Commit Graph

395 Commits

Author SHA1 Message Date
ryan efa75558af autoresearch iter 20: give the telegram poller a real long-poll window
telebot types LongPoller.Timeout as time.Duration and sends
int(timeout / time.Second) to getUpdates, so the literal 10 meant ten
nanoseconds: Telegram received timeout=0, long polling never held the
connection, and the adapter polled the Bot API in a tight loop instead.
Use 10 seconds and extract the settings so the conversion is asserted.

The adapter also has no media temp-dir cleanup (downloadMedia creates an
MkdirTemp per attachment and nothing removes it); that is left as a separate
change rather than bundled here.
2026-08-29 09:32:27 +08:00
ryan ae8bbd98f8 chore(autoresearch): log iter 19 2026-08-29 09:24:33 +08:00
ryan 84eaf3f555 autoresearch iter 19: make task handlers driver-agnostic so they run under both workers
upload's four real background tasks (system cleanup, stats rebuild, storage
migration, image warmup) plus the admin and user stubs registered handlers
typed as func(ctx, *asynq.Task) error. Only the asynq worker accepts that
shape; the Redis-free in-process worker's invokeHandler rejects it with
'unsupported handler type', so none of those tasks could ever run in that
deployment mode. Take payload bytes instead, which both drivers support.

Adds architecture gate check 7 forbidding asynq imports from business and
infrastructure plugins. It deliberately does not cover robfig/cron: the admin
plugin uses cron.ParseStandard only to validate a user-entered spec, which is
a library call rather than a driver binding, and the in-process scheduler
already normalizes 5-field specs.
2026-08-29 09:23:01 +08:00
ryan fd83496a05 docs(config): add implementation plan for the Cordis config extension point
覆盖 P1+P2:core 配置引擎、viper 适配器隔离、门禁与 FiberSkipped、
新旧解析对拍。迁移 27 个消费文件与旧单例退场由后续计划承接。
2026-08-29 09:20:22 +08:00
ryan 020ebebfaa chore(autoresearch): log iter 18 2026-08-29 09:12:03 +08:00
ryan 8c4955c835 autoresearch iter 18: remove the phantom user:daily_audit schedule
The user plugin registered a cron dispatching to user:daily_audit, a task
pattern it never registers, and no audit logic exists anywhere in the plugin.
The daily run therefore went nowhere while a test asserted the schedule was
registered — proving the wiring existed, not that it worked. Implementing a
real daily audit is unstarted functionality, so the schedule is removed rather
than stubbed.

