Merge branch 'main' into fix/merge-main-into-batch-t173

# Conflicts:
#	console-ui/public/portal/index.html
#	cypher-executor/src/routes/health.ts
#	cypher-executor/src/routes/portal.ts
#	registry/components/kbdb_upsert_block/component.contract.yaml
#	registry/examples/km-wiki-ingest/workflow.yaml
This commit is contained in:
2026-08-02 23:43:16 +08:00
34 changed files with 2039 additions and 33 deletions
+21
View File
@@ -126,6 +126,27 @@ export async function deleteEntry(db: D1Database, id: string): Promise<void> {
await db.prepare('DELETE FROM entries WHERE id = ?').bind(id).run();
}
/**
* 把某 owner 下某庫的所有 entries 標 deprecatedt135 by-name 移除語意)。
* 沿用既有 deprecated 機制:metadata_json.status='deprecated' → 搜尋端過濾、庫列表排除。
* 回 deprecated 的筆數(0 = 庫名不存在或早已全部 deprecated)。
*/
export async function deprecateEntriesByLibrary(db: D1Database, ownerId: string, library: string): Promise<number> {
const result = await db
.prepare(
`UPDATE entries
SET metadata_json = json_set(COALESCE(metadata_json, '{}'), '$.status', 'deprecated'),
updated_at = unixepoch()
WHERE owner_id = ?
AND COALESCE(json_extract(metadata_json, '$.library'), 'general') = ?
AND (json_extract(metadata_json, '$.status') IS NULL
OR json_extract(metadata_json, '$.status') != 'deprecated')`,
)
.bind(ownerId, library)
.run();
return (result.meta?.changes as number | undefined) ?? 0;
}
// 「庫」filter 的 SQL 謂詞(portal-auth P1design §3.2/§3.3;零建表,同 #5.1 source 的 json_extract 先例)。
// COALESCE(x,'general') IN (…) ≡ SDD §3.3 寫的 (x IN (…) OR (x IS NULL AND 'general' IN (…)))——
// 語意完全相同(未標記/無 metadata_json 的舊資料歸 'general'),但單組佔位符、不用重複綁參數。
+15
View File
@@ -209,3 +209,18 @@ export async function searchByTemplate(db: D1Database, template: string, owner_i
}
return ids.map((id) => byId.get(id)).filter((r): r is RecordResult => !!r);
}
/** 刪除一筆 record:先刪 entry_valuesFK),再刪底層 entries。回 false 表示 record 不存在。 */
export async function deleteRecord(db: D1Database, recordId: string): Promise<boolean> {
const evRes = await db
.prepare('SELECT entry_id FROM entry_values WHERE record_id = ?')
.bind(recordId)
.all<{ entry_id: string }>();
const rows = evRes.results ?? [];
if (rows.length === 0) return false;
await db.prepare('DELETE FROM entry_values WHERE record_id = ?').bind(recordId).run();
for (const { entry_id } of rows) {
await db.prepare('DELETE FROM entries WHERE id = ?').bind(entry_id).run();
}
return true;
}
+21
View File
@@ -14,6 +14,27 @@ import { mapRoutes } from './routes/map';
const app = new Hono<{ Bindings: Bindings }>();
// t115 global auth guard(三修=總管手改,fail-closed 到底).
