Rogee and rogee
1287b7702a
fix(HH-600): isolate notification Redis lifecycle ( #157 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-24 12:24:34 +08:00
Rogee and rogee
57f8a64fd8
fix(HH-591): bound notification shutdown XACK ( #154 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-24 11:36:24 +08:00
Rogee and rogee
34c45ff2c4
HH-463: wait for redisstream XAck during shutdown ( #149 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-24 10:30:50 +08:00
Rogee and rogee
4204ae6a3a
HH-581: restore WebChannel status and reply visibility ( #145 )
...
* fix(realtime): normalize web channel status events (HH-581)
* fix(realtime): resolve legacy widget tokens safely (HH-581)
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-24 08:06:56 +08:00
Rogee and rogee
60a6ac4785
fix: restore web widget realtime replies (HH-556) ( #136 )
...
* fix: restore web widget realtime replies (HH-556)
* fix: make realtime delivery durable (HH-556)
* fix: make realtime message outbox atomic (HH-556)
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 22:35:10 +08:00
Rogee and rogee
8d5d019bb5
HH-548: allow Super Admin sessions to load platform lists ( #125 )
...
* fix(HH-548): authorize super admin platform lists
* fix(HH-548): limit dual auth to platform lists
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 20:21:05 +08:00
Rogee and rogee
a2e4f9a1e8
HH-540: scope iframe policy to Widget page ( #123 )
...
* fix(HH-540): scope iframe policy to widget page
* fix(HH-540): reject non-string allowed domains
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 18:37:08 +08:00
Rogee and rogee
867092fd99
HH-530: replace user-facing Chatwoot branding with GoChat ( #117 )
...
* fix(HH-530): replace user-facing Chatwoot branding
* fix(HH-530): close branding review blockers
* test(HH-530): cover update banner binding
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 18:14:02 +08:00
rogee
2c5e6e595f
fix(shangwutong): initialize contact attributes on inbox creation
2026-08-23 17:32:35 +08:00
Rogee and rogee
3aac701495
fix(HH-528): persist auto resolve message ( #116 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 16:54:20 +08:00
Rogee and rogee
dac8c5e068
HH-502: cover non-widget message sender events ( #113 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 07:40:38 +08:00
Rogee and rogee
ef8931099c
HH-469: close WebSocket fanout contract gaps ( #109 )
...
* HH-469: close websocket fanout contract gaps
* fix: unify message sender contracts
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 00:22:01 +08:00
Rogee and rogee
2b75390529
HH-452: cover upload security boundaries ( #106 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 21:19:43 +08:00
Rogee and rogee
f719529d66
fix(security): harden auth and secret handling (HH-444) ( #101 )
...
* fix(security): harden auth and credential handling (HH-444)
* fix(security): address HH-444 review blockers
* fix(security): close remaining HH-444 review blockers
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 15:45:06 +08:00
Rogee and rogee
02a188dc29
HH-443: establish production CI and supply-chain evidence ( #93 )
...
* ci: enforce production release gates
* ci: close release gate review blockers
* ci: preserve verified digests during promotion
* ci: serialize and verify release cleanup
* ci: build govulncheck with Shangwutong toolchain
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 03:26:38 +08:00
Rogee and rogee
798ea43c2f
HH-442: isolate runtime processes and harden shutdown ( #90 )
...
* HH-442: isolate runtime processes and harden shutdown
* HH-442: harden worker shutdown races
* HH-442: gate dependency shutdown on active handlers
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 02:38:15 +08:00
Rogee and rogee
6d6d80dd86
HH-441: harden durable storage and recovery ( #92 )
...
* HH-441: harden durable storage and recovery
* HH-441: clear recovery review blockers
* HH-441: enforce offsite backup failure domain
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 02:16:02 +08:00
Rogee and rogee
77c91662d2
HH-438: close upload and remote URL attack surfaces ( #89 )
...
* HH-438: close upload and remote URL attack surfaces
* HH-438: use valid PNG in direct upload test
* HH-438: align PostgreSQL upload staging schema
* HH-438: run upload migrations before PostgreSQL E2E
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 20:36:52 +08:00
Rogee and rogee
517a6090b3
test(H-359): assert direct upload completes after retry ( #70 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 13:13:58 +08:00
Rogee and rogee
d948222ac6
H-337: restore Captain inbox takeover and KB citations ( #65 )
...
* fix(captain): restore inbox takeover and KB citations
* fix(captain): harden grounded citations and smoke seed
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-20 22:33:38 +08:00
Rogee and rogee
b31b1b9562
H-337: restore Web widget reply visibility ( #64 )
...
