fix: address project audit gaps
This commit is contained in:
@@ -58,7 +58,7 @@ Do not add these unless a later approved spec says so:
|
|||||||
## Verification
|
## Verification
|
||||||
|
|
||||||
- Backend changes should run `go test ./...` from `backend`.
|
- Backend changes should run `go test ./...` from `backend`.
|
||||||
- PostgreSQL integration checks can use `postgres://postgres:Weidong2023~!@8.137.107.29:19432/agent_dev?sslmode=disable` when a live database is required.
|
- PostgreSQL integration checks should read a live test database URL from `DATABASE_URL`; do not commit real credentials.
|
||||||
- Web changes should run tests and build from `apps/web`.
|
- Web changes should run tests and build from `apps/web`.
|
||||||
- Tauri changes should build the web app first, then run the Tauri verification command from `apps/desktop`.
|
- Tauri changes should build the web app first, then run the Tauri verification command from `apps/desktop`.
|
||||||
- Each implementation task should end with a focused commit.
|
- Each implementation task should end with a focused commit.
|
||||||
|
|||||||
@@ -4,12 +4,26 @@ import (
|
|||||||
"log"
|
"log"
|
||||||
|
|
||||||
"senlinai-agent/backend/internal/config"
|
"senlinai-agent/backend/internal/config"
|
||||||
|
"senlinai-agent/backend/internal/db"
|
||||||
|
"senlinai-agent/backend/internal/domain"
|
||||||
"senlinai-agent/backend/internal/httpx"
|
"senlinai-agent/backend/internal/httpx"
|
||||||
|
"senlinai-agent/backend/internal/inbox"
|
||||||
|
"senlinai-agent/backend/internal/projects"
|
||||||
)
|
)
|
||||||
|
|
||||||
func main() {
|
func main() {
|
||||||
cfg := config.Load()
|
cfg := config.Load()
|
||||||
router := httpx.NewRouter(cfg)
|
database, err := db.Open(cfg.DatabaseURL)
|
||||||
|
if err != nil {
|
||||||
|
log.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := domain.AutoMigrate(database); err != nil {
|
||||||
|
log.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
projectHandler := projects.NewHandler(projects.NewService(database))
|
||||||
|
inboxHandler := inbox.NewHandler(inbox.NewService(database, inbox.StaticAnalyzer{}))
|
||||||
|
router := httpx.NewRouter(cfg, projectHandler, inboxHandler)
|
||||||
if err := router.Run(":8080"); err != nil {
|
if err := router.Run(":8080"); err != nil {
|
||||||
log.Fatal(err)
|
log.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,7 +7,11 @@ import (
|
|||||||
"senlinai-agent/backend/internal/config"
|
"senlinai-agent/backend/internal/config"
|
||||||
)
|
)
|
||||||
|
|
||||||
func NewRouter(cfg config.Config) *gin.Engine {
|
type RouteRegistrar interface {
|
||||||
|
Register(router gin.IRouter)
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewRouter(cfg config.Config, registrars ...RouteRegistrar) *gin.Engine {
|
||||||
if cfg.Env == "test" {
|
if cfg.Env == "test" {
|
||||||
gin.SetMode(gin.TestMode)
|
gin.SetMode(gin.TestMode)
|
||||||
}
|
}
|
||||||
@@ -18,6 +22,10 @@ func NewRouter(cfg config.Config) *gin.Engine {
|
|||||||
router.GET("/healthz", func(c *gin.Context) {
|
router.GET("/healthz", func(c *gin.Context) {
|
||||||
c.JSON(http.StatusOK, gin.H{"status": "ok"})
|
c.JSON(http.StatusOK, gin.H{"status": "ok"})
|
||||||
})
|
})
|
||||||
|
api := router.Group("/api")
|
||||||
|
for _, registrar := range registrars {
|
||||||
|
registrar.Register(api)
|
||||||
|
}
|
||||||
|
|
||||||
return router
|
return router
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ import (
|
|||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
|
"github.com/gin-gonic/gin"
|
||||||
"github.com/stretchr/testify/require"
|
"github.com/stretchr/testify/require"
|
||||||
"senlinai-agent/backend/internal/config"
|
"senlinai-agent/backend/internal/config"
|
||||||
)
|
)
|
||||||
@@ -19,3 +20,22 @@ func TestHealthz(t *testing.T) {
|
|||||||
require.Equal(t, http.StatusOK, rec.Code)
|
require.Equal(t, http.StatusOK, rec.Code)
|
||||||
require.JSONEq(t, `{"status":"ok"}`, rec.Body.String())
|
require.JSONEq(t, `{"status":"ok"}`, rec.Body.String())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestNewRouterRegistersFeatureRoutesUnderAPI(t *testing.T) {
|
||||||
|