The combined domain test now asserts the real invariant across all applied
plugins: every schedule's task type must have a registered handler.
2026-08-29 09:11:16 +08:00
ryan d80f9d209b chore(autoresearch): log iter 17 2026-08-29 09:03:54 +08:00
ryan 1b1c45206c autoresearch iter 17: wire the pairing-code cleanup cron to a real handler
message_gateway scheduled message_gateway:cleanup_pairing_codes every 10
minutes but never registered a task under that pattern, so every dispatch
went to a task type with no handler and expired pairing rows accumulated
forever, even though repository.DeleteExpiredPairingCodes already existed.
Add a test that fails for any schedule whose task pattern is unregistered:
it reports the exact orphan rather than relying on a schedule-exists assert.
2026-08-29 09:03:33 +08:00
ryan 84946977bf chore(autoresearch): log iter 16 (perf, contract batch) 2026-08-29 08:52:18 +08:00
ryan 976f9b15ae autoresearch iter 16: add batch user lookup and use it for log enrichment
enrichAccessLogsWithUsers preferred the UserService contract over the local
repository — correct layering, but it looped GetUserByID and issued up to a
page-size worth of separate SELECTs against w_users, while the single-query
WHERE id IN variant was only reached in the no-contract fallback branch.
Give the contract a GetUsersByIDs so callers can keep the layering and drop
the N+1. The test asserts 1 query batched against 3 per-id, so the counting
itself is checked.
2026-08-29 08:51:30 +08:00
ryan 5df282f296 chore(autoresearch): log iter 15 (perf, proven) 2026-08-29 08:45:21 +08:00
ryan 2c415638fd autoresearch iter 15: stop CORS from querying the database on every request
isOriginAllowed read server_address from w_system_configs for every request
carrying an Origin header — one uncached primary-DB round-trip plus a split
and trim loop per browser request, while sibling config reads in the storage
driver are already TTL cached. Read it through the shared CacheService with
the same 5s window, falling back to the database when no cache is bound.
driver_http now binds CacheService in Apply the way it already binds DBService.
2026-08-29 08:44:37 +08:00
ryan 2654eb6e2c chore(autoresearch): correct iter 14 log (debt held at 79, kept via proven-fix gate) 2026-08-29 08:39:53 +08:00
ryan 45bf1d8933 chore(autoresearch): log iter 14 2026-08-29 08:39:38 +08:00
ryan 6932b54a30 autoresearch iter 14: stop a cache read error from clobbering the buffered task log
AppendTaskExecutionLog discarded the error from its read of the buffer, so a
transient cache failure looked like an empty buffer and the very next write
replaced the whole accumulated log with just the newest line. Flush already
distinguished miss from failure; append now does the same.
2026-08-29 08:38:55 +08:00
ryan 00ab727791 chore(autoresearch): log iter 12 (debt 80 -> 79) 2026-08-29 08:35:26 +08:00
ryan 101cb2ff7a autoresearch iter 12: inproc driver reports untracked executions as an error
GetExecution returned (nil, nil) under the in-process driver where the asynq
driver returns an error, so the same contract call meant 'empty' in one
deployment mode and 'failed' in the other.
2026-08-29 08:35:00 +08:00
ryan 2c8020188d chore(autoresearch): log iter 11 (debt 84 -> 80) 2026-08-29 08:33:56 +08:00
ryan 3d2038a251 autoresearch iter 11: unimplemented auth mocks fail loudly instead of returning (nil, nil)
Authenticate, CreateAuthSource, UpdateAuthSource and ToggleAuthSource claimed
success with a nil record, so any test that reached them surfaced a nil
pointer dereference instead of the actual cause. Full suite confirms no test
relied on the silent behaviour.
2026-08-29 08:33:16 +08:00
ryan 643bfca996 chore(autoresearch): log iter 10 (debt 87 -> 84, errorlint 12 -> 0) 2026-08-29 08:30:33 +08:00
ryan c4068efd54 autoresearch iter 10: keep error identity at the last errorlint sites
RunPushTest flattened channel validation failures with %v, telegram's
fallback path discarded the original send error, and the config loader's
type assertion on viper.ConfigFileNotFoundError would miss a wrapped form
and fatally abort over a merely missing file. errorlint now reports zero.
2026-08-29 08:29:40 +08:00
ryan f7fd980429 chore(autoresearch): log iter 9 (debt 89 -> 87) 2026-08-29 08:27:21 +08:00
ryan 22ecafdbc2 autoresearch iter 9: drop always-nil error results from task log loaders
loadTaskExecutionLog and loadTaskExecutionLogs could never fail, yet four
call sites branched on their error as if they could, presenting unreachable
code as error handling.
2026-08-29 08:26:39 +08:00
ryan a529700ed3 chore(autoresearch): log iter 8 (proven bug fix, debt held at 89) 2026-08-29 08:24:09 +08:00
ryan 18820b17f6 autoresearch iter 8: render synthesized notification content in stable order
bodyContent's fallback ranged over the body map, and Go randomizes map
iteration, so the same notification rendered its fields in a different order
on every send. Observed failing before the fix: the second call already
reordered the output. Iterate sorted keys instead.
2026-08-29 08:23:23 +08:00
ryan 03f48a9a80 chore(autoresearch): log iter 7 (debt 92 -> 89) 2026-08-29 08:21:24 +08:00
ryan c66399eedc autoresearch iter 7: share body field extraction across push channels
email, telegram and lark each re-implemented the title/content/level lookup
with only their markup differing, and each carried a dead content := ""
initialization that every branch overwrote. Three small helpers in template.go
now own that logic.
2026-08-29 08:20:43 +08:00
ryan bf364f4036 chore(autoresearch): log iter 6, distinguish compile-level from assertion-level proof 2026-08-29 08:17:59 +08:00
ryan ce33997c23 autoresearch iter 6: reject negative cursor instead of silently using 0
parsePositiveInt reported invalidity through a bool that both call sites
discarded, and returned (false, nil) whenever Atoi succeeded on a negative
number. GetLogs therefore accepted ?cursor=-5 and served it as cursor 0
('latest') instead of the documented 400. Validity now travels through the
error result, which no caller can ignore.
2026-08-29 08:16:50 +08:00
ryan 850f99a2c8 docs(config): add Cordis config extension point design
pkg/config 以全局单例暴露全量配置,使组合根可跨插件判断 redis.enabled、
配置读者与所有者无约束。本设计将配置读取框架下沉为内核扩展点,由 infra
适配器隔离 viper,各插件声明自读字段并以门禁谓词取代组合根选型判断,
一次性迁移全部 27 个消费文件。
2026-08-29 08:16:24 +08:00
ryan 58c34ad5c1 chore(autoresearch): log iter 5 (4 bare goroutines hardened, gate widened) 2026-08-29 08:13:17 +08:00
ryan 381c79417e autoresearch iter 5: recover panics in background cleanup loops
Four long-running goroutines were launched with a bare go statement, so a
panic in any of them took down the whole process: the RAM cache's expired-key
eviction, the batch writer's flush worker, the disk cache cleanup worker and
the PoW memory store sweeper. Route them through util.Go.