* H-337: restore widget reply delivery
* H-337: harden widget conversation ownership
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-20 22:22:27 +08:00
Rogee and rogee
60ad320e8d
[H-337] Fix Captain provider runtime and knowledge flow ( #61 )
...
* fix(H-337): configure Captain provider runtime
* fix(captain): make knowledge rebuild atomic
* fix(captain): scope retrieval provider failures
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-20 14:46:01 +08:00
Rogee and rogee
3d9817c9f5
H-337: fix Web Channel availability and realtime delivery ( #60 )
...
* H-337: fix Web Channel availability and realtime delivery
* fix(widget): preserve realtime sender and activity contracts
* fix(widget): keep realtime sender payloads consistent
* fix(widget): make public message persistence atomic
* fix(inbox): keep availability projection out of schema
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-20 14:30:05 +08:00
Rogee and rogee
6c78820a1f
H-338: close H-335 release blockers ( #59 )
...
* H-16: align takeover with channel AI workflow (#2 )
* feat(conversations): complete manual AI takeover
* fix(conversations): align AI takeover flow with channel AI
* fix(conversations): close takeover review gaps
---------
Co-authored-by: Rogee <rogee@ipao.vip >
* feat(shangwutong): sync customer names back to channel (#3 )
Co-authored-by: Rogee <rogee@ipao.vip >
* fix(shangwutong): close contact sync review gaps (#4 )
Co-authored-by: Rogee <rogee@ipao.vip >
* H-28: harden Shangwutong CID sync (#5 )
* fix(shangwutong): close contact sync review gaps
* fix(shangwutong): harden CID sync boundaries
---------
Co-authored-by: Rogee <rogee@ipao.vip >
* fix(conversations): sync AI takeover exit in realtime (#6 )
Co-authored-by: Rogee <rogee@ipao.vip >
* test(shangwutong): cover CID rename reliability (#7 )
Co-authored-by: Rogee <rogee@ipao.vip >
* H-43: fix WEB Captain takeover E2E flow (#8 )
* test(shangwutong): cover CID rename reliability
* H-43: fix WEB Captain takeover flow
* H-48: preserve compatible provider model
* H-49: make Captain takeover atomic
* H-50: prevent duplicate widget initialization
---------
Co-authored-by: Rogee <rogee@ipao.vip >
* H-55: make Captain bindings atomic (#9 )
Co-authored-by: Rogee <rogee@ipao.vip >
* H-60: harden Captain migration rollback and concurrency
* chore(agent): baseline — uncommitted work from the local directory
* H-335: add safe Captain skills and user deactivation
* H-338: close auth and Captain review blockers
* H-338: close assignment and session races
* H-338: close assignment and websocket invalidation gaps
* H-338: enforce assignment write invariants
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-20 10:21:19 +08:00
Rogee and rogee
644267f24a
H-303: count cached Skill payloads against budget ( #53 )
...
* H-303: count cached skill payloads against budget
* H-303: exercise cached budget through skill runtime
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-19 18:23:09 +08:00
Rogee and rogee
aaad337ef3
H-292: prove Captain Skill updates reach CAS ( #54 )
...
* H-292: prove Captain Skill updates reach CAS
* H-292: prove handler conflict comes from CAS
* H-292: reuse profile test password digest
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-19 17:55:19 +08:00
Rogee and rogee
2b182f9956
H-300: wire Captain Skills into Web runtime ( #48 )
...
* H-300: wire Captain Skills into Web runtime
* H-300: enforce effective model and conservative skill budget
* H-300: fix CI gosec step
* ci: extend golangci-lint timeout
* fix lint findings across backend
* fix(push): resolve delivery protocol blockers
* test(repository): close SQLite test databases
* test(repository): reuse SQLite schema per package
* H-307: restore backend Go cache in CI
* H-307: prefetch modules before cold lint
* H-307: resolve govulncheck security gate
* H-307: build lint with patched Go toolchain
* H-307: clear remaining security scan findings
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-19 07:08:14 +08:00
Rogee and rogee
0f2b8d7857
H-289: add Captain Skill management API ( #46 )
...
* H-289: add Captain Skill management API
* H-289: guard Captain Skill updates with CAS
* H-289: version all Captain Skill updates
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-18 14:29:10 +08:00
Rogee and rogee
fad2631b23
test(H-271): remove race-suite lifecycle blockers ( #45 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-18 10:20:11 +08:00
Rogee and rogee
f604466d4a
H-162: make message routes display-ID only ( #35 )
...
