Skip to content

[Task][RFC]: Deliver human-confirmed operations across frontend and Lark #5209

Description

@huangruiteng

Outcome / 目标

交付前端与 Lark 一致的人类确认操作。One task tracks this RFC's delivery; keep implementation PRs and milestone evidence here instead of creating a parallel task tree.

Canonical design: RFC. Roadmap: S8/S9, under #4574. Design acceptance is distinct from implementation, live qualification and promotion.

Current boundary

Source audit: main at ce3862e33 (2026-09-28). This is source/PR inspection, not a new test or live-qualification claim.

The RFC separates generic interaction authority, optional domain execution and venue adapters. Existing typed action and operation-card work must be inventoried before adding anything; M1 requires a simulated consumer plus both entrypoints.

Work remaining

  • Complete the generic preview/confirm/execute/reconcile/return lifecycle through the existing typed-action owner and authenticated callback path.
  • Use one optional simulated domain consumer for M1; keep domain reservation/precision/state with that provider. M2/M3 remain separately gated.

Ownership and ongoing work

Coordinate with current generic operation-card and simulated-provider work. Do not open a competing approval/financial ledger. This public task authorizes no trading, payment, account mutation, credential setup or live order; M3 requires the RFC’s exact user authorization.

Contribution route: implementation/integration overlaps active work. Start from the linked current owners/PRs and identify an unowned acceptance gap in a claim comment; do not begin a competing rewrite.

Acceptance

  • The same exact request confirmed from two entrypoints executes once; stale/rejected/expired confirmations cannot execute.
  • Ambiguous submission, restart and duplicate callback recover one outcome and return it to the originating conversation.
  • Packaged frontend, Lark and receipt readback agree; default-off and protected-operation boundaries hold.
  • Reconcile the RFC's current delivery checkpoint and this issue with the integrated revision, commands, passed/failed/untested evidence and remaining gates. Close the accepted scope only; no claim that a merged PR alone completes the RFC.

Starting points and delivery boundary

Base: latest main. Reuse the existing typed owner and provider boundaries. Include affected CLI/frontend/Lark companions; verify real entrypoints and backend where changed. Preserve existing first-screen review and maintainer merge gates. Public artifacts contain only synthetic/public-safe evidence, no private operational state. This task does not authorize provider promotion, benchmark launches, release/deployment or unrelated protected effects.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions