- server-side employee position resolution (org snapshot) with hard
position gate for EXPERIENCE/CASE sources; formal sources unaffected;
unresolvable position fails closed to general-scope only
- merge published experiences (aihr_case_record, CASE_EXP) and moderated
best answers (COMMUNITY, no submitter identity) into the citation pool
as REFERENCE tier; auxiliary sources never alter formal answers and
fail without breaking the main chain; grading re-grades ROUTE into
GUIDANCE when only auxiliary evidence exists
- case recall endpoints enforce the same position gate
- moderator endpoint to promote a best answer into a CANDIDATE case
record (idempotent via source_ref unique key, never auto-published)
- migration aihr_20260822_case_source_ref_and_best_answer_index_mysql8.sql
- COMMUNITY citations carry community-question:{id} in detailRef for
direct navigation
- CHANGELOG: 2026-08-05 entry with deploy evidence, verification
levels and open items
- runbook: execution log entry + two new migrations in the sequence
- AGENTS.md: macOS GNU stat shim requirement for release scripts
Document the `/api/aihr/org/sync-changes` change feed shipped in 30ef6a8f:
`employee.id` is the stable subject key, the dry-run-then-apply order, and the
fail-closed rules that full `/sync` keeps for masked phone numbers and
duplicate memberships. Adds the endpoint row and a curl example alongside the
existing full-sync entry.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
App-Plus has no WebRTC or getUserMedia in the logic layer, so realtime
practice was H5-only and the native entry had to advertise a record-then-
transcribe downgrade.
Move the media/WebRTC engine into `realtime-browser-engine.js` and drive it
from `RealtimePracticeAppBridge.vue`, whose renderjs script runs inside the
system WebView where those APIs do exist. The logic layer keeps the
authenticated calls: SDP exchange and `search_knowledge` tool invocation stay
server-proxied, so the access token is never handed to the view layer. Both
sides talk over the renderjs bridge only in session payloads the server
already assembled.
Verified against a real App build (`app-renderjs.js` holds RTCPeerConnection
and getUserMedia; `app-service.js` holds the SDP endpoint, renderjs side has
zero hits). Microphone permission, live transcription, remote playback,
foreground/background switching and disconnect fallback still require Android
and iOS device verification.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- rename brand docs to 帮道 prefix; reframe 20260721 plan as historical snapshot
- compress AGENTS.md rule detail into API_INTEGRATION.md, keep boundaries only
- scrub test phone numbers from design-qa, DEV_SETUP, org-sync and rebuild docs
- document summary-card evidence binding contract and 20260725 config migrations
- pin relative dates in README and audit baseline
- Move root design-qa.md → docs/archive/2026-07-mvp-delivery/ (MVP-phase
screenshot QA, concluded passed; register in archive README)
- Rename 20260708 UUID screenshot to descriptive name
- Index the 2026-07-08 integration plan in README, docs/README, AGENTS.md