// 為什麼不留讀取的寬容窗口:leo 07-28 實證的洞就是「知道網址即可讀走全部知識」——
// 讀取放行等於洞沒補。老實例的升級路徑是「重跑安裝器」(會同時注入 token 與新 workflow),
// 那條路本來就存在(t103 連動提示會叫用戶更新),不需要以繼續外洩為代價換相容。
// Health/ 與 /health)永遠豁免:daemon 的雲端版本偵測與監控要打得到。
app.use('*', async (c, next) => {
const path = new URL(c.req.url).pathname;
if (path === '/' || path === '/health') return next();
const token = c.env.KBDB_INTERNAL_TOKEN;
if (!token) {
// 沒有 token=這個實例還沒封口。一律拒絕(含讀取),並在訊息裡告訴維運怎麼修。
console.warn('[kbdb] KBDB_INTERNAL_TOKEN 未設定——全部請求拒絕,請重跑安裝器以注入金鑰');
return c.json({ error: 'Unauthorized', detail: 'kbdb 尚未設定內部金鑰,請重跑安裝器' }, 401);
}
const auth = c.req.header('Authorization');
if (!auth || auth !== `Bearer ${token}`) {
return c.json({ error: 'Unauthorized' }, 401);
}
return next();
});
app.get('/', (c) => c.json({ service: 'arcrun-kbdb', tier: 'base', status: 'ok' }));
app.get('/health', (c) => c.json({ ok: true }));
+56
View File
@@ -3,6 +3,7 @@ import { Hono } from 'hono';
import type { Bindings } from '../types';
import {
createEntry,
deprecateEntriesByLibrary,
getEntry,
listEntries,
updateEntry,
@@ -32,6 +33,49 @@ entryRoutes.post('/', async (c) => {
return c.json({ success: true, entry });
});
// GET /entries/libraries?owner_id=... — 這個租戶的資料裡實際出現過哪些庫(distinct)。
// t52leo 2026-07-26:地端幾個資料夾=雲端幾個庫):庫由 ingest 蓋章決定,這裡直接從
// 資料反查,讓「蓋了章的庫」一定看得到,不必依賴任何登記動作。未蓋章的舊資料=general。
// 註冊在 '/' 之前——Hono 路由先到先比,放後面會被 '/:id' 之類的樣式吃掉。
entryRoutes.get('/libraries', async (c) => {
const owner = c.req.query('owner_id') || '';
const rows = await c.env.DB.prepare(
`SELECT DISTINCT COALESCE(NULLIF(json_extract(metadata_json, '$.library'), ''), 'general') AS library
FROM entries
WHERE (?1 = '' OR owner_id = ?1)
AND COALESCE(json_extract(metadata_json, '$.status'), '') != 'deprecated'
ORDER BY library`,
)
.bind(owner)
.all<{ library: string }>();
const libraries = (rows.results ?? []).map((r) => r.library).filter(Boolean);
return c.json({ success: true, libraries, count: libraries.length });
});
// GET /entries/library-stats?owner_id=... — 每個庫的知識卡數(distinct page_name,非 block 數)。
// t1422026-07-29):政府驗收用——一眼看出每個庫有幾張卡(page 粒度,不是 block 粒度,
// 一張卡通常對應 3-5 個 block;不含 deprecated entries)。
// 只計 entry_type='block' 的條目,因為 block 才對應知識卡的一個段落(page_name 標記所屬頁面)。
entryRoutes.get('/library-stats', async (c) => {
const owner = c.req.query('owner_id') || '';
const rows = await c.env.DB.prepare(
`SELECT
COALESCE(NULLIF(json_extract(metadata_json, '$.library'), ''), 'general') AS library,
COUNT(DISTINCT page_name) AS card_count
FROM entries
WHERE (?1 = '' OR owner_id = ?1)
AND entry_type = 'block'
AND page_name IS NOT NULL
AND COALESCE(json_extract(metadata_json, '$.status'), '') != 'deprecated'
GROUP BY library
ORDER BY library`,
)
.bind(owner)
.all<{ library: string; card_count: number }>();
const stats = (rows.results ?? []).map((r) => ({ library: r.library, card_count: r.card_count }));
return c.json({ success: true, stats });
});
// GET /entries — list with filters (entry_type, owner_id, parent_id, page_name, source, q/search)
// e.g. list workflows under a project: ?parent_id=PROJECT&entry_type=workflow
// e.g. get one by idempotency key: ?page_name=skill-rag_with_arcrun
@@ -142,6 +186,18 @@ entryRoutes.get('/:id', async (c) => {
return c.json({ success: true, entry });
});
// PATCH /entries/deprecate-by-library — body {owner_id, library}。
// t135:把某租戶某庫的所有 entries 標 deprecated,讓庫從 auto 清單消失。
// 此路由必須在 '/:id' 之前,否則 'deprecate-by-library' 會被當成 id 參數。
entryRoutes.patch('/deprecate-by-library', async (c) => {
const body = (await c.req.json().catch(() => null)) as { owner_id?: string; library?: string } | null;
const ownerId = String(body?.owner_id ?? '').trim();
const library = String(body?.library ?? '').trim();
if (!ownerId || !library) return c.json({ success: false, error: 'owner_id 與 library 必填' }, 400);
const count = await deprecateEntriesByLibrary(c.env.DB, ownerId, library);
return c.json({ success: true, deprecated_count: count });
});
// PATCH /entries/:id
entryRoutes.patch('/:id', async (c) => {
const body = await c.req.json().catch(() => ({}));
+40 -1
View File
@@ -1,7 +1,7 @@
// Records route — structured records (entry_values composed by a template).
