Rogee and rogee
14b25959ab
HH-553: remove deprecated CORS env references ( #130 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 20:46:40 +08:00
Rogee and rogee
56a2f2e6a5
ci: disable GitHub Actions workflow ( #118 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 17:23:54 +08:00
Rogee and rogee
ef8931099c
HH-469: close WebSocket fanout contract gaps ( #109 )
...
* HH-469: close websocket fanout contract gaps
* fix: unify message sender contracts
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 00:22:01 +08:00
Rogee and rogee
6444c40531
test: preserve quality and websocket evidence ( #107 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 21:19:09 +08:00
Rogee and rogee
fb83285617
HH-445: deploy production observability and runbooks ( #96 )
...
* HH-445: deploy production observability and runbooks
* fix(ops): share production database DSN
* fix(HH-445): enforce database TLS gate
* fix(HH-445): preserve production serve command
* fix(prod): require external database dependencies
* fix(prod): unify database host rejection gates
* test(prod): enforce exact database TLS runbook contract
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 19:39:57 +08:00
Rogee and rogee
61376a57fd
HH-446: restore auditable quality gates from current main ( #102 )
...
* HH-446: restore auditable quality gates
* test(HH-446): restore help center smoke contract
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 15:45:58 +08:00
Rogee and rogee
f719529d66
fix(security): harden auth and secret handling (HH-444) ( #101 )
...
* fix(security): harden auth and credential handling (HH-444)
* fix(security): address HH-444 review blockers
* fix(security): close remaining HH-444 review blockers
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 15:45:06 +08:00
Rogee and rogee
fccfa85c3a
ci(HH-464): pin browser harness Chrome ( #97 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 04:30:06 +08:00
Rogee and rogee
b6b1597e90
HH-462: harden release attestation semantics ( #94 )
...
* HH-462: bind release attestations to source and digest
* HH-462: exercise release attestation production paths
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 04:07:32 +08:00
Rogee and rogee
0e23ccc465
ci(HH-451): harden production Compose smoke ( #95 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 03:58:11 +08:00
Rogee and rogee
02a188dc29
HH-443: establish production CI and supply-chain evidence ( #93 )
...
* ci: enforce production release gates
* ci: close release gate review blockers
* ci: preserve verified digests during promotion
* ci: serialize and verify release cleanup
* ci: build govulncheck with Shangwutong toolchain
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 03:26:38 +08:00
Rogee and rogee
798ea43c2f
HH-442: isolate runtime processes and harden shutdown ( #90 )
...
* HH-442: isolate runtime processes and harden shutdown
* HH-442: harden worker shutdown races
* HH-442: gate dependency shutdown on active handlers
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 02:38:15 +08:00
Rogee and rogee
6d6d80dd86
HH-441: harden durable storage and recovery ( #92 )
...
* HH-441: harden durable storage and recovery
* HH-441: clear recovery review blockers
* HH-441: enforce offsite backup failure domain
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 02:16:02 +08:00
Rogee and rogee
77c91662d2
HH-438: close upload and remote URL attack surfaces ( #89 )
...
* HH-438: close upload and remote URL attack surfaces
* HH-438: use valid PNG in direct upload test
* HH-438: align PostgreSQL upload staging schema
* HH-438: run upload migrations before PostgreSQL E2E
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 20:36:52 +08:00
Rogee and rogee
7a9fec33c5
HH-439: harden production artifact pipeline ( #86 )
...
* HH-439: harden production artifact pipeline
* fix(HH-439): address production compose review
* fix(HH-439): preserve previous JWT secrets in production
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 20:20:00 +08:00
Rogee and rogee
7e3872170f
HH-448: enforce PostgreSQL E2E gate ( #87 )
...
* HH-448 enforce PostgreSQL E2E gate
* HH-448 fail CI when concurrency test is missing
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 20:00:41 +08:00
Rogee and rogee
04c1654086
HH-427: add runtime config browser smoke ( #81 )
...
* HH-427: add runtime config browser smoke
* HH-427: enforce browser smoke in CI
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 16:02:54 +08:00
Rogee and rogee
e665abbfb8
H-417: include frontend TypeScript in format checks ( #78 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 14:37:23 +08:00
Rogee and rogee
a0f668b2d8
H-419: run auto-assignment concurrency on PostgreSQL ( #77 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 14:18:32 +08:00
Rogee and rogee
b971b09ac7
H-409: restore frontend ESLint and Prettier baseline ( #72 )
...
