Files
QiufengandClaude Opus 4.8 5e51dc3f56 SNAPSHOT W7 已部署稳定态 — 凯迪ERP+OA一体化平台 (MET 73.3%)
恢复点(restore point)。别人改崩后可 git reset --hard 回到此提交。

== 此快照内容 ==
- 后端 oa-backend: 734 控制器 / 711 实体 (Spring Boot 3.2.5 + SQLite, 端口8091)
- 前端 modern-ui/app: Vue3+Vite, 约700页 (构建产物已在 oa-backend/src/main/resources/static)
- 数据库 oa-backend/data/oa.db: 含全部演示数据 (强制入库, 6.6MB)
- 交接文档 go.md + go-code-reference/endpoints/entities/database.md
- 多代理建设脚本 .claude/wf-*.js

== 状态 ==
- 对 凯迪科技ERP_20260507.xlsx 合规 MET ~73.3% (PARTIAL 75: 34可建+6种子/bug+35外部硬天花板)
- 安全: 5轮红队+5轮复检, default-deny分级鉴权, 连续零可利用
- W3~W7 累计补完436缺口; W8末轮(40缺口)为半成品(源码树可编译但未集成)
- 运行: cd oa-backend; java -jar build/libs/oa-backend-0.1.0.jar --server.port=8091; admin/123456

== 排除(gitignore, 可再生) ==
node_modules / oa-backend/build / .jdks / *.log / Backup-ERP-* / 弃用的OFBiz核心(只保留modern-ui)
完整文件夹备份见同目录 Backup-ERP-20260615-191517/ (含上述全部, 仅缺 node_modules)

