Compare commits
@@ -29,6 +29,11 @@ N8N_BASIC_AUTH_ACTIVE=true
|
||||
N8N_BASIC_AUTH_USER=admin
|
||||
N8N_BASIC_AUTH_PASSWORD=change-me
|
||||
MOBILITYOPS_CALLBACK_TOKEN=replace-me-n8n-callback-token
|
||||
# Sent as the X-Fleet-Ops-Trigger-Token header when Fleet Ops calls the n8n return-
|
||||
# processing webhook, so the webhook trigger can require Header Auth instead of being
|
||||
# publicly callable by anyone who discovers the URL. Must match the value stored in
|
||||
# n8n's "Fleet Ops Webhook Trigger Token" Header Auth credential.
|
||||
MOBILITYOPS_WEBHOOK_TRIGGER_TOKEN=replace-me-n8n-webhook-trigger-token
|
||||
|
||||
# RAGcore integration
|
||||
KNOWLEDGE_PROVIDER=demo
|
||||
@@ -37,9 +42,14 @@ RAGCORE_TENANT=northstar-mobility-demo
|
||||
RAGCORE_WORKSPACE=mobilityops
|
||||
RAGCORE_COLLECTION=internal-procedures
|
||||
RAGCORE_API_TOKEN=
|
||||
# UUID of the RAGcore knowledge space procedures were synced into (see workflow 3).
|
||||
RAGCORE_SPACE_ID=
|
||||
|
||||
# ITWorx MCP Hub integration
|
||||
# ITWorx MCP Hub integration. Registration itself is catalog-driven on the Hub's own
|
||||
# side (it reconciles its catalog into the gateway; Fleet Ops never pushes a
|
||||
# registration call) -- MCP_HUB_BASE_URL is only used here for an honest reachability
|
||||
# health check surfaced on the integration status page.
|
||||
MCP_HUB_REGISTRATION_ENABLED=false
|
||||
MCP_HUB_BASE_URL=http://itworx-mcp-hub:8000
|
||||
MCP_HUB_SERVICE_TOKEN=replace-me-mcp-hub-token
|
||||
MCP_PROVIDER_ID=mobilityops
|
||||
MCP_PROVIDER_ID=fleet-ops
|
||||
|
||||
@@ -14,3 +14,5 @@ test-results/
|
||||
.idea/
|
||||
.vscode/
|
||||
*.tsbuildinfo
|
||||
*.zip
|
||||
*.tar.gz
|
||||
|
||||
@@ -60,7 +60,10 @@
|
||||
- `knowledge/procedures/09-booking-conflicts.md`
|
||||
- `knowledge/procedures/10-roles-and-escalation.md`
|
||||
- `n8n/README.md`
|
||||
- `n8n/mobilityops-return-processing.json`
|
||||
- `n8n/workflows/MANIFEST.md`
|
||||
- `n8n/workflows/fleet-ops-vehicle-return.json`
|
||||
- `n8n/workflows/fleet-ops-data-quality-scan.json`
|
||||
- `n8n/workflows/check_drift.py`
|
||||
- `seed/README.md`
|
||||
- `seed/bookings.csv`
|
||||
- `seed/customers.csv`
|
||||
|
||||
@@ -26,16 +26,19 @@ reset:
|
||||
# One-time per environment: imports and activates the n8n return-processing workflow.
|
||||
# The n8n owner account itself cannot be scripted safely and must be created once at
|
||||
# http://localhost:5678/setup (any email/password, no verification required) before
|
||||
# this target's activation takes effect. See docs/17-runbook.md.
|
||||
# this target's activation takes effect. The workflow also needs the "Fleet Ops Webhook
|
||||
# Trigger Token" and "Fleet Ops Service Token" Header Auth credentials created manually in
|
||||
# the n8n UI before it will actually process a return -- see docs/17-runbook.md.
|
||||
n8n-setup:
|
||||
docker compose exec n8n n8n import:workflow --input=//imports/mobilityops-return-processing.json
|
||||
docker compose exec n8n n8n import:workflow --input=//imports/workflows/fleet-ops-vehicle-return.json
|
||||
docker compose exec n8n n8n publish:workflow --id=mobilityops-return-processing
|
||||
docker compose restart n8n
|
||||
|
||||
# One-time per environment: imports and activates the scheduled quality-scan workflow.
|
||||
# Same owner-account precondition as n8n-setup above.
|
||||
# Same owner-account and credential preconditions as n8n-setup above (this workflow only
|
||||
# needs "Fleet Ops Service Token").
|
||||
n8n-setup-scan:
|
||||
docker compose exec n8n n8n import:workflow --input=//imports/mobilityops-scheduled-quality-scan.json
|
||||
docker compose exec n8n n8n import:workflow --input=//imports/workflows/fleet-ops-data-quality-scan.json
|
||||
docker compose exec n8n n8n publish:workflow --id=mobilityops-scheduled-quality-scan
|
||||
docker compose restart n8n
|
||||
|
||||
|
||||
@@ -1,8 +1,18 @@
|
||||
# MobilityOps
|
||||
# Fleet Ops
|
||||
|
||||
**Connected operations for vehicle rental and service teams.**
|
||||
|
||||
MobilityOps is a working proof of concept for a fictitious mobility company. It combines vehicle and booking operations, a controlled vehicle-return workflow, data-quality review, RAGcore-backed internal knowledge, n8n orchestration and read-only tools published through ITWorx MCP Hub.
|
||||
Fleet Ops is a working proof of concept for a fictitious mobility company. It combines vehicle and booking operations, a controlled vehicle-return workflow, data-quality review, RAGcore-backed internal knowledge, n8n orchestration and read-only tools published through ITWorx MCP Hub.
|
||||
|
||||
**Naming:** "Fleet Ops" is the product's visible name everywhere in the UI, the demo
|
||||
knowledge base, and this documentation. "MobilityOps" remains the technical
|
||||
identifier only — the repository name, local directory, package/module names, Docker
|
||||
Compose project, deployment directory, and database names. The UI is fully trilingual
|
||||
(nl-BE default, en-GB, fr-BE); see `docs/fleet-ops-correction/` for the localization
|
||||
architecture, the vehicle-status decision table, and the correction evidence, and
|
||||
`docs/fleet-ops-final-localization/` for the follow-up correction round (remaining
|
||||
NL/FR translation gaps, centralized API-error localization, the time-dependent
|
||||
Europe/Brussels dashboard greeting).
|
||||
|
||||
The web application uses the premium responsive **Control Rail** interface: a compact
|
||||
operations-first workspace with persisted readiness metrics, evidence-led exceptions,
|
||||
@@ -58,15 +68,21 @@ It is not an ERP, CRM, accounting package, public booking site, payment system o
|
||||
delivery counts, not just the most recent event.
|
||||
- **RAGcore**: the demo `KnowledgeProvider` (deterministic TF-IDF extractive retrieval
|
||||
over the local procedure documents) is what satisfies the knowledge-assistant
|
||||
acceptance criteria and is fully verified. A `RAGcoreKnowledgeProvider` HTTP adapter is
|
||||
implemented and unit-tested, including its unavailable-degradation path, but was never
|
||||
exercised against a live RAGcore instance in this environment.
|
||||
acceptance criteria and is what's active in production (`KNOWLEDGE_PROVIDER=demo`). A
|
||||
`RAGcoreKnowledgeProvider` HTTP adapter is implemented, unit-tested, and has been
|
||||
exercised live against the deployed RAGcore instance: a real filesystem-permission bug
|
||||
that caused every live retrieval to return zero candidates was found and fixed
|
||||
(`docs/final-integrations/current-state-audit.md`), but a second, deeper gap — RAGcore's
|
||||
reranker adapter calls an Ollama HTTP route (`/api/rerank`) that does not exist on the
|
||||
deployed Ollama version — still blocks real grounded answers. `KNOWLEDGE_PROVIDER` stays
|
||||
`demo` until that is resolved on the RAGcore side.
|
||||
- **ITWorx MCP Hub**: the four read-only provider endpoints are implemented, tested, and
|
||||
directly `curl`-verified with correct auth enforcement and audit logging.
|
||||
`MCP_HUB_REGISTRATION_ENABLED` is now actually wired into `Settings` (it was previously
|
||||
declared in `.env.example` but silently dropped) and reported honestly by the
|
||||
integration-status endpoint. No live Hub instance was reachable in this environment to
|
||||
verify an actual Hub round trip.
|
||||
`MCP_HUB_REGISTRATION_ENABLED` is actually wired into `Settings` and reported honestly
|
||||
by the integration-status endpoint (evidence-based: real tool-call audit history, not
|
||||
just the flag). The Fleet Ops connector is confirmed live in the ITWorx MCP Hub's own
|
||||
production deployment (Tower), with a real contract fix already applied there
|
||||
(`vehicle.get`'s wire parameter normalized to `vehicleRef`).
|
||||
|
||||
See `artifacts/functional-completion/final-summary.md` for the functional-completion
|
||||
audit evidence (supersedes the design-validation summary below for integration status),
|
||||
@@ -114,9 +130,9 @@ All defaults are configurable via `.env` (see `.env.example`).
|
||||
## Quality gates
|
||||
|
||||
```bash
|
||||
make test # backend: pytest (127 tests)
|
||||
make test # backend: pytest (151 tests)
|
||||
make lint # backend: ruff + mypy (strict, zero errors)
|
||||
make e2e # frontend: Playwright end-to-end (56 tests, live stack required)
|
||||
make e2e # frontend: Playwright end-to-end (138 tests, live stack required)
|
||||
```
|
||||
|
||||
Frontend build/typecheck: `cd frontend && npm run build` (`tsc -b && vite build`).
|
||||
|
||||
@@ -0,0 +1,161 @@
|
||||
# Fleet Ops final integrations — evidence summary
|
||||
|
||||
Session date: 2026-08-05. Branch `feat/fleet-ops-final-integrations`.
|
||||
|
||||
## Repository state
|
||||
|
||||
| Repo | Start | End | Branch | Notes |
|
||||
|---|---|---|---|---|
|
||||
| Fleet Ops (MobilityOps) | `3ebca9e` (from `feat/live-n8n-ragcore-integration`) | `727c19a` (+ e2e test fixes, uncommitted at write time) | `feat/fleet-ops-final-integrations`, pushed to `origin` | 3 commits: `34df66d`, `2ae2044`, `727c19a` |
|
||||
| RAGcore | `64a908a` | `64a908a` (+1 isolated commit `ce0ad56`) | `main` | Only a backlog handoff entry committed; no code changes (36-file concurrent-session collision — see below) |
|
||||
| ITWorx MCP Hub | not modified this session | — | `feature/wp240-final-acceptance` | Connector already live in production before this session started; not touched |
|
||||
|
||||
## Deployed revisions
|
||||
|
||||
- Fleet Ops: `http://192.168.10.150:1236`, redeployed twice this session (after Batches
|
||||
1-3 and after Batch 4), `docker compose -p mobilityops -f compose.yaml -f
|
||||
compose.unraid.yaml up --build -d db api web`, `.deploy/source-revision` = `727c19a...`.
|
||||
- RAGcore: `http://192.168.10.150:1237`, `ragcore-app-1`. No image redeploy — the two live
|
||||
fixes (filesystem permissions, reranker model pull) were applied directly to the
|
||||
running container/Ollama instance, not via a code deploy.
|
||||
- ITWorx MCP Hub: `http://192.168.10.150:1100` (Tower), unchanged, already live before
|
||||
this session at commit `c4a0f6d` per the Hub's own state.
|
||||
|
||||
## GUI polish (Batch 1)
|
||||
|
||||
- Dashboard Attention Queue: curated severity mix (grouped "Handle now / Follow up
|
||||
today / Review later"), replacing pure severity-sort that let `high` crowd out
|
||||
everything else.
|
||||
- Today's Movements: seed data curated (`seed/bookings.csv`) so a fresh reset shows ≥2
|
||||
departures and ≥2 returns; new `test_seed_today_movements_are_a_credible_mix` test.
|
||||
Live-verified after a real demo reset: 2 returns + 2 departures shown.
|
||||
- About Demo: restructured into a compact grid with `<details>` progressive disclosure
|
||||
for architecture/security/testing sections.
|
||||
- Duplicate Customer Merge: match/conflict counts shown, matching fields hidden by
|
||||
default (toggle to reveal), compact preview of the merged record before confirmation.
|
||||
- Repo hygiene: removed a stray empty `backend;C` dir and an untracked 31MB zip export;
|
||||
`.gitignore` now excludes future archive exports.
|
||||
- All four live-verified via browser against the deployed instance (see screenshots
|
||||
taken during the session — not separately saved to disk).
|
||||
|
||||
## n8n (Batch 2)
|
||||
|
||||
- 4 canonical workflows confirmed live: Vehicle Return Orchestration, Scheduled Data
|
||||
Quality Scan, RAGcore Procedure Sync, Workflow Error Handler.
|
||||
- Fixed genuinely invalid JSON in the committed `fleet-ops-vehicle-return.json` (a
|
||||
missing `},` between two node objects — the file could not be parsed).
|
||||
- Workflow 3 (RAGcore Procedure Sync): confirmed 6 real nodes built and saved. Found and
|
||||
fixed two real defects via the safe `n8n import:workflow` CLI path (not the REST API,
|
||||
which caused a documented wipe incident in an earlier session): three body-parameter
|
||||
expressions had a stray trailing `}}`, and `settings.errorWorkflow` was unset. Exported
|
||||
the corrected definition to `n8n/workflows/fleet-ops-ragcore-procedure-sync.json`,
|
||||
added to `MANIFEST.md` and `check_drift.py`.
|
||||
- **Not published** — the Schedule Trigger runs daily at midnight; activating it starts
|
||||
real unattended production runs, deliberately left as a separate go-live decision.
|
||||
- No no-op/sync/error-handler live-execution smoke test was run this session beyond the
|
||||
structural CLI-export verification above (workflow remains unpublished).
|
||||
|
||||
## RAGcore (Batch 3)
|
||||
|
||||
- **Root cause found and fixed, live, user-approved**: the "zero retrieval candidates"
|
||||
bug was a filesystem permission bug (`/workspace/.state/models/embedding_profiles.json`
|
||||
was `root:root` mode `600` on the host bind mount, unreadable by the app's actual
|
||||
runtime uid 10001) — not authorization, not Qdrant, not embeddings, all independently
|
||||
verified healthy first. Fixed via `chown`/`chmod`; re-verified in-process (5 real hits,
|
||||
up from 0).
|
||||
- **Second, deeper gap found, not fixed**: the reranker adapter calls
|
||||
`{ollama}/api/rerank`, a route this Ollama version (`0.32.5`) does not serve (404).
|
||||
Pulled a working model (`xitao/bge-reranker-v2-m3:latest`, 1.2GB, approved) — did not
|
||||
fix it, since the problem is the HTTP route, not the model. `/v1/answers` still returns
|
||||
`not_answerable`/0 citations for real questions against real matching content.
|
||||
- User decision: leave `KNOWLEDGE_PROVIDER=demo`; hand the reranker fix off to RAGcore's
|
||||
own backlog (`docs/ai/BACKLOG.yaml`, task `M8-01`, committed in that repo as `ce0ad56`
|
||||
— the only commit made in RAGcore this session) rather than editing RAGcore code amid
|
||||
its own 36-file concurrent-session collision.
|
||||
- Side effect: minting the live-verification credential rotated the existing "Fleet Ops
|
||||
Knowledge Assistant (production)" service account's credential (2-active-credential cap
|
||||
reached). A fresh credential must be issued before actually flipping the provider live.
|
||||
|
||||
## MCP Hub (Batch 4)
|
||||
|
||||
- Confirmed the Fleet Ops connector is already live in production on the Hub side
|
||||
(Tower, commit `c4a0f6d`), with a real contract fix already applied there
|
||||
(`vehicle.get`'s wire parameter normalized to camelCase `vehicleRef`).
|
||||
- Fixed two concrete gaps in Fleet Ops's own `search-knowledge` endpoint: no `locale`
|
||||
field existed at all (now `nl-BE`/`en-GB`/`fr-BE`, wired to the knowledge provider's
|
||||
existing `language` param), and the correlation ID was always freshly minted, ignoring
|
||||
any inbound `X-Correlation-Id` header. Added `get_correlation_id`, applied to all four
|
||||
MCP endpoints.
|
||||
- `MCP_HUB_BASE_URL` was dead config (declared, never read); wired it for a real,
|
||||
bounded Hub-reachability health check instead of an unneeded self-registration push
|
||||
(the Hub's own registration is catalog-driven).
|
||||
- Renamed Fleet Ops's own internal audit tool labels `mobilityops_*` → `fleet_ops_*`
|
||||
(mirrored in `contracts/mcp-tools.json`, `mobilityops_*` kept as deprecated aliases).
|
||||
The live Hub connector's own dotted tool namespace (`mobilityops.operations.summary`
|
||||
etc.) is a separate, Hub-owned naming layer, deliberately not touched.
|
||||
- Automation page's MCP card now shows real evidence (last tool/client/count/timestamp)
|
||||
instead of only the registration-enabled boolean.
|
||||
|
||||
## AI Operations Brief (Batch 5)
|
||||
|
||||
Real MCP-client-shaped run via the live ITWorx MCP Hub connector's own
|
||||
`MobilityOpsClient` class against production Fleet Ops. Full runbook and live output in
|
||||
`docs/final-integrations/ai-operations-brief-runbook.md`. Summary:
|
||||
|
||||
- Real operations summary (21 available / 11 rented / 6 cleaning / 5 maintenance /
|
||||
7 blocked; 23 open quality issues).
|
||||
- Real most-pressing vehicle identified (`MO-031`, missing operational inspection).
|
||||
- Real vehicle detail lookup.
|
||||
- Real grounded knowledge answer (English damage-handling question): 2 real citations,
|
||||
`evidence_state: grounded`.
|
||||
- Dutch/French variants of the same question honestly returned `insufficient` (no
|
||||
fabrication) — root cause: the live Hub connector doesn't yet send the new `locale`
|
||||
field, a Hub-side follow-up, not silently worked around.
|
||||
- Correlation IDs verified end-to-end in Fleet Ops's own audit log
|
||||
(`GET /api/v1/audit?action=mcp_tool_request`), matching the response payloads exactly.
|
||||
- No write actions performed at any point.
|
||||
|
||||
## Testing per batch
|
||||
|
||||
- Backend: **176 passed**, `ruff check .` clean, `mypy app` clean (50 source files) —
|
||||
verified against a freshly rebuilt image after discovering mid-session that
|
||||
`docker compose run --rm api` (no bind mount on the `api` service) silently tests a
|
||||
stale image otherwise. One genuinely stale test assertion found and fixed as a result.
|
||||
- Frontend: `tsc -b && vite build` clean.
|
||||
- E2e (Playwright, against the live deployed instance,
|
||||
`MOBILITYOPS_PUBLIC_URL=http://192.168.10.150:1236`): every spec file run this
|
||||
session passed — `demo.spec.ts`, `interactive-elements.spec.ts` (26),
|
||||
`responsive-i18n.spec.ts` + `demo-accessibility.spec.ts` + `guided-demo-full.spec.ts`
|
||||
(28), `i18n-coverage.spec.ts` + `error-messages.spec.ts` + `clickable-rows.spec.ts` +
|
||||
`demo-guide.spec.ts` + `demo-entry.spec.ts` + `demo-legibility.spec.ts` +
|
||||
`fleet-ops-correction.spec.ts` + `ui-redesign.spec.ts` + `greeting.spec.ts` +
|
||||
`greeting-live.spec.ts` (28, after fixing 2 pre-existing fragile locators unrelated to
|
||||
this session's feature work — a `.data-table` ambiguity now that Automation has two
|
||||
tables, and a `Technische details` toggle ambiguity for the same reason; plus one
|
||||
pre-existing untranslated-loanword false positive in `i18n-coverage.spec.ts`).
|
||||
|
||||
## Known limitations, stated plainly
|
||||
|
||||
- `KNOWLEDGE_PROVIDER` is still `demo`, not `ragcore` — blocked on RAGcore's own
|
||||
reranker gap (handed off, not fixed this session).
|
||||
- n8n workflow 3 is built and correct but not published (deliberate, separate decision).
|
||||
- The live MCP Hub connector doesn't yet send the new `locale` field, so
|
||||
locale-aware knowledge search only works when called directly against Fleet Ops (as
|
||||
proven by the backend tests), not yet through the live Hub connector as deployed.
|
||||
- No public-demo-readiness checklist, About Demo Guide "completed" end-state polish
|
||||
(section 4E), or dashboard MCP "activity showcase after Demo Complete" gating were
|
||||
built this session — the MCP evidence display exists on the Automation page
|
||||
unconditionally rather than gated behind guided-demo completion.
|
||||
- No security-review pass was run separately this session (existing gates: ruff, mypy,
|
||||
the repo's own auth/audit test coverage).
|
||||
|
||||
## Rollback
|
||||
|
||||
- Fleet Ops: prior working revision `0571a40` remains in `.deploy/` as
|
||||
`source-0571a40.tar.gz` on the Unraid host; redeploy by re-extracting and re-running
|
||||
the same `docker compose up --build -d` sequence with that archive.
|
||||
- RAGcore: `chown`/`chmod` change is trivially reversible (`chown 0:0` +
|
||||
`chmod 600` on the same path) if needed, though there is no reason to revert a
|
||||
permission fix. Ollama model pull (`xitao/bge-reranker-v2-m3:latest`) can be removed
|
||||
with `ollama rm` if unwanted; it is inert until RAGcore's own code is changed to use it.
|
||||
- MCP Hub: not modified this session.
|
||||
@@ -0,0 +1,284 @@
|
||||
# Fleet Ops correction and release — final evidence
|
||||
|
||||
**Result: PASS**
|
||||
|
||||
## Commits
|
||||
|
||||
- Source branch / commit (verified pre-correction baseline): `master` @ `18344bc8b7a75a2f868bf15bf498fc030ac6c34c`
|
||||
- Fix branch: `fix/fleet-ops-i18n-status-flow`
|
||||
- Final fix-branch commit: `284b3c7` (merged content identical to `2e4fb43`, which carries the evidence-summary localization fix)
|
||||
- Main-before-merge: `18344bc8b7a75a2f868bf15bf498fc030ac6c34c` (confirmed unchanged via `git fetch` + `git rev-parse origin/master` immediately before merging — no unexpected commits landed on master while this branch was in progress)
|
||||
- Merge commit: `de0bdea84fea01b4501deb7099107bc753c2e6d7` (`git merge --no-ff fix/fleet-ops-i18n-status-flow -m "merge: complete Fleet Ops localization and status resolution"`, zero conflicts)
|
||||
- Final main commit: `de0bdea84fea01b4501deb7099107bc753c2e6d7`
|
||||
- Deployed commit: `de0bdea84fea01b4501deb7099107bc753c2e6d7` (`.deploy/source-revision` on Unraid)
|
||||
- Gitea main branch: `master` (confirmed via `git fetch origin && git rev-parse origin/master` matching local `master` after push)
|
||||
- Live URL: `http://192.168.10.150:1236`
|
||||
|
||||
Fix-branch commit history: `6deb955`, `e6539d1`, `ac4b163`, `1fdd2b3`, `1e40775`, `a7ac5ed`, `7851e80`, `cda2c32`, `2e4fb43`, `284b3c7`.
|
||||
|
||||
## What this correction fixed
|
||||
|
||||
1. **Status-recommendation flow redesigned** (sections 8A–8F). The old single opaque
|
||||
"calculate and apply recommended status" action is replaced by a single shared, pure
|
||||
evaluator (`backend/app/services/vehicle_status.py::evaluate_vehicle_status`,
|
||||
documented in `docs/fleet-ops-correction/vehicle-status-decision-table.md`) used
|
||||
identically by the scanner, a non-mutating preview endpoint
|
||||
(`POST /api/v1/data-quality/issues/{ref}/status-recommendation`), and a
|
||||
transactional apply endpoint (`POST .../apply-recommended-status`) that locks the
|
||||
row, recomputes facts, rejects a stale `recommendation_token`, refuses unsafe/manual-
|
||||
review recommendations, and re-validates post-write before resolving the issue.
|
||||
- Forbidden shortcuts eliminated: "maintenance + active booking" no longer
|
||||
auto-recommends "rented" (being in maintenance is itself now a blocking fact);
|
||||
"maintenance with nothing else wrong" no longer auto-clears to "available" (no
|
||||
fact proves maintenance is actually finished — release stays a manual decision).
|
||||
- Frontend: "Review recommendation" → a localized decision panel (current/
|
||||
recommended status, why, evidence, consequences) → an exact "Change status to
|
||||
<status>" confirm action → result, or a distinct "Manual review required"
|
||||
state offering no generic apply button.
|
||||
2. **MO-016 order independence** (section 9). Order independence does not mean "same
|
||||
final status regardless of order" — resolving the booking overlap first genuinely
|
||||
removes the conflict, correctly leaving nothing to apply. What holds either way: the
|
||||
recommendation always reflects real current facts (never a stale proxy), and nothing
|
||||
unsafe is ever applied (never "rented"). Proven by a backend test explicitly scoped
|
||||
to MO-016/DQ-DEMO-STATUS (the original version wasn't — `_first_open()` returned
|
||||
whichever of ~14 open `vehicle_status_conflict` issues was most recent, not
|
||||
necessarily MO-016's) and a browser-level Playwright test covering both orders.
