTriangle + retry + decoded error.message
  - Empty state: passthrough to existing EmptyState
  - Loading: passthrough to caller's loadingFallback or 3 skeleton rows

Applied to:
  - AgnetDeploymentsPage (replaces inline loading/empty ternary)
  - AgnetAuditPage (same)
  - AgnetEventsPage (wraps the events ol)

In all three, the existing useQuery now also surfaces error + refetch.
retry: false set so QueryState handles error display directly
instead of TanStack retrying 3 times silently.

i18n strings added for 5 new copy keys (permission denied, network
unreachable, retry, load failed) in en + zh.

Verification:
  - tsc --noEmit clean
  - no backend change

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 14:48:31 +08:00
chenchenandClaude Opus 4.7 d8f61957f0 feat(manager): version 1.4.2 — H2 sk- hash + M9 audit drawer + M3 docs + M7 vault
Bundled release bumping Manager to 1.4.2 with four product-doc gap
closures lined up in a single deploy.

VERSION:
  - 1.2.0 → 1.4.2 (catches up after Sprints 1-5 shipped under 1.2.0)

H2 — sk- hash phase A (server-side, zero client impact):
  - tokens table: new key_hash varchar(64) index column
  - Token.Insert() dual-writes Key + KeyHash on every new token
  - BackfillTokenKeyHash() runs at startup, batches 500 rows at a
    time, idempotent. Fills legacy rows that pre-date the column
    without blocking app boot
  - 5 unit tests pin: sha256 correctness, dual-write on Insert,
    empty Key → empty hash, backfill behaviour, idempotency
  - Phase B (switch lookup index off plaintext + drop Key column)
    can ship later once telemetry shows key_hash IS NULL count is 0

M9 — task detail drawer with audit timeline:
  - Deployments page click → Sheet drawer with RunDetailPanel +
    new RunAuditTimeline component
  - Timeline pulls from existing /api/agnet/deployments/:id/events
    which Sprint 1 already wired to the persistent
    agnet_audit_events table — no new backend
  - Vertical timeline w/ coloured dots (primary / amber / rose by
    classifyEventLevel), occurred_at + correlation_id per row,
    max-height + overflow for long traces
  - 15s polling; empty/loading/error states all rendered

M3 — project_doc as a first-class binding step:
  - Resource binding wizard split "SK or project docs" into two
    distinct steps: "Connect project docs" + "Connect SK skill packs"
  - Each step's Connect button pre-selects the matching type in
    the advanced sheet so users don't accidentally tag a doc repo
    as Git or SK
  - Summary dialog still receives the combined skOrDocSources view
    to keep the recommendation-card contract unchanged

M7 — secret vault status (admin panel):
  - controller/secret_store.go: new GetSecretStoreStatus handler
    + fetchHealth() method. Hits OpenBao /sys/health (token-less
    upstream endpoint), maps to a sanitized response — NEVER
    returns secret names or values per product docs §13.9
  - Graceful degradation: env vars unset → "not configured" pill;
    network error → "unreachable"; sealed → amber warning; healthy
    → green
  - Mounted at GET /api/secret-store/status behind middleware.AdminAuth
  - New SecretStoreSection in system-settings/maintenance,
    registered before Performance. Read-only card with refresh
    button, 7 status fields, message line, "how to enable" hint

Verification:
  - go vet ./... clean
  - go test ./controller/... ./middleware/... ./model/... all green
  - tsc --noEmit clean
  - Backend M7 endpoint deliberately tolerant — production may not
    have OPENBAO_ADDR set yet, UI shows "not configured" instead of
    500ing

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 11:19:42 +08:00
chenchenandClaude Opus 4.7 3fa345ff5e feat(privacy): per-session consent modal on first authenticated entry
Sprint 5. Pops a non-dismissable modal once per browser tab session
after the user lands on any /_authenticated/* route. Covers two
user-visible policy points the product team called out:

  1. Project data: Heicode does NOT guarantee against project loss.
     Users must back up to their own Git / local storage.
  2. Model privacy: when calling third-party models (OpenAI /
     Anthropic / Google etc.), each vendor's privacy, retention,
     and training-use terms apply. Heicode does NOT modify those
     terms and makes no privacy promises on the vendors' behalf.

Design:
  - Pure frontend, no schema migration, no backend endpoint. The
    "show every login" requirement is satisfied by sessionStorage
    (cleared when the tab closes); persisting acceptance server-
    side would force a forced-consent log we don't need yet.
  - Modal is intentionally non-dismissable (no overlay close, no
    Escape key, no X button). User must explicitly Agree or
    Decline.
  - Decline triggers auth.reset() + redirect to /sign-in — same
    logout path the sidebar uses.
  - Agree button stays disabled until the acknowledgement checkbox
    is ticked.
  - i18n localized en + zh.

If we later need an auditable consent trail (e.g. regulator asks
"prove user X clicked agree on date Y"), promote this to a DB-backed
flow with a users.accepted_privacy_at column and a POST endpoint.
Until then sessionStorage is the right scope.

Verification:
  - tsc --noEmit clean
  - mounted at AuthenticatedLayout — every authenticated route hits
    it; sign-in / sign-up / public pages do not
  - sessionStorage flag survives navigation within a tab, clears on
    tab close — matches "弹一次每次登录" requirement

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 20:38:58 +08:00