时间戳: 20260615-191517

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 19:19:15 +08:00

151 lines
6.4 KiB
JavaScript

#!/usr/bin/env node
/*
* Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the
* specific language governing permissions and limitations
* under the License.
*/
import { readFile } from 'node:fs/promises'
import path from 'node:path'
import { fileURLToPath } from 'node:url'
const scriptPath = fileURLToPath(import.meta.url)
const appRoot = path.resolve(path.dirname(scriptPath), '..')
const parityScript = path.join(appRoot, 'scripts/verify-parity.mjs')
const browserScript = path.join(appRoot, 'scripts/verify-browser-runtime.mjs')
const adminProductScript = path.join(appRoot, 'scripts/verify-admin-product.mjs')
const adminSiteScript = path.join(appRoot, 'scripts/verify-admin-site.mjs')
const rendererCopyScript = path.join(appRoot, 'scripts/verify-erp-renderer-production-copy.mjs')
const packageFile = path.join(appRoot, 'package.json')
const source = await readFile(parityScript, 'utf8')
const browserSource = await readFile(browserScript, 'utf8')
const adminProductSource = await readFile(adminProductScript, 'utf8')
const adminSiteSource = await readFile(adminSiteScript, 'utf8')
const rendererCopySource = await readFile(rendererCopyScript, 'utf8')
const packageJson = JSON.parse(await readFile(packageFile, 'utf8'))
function functionBody(name) {
const marker = `async function ${name}`
const start = source.indexOf(marker)
if (start < 0) return ''
const braceStart = source.indexOf('{', start)
if (braceStart < 0) return ''
let depth = 0
for (let index = braceStart; index < source.length; index += 1) {
const char = source[index]
if (char === '{') depth += 1
if (char === '}') depth -= 1
if (depth === 0) return source.slice(braceStart + 1, index)
}
return ''
}
const smokeBody = functionBody('verifyRuntimeSmoke')
const pageBody = functionBody('verifyModernUiRuntime')
const runtimeBody = functionBody('openModernUiRuntime')
function includesAll(content, tokens) {
return tokens.every((token) => content.includes(token))
}
const checks = [
{
id: 'single-browser-runtime',
passed: runtimeBody.includes('launchChrome(')
&& smokeBody.includes('openModernUiRuntime(chrome)')
&& smokeBody.includes('closeModernUiRuntime(modernRuntime)')
},
{
id: 'no-per-page-chrome-launch',
passed: !pageBody.includes('launchChrome(') && !pageBody.includes('closeChrome(')
},
{
id: 'cdp-fallback-labelled',
passed: source.includes("renderMode: 'chrome-cdp'")
},
{
id: 'browser-runtime-script',
passed: packageJson.scripts?.['verify:browser-runtime'] === 'node scripts/verify-browser-runtime.mjs'
&& browserSource.includes('launchChrome(chrome')
&& browserSource.includes('Page.captureScreenshot')
&& browserSource.includes('browser-runtime-report.json')
},
{
id: 'browser-runtime-product-anchors',
passed: browserSource.includes('document.body.innerText')
&& includesAll(browserSource, ['ERP 管理员工作台', '今日运营', '待办队列', '最近记录', '快捷动作'])
&& !browserSource.includes("text.includes('<div id=\"app\">')")
&& !browserSource.includes("text.includes('<div id=\"app\"')")
},
{
id: 'runtime-console-capture',
passed: browserSource.includes('__modernRuntimeConsoleErrors')
&& browserSource.includes('runtimeDiagnostics(client')
},
{
id: 'parity-runtime-uses-authenticated-modern-session',
passed: runtimeBody.includes('Network.enable')
&& runtimeBody.includes('loginApiSession()')
&& runtimeBody.includes('setRuntimeCookie(client, cookie)')
&& source.includes('securedLoginToken')
&& source.includes('modernSecuredLoginIdCookieName')
},
{
id: 'admin-rendering-alias-is-product-verification',
passed: packageJson.scripts?.['verify:admin-rendering']?.includes('verify:admin-site')
&& packageJson.scripts?.['verify:admin-rendering']?.includes('verify:admin-product')
&& packageJson.scripts?.['verify:admin-rendering']?.includes('verify:erp-renderer-copy')
&& packageJson.scripts?.['verify:admin-rendering']?.includes('verify:browser-runtime-policy')
&& !packageJson.scripts?.['verify:admin-rendering']?.includes('verify:preview')
},
{
id: 'static-product-verifiers-block-visible-leakage',
passed: includesAll(adminProductSource, ['visibleUiLeakageTerms', 'assertNoVisibleUiLeakage'])
&& includesAll(adminSiteSource, ['visibleUiLeakageTerms', 'assertNoVisibleUiLeakage'])
&& rendererCopySource.includes('visibleLeakageTerms')
&& includesAll(adminProductSource + adminSiteSource + rendererCopySource, ['组件展厅', '业务等价', '待验收', '技术预览', '页面清单'])
},
{
id: 'static-product-verifiers-require-post-login-anchors',
passed: includesAll(adminProductSource, ['postLoginCoreModuleAnchors', 'businessPageAnchors', 'assertPostLoginProductAnchors'])
&& includesAll(adminSiteSource, ['postLoginCoreModuleAnchors', 'assertPostLoginProductAnchors'])
&& includesAll(adminProductSource + adminSiteSource, ['#/orders', '#/catalog/products', '#/parties', '#/accounting', '#/facility', '#/business'])
&& includesAll(adminProductSource, ['order__showcart', 'party__NewCustomer', 'accounting__ManualTransaction', 'facility__ReceiveInventoryAgainstPurchaseOrder'])
},
{
id: 'parity-report-keeps-honest-boundary',
passed: includesAll(source, [
'businessDepthParityGate',
'fullBusinessParityVerified',
'fullCompletionClaimAllowed',
'mustNotClaim100PercentBusinessParity',
'structural-route-action-coverage-complete-business-e2e-pending',
'This report separates frontend rewrite coverage from deep business parity'
])
}
]
const failed = checks.filter((check) => !check.passed)
console.log(JSON.stringify({
status: failed.length ? 'failed' : 'passed',
checks
}, null, 2))
if (failed.length) {
process.exitCode = 1
}