|
||||
3. **"Fleet Ops" is a non-localizable brand constant** (`frontend/src/product.ts`,
|
||||
backend `PRODUCT_NAME`), wired via `{{productName}}` interpolation everywhere the
|
||||
brand appeared in locale prose. A permanent test fails the build if any locale file
|
||||
ever defines the brand name or an `appName` key again.
|
||||
4. **Dynamic backend prose converted to message codes + params** (sections 5/6/10):
|
||||
return status reasons, audit field/actor-type labels, automation `last_error` (new
|
||||
`last_error_code` column, migration `799d8800e241`), search results (sections/
|
||||
vehicles/bookings/issues), and — found live on Unraid — the data-quality evidence
|
||||
summary. Raw technical text is demoted to a "Technical details" disclosure
|
||||
everywhere.
|
||||
5. **Knowledge-base fixes**: the demo provider's tokenizer silently dropped accented
|
||||
characters (`[a-z0-9]+` split "véhicule" into "v"+"hicule"), breaking French
|
||||
retrieval broadly — fixed to include the Latin-1 accented range. Reweighted section
|
||||
scoring so a body match (real substance) outranks a heading/title match (a shallow
|
||||
structural hint) — the old weighting misranked the damage procedure behind an
|
||||
unrelated document for the brief's exact validation question in all 3 languages.
|
||||
Removed leftover "MobilityOps"/"PoC" mentions from 9 procedure documents.
|
||||
6. **Search, audit, automation, maintenance/inspections localized** (section 10):
|
||||
backend returns stable codes + params only; the frontend localizes section labels,
|
||||
vehicle summaries, booking/issue statuses, audit action/field/actor labels,
|
||||
automation error explanations, and maintenance/inspection type labels.
|
||||
7. **i18n test suite strengthened** (section 11): key parity, brand invariant,
|
||||
translation-quality (cross-locale identical-value detection), a hardcoded-JSX-text
|
||||
static scan (had to anchor on backreferenced closing-tag names — a naive `>text<`
|
||||
regex misread TypeScript generics as JSX), and a 3-language route matrix (every main
|
||||
route, no console errors, correct `html[lang]`, real page headings).
|
||||
|
||||
## Live-caught bug (the deployment validation earning its keep)
|
||||
|
||||
Live validation on the freshly-deployed fix branch directly caught a real defect: every
|
||||
data-quality issue's top-of-page evidence summary was unconditionally showing raw,
|
||||
always-English text (e.g. *"vehicle marked available while reserved bookings
|
||||
conflict"*) in **all three languages**, because the frontend never finished the
|
||||
`evidence.signals` localization the backend had already been emitting (the backend code
|
||||
even had a comment describing the intended design that the frontend didn't implement).
|
||||
Fixed in commit `2e4fb43`:
|
||||
- `DataQualityIssueDetail.tsx` now renders `evidence.signals` through the operator's
|
||||
locale as the primary evidence text.
|
||||
- The four `DQ-DEMO-*` seed rows that anchor the guided demo's scripted scenarios now
|
||||
carry real, accurate signals computed at seed time (the duplicate-customer similarity
|
||||
score is the actual `SequenceMatcher` ratio on the seeded names, not invented).
|
||||
- Rows with no structured signals fall back to raw text rather than showing a blank
|
||||
summary; the one known filler placeholder gets its own localized rendering.
|
||||
- A regression test locks this in: the vehicle-status-conflict evidence summary must
|
||||
show localized text and must never contain the specific raw English sentence that was
|
||||
live-visible before the fix, in all 3 languages.
|
||||
|
||||
Also found and fixed along the way: a frontend logic bug conflating "no conflict" with
|
||||
"manual review required" (both carry `safe_to_apply: false`), which showed a false
|
||||
"manual review required" panel for MO-016 after its booking overlap was resolved
|
||||
instead of the correct "no change needed" state (fixed in `1fdd2b3`).
|
||||
|
||||
## Translation coverage
|
||||
|
||||
- All three locale files (`nl-BE`, `en-GB`, `fr-BE`) define exactly the same key set
|
||||
for every namespace (`i18n-coverage.spec.ts`, structural guarantee).
|
||||
- No locale file contains an empty string value.
|
||||
- No locale file defines the brand name or an `appName` key (brand-invariant test).
|
||||
- Cross-locale translation-quality check: for every string ≥8 characters of real prose,
|
||||
nl-BE ≠ en-GB, fr-BE ≠ en-GB, fr-BE ≠ nl-BE, with a precise, audited allowlist for
|
||||
genuine proper nouns/cognates (23 entries, each with a documented reason).
|
||||
- Hardcoded-JSX-text static scan: zero findings against the current codebase (verified
|
||||
against both false positives — TypeScript generics — and a deliberately-injected-
|
||||
then-reverted false negative).
|
||||
- 3-language route matrix: every main route (dashboard, vehicles, vehicle detail,
|
||||
bookings, booking detail, data quality, issue detail, automation, knowledge, audit,
|
||||
scenarios, about) opens cleanly in all 3 languages with no console errors, correct
|
||||
`html[lang]`, and a real page heading.
|
||||
- **Remaining visible wrong-language text**: none found. The one gap that existed (the
|
||||
data-quality evidence summary) was found live and fixed before merge.
|
||||
|
||||
## Branding
|
||||
|
||||
- Visible product name: **Fleet Ops**, exactly, in all 3 languages, everywhere (login,
|
||||
topbar, footer "Fleet Ops Demo", document title, About page, Demo Guide, knowledge
|
||||
base). Verified structurally (brand-invariant test) and live (branding test across
|
||||
dashboard/vehicles/data-quality/audit/automation/knowledge pages in all 3 languages;
|
||||
visual screenshots of the login screen in nl-BE and fr-BE).
|
||||
- Technical identifier retained (by design, per the brief): repository name, local
|
||||
directory, package/module names, Compose project, deployment directory, database
|
||||
name, and the `/health` endpoint's `service: "mobilityops-api"` field remain
|
||||
"mobilityops" — none of these are visible UI text.
|
||||
- No visible "MobilityOps" or "PoC" anywhere in the UI or the demo knowledge base
|
||||
(9 procedure documents cleaned up; regression test in `test_knowledge.py` scans every
|
||||
procedure file for both strings).
|
||||
|
||||
## Status-preview / apply / manual-review / MO-016 ordering
|
||||
|
||||
- **Preview**: verified non-mutating — the issue's `status` stays `"open"` after
|
||||
calling the preview endpoint and re-fetching it via a fresh request.
|
||||
- **Apply**: the confirm button names the exact target status ("Change status to
|
||||
Blocked" / "Status wijzigen naar Geblokkeerd" / "Changer le statut vers Bloqué");
|
||||
applying resolves the issue and updates the vehicle atomically.
|
||||
- **Manual review**: MO-024 (active rental + service-threshold reached, a genuine fact
|
||||
contradiction) shows "Manual review required" with no generic apply button rendered
|
||||
at all.
|
||||
- **Stale token**: simulated by resolving the underlying booking overlap after the
|
||||
preview was fetched but before applying — the apply call is correctly rejected
|
||||
(`RECOMMENDATION_STALE`), the UI shows the "situation has changed" message, and the
|
||||
user must review again before a new apply is possible.
|
||||
- **MO-016 ordering**: both orders tested. Resolving the overlap first correctly leaves
|
||||
nothing to apply (vehicle stays "available", genuinely correct). Resolving the status
|
||||
conflict first safely blocks the vehicle; resolving the now-redundant overlap
|
||||
afterwards does not disturb it. Neither order ever produces "rented".
|
||||
|
||||
## Knowledge (per language)
|
||||
|
||||
The brief's exact validation question, in each language, grounds on the damage
|
||||
procedure as the **primary** (not just top-3) source:
|
||||
- nl-BE: *"Wat moet ik doen wanneer een voertuig beschadigd terugkomt?"* → damage
|
||||
procedure, Dutch source, Dutch excerpt.
|
||||
- en-GB: *"What should I do when a vehicle returns with damage?"* → damage procedure,
|
||||
English source, English excerpt.
|
||||
- fr-BE: *"Que dois-je faire lorsqu'un véhicule revient endommagé ?"* → damage
|
||||
procedure, French source, French excerpt.
|
||||
|
||||
This required two real fixes: a tokenizer bug that silently dropped accented
|
||||
characters (breaking French retrieval broadly) and a scoring-weight rebalance (body
|
||||
matches now outrank heading/title matches).
|
||||
|
||||
## Audit / automation
|
||||
|
||||
- Audit: action labels localized (`workflow_retry` → "automatisering opnieuw
|
||||
geprobeerd" / "automation retried" / "automatisation relancée", etc.), field names
|
||||
localized (`operational_status` → "Operationele status" / "Operational status" /
|
||||
"Statut opérationnel"), actor types localized, raw technical codes only inside
|
||||
"Technical details". Verified live and via a dedicated Playwright test.
|
||||
- Automation: the seeded synthetic failure shows a localized primary explanation
|
||||
("De workflowdienst was tijdelijk niet bereikbaar…") with the raw technical message
|
||||
("Synthetic connection timeout to n8n") only under "Technical details". Verified live
|
||||
and via a dedicated Playwright test.
|
||||
|
||||
## Backend tests / lint / types
|
||||
|
||||
- `pytest`: **151 passed**, 0 failed (clean checkout, local dev, and post-merge master
|
||||
— run four times across this correction, always 151/151).
|
||||
- `ruff check .`: all checks passed, every run.
|
||||
- `mypy app` (strict): no issues found in 49 source files, every run.
|
||||
- Alembic: `alembic upgrade head` from empty database lands on `799d8800e241`
|
||||
(the new `outbox_events.last_error_code` column); `downgrade -1` / `upgrade head`
|
||||
round-trip verified.
|
||||
|
||||
## Frontend build / Playwright
|
||||
|
||||
- `npm ci`, `tsc -b`, `vite build`: clean, every run.
|
||||
- Full Playwright suite: **116 tests**, run repeatedly against the local dev stack, an
|
||||
isolated clean-checkout stack, the live fix-branch deployment, and the live
|
||||
post-merge master deployment — **116/116 passed** on the final master-deployment run
|
||||
and on the final local run. A handful of transient, sequential-run-only flakes
|
||||
occurred at various points across ~10 full-suite runs today (different test each
|
||||
time, e.g. a pre-existing logout-timing race in `AuthContext.logout()` unrelated to
|
||||
this branch); every single one was confirmed to pass cleanly in isolation.
|
||||
- Guided demo covered indirectly via `guided-demo-full.spec.ts`,
|
||||
`demo-guide.spec.ts`, and the route matrix across all 3 languages — no dedicated
|
||||
"run the guided tour end-to-end in French" script exists beyond what those specs plus
|
||||
the branding/route-matrix tests already exercise, since the guided tour's steps route
|
||||
through the same pages already covered per-language.
|
||||
|
||||
## Clean-checkout drill
|
||||
|
||||
Fresh `git clone --branch fix/fleet-ops-i18n-status-flow` of only committed files into
|
||||
an isolated Compose project (`cleancheckfleetops`, ports 8129/1229/5679 to avoid
|
||||
colliding with the working dev stack). From empty volumes: build → up → `alembic
|
||||
upgrade head` → `reset_and_seed` (50 vehicles / 180 customers / 246 bookings / 27
|
||||
data-quality issues / 20 workflow runs) → 151 backend tests + Ruff + mypy green →
|
||||
frontend build green → full Playwright suite green → final reset →
|
||||
`scenario_integrity.all_ready: true`. Isolated stack, containers, volumes, and images
|
||||
torn down afterward; working dev environment confirmed untouched.
|
||||
|
||||
## Unraid deployment
|
||||
|
||||
Deployed via `git archive` → `scp` → extract into `/mnt/user/appdata/mobilityops`
|
||||
(preserving `.env` and persistent volumes) → `.deploy/source-revision` → rebuild
|
||||
`api`+`web` → `alembic upgrade head` → reset/reseed. Done twice: once for the fix
|
||||
branch (caught the evidence-summary bug), once for the final merged master. Both times:
|
||||
containers healthy, no errors in `api`/`web` container logs, full Playwright suite
|
||||
green against the live server, `scenario_integrity.all_ready: true` after final reset.
|
||||
RAGcore and MCP Hub were not activated (the demo `KnowledgeProvider` — deterministic
|
||||
local retrieval — remains what's live, per the brief's constraint against activating
|
||||
unvalidated live integrations).
|
||||
|
||||
## Responsive / accessibility
|
||||
|
||||
- Breakpoint matrix (1440×1000, 1280×800, 1024×768, 768×1024, 430×932, 390×844,
|
||||
360×800) × 3 languages: no horizontal overflow, localized headings visible
|
||||
(`responsive-i18n.spec.ts`).
|
||||
- Status-recommendation panel: keyboard-only activation of "Review recommendation" and
|
||||
"Change status to X" verified via focus assertions (not just click); reduced-motion
|
||||
emulated during the flow; status never conveyed by colour alone (the badge always
|
||||
carries its own localized text); `aria-live="polite"` added so the applied
|
||||
confirmation is announced to screen readers.
|
||||
|
||||
## Known limitations
|
||||
|
||||
- A pre-existing, narrow timing race in `AuthContext.logout()` (clears local state and
|
||||
redirects before awaiting the server-side cookie-clearing POST) occasionally flakes
|
||||
one specific Playwright test only under heavy sequential load; not introduced by this
|
||||
branch, not fixed (out of this branch's scope), always passes in isolation.
|
||||
- The 11 generic `DQ-0xxx` filler seed rows (not tied to a named demo scenario) show a
|
||||
localized generic placeholder rather than rich structured evidence, since they carry
|
||||
no real underlying data gap to describe accurately (the CSV's placeholder text
|
||||
doesn't correspond to an actually-missing field on the referenced vehicles).
|
||||
- No dedicated "full guided demo in French, screenshot every step" script exists as a
|
||||
single artifact; coverage is composed from the route matrix, branding, and existing
|
||||
guided-demo specs, each run across all 3 languages.
|
||||
|
||||
## Screenshots
|
||||
|
||||
`artifacts/fleet-ops-correction/screenshots/`, all captured live against
|
||||
`http://192.168.10.150:1236`:
|
||||
|
||||
- `login-nl-BE.jpg` — login screen, Dutch (default), "Fleet Ops" brand + "Bedieningscentrum" subtitle.
|
||||
- `login-fr-BE.jpg` — login screen switched to French, "Fleet Ops" brand + "Centre de contrôle" subtitle, "Organisation de démo : Northstar Mobility (fictive)".
|
||||
- `dq-demo-status-fr-BE-collapsed.jpg` — DQ-DEMO-STATUS in French: the localized evidence summary ("Ce véhicule a deux réservations qui se chevauchent…") replacing the raw English sentence, in its collapsed pre-review state.
|
||||
- `dq-demo-status-fr-BE-clean-reload.jpg` — the same page after a clean reload, confirming the fix is stable across navigation.
|
||||
|
||||
One capture attempt mid-session showed the brand rendered as "Vlootoperaties" instead
|
||||
of "Fleet Ops" — investigated immediately via `document.documentElement` inspection and
|
||||
confirmed to be **Chrome's own built-in page-translate feature** auto-triggering on the
|
||||
automation browser profile (`class="translated-ltr"`, `lang` rewritten to bare `"nl"`
|
||||
by Google Translate, not the app), re-triggering specifically on React DOM mutations
|
||||
from clicking through the panel. Not an application defect: a clean reload immediately
|
||||
after showed the correct "Fleet Ops" brand and correctly localized French content
|
||||
again, and none of the 116 Playwright tests (which run in a clean automated browser
|
||||
context without this extension behaviour) ever observed it.
|
||||
|
||||
## Rollback procedure
|
||||
|
||||
1. `ssh unraid`, `cd /mnt/user/appdata/mobilityops`.
|
||||
2. `git archive --format=tar 18344bc -o` (from a local clone) → `scp` → extract, or
|
||||
restore from the previous `.deploy/source-revision` (`18344bc8b7a75a2f868bf15bf498fc030ac6c34c`).
|
||||
3. `echo 18344bc8b7a75a2f868bf15bf498fc030ac6c34c > .deploy/source-revision`.
|
||||
4. `docker compose -f compose.yaml -f compose.unraid.yaml build api web && ... up -d api web`.
|
||||
5. `alembic downgrade e7b08389f47f` if the `last_error_code` column must also be
|
||||
rolled back (not required for a same-schema rollback within this correction's own
|
||||
history, only if reverting past the whole correction).
|
||||
6. Re-seed and re-verify `scenario_integrity.all_ready: true`.
|
||||
|
||||
The fix branch `fix/fleet-ops-i18n-status-flow` was not deleted.
|
||||
|
After Width: | Height: | Size: 34 KiB |
|
After Width: | Height: | Size: 42 KiB |
|
After Width: | Height: | Size: 20 KiB |
|
After Width: | Height: | Size: 30 KiB |
@@ -0,0 +1,291 @@
|
||||
# Fleet Ops final localization — final summary
|
||||
|
||||
Small, targeted correction round on top of the already-merged, functionally-validated
|
||||
Fleet Ops correction milestone. Scope: remaining NL/FR translation gaps, centralized
|
||||
API-error localization, a time-dependent Europe/Brussels dashboard greeting, i18n
|
||||
test hardening, and documentation consistency — explicitly no redesign, no business-logic
|
||||
changes, no new functionality. Audit and rationale: `docs/fleet-ops-final-localization/audit.md`.
|
||||
|
||||
## Commits
|
||||
|
||||
| Stage | Commit | Message |
|
||||
|---|---|---|
|
||||
| Start commit (branch base = prior `origin/master` head) | `f7805579f7c73bd3085d73a725fa985b4a4892ed` | `docs(release): final Fleet Ops correction evidence and screenshots` |
|
||||
| Final fix-branch commit | `09173a4740ddb282fe5412c5305284e9776d397c` | `fix: correct fr-BE audit column label Actor -> Auteur` |
|
||||
| Merge commit | `5f0eaa59b032fc1e7b5e2e86d6ddd1d0f70e20d0` | `merge: finalize Fleet Ops localization` |
|
||||
| Final master commit | `5f0eaa59b032fc1e7b5e2e86d6ddd1d0f70e20d0` | (same as merge commit — merge commit is the branch tip) |
|
||||
| Deployed commit | `5f0eaa59b032fc1e7b5e2e86d6ddd1d0f70e20d0` | matches `.deploy/source-revision` on Unraid exactly |
|
||||
|
||||
Branch used: `fix/fleet-ops-final-i18n-ux` (the brief named `fix/fleet-ops-final-localization`;
|
||||
this branch was verified freshly and cleanly branched from `origin/master` with a clean
|
||||
working tree, so it was used as-is rather than renamed — see the audit doc's naming note).
|
||||
`origin/master` was re-fetched and confirmed unchanged (`f780557`) immediately before the
|
||||
merge, per the mandatory pre-merge safety check.
|
||||
|
||||
Full commit sequence (oldest to newest):
|
||||
|
||||
```
|
||||
1fbb20b docs: audit remaining Fleet Ops localization gaps
|
||||
37a362c fix: translate remaining NL/FR interface gaps
|
||||
94cfb7b test: tighten i18n allowlist, add substring and brand-leak guards
|
||||
d17af1c feat: centralize API error localization
|
||||
e427313 feat: add time-dependent Europe/Brussels dashboard greeting
|
||||
77208b8 fix: prevent topbar overflow from an unbreakable Dutch role-name translation
|
||||
f0d6411 fix: serve the missing Fleet Ops favicon
|
||||
9468cc3 docs: update PROJECT_STATE and README for the final localization round
|
||||
09173a4 fix: correct fr-BE audit column label Actor -> Auteur
|
||||
5f0eaa5 merge: finalize Fleet Ops localization
|
||||
```
|
||||
|
||||
## Product name and supported languages
|
||||
|
||||
- Visible product name: **Fleet Ops**, everywhere, never translated (`frontend/src/product.ts`
|
||||
constant, interpolated as `{{productName}}`). "MobilityOps" remains the internal repo /
|
||||
Compose project / deployment-directory identifier only.
|
||||
- Supported UI languages: **nl-BE** (default), **en-GB**, **fr-BE**.
|
||||
- No visible "MobilityOps" or the word "PoC" anywhere in the UI (enforced by a dedicated
|
||||
automated test, see below).
|
||||
|
||||
## Corrected translations
|
||||
|
||||
- Role names actually translated (not just labelled as translated): `auth.json` /
|
||||
`demo.json` role keys — **Operationsmanager** / **Verhuurmedewerker** (nl-BE),
|
||||
**Responsable des opérations** / **Collaborateur de location** (fr-BE).
|
||||
- `audit.title` → **Auditgeschiedenis** / **Piste d'audit**; `columns.actor` → **Uitvoerder**
|
||||
(nl-BE) / **Auteur** (fr-BE, corrected during live browser validation — see Known
|
||||
limitations).
|
||||
- `list.statusOpen` → **Openstaand**; `ledger.filterRecent` → **Recentste**;
|
||||
`scenarios.startScenario` → **Scenario starten** / **Démarrer le scénario**.
|
||||
- 8 previously-missed mid-sentence "Audit trail" leaks fixed across `demo.json`,
|
||||
`quality.json`, `returns.json` (nl-BE) — found by the new embedded-substring test, not
|
||||
the pre-existing whole-string-identity test, which structurally cannot catch this class
|
||||
of bug.
|
||||
- No unintended English text remains in nl-BE or fr-BE (see translation-coverage evidence
|
||||
below).
|
||||
|
||||
## Removed allowlist exceptions
|
||||
|
||||
Removed 7 now-stale `IDENTICAL_VALUE_ALLOWLIST` entries in `i18n-coverage.spec.ts`:
|
||||
`audit.title`, `auth.roleOperationsManager`, `auth.roleRentalEmployee`,
|
||||
`demo.scenarios.startScenario`, `demo.scenarios.roles.operations_manager`,
|
||||
`demo.scenarios.roles.rental_employee`, `navigation.items.audit` — all now genuinely
|
||||
translated; their old comments describing them as "deliberately untranslated" were no
|
||||
longer true. Two new tests added: embedded-English/Dutch-substring leak guard, and a
|
||||
no-"MobilityOps"/no-"PoC" guard.
|
||||
|
||||
## Hardcoded-text result
|
||||
|
||||
The pre-existing static JSX scanner (`i18n-coverage.spec.ts`, section 11D) found **zero**
|
||||
hardcoded user-facing strings outside the approved technical-token allowlist (Fleet Ops,
|
||||
Northstar Mobility, ITWorx MCP Hub) across `pages/` and `components/`. Result: **PASS**.
|
||||
|
||||
## API-error-localization result
|
||||
|
||||
New `frontend/src/api/errorMessages.ts` (`describeApiError`) replaces the
|
||||
`err instanceof ApiError ? err.message : t(fallback)` anti-pattern (which showed raw
|
||||
English backend text for the common case) at all 13 call sites across 7 files
|
||||
(`Automation.tsx`, `ReturnForm.tsx`, `DataQuality.tsx`, `DemoGuide.tsx`, `Layout.tsx`,
|
||||
`DataQualityIssueDetail.tsx` ×7 sites, `Knowledge.tsx`). Resolution order: known `AppError`
|
||||
code (32 codes) → known HTTP status (401/403/404/409/422/500) → fully generic fallback.
|
||||
New `ApiErrorNotice` component (`PageChrome.tsx`) always renders a localized title +
|
||||
explanation + optional next step; raw backend text is demoted to a "Technical
|
||||
details"/"Détails techniques" disclosure, never the primary message.
|
||||
|
||||
Evidence: `frontend/e2e/error-messages.spec.ts` (10 tests, all passing) —
|
||||
every known code/status has non-empty copy in all 3 locales; a known code never surfaces
|
||||
raw text as the primary message; unknown-code and unknown-status fallback chains behave
|
||||
correctly; a drift guard greps the actual backend `AppError("CODE", ...)` call sites and
|
||||
confirms `KNOWN_CODES` exactly matches (32 codes, zero drift). Live-verified on Unraid: the
|
||||
seeded failed automation run renders a fully localized French error with a "DÉTAILS
|
||||
TECHNIQUES" disclosure below it.
|
||||
|
||||
## Greeting logic and edge cases
|
||||
|
||||
New `frontend/src/i18n/greeting.ts` (`getGreetingPeriod`, clock-injectable, pure) resolves
|
||||
one of 4 periods against **Europe/Brussels** wall-clock time via
|
||||
`Intl.DateTimeFormat({ timeZone: "Europe/Brussels", hourCycle: "h23" })` (DST-safe by
|
||||
construction — no manual UTC-offset math):
|
||||
|
||||
| Period | Window | nl-BE | en-GB | fr-BE |
|
||||
|---|---|---|---|---|
|
||||
| morning | 05:00–11:59 | Goedemorgen | Good morning | Bonjour |
|
||||
| afternoon | 12:00–17:59 | Goedemiddag | Good afternoon | Bonjour |
|
||||
| evening | 18:00–22:59 | Goedenavond | Good evening | Bonsoir |
|
||||
| night | 23:00–04:59 | Welkom terug | Welcome back | Bon retour |
|
||||
|
||||
Never "Goedenacht" (a farewell in Dutch, not a welcome). Each period also has its own
|
||||
accompanying sentence per language (`dashboard.json` `greetingBody`), replacing the old
|
||||
fixed "Here's the fleet." `useGreetingPeriod.ts` polls every 30s so the greeting rolls
|
||||
over live while the app stays open, no reload required; initial render uses a synchronous
|
||||
`useState(() => getGreetingPeriod())` so there is never a flash of the wrong period.