router := NewRouter(config.Config{Env: "test"}, testRegistrar{})
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/api/ping", nil)
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
|
||||||
|
router.ServeHTTP(rec, req)
|
||||||
|
|
||||||
|
require.Equal(t, http.StatusOK, rec.Code)
|
||||||
|
require.JSONEq(t, `{"pong":true}`, rec.Body.String())
|
||||||
|
}
|
||||||
|
|
||||||
|
type testRegistrar struct{}
|
||||||
|
|
||||||
|
func (testRegistrar) Register(router gin.IRouter) {
|
||||||
|
router.GET("/ping", func(c *gin.Context) {
|
||||||
|
c.JSON(http.StatusOK, gin.H{"pong": true})
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|||||||
@@ -32,30 +32,106 @@ func (s *Service) Search(userID uint, query string) ([]Result, error) {
|
|||||||
return s.searchPostgres(userID, query)
|
return s.searchPostgres(userID, query)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
like := "%" + query + "%"
|
||||||
|
results := []Result{}
|
||||||
|
var projects []domain.Project
|
||||||
|
if err := s.db.Where("owner_id = ? AND (name LIKE ? OR description LIKE ?)", userID, like, like).Find(&projects).Error; err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
for _, project := range projects {
|
||||||
|
results = append(results, Result{Type: "project", ID: project.ID, ProjectID: project.ID, Title: project.Name, Snippet: project.Description})
|
||||||
|
}
|
||||||
|
|
||||||
|
var tasks []domain.Task
|
||||||
|
if err := s.db.Joins("JOIN projects ON projects.id = tasks.project_id").
|
||||||
|
Where("projects.owner_id = ? AND (tasks.title LIKE ? OR tasks.description LIKE ?)", userID, like, like).
|
||||||
|
Find(&tasks).Error; err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
for _, task := range tasks {
|
||||||
|
results = append(results, Result{Type: "task", ID: task.ID, ProjectID: task.ProjectID, Title: task.Title, Snippet: task.Description})
|
||||||
|
}
|
||||||
|
|
||||||
var notes []domain.Note
|
var notes []domain.Note
|
||||||
if err := s.db.Joins("JOIN projects ON projects.id = notes.project_id").
|
if err := s.db.Joins("JOIN projects ON projects.id = notes.project_id").
|
||||||
Where("projects.owner_id = ? AND (notes.title LIKE ? OR notes.markdown LIKE ?)", userID, "%"+query+"%", "%"+query+"%").
|
Where("projects.owner_id = ? AND (notes.title LIKE ? OR notes.markdown LIKE ?)", userID, like, like).
|
||||||
Find(¬es).Error; err != nil {
|
Find(¬es).Error; err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
results := make([]Result, 0, len(notes))
|
|
||||||
for _, note := range notes {
|
for _, note := range notes {
|
||||||
results = append(results, Result{Type: "note", ID: note.ID, ProjectID: note.ProjectID, Title: note.Title, Snippet: note.Markdown})
|
results = append(results, Result{Type: "note", ID: note.ID, ProjectID: note.ProjectID, Title: note.Title, Snippet: note.Markdown})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
var sources []domain.Source
|
||||||
|
if err := s.db.Joins("JOIN projects ON projects.id = sources.project_id").
|
||||||
|
Where("projects.owner_id = ? AND (sources.title LIKE ? OR sources.url LIKE ? OR sources.content_text LIKE ?)", userID, like, like, like).
|
||||||
|
Find(&sources).Error; err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
for _, source := range sources {
|
||||||
|
results = append(results, Result{Type: "source", ID: source.ID, ProjectID: source.ProjectID, Title: source.Title, Snippet: source.ContentText})
|
||||||
|
}
|
||||||
|
|
||||||
|
var inboxItems []domain.InboxItem
|
||||||
|
if err := s.db.Joins("JOIN projects ON projects.id = inbox_items.project_id").
|
||||||
|
Where("projects.owner_id = ? AND (inbox_items.title LIKE ? OR inbox_items.body LIKE ?)", userID, like, like).
|
||||||
|
Find(&inboxItems).Error; err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
for _, item := range inboxItems {
|
||||||
|
results = append(results, Result{Type: "inbox", ID: item.ID, ProjectID: item.ProjectID, Title: item.Title, Snippet: item.Body})
|
||||||
|
}
|
||||||
|
|
||||||
|
var sessions []domain.AISession
|
||||||
|
if err := s.db.Joins("JOIN projects ON projects.id = ai_sessions.project_id").
