feat(agent): telemetry + CI-gate quick wins from the "AI systems that ship" audit (#677)
* feat(agent): telemetry completeness + durability, CI gates, commit_method provenance Quick wins from the "Building AI systems that ship" audit: - mcp.tool_called gains errorMessage (message_sv, truncated 500 chars) on all failure exits; new mcp.skill_loaded event on every gnubok_load_skill (all tiers) so atom usage is finally measurable - event_log: (event_type, created_at) index; cleanup cron keeps mcp.*/agent.* telemetry 180 days (delivery events stay 30) - CI: lint ratchet (npm run check:lint — 60 legacy errors baselined, fails only on NEW errors) and a pg-real coverage gate (migrations touching trigger/RPC/RLS/DEFERRABLE require a *.pg.test.ts change; escape hatch: -- pg-test: covered-by/skip) - journal_entries.commit_method CHECK widened with 'api_key'/'agent'; the MCP approve path records 'api_key' truthfully instead of 'user_accept' (agent_first_vision §8 P0-1). 'agent' is reserved — ALL MCP traffic (incl. claude.ai OAuth, whose access_token is a minted API key) authenticates as api_key today Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(import): derive opening balances from prior-year #UB when SIE lacks #IB (#675) SIE files exported without #IB 0 rows (only #UB -1) previously imported with zero opening balances. getEffectiveOpeningBalances() now derives IB from prior-year UB for balance-sheet accounts when explicit #IB is absent, surfaces the derivation as an info issue in the import preview, and excludes share-capital vouchers from opening-balance detection. Detection regexes are shared between parser and importer so the two checks cannot drift. 507 lib/import tests pass. (Authored in a parallel session in this checkout; included per request.) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(review): address PR #677 bot findings — RoPA entry, execFileSync, gate scope note Triage of the compliance-swarm + Greptile findings: Applied: - .compliance/ropa.yaml: new mcp.telemetry processing activity declaring the 180-day mcp.*/agent.* retention, lawful basis, data categories, and the no-args/no-results minimisation (ISO A.8.10, GDPR Art.5(1)(c) — the retention split is now formally documented, referenced from the cron) - check-pg-test-coverage.mjs: execFileSync with argv array — no shell, so a hostile base-ref can't inject (ASVS V13.2.1); verified an injection attempt exits 2 without executing - check-pg-test-coverage.mjs: documented the PR-level (not per-migration) scope of the gate so reviewers know to check coverage per migration when a PR carries several risky migrations (Greptile P2) Acknowledged, no change: - errorMessage PII risk: messages are domain-mapped strings; event_log already persists far richer delivery payloads under the same RLS; now declared in ropa.yaml - cron error envelope: errorResponse maps to the canonical safe envelope and the endpoint is CRON_SECRET-gated - two-pass delete "partial state": TTL deletes are idempotent — the next daily run sweeps whatever a failed pass left behind - skill_loaded actorLabel/sessionId: mirrors the pre-existing mcp.tool_called payload; sessionId is the join key the analytics exist for Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
076bb169f8
commit
bc61862e76
@@ -104,14 +104,19 @@ export interface CommitOptions {
|
||||
userEmail?: string
|
||||
/**
|
||||
* commit_method recorded on any journal_entries created by this operation.
|
||||
* Must match the CHECK constraint on journal_entries.commit_method:
|
||||
* 'user_accept' | 'bulk_accept' | 'timing_ceiling' | 'migration' | 'legacy'.
|
||||
* Single-approval route passes 'user_accept' (default); bulk-approval passes
|
||||
* 'bulk_accept'. Defaults to 'user_accept' since the dispatcher is only
|
||||
* invoked from human-approval paths after agent auto-commit was removed
|
||||
* (migration 20260505190027_drop_agent_auto_commit).
|
||||
* Must match the CHECK constraint on journal_entries.commit_method
|
||||
* (migration 20260618120001): 'user_accept' | 'bulk_accept' |
|
||||
* 'timing_ceiling' | 'migration' | 'legacy' | 'agent' | 'api_key'.
|
||||
*
|
||||
* Web-UI single-approval passes 'user_accept'; bulk-approval passes
|
||||
* 'bulk_accept'. MCP approvals pass the relaying credential — 'api_key'
|
||||
* (gnubok-mcp bridge) or 'agent' (OAuth connector) — so the immutable layer
|
||||
* records that the acknowledgment was agent-relayed rather than a
|
||||
* first-party human session (agent_first_vision.md §8 P0-1). Every path is
|
||||
* still human-approval-gated; agent auto-commit was removed in
|
||||
* 20260505190027_drop_agent_auto_commit.
|
||||
*/
|
||||
commitMethod?: 'user_accept' | 'bulk_accept'
|
||||
commitMethod?: 'user_accept' | 'bulk_accept' | 'agent' | 'api_key'
|
||||
}
|
||||
|
||||
// ── Helper: ensure fiscal period covers the date ──────────────────
|
||||
@@ -2470,10 +2475,11 @@ async function commitCreateVoucher(
|
||||
notes: (params.notes as string) || undefined,
|
||||
lines,
|
||||
},
|
||||
// commit_method records HOW it was committed, not who staged it. MCP-
|
||||
// staged ops still go through human approval, so 'user_accept' (or
|
||||
// 'bulk_accept' from the bulk route) is the correct value. The DB CHECK
|
||||
// constraint rejects anything else (migration 20260420120001).
|
||||
// commit_method records HOW it was committed, not who staged it.
|
||||
// Web routes pass 'user_accept'/'bulk_accept'; the MCP approve path
|
||||
// passes 'api_key'/'agent' so agent-relayed acknowledgments are
|
||||
// distinguishable in the immutable layer. The DB CHECK constraint
|
||||
// rejects anything else (migrations 20260420120001, 20260618120001).
|
||||
opts.commitMethod ?? 'user_accept'
|
||||
)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user