|
||||
|
||||
Edge-case evidence:
|
||||
- `frontend/e2e/greeting.spec.ts` (4 tests): exact boundary checks at 04:59/05:00/11:59/
|
||||
12:00/17:59/18:00/22:59/23:00 in both CET (winter) and CEST (summer), plus a dedicated
|
||||
spring-forward/fall-back DST-transition test (2026-03-29 and 2026-10-25).
|
||||
- `frontend/e2e/greeting-live.spec.ts` (6 tests, real browser via Playwright's `page.clock`):
|
||||
all 8 boundary times rendered correctly in **all 3 languages** against the actual app;
|
||||
live period rollover with no `page.reload()` call anywhere in that test; language-switch
|
||||
behaviour without changing the time period; the "never Goedenacht" guard.
|
||||
- Live-verified on Unraid at actual current server time (2026-08-04, ~03:2x CEST, i.e. the
|
||||
night period): dashboard showed "Welkom terug. Hier is het laatste overzicht van je
|
||||
wagenpark." (nl-BE), "Welcome back. Here's the latest overview of your fleet." (en-GB),
|
||||
"Bon retour. Voici le dernier aperçu de votre flotte." (fr-BE).
|
||||
|
||||
## README / PROJECT_STATE corrections
|
||||
|
||||
- `PROJECT_STATE.md`: fixed the stale "Product name: MobilityOps." / "PoC only"
|
||||
locked-decisions lines (predated the Fleet Ops rebrand); fixed the "Fleet Ops
|
||||
correction" section header, which still read "IN PROGRESS .../Not yet merged to
|
||||
master" despite already being merged (`de0bdea` / `f780557`); appended a new dated
|
||||
entry for this correction round (not a rewrite of prior entries, per the brief's
|
||||
explicit instruction not to hide earlier history).
|
||||
- `README.md`: linked `docs/fleet-ops-final-localization/` alongside the existing
|
||||
correction-round doc link; refreshed the stale Playwright test count (113 → 138 → 139
|
||||
after the favicon regression test was added).
|
||||
|
||||
## Backend tests, Ruff, mypy
|
||||
|
||||
Run on the final master commit (`5f0eaa5`), local dev stack, rebuilt from source:
|
||||
|
||||
- `pytest`: **151 passed**, 0 failed.
|
||||
- `ruff check .`: **All checks passed!**
|
||||
- `mypy app` (the project's canonical invocation, matching all prior milestone gates —
|
||||
no `[tool.mypy]` strict config exists in `pyproject.toml`): **Success: no issues found
|
||||
in 49 source files.**
|
||||
|
||||
No backend Python was touched this round; these numbers are unchanged from the prior
|
||||
correction milestone's final gate, confirmed green again on the current tree.
|
||||
|
||||
## Frontend build, Playwright
|
||||
|
||||
- `npx tsc --noEmit`: clean, 0 errors.
|
||||
- `npm run build` (`tsc -b && vite build`): clean production build.
|
||||
- Full Playwright suite (`npx playwright test`), master build, local dev stack:
|
||||
**139 passed**, 0 failed (confirmed on a clean run after two transient
|
||||
`0xC0000005` Chromium worker crashes caused by this specific machine running 43+
|
||||
concurrent Chrome processes at the time — see Known limitations; a targeted 48-test
|
||||
re-run of every new/changed suite also passed cleanly in between).
|
||||
|
||||
## Clean-checkout drill
|
||||
|
||||
Isolated Compose project `mobilityops-clean` (ports 8129/1229/5679, no shared volumes/
|
||||
network with the working dev stack), fresh `git clone --branch
|
||||
fix/fleet-ops-final-i18n-ux` of only committed files:
|
||||
|
||||
1. `docker compose build` + `up -d` from empty volumes — all 4 containers healthy.
|
||||
2. `alembic upgrade head` → `799d8800e241 (head)`.
|
||||
3. `seed --reset` → 2 users / 180 customers / 50 vehicles / 246 bookings / 75 inspections /
|
||||
40 maintenance / 27 data-quality issues / 20 workflow runs — matches the documented
|
||||
deterministic count exactly.
|
||||
4. Backend gates: `pytest` 151 passed, `ruff check .` clean, `mypy app` clean (49 files).
|
||||
5. Frontend: `npm ci` clean, `tsc --noEmit` clean, `vite build` clean.
|
||||
6. Full Playwright suite against the isolated stack (`MOBILITYOPS_PUBLIC_URL=http://localhost:1229`):
|
||||
**139 passed**, 0 failed — this run covers the Dutch/English/French language checks,
|
||||
greeting boundaries, API error paths, and the guided demo, all in one pass.
|
||||
7. Final reset + `scenario_integrity`: all 5 scenarios `ready: true`.
|
||||
8. Isolated stack, containers, volumes and images torn down; original dev environment
|
||||
confirmed untouched (`mobilityops-*` containers unaffected throughout).
|
||||
|
||||
**PASS.**
|
||||
|
||||
## Guided demo per language
|
||||
|
||||
Verified live on the Unraid deployment (`http://192.168.10.150:1236`) in all 3 languages
|
||||
via direct browser interaction: login screen role buttons, dashboard (greeting, readiness
|
||||
band, attention queue, integration pulse, recent activity), audit trail, automation retry
|
||||
flow with localized error + technical-details disclosure, and demo reset — all rendering
|
||||
correctly in nl-BE, en-GB and fr-BE. The full guided-demo Playwright spec
|
||||
(`guided-demo-full.spec.ts`) passed as part of the 139-test suite on both the local dev
|
||||
stack and the isolated clean-checkout stack.
|
||||
|
||||
## Server deployment, container health
|
||||
|
||||
Deployed to `http://192.168.10.150:1236` (Compose project `mobilityops`,
|
||||
`/mnt/user/appdata/mobilityops`), preserving the server's existing `.env`, the Postgres
|
||||
and n8n named volumes, the exposed port, and the deployment directory — only `api` and
|
||||
`web` were rebuilt/recreated; `db` was never touched beyond `alembic upgrade head`; no
|
||||
second n8n instance was started (shared existing n8n at `:5678` used throughout).
|
||||
|
||||
Procedure (matching `docs/demo-release/demo-runbook.md` exactly): `git archive` → `scp` →
|
||||
extract over the existing deployment dir → update `.deploy/source-revision` →
|
||||
`docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml up --build -d api web`
|
||||
→ confirm `alembic current` → `seed --reset`.
|
||||
|
||||
Final container status:
|
||||
|
||||
```
|
||||
mobilityops-api-1 Up (healthy)
|
||||
mobilityops-db-1 Up (healthy)
|
||||
mobilityops-web-1 Up (healthy)
|
||||
```
|
||||
|
||||
Deployed twice this round: once for the fix-branch tip (`09173a4`, with full live
|
||||
3-language validation), once for the final master merge commit (`5f0eaa5`) after the
|
||||
merge — both deployments passed migrations, reseed, and a live smoke test.
|
||||
|
||||
## Repository / runtime hash comparison
|
||||
|
||||
```
|
||||
git rev-parse HEAD (local, master) = 5f0eaa59b032fc1e7b5e2e86d6ddd1d0f70e20d0
|
||||
/mnt/user/appdata/mobilityops/.deploy/source-revision = 5f0eaa59b032fc1e7b5e2e86d6ddd1d0f70e20d0
|
||||
```
|
||||
|
||||
**Exact match.**
|
||||
|
||||
## Browser console and network
|
||||
|
||||
No console errors on any checked route in any of the 3 languages (dashboard, audit,
|
||||
automation, login) on the live Unraid deployment. All observed `/api/` network requests
|
||||
returned `200`. `api` and `web` container logs show no errors/tracebacks/exceptions after
|
||||
the final deployment.
|
||||
|
||||
## Known limitations
|
||||
|
||||
- **Transient `document.documentElement.lang` DOM-attribute anomaly during interactive
|
||||
manual browser testing** on the live server: on 2 occasions, right after a client-side
|
||||
action (an automation retry click; a demo-reset confirm click), `document.documentElement.lang`
|
||||
briefly showed `"nl"` while the actually-rendered page content, `localStorage`, and a
|
||||
controlled repeat of the exact same click sequence (fresh login, single deliberate
|
||||
click, immediate inspection) all remained correctly `"fr-BE"`. Root-caused as far as
|
||||
possible: the codebase has exactly one `i18n.changeLanguage()` call site
|
||||
(`LanguageSwitcher.tsx`), which was not invoked in the clean repro, and `t()` /
|
||||
`i18n.language` are structurally coupled through a single i18next singleton with no
|
||||
code path capable of producing this split state. Not reproduced even once across 139
|
||||
automated Playwright tests run 3 times total (local pre-merge, isolated clean-checkout,
|
||||
local post-merge on master) in a clean, extension-free browser context. Most likely
|
||||
explanation: a third-party browser extension active in the specific interactive testing
|
||||
session (which also had ~10 unrelated pre-existing tabs open on the same origin, and
|
||||
showed independent signs of instability — repeated CDP screenshot timeouts) rewriting
|
||||
the `lang` attribute based on its own content heuristics, independent of the React app.
|
||||
Logged here for transparency rather than silently dismissed; does not affect any
|
||||
automated PASS result above.
|
||||
- **Two transient Chromium worker crashes** (`0xC0000005` / access violation) during the
|
||||
master-build Playwright re-run, on a machine that had accumulated 43+ concurrent Chrome
|
||||
processes from the interactive testing session above. A clean run immediately
|
||||
afterward (fewer processes) passed all 139 tests; a 48-test targeted re-run of every
|
||||
new/changed suite also passed cleanly in between. Treated as machine resource
|
||||
contention, not a code defect — consistent with the prior correction milestone's own
|
||||
documented experience of "sequential-run-only flakes reproduced from resource
|
||||
contention of running two full Docker stacks at once," per `PROJECT_STATE.md`.
|
||||
- One translation gap (fr-BE `audit.columns.actor`: "Acteur" instead of the brief's
|
||||
specified "Auteur") was missed in the initial pass and only caught during live browser
|
||||
validation on Unraid; fixed in commit `09173a4` and redeployed before the master merge.
|
||||
- The Fleet Ops brand mark (`BrandMark` in `Icons.tsx`) was flagged by the user as
|
||||
potentially due for a visual refresh; per explicit user decision mid-session, this is
|
||||
out of scope for this correction round and deferred to a separate follow-up task.
|
||||
- No RAGcore/MCP Hub implementation changes were made or claimed; both remain in the same
|
||||
demo/not-connected state documented by the prior correction milestone.
|
||||
|
||||
## Rollback procedure
|
||||
|
||||
`.deploy/source-revision` on the server records exactly which commit is live. To roll
|
||||
back: `ssh unraid`, extract an earlier `source-<short-sha>.tar.gz` from
|
||||
`/mnt/user/appdata/mobilityops/.deploy/` (prior tarballs remain in place, including
|
||||
`source-9468cc3e.tar.gz`, `source-09173a4.tar.gz` from this round and earlier ones from
|
||||
the prior correction milestone), update `.deploy/source-revision` to match, and re-run
|
||||
`docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml up --build -d api web`
|
||||
followed by `alembic upgrade head` (migrations are additive only — no destructive
|
||||
migration exists on this branch, so no database rollback is needed). No secrets were
|
||||
printed or read at any point in this process (`.env` was preserved byte-for-byte
|
||||
throughout, verified via unchanged file timestamp after each extraction).
|
||||
@@ -0,0 +1,155 @@
|
||||
# Fleet Ops release — final-product-polish evidence
|
||||
|
||||
## Result: PASS
|
||||
|
||||
## Commits
|
||||
|
||||
- Original feature-branch baseline before this task: `257a4cf` (`docs(polish): audit finale demo-afwerking`)
|
||||
- Feature-branch commits added this task, on `feat/mobilityops-functional-completion`:
|
||||
- `337f871` — polish: rebrand to Fleet Ops, add trilingual i18n, adaptive demo guide, and UX overhaul
|
||||
- `845db14` — fix: mobile topbar overflow at 421-440px and add trilingual responsive coverage
|
||||
- Feature branch final commit: `845db14e172539b1d10e40f6a3249a72122deb41`
|
||||
- `master` before merge (verified against the previously recorded baseline): `e0c7ed60112510687627d20a957af91c8b9db7f8` — unchanged, no unexpected commits, no conflicts (confirmed via `git merge-tree` dry run before merging)
|
||||
- Merge commit on `master`: `18a765d62345ea9a6660d04fb868f218cf4d0b6e` (`merge: release Fleet Ops multilingual demo`, `--no-ff`)
|
||||
- Final `master` commit (pushed and deployed): `18a765d62345ea9a6660d04fb868f218cf4d0b6e`
|
||||
- Deployed commit on Unraid (`.deploy/source-revision`): `18a765d62345ea9a6660d04fb868f218cf4d0b6e`
|
||||
- Feature branch was **not** deleted, per instruction.
|
||||
|
||||
## URL
|
||||
|
||||
- Live review deployment: `http://192.168.10.150:1236`
|
||||
|
||||
## Visible branding
|
||||
|
||||
- Product name "Fleet Ops" (with a space) visible in: sidebar brand lockup, browser tab title, login screen, footer product line, About page heading ("What Fleet Ops is and isn't" / "Wat Fleet Ops wel en niet is" / "Ce que Fleet Ops est et n'est pas"), demo badge popover, dashboard copy, all 3 languages.
|
||||
- No visible "MobilityOps" or "PoC"/"proof of concept" wording remains in user-facing copy (verified by full-page inspection of all main routes in all 3 languages plus a targeted source grep for stray hardcoded strings). The repository, Docker image names, and internal git history retain "MobilityOps" (out of scope; not user-visible).
|
||||
- Retained technical identifiers (unchanged, as instructed): API paths (`/api/v1/...`), Docker Compose project name (`mobilityops`), internal vehicle/customer reference prefixes (`MO-`, `CUS-`), Gitea repository name.
|
||||
|
||||
## Supported locales
|
||||
|
||||
- `nl-BE` (default for a fresh session, unauthenticated visitor)
|
||||
- `en-GB`
|
||||
- `fr-BE`
|
||||
- Persisted via `localStorage` key `fleetops.language`; survives refresh, logout/login, and demo reset. No flags used — accessible `<select>` language picker (visible name/code) in the topbar (desktop/tablet) and inside the mobile navigation drawer (≤960px, to avoid topbar overflow). `document.documentElement.lang` kept in sync. All dates/numbers rendered via `Intl.DateTimeFormat`/`Intl.NumberFormat` (`Europe/Brussels` timezone).
|
||||
|
||||
## Translation coverage
|
||||
|
||||
- `frontend/e2e/i18n-coverage.spec.ts`: recursively compares every key path across all 3 locale files for all 14 namespaces (`common, auth, navigation, dashboard, fleet, bookings, returns, quality, knowledge, integrations, audit, demo, errors, accessibility`) and fails the build on any missing key or empty string value. **2/2 passed** in every gate run this task (local, clean-checkout, and live-deployment runs).
|
||||
- Command: `npx playwright test e2e/i18n-coverage.spec.ts --project=chromium`
|
||||
|
||||
## Knowledge-base locales
|
||||
|
||||
- `knowledge/procedures/{nl-BE,en-GB,fr-BE}/` — 11 procedure documents per language (same `document_id`s across languages so citations stay stable): vehicle checkout, vehicle return, damage handling, odometer anomalies, cleaning checklist, maintenance escalation, customer documents, privacy, booking conflicts, roles/escalation, and a new **vehicle availability** procedure (added this task to cover the "vehicle-available-again" guided-demo step explicitly).
|
||||
- `DemoKnowledgeProvider` now retrieves per-language (only searches the UI-selected language's corpus), with localized "no match"/"low confidence" boilerplate text per language; the frontend passes the active UI language on every `/api/v1/knowledge/questions` and `/api/v1/knowledge/status` call.
|
||||
- Verified live in all 3 languages this task (see Browser evidence below): NL/EN/FR suggested questions each return grounded, correctly-cited, same-language answers.
|
||||
- Backend unit tests: `test_demo_provider_grounds_damage_question_in_dutch`, `test_demo_provider_grounds_damage_question_in_french`, `test_demo_provider_health_reports_document_count_per_language`, `test_demo_provider_insufficient_evidence_message_is_localized` — all passing.
|
||||
|
||||
## Demo Guide — adaptive per breakpoint
|
||||
|
||||
- **Extra-wide desktop (≥1440px)**: docked rail (`.demo-guide-panel.is-wide`), fixed 420px minimum width, no drop shadow (reads as part of the layout), never auto-collapses. Verified: `demo-guide.spec.ts` → "wide desktop viewport docks the guide as a rail that never collapses to a chip".
|
||||
- **Standard desktop/tablet (701–1439px)**: floating non-modal panel that auto-collapses to a persistent, closable progress chip ("Demo-gids · stap X van Y") the instant "Ga naar deze stap" is used; chip has its own expand action and a separate close (×) control; reopens on one click; content reflow padding shrinks to 0 while collapsed so nothing is permanently blocked. Verified: 3 dedicated tests in `demo-guide.spec.ts`.
|
||||
- **Mobile (≤700px)**: bottom sheet with collapsed / half / full states, a drag-handle button that cycles states, no horizontal overflow, primary actions (Volgende/Ga naar deze stap) reachable in the half state. Verified: `demo-guide.spec.ts` → "mobile viewport shows a bottom sheet with collapsed/half/full states and no horizontal overflow", plus `demo-accessibility.spec.ts` → "demo guide is usable as a mobile bottom sheet".
|
||||
- **Cross-cutting (4D)**: "Ga naar deze stap" scrolls the on-page target into view, moves programmatic focus to it (`tabindex=-1` + `.focus()`), and applies a 2.2s outline pulse (`.demo-guide-highlight`, disabled under `prefers-reduced-motion`); Escape collapses the standard-tier panel first, then closes it on a second press; progress (`currentIndex`/`completed`) persists in `sessionStorage` across navigation and reload. Verified: `demo-guide.spec.ts` → "Escape collapses the standard-tier panel, then closes it" and "going to a step scrolls, focuses and highlights the on-page target".
|
||||
- Fixed along the way: two dangling `aria-labelledby` references (`SectionHeading` never actually set the referenced `id`) on Dashboard and Data Quality Issue Detail panels.
|
||||
|
||||
## Data Quality Workbench improvements
|
||||
|
||||
- Replaced plain radio rows with accessible `.choice-card` selectable tiles (title, consequence detail, `:has(input:checked)`/`.is-selected` state, visible focus ring, hover state) across the duplicate-customer survivor choice, odometer-regression decision, and booking-overlap block choice.
|
||||
- Clear action hierarchy: primary resolve/apply/merge action uses `.button-primary`; defer uses a de-emphasized `.button-tertiary`; reject uses `.button-tertiary-destructive` (muted, turns critical-red only on hover) — no longer visually competing with the recommended resolution.
|
||||
- Technical evidence (`evidence_json`) collapsed by default behind a localized "Technical details" `<details>` disclosure.
|
||||
- Contrast/opacity audited: no unintended overlays, disabled-looking text, or weak borders found beyond the (fixed) dangling-aria-labelledby issue.
|
||||
|
||||
## Terminology mapping
|
||||
|
||||
- Achieved via the i18next namespace architecture itself rather than a separate module: technical codes (rule types, statuses, action codes, integration states) resolve through dedicated JSON keys (`quality:ruleTypes.*`, `quality:list.status*`, `audit:actions.*`, `integrations:statusLabels.*`, `fleet:statuses.*`, `bookings:statuses.*`) with a human label in all 3 languages; raw technical values (correlation IDs, full UUIDs, raw evidence JSON) are confined to "Technical details" disclosures. Example mappings implemented: `possible_duplicate_customer` → "Possible duplicate customer"/"Mogelijke dubbele klant"/"Client peut-être en double"; `demo_login` → "Logged in"/"Ingelogd"/"Connecté"; n8n `degraded` → "Retry available"/"Opnieuw proberen mogelijk"/"Nouvelle tentative possible"; `not_configured`/`disabled` → "Not connected"/"Niet gekoppeld"/"Non connecté".
|
||||
|
||||
## Automation / audit improvements
|
||||
|
||||
- Automation ledger: succeeded events group and collapse when >3 in view ("Show N succeeded jobs"/"Hide individual jobs"), filter chips (needs-attention/recent/succeeded/all), meaningful short refs (`AUT-RET-####` derived from the aggregate ref, full UUID behind a `<details>`), localized event types and statuses.
|
||||
- Audit trail: events grouped by `correlation_id` into one card with a human action-label heading (`audit:actions.*`), related-event count and an expandable technical list; readable before/after diff (`ChangeDiff` component: humanized field names, `set to`/`was`/`X → Y` phrasing) instead of raw JSON by default; short reference (`AUD-XXXXXXXX`) with full UUID and correlation ID behind "Technical details".
|
||||
|
||||
## Attention Queue / clickable rows
|
||||
|
||||
- Full "stretched link" pattern applied to: Attention Queue, Today's movements, Vehicles table, Bookings table, Data Quality table. Entire row is one activation target (pointer cursor, hover state, keyboard-focusable, Enter/Space activates), secondary in-row links (e.g. the vehicle reference inside a booking row) remain independently clickable via `.cell-link { z-index: 2 }` layered above the row overlay.
|
||||
- Dedicated tests in `frontend/e2e/clickable-rows.spec.ts` (8 tests): click on empty row space, keyboard focus + Enter, mobile-viewport click, secondary-link independence, correct routing for each of the 5 surfaces, pointer-cursor/focus-ring check.
|
||||
|
||||
## Test results (all commands re-run against this exact final state)
|
||||
|
||||
### Backend (local dev stack, clean-checkout instance, and live Unraid deployment — all three, all green)
|
||||
|
||||
```
|
||||
docker compose exec api pytest -q → 131 passed
|
||||
docker compose exec api ruff check . → All checks passed!
|
||||
docker compose exec api mypy app → Success: no issues found in 48 source files
|
||||
```
|
||||
|
||||
### Frontend
|
||||
|
||||
```
|
||||
cd frontend && npm run build → tsc -b && vite build: success
|
||||
```
|
||||
|
||||
### Playwright (92 tests; run against local dev stack, the isolated clean-checkout stack, and the live Unraid deployment — 92/92 passed in all three runs)
|
||||
|
||||
```
|
||||
npx playwright test --project=chromium
|
||||
```
|
||||
|
||||
Suites: `demo-accessibility`, `demo-entry`, `demo-guide` (including the 3 new adaptive-breakpoint tests, chip close-control test, Escape test, scroll/focus/highlight test), `demo-legibility`, `demo`, `guided-demo-full`, `i18n-coverage`, `interactive-elements`, `responsive-i18n` (7 breakpoints × 3 languages = 21 tests), `ui-redesign`, `clickable-rows` (new, 8 tests).
|
||||
|
||||
## Clean-checkout drill (evidence)
|
||||
|
||||
Performed in an isolated environment (separate Compose project `mobilityops-clean`, separate host ports 8129/1229, no shared volumes or n8n) so the user's existing long-running dev/n8n environment was never touched:
|
||||
|
||||
1. `git clone` of the local repository at commit `845db14` (feature branch, pre-merge) into a scratch directory.
|
||||
2. `cp .env.example .env` (project name and ports overridden for isolation only).
|
||||
3. `docker compose up --build -d db api web` — migrations ran automatically on API startup.
|
||||
4. `docker compose exec api python -m app.cli seed --reset` — deterministic seed loaded (users:2, customers:180, vehicles:50, bookings:246, inspections:75, maintenance:40, data_quality_issues:26, workflow_runs:20).
|
||||
5. `docker compose exec api pytest -q` → 131 passed. `ruff check .` → clean. `mypy app` → clean.
|
||||
6. `npm ci && npm run build` → clean build.
|
||||
7. `npx playwright test --project=chromium` (pointed at the isolated stack via `MOBILITYOPS_PUBLIC_URL`) → 92 passed.
|
||||
8. Live browser verification in English and French (Dutch already covered as the automated-suite default): guided-demo dashboard, knowledge-assistant grounded answers in both languages with correct same-language citations.
|
||||
9. `POST /api/v1/demo/reset` → `scenario_integrity: {"all_ready": true, "not_ready": []}`.
|
||||
10. Isolated stack torn down (`docker compose down -v`) — original dev environment (containers, n8n owner account/workflows) confirmed untouched and healthy throughout.
|
||||
|
||||
No PASS was claimed from pre-existing containers at any point — every gate above ran against a stack built from empty volumes.
|
||||
|
||||
## Server deployment evidence
|
||||
|
||||
- Deployed via the established safe method: `git archive` from the exact commit → `scp` to `.deploy/source-<sha>.tar.gz` on Unraid → extract → update `.deploy/source-revision` → `docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml up --build -d api web` (db never rebuilt; server `.env` and named volumes — Postgres, n8n — preserved throughout).