* H-409: restore frontend lint baseline
* ci(H-409): check representative frontend lint
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 14:11:08 +08:00
Rogee and rogee
55b56ee172
H-337: restore minimal GitHub Actions CI ( #62 )
...
* ci(H-337): restore minimal GitHub Actions checks
* ci(H-337): preserve workflow check identity
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-20 14:17:41 +08:00
Rogee and rogee
d54700ac13
chore(H-296): remove GitHub Actions workflow ( #55 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-19 17:02:37 +08:00
Rogee and rogee
2b182f9956
H-300: wire Captain Skills into Web runtime ( #48 )
...
* H-300: wire Captain Skills into Web runtime
* H-300: enforce effective model and conservative skill budget
* H-300: fix CI gosec step
* ci: extend golangci-lint timeout
* fix lint findings across backend
* fix(push): resolve delivery protocol blockers
* test(repository): close SQLite test databases
* test(repository): reuse SQLite schema per package
* H-307: restore backend Go cache in CI
* H-307: prefetch modules before cold lint
* H-307: resolve govulncheck security gate
* H-307: build lint with patched Go toolchain
* H-307: clear remaining security scan findings
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-19 07:08:14 +08:00
Rogee
3d7ff5a6b1
chore: complete Shangwutong connector integration
2026-08-04 18:00:10 +08:00
rogee
897b4e018f
feat(channels): add Shangwutong connector
2026-08-03 10:13:40 +08:00
Rogee
92f0d51375
refactor: 统一 DB/Redis 配置为 DSN 模式 + 移除 Helm/K8s 部署
...
- DatabaseConfig: Host/Port/User/Password/Name/DBName/SSLMode → 单个 DSN 字段
- RedisConfig: Host/Port/Password/DB/URL → 单个 DSN 字段
- 环境变量: GOCHAT_DATABASE_* (7个) → GOCHAT_DATABASE_DSN, GOCHAT_REDIS_* (5个) → GOCHAT_REDIS_DSN
- validator.go: DSN URL 解析校验 (scheme + host)
- redis.go: redis.ParseURL(cfg.DSN) 直连
- 所有 docker-compose / CI / shell 脚本 / .env 同步更新
- 删除 deploy/helm/ 整个目录 (20个文件)
- CI 删除 helm-validate / deploy-staging / deploy-production 三个 job
- 文档同步更新 (README, 架构设计, PRD, 滚动升级)
2026-07-29 20:58:10 +08:00
rogee
aeddedf2a3
Reorganize repo: backend/, deploy/, docs/ layout + AGENTS.md
...
Restructure the monorepo into clear top-level directories:
- backend/: Go module root (cmd, internal, pkg, configs, migrations,
docs/swagger, scripts, tests, go.mod, Makefile, .air.toml)
- deploy/: Docker (Dockerfile, docker-compose*), quickstart, fluentd
- docs/: project documentation + reports/ (moved from repo root)
- AGENTS.md: new AI coding-agent guide at repo root
Update all references to the new layout:
- Dockerfile: COPY backend/go.mod, COPY backend/ (context = repo root)
- docker-compose files: context ../.., dockerfile deploy/docker/Dockerfile,
env_file ../../.env, volume mounts ../../backend:/app
- deploy/quickstart/compose.yaml: dockerfile deploy/docker/Dockerfile
- CI: working-directory: backend for go commands, file deploy/docker/Dockerfile,
coverage path backend/coverage.out, health_check backend/scripts/
- backend/Makefile: docker target uses -f ../deploy/docker/Dockerfile ../
- README: architecture tree, quickstart, config paths updated
Move root stray scripts (rename_models.*, run_m11_tests.sh, verify_build.sh,
gorm_bool_main.go) to backend/scripts/legacy/. All moves via git mv to
preserve history. Build, vet, SQLite tests, and docker compose config verified.
2026-07-07 14:44:12 +08:00
Rogee
8ac150bc7b
second commit
2026-06-04 15:44:48 +08:00