The architecture gate only grepped for 'go func(', which is why the named-call
form went unnoticed; widen it to cover both launch styles.
2026-08-29 08:12:27 +08:00
ryan 57b39f7fcf chore(autoresearch): log iter 4 (proven bug fix, debt held at 93) 2026-08-29 08:08:16 +08:00
ryan 7e6b9e7c2f autoresearch iter 4: stop one disconnected client from failing a shared image flight
EnsureCompressedImageCache passed the arriving caller's request context into
the singleflight body, which runs once for every concurrent requester of that
cache key. If the first client disconnected, gin canceled the context, the
shared generation aborted, and every follower received that failure and fell
back to the uncompressed original. Detach cancellation with
context.WithoutCancel so trace values still propagate but the shared work
outlives any single requester.
2026-08-29 08:07:19 +08:00
ryan 5b84fd906d chore(autoresearch): log iter 3 (debt 95 -> 93) 2026-08-29 08:03:26 +08:00
ryan 686e3ef5a6 autoresearch iter 3: share upload-record error mapping via filesrv helper
ServeFileByID and DownloadFile duplicated the lookup failure mapping and
each used an unchecked *strconv.NumError assertion that cannot match a
wrapped error. One helper now classifies 404 vs 400 via errors.As; each
endpoint keeps its own fallback for unclassified failures. ErrInvalidUploadID
became unused once both sites report ErrInvalidFileID for a malformed ID.
2026-08-29 08:02:42 +08:00
ryan 4e6209bf61 chore(autoresearch): log iter 2 (debt 100 -> 95) 2026-08-29 07:59:39 +08:00
ryan 37ad58699d autoresearch iter 2: compare error sentinels with errors.Is
Five sites used == against sentinels (redis.Nil, ingest.ErrForbidden,
errs.ErrDatabaseUninitialized). The neighbouring not-found checks already
went through errors.Is helpers, so a wrapped error would silently downgrade
a 403 to a 400 and a 500 to a 400.
2026-08-29 07:58:59 +08:00
ryan edf0c0e934 chore(autoresearch): log iter 1 (debt 102 -> 100, proven fix) 2026-08-29 07:57:10 +08:00
ryan 1c5731bf75 autoresearch iter 1: keep Using2/Using3 dependency causes reachable
Using2/Using3 flattened per-dependency injection failures with %v while
Using1 wrapped with %w, so errors.Is could not see ErrServiceNotFound
through a multi-dependency resolution failure.
2026-08-29 07:56:02 +08:00
ryan 5971e2a9ed chore(autoresearch): re-baseline harness on pinned real-risk yardstick
The committed golangci gate now reports 0 issues, so the previous
lint_issues metric was saturated and could no longer measure progress.
Measure debt against an immutable .auto/lint.ref.yaml snapshot that adds
analyzers for genuine defects (panics, error unwrapping, dead stores,
missing enum cases, method ordering, suppression hygiene) while excluding
cosmetic churn (tagliatelle, wrapcheck). Guard enforces build, vet, tests,
the Cordis architecture gate, and anti-cheat floors: the yardstick cannot
be edited, the project gate may only be strengthened, nolint directives may
only shrink, and no test may disappear.
2026-08-29 07:52:03 +08:00
ryan 4f30e2d57b fix(docker): repair embed packaging for backend/ module layout
The Dockerfiles and the release workflow still assumed the pre-refactor tree:
go.mod, go.sum and main.go now live under backend/, so `COPY go.mod go.sum`
failed outright, and the Go module is the bare `Wavelet`, so the buildinfo
ldflags pointed at github.com/Rain-kl/Wavelet and stamped nothing. The
frontend export was also overlaid onto ./plugins/... rather than the
driver_http path that `//go:embed all:dist` actually reads.

Repoint every packaging path at backend/, correct the ldflags module prefix,
and assert dist/index.html in both docker stages, in build-embedded and in the
release workflow, so a silently empty static export can no longer ship an
API-only binary. Also carry pnpm-workspace.yaml into the cached install layer.
2026-08-29 07:40:57 +08:00
ryan f4975d6732 refactor(plugins): restructure admin and message_gateway into standard layered sub-packages 2026-08-28 22:33:26 +08:00
ryan 85b383a4e0 skills: autoresearch 2026-08-28 20:36:15 +08:00
ryan b68060255f docs(plugins): add plugin layered architecture spec and templates 2026-08-28 20:35:11 +08:00
ryan 0035e548a5 fix(risk_control,message_gateway): fix SQL LIKE escape syntax and use UserService contract 2026-08-28 20:19:24 +08:00
ryan df351cbd33 refactor(core): decouple gin from pkg/util and reduce code duplication 2026-08-28 20:15:47 +08:00
ryan c52b7c4abf test(upload): move storage task fixtures to in-memory mock 2026-08-28 18:54:23 +08:00
ryan 4d6be2fa77 fix(drivers): propagate app-lifetime context through inproc cron/worker drivers
cron 触发与 worker 执行的任务现在继承应用生命周期 context(关闭时级联取消,带超时子上下文),
替代裸 context.Background()。contextcheck 清零。
lint_issues 26→24
2026-08-28 17:04:44 +08:00
ryan 02b93a3b20 chore(autoresearch): log iter 2-3 2026-08-28 16:53:51 +08:00