|
||||
- Deployed twice this task: once for the feature branch (`845db14`) for pre-merge live validation, once for the merged `master` (`18a765d`) for the final release.
|
||||
- Post-deploy, both times: migrations confirmed at head (`e7b08389f47f`), reseed run, `pytest`/`ruff`/`mypy` re-run in the container (all green), full 92-test Playwright suite re-run against the live URL (all green), console/network inspected via live browser (no errors, all `/api/*` calls 200), demo reset performed, `scenario_integrity.all_ready: true` confirmed both times.
|
||||
- Real shared n8n instance (`http://192.168.10.150:5678`) integration confirmed live: the seeded failed-demo automation event correctly shows "Retry available"/"Opnieuw proberen mogelijk" (not the raw `degraded` string) on the Integration pulse card.
|
||||
|
||||
## Responsive / accessibility
|
||||
|
||||
- No-horizontal-overflow verified across the full 7-breakpoint matrix (1440×1000, 1280×800, 1024×768, 768×1024, 430×932, 390×844, 360×800) in all 3 languages (`responsive-i18n.spec.ts`, 21 tests) plus the original 4-breakpoint English suite (`ui-redesign.spec.ts`).
|
||||
- Real bug found and fixed during this pass: the new topbar language switcher pushed the 421–440px range into horizontal overflow (the existing "compact topbar" breakpoint stopped at 420px). Fixed by widening that breakpoint to 440px; re-verified clean at exactly 430px in all 3 languages.
|
||||
- Focus-visible outlines, `prefers-reduced-motion` handling (demo-guide highlight pulse, bottom-sheet height transitions), and keyboard reachability verified via `demo-accessibility.spec.ts` and the new adaptive-guide/clickable-row tests.
|
||||
|
||||
## Screenshots
|
||||
|
||||
`artifacts/fleet-ops-release/screenshots/`:
|
||||
- `01-login-nl.jpg` — login screen, Dutch default, language selector visible
|
||||
- `02-dashboard-nl-desktop.jpg` — dashboard, Dutch, Attention Queue + Integration status
|
||||
- `03-data-quality-choice-cards.jpg` — Data Quality Workbench choice-card redesign (duplicate-customer merge)
|
||||
- `04-integrations-nl.jpg` — Integrations page, grouped/filterable automation ledger
|
||||
- `05-audit-trail-nl.jpg` — Audit trail, correlation-grouped human action labels
|
||||
- `06-dashboard-en-desktop.jpg` — dashboard, English
|
||||
- `07-dashboard-fr-desktop.jpg` — dashboard, French
|
||||
- `08-about-fr.jpg` — About page, French, confirming full rebrand + translated content
|
||||
- `09-mobile-guide-bottom-sheet.png` — mobile bottom sheet, half state (390×844)
|
||||
- `10-mobile-guide-full.png` — mobile bottom sheet, full state (390×844)
|
||||
|
||||
## Known limitations
|
||||
|
||||
- Data-quality evidence "summary" strings (the free-text detail line under each Attention Queue/Data Quality row, e.g. "exact email; exact phone; similar name") remain English-only — these are generated deep in the deterministic rule engine as diagnostic strings, not yet converted to message codes. The rule-type label, status, and all surrounding UI are fully localized; only this one diagnostic fragment is not. Documented as a follow-up, not blocking.
|
||||
- RAGcore and ITWorx MCP Hub remain honestly labelled as not live-connected (unchanged from prior milestones) — the demo knowledge base is the multilingual, fully-verified stand-in.
|
||||
- Vehicle/customer internal reference prefixes (`MO-`, `CUS-`) were left unchanged; they are generic internal codes, not user-visible "MobilityOps" branding, and changing them was out of scope for this task.
|
||||
- Automated live-browser evidence for the guided demo was captured in Dutch (via the automated Playwright suite, which defaults to the app's own nl-BE default) and manually spot-checked live in English and French (knowledge assistant, dashboard, About page); a full manual click-through of all 8 guided-demo steps was not repeated live in all 3 languages beyond the automated `guided-demo-full.spec.ts` (Dutch) and the targeted EN/FR checks documented above, given the exhaustive automated coverage already exercising the same code paths per language via `responsive-i18n.spec.ts` and `i18n-coverage.spec.ts`.
|
||||
|
||||
## Rollback procedure
|
||||
|
||||
- `.deploy/source-revision` on Unraid records the exact deployed commit (`18a765d62345ea9a6660d04fb868f218cf4d0b6e`).
|
||||
- Prior tarballs remain in `.deploy/` on the server, including `.deploy/source-845db14.tar.gz` (feature branch, pre-merge) and `.deploy/source-4a268c7.tar.gz` (previous release, pre-polish).
|
||||
- To roll back: extract the desired `source-<short-sha>.tar.gz`, update `.deploy/source-revision` to match, and re-run `docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml up --build -d api web`. Database migrations on this branch are additive only; no destructive migration was introduced.
|
||||
|
After Width: | Height: | Size: 30 KiB |
|
After Width: | Height: | Size: 43 KiB |
|
After Width: | Height: | Size: 39 KiB |
|
After Width: | Height: | Size: 30 KiB |
|
After Width: | Height: | Size: 29 KiB |
|
After Width: | Height: | Size: 42 KiB |
|
After Width: | Height: | Size: 44 KiB |
|
After Width: | Height: | Size: 54 KiB |
|
After Width: | Height: | Size: 40 KiB |
|
After Width: | Height: | Size: 40 KiB |
@@ -0,0 +1,207 @@
|
||||
# Live n8n + RAGcore integration — final evidence
|
||||
|
||||
No credential values, tokens, or secrets appear anywhere in this document. Where a
|
||||
credential or trace ID is referenced, only its name or an opaque reference identifier is
|
||||
given, never its value.
|
||||
|
||||
## Commit
|
||||
|
||||
Built on branch `feat/live-n8n-ragcore-integration`, HEAD at commit
|
||||
`aaa16305354d34f9c1f4d57253d33d9062c38faa` ("docs: record WF2 retry fix and WF4's
|
||||
n8n-session-expiry blocker"). Run `git log --oneline feat/live-n8n-ragcore-integration`
|
||||
for the full history of this effort.
|
||||
|
||||
## Scope
|
||||
|
||||
The brief required treating n8n (`https://n8n.itworx.tech`) as a full third integration
|
||||
layer alongside RAGcore and MCP Hub, with Fleet Ops keeping exclusive ownership of
|
||||
business rules, authorization, transactions, audit, and idempotency. Four canonical n8n
|
||||
workflows were required. The repository (`n8n/workflows/*.json` + `MANIFEST.md` +
|
||||
`n8n/workflows/check_drift.py`) is the source of truth for cleaned workflow definitions;
|
||||
the Fleet Ops integration status page (`/automation`) shows real per-workflow operational
|
||||
evidence, not a config boolean.
|
||||
|
||||
## Result summary
|
||||
|
||||
| # | Workflow | Status | Live evidence this round |
|
||||
|---|---|---|---|
|
||||
| 1 | Fleet Ops — Vehicle Return Orchestration | **Live, hardened** | Timeout+bounded-retry gap found and fixed |
|
||||
| 2 | Fleet Ops — Scheduled Data Quality Scan | **Live, hardened** | Same gap found and fixed |
|
||||
| 3 | Fleet Ops — RAGcore Procedure Sync | **Blocked** | Not built — RAGcore rejects credential issuance (see below) |
|
||||
| 4 | Fleet Ops — Workflow Error Handler | **Live, validated** | Mock + genuine induced-failure test; own hardening incomplete (see below) |
|
||||
|
||||
Full per-workflow detail (purpose, trigger, event contract, required credentials, live
|
||||
workflow ID, checksum) is in `n8n/workflows/MANIFEST.md`, which is the authoritative,
|
||||
continuously-updated source — this document is a point-in-time summary of that state
|
||||
plus the reasoning behind what's not done.
|
||||
|
||||
## Workflow 1 — Vehicle Return Orchestration
|
||||
|
||||
Live workflow ID `mobilityops-return-processing`. Validated in an earlier round of this
|
||||
effort: webhook trigger requires Header Auth (`Fleet Ops Webhook Trigger Token`),
|
||||
validates `event_type == vehicle.returned.v1`, derives a follow-up category, calls Fleet
|
||||
Ops's `/return-callback` endpoint with an `Idempotency-Key` header via a named
|
||||
`Fleet Ops Service Token` credential (not a literal secret), and responds with a
|
||||
controlled JSON result. Idempotent on both sides (`event_id` flows through as the
|
||||
dedup key; the backend independently checks for a prior audit event before recording
|
||||
again).
|
||||
|
||||
**This round's finding**: the `Record follow-up` HTTP node had no explicit timeout and
|
||||
"Retry On Fail" disabled — a real gap against the requirement that external dependencies
|
||||
have timeouts and bounded retries. Fixed live: Retry On Fail (3 tries, 1000ms wait) + a
|
||||
15000ms timeout, published. Safe to retry because the callback is idempotent. Repo
|
||||
definition and manifest checksum synced (commit `0562893`).
|
||||
|
||||
Attached to workflow 4 as its Error Workflow.
|
||||
|
||||
## Workflow 2 — Scheduled Data Quality Scan
|
||||
|
||||
Live workflow ID `mobilityops-scheduled-quality-scan`. Validated earlier: hourly
|
||||
Schedule Trigger + a Manual Trigger for on-demand testing, both feeding a single HTTP
|
||||
call to Fleet Ops's `/scheduled-scan` endpoint (Header Auth via the same `Fleet Ops
|
||||
Service Token` credential, 15000ms timeout already configured), which runs the
|
||||
domain-level `run_scan()` function — documented and tested as idempotent by
|
||||
construction (only ever creates an issue for a condition that doesn't already have one
|
||||
open), so overlapping or retried triggers do no duplicate domain work.
|
||||
|
||||
**This round's finding**: the same Retry On Fail gap as workflow 1 (timeout was already
|
||||
set, retries were not). Fixed live the same way (3 tries, 1000ms wait), published. Repo
|
||||
definition and manifest checksum synced (commit `167bf49`).
|
||||
|
||||
Attached to workflow 4 as its Error Workflow.
|
||||
|
||||
## Workflow 3 — RAGcore Procedure Sync — blocked
|
||||
|
||||
**Not built.** This workflow needs an application credential (scope `sources:sync`) for
|
||||
the `fleet-ops` application in RAGcore. Two independent issuance attempts, in two
|
||||
separate rounds of this effort, both failed with an opaque server-side rejection:
|
||||
|
||||
1. **Raw API**: `POST /v1/applications/{id}/credentials` → `400`, "authoritative
|
||||
service-account state rejected issuance".
|
||||
2. **RAGcore admin UI**, this round, after the project owner explicitly authorized
|
||||
Claude to self-issue the credential: the "Issue credential" form for the `fleet-ops`
|
||||
application, submitted as the Platform Admin role (the highest role visible in the
|
||||
RAGcore admin), with name `n8n-ragcore-procedure-sync` and scope `sources:sync` only.
|
||||
Result: "Something went wrong. The credential could not be issued with those
|
||||
values.", trace reference `1955c6a8968c4941a22a1faef39e17a7`.
|
||||
|
||||
The `fleet-ops` application itself shows as ordinary/`Active` in the RAGcore admin, with
|
||||
no visible lock flag, and RAGcore's own OpenAPI spec documents no validation rule that
|
||||
would explain either rejection (no `422`, no field-level errors). Two independent paths
|
||||
— a raw API call and the admin UI as the top admin role — hitting the same failure
|
||||
signature is conclusive evidence this is a RAGcore-side policy or bug, not a Fleet Ops
|
||||
request-shape or permission problem. It is not fixable from the Fleet Ops side or
|
||||
through further UI automation. Resolving it requires whoever operates the RAGcore
|
||||
instance to look up the trace ID above (and the earlier raw-API rejection) in RAGcore's
|
||||
own logs.
|
||||
|
||||
The real RAGcore contract this workflow will be built against — once a working
|
||||
credential exists — was independently inspected via RAGcore's live OpenAPI spec and is
|
||||
recorded in `docs/live-ai-integration/n8n-current-state.md` and
|
||||
`contracts/ragcore-contract-assumptions.md`: control-plane endpoints require an
|
||||
`Idempotency-Key` header; ingestion is `POST /v1/uploads`; retrieval is `POST
|
||||
/v1/search` / `/v1/context` / `/v1/answers` (the latter requiring `requested_space_ids`,
|
||||
an array of knowledge-space UUIDs); health is `/health/live` and `/health/ready` (not
|
||||
`/health`); the scope enum is `search, context, answer, documents:read, citations:read,
|
||||
feedback:write, sources:sync`.
|
||||
|
||||
**`RAGcoreKnowledgeProvider` adapter** (`backend/app/services/knowledge/ragcore.py`)
|
||||
still targets the earlier speculative contract (`/health`, `POST /api/v1/ask`, Bearer
|
||||
token) rather than the real one above. This was deliberately **not** rewritten this
|
||||
round: rewriting it blind, without a credential to validate against, risks introducing
|
||||
a silent behavioral bug in exactly the code path responsible for the project's "AI must
|
||||
never invent an answer when RAGcore is unavailable or returns insufficient evidence"
|
||||
guarantee — for example a wrong `evidence_state` mapping that looks fine in code review
|
||||
but misclassifies "unavailable" as "insufficient" (or vice versa) against the real
|
||||
response shape. The adapter's current behavior is honest and safe (it degrades cleanly
|
||||
to `unavailable` on any request or parsing failure, and `ragcore_api_token` is unset by
|
||||
default so the app correctly runs on the local demo knowledge provider today). The
|
||||
rewrite stays queued behind the same credential blocker as workflow 3.
|
||||
|
||||
## Workflow 4 — Workflow Error Handler
|
||||
|
||||
Live workflow ID `Xppn2rAEqUuyiCJF`. Built and live-validated in an earlier round:
|
||||
Error Trigger → a Code node that derives a bounded, secret-free failure report (error
|
||||
category classified from the message text, truncated summary, no stack trace, no
|
||||
headers or tokens) → an HTTP call to Fleet Ops's `/workflow-error` endpoint (Header Auth
|
||||
via the same `Fleet Ops Service Token` credential), which registers the failure as an
|
||||
audit event idempotently keyed on `execution_id`.
|
||||
|
||||
Set as the Error Workflow on both workflow 1 and workflow 2. Confirmed workflow 4 has no
|
||||
Error Workflow of its own (prevents a recursive loop).
|
||||
|
||||
**Live validation performed**: a pinned mock Error Trigger payload produced a real `200
|
||||
{"status":"registered", ...}` from the live Fleet Ops server; re-running the identical
|
||||
payload produced `"status":"already_registered"`, confirming idempotency. A genuine
|
||||
induced failure (temporarily pointing workflow 2's HTTP node at a nonexistent path, then
|
||||
reverting) confirmed workflow 2 itself fails correctly against a broken endpoint and
|
||||
recovers cleanly once reverted.
|
||||
|
||||
**Known limitation**: n8n's Error Workflow trigger does not fire for manual editor
|
||||
"Execute workflow" test runs — checked via workflow 4's own Executions list after the
|
||||
induced workflow-2 failure, and confirmed no new execution appeared. n8n only invokes a
|
||||
workflow's assigned Error Workflow for unattended/production trigger executions, not
|
||||
manual test runs from the editor. The mock-data path exercises the same nodes, logic,
|
||||
and real Fleet Ops endpoint, but a fully automatic (schedule- or webhook-triggered)
|
||||
failure cascading into workflow 4 was not observed live in either round.
|
||||
|
||||
**Open follow-up (minor, non-blocking)**: continuing this round's acceptance pass to
|
||||
workflow 4 found the same timeout/retry gap as workflows 1 and 2 on its own outbound
|
||||
HTTP call. A fix was started (15000ms timeout added, Retry On Fail toggled on) but n8n's
|
||||
autosave began failing with "Unauthorized" mid-edit; a fresh browser tab confirmed the
|
||||
n8n session had expired (redirected to `/signin`). Nothing was saved — workflow 4's live
|
||||
definition is unchanged from before this round, so there is no partial or broken state.
|
||||
This is lower-stakes than workflows 1/2 (workflow 4 is the error notifier itself, not a
|
||||
primary business flow, and a failed error-report is already visible in n8n's own
|
||||
execution history via `On Error: Stop Workflow`) but should be finished once the n8n
|
||||
browser session is re-authenticated.
|
||||
|
||||
## Repository source of truth
|
||||
|
||||
`n8n/workflows/` holds cleaned, credential-value-free JSON definitions for all built
|
||||
workflows, `n8n/workflows/MANIFEST.md` documents purpose/trigger/contract/credentials/
|
||||
live-ID/checksum for all four canonical workflows (including workflow 3's blocked
|
||||
status), and `n8n/workflows/check_drift.py` is a read-only script that compares the
|
||||
repo definitions against the live instance via n8n's Public API and reports drift —
|
||||
safe to run in CI as a non-blocking check. No literal export/download mechanism was
|
||||
found working in this n8n version, so each definition was reconstructed from direct,
|
||||
verified UI inspection rather than a native export; this limitation is noted in the
|
||||
manifest itself.
|
||||
|
||||
## Integration status page
|
||||
|
||||
`/automation` (Operations Manager only) surfaces real per-workflow evidence derived
|
||||
purely from Fleet Ops's own audit/outbox tables — no new dependency on n8n's API was
|
||||
added to the backend. Each of the four canonical workflows shows a status (not built /
|
||||
no evidence yet / operational) and a last-evidence timestamp; the scheduled-scan
|
||||
evidence specifically filters to `actor_type == "service"` so a manually-triggered scan
|
||||
in the UI doesn't count as n8n evidence. An error-handler summary line reports total
|
||||
registered automation failures and the most recent one.
|
||||
|
||||
Verified live in the browser (Dutch locale) both locally and on the deployed
|
||||
production server (`http://192.168.10.150:1236/automation`): correctly showed "3 van 4
|
||||
canonieke n8n-workflows hebben actuele evidentie van werking" with real timestamps for
|
||||
the return/scan/error-handler workflows, "Nog Niet Gebouwd" for the RAGcore sync, and
|
||||
the real error-handler registration from this effort's live testing.
|
||||
|
||||
## Deployments performed (all explicitly user-approved)
|
||||
|
||||
1. Backend `/workflow-error` endpoint (commit `bbdb4a9`) — deployed and verified
|
||||
(`/health` OK, new endpoint returns `422` not `404` on an empty POST body).
|
||||
2. Integration status page, backend + frontend (commit `4049c0c`) — deployed and
|
||||
verified (`/health` OK, page renders real evidence in the browser).
|
||||
|
||||
The three n8n-side node edits this round (WF1 timeout/retry, WF2 timeout/retry, WF4's
|
||||
incomplete attempt) are live edits to the n8n instance itself and do not require a
|
||||
Fleet Ops redeploy.
|
||||
|
||||
## What's left
|
||||
|
||||
1. **RAGcore credential issuance** — blocked on RAGcore's own server-side rejection
|
||||
(trace `1955c6a8968c4941a22a1faef39e17a7` and the earlier raw-API `400`). Needs
|
||||
RAGcore's operator to investigate. Unblocks workflow 3 and the
|
||||
`RAGcoreKnowledgeProvider` real-contract rewrite.
|
||||
2. **Workflow 4's own timeout/bounded-retry hardening** — needs the n8n browser session
|
||||
re-authenticated to finish; a small, well-understood, non-blocking edit.
|
||||
3. **Fleet Ops logo/favicon** — explicitly deferred by the project owner as a separate,
|
||||
unrelated follow-up task, not part of this integration effort.
|
||||
@@ -0,0 +1,25 @@
|
||||
"""outbox last_error_code
|
||||
|
||||
Revision ID: 799d8800e241
|
||||
Revises: e7b08389f47f
|
||||
Create Date: 2026-08-03 10:00:00.000000
|
||||
|
||||
"""
|
||||
from typing import Sequence, Union
|
||||
|
||||
from alembic import op
|
||||
import sqlalchemy as sa
|
||||
|
||||
# revision identifiers, used by Alembic.
|
||||
revision: str = '799d8800e241'
|
||||
down_revision: Union[str, None] = 'e7b08389f47f'
|
||||
branch_labels: Union[str, Sequence[str], None] = None
|
||||
depends_on: Union[str, Sequence[str], None] = None
|
||||
|
||||
|
||||
def upgrade() -> None:
|
||||
op.add_column('outbox_events', sa.Column('last_error_code', sa.String(length=60), nullable=True))
|
||||
|
||||
|
||||
def downgrade() -> None:
|
||||
op.drop_column('outbox_events', 'last_error_code')
|
||||
@@ -2,10 +2,11 @@ from __future__ import annotations
|
||||
|
||||
import uuid
|
||||
from collections.abc import Sequence
|
||||
from datetime import datetime
|
||||
from typing import Any
|
||||
|
||||
from fastapi import APIRouter, Depends, Query
|
||||
from sqlalchemy import select
|
||||
from sqlalchemy import func, select
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from app.api.deps import get_db, require_operations_manager
|
||||
@@ -14,7 +15,7 @@ from app.models.booking import Booking
|
||||
from app.models.customer import Customer
|
||||
from app.models.data_quality import DataQualityIssue
|
||||
from app.models.vehicle import Vehicle
|
||||
from app.schemas import AuditEventOut, CurrentUser
|
||||
from app.schemas import AuditEventOut, AuditEventPageOut, CurrentUser
|
||||
|
||||
router = APIRouter(prefix="/api/v1/audit", tags=["audit"])
|
||||
|
||||
@@ -51,26 +52,51 @@ def _resolve_entity_refs(db: Session, events: Sequence[AuditEvent]) -> dict[uuid
|
||||
return refs
|
||||
|
||||
|
||||
@router.get("", response_model=list[AuditEventOut])
|
||||
@router.get("", response_model=list[AuditEventOut] | AuditEventPageOut)
|
||||
def list_audit_events(
|
||||
actor_label: str | None = Query(default=None),
|
||||
action: str | None = Query(default=None),
|
||||
entity_type: str | None = Query(default=None),
|
||||
entity_ref: str | None = Query(default=None, min_length=1, max_length=100),
|
||||
correlation_id: str | None = Query(default=None),
|
||||
limit: int = Query(default=100, le=500),
|
||||
occurred_from: datetime | None = Query(default=None),
|
||||
occurred_to: datetime | None = Query(default=None),
|
||||
page: int | None = Query(default=None, ge=1),
|
||||
page_size: int = Query(default=25, ge=1, le=25),
|
||||
db: Session = Depends(get_db),
|
||||
_user: CurrentUser = Depends(require_operations_manager),
|
||||
) -> list[AuditEventOut]:
|
||||
stmt = select(AuditEvent).order_by(AuditEvent.occurred_at.desc()).limit(limit)
|
||||
) -> list[AuditEventOut] | AuditEventPageOut:
|
||||
stmt = select(AuditEvent).order_by(AuditEvent.occurred_at.desc())
|
||||
if actor_label:
|
||||
stmt = stmt.where(AuditEvent.actor_label == actor_label)
|
||||
if action:
|
||||
stmt = stmt.where(AuditEvent.action == action)
|
||||
if entity_type:
|
||||
stmt = stmt.where(AuditEvent.entity_type == entity_type)
|
||||
if entity_ref:
|
||||
matched_ids: set[uuid.UUID] = set()
|
||||
for model in _ENTITY_MODELS.values():
|
||||
matched_ids.update(
|
||||
db.scalars(select(model.id).where(model.public_ref.ilike(f"%{entity_ref.strip()}%"))).all()
|
||||
)
|
||||
if not matched_ids:
|
||||
if page is None:
|
||||
return []
|
||||
return AuditEventPageOut(
|
||||
items=[], page=1, page_size=page_size, total=0, total_pages=1
|
||||
)
|
||||
stmt = stmt.where(AuditEvent.entity_id.in_(matched_ids))
|
||||
if correlation_id:
|
||||
stmt = stmt.where(AuditEvent.correlation_id == correlation_id)
|
||||
events = db.scalars(stmt).all()
|
||||
if occurred_from:
|
||||
stmt = stmt.where(AuditEvent.occurred_at >= occurred_from)
|
||||
if occurred_to:
|
||||
stmt = stmt.where(AuditEvent.occurred_at <= occurred_to)
|
||||
total = db.scalar(select(func.count()).select_from(stmt.subquery())) or 0
|
||||
page_number = page or 1
|
||||
events = db.scalars(
|
||||
stmt if page is None else stmt.offset((page_number - 1) * page_size).limit(page_size)
|
||||
).all()
|
||||
entity_refs = _resolve_entity_refs(db, events)
|
||||
|
||||
out = []
|
||||
@@ -94,4 +120,13 @@ def list_audit_events(
|
||||
metadata=e.metadata_json,
|
||||
)
|
||||
)
|
||||
if page is None:
|
||||
return out
|
||||
total_pages = max(1, (total + page_size - 1) // page_size)
|
||||
return AuditEventPageOut(
|
||||
items=out,
|
||||
page=min(page_number, total_pages),
|
||||
page_size=page_size,
|
||||
total=total,
|
||||
total_pages=total_pages,
|
||||
)
|
||||
|
||||
@@ -89,6 +89,8 @@ def preview_return(
|
||||
resulting_odometer_km=evaluation.resulting_odometer_km,
|
||||
resulting_vehicle_status=evaluation.resulting_vehicle_status,
|
||||
status_reason=evaluation.status_reason,
|
||||
status_reason_code=evaluation.status_reason_code,
|
||||
status_reason_params=evaluation.status_reason_params,
|
||||
would_create_quality_issue=evaluation.would_create_quality_issue,
|
||||
attention_reasons=evaluation.attention_reasons,
|
||||
next_booking_risk=(
|
||||
|
||||
@@ -19,6 +19,7 @@ from app.schemas import (
|
||||
AutomationRunOut,
|
||||
CurrentUser,
|
||||
DashboardOut,
|
||||
EvidenceSignalOut,
|
||||
TodayItem,
|
||||
)
|
||||
from app.services.operations import compute_metrics
|
||||
@@ -61,19 +62,34 @@ def get_dashboard(
|
||||
entity = customers_by_id.get(issue.entity_id)
|
||||
link_type = "customer"
|
||||
link_ref = entity.public_ref if entity else ""
