 Rogeeandrogee
|
eb83d241fe
|
HH-547: allow cross-origin widget requests (#126)
* HH-547: allow cross-origin widget requests
* fix(HH-547): align production preflight with wildcard CORS
---------
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-23 20:11:04 +08:00 |
|
 Rogeeandrogee
|
5a61aac1f2
|
HH-529: allow blob avatar previews in CSP (#115)
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-23 16:52:20 +08:00 |
|
 Rogeeandrogee
|
f719529d66
|
fix(security): harden auth and secret handling (HH-444) (#101)
* fix(security): harden auth and credential handling (HH-444)
* fix(security): address HH-444 review blockers
* fix(security): close remaining HH-444 review blockers
---------
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-22 15:45:06 +08:00 |
|
 Rogeeandrogee
|
798ea43c2f
|
HH-442: isolate runtime processes and harden shutdown (#90)
* HH-442: isolate runtime processes and harden shutdown
* HH-442: harden worker shutdown races
* HH-442: gate dependency shutdown on active handlers
---------
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-22 02:38:15 +08:00 |
|
 Rogeeandrogee
|
cf263d10b4
|
HH-437: harden production auth and tenant authorization (#84)
* HH-437 harden auth and account authorization
* HH-437 reject revoked platform access
---------
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-21 19:13:10 +08:00 |
|
 Rogeeandrogee
|
6c78820a1f
|
H-338: close H-335 release blockers (#59)
* H-16: align takeover with channel AI workflow (#2)
* feat(conversations): complete manual AI takeover
* fix(conversations): align AI takeover flow with channel AI
* fix(conversations): close takeover review gaps
---------
Co-authored-by: Rogee <rogee@ipao.vip>
* feat(shangwutong): sync customer names back to channel (#3)
Co-authored-by: Rogee <rogee@ipao.vip>
* fix(shangwutong): close contact sync review gaps (#4)
Co-authored-by: Rogee <rogee@ipao.vip>
* H-28: harden Shangwutong CID sync (#5)
* fix(shangwutong): close contact sync review gaps
* fix(shangwutong): harden CID sync boundaries
---------
Co-authored-by: Rogee <rogee@ipao.vip>
* fix(conversations): sync AI takeover exit in realtime (#6)
Co-authored-by: Rogee <rogee@ipao.vip>
* test(shangwutong): cover CID rename reliability (#7)
Co-authored-by: Rogee <rogee@ipao.vip>
* H-43: fix WEB Captain takeover E2E flow (#8)
* test(shangwutong): cover CID rename reliability
* H-43: fix WEB Captain takeover flow
* H-48: preserve compatible provider model
* H-49: make Captain takeover atomic
* H-50: prevent duplicate widget initialization
---------
Co-authored-by: Rogee <rogee@ipao.vip>
* H-55: make Captain bindings atomic (#9)
Co-authored-by: Rogee <rogee@ipao.vip>
* H-60: harden Captain migration rollback and concurrency
* chore(agent): baseline — uncommitted work from the local directory
* H-335: add safe Captain skills and user deactivation
* H-338: close auth and Captain review blockers
* H-338: close assignment and session races
* H-338: close assignment and websocket invalidation gaps
* H-338: enforce assignment write invariants
---------
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-20 10:21:19 +08:00 |
|
 Rogeeandrogee
|
2b182f9956
|
H-300: wire Captain Skills into Web runtime (#48)
* H-300: wire Captain Skills into Web runtime
* H-300: enforce effective model and conservative skill budget
* H-300: fix CI gosec step
* ci: extend golangci-lint timeout
* fix lint findings across backend
* fix(push): resolve delivery protocol blockers
* test(repository): close SQLite test databases
* test(repository): reuse SQLite schema per package