* H-162: make message routes display-ID only
* H-162: cover frontend display-ID message flow
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-16 10:18:16 +08:00
Rogee and rogee
18ecee3e46
H-116: close visitor payload trust boundaries ( #19 )
...
* H-116: close visitor payload trust boundaries
* H-129: unblock SQLite backend tests
* H-129: remove stale last-seen response assertions
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-15 01:15:04 +08:00
Rogee and rogee
6a3cb49781
H-105: ground Captain replies with inbox knowledge ( #18 )
...
* H-105: ground Captain replies with inbox knowledge
* H-105: harden Captain grounding
* H-126: exclude deleted article embeddings
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-14 19:41:45 +08:00
Rogee and rogee
fcfe5bd37c
H-60: harden Captain migration rollback and concurrency ( #10 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-13 17:13:17 +08:00
Rogee and rogee
0540ae3791
H-55: make Captain bindings atomic ( #9 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-13 16:24:39 +08:00
Rogee and rogee
74eb006985
H-43: fix WEB Captain takeover E2E flow ( #8 )
...
* test(shangwutong): cover CID rename reliability
* H-43: fix WEB Captain takeover flow
* H-48: preserve compatible provider model
* H-49: make Captain takeover atomic
* H-50: prevent duplicate widget initialization
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-13 14:49:04 +08:00
Rogee and rogee
fff3dce1bd
test(shangwutong): cover CID rename reliability ( #7 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-13 09:31:25 +08:00
Rogee and rogee
0555b296cc
fix(conversations): sync AI takeover exit in realtime ( #6 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-13 01:28:31 +08:00
Rogee and rogee
d0995798f4
H-28: harden Shangwutong CID sync ( #5 )
...
* fix(shangwutong): close contact sync review gaps
* fix(shangwutong): harden CID sync boundaries
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-13 01:26:56 +08:00
Rogee and rogee
0e9bf8dc14
fix(shangwutong): close contact sync review gaps ( #4 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-13 01:21:07 +08:00
Rogee and rogee
406e7a07fe
feat(shangwutong): sync customer names back to channel ( #3 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-12 22:58:46 +08:00
Rogee and rogee
83a8ab315a
H-16: align takeover with channel AI workflow ( #2 )
...
* feat(conversations): complete manual AI takeover
* fix(conversations): align AI takeover flow with channel AI
* fix(conversations): close takeover review gaps
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-12 22:57:06 +08:00
rogee
4bf6ba6b20
feat(conversations): complete manual AI takeover
2026-08-12 21:16:49 +08:00
Rogee
518f9c5d6b
fix: 修复客服权限与收件箱配置问题
2026-08-08 19:52:18 +08:00
Rogee
dc2a6577bf
fix(shangwutong): 来源信息改为系统消息
2026-08-06 17:55:54 +08:00
Rogee
d2aeea5f44
fix(shangwutong): 展示会话来源信息
2026-08-06 16:54:57 +08:00
Rogee
b78f963472
chore: 提交剩余开发改动
...
包含商务通消息映射、会话时间与未读状态、前端消息展示、数据库修复迁移、测试覆盖备份及 Captain 设计文档。
2026-08-06 10:10:25 +08:00
Rogee
8f2cc12628
fix(conversations): 修复状态切换与历史会话路由
...
- 处理历史主键与 display_id 冲突,确保消息和状态操作命中同一会话
- 允许已软删除收件箱中的历史会话切换状态
- 解决会话后自动打开列表中的相邻会话
2026-08-06 10:08:05 +08:00
Rogee
4611c0201f
test: improve backend unit coverage
2026-08-04 12:26:25 +08:00
rogee
897b4e018f
feat(channels): add Shangwutong connector
2026-08-03 10:13:40 +08:00
Rogee
96f5c796a6
fix: widget SDK无法加载的三个问题
...
1. Vite proxy缺少/widget转发 — SDK调用/widget/init等API时被SPA fallback
拦截返回HTML。添加/widget proxy并bypass HTML页面请求到/widget.html。
2. ParseWebWidgetConfig类型不匹配 — seed数据中channel_config JSON的
"continuity_via_email":""是空字符串,但Go结构体字段是bool,
json.Unmarshal报UnmarshalTypeError导致整个config解析失败,
findInboxByWebsiteToken跳过该inbox。容忍类型不匹配错误,
只对JSON语法错误返回error。
3. dev模式SDK bundle不可用 — /sdk/js/sdk.js在Vite dev模式下无构建产物,
被SPA fallback返回HTML。构建SDK后放入public/供dev server静态提供。
2026-08-01 22:59:57 +08:00