|
||||
# The backend never emits prose for the attention queue -- only stable signal
|
||||
# codes + raw data params, exactly like the issue detail page's evidence list
|
||||
# (see app/services/data_quality.py::_open_issue). The frontend is the one place
|
||||
# that turns these into the operator's selected language; `evidence_json["summary"]`
|
||||
# is a technical fallback only, never rendered here.
|
||||
signals = [
|
||||
EvidenceSignalOut(code=s["code"], params=s.get("params", {}))
|
||||
for s in issue.evidence_json.get("signals", [])
|
||||
]
|
||||
attention_items.append(
|
||||
AttentionItem(
|
||||
kind="quality_issue",
|
||||
severity=issue.severity,
|
||||
rule_type=issue.rule_type,
|
||||
detail=issue.evidence_json.get("summary", ""),
|
||||
evidence_signals=signals,
|
||||
link_type=link_type,
|
||||
link_ref=link_ref,
|
||||
issue_ref=issue.public_ref,
|
||||
)
|
||||
)
|
||||
attention_items.sort(key=lambda item: _SEVERITY_ORDER.get(item.severity, 3))
|
||||
attention_items = attention_items[:8]
|
||||
# Curate a credible severity mix instead of letting `high` dominate every slot:
|
||||
# each item's real severity is unchanged, only the display selection is capped per
|
||||
# tier (a handful of "now", then "today", then "later") so a heavy day of high-severity
|
||||
# issues doesn't crowd out medium/low ones the operator should still see.
|
||||
high_items = [i for i in attention_items if i.severity == "high"]
|
||||
medium_items = [i for i in attention_items if i.severity == "medium"]
|
||||
low_items = [i for i in attention_items if i.severity == "low"]
|
||||
attention_items = (high_items[:3] + medium_items[:3] + low_items[:2])[:8]
|
||||
|
||||
today = _today()
|
||||
bookings = db.scalars(select(Booking)).all()
|
||||
@@ -108,6 +124,7 @@ def get_dashboard(
|
||||
status=r.delivery_status,
|
||||
attempts=r.attempts,
|
||||
last_error=r.last_error,
|
||||
last_error_code=r.last_error_code,
|
||||
occurred_at=r.occurred_at,
|
||||
)
|
||||
for r in recent
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from fastapi import APIRouter, Depends, HTTPException, Query
|
||||
from sqlalchemy import select
|
||||
from sqlalchemy import func, select
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from app.api.deps import get_db, require_operations_manager
|
||||
@@ -11,21 +11,26 @@ from app.models.data_quality import DataQualityIssue
|
||||
from app.models.inspection import Inspection
|
||||
from app.models.vehicle import Vehicle
|
||||
from app.schemas import (
|
||||
ApplyRecommendedStatusRequest,
|
||||
ApplyRecommendedStatusResult,
|
||||
CurrentUser,
|
||||
DataQualityIssueDetailOut,
|
||||
DataQualityIssueOut,
|
||||
DataQualityIssuePageOut,
|
||||
MergeCustomersRequest,
|
||||
MergeCustomersResult,
|
||||
ProvideFieldsRequest,
|
||||
ResolveOdometerRegressionRequest,
|
||||
ResolveOverlapRequest,
|
||||
ScanResultOut,
|
||||
StatusRecommendationOut,
|
||||
VehicleStatusFactsOut,
|
||||
)
|
||||
from app.services.data_quality import (
|
||||
apply_recommended_status,
|
||||
defer_issue,
|
||||
merge_customers,
|
||||
preview_vehicle_status_recommendation,
|
||||
provide_missing_fields,
|
||||
reject_issue,
|
||||
resolve_booking_overlap,
|
||||
@@ -50,14 +55,16 @@ def _to_out(issue: DataQualityIssue) -> DataQualityIssueOut:
|
||||
)
|
||||
|
||||
|
||||
@router.get("/issues", response_model=list[DataQualityIssueOut])
|
||||
@router.get("/issues", response_model=list[DataQualityIssueOut] | DataQualityIssuePageOut)
|
||||
def list_issues(
|
||||
status: str | None = Query(default=None),
|
||||
rule_type: str | None = Query(default=None),
|
||||
severity: str | None = Query(default=None),
|
||||
page: int | None = Query(default=None, ge=1),
|
||||
page_size: int = Query(default=25, ge=1, le=25),
|
||||
db: Session = Depends(get_db),
|
||||
_user: CurrentUser = Depends(require_operations_manager),
|
||||
) -> list[DataQualityIssueOut]:
|
||||
) -> list[DataQualityIssueOut] | DataQualityIssuePageOut:
|
||||
stmt = select(DataQualityIssue).order_by(DataQualityIssue.detected_at.desc())
|
||||
if status:
|
||||
stmt = stmt.where(DataQualityIssue.status == status)
|
||||
@@ -65,8 +72,22 @@ def list_issues(
|
||||
stmt = stmt.where(DataQualityIssue.rule_type == rule_type)
|
||||
if severity:
|
||||
stmt = stmt.where(DataQualityIssue.severity == severity)
|
||||
issues = db.scalars(stmt).all()
|
||||
return [_to_out(i) for i in issues]
|
||||
total = db.scalar(select(func.count()).select_from(stmt.subquery())) or 0
|
||||
page_number = page or 1
|
||||
issues = db.scalars(
|
||||
stmt if page is None else stmt.offset((page_number - 1) * page_size).limit(page_size)
|
||||
).all()
|
||||
items = [_to_out(i) for i in issues]
|
||||
if page is None:
|
||||
return items
|
||||
total_pages = max(1, (total + page_size - 1) // page_size)
|
||||
return DataQualityIssuePageOut(
|
||||
items=items,
|
||||
page=min(page_number, total_pages),
|
||||
page_size=page_size,
|
||||
total=total,
|
||||
total_pages=total_pages,
|
||||
)
|
||||
|
||||
|
||||
# Every public reference in this system carries its entity type in its own prefix
|
||||
@@ -111,6 +132,7 @@ def _snapshot(entity_type: str, ref: str, db: Session) -> dict | None:
|
||||
return {
|
||||
"entity_type": "vehicle",
|
||||
"public_ref": vehicle.public_ref,
|
||||
"registration_number": vehicle.registration_number,
|
||||
"make": vehicle.make,
|
||||
"model": vehicle.model,
|
||||
"location": vehicle.location,
|
||||
@@ -241,17 +263,43 @@ def resolve_overlap(
|
||||
return _to_out(issue)
|
||||
|
||||
|
||||
@router.post(
|
||||
"/issues/{public_ref}/status-recommendation", response_model=StatusRecommendationOut
|
||||
)
|
||||
def status_recommendation(
|
||||
public_ref: str,
|
||||
db: Session = Depends(get_db),
|
||||
user: CurrentUser = Depends(require_operations_manager),
|
||||
) -> StatusRecommendationOut:
|
||||
"""Non-mutating preview: computes the recommendation without changing anything,
|
||||
resolving no issue and writing no audit event. Safe to call repeatedly."""
|
||||
_issue, _vehicle, recommendation, token = preview_vehicle_status_recommendation(db, public_ref)
|
||||
return StatusRecommendationOut(
|
||||
current_status=recommendation.current_status,
|
||||
recommended_status=recommendation.recommended_status,
|
||||
recommendation_code=recommendation.recommendation_code,
|
||||
safe_to_apply=recommendation.safe_to_apply,
|
||||
manual_review_required=recommendation.manual_review_required,
|
||||
facts=VehicleStatusFactsOut(**recommendation.facts.as_dict()),
|
||||
blocking_reasons=recommendation.blocking_reasons,
|
||||
recommendation_token=token,
|
||||
)
|
||||
|
||||
|
||||
@router.post(
|
||||
"/issues/{public_ref}/apply-recommended-status", response_model=ApplyRecommendedStatusResult
|
||||
)
|
||||
def apply_status(
|
||||
public_ref: str,
|
||||
body: ApplyRecommendedStatusRequest,
|
||||
db: Session = Depends(get_db),
|
||||
user: CurrentUser = Depends(require_operations_manager),
|
||||
) -> ApplyRecommendedStatusResult:
|
||||
issue, applied_status, reason = apply_recommended_status(db, public_ref, user)
|
||||
issue, applied_status, reason_code = apply_recommended_status(
|
||||
db, public_ref, user, body.recommendation_token
|
||||
)
|
||||
return ApplyRecommendedStatusResult(
|
||||
issue=_to_out(issue), applied_status=applied_status, reason=reason
|
||||
issue=_to_out(issue), applied_status=applied_status, reason_code=reason_code
|
||||
)
|
||||
|
||||
|
||||
|
||||
@@ -4,16 +4,10 @@ from fastapi import APIRouter, Depends
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from app.api.deps import get_db, require_operations_manager
|
||||
from app.core.config import get_settings
|
||||
from app.schemas import (
|
||||
CurrentUser,
|
||||
IntegrationStatusOut,
|
||||
McpHubIntegrationStatus,
|
||||
)
|
||||
from app.services.integration_status import derive_n8n_status
|
||||
from app.schemas import CurrentUser, IntegrationStatusOut
|
||||
from app.services.integration_status import derive_mcp_hub_status, derive_n8n_status
|
||||
|
||||
router = APIRouter(prefix="/api/v1/integrations", tags=["integrations"])
|
||||
settings = get_settings()
|
||||
|
||||
|
||||
@router.get("/status", response_model=IntegrationStatusOut)
|
||||
@@ -23,8 +17,5 @@ def integration_status(
|
||||
) -> IntegrationStatusOut:
|
||||
return IntegrationStatusOut(
|
||||
n8n=derive_n8n_status(db),
|
||||
mcp_hub=McpHubIntegrationStatus(
|
||||
registration_enabled=settings.mcp_hub_registration_enabled,
|
||||
state="configured" if settings.mcp_hub_registration_enabled else "not_configured",
|
||||
),
|
||||
mcp_hub=derive_mcp_hub_status(db),
|
||||
)
|
||||
|
||||
@@ -2,6 +2,7 @@ from __future__ import annotations
|
||||
|
||||
import uuid
|
||||
from datetime import UTC, datetime
|
||||
from pathlib import Path
|
||||
from typing import Any
|
||||
|
||||
from fastapi import APIRouter, Depends, Header
|
||||
@@ -13,9 +14,18 @@ from app.core.config import get_settings
|
||||
from app.core.errors import AppError
|
||||
from app.models.audit import AuditEvent
|
||||
from app.models.outbox import OutboxEvent
|
||||
from app.schemas import ScanResultOut
|
||||
from app.schemas import (
|
||||
ProcedureDocumentOut,
|
||||
ProcedureListOut,
|
||||
ProcedureSyncResultIn,
|
||||
ProcedureSyncResultResult,
|
||||
ScanResultOut,
|
||||
WorkflowErrorReportIn,
|
||||
WorkflowErrorReportResult,
|
||||
)
|
||||
from app.services.audit import record_audit_event
|
||||
from app.services.data_quality import run_scan
|
||||
from app.services.knowledge.procedures import iter_procedure_documents
|
||||
|
||||
router = APIRouter(prefix="/api/v1/integrations/n8n", tags=["integrations"])
|
||||
settings = get_settings()
|
||||
@@ -89,3 +99,124 @@ def scheduled_scan(
|
||||
|
||||
result = run_scan(db, actor_label="n8n scheduled scan", actor_type="service")
|
||||
return ScanResultOut(created=result.created)
|
||||
|
||||
|
||||
@router.post("/workflow-error", response_model=WorkflowErrorReportResult)
|
||||
def workflow_error(
|
||||
body: WorkflowErrorReportIn,
|
||||
service_token: str = Header(..., alias="X-Service-Token"),
|
||||
db: Session = Depends(get_db),
|
||||
) -> WorkflowErrorReportResult:
|
||||
"""Receives a bounded, secret-free failure report from the central n8n "Fleet Ops --
|
||||
Workflow Error Handler" workflow, which is attached as the Error Workflow on every
|
||||
other Fleet Ops n8n workflow. Idempotent on execution_id: n8n may redeliver the same
|
||||
error report (e.g. after a timed-out response), so this must not double-record."""
|
||||
if service_token != settings.n8n_callback_token:
|
||||
raise AppError("UNAUTHORIZED_SERVICE", "Invalid service token.", status_code=401)
|
||||
|
||||
already_recorded = (
|
||||
db.scalar(
|
||||
select(AuditEvent.id).where(
|
||||
AuditEvent.action == "n8n_workflow_failure_registered",
|
||||
AuditEvent.metadata_json["execution_id"].astext == body.execution_id,
|
||||
)
|
||||
)
|
||||
is not None
|
||||
)
|
||||
if not already_recorded:
|
||||
correlation_id: uuid.UUID | None = None
|
||||
if body.correlation_id:
|
||||
try:
|
||||
correlation_id = uuid.UUID(body.correlation_id)
|
||||
except ValueError:
|
||||
correlation_id = None
|
||||
record_audit_event(
|
||||
db,
|
||||
actor_type="service",
|
||||
actor_label="n8n error handler",
|
||||
action="n8n_workflow_failure_registered",
|
||||
entity_type="automation",
|
||||
correlation_id=correlation_id,
|
||||
after={
|
||||
"workflow_id": body.workflow_id,
|
||||
"workflow_name": body.workflow_name,
|
||||
"error_category": body.error_category,
|
||||
"error_summary": body.error_summary,
|
||||
"trigger_context": body.trigger_context,
|
||||
"attempt": body.attempt,
|
||||
"retry_action": body.retry_action,
|
||||
"failed_at": body.failed_at.isoformat(),
|
||||
},
|
||||
metadata={"execution_id": body.execution_id},
|
||||
)
|
||||
db.commit()
|
||||
|
||||
return WorkflowErrorReportResult(
|
||||
status="already_registered" if already_recorded else "registered",
|
||||
execution_id=body.execution_id,
|
||||
occurred_at=datetime.now(UTC),
|
||||
)
|
||||
|
||||
|
||||
@router.get("/procedures", response_model=ProcedureListOut)
|
||||
def list_procedures(service_token: str = Header(..., alias="X-Service-Token")) -> ProcedureListOut:
|
||||
"""Read-only source list for the RAGcore Procedure Sync workflow: every procedure
|
||||
Markdown file Fleet Ops ships, across every supported language, with a stable
|
||||
per-document id (source_id) and a content hash so the caller can detect changes
|
||||
without re-fetching content it already has."""
|
||||
if service_token != settings.n8n_callback_token:
|
||||
raise AppError("UNAUTHORIZED_SERVICE", "Invalid service token.", status_code=401)
|
||||
|
||||
documents = [
|
||||
ProcedureDocumentOut(
|
||||
id=doc.source_id,
|
||||
language=doc.language,
|
||||
document_id=doc.document_id,
|
||||
title=doc.title,
|
||||
version=doc.version,
|
||||
content=doc.content,
|
||||
content_hash=doc.content_hash,
|
||||
)
|
||||
for doc in iter_procedure_documents(Path(settings.knowledge_dir))
|
||||
]
|
||||
return ProcedureListOut(documents=documents)
|
||||
|
||||
|
||||
@router.post("/procedures-sync-result", response_model=ProcedureSyncResultResult)
|
||||
def procedures_sync_result(
|
||||
body: ProcedureSyncResultIn,
|
||||
service_token: str = Header(..., alias="X-Service-Token"),
|
||||
db: Session = Depends(get_db),
|
||||
) -> ProcedureSyncResultResult:
|
||||
"""Receives a summary (counts only, no document content) from the n8n "Fleet Ops --
|
||||
RAGcore Procedure Sync" workflow once it finishes uploading procedures to RAGcore.
|
||||
Idempotent on execution_id, matching the workflow-error and return-callback pattern."""
|
||||
if service_token != settings.n8n_callback_token:
|
||||
raise AppError("UNAUTHORIZED_SERVICE", "Invalid service token.", status_code=401)
|
||||
|
||||
already_recorded = (
|
||||
db.scalar(
|
||||
select(AuditEvent.id).where(
|
||||
AuditEvent.action == "n8n_procedures_synced",
|
||||
AuditEvent.metadata_json["execution_id"].astext == body.execution_id,
|
||||
)
|
||||
)
|
||||
is not None
|
||||
)
|
||||
if not already_recorded:
|
||||
record_audit_event(
|
||||
db,
|
||||
actor_type="service",
|
||||
actor_label="n8n procedure sync",
|
||||
action="n8n_procedures_synced",
|
||||
entity_type="automation",
|
||||
after={"synced": body.synced, "failed": body.failed},
|
||||
metadata={"execution_id": body.execution_id},
|
||||
)
|
||||
db.commit()
|
||||
|
||||
return ProcedureSyncResultResult(
|
||||
status="already_registered" if already_recorded else "registered",
|
||||
execution_id=body.execution_id,
|
||||
occurred_at=datetime.now(UTC),
|
||||
)
|
||||
|
||||
@@ -3,7 +3,7 @@ from __future__ import annotations
|
||||
import uuid
|
||||
from datetime import date
|
||||
|
||||
from fastapi import APIRouter, Depends, Query
|
||||
from fastapi import APIRouter, Depends, Header, Query
|
||||
from sqlalchemy import select
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
@@ -27,14 +27,30 @@ router = APIRouter(prefix="/api/v1/integrations/mcp", tags=["mcp"])
|
||||
settings = get_settings()
|
||||
|
||||
|
||||
def _audit_service_request(db: Session, *, client_id: str, tool: str, status_label: str) -> None:
|
||||
def get_correlation_id(
|
||||
x_correlation_id: str | None = Header(default=None, alias="X-Correlation-Id"),
|
||||
) -> str:
|
||||
"""Preserve the Hub's own inbound correlation ID through MCP client -> Hub -> Fleet
|
||||
Ops -> RAGcore -> Fleet Ops Audit; only mint a fresh one when none was supplied or
|
||||
it isn't a valid UUID (per the task's own correlation-propagation contract)."""
|
||||
if x_correlation_id:
|
||||
try:
|
||||
return str(uuid.UUID(x_correlation_id))
|
||||
except ValueError:
|
||||
pass
|
||||
return str(uuid.uuid4())
|
||||
|
||||
|
||||
def _audit_service_request(
|
||||
db: Session, *, client_id: str, tool: str, status_label: str, correlation_id: str
|
||||
) -> None:
|
||||
record_audit_event(
|
||||
db,
|
||||
actor_type="service",
|
||||
actor_label=client_id,
|
||||
action="mcp_tool_request",
|
||||
entity_type="mcp_tool",
|
||||
correlation_id=uuid.uuid4(),
|
||||
correlation_id=uuid.UUID(correlation_id),
|
||||
metadata={"tool": tool, "status": status_label},
|
||||
)
|
||||
db.commit()
|
||||
@@ -44,10 +60,15 @@ def _audit_service_request(db: Session, *, client_id: str, tool: str, status_lab
|
||||
def operations_summary(
|
||||
db: Session = Depends(get_db),
|
||||
client_id: str = Depends(require_mcp_service_token),
|
||||
correlation_id: str = Depends(get_correlation_id),
|
||||
) -> OperationsSummaryOut:
|
||||
metrics = compute_metrics(db)
|
||||
_audit_service_request(
|
||||
db, client_id=client_id, tool="mobilityops_get_operations_summary", status_label="ok"
|
||||
db,
|
||||
client_id=client_id,
|
||||
tool="fleet_ops_get_operations_summary",
|
||||
status_label="ok",
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
return OperationsSummaryOut(tenant=settings.ragcore_tenant, metrics=metrics)
|
||||
|
||||
@@ -59,12 +80,17 @@ def attention_vehicles(
|
||||
limit: int = Query(default=20, ge=1, le=50),
|
||||
db: Session = Depends(get_db),
|
||||
client_id: str = Depends(require_mcp_service_token),
|
||||
correlation_id: str = Depends(get_correlation_id),
|
||||
) -> list[AttentionVehicleOut]:
|
||||
results = list_attention_vehicles(
|
||||
db, minimum_severity=minimum_severity, on_or_before=date_filter, limit=limit
|
||||
)
|
||||
_audit_service_request(
|
||||
db, client_id=client_id, tool="mobilityops_list_attention_vehicles", status_label="ok"
|
||||
db,
|
||||
client_id=client_id,
|
||||
tool="fleet_ops_list_attention_vehicles",
|
||||
status_label="ok",
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
return [AttentionVehicleOut(**r) for r in results]
|
||||
|
||||
@@ -74,14 +100,16 @@ def vehicle_details(
|
||||
vehicle_ref: str,
|
||||
db: Session = Depends(get_db),
|
||||
client_id: str = Depends(require_mcp_service_token),
|
||||
correlation_id: str = Depends(get_correlation_id),
|
||||
) -> McpVehicleDetailOut:
|
||||
vehicle = db.scalar(select(Vehicle).where(Vehicle.public_ref == vehicle_ref))
|
||||
if vehicle is None:
|
||||
_audit_service_request(
|
||||
db,
|
||||
client_id=client_id,
|
||||
tool="mobilityops_get_vehicle_details",
|
||||
tool="fleet_ops_get_vehicle_details",
|
||||
status_label="not_found",
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
raise AppError("VEHICLE_NOT_FOUND", "Vehicle not found.", status_code=404)
|
||||
|
||||
@@ -99,7 +127,11 @@ def vehicle_details(
|
||||
)
|
||||
|
||||
_audit_service_request(
|
||||
db, client_id=client_id, tool="mobilityops_get_vehicle_details", status_label="ok"
|
||||
db,
|
||||
client_id=client_id,
|
||||
tool="fleet_ops_get_vehicle_details",
|
||||
status_label="ok",
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
return McpVehicleDetailOut(
|
||||
public_ref=vehicle.public_ref,
|
||||
@@ -120,15 +152,16 @@ def search_knowledge(
|
||||
body: McpKnowledgeSearchRequest,
|
||||
db: Session = Depends(get_db),
|
||||
client_id: str = Depends(require_mcp_service_token),
|
||||
correlation_id: str = Depends(get_correlation_id),
|
||||
) -> GroundedAnswer:
|
||||
provider = get_knowledge_provider()
|
||||
correlation_id = str(uuid.uuid4())
|
||||
answer = provider.ask(body.question, correlation_id)
|
||||
answer = provider.ask(body.question, correlation_id, language=body.locale)
|
||||
answer.sources = answer.sources[: body.max_sources]
|
||||
_audit_service_request(
|
||||
db,
|
||||
client_id=client_id,
|
||||
tool="mobilityops_search_knowledge",
|
||||
tool="fleet_ops_search_knowledge",
|
||||
status_label=answer.evidence_state,
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
return answer
|
||||
|
||||
@@ -12,53 +12,81 @@ from app.schemas import CurrentUser, SearchResponse, SearchResultItem
|
||||
|
||||
router = APIRouter(prefix="/api/v1/search", tags=["search"])
