feat(aihr): add owner identity profiles for realtime practice

- remove owner-impatient persona; owner-calm renamed to 业主
- aihr_realtime_owner_profile table (tenant+project unique, enabled,
  version) with formal migration
- admin CRUD under moderator role gate; project code validated against
  org snapshot and project name taken from snapshot authoritatively
- employee endpoint returns display-safe fields plus defaultProfileId
  from the employee's own community; profile body never exposed
- session creation renders {community}/{profile} server-side; client
  text can never enter instructions; invalid profileId rejected,
  default resolution fails closed
- duplicate create returns 409
This commit is contained in:
2026-08-05 03:18:50 +08:00
parent 83fb657b1b
commit d9ff43eae3
12 changed files with 867 additions and 28 deletions
+4
View File
@@ -186,6 +186,7 @@ mysql --default-character-set=utf8mb4 "$DB_NAME" < backend/script/sql/update/aih
mysql --default-character-set=utf8mb4 "$DB_NAME" < backend/script/sql/update/aihr_20260820_knowledge_migration_orchestration_mysql8.sql
mysql --default-character-set=utf8mb4 "$DB_NAME" < backend/script/sql/update/aihr_20260821_knowledge_shadow_gate_mysql8.sql
mysql --default-character-set=utf8mb4 "$DB_NAME" < backend/script/sql/update/aihr_20260822_case_source_ref_and_best_answer_index_mysql8.sql
mysql --default-character-set=utf8mb4 "$DB_NAME" < backend/script/sql/update/aihr_20260823_realtime_owner_profile_mysql8.sql
mysql --default-character-set=utf8mb4 "$DB_NAME" < backend/script/sql/aihr_personal_knowledge_mysql8.sql
```
@@ -197,6 +198,8 @@ mysql --default-character-set=utf8mb4 "$DB_NAME" < backend/script/sql/aihr_perso
`aihr_20260822_case_source_ref_and_best_answer_index_mysql8.sql` 位于全部知识生命周期迁移之后:为 `aihr_case_record` 增加 `source_ref` 来源引用列和 `(tenant_id, source_type, source_ref)` 唯一键,支撑“最佳答案转经验候选”的幂等追溯;为 `aihr_community_answer` 增加 `(tenant_id, is_best, answer_status)` 索引以服务问模块最佳答案只读检索。脚本只加列和索引,不批准、不发布、不改写任何既有案例或回答。
`aihr_20260823_realtime_owner_profile_mysql8.sql` 紧随 20260822 之后:新建 `aihr_realtime_owner_profile` 实时陪练业主身份档案表(`(tenant_id, project_code)` 唯一键)。画像属内容运营数据,脚本只建空表,不写入、不启用任何画像;档案由管理端 moderator 逐项目维护,仅 `enabled=1` 对员工可见并可渲染进实时会话。
生产物理删除不是部署步骤,也不得与 schema/JAR 发布同窗口批量执行。日常纠错只做 `withdraw`;`purge` 必须有业务/法务确认的保留分类、影响快照、异人批准和已到期 `execute_after`。活动 generation 仍包含该资产时,先构建并启用排除该资产的新 generation,系统不会允许直接清理;清理成功后,受影响的非活动代次会被自动重算并标记失效,不能再作为回滚目标。发布后先运行 reconciliation 并处理不一致,再考虑清理。ENFORCED 启用后旧 generation 保留七天;窗口内指标恶化且旧代次未失效时可从管理端回退,超过窗口或旧代次已失效时必须重新构建候选 generation 和重新通过门禁。
8 月 1 日受控内部试点的正式来源注册是独立的业务数据变更,不随通用 schema 自动执行。先逐一核对附件 `id + doc_id`、原文件 SHA-256、发文号/版本、生效日期和适用范围,再由已授权负责人执行 `backend/script/sql/ops/aihr_20260730_aug1_formal_source_registry_mysql8.sql`。执行后必须只读确认恰好 10 条 `FORMAL_POLICY + APPROVED` 记录;任何缺失都保持无正式依据,不得把访谈、经验萃取、AI 生成内容或草稿补进白名单。
@@ -235,6 +238,7 @@ WHERE table_schema = DATABASE()
'aihr_work_report', 'aihr_broadcast_message', 'aihr_broadcast_read', 'aihr_broadcast_version',
'aihr_broadcast_target_rule', 'aihr_broadcast_target_recipient', 'aihr_broadcast_attachment',
'aihr_direct_feedback',
'aihr_realtime_owner_profile',
'aihr_personal_space', 'aihr_personal_item', 'aihr_personal_fragment',
'aihr_personal_chat_session', 'aihr_personal_chat_message', 'aihr_personal_cleanup_job',
'aihr_personal_ocr_job', 'aihr_personal_ocr_page', 'aihr_personal_export_task',