import { Hono } from 'hono';
import type { Bindings } from '../types';
import { createRecord, getRecord, searchByTemplate, updateRecord } from '../actions/record-crud';
import { createRecord, deleteRecord, getRecord, searchByTemplate, updateRecord } from '../actions/record-crud';
export const recordRoutes = new Hono<{ Bindings: Bindings }>();
@@ -19,6 +19,38 @@ recordRoutes.post('/', async (c) => {
}
});
// GET /records/triplet-stats?owner_id=... — 每個庫的三元組(關聯)數。
// t1422026-07-29):政府驗收——顯示每個庫整理出幾條知識關聯。
// 計法:依 triplet 型 record 的 'library' slot 值分組計數。無 library slot 的舊三元組歸 general。
// 使用子查詢先取 distinct triplet record IDs(針對 owner),再 LEFT JOIN library slot
// 避免 N+1(全部一次 SQL 完成,不逐筆 getRecord)。
recordRoutes.get('/triplet-stats', async (c) => {
const owner = c.req.query('owner_id') || '';
// 子查詢:找到屬於這個 owner 的所有 triplet recordsLEFT JOIN library slot 取庫名
const rows = await c.env.DB.prepare(
`SELECT
COALESCE(NULLIF(lib_e.content, ''), 'general') AS library,
COUNT(*) AS triplet_count
FROM (
SELECT DISTINCT ev.record_id
FROM entry_values ev
JOIN templates t ON ev.template_id = t.id
JOIN entries e ON ev.entry_id = e.id
WHERE t.name = 'triplet'
AND (?1 = '' OR e.owner_id = ?1)
) AS tr
LEFT JOIN entry_values lev
ON lev.record_id = tr.record_id AND lev.slot_name = 'library'
LEFT JOIN entries lib_e ON lib_e.id = lev.entry_id
GROUP BY COALESCE(NULLIF(lib_e.content, ''), 'general')
ORDER BY library`,
)
.bind(owner)
.all<{ library: string; triplet_count: number }>();
const stats = (rows.results ?? []).map((r) => ({ library: r.library, triplet_count: r.triplet_count }));
return c.json({ success: true, stats });
});
// GET /records/by-template/:template — list records of a template
recordRoutes.get('/by-template/:template', async (c) => {
const records = await searchByTemplate(c.env.DB, c.req.param('template'), c.req.query('owner_id') || undefined);
@@ -47,3 +79,10 @@ recordRoutes.patch('/:recordId', async (c) => {
return c.json({ success: false, error: e instanceof Error ? e.message : String(e) }, 400);
}
});
// DELETE /records/:recordId — 刪除一筆 record 及其底層 entries。
recordRoutes.delete('/:recordId', async (c) => {
const found = await deleteRecord(c.env.DB, c.req.param('recordId'));
if (!found) return c.json({ success: false, error: 'not found' }, 404);
return c.json({ success: true });
});
+7
View File
@@ -4,6 +4,13 @@
export type Bindings = {
DB: D1Database;
ENVIRONMENT: string;
// Auth guard (t115 二修, fail-closed): provisioned by the installer automatically.
// NOT set → writes (POST/PATCH/DELETE/PUT) rejected 401; reads pass with a warning
// (upgrade-window grace so read-only workflows don't break before both workers are
// updated together).
// SET → all non-health routes require `Authorization: Bearer <token>`.
// cypher-executor sends this via kbdbBase(); portal/webhooks/recipes send it inline.
KBDB_INTERNAL_TOKEN?: string;
// Optional embed module (issue #7 / SDD T2.4). Present ONLY when the self-host opened
// semantic search (kbdb_embed:true → deploy injects [[vectorize]] + [ai]). Base never
// requires them; code checks `if (env.VECTORIZE && env.AI)` before touching embed.