|
||||
|
||||
# Static application sections. Manager-only sections are filtered by role, mirroring the
|
||||
# same nav visibility rule Layout.tsx applies -- search must never surface a destination
|
||||
# the current role can't actually reach.
|
||||
# Static application sections. `id` is a stable code matching navigation.json's
|
||||
# `items.*` keys -- the frontend localizes both the section label and its one-line
|
||||
# detail from `id`, so no English prose is sent over the wire (search.sections.<id> in
|
||||
# every locale; see docs/fleet-ops-correction/i18n-inventory.md). Manager-only sections
|
||||
# are filtered by role, mirroring the same nav visibility rule Layout.tsx applies --
|
||||
# search must never surface a destination the current role can't actually reach.
|
||||
_SECTIONS: list[dict] = [
|
||||
{
|
||||
"label": "Overview",
|
||||
"detail": "Operations dashboard",
|
||||
"id": "overview",
|
||||
"link": "/dashboard",
|
||||
"terms": ["overview", "dashboard", "readiness"],
|
||||
# Search terms deliberately span all three supported UI languages (not just
|
||||
# English) so a query never depends on the operator's selected locale.
|
||||
"terms": ["overview", "dashboard", "readiness", "overzicht", "aperçu", "tableau de bord"],
|
||||
},
|
||||
{
|
||||
"label": "Fleet",
|
||||
"detail": "Vehicle registry",
|
||||
"id": "fleet",
|
||||
"link": "/vehicles",
|
||||
"terms": ["fleet", "vehicle", "vehicles"],
|
||||
"terms": ["fleet", "vehicle", "vehicles", "wagenpark", "voertuig", "flotte", "véhicule"],
|
||||
},
|
||||
{
|
||||
"label": "Bookings",
|
||||
"detail": "Rental bookings",
|
||||
"id": "bookings",
|
||||
"link": "/bookings",
|
||||
"terms": ["booking", "bookings", "rental"],
|
||||
"terms": [
|
||||
"booking",
|
||||
"bookings",
|
||||
"rental",
|
||||
"boeking",
|
||||
"boekingen",
|
||||
"verhuur",
|
||||
"réservation",
|
||||
"réservations",
|
||||
"location",
|
||||
],
|
||||
},
|
||||
{
|
||||
"label": "Data quality",
|
||||
"detail": "Quality workbench",
|
||||
"id": "quality",
|
||||
"link": "/data-quality",
|
||||
"terms": ["quality", "data quality", "issues"],
|
||||
"terms": [
|
||||
"quality",
|
||||
"data quality",
|
||||
"issues",
|
||||
"kwaliteit",
|
||||
"datakwaliteit",
|
||||
"problemen",
|
||||
"qualité",
|
||||
"problèmes",
|
||||
],
|
||||
"role": "operations_manager",
|
||||
},
|
||||
{
|
||||
"label": "Knowledge",
|
||||
"detail": "Procedure assistant",
|
||||
"id": "knowledge",
|
||||
"link": "/knowledge",
|
||||
"terms": ["knowledge", "procedures"],
|
||||
"terms": ["knowledge", "procedures", "kennis", "procedures", "connaissances", "procédures"],
|
||||
},
|
||||
{
|
||||
"label": "Integrations",
|
||||
"detail": "Automation and integration status",
|
||||
"id": "integrations",
|
||||
"link": "/automation",
|
||||
"terms": ["automation", "integrations", "systems", "n8n"],
|
||||
"terms": [
|
||||
"automation",
|
||||
"integrations",
|
||||
"systems",
|
||||
"n8n",
|
||||
"automatisering",
|
||||
"integraties",
|
||||
"systemen",
|
||||
"automatisation",
|
||||
"intégrations",
|
||||
"systèmes",
|
||||
],
|
||||
"role": "operations_manager",
|
||||
},
|
||||
{
|
||||
"label": "Audit trail",
|
||||
"detail": "Audit history",
|
||||
"id": "audit",
|
||||
"link": "/audit",
|
||||
"terms": ["audit", "history"],
|
||||
"terms": ["audit", "history", "geschiedenis", "historique"],
|
||||
"role": "operations_manager",
|
||||
},
|
||||
]
|
||||
@@ -83,8 +111,8 @@ def search(
|
||||
results.append(
|
||||
SearchResultItem(
|
||||
type="section",
|
||||
label=section["label"],
|
||||
detail=section["detail"],
|
||||
label=section["id"],
|
||||
detail_code=section["id"],
|
||||
link=section["link"],
|
||||
)
|
||||
)
|
||||
@@ -108,7 +136,8 @@ def search(
|
||||
SearchResultItem(
|
||||
type="vehicle",
|
||||
label=v.public_ref,
|
||||
detail=f"{v.make} {v.model} · {v.location}",
|
||||
detail_code="vehicleSummary",
|
||||
detail_params={"make": v.make, "model": v.model, "location": v.location},
|
||||
link=f"/vehicles/{v.public_ref}",
|
||||
)
|
||||
)
|
||||
@@ -120,7 +149,7 @@ def search(
|
||||
SearchResultItem(
|
||||
type="booking",
|
||||
label=b.public_ref,
|
||||
detail=b.status,
|
||||
detail_code=b.status,
|
||||
link=f"/bookings/{b.public_ref}",
|
||||
)
|
||||
)
|
||||
@@ -138,7 +167,7 @@ def search(
|
||||
SearchResultItem(
|
||||
type="data_quality_issue",
|
||||
label=i.public_ref,
|
||||
detail=i.rule_type.replace("_", " "),
|
||||
detail_code=i.rule_type,
|
||||
link=f"/data-quality/{i.public_ref}",
|
||||
)
|
||||
)
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from fastapi import APIRouter, Depends, HTTPException, Query
|
||||
from sqlalchemy import select
|
||||
from sqlalchemy import func, or_, select
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from app.api.deps import get_current_user, get_db
|
||||
@@ -19,6 +19,7 @@ from app.schemas import (
|
||||
MaintenanceOut,
|
||||
VehicleDetailOut,
|
||||
VehicleOut,
|
||||
VehiclePageOut,
|
||||
)
|
||||
|
||||
router = APIRouter(prefix="/api/v1/vehicles", tags=["vehicles"])
|
||||
@@ -34,19 +35,41 @@ def _attention_vehicle_ids(db: Session) -> set:
|
||||
return set(rows)
|
||||
|
||||
|
||||
@router.get("", response_model=list[VehicleOut])
|
||||
@router.get("", response_model=list[VehicleOut] | VehiclePageOut)
|
||||
def list_vehicles(
|
||||
status: str | None = Query(default=None),
|
||||
attention_only: bool = Query(default=False),
|
||||
query: str | None = Query(default=None, min_length=1, max_length=100),
|
||||
page: int | None = Query(default=None, ge=1),
|
||||
page_size: int = Query(default=25, ge=1, le=25),
|
||||
db: Session = Depends(get_db),
|
||||
_user: CurrentUser = Depends(get_current_user),
|
||||
) -> list[VehicleOut]:
|
||||
) -> list[VehicleOut] | VehiclePageOut:
|
||||
stmt = select(Vehicle).order_by(Vehicle.public_ref)
|
||||
if status:
|
||||
stmt = stmt.where(Vehicle.operational_status == status)
|
||||
vehicles = db.scalars(stmt).all()
|
||||
if query:
|
||||
term = f"%{query.strip()}%"
|
||||
stmt = stmt.where(
|
||||
or_(
|
||||
Vehicle.public_ref.ilike(term),
|
||||
Vehicle.make.ilike(term),
|
||||
Vehicle.model.ilike(term),
|
||||
Vehicle.location.ilike(term),
|
||||
Vehicle.registration_number.ilike(term),
|
||||
)
|
||||
)
|
||||
attention_ids = _attention_vehicle_ids(db)
|
||||
out = [
|
||||
if attention_only:
|
||||
stmt = stmt.where(
|
||||
or_(Vehicle.id.in_(attention_ids), Vehicle.operational_status == "blocked")
|
||||
)
|
||||
total = db.scalar(select(func.count()).select_from(stmt.subquery())) or 0
|
||||
page_number = page or 1
|
||||
vehicles = db.scalars(
|
||||
stmt if page is None else stmt.offset((page_number - 1) * page_size).limit(page_size)
|
||||
).all()
|
||||
items = [
|
||||
VehicleOut(
|
||||
public_ref=v.public_ref,
|
||||
make=v.make,
|
||||
@@ -62,9 +85,16 @@ def list_vehicles(
|
||||
)
|
||||
for v in vehicles
|
||||
]
|
||||
if attention_only:
|
||||
out = [v for v in out if v.attention]
|
||||
return out
|
||||
if page is None:
|
||||
return items
|
||||
total_pages = max(1, (total + page_size - 1) // page_size)
|
||||
return VehiclePageOut(
|
||||
items=items,
|
||||
page=min(page_number, total_pages),
|
||||
page_size=page_size,
|
||||
total=total,
|
||||
total_pages=total_pages,
|
||||
)
|
||||
|
||||
|
||||
@router.get("/{public_ref}", response_model=VehicleDetailOut)
|
||||
|
||||
@@ -8,7 +8,7 @@ from sqlalchemy.orm import Session
|
||||
|
||||
from app.api.deps import get_db, require_operations_manager
|
||||
from app.core.errors import AppError
|
||||
from app.models.outbox import OutboxEvent
|
||||
from app.models.outbox import OutboxEvent, is_demo_scenario_failure
|
||||
from app.schemas import AutomationRunOut, CurrentUser
|
||||
from app.services.audit import record_audit_event
|
||||
|
||||
@@ -23,6 +23,8 @@ def _to_out(event: OutboxEvent) -> AutomationRunOut:
|
||||
status=event.delivery_status,
|
||||
attempts=event.attempts,
|
||||
last_error=event.last_error,
|
||||
last_error_code=event.last_error_code,
|
||||
is_demo_scenario=is_demo_scenario_failure(event),
|
||||
occurred_at=event.occurred_at,
|
||||
)
|
||||
|
||||
@@ -62,15 +64,27 @@ def retry_workflow(
|
||||
status_code=409,
|
||||
)
|
||||
|
||||
# Captured before the status flips, so the audit records what was actually retried.
|
||||
was_demo_scenario = is_demo_scenario_failure(event)
|
||||
|
||||
event.delivery_status = "pending"
|
||||
event.next_attempt_at = None
|
||||
# The retry itself is real either way: the event goes back on the outbox and the
|
||||
# dispatcher delivers it to the configured n8n webhook like any other. The only
|
||||
# difference recorded here is *what* was retried -- a staged demo failure or a real
|
||||
# one -- so the audit trail never implies a production incident was resolved when a
|
||||
# prop was.
|
||||
record_audit_event(
|
||||
db,
|
||||
actor_type="user",
|
||||
actor_label=user.display_name,
|
||||
action="workflow_retry",
|
||||
entity_type="outbox_event",
|
||||
metadata={"event_id": event_id, "previous_attempts": event.attempts},
|
||||
metadata={
|
||||
"event_id": event_id,
|
||||
"previous_attempts": event.attempts,
|
||||
"demo_scenario": was_demo_scenario,
|
||||
},
|
||||
)
|
||||
db.commit()
|
||||
return _to_out(event)
|
||||
|
||||
@@ -2,6 +2,12 @@ from functools import lru_cache
|
||||
|
||||
from pydantic_settings import BaseSettings, SettingsConfigDict
|
||||
|
||||
# The visible product name is fixed and never translated or configured per-deployment --
|
||||
# see docs/fleet-ops-correction/current-gap-audit.md section 1. Internal identifiers
|
||||
# (package name, Compose project, database name, repository) intentionally remain
|
||||
# "mobilityops"; this constant is only for user-facing surfaces (e.g. the OpenAPI title).
|
||||
PRODUCT_NAME = "Fleet Ops"
|
||||
|
||||
|
||||
class Settings(BaseSettings):
|
||||
model_config = SettingsConfigDict(env_file=".env", extra="ignore")
|
||||
@@ -15,8 +21,10 @@ class Settings(BaseSettings):
|
||||
ragcore_workspace: str = "mobilityops"
|
||||
ragcore_collection: str = "internal-procedures"
|
||||
ragcore_api_token: str = ""
|
||||
ragcore_space_id: str = ""
|
||||
ragcore_http_timeout_seconds: float = 5.0
|
||||
n8n_webhook_url: str = "http://n8n:5678/webhook/mobilityops-return"
|
||||
n8n_webhook_trigger_token: str = "replace-me-n8n-webhook-trigger-token"
|
||||
n8n_callback_token: str = "replace-me-n8n-callback-token"
|
||||
n8n_dispatch_enabled: bool = True
|
||||
n8n_dispatch_interval_seconds: float = 3.0
|
||||
@@ -31,6 +39,11 @@ class Settings(BaseSettings):
|
||||
knowledge_dir: str = "/app/knowledge/procedures"
|
||||
mcp_hub_service_token: str = "replace-me-mcp-hub-token"
|
||||
mcp_hub_registration_enabled: bool = False
|
||||
# MCP Hub's own registration is catalog-driven on the Hub side (the Hub reconciles
|
||||
# its catalog into the gateway; Fleet Ops never pushes a registration call), so
|
||||
# these are only used for an honest reachability health check, not self-registration.
|
||||
mcp_hub_base_url: str = ""
|
||||
mcp_provider_id: str = "fleet-ops"
|
||||
cors_allow_origins: str = "http://localhost:1228"
|
||||
demo_organization_name: str = "Northstar Mobility"
|
||||
demo_timezone: str = "Europe/Brussels"
|
||||
|
||||
@@ -19,7 +19,7 @@ from app.api.routers import (
|
||||
vehicles,
|
||||
workflows,
|
||||
)
|
||||
from app.core.config import get_settings
|
||||
from app.core.config import PRODUCT_NAME, get_settings
|
||||
from app.core.errors import AppError, error_body
|
||||
from app.services.dispatcher import start_background_dispatcher, stop_background_dispatcher
|
||||
|
||||
@@ -33,7 +33,7 @@ async def lifespan(_app: FastAPI):
|
||||
stop_background_dispatcher()
|
||||
|
||||
|
||||
app = FastAPI(title="MobilityOps API", version="0.1.0", lifespan=lifespan)
|
||||
app = FastAPI(title=f"{PRODUCT_NAME} API", version="0.1.0", lifespan=lifespan)
|
||||
|
||||
app.add_middleware(
|
||||
CORSMiddleware,
|
||||
|
||||
@@ -10,6 +10,25 @@ from app.models.mixins import TimestampMixin
|
||||
|
||||
DELIVERY_STATUSES = ("pending", "delivering", "succeeded", "failed")
|
||||
|
||||
# The one delivery failure the demo seed deliberately plants (BK-H-0020, see
|
||||
# seed/workflow_runs.csv). It exists to show retry and audit working, so it must never
|
||||
# be read as an integration-health problem: it is a scripted prop, not evidence that
|
||||
# n8n is unhealthy. A dedicated error code -- rather than the generic
|
||||
# "connectionError" a real timeout produces -- is what lets every reader tell the two
|
||||
# apart without guessing from the message text.
|
||||
#
|
||||
# It is deliberately a `last_error_code` value and not a new column: the code is
|
||||
# already persisted, already surfaced to the UI, and already localizable, so no schema
|
||||
# change or migration is needed. A genuine later failure of this same event overwrites
|
||||
# the code with the real one, which is exactly right -- from that moment it *is* a real
|
||||
# failure.
|
||||
DEMO_SCENARIO_ERROR_CODE = "demoScenarioTimeout"
|
||||
|
||||
|
||||
def is_demo_scenario_failure(event: "OutboxEvent") -> bool:
|
||||
"""True for the prepared demo failure, false for every real one."""
|
||||
return event.delivery_status == "failed" and event.last_error_code == DEMO_SCENARIO_ERROR_CODE
|
||||
|
||||
|
||||
class OutboxEvent(TimestampMixin, Base):
|
||||
__tablename__ = "outbox_events"
|
||||
@@ -26,4 +45,9 @@ class OutboxEvent(TimestampMixin, Base):
|
||||
attempts: Mapped[int] = mapped_column(Integer, nullable=False, default=0)
|
||||
next_attempt_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True))
|
||||
last_error: Mapped[str | None] = mapped_column(Text)
|
||||
# Stable, localizable classification of last_error -- the frontend renders a
|
||||
# localized summary from this code as the primary text and shows last_error itself
|
||||
# only under "Technical details" (section 10 of docs/fleet-ops-correction/
|
||||
# current-gap-audit.md). Kept alongside the raw message for backward compatibility.
|
||||
last_error_code: Mapped[str | None] = mapped_column(String(60))
|
||||
external_run_id: Mapped[str | None] = mapped_column(String(120))
|
||||
|
||||
@@ -32,6 +32,14 @@ class VehicleOut(BaseModel):
|
||||
attention: bool = False
|
||||
|
||||
|
||||
class VehiclePageOut(BaseModel):
|
||||
items: list[VehicleOut]
|
||||
page: int
|
||||
page_size: int
|
||||
total: int
|
||||
total_pages: int
|
||||
|
||||
|
||||
class BookingSummaryOut(BaseModel):
|
||||
public_ref: str
|
||||
customer_ref: str
|
||||
@@ -83,6 +91,8 @@ class ReturnPreviewResult(BaseModel):
|
||||
resulting_odometer_km: int
|
||||
resulting_vehicle_status: str
|
||||
status_reason: str
|
||||
status_reason_code: str
|
||||
status_reason_params: dict[str, str | int] = {}
|
||||
would_create_quality_issue: bool
|
||||
attention_reasons: list[str]
|
||||
next_booking_risk: NextBookingRisk | None
|
||||
@@ -120,6 +130,14 @@ class DataQualityIssueOut(BaseModel):
|
||||
resolved_at: datetime | None = None
|
||||
|
||||
|
||||
class DataQualityIssuePageOut(BaseModel):
|
||||
items: list[DataQualityIssueOut]
|
||||
page: int
|
||||
page_size: int
|
||||
total: int
|
||||
total_pages: int
|
||||
|
||||
|
||||
class DataQualityIssueDetailOut(DataQualityIssueOut):
|
||||
entity_snapshot: dict[str, Any] | None = None
|
||||
related_snapshots: list[dict[str, Any]] = Field(default_factory=list)
|
||||
@@ -141,6 +159,53 @@ class ScanResultOut(BaseModel):
|
||||
created: dict[str, int]
|
||||
|
||||
|
||||
class WorkflowErrorReportIn(BaseModel):
|
||||
workflow_id: str = Field(max_length=120)
|
||||
workflow_name: str = Field(max_length=200)
|
||||
execution_id: str = Field(max_length=120)
|
||||
failed_at: datetime
|
||||
error_category: Literal[
|
||||
"timeout", "authError", "connectionError", "httpError", "validationError", "unknown"
|
||||
]
|
||||
error_summary: str = Field(max_length=500)
|
||||
trigger_context: str | None = Field(default=None, max_length=200)
|
||||
correlation_id: str | None = None
|
||||
attempt: int = Field(default=1, ge=1, le=1000)
|
||||
retry_action: str | None = Field(default=None, max_length=200)
|
||||
|
||||
|
||||
class WorkflowErrorReportResult(BaseModel):
|
||||
status: Literal["registered", "already_registered"]
|
||||
execution_id: str
|
||||
occurred_at: datetime
|
||||
|
||||
|
||||
class ProcedureDocumentOut(BaseModel):
|
||||
id: str
|
||||
language: str
|
||||
document_id: str
|
||||
title: str
|
||||
version: str
|
||||
content: str
|
||||
content_hash: str
|
||||
|
||||
|
||||
class ProcedureListOut(BaseModel):
|
||||
documents: list[ProcedureDocumentOut]
|
||||
|
||||
|
||||
class ProcedureSyncResultIn(BaseModel):
|
||||
execution_id: str = Field(max_length=120)
|
||||
synced: int = Field(ge=0)
|
||||
failed: int = Field(default=0, ge=0)
|
||||
|
||||
|
||||
class ProcedureSyncResultResult(BaseModel):
|
||||
status: Literal["registered", "already_registered"]
|
||||
execution_id: str
|
||||
occurred_at: datetime
|
||||
|
||||
|
||||
class ProvideFieldsRequest(BaseModel):
|
||||
fields: dict[str, str]
|
||||
|
||||
@@ -157,16 +222,41 @@ class ResolveOverlapRequest(BaseModel):
|
||||
note: str | None = Field(default=None, max_length=500)
|
||||
|
||||
|
||||
class VehicleStatusFactsOut(BaseModel):
|
||||
active_booking_refs: list[str]
|
||||
overlapping_booking_pairs: list[list[str]]
|
||||
service_threshold_reached: bool
|
||||
odometer_km: int
|
||||
next_service_km: int
|
||||
open_booking_overlap_issue_ref: str | None = None
|
||||
|
||||
|
||||
class StatusRecommendationOut(BaseModel):
|
||||
current_status: str
|
||||
recommended_status: str | None
|
||||
recommendation_code: str
|
||||
safe_to_apply: bool
|
||||
manual_review_required: bool
|
||||
facts: VehicleStatusFactsOut
|
||||
blocking_reasons: list[str]
|
||||
recommendation_token: str
|
||||
|
||||
|
||||
class ApplyRecommendedStatusRequest(BaseModel):
|
||||
recommendation_token: str
|
||||
|
||||
|
||||
class ApplyRecommendedStatusResult(BaseModel):
|
||||
issue: DataQualityIssueOut
|
||||
applied_status: str
|
||||
reason: str
|
||||
reason_code: str
|
||||
|
||||
|
||||
class SearchResultItem(BaseModel):
|
||||
type: Literal["vehicle", "booking", "data_quality_issue", "section"]
|
||||
label: str
|
||||
detail: str
|
||||
detail_code: str
|
||||
detail_params: dict[str, str] = {}
|
||||
link: str
|
||||
|
||||
|
||||
@@ -175,21 +265,52 @@ class SearchResponse(BaseModel):
|
||||
results: list[SearchResultItem]
|
||||
|
||||
|
||||
class N8nWorkflowEvidence(BaseModel):
|
||||
name: str
|
||||
built: bool
|
||||
last_seen_at: datetime | None
|
||||
|
||||
|
||||
class N8nErrorHandlerStatus(BaseModel):
|
||||
total_failures_registered: int
|
||||
latest_failure_at: datetime | None
|
||||
latest_failure_workflow: str | None
|
||||
|
||||
|
||||
class N8nIntegrationStatus(BaseModel):
|
||||
configured: bool
|
||||
dispatch_enabled: bool
|
||||
state: Literal["disabled", "unavailable", "degraded", "operational", "no_evidence"]
|
||||
pending: int
|
||||
delivering: int
|
||||
#: Every failed delivery, staged and real together -- the number a viewer sees in
|
||||
#: the run list.
|
||||
failed: int
|
||||
#: Failures that were not planted by the demo seed. This is the only failure count
|
||||
#: that may influence `state`.
|
||||
unexpected_failed: int = 0
|
||||
#: Prepared demo failures (see `app.models.outbox.DEMO_SCENARIO_ERROR_CODE`).
|
||||
#: Present so the UI can label them instead of implying the automation is broken.
|
||||
demo_scenario_failed: int = 0
|
||||
delivering: int
|
||||
succeeded: int
|
||||
latest_success_at: datetime | None
|
||||
#: Most recent *real* failure; a staged one never sets this.
|
||||
latest_failure_at: datetime | None
|
||||
latest_demo_scenario_at: datetime | None = None
|
||||
expected_workflow_count: int
|
||||
known_workflow_count: int
|
||||
workflows: list[N8nWorkflowEvidence]
|
||||
error_handler: N8nErrorHandlerStatus
|
||||
|
||||
|
||||
class McpHubIntegrationStatus(BaseModel):
|
||||
registration_enabled: bool
|
||||
state: Literal["not_configured", "configured"]
|
||||
state: Literal["not_configured", "no_evidence", "operational"]
|
||||
total_calls: int
|
||||
last_tool: str | None = None
|
||||
last_client: str | None = None
|
||||
last_called_at: datetime | None = None
|
||||
hub_reachable: bool | None = None
|
||||
|
||||
|
||||
class IntegrationStatusOut(BaseModel):
|
||||
@@ -245,11 +366,16 @@ class DashboardMetrics(BaseModel):
|
||||
pending_or_failed_workflows: int
|
||||
|
||||
|
||||
class EvidenceSignalOut(BaseModel):
|
||||
code: str
|
||||
params: dict[str, Any] = Field(default_factory=dict)
|
||||
|
||||
|
||||
class AttentionItem(BaseModel):
|
||||
kind: Literal["quality_issue", "vehicle"]
|
||||
severity: str
|
||||
rule_type: str
|
||||
detail: str
|
||||
evidence_signals: list[EvidenceSignalOut] = Field(default_factory=list)
|
||||
link_type: Literal["vehicle", "booking", "customer"]
|
||||
link_ref: str
|
||||
issue_ref: str | None = None
|
||||
@@ -269,6 +395,11 @@ class AutomationRunOut(BaseModel):
|
||||
status: str
|
||||
attempts: int
|
||||
last_error: str | None
|
||||
last_error_code: str | None
|
||||
#: True for the deliberately seeded demo failure. The UI uses this to label the run
|
||||
#: as a prepared scenario and to offer the demo retry, instead of presenting it as
|
||||
#: an unexplained production error.
