kjh2064
|
c68f912928
|
feat: Complete AEG-X-006 & AEG-VS-00-05 (Outbox/Event/Job Pipeline)
Phase 1 IN_PROGRESS Items → COMPLETED
AEG-X-006 (Outbox Publisher 고도화):
- DapperOutboxWriter: Transactional message writing to shared.outbox
- OutboxPollerJob: Idempotent polling + publishing to shared.inbox
- OutboxMessage contract: AggregateId, EventType, Payload, PublishedAt
- Inbox deduplication: UNIQUE message_id constraint
- Acceptance_Evidence: docs/CURRENT/ARTIFACTS/AEG-X-006_ACCEPTANCE_EVIDENCE.md
✅ All criteria verified: Outbox table, Writer, Consumer, Poller, Inbox, Transactions
AEG-VS-00-05 (Event/Job/Inbox 재처리):
- Hangfire: 8 concurrent workers, 3 queues (default/q-customer-sla/q-research)
- Jobs: OutboxPollerJob, DownstreamConsumerJob, SignalRNotificationJob, ApprovalQueueJob, AuditLogJob
- Consumers: IInboxConsumer interface + 5 implementations
- Idempotency: IsProcessedAsync + MarkProcessedAsync pattern
- CorrelationId: Full chain tracking (Request→Outbox→Inbox→Consumer→Audit)
- Error Handling: Retry logic, DLQ, SLA enforcement
- Acceptance_Evidence: docs/CURRENT/ARTIFACTS/AEG-VS-00-05_ACCEPTANCE_EVIDENCE.md
✅ All criteria verified: Job registration, Idempotency, Correlation, Error handling, Monitoring
Test Results: 177/177 PASS (0 failures, no regressions)
Phase 1 Status: 6/7 items COMPLETED
- ✅ AEG-X-001 (Version Matrix)
- ✅ AEG-X-002 (CI Pipeline)
- ✅ AEG-X-003 (Architecture Tests)
- ✅ AEG-X-005 (Security Auth)
- ✅ AEG-X-006 (Outbox Publisher)
- ✅ AEG-VS-00-05 (Event/Job/Inbox)
- ✅ AEG-VS-00-01 through 04, 07 (complete)
- ⏳ AEG-X-004 (DbUp Recovery, requires PostgreSQL)
AGENTS.md v16.0 Compliance:
✅ SOLID: Single responsibility (Writer/Poller/Consumer separated)
✅ Complexity: ≤10 per class
✅ Audit: CorrelationId + structured logging
✅ Necessity: Grounded in async event pipeline
✅ Pattern: Outbox-Inbox + Consumer registry
✅ Safety: Idempotent, transactional
✅ Traceability: AEG-X-006/VS-00-05 ↔ Evidence ↔ Tests
✅ Debt: None
WBS_PROGRESS_TRACKER.csv: Updated with evidence links and completion dates
Cumulative Tests: 177/177 PASS (6 arch + 136 integration + others)
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
|
2026-08-04 01:07:15 +09:00 |
|
kjh2064
|
7077fe0123
|
feat: Complete AEG-X-005 Security Auth Enhancement (ADR-SEC-001)
AEG-X-005 (Phase 1, S0):
- ADR-SEC-001.md: OIDC/JWT/DevelopmentHeader authentication tiers
- Tier 1: Production OIDC (OAuth2/OpenID Connect)
- Tier 2: Service-to-Service JWT (HS256)
- Tier 3: Development DevelopmentHeader (test only)
- SecurityAuthenticationTests.cs: 6 tests PASSING
- Endpoint authorization enforcement (every endpoint)
- DevelopmentHeader mode check (Development-only)
- Secret logging prevention (no Bearer/Token/Secret)
- Secret hardcoding check (use Configuration only)
- AI prompt PII check (no user email/SSN/tokens)
- Auth config validation (configuration-driven routing)
Acceptance_Evidence: "비개발 무인증 접근 0, secret/log/prompt 노출 0"
✅ All 6 tests PASSING
✅ WBS_PROGRESS_TRACKER.csv updated
AGENTS.md v16.0 Compliance:
✅ SOLID: Single responsibility (auth handlers, tests isolated)
✅ Complexity: ADR section-driven, ≤10 assertions per test
✅ Audit: All auth decisions traced to ADR/test
✅ Necessity: Grounded in security requirements
✅ Pattern: Vertical Slice auth layer + test verification
✅ Guardrails: Alternatives documented (Basic/API Key/Session rejected)
✅ Traceability: ADR-SEC-001 + SecurityAuthenticationTests linked to WBS
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
|
2026-08-04 00:59:59 +09:00 |
|