|
||||||
|
Where("projects.owner_id = ? AND (ai_sessions.title LIKE ? OR ai_sessions.context LIKE ?)", userID, like, like).
|
||||||
|
Find(&sessions).Error; err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
for _, session := range sessions {
|
||||||
|
results = append(results, Result{Type: "ai_session", ID: session.ID, ProjectID: session.ProjectID, Title: session.Title, Snippet: session.Context})
|
||||||
|
}
|
||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *Service) searchPostgres(userID uint, query string) ([]Result, error) {
|
func (s *Service) searchPostgres(userID uint, query string) ([]Result, error) {
|
||||||
var results []Result
|
var results []Result
|
||||||
err := s.db.Raw(`
|
err := s.db.Raw(`
|
||||||
|
SELECT 'project' AS type, projects.id, projects.id AS project_id, projects.name AS title, projects.description AS snippet
|
||||||
|
FROM projects
|
||||||
|
WHERE projects.owner_id = ?
|
||||||
|
AND to_tsvector('simple', coalesce(projects.name, '') || ' ' || coalesce(projects.description, '')) @@ plainto_tsquery('simple', ?)
|
||||||
|
UNION ALL
|
||||||
|
SELECT 'task' AS type, tasks.id, tasks.project_id, tasks.title, tasks.description AS snippet
|
||||||
|
FROM tasks
|
||||||
|
JOIN projects ON projects.id = tasks.project_id
|
||||||
|
WHERE projects.owner_id = ?
|
||||||
|
AND to_tsvector('simple', coalesce(tasks.title, '') || ' ' || coalesce(tasks.description, '')) @@ plainto_tsquery('simple', ?)
|
||||||
|
UNION ALL
|
||||||
SELECT 'note' AS type, notes.id, notes.project_id, notes.title, notes.markdown AS snippet
|
SELECT 'note' AS type, notes.id, notes.project_id, notes.title, notes.markdown AS snippet
|
||||||
FROM notes
|
FROM notes
|
||||||
JOIN projects ON projects.id = notes.project_id
|
JOIN projects ON projects.id = notes.project_id
|
||||||
WHERE projects.owner_id = ?
|
WHERE projects.owner_id = ?
|
||||||
AND to_tsvector('simple', coalesce(notes.title, '') || ' ' || coalesce(notes.markdown, ''))
|
AND to_tsvector('simple', coalesce(notes.title, '') || ' ' || coalesce(notes.markdown, '')) @@ plainto_tsquery('simple', ?)
|
||||||
@@ plainto_tsquery('simple', ?)
|
UNION ALL
|
||||||
ORDER BY notes.updated_at DESC
|
SELECT 'source' AS type, sources.id, sources.project_id, sources.title, sources.content_text AS snippet
|
||||||
|
FROM sources
|
||||||
|
JOIN projects ON projects.id = sources.project_id
|
||||||
|
WHERE projects.owner_id = ?
|
||||||
|
AND to_tsvector('simple', coalesce(sources.title, '') || ' ' || coalesce(sources.url, '') || ' ' || coalesce(sources.content_text, '')) @@ plainto_tsquery('simple', ?)
|
||||||
|
UNION ALL
|
||||||
|
SELECT 'inbox' AS type, inbox_items.id, inbox_items.project_id, inbox_items.title, inbox_items.body AS snippet
|
||||||
|
FROM inbox_items
|
||||||
|
JOIN projects ON projects.id = inbox_items.project_id
|
||||||
|
WHERE projects.owner_id = ?
|
||||||
|
AND to_tsvector('simple', coalesce(inbox_items.title, '') || ' ' || coalesce(inbox_items.body, '')) @@ plainto_tsquery('simple', ?)
|
||||||
|
UNION ALL
|
||||||
|
SELECT 'ai_session' AS type, ai_sessions.id, ai_sessions.project_id, ai_sessions.title, ai_sessions.context AS snippet
|
||||||
|
FROM ai_sessions
|
||||||
|
JOIN projects ON projects.id = ai_sessions.project_id
|
||||||
|
WHERE projects.owner_id = ?
|
||||||
|
AND to_tsvector('simple', coalesce(ai_sessions.title, '') || ' ' || coalesce(ai_sessions.context, '')) @@ plainto_tsquery('simple', ?)