|
||||
is_demo_scenario: bool = False
|
||||
occurred_at: datetime
|
||||
|
||||
|
||||
@@ -308,6 +439,7 @@ class McpVehicleDetailOut(BaseModel):
|
||||
class McpKnowledgeSearchRequest(BaseModel):
|
||||
question: str = Field(min_length=3, max_length=1000)
|
||||
max_sources: int = Field(default=4, ge=1, le=8)
|
||||
locale: Literal["nl-BE", "en-GB", "fr-BE"] = "en-GB"
|
||||
|
||||
|
||||
class AuditEventOut(BaseModel):
|
||||
@@ -324,3 +456,11 @@ class AuditEventOut(BaseModel):
|
||||
before: dict[str, Any] | None = None
|
||||
after: dict[str, Any] | None = None
|
||||
metadata: dict[str, Any] | None = None
|
||||
|
||||
|
||||
class AuditEventPageOut(BaseModel):
|
||||
items: list[AuditEventOut]
|
||||
page: int
|
||||
page_size: int
|
||||
total: int
|
||||
total_pages: int
|
||||
|
||||
@@ -4,6 +4,7 @@ import csv
|
||||
import uuid
|
||||
from dataclasses import dataclass
|
||||
from datetime import UTC, date, datetime, timedelta
|
||||
from difflib import SequenceMatcher
|
||||
from pathlib import Path
|
||||
|
||||
from sqlalchemy import delete, insert, update
|
||||
@@ -17,7 +18,7 @@ from app.models.data_quality import DataQualityIssue
|
||||
from app.models.idempotency import IdempotencyRecord
|
||||
from app.models.inspection import Inspection
|
||||
from app.models.maintenance import MaintenanceRecord
|
||||
from app.models.outbox import OutboxEvent
|
||||
from app.models.outbox import DEMO_SCENARIO_ERROR_CODE, OutboxEvent
|
||||
from app.models.user import User
|
||||
from app.models.vehicle import Vehicle
|
||||
from app.services.audit import record_audit_event
|
||||
@@ -108,11 +109,11 @@ def load_seed(db: Session) -> SeedResult:
|
||||
|
||||
customer_id_by_ref: dict[str, uuid.UUID] = {}
|
||||
customer_rows = []
|
||||
customer_row_by_ref: dict[str, dict] = {}
|
||||
for row in _read_csv("customers.csv"):
|
||||
cid = uuid.uuid4()
|
||||
customer_id_by_ref[row["public_ref"]] = cid
|
||||
customer_rows.append(
|
||||
{
|
||||
customer_row = {
|
||||
"id": cid,
|
||||
"public_ref": row["public_ref"],
|
||||
"first_name": row["first_name"],
|
||||
@@ -122,7 +123,8 @@ def load_seed(db: Session) -> SeedResult:
|
||||
"postal_code": row["postal_code"] or None,
|
||||
"city": row["city"] or None,
|
||||
}
|
||||
)
|
||||
customer_rows.append(customer_row)
|
||||
customer_row_by_ref[row["public_ref"]] = customer_row
|
||||
db.execute(insert(Customer), customer_rows)
|
||||
counts["customers"] = len(customer_rows)
|
||||
# Second pass for merged_into (self-referencing FK) since target must exist first.
|
||||
@@ -137,11 +139,11 @@ def load_seed(db: Session) -> SeedResult:
|
||||
|
||||
vehicle_id_by_ref: dict[str, uuid.UUID] = {}
|
||||
vehicle_rows = []
|
||||
vehicle_row_by_ref: dict[str, dict] = {}
|
||||
for row in _read_csv("vehicles.csv"):
|
||||
vid = uuid.uuid4()
|
||||
vehicle_id_by_ref[row["public_ref"]] = vid
|
||||
vehicle_rows.append(
|
||||
{
|
||||
vehicle_row = {
|
||||
"id": vid,
|
||||
"public_ref": row["public_ref"],
|
||||
"make": row["make"],
|
||||
@@ -155,17 +157,18 @@ def load_seed(db: Session) -> SeedResult:
|
||||
"active": _parse_bool(row["active"]),
|
||||
"version": 1,
|
||||
}
|
||||
)
|
||||
vehicle_rows.append(vehicle_row)
|
||||
vehicle_row_by_ref[row["public_ref"]] = vehicle_row
|
||||
db.execute(insert(Vehicle), vehicle_rows)
|
||||
counts["vehicles"] = len(vehicle_rows)
|
||||
|
||||
booking_id_by_ref: dict[str, uuid.UUID] = {}
|
||||
booking_rows = []
|
||||
booking_row_by_ref: dict[str, dict] = {}
|
||||
for row in _read_csv("bookings.csv"):
|
||||
bid = uuid.uuid4()
|
||||
booking_id_by_ref[row["public_ref"]] = bid
|
||||
booking_rows.append(
|
||||
{
|
||||
booking_row = {
|
||||
"id": bid,
|
||||
"public_ref": row["public_ref"],
|
||||
"customer_id": customer_id_by_ref[row["customer_ref"]],
|
||||
@@ -177,7 +180,8 @@ def load_seed(db: Session) -> SeedResult:
|
||||
"end_odometer_km": _parse_optional_int(row["end_odometer_km"]),
|
||||
"requirements_complete": _parse_bool(row["requirements_complete"]),
|
||||
}
|
||||
)
|
||||
booking_rows.append(booking_row)
|
||||
booking_row_by_ref[row["public_ref"]] = booking_row
|
||||
db.execute(insert(Booking), booking_rows)
|
||||
counts["bookings"] = len(booking_rows)
|
||||
|
||||
@@ -223,11 +227,118 @@ def load_seed(db: Session) -> SeedResult:
|
||||
return "customer", customer_id_by_ref[entity_ref]
|
||||
return "vehicle", vehicle_id_by_ref[entity_ref]
|
||||
|
||||
def _vehicle_conflict_facts(vehicle_ref: str, *, service_threshold_reached: bool) -> dict:
|
||||
# Mirrors app.services.vehicle_status.VehicleStatusFacts.as_dict() for the
|
||||
# handful of seed-only rows below -- none of them carry an active rental or a
|
||||
# real booking conflict (verified against the fixed seed dataset), only a
|
||||
# genuinely-crossed service threshold or none at all, so those two fields are
|
||||
# the only ones that vary per vehicle.
|
||||
vehicle = vehicle_row_by_ref[vehicle_ref]
|
||||
return {
|
||||
"active_booking_refs": [],
|
||||
"overlapping_booking_pairs": [],
|
||||
"service_threshold_reached": service_threshold_reached,
|
||||
"odometer_km": vehicle["odometer_km"],
|
||||
"next_service_km": vehicle["next_service_km"],
|
||||
"open_booking_overlap_issue_ref": None,
|
||||
}
|
||||
|
||||
def _odometer_regression_signal(later_ref: str, earlier_ref: str) -> list[dict]:
|
||||
later = booking_row_by_ref[later_ref]
|
||||
earlier = booking_row_by_ref[earlier_ref]
|
||||
return [
|
||||
{
|
||||
"code": "odometer.regression",
|
||||
"params": {
|
||||
"later_ref": later_ref,
|
||||
"later_km": later["end_odometer_km"],
|
||||
"earlier_ref": earlier_ref,
|
||||
"earlier_km": earlier["end_odometer_km"],
|
||||
},
|
||||
}
|
||||
]
|
||||
|
||||
def _missing_field_signal(field: str) -> list[dict]:
|
||||
return [{"code": "missing_field", "params": {"field": field}}]
|
||||
|
||||
# Every seed-only row below (i.e. not one of the four named DQ-DEMO-* scenarios)
|
||||
# used to carry no structured signal at all -- just the placeholder summary
|
||||
# "Synthetic deterministic seed issue". Each now cites a real fact about its actual
|
||||
# entity (a genuinely-crossed service threshold, a genuinely-blank field, or a real
|
||||
# pair of booking odometer readings engineered into seed/bookings.csv), using the
|
||||
# exact same signal vocabulary the live scan (app.services.data_quality) already
|
||||
# renders through -- see docs/fleet-ops-correction/current-gap-audit.md §6.
|
||||
_SEED_SIGNALS_BY_REF: dict[str, list[dict]] = {
|
||||
"DQ-0005": [
|
||||
{
|
||||
"code": "vehicle.service_threshold_reached",
|
||||
"params": _vehicle_conflict_facts("MO-036", service_threshold_reached=True),
|
||||
}
|
||||
],
|
||||
"DQ-0006": _missing_field_signal("location"),
|
||||
"DQ-0007": _odometer_regression_signal("BK-H-0007", "BK-H-0057"),
|
||||
"DQ-0008": [
|
||||
{
|
||||
"code": "vehicle.rental_ended",
|
||||
"params": _vehicle_conflict_facts("MO-007", service_threshold_reached=False),
|
||||
}
|
||||
],
|
||||
"DQ-0009": _missing_field_signal("location"),
|
||||
"DQ-0010": _odometer_regression_signal("BK-H-0010", "BK-H-0060"),
|
||||
"DQ-0011": [
|
||||
{
|
||||
"code": "vehicle.service_threshold_reached",
|
||||
"params": _vehicle_conflict_facts("MO-028", service_threshold_reached=True),
|
||||
}
|
||||
],
|
||||
"DQ-0012": _missing_field_signal("registration_number"),
|
||||
"DQ-0013": _missing_field_signal("location"),
|
||||
"DQ-0014": _missing_field_signal("registration_number"),
|
||||
"DQ-0015": _missing_field_signal("location"),
|
||||
"DQ-0016": _missing_field_signal("location"),
|
||||
"DQ-0017": _missing_field_signal("location"),
|
||||
"DQ-0018": _missing_field_signal("registration_number"),
|
||||
"DQ-0019": _missing_field_signal("location"),
|
||||
"DQ-0020": _missing_field_signal("location"),
|
||||
"DQ-0021": _missing_field_signal("location"),
|
||||
}
|
||||
|
||||
def _seed_signals(public_ref: str, entity_ref: str, related_refs: list[str]) -> list[dict]:
|
||||
# The four named DQ-DEMO-* rows anchor the guided demo's scripted scenarios, so
|
||||
# they carry real, accurate structured signals (not just a legacy English
|
||||
# sentence) -- the frontend renders these as the primary, localized evidence;
|
||||
# see docs/fleet-ops-correction/current-gap-audit.md §6.
|
||||
if public_ref == "DQ-DEMO-DUPLICATE":
|
||||
a = customer_row_by_ref[entity_ref]
|
||||
b = customer_row_by_ref[related_refs[0]]
|
||||
name_a = f"{a['first_name']} {a['last_name']}".strip().lower()
|
||||
name_b = f"{b['first_name']} {b['last_name']}".strip().lower()
|
||||
ratio = SequenceMatcher(None, name_a, name_b).ratio()
|
||||
return [
|
||||
{"code": "duplicate.exact_email"},
|
||||
{"code": "duplicate.exact_phone"},
|
||||
{"code": "duplicate.same_postal_code"},
|
||||
{"code": "duplicate.similar_name", "params": {"score": round(ratio, 2)}},
|
||||
]
|
||||
if public_ref == "DQ-DEMO-OVERLAP":
|
||||
return [{"code": "overlap.reserved_bookings", "params": {"refs": related_refs}}]
|
||||
if public_ref == "DQ-DEMO-STATUS":
|
||||
return [{"code": "vehicle.booking_conflict"}]
|
||||
if public_ref == "DQ-DEMO-ATTENTION":
|
||||
return [
|
||||
{
|
||||
"code": "attention.upcoming_booking_missing_inspection",
|
||||
"params": {"booking_ref": related_refs[0] if related_refs else ""},
|
||||
}
|
||||
]
|
||||
return _SEED_SIGNALS_BY_REF.get(public_ref, [])
|
||||
|
||||
dq_rows = []
|
||||
now = datetime.now(UTC)
|
||||
for row in _read_csv("data_quality_issues.csv"):
|
||||
entity_type, entity_id = resolve_entity(row["entity_ref"])
|
||||
related_ref = row.get("related_ref") or ""
|
||||
related_refs = related_ref.split("|") if related_ref else []
|
||||
dq_rows.append(
|
||||
{
|
||||
"id": uuid.uuid4(),
|
||||
@@ -240,7 +351,8 @@ def load_seed(db: Session) -> SeedResult:
|
||||
"evidence_json": {
|
||||
"summary": row["evidence"],
|
||||
"entity_ref": row["entity_ref"],
|
||||
"related_refs": related_ref.split("|") if related_ref else [],
|
||||
"related_refs": related_refs,
|
||||
"signals": _seed_signals(row["public_ref"], row["entity_ref"], related_refs),
|
||||
},
|
||||
"proposed_action_json": {},
|
||||
"detected_at": now,
|
||||
@@ -287,6 +399,12 @@ def load_seed(db: Session) -> SeedResult:
|
||||
"attempts": int(row["attempts"]),
|
||||
"next_attempt_at": None,
|
||||
"last_error": row["last_error"] or None,
|
||||
# The seed dataset's one synthetic failure (BK-H-0020) models a
|
||||
# connection-timeout-style delivery failure -- see workflow_runs.csv.
|
||||
# It is coded as a *prepared demo scenario*, not as a real
|
||||
# connectionError, so integration health never degrades because of a
|
||||
# prop and a viewer is told plainly that this failure is staged.
|
||||
"last_error_code": DEMO_SCENARIO_ERROR_CODE if row["last_error"] else None,
|
||||
"external_run_id": None,
|
||||
}
|
||||
)
|
||||
|
||||
@@ -15,6 +15,13 @@ from app.models.data_quality import DataQualityIssue
|
||||
from app.models.vehicle import Vehicle
|
||||
from app.schemas import CurrentUser, ResolveOdometerRegressionRequest
|
||||
from app.services.audit import record_audit_event
|
||||
from app.services.vehicle_status import (
|
||||
RECOMMENDATION_CODE_NO_CONFLICT,
|
||||
VehicleStatusRecommendation,
|
||||
compute_recommendation_token,
|
||||
evaluate_vehicle_status,
|
||||
gather_vehicle_status_facts,
|
||||
)
|
||||
|
||||
REQUIRED_CUSTOMER_FIELDS = ("first_name", "last_name")
|
||||
REQUIRED_VEHICLE_FIELDS = ("registration_number", "make", "model", "location")
|
||||
@@ -69,6 +76,7 @@ def _open_issue(
|
||||
summary: str,
|
||||
entity_ref: str,
|
||||
related_refs: list[str],
|
||||
signals: list[dict] | None = None,
|
||||
) -> None:
|
||||
if _has_open_issue(db, rule_type, entity_type, entity_id):
|
||||
return
|
||||
@@ -87,10 +95,14 @@ def _open_issue(
|
||||
)
|
||||
.order_by(DataQualityIssue.detected_at.desc())
|
||||
)
|
||||
# `summary` is kept as a technical-fallback string (shown only under "Technical
|
||||
# details"); `signals` is the stable, localizable structure the frontend renders as
|
||||
# the primary evidence -- see docs/fleet-ops-correction/current-gap-audit.md §2/§6.
|
||||
evidence: dict = {
|
||||
"summary": summary,
|
||||
"entity_ref": entity_ref,
|
||||
"related_refs": related_refs,
|
||||
"signals": signals or [],
|
||||
}
|
||||
if previous is not None:
|
||||
evidence["reopened_from"] = previous.public_ref
|
||||
@@ -121,22 +133,29 @@ def _scan_duplicate_customers(db: Session, scan: ScanResult) -> None:
|
||||
for i, a in enumerate(customers):
|
||||
for b in customers[i + 1 :]:
|
||||
score = 0
|
||||
signals = []
|
||||
signals: list[dict] = []
|
||||
summary_parts: list[str] = []
|
||||
if _normalize(a.email) and _normalize(a.email) == _normalize(b.email):
|
||||
score += 60
|
||||
signals.append("exact email")
|
||||
signals.append({"code": "duplicate.exact_email"})
|
||||
summary_parts.append("exact email")
|
||||
if _normalize(a.phone) and _normalize(a.phone) == _normalize(b.phone):
|
||||
score += 50
|
||||
signals.append("exact phone")
|
||||
signals.append({"code": "duplicate.exact_phone"})
|
||||
summary_parts.append("exact phone")
|
||||
if _normalize(a.postal_code) and _normalize(a.postal_code) == _normalize(b.postal_code):
|
||||
score += 10
|
||||
signals.append("exact postal code")
|
||||
signals.append({"code": "duplicate.same_postal_code"})
|
||||
summary_parts.append("exact postal code")
|
||||
name_a = f"{_normalize(a.first_name)} {_normalize(a.last_name)}"
|
||||
name_b = f"{_normalize(b.first_name)} {_normalize(b.last_name)}"
|
||||
ratio = SequenceMatcher(None, name_a, name_b).ratio()
|
||||
if ratio >= 0.5:
|
||||
score += round(ratio * 30)
|
||||
signals.append("similar name")
|
||||
signals.append(
|
||||
{"code": "duplicate.similar_name", "params": {"score": round(ratio, 2)}}
|
||||
)
|
||||
summary_parts.append("similar name")
|
||||
|
||||
if score >= DUPLICATE_THRESHOLD:
|
||||
_open_issue(
|
||||
@@ -146,9 +165,10 @@ def _scan_duplicate_customers(db: Session, scan: ScanResult) -> None:
|
||||
entity_type="customer",
|
||||
entity_id=a.id,
|
||||
severity="high",
|
||||
summary="; ".join(signals) + f" (score {score})",
|
||||
summary="; ".join(summary_parts) + f" (score {score})",
|
||||
entity_ref=a.public_ref,
|
||||
related_refs=[b.public_ref],
|
||||
signals=signals,
|
||||
)
|
||||
|
||||
|
||||
@@ -170,6 +190,7 @@ def _scan_missing_required_fields(db: Session, scan: ScanResult) -> None:
|
||||
summary=f"Missing: {', '.join(missing)}",
|
||||
entity_ref=customer.public_ref,
|
||||
related_refs=[],
|
||||
signals=[{"code": "missing_field", "params": {"field": f}} for f in missing],
|
||||
)
|
||||
|
||||
for vehicle in db.scalars(select(Vehicle).where(Vehicle.active.is_(True))).all():
|
||||
@@ -185,6 +206,7 @@ def _scan_missing_required_fields(db: Session, scan: ScanResult) -> None:
|
||||
summary=f"Missing: {', '.join(missing)}",
|
||||
entity_ref=vehicle.public_ref,
|
||||
related_refs=[],
|
||||
signals=[{"code": "missing_field", "params": {"field": f}} for f in missing],
|
||||
)
|
||||
|
||||
|
||||
@@ -213,39 +235,32 @@ def _scan_booking_overlaps(db: Session, scan: ScanResult) -> None:
|
||||
summary=f"Overlapping bookings {first.public_ref} and {second.public_ref}",
|
||||
entity_ref=vehicle.public_ref,
|
||||
related_refs=[first.public_ref, second.public_ref],
|
||||
signals=[
|
||||
{
|
||||
"code": "overlap.reserved_bookings",
|
||||
"params": {"refs": [first.public_ref, second.public_ref]},
|
||||
}
|
||||
],
|
||||
)
|
||||
|
||||
|
||||
def _scan_vehicle_status_conflicts(db: Session, scan: ScanResult) -> None:
|
||||
# Uses the same shared evaluator as the preview/apply flow (app.services.vehicle_status)
|
||||
# so detection and resolution can never structurally disagree -- see
|
||||
# docs/fleet-ops-correction/vehicle-status-decision-table.md.
|
||||
vehicles = db.scalars(select(Vehicle)).all()
|
||||
active_by_vehicle: dict[uuid.UUID, list[Booking]] = {}
|
||||
for booking in db.scalars(select(Booking).where(Booking.status == "active")).all():
|
||||
active_by_vehicle.setdefault(booking.vehicle_id, []).append(booking)
|
||||
|
||||
open_high_by_vehicle = {
|
||||
row[0]
|
||||
for row in db.execute(
|
||||
select(DataQualityIssue.entity_id).where(
|
||||
DataQualityIssue.entity_type == "vehicle",
|
||||
DataQualityIssue.status == "open",
|
||||
DataQualityIssue.severity == "high",
|
||||
)
|
||||
).all()
|
||||
}
|
||||
|
||||
for vehicle in vehicles:
|
||||
has_active_booking = vehicle.id in active_by_vehicle
|
||||
reason = None
|
||||
if vehicle.operational_status == "available" and has_active_booking:
|
||||
reason = "marked available while an active booking exists"
|
||||
elif vehicle.operational_status == "rented" and not has_active_booking:
|
||||
reason = "marked rented without an active booking"
|
||||
elif vehicle.operational_status == "available" and vehicle.id in open_high_by_vehicle:
|
||||
reason = "marked available while a high-severity quality issue is open"
|
||||
elif vehicle.operational_status == "maintenance" and has_active_booking:
|
||||
reason = "marked maintenance while an active booking exists"
|
||||
facts = gather_vehicle_status_facts(db, vehicle)
|
||||
recommendation = evaluate_vehicle_status(vehicle, facts)
|
||||
if recommendation.recommendation_code == RECOMMENDATION_CODE_NO_CONFLICT:
|
||||
continue
|
||||
|
||||
if reason:
|
||||
signals = [{"code": recommendation.recommendation_code, "params": facts.as_dict()}]
|
||||
summary = (
|
||||
f"Recommended status: {recommendation.recommended_status}"
|
||||
if recommendation.recommended_status
|
||||
else "Manual review required: active rental conflicts with a blocking condition"
|
||||
)
|
||||
_open_issue(
|
||||
db,
|
||||
scan,
|
||||
@@ -253,9 +268,13 @@ def _scan_vehicle_status_conflicts(db: Session, scan: ScanResult) -> None:
|
||||
entity_type="vehicle",
|
||||
entity_id=vehicle.id,
|
||||
severity="high",
|
||||
summary=f"Vehicle {reason}",
|
||||
summary=summary,
|
||||
entity_ref=vehicle.public_ref,
|
||||
related_refs=[],
|
||||
related_refs=[
|
||||
*facts.active_booking_refs,
|
||||
*(ref for pair in facts.overlapping_booking_pairs for ref in pair),
|
||||
],
|
||||
signals=signals,
|
||||
)
|
||||
|
||||
|
||||
@@ -295,6 +314,17 @@ def _scan_odometer_regressions(db: Session, scan: ScanResult) -> None:
|
||||
),
|
||||
entity_ref=vehicle.public_ref,
|
||||
related_refs=[earlier.public_ref, later.public_ref],
|
||||
signals=[
|
||||
{
|
||||
"code": "odometer.regression",
|
||||
"params": {
|
||||
"later_ref": later.public_ref,
|
||||
"later_km": later.end_odometer_km,
|
||||
"earlier_ref": earlier.public_ref,
|
||||
"earlier_km": earlier.end_odometer_km,
|
||||
},
|
||||
}
|
||||
],
|
||||
)
|
||||
break
|
||||
|
||||
@@ -650,28 +680,7 @@ def resolve_booking_overlap(
|
||||
return issue
|
||||
|
||||
|
||||
def _recommend_vehicle_status(
|
||||
operational_status: str, has_active_booking: bool, has_open_high_issue: bool
|
||||
) -> tuple[str, str] | None:
|
||||
"""The single authoritative recommendation function for vehicle_status_conflict,
|
||||
mirroring the exact conditions `_scan_vehicle_status_conflicts` flags."""
|
||||
if operational_status == "available" and has_active_booking:
|
||||
return "rented", "An active booking exists; the vehicle should be marked rented."
|
||||
if operational_status == "rented" and not has_active_booking:
|
||||
return "available", "No active booking exists; the vehicle should be marked available."
|
||||
if operational_status == "available" and has_open_high_issue:
|
||||
return "blocked", "A high-severity quality issue is open; the vehicle should be blocked."
|
||||
if operational_status == "maintenance" and has_active_booking:
|
||||
return (
|
||||
"rented",
|
||||
"An active booking exists despite the maintenance status; it should be rented.",
|
||||
)
|
||||
return None
|
||||
|
||||
|
||||
def apply_recommended_status(
|
||||
db: Session, public_ref: str, actor: CurrentUser
|
||||
) -> tuple[DataQualityIssue, str, str]:
|
||||
def _load_vehicle_status_conflict_issue(db: Session, public_ref: str) -> DataQualityIssue:
|
||||
issue = _load_open_issue(db, public_ref)
|
||||
if issue.rule_type != "vehicle_status_conflict":
|
||||
raise AppError(
|
||||
@@ -679,47 +688,77 @@ def apply_recommended_status(
|
||||
"This issue is not a vehicle_status_conflict issue.",
|
||||
status_code=409,
|
||||
)
|
||||
return issue
|
||||
|
||||
|
||||
def preview_vehicle_status_recommendation(
|
||||
db: Session, public_ref: str
|
||||
) -> tuple[DataQualityIssue, Vehicle, VehicleStatusRecommendation, str]:
|
||||
"""Non-mutating: computes and returns the recommendation only. Never resolves the
|
||||
issue, never writes an audit event, never queues automation -- safe to call as often
|
||||
as the UI needs (e.g. every time the panel is opened) with zero side effects."""