* H-307: restore backend Go cache in CI
* H-307: prefetch modules before cold lint
* H-307: resolve govulncheck security gate
* H-307: build lint with patched Go toolchain
* H-307: clear remaining security scan findings
---------
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-19 07:08:14 +08:00 |
|
 Rogeeandrogee
|
a3b01e664e
|
H-263 restore PostgreSQL E2E coverage (#41)
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-18 00:55:45 +08:00 |
|
 Rogeeandrogee
|
21a9a6793d
|
H-162: serve built frontend from Go image (#34)
Co-authored-by: Rogee <rogee@ipao.vip>
|
2026-08-15 20:49:26 +08:00 |
|
Rogee
|
4611c0201f
|
test: improve backend unit coverage
|
2026-08-04 12:26:25 +08:00 |
|
rogee
|
897b4e018f
|
feat(channels): add Shangwutong connector
|
2026-08-03 10:13:40 +08:00 |
|
Rogee
|
37e6d77a2d
|
fix: 帮助中心设置页报 Feature 'knowledge_base' is not available
三个问题:
1. router.go: portal 路由检查 FeatureKnowledgeBase("knowledge_base"),
但账户 feature_flags 中只有 help_center,没有 knowledge_base。
改为检查 FeatureHelpCenter("help_center")。
2. feature_flag.go: 中间件从 context 读取 feature_flags,但没有任何
上游中间件设置它,导致 exists=false 直接 403。GoChat 是自托管非 SaaS,
无 flags 时应放行(所有功能可用)。
3. feature_flag.go: Account.FeatureFlags 存储为 JSON 对象格式
({"help_center":true}),但旧代码只解析 JSON 数组格式。
新增 JSON 对象解析支持。
测试:新增 JSONObjectFormat / JSONObjectFormatDisabled 用例,
更新 NoFeatureFlags 用例为 200(自托管放行)。
|
2026-07-30 11:40:02 +08:00 |
|
Rogee
|
fa6737e258
|
refactor: 精简配置体系,移除 OAuth 登录/Rate Limit/Admin env 配置
- 移除 .env.example 中 Feature Flags 段(代码中不存在这些 env var)
- 移除 Google/GitHub OAuth 登录认证代码(auth/oauth.go、auth_handler
OAuthAuthorize/OAuthCallback 路由、auth_service OAuthLogin),保留
Twitter/Google 作为消息渠道 provider
- 从 OAuthConfig 移除 GitHub 字段(Google 保留供 channel provider 使用)
- 移除 RateLimitConfig 可配置性,RateLimit 中间件改为硬编码 100 req/min、
60s window,移除 config/validator/reloader 中的 rate_limit 相关代码
- 移除 .env.example 中 GOCHAT_ADMIN_EMAIL/PASSWORD 配置
- 新增 gochat init 命令:交互式或通过 --email/--password/--name flags
初始化超级管理员账户,创建默认 Account + AccountUser 关联
|
2026-07-29 16:26:19 +08:00 |
|
rogee
|
c3806b701a
|
feat(parity): align Chatwoot 4.15.1 contracts
|
2026-07-14 12:11:52 +08:00 |
|
rogee
|
8b9eedc0e2
|
feat(copilot): finish configuration center
|
2026-07-13 14:57:28 +08:00 |
|
rogee
|
f923791d39
|
update
|
2026-07-12 12:20:23 +08:00 |
|
rogee
|
aeddedf2a3
|
Reorganize repo: backend/, deploy/, docs/ layout + AGENTS.md
Restructure the monorepo into clear top-level directories:
- backend/: Go module root (cmd, internal, pkg, configs, migrations,
docs/swagger, scripts, tests, go.mod, Makefile, .air.toml)
- deploy/: Docker (Dockerfile, docker-compose*), quickstart, fluentd
- docs/: project documentation + reports/ (moved from repo root)
- AGENTS.md: new AI coding-agent guide at repo root
Update all references to the new layout:
- Dockerfile: COPY backend/go.mod, COPY backend/ (context = repo root)
- docker-compose files: context ../.., dockerfile deploy/docker/Dockerfile,
env_file ../../.env, volume mounts ../../backend:/app
- deploy/quickstart/compose.yaml: dockerfile deploy/docker/Dockerfile
- CI: working-directory: backend for go commands, file deploy/docker/Dockerfile,
coverage path backend/coverage.out, health_check backend/scripts/
- backend/Makefile: docker target uses -f ../deploy/docker/Dockerfile ../
- README: architecture tree, quickstart, config paths updated
Move root stray scripts (rename_models.*, run_m11_tests.sh, verify_build.sh,
gorm_bool_main.go) to backend/scripts/legacy/. All moves via git mv to
preserve history. Build, vet, SQLite tests, and docker compose config verified.
|
2026-07-07 14:44:12 +08:00 |
|