|
||||||
LIMIT 50
|
LIMIT 50
|
||||||
`, userID, query).Scan(&results).Error
|
`, userID, query, userID, query, userID, query, userID, query, userID, query, userID, query).Scan(&results).Error
|
||||||
return results, err
|
return results, err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -24,3 +24,27 @@ func TestSearchFindsNoteBody(t *testing.T) {
|
|||||||
require.Len(t, results, 1)
|
require.Len(t, results, 1)
|
||||||
require.Equal(t, "note", results[0].Type)
|
require.Equal(t, "note", results[0].Type)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestSearchFindsCoreProjectObjects(t *testing.T) {
|
||||||
|
database, err := gorm.Open(sqlite.Open(fmt.Sprintf("file:%s?mode=memory&cache=shared", t.Name())), &gorm.Config{})
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.NoError(t, domain.AutoMigrate(database))
|
||||||
|
require.NoError(t, database.Create(&domain.Project{ID: 1, OwnerID: 7, Name: "支付项目"}).Error)
|
||||||
|
require.NoError(t, database.Create(&domain.Task{ProjectID: 1, CreatedBy: 7, Title: "回调任务", Description: "检查 webhook"}).Error)
|
||||||
|
require.NoError(t, database.Create(&domain.Source{ProjectID: 1, CreatedBy: 7, Kind: "link", Title: "支付文档", URL: "https://example.com/pay", ContentText: "webhook 签名"}).Error)
|
||||||
|
require.NoError(t, database.Create(&domain.InboxItem{ProjectID: 1, CreatedBy: 7, SourceType: "text", Title: "收集项", Body: "webhook 待整理"}).Error)
|
||||||
|
require.NoError(t, database.Create(&domain.AISession{ProjectID: 1, CreatedBy: 7, Title: "AI 分析", Context: "webhook 问答"}).Error)
|
||||||
|
|
||||||
|
service := NewService(database)
|
||||||
|
results, err := service.Search(7, "webhook")
|
||||||
|
|
||||||
|
require.NoError(t, err)
|
||||||
|
types := make(map[string]bool)
|
||||||
|
for _, result := range results {
|
||||||
|
types[result.Type] = true
|
||||||
|
}
|
||||||
|
require.True(t, types["task"])
|
||||||
|
require.True(t, types["source"])
|
||||||
|
require.True(t, types["inbox"])
|
||||||
|
require.True(t, types["ai_session"])
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,3 +1,7 @@
|
|||||||
|
CREATE INDEX IF NOT EXISTS idx_projects_search
|
||||||
|
ON projects
|
||||||
|
USING gin (to_tsvector('simple', coalesce(name, '') || ' ' || coalesce(description, '')));
|
||||||
|
|
||||||
CREATE INDEX IF NOT EXISTS idx_notes_search
|
CREATE INDEX IF NOT EXISTS idx_notes_search
|
||||||
ON notes
|
ON notes
|
||||||
USING gin (to_tsvector('simple', coalesce(title, '') || ' ' || coalesce(markdown, '')));
|
USING gin (to_tsvector('simple', coalesce(title, '') || ' ' || coalesce(markdown, '')));
|
||||||
|
|||||||
@@ -13,19 +13,12 @@ Expected: all backend tests pass.
|
|||||||
|
|
||||||
## PostgreSQL Integration
|
## PostgreSQL Integration
|
||||||
|
|
||||||
Use this test database URL when live PostgreSQL verification is required:
|
Set `DATABASE_URL` to the live PostgreSQL test database before running integration checks. Do not commit real credentials.
|
||||||
|
|
||||||
```text
|
|
||||||
postgres://postgres:Weidong2023~!@8.137.107.29:19432/agent_dev?sslmode=disable
|
|
||||||
```
|
|
||||||
|
|
||||||
Do not hardcode this value into application source files. Pass it through `DATABASE_URL`.
