mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
* feat(gateway): reviewer/PM collision map (W5)
The collision surface (intends_to_touch / adds_migration / touches_shared)
is authored at delegate time, consumed once by SequencingService to wire
dependency edges, then never shown to a reviewer again. This surfaces it:
- Pure builder (services/gateway/choreographer/collision.py): for a task
under review, the surfaced siblings (same parent) that would collide —
file-overlap globs or a shared migration chain (both adds_migration) —
with the overlapping globs and a declared-vs-actual drift check. No
DB/IO; callers fetch siblings (one indexed get_subtasks query, mig 069)
+ actual files (git). Caps: 10 siblings, 5 globs.
- Evidence envelopes: collision_context block injected into QA
claim_review, PR-gate claim_gate_review (both carry real touched files
so drift is populated), and the PM i_will_plan briefing (no actual
files at plan time, drift omitted). Best-effort — a failure omits the
block, never breaks the verb/briefing. Empty block omitted (zero token
cost via _EVIDENCE_OMIT_WHEN_EMPTY).
- Panel: GET /api/tasks/{id}/collision-map (declared surface + sibling
overlap; no drift — the panel route resolves no workspace) + a Collision
tab on the task detail (8th tab). Mock-mode returns an empty map.
- docs/map added to the RAG auto-index dirs so the collision-map concept
is fleet-retrievable; skipped gracefully if the dir is absent.
19 new tests (15 unit on the pure builder + 4 integration on the route).
Gate green: ruff/mypy/xenon (module rank A)/pytest 13000/coverage 94.81%,
panel typecheck/lint/516 tests.
* [w6-telegram] Add Telegram notifications bridge (V1)
CEO-facing Telegram DM bridge, flag-gated off by default
(ROBOCO_TELEGRAM_ENABLED). Mirrors the X-credentials / X-client pattern:
- TelegramCredentialsTable (migration 073) — singleton Fernet-encrypted
bot_token + chat_id, all-or-nothing set/clear; API never returns plaintext.
- TelegramClient ABC / NullTelegramClient (no-op, configured->False, never
raises) / LiveTelegramClient (httpx POST sendMessage) / build_telegram_client
factory (Null when creds unset).
- /telegram/credentials CEO-only routes (write-only, guard-decorated).
- Best-effort _notify_telegram fan-out from the two CEO-notify producers
(notify_ceo_of_escalation, notify_ceo_of_completion) — guarded by the flag,
never raises into the producer, carries a panel deep-link when
panel_base_url is set.
- panel credentials card (2 fields) nested in the Telegram feature-flag row.
- panel_base_url + telegram_timeout_seconds config fields.
V1 scope only: credentials + flag + panel card + client + one-line fan-out.
Out of scope (V2): inbound commands, a TelegramEngine background loop, a
dedup ledger, a bus subscription.
* [w6-telegram] fix: slave mypy/xenon regression (product tests + helper extract)
Pre-existing on slave from prior session's merges — no PR's CI caught them
(squash merges don't re-CI the result; each branch was based on older slave).
- test_product: _product helper returned MagicMock -> list invariant error;
cast to ProductTable, move import under TYPE_CHECKING.
- test_usage: svc.session.execute (AsyncSession) has no call_args_list;
cast to MagicMock at the two call sites.
- product.progress_for_products: xenon rank C -> extract module-level
_project_to_products_map helper (repo pattern: helper-extract).
---------
Co-authored-by: Renn F <rennf93@users.noreply.github.com>
62 lines
2.3 KiB
Python
62 lines
2.3 KiB
Python
"""Telegram notifications bridge API — CEO-managed credentials (write-only).
|
|
|
|
The bridge itself is a server-side fan-out from the CEO-notify producers; the
|
|
only surface here is the credentials card. CEO-only; credentials are
|
|
write-only (the API never returns plaintext, mirroring ``/x/credentials``).
|
|
"""
|
|
|
|
from fastapi import APIRouter, HTTPException, status
|
|
|
|
from roboco.api.deps import CurrentAgentContext, DbSession, require_ceo_role
|
|
from roboco.api.schemas.telegram import (
|
|
TelegramCredentialsSetRequest,
|
|
TelegramCredentialsStatus,
|
|
)
|
|
from roboco.security import guard_deco
|
|
from roboco.services.telegram_credentials import (
|
|
TelegramCredentialsValidationError,
|
|
get_telegram_credentials_service,
|
|
)
|
|
|
|
router = APIRouter()
|
|
|
|
|
|
def _require_ceo(agent: CurrentAgentContext) -> None:
|
|
require_ceo_role(agent.role, action="manage Telegram credentials")
|
|
|
|
|
|
@router.get("/credentials", response_model=TelegramCredentialsStatus)
|
|
async def get_telegram_credentials(
|
|
db: DbSession, agent: CurrentAgentContext
|
|
) -> TelegramCredentialsStatus:
|
|
"""Whether the bot token + chat id are stored. Never the secrets."""
|
|
_require_ceo(agent)
|
|
has_creds = await get_telegram_credentials_service(db).has_credentials()
|
|
return TelegramCredentialsStatus(has_credentials=has_creds)
|
|
|
|
|
|
@router.post("/credentials", response_model=TelegramCredentialsStatus)
|
|
@guard_deco.rate_limit(requests=10, window=60)
|
|
@guard_deco.max_request_size(size_bytes=8192)
|
|
@guard_deco.block_clouds()
|
|
@guard_deco.content_type_filter(["application/json"])
|
|
@guard_deco.honeypot_detection(["email", "phone", "website"])
|
|
@guard_deco.usage_monitor(max_calls=30, window=3600)
|
|
async def set_telegram_credentials(
|
|
data: TelegramCredentialsSetRequest, db: DbSession, agent: CurrentAgentContext
|
|
) -> TelegramCredentialsStatus:
|
|
"""Set (or, passing both empty, clear) the bot token + chat id together."""
|
|
_require_ceo(agent)
|
|
svc = get_telegram_credentials_service(db)
|
|
try:
|
|
has_creds = await svc.set_credentials(
|
|
bot_token=data.bot_token,
|
|
chat_id=data.chat_id,
|
|
)
|
|
except TelegramCredentialsValidationError as e:
|
|
raise HTTPException(
|
|
status_code=status.HTTP_400_BAD_REQUEST, detail=str(e)
|
|
) from e
|
|
await db.commit()
|
|
return TelegramCredentialsStatus(has_credentials=has_creds)
|