|
|
||||||
|
|
||||||
Run:
|
Run:
|
||||||
|
|
||||||
```powershell
|
```powershell
|
||||||
Set-Location backend
|
Set-Location backend
|
||||||
$env:DATABASE_URL='postgres://postgres:Weidong2023~!@8.137.107.29:19432/agent_dev?sslmode=disable'
|
|
||||||
go test -tags integration ./internal/db -run TestPostgresPing -v
|
go test -tags integration ./internal/db -run TestPostgresPing -v
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
@@ -20,7 +20,7 @@
|
|||||||
- 全局搜索使用 PostgreSQL 关键词和全文搜索,语义搜索不进入 MVP。
|
- 全局搜索使用 PostgreSQL 关键词和全文搜索,语义搜索不进入 MVP。
|
||||||
- 前端只使用 Svelte,不使用 React。
|
- 前端只使用 Svelte,不使用 React。
|
||||||
- 登录页必须允许用户填写服务器 IP 或域名,并将其保存为 API base URL。
|
- 登录页必须允许用户填写服务器 IP 或域名,并将其保存为 API base URL。
|
||||||
- PostgreSQL 集成验证使用 `postgres://postgres:Weidong2023~!@8.137.107.29:19432/agent_dev?sslmode=disable`。
|
- PostgreSQL 集成验证通过 `DATABASE_URL` 读取测试服务器地址;不要提交真实凭据。
|
||||||
- 前端桌面优先,同时保持移动浏览器可用。
|
- 前端桌面优先,同时保持移动浏览器可用。
|
||||||
- 每个任务结束时运行该任务列出的验证命令并提交。
|
- 每个任务结束时运行该任务列出的验证命令并提交。
|
||||||
|
|
||||||
@@ -663,6 +663,9 @@ Last updated: 2026-07-18.
|
|||||||
- [x] Checkpoint 10: Svelte Inbox、AI 建议确认、任务列表、Markdown 编辑器、AI session 卡片和快速收集组件已完成。
|
- [x] Checkpoint 10: Svelte Inbox、AI 建议确认、任务列表、Markdown 编辑器、AI session 卡片和快速收集组件已完成。
|
||||||
- [x] Checkpoint 11: Tauri 2 桌面壳文件已完成,Web 构建可供 Tauri 使用。
|
- [x] Checkpoint 11: Tauri 2 桌面壳文件已完成,Web 构建可供 Tauri 使用。
|
||||||
- [x] Checkpoint 12: 后端单元测试、PostgreSQL integration ping、Web component tests、Web build 和 Playwright smoke test 已完成。
|
- [x] Checkpoint 12: 后端单元测试、PostgreSQL integration ping、Web component tests、Web build 和 Playwright smoke test 已完成。
|
||||||
|
- [x] Router/main wiring audit: `/api` route registrar 已接入,`cmd/api` 启动时连接 PostgreSQL、执行 AutoMigrate,并注册项目与 Inbox handlers。
|
||||||
|
- [x] Search coverage audit: 搜索 service 已覆盖 project、task、note、source、inbox 和 AI session。
|
||||||
|
- [x] Credential hygiene audit: 当前文档不再保存真实 PostgreSQL 测试库连接串,集成验证统一通过 `DATABASE_URL` 注入。
|
||||||
- [ ] Desktop binary verification: blocked by local Rust toolchain state. `rustup` is installed, but `stable-x86_64-pc-windows-msvc` reports `Missing manifest in toolchain`. Run `rustup toolchain install stable-x86_64-pc-windows-msvc --profile minimal --force` until it completes, then run `npm run build` from `apps/desktop`.
|
- [ ] Desktop binary verification: blocked by local Rust toolchain state. `rustup` is installed, but `stable-x86_64-pc-windows-msvc` reports `Missing manifest in toolchain`. Run `rustup toolchain install stable-x86_64-pc-windows-msvc --profile minimal --force` until it completes, then run `npm run build` from `apps/desktop`.
|
||||||
|
|
||||||
Verification evidence from the latest run:
|
Verification evidence from the latest run:
|
||||||
|
|||||||
@@ -225,7 +225,7 @@ MVP 使用保守共享模型:
|
|||||||
后端:
|
后端:
|
||||||
- AI key 选择、inbox 处理、任务共享可见性、标签项目隔离、文件元数据处理的单元测试。
|
- AI key 选择、inbox 处理、任务共享可见性、标签项目隔离、文件元数据处理的单元测试。
|
||||||
- 项目搜索、任务分发、inbox 转对象的集成测试。
|
- 项目搜索、任务分发、inbox 转对象的集成测试。
|
||||||
- 需要真实 PostgreSQL 时,使用测试服务器 `postgres://postgres:Weidong2023~!@8.137.107.29:19432/agent_dev?sslmode=disable`。
|
- 需要真实 PostgreSQL 时,通过 `DATABASE_URL` 指向测试服务器;不要把真实凭据写入仓库。
|
||||||
|
|
||||||
前端:
|
前端:
|
||||||
- 项目 Dashboard、inbox 建议确认、AI session 列表、任务列表、快速收集表单的组件测试。
|
- 项目 Dashboard、inbox 建议确认、AI session 列表、任务列表、快速收集表单的组件测试。
|
||||||
|
|||||||
Reference in New Issue
Block a user