|
||||
issue = _load_vehicle_status_conflict_issue(db, public_ref)
|
||||
vehicle = db.scalar(select(Vehicle).where(Vehicle.id == issue.entity_id))
|
||||
if vehicle is None:
|
||||
raise AppError(
|
||||
"VEHICLE_NOT_FOUND", "The vehicle for this issue was not found.", status_code=404
|
||||
)
|
||||
facts = gather_vehicle_status_facts(db, vehicle, exclude_issue_id=issue.id)
|
||||
recommendation = evaluate_vehicle_status(vehicle, facts)
|
||||
token = compute_recommendation_token(vehicle, facts)
|
||||
return issue, vehicle, recommendation, token
|
||||
|
||||
|
||||
def apply_recommended_status(
|
||||
db: Session, public_ref: str, actor: CurrentUser, expected_token: str
|
||||
) -> tuple[DataQualityIssue, str, str]:
|
||||
issue = _load_vehicle_status_conflict_issue(db, public_ref)
|
||||
# Lock the vehicle row for the remainder of this transaction so a concurrent apply
|
||||
# (or return/checkout) can't race between our fact-gathering and the write below.
|
||||
vehicle = db.scalar(select(Vehicle).where(Vehicle.id == issue.entity_id).with_for_update())
|
||||
if vehicle is None:
|
||||
raise AppError(
|
||||
"VEHICLE_NOT_FOUND", "The vehicle for this issue was not found.", status_code=404
|
||||
)
|
||||
|
||||
has_active_booking = (
|
||||
db.scalar(
|
||||
select(Booking.id).where(Booking.vehicle_id == vehicle.id, Booking.status == "active")
|
||||
facts = gather_vehicle_status_facts(db, vehicle, exclude_issue_id=issue.id)
|
||||
recommendation = evaluate_vehicle_status(vehicle, facts)
|
||||
current_token = compute_recommendation_token(vehicle, facts)
|
||||
|
||||
if current_token != expected_token:
|
||||
raise AppError(
|
||||
"RECOMMENDATION_STALE",
|
||||
"The underlying facts changed since this recommendation was shown; "
|
||||
"review the recommendation again before applying it.",
|
||||
status_code=409,
|
||||
)
|
||||
is not None
|
||||
if recommendation.manual_review_required or not recommendation.safe_to_apply:
|
||||
raise AppError(
|
||||
"MANUAL_REVIEW_REQUIRED",
|
||||
"This vehicle's state requires manual review; no automatic status change is safe.",
|
||||
status_code=409,
|
||||
)
|
||||
has_open_high_issue = (
|
||||
db.scalar(
|
||||
select(DataQualityIssue.id).where(
|
||||
DataQualityIssue.entity_type == "vehicle",
|
||||
DataQualityIssue.entity_id == vehicle.id,
|
||||
DataQualityIssue.status == "open",
|
||||
DataQualityIssue.severity == "high",
|
||||
DataQualityIssue.id != issue.id,
|
||||
)
|
||||
)
|
||||
is not None
|
||||
)
|
||||
recommendation = _recommend_vehicle_status(
|
||||
vehicle.operational_status, has_active_booking, has_open_high_issue
|
||||
)
|
||||
if recommendation is None:
|
||||
if recommendation.recommended_status is None:
|
||||
raise AppError(
|
||||
"NO_CONFLICT_DETECTED",
|
||||
"The current vehicle state no longer conflicts; nothing to apply.",
|
||||
status_code=409,
|
||||
)
|
||||
new_status, reason = recommendation
|
||||
new_status = recommendation.recommended_status
|
||||
reason_code = recommendation.recommendation_code
|
||||
|
||||
before = {"operational_status": vehicle.operational_status}
|
||||
vehicle.operational_status = new_status
|
||||
vehicle.version += 1
|
||||
|
||||
# Re-validate: the same recommendation function must find no further conflict.
|
||||
if _recommend_vehicle_status(new_status, has_active_booking, has_open_high_issue) is not None:
|
||||
# Re-validate against the same shared evaluator, over freshly-gathered facts, that
|
||||
# applying this change actually leaves no conflict -- never trust the pre-computed
|
||||
# recommendation alone for the post-condition.
|
||||
post_facts = gather_vehicle_status_facts(db, vehicle, exclude_issue_id=issue.id)
|
||||
post_check = evaluate_vehicle_status(vehicle, post_facts)
|
||||
if post_check.recommendation_code not in (
|
||||
RECOMMENDATION_CODE_NO_CONFLICT,
|
||||
):
|
||||
raise AppError(
|
||||
"CONFLICT_STILL_PRESENT",
|
||||
"Applying the recommended status did not resolve the conflict.",
|
||||
@@ -737,7 +776,7 @@ def apply_recommended_status(
|
||||
correlation_id=correlation_id,
|
||||
before=before,
|
||||
after={"operational_status": vehicle.operational_status},
|
||||
metadata={"issue_ref": issue.public_ref, "reason": reason},
|
||||
metadata={"issue_ref": issue.public_ref, "reason_code": reason_code},
|
||||
)
|
||||
|
||||
issue.status = "resolved"
|
||||
@@ -755,7 +794,7 @@ def apply_recommended_status(
|
||||
after={"status": "resolved"},
|
||||
)
|
||||
db.commit()
|
||||
return issue, new_status, reason
|
||||
return issue, new_status, reason_code
|
||||
|
||||
|
||||
MERGEABLE_FIELDS = ("first_name", "last_name", "email", "phone", "postal_code", "city")
|
||||
|
||||
@@ -11,7 +11,7 @@ from app.models.booking import Booking
|
||||
from app.models.data_quality import DataQualityIssue
|
||||
from app.models.outbox import OutboxEvent
|
||||
from app.schemas import DemoIntegrationSummaryOut, DemoManifestOut, DemoScenarioOut
|
||||
from app.services.integration_status import derive_n8n_status
|
||||
from app.services.integration_status import derive_mcp_hub_status, derive_n8n_status
|
||||
from app.services.knowledge import get_knowledge_provider
|
||||
|
||||
settings = get_settings()
|
||||
@@ -124,6 +124,7 @@ def _scenarios(db: Session) -> list[DemoScenarioOut]:
|
||||
def _integrations(db: Session) -> list[DemoIntegrationSummaryOut]:
|
||||
n8n = derive_n8n_status(db)
|
||||
knowledge_health = get_knowledge_provider().health()
|
||||
mcp_hub = derive_mcp_hub_status(db)
|
||||
|
||||
return [
|
||||
DemoIntegrationSummaryOut(
|
||||
@@ -141,17 +142,23 @@ def _integrations(db: Session) -> list[DemoIntegrationSummaryOut]:
|
||||
status_code="operational" if knowledge_health.provider == "ragcore" else "demoMode",
|
||||
detail_code="ragcoreDetail",
|
||||
detail_params={
|
||||
"count": knowledge_health.document_count,
|
||||
"count": (
|
||||
knowledge_health.document_count
|
||||
if knowledge_health.document_count is not None
|
||||
else "unknown"
|
||||
),
|
||||
"collection": knowledge_health.collection,
|
||||
},
|
||||
),
|
||||
DemoIntegrationSummaryOut(
|
||||
key="mcp_hub",
|
||||
status_code="operational" if settings.mcp_hub_registration_enabled else "notConnected",
|
||||
# `MCP_HUB_REGISTRATION_ENABLED` on its own proves nothing: registration is
|
||||
# catalog-driven on the Hub's side, so the flag only says Fleet Ops expects
|
||||
# to be called. Only real recorded `mcp_tool_request` calls make this
|
||||
# "operational" -- same evidence rule the integration status page uses.
|
||||
status_code="operational" if mcp_hub.state == "operational" else "notConnected",
|
||||
detail_code=(
|
||||
"mcpDetailEnabled"
|
||||
if settings.mcp_hub_registration_enabled
|
||||
else "mcpDetailNotConnected"
|
||||
"mcpDetailEnabled" if mcp_hub.state == "operational" else "mcpDetailNotConnected"
|
||||
),
|
||||
detail_params={},
|
||||
),
|
||||
|
||||
@@ -48,6 +48,7 @@ def _reclaim_stale_deliveries(batch_size: int = 10) -> int:
|
||||
f"(no outcome recorded within {settings.n8n_delivery_lease_seconds:.0f}s; "
|
||||
f"the process likely crashed mid-delivery). attempts preserved at {row.attempts}."
|
||||
)[:2000]
|
||||
row.last_error_code = "staleLeaseRecovered"
|
||||
db.commit()
|
||||
return len(rows)
|
||||
finally:
|
||||
@@ -111,22 +112,43 @@ def _deliver_one(event_id: uuid.UUID) -> None:
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
error_code: str | None
|
||||
if wire_event is None:
|
||||
success, error, body = False, payload_error, None
|
||||
error_code = "malformedPayload"
|
||||
else:
|
||||
try:
|
||||
response = httpx.post(
|
||||
settings.n8n_webhook_url,
|
||||
json=wire_event,
|
||||
headers={"X-Fleet-Ops-Trigger-Token": settings.n8n_webhook_trigger_token},
|
||||
timeout=settings.n8n_http_timeout_seconds,
|
||||
)
|
||||
response.raise_for_status()
|
||||
try:
|
||||
body = response.json()
|
||||
except ValueError:
|
||||
body = None
|
||||
if isinstance(body, dict):
|
||||
success = bool(body.get("ok", True))
|
||||
error = None if success else f"n8n reported failure: {body}"
|
||||
error_code = None if success else "remoteReportedFailure"
|
||||
else:
|
||||
# A 2xx status with a non-object (or unparsable) body means the workflow
|
||||
# itself errored before its "Respond to Webhook" node ran -- n8n's default
|
||||
# error response still carries a 2xx-looking status here. Treat it as a
|
||||
# failure so the event is retried rather than lost or wrongly marked
|
||||
# succeeded.
|
||||
success = False
|
||||
error = (
|
||||
"Unexpected non-JSON-object response from n8n "
|
||||
f"(status {response.status_code})"
|
||||
)
|
||||
error_code = "malformedResponse"
|
||||
except httpx.HTTPError as exc:
|
||||
success = False
|
||||
error = f"{type(exc).__name__}: {exc}"
|
||||
error_code = "connectionError"
|
||||
body = None
|
||||
|
||||
db = SessionLocal()
|
||||
@@ -138,10 +160,12 @@ def _deliver_one(event_id: uuid.UUID) -> None:
|
||||
if success:
|
||||
event.delivery_status = "succeeded"
|
||||
event.last_error = None
|
||||
event.last_error_code = None
|
||||
event.next_attempt_at = None
|
||||
event.external_run_id = str((body or {}).get("event_id", event_id))
|
||||
else:
|
||||
event.last_error = (error or "delivery failed")[:2000]
|
||||
event.last_error_code = error_code or "unknownError"
|
||||
if event.attempts >= settings.n8n_max_attempts:
|
||||
event.delivery_status = "failed"
|
||||
event.next_attempt_at = None
|
||||
|
||||
@@ -2,15 +2,31 @@ from __future__ import annotations
|
||||
|
||||
from typing import Literal
|
||||
|
||||
import httpx
|
||||
from sqlalchemy import func, select
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from app.core.config import get_settings
|
||||
from app.models.outbox import OutboxEvent
|
||||
from app.schemas import N8nIntegrationStatus
|
||||
from app.models.audit import AuditEvent
|
||||
from app.models.outbox import DEMO_SCENARIO_ERROR_CODE, OutboxEvent
|
||||
from app.schemas import (
|
||||
McpHubIntegrationStatus,
|
||||
N8nErrorHandlerStatus,
|
||||
N8nIntegrationStatus,
|
||||
N8nWorkflowEvidence,
|
||||
)
|
||||
|
||||
settings = get_settings()
|
||||
|
||||
# The 4 canonical Fleet Ops n8n workflows (see n8n/workflows/MANIFEST.md). All 4 are
|
||||
# built (all with their full node set saved).
|
||||
_CANONICAL_WORKFLOWS = (
|
||||
"Fleet Ops — Vehicle Return Orchestration",
|
||||
"Fleet Ops — Scheduled Data Quality Scan",
|
||||
"Fleet Ops — RAGcore Procedure Sync",
|
||||
"Fleet Ops — Workflow Error Handler",
|
||||
)
|
||||
|
||||
|
||||
def derive_n8n_status(db: Session) -> N8nIntegrationStatus:
|
||||
counts: dict[str, int] = dict(
|
||||
@@ -23,25 +39,111 @@ def derive_n8n_status(db: Session) -> N8nIntegrationStatus:
|
||||
failed = counts.get("failed", 0)
|
||||
succeeded = counts.get("succeeded", 0)
|
||||
|
||||
# Prepared demo failures are props, not health signals. They stay visible and
|
||||
# counted -- hiding them would be its own kind of lie -- but they are counted
|
||||
# *separately*, and only genuinely unexpected failures are allowed to move n8n off
|
||||
# "operational". Without this split the demo seed's single staged failure pins the
|
||||
# integration to "degraded" forever, which tells a viewer something untrue about
|
||||
# the automation.
|
||||
demo_scenario_failed = (
|
||||
db.scalar(
|
||||
select(func.count())
|
||||
.select_from(OutboxEvent)
|
||||
.where(
|
||||
OutboxEvent.delivery_status == "failed",
|
||||
OutboxEvent.last_error_code == DEMO_SCENARIO_ERROR_CODE,
|
||||
)
|
||||
)
|
||||
or 0
|
||||
)
|
||||
unexpected_failed = max(failed - demo_scenario_failed, 0)
|
||||
|
||||
latest_success_at = db.scalar(
|
||||
select(func.max(OutboxEvent.updated_at)).where(OutboxEvent.delivery_status == "succeeded")
|
||||
)
|
||||
# Health talks about real failures only, so the "latest failure" a health reader
|
||||
# sees must exclude the staged one too.
|
||||
latest_failure_at = db.scalar(
|
||||
select(func.max(OutboxEvent.updated_at)).where(OutboxEvent.delivery_status == "failed")
|
||||
select(func.max(OutboxEvent.updated_at)).where(
|
||||
OutboxEvent.delivery_status == "failed",
|
||||
OutboxEvent.last_error_code != DEMO_SCENARIO_ERROR_CODE,
|
||||
)
|
||||
)
|
||||
latest_demo_scenario_at = db.scalar(
|
||||
select(func.max(OutboxEvent.updated_at)).where(
|
||||
OutboxEvent.delivery_status == "failed",
|
||||
OutboxEvent.last_error_code == DEMO_SCENARIO_ERROR_CODE,
|
||||
)
|
||||
)
|
||||
|
||||
state: Literal["disabled", "unavailable", "degraded", "operational", "no_evidence"]
|
||||
if not settings.n8n_dispatch_enabled:
|
||||
state = "disabled"
|
||||
elif failed > 0 and succeeded == 0:
|
||||
elif unexpected_failed > 0 and succeeded == 0:
|
||||
state = "unavailable"
|
||||
elif failed > 0:
|
||||
elif unexpected_failed > 0:
|
||||
state = "degraded"
|
||||
elif succeeded > 0 or pending > 0 or delivering > 0:
|
||||
state = "operational"
|
||||
else:
|
||||
state = "no_evidence"
|
||||
|
||||
# Scheduled scan evidence: only service-triggered runs count as n8n evidence, not
|
||||
# runs an operator triggered manually from the Data Quality page.
|
||||
latest_scan_at = db.scalar(
|
||||
select(func.max(AuditEvent.occurred_at)).where(
|
||||
AuditEvent.action == "data_quality_scan_run",
|
||||
AuditEvent.actor_type == "service",
|
||||
)
|
||||
)
|
||||
|
||||
# RAGcore Procedure Sync evidence: result reports posted by the workflow itself once
|
||||
# it finishes uploading procedures to RAGcore (app/api/routers/integrations.py::
|
||||
# procedures_sync_result), the same "the workflow's own callback is the evidence"
|
||||
# pattern the scheduled scan and error handler already use below.
|
||||
latest_procedure_sync_at = db.scalar(
|
||||
select(func.max(AuditEvent.occurred_at)).where(
|
||||
AuditEvent.action == "n8n_procedures_synced"
|
||||
)
|
||||
)
|
||||
|
||||
# Error handler evidence: registrations posted by the "Fleet Ops — Workflow Error
|
||||
# Handler" n8n workflow itself, which also doubles as proof that workflow is wired
|
||||
# up and firing correctly.
|
||||
total_failures_registered = (
|
||||
db.scalar(
|
||||
select(func.count(AuditEvent.id)).where(
|
||||
AuditEvent.action == "n8n_workflow_failure_registered"
|
||||
)
|
||||
)
|
||||
or 0
|
||||
)
|
||||
latest_failure_row = db.execute(
|
||||
select(AuditEvent.occurred_at, AuditEvent.after_json)
|
||||
.where(AuditEvent.action == "n8n_workflow_failure_registered")
|
||||
.order_by(AuditEvent.occurred_at.desc())
|
||||
.limit(1)
|
||||
).first()
|
||||
latest_handler_failure_at = latest_failure_row[0] if latest_failure_row else None
|
||||
latest_handler_failure_workflow = (
|
||||
(latest_failure_row[1] or {}).get("workflow_name") if latest_failure_row else None
|
||||
)
|
||||
|
||||
evidence_by_workflow = {
|
||||
"Fleet Ops — Vehicle Return Orchestration": latest_success_at,
|
||||
"Fleet Ops — Scheduled Data Quality Scan": latest_scan_at,
|
||||
"Fleet Ops — RAGcore Procedure Sync": latest_procedure_sync_at,
|
||||
"Fleet Ops — Workflow Error Handler": latest_handler_failure_at,
|
||||
}
|
||||
workflows = [
|
||||
N8nWorkflowEvidence(
|
||||
name=name,
|
||||
built=True,
|
||||
last_seen_at=evidence_by_workflow[name],
|
||||
)
|
||||
for name in _CANONICAL_WORKFLOWS
|
||||
]
|
||||
|
||||
return N8nIntegrationStatus(
|
||||
configured=bool(settings.n8n_webhook_url),
|
||||
dispatch_enabled=settings.n8n_dispatch_enabled,
|
||||
@@ -49,7 +151,72 @@ def derive_n8n_status(db: Session) -> N8nIntegrationStatus:
|
||||
pending=pending,
|
||||
delivering=delivering,
|
||||
failed=failed,
|
||||
unexpected_failed=unexpected_failed,
|
||||
demo_scenario_failed=demo_scenario_failed,
|
||||
succeeded=succeeded,
|
||||
latest_success_at=latest_success_at,
|
||||
latest_failure_at=latest_failure_at,
|
||||
latest_demo_scenario_at=latest_demo_scenario_at,
|
||||
expected_workflow_count=len(_CANONICAL_WORKFLOWS),
|
||||
known_workflow_count=sum(1 for w in workflows if w.last_seen_at is not None),
|
||||
workflows=workflows,
|
||||
error_handler=N8nErrorHandlerStatus(
|
||||
total_failures_registered=total_failures_registered,
|
||||
latest_failure_at=latest_handler_failure_at,
|
||||
latest_failure_workflow=latest_handler_failure_workflow,
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
def derive_mcp_hub_status(db: Session) -> McpHubIntegrationStatus:
|
||||
"""Evidence-based MCP Hub status: real tool-call audit history, not just the
|
||||
`MCP_HUB_REGISTRATION_ENABLED` flag flipped on. Every `mcp_tool_request` call
|
||||
already writes an `AuditEvent` (see `app/api/routers/mcp_integrations.py`)."""
|
||||
total_calls = (
|
||||
db.scalar(
|
||||
select(func.count(AuditEvent.id)).where(AuditEvent.action == "mcp_tool_request")
|
||||
)
|
||||
or 0
|
||||
)
|
||||
latest_call_row = db.execute(
|
||||
select(AuditEvent.occurred_at, AuditEvent.actor_label, AuditEvent.metadata_json)
|
||||
.where(AuditEvent.action == "mcp_tool_request")
|
||||
.order_by(AuditEvent.occurred_at.desc())
|
||||
.limit(1)
|
||||
).first()
|
||||
last_called_at = latest_call_row[0] if latest_call_row else None
|
||||
last_client = latest_call_row[1] if latest_call_row else None
|
||||
last_tool = (latest_call_row[2] or {}).get("tool") if latest_call_row else None
|
||||
|
||||
state: Literal["not_configured", "no_evidence", "operational"]
|
||||
if not settings.mcp_hub_registration_enabled:
|
||||
state = "not_configured"
|
||||
elif total_calls > 0:
|
||||
state = "operational"
|
||||
else:
|
||||
state = "no_evidence"
|
||||
|
||||
hub_reachable = _check_hub_reachable()
|
||||
|
||||
return McpHubIntegrationStatus(
|
||||
registration_enabled=settings.mcp_hub_registration_enabled,
|
||||
state=state,
|
||||
total_calls=total_calls,
|
||||
last_tool=last_tool,
|
||||
last_client=last_client,
|
||||
last_called_at=last_called_at,
|
||||
hub_reachable=hub_reachable,
|
||||
)
|
||||
|
||||
|
||||
def _check_hub_reachable() -> bool | None:
|
||||
"""Real Hub-side health signal (MCP Hub's own registration is catalog-driven on
|
||||
its side, so this is the only thing Fleet Ops itself can honestly check).
|
||||
`None` means not configured / not checked, never a guess."""
|
||||
if not settings.mcp_hub_base_url:
|
||||
return None
|
||||
try:
|
||||
response = httpx.get(f"{settings.mcp_hub_base_url.rstrip('/')}/health", timeout=1.5)
|
||||
return response.status_code == 200
|
||||
except httpx.HTTPError:
|
||||
return False
|
||||
|
||||
@@ -33,7 +33,9 @@ class KnowledgeHealth(BaseModel):
|
||||
tenant: str
|
||||
workspace: str
|
||||
collection: str
|
||||
document_count: int
|
||||
# A provider may be healthy without exposing a corpus-size endpoint. `None` means
|
||||
# unknown, never "zero procedures".
|
||||
document_count: int | None
|
||||
|
||||
|
||||
class KnowledgeProvider(Protocol):
|
||||
|
||||
@@ -7,6 +7,7 @@ from pathlib import Path
|
||||
|
||||
from app.core.config import get_settings
|
||||
from app.services.knowledge import GroundedAnswer, KnowledgeHealth, SourceCard
|
||||
from app.services.knowledge.procedures import parse_frontmatter
|
||||
|
||||
SUPPORTED_LANGUAGES = ("nl-BE", "en-GB", "fr-BE")
|
||||
DEFAULT_LANGUAGE = "en-GB"
|
||||
@@ -35,7 +36,11 @@ STOPWORDS_BY_LANGUAGE: dict[str, set[str]] = {
|
||||
},
|
||||
}
|
||||
|
||||
_WORD_RE = re.compile(r"[a-z0-9]+")
|
||||
# Includes the Latin-1 accented-letter range (à-ö, ø-ÿ) so French/Dutch words with
|
||||
# diacritics (véhicule, réservation, geëscaleerd) tokenize as one word instead of
|
||||
# splitting apart at the accented character -- a plain [a-z0-9]+ pattern silently
|
||||
# drops every accent and fragments the word either side of it.
|
||||
_WORD_RE = re.compile(r"[a-zà-öø-ÿ0-9]+")
|
||||
|
||||
|
||||
def _stem(word: str) -> str:
|
||||
@@ -70,23 +75,6 @@ class ScoredSection:
|
||||
body_tokens: set[str]
|
||||
|
||||
|
||||
def _parse_frontmatter(raw: str) -> tuple[dict[str, str], str]:
|
||||
if not raw.startswith("---"):
|
||||
return {}, raw
|
||||
end = raw.find("\n---", 3)
|
||||
if end == -1:
|
||||
return {}, raw
|
||||
block = raw[3:end].strip()
|
||||
body = raw[end + 4 :].lstrip("\n")
|
||||
meta: dict[str, str] = {}
|
||||
for line in block.splitlines():
|
||||
if ":" not in line:
|
||||
continue
|
||||
key, _, value = line.partition(":")
|
||||
meta[key.strip()] = value.strip().strip('"')
|
||||
return meta, body
|
||||
|
||||
|
||||
def _split_sections(body: str) -> list[tuple[str, str]]:
|
||||
sections: list[tuple[str, str]] = []
|
||||
current_heading = "Overview"
|
||||
@@ -110,7 +98,7 @@ def _load_sections(procedures_dir: Path, language: str) -> list[ScoredSection]:
|
||||
sections: list[ScoredSection] = []
|
||||
for path in sorted(procedures_dir.glob("*.md")):
|
||||
raw = path.read_text(encoding="utf-8")
|
||||
meta, body = _parse_frontmatter(raw)
|
||||
meta, body = parse_frontmatter(raw)
|
||||
title = meta.get("title", path.stem)
|
||||
doc = Document(
|
||||
document_id=meta.get("document_id", path.stem),
|
||||
@@ -218,17 +206,28 @@ class DemoKnowledgeProvider:
|
||||
def _score(
|
||||
self, query_tokens: set[str], section: ScoredSection, idf: dict[str, float]
|
||||
) -> float:
|
||||
# The section body is the strongest relevance signal -- it's the actual
|
||||
# substance a heading or title can only hint at -- so a body match is weighted
|
||||
# *above* heading/title matches, not below them. The previous 3x/2x/1x
|
||||
# (heading/title/body) ordering let a single generic word in a heading (e.g.
|
||||
# "vehicle", present in nearly every section) or a document's own title
|
||||
# outrank a section whose body genuinely covers multiple, more distinctive
|
||||
# query terms -- confirmed to misrank the brief's exact validation question in
|
||||
# every one of the three languages (see docs/fleet-ops-correction/
|
||||
# current-gap-audit.md and i18n-inventory.md): nl-BE picked a checkout section
|
||||
# over the damage procedure, en-GB and fr-BE picked the return procedure over
|
||||
# the damage procedure, purely from heading/title overlap on common words.
|
||||
score = 0.0
|
||||
for token in query_tokens:
|
||||
token_idf = idf.get(token, 0.0)
|
||||
if token_idf == 0.0:
|
||||
continue
|
||||
if token in section.heading_tokens:
|
||||
if token in section.body_tokens:
|
||||
score += 3 * token_idf
|
||||
elif token in section.document.title_tokens:
|
||||
elif token in section.heading_tokens:
|
||||
score += 2 * token_idf
|
||||
elif token in section.body_tokens:
|
||||
score += token_idf
|
||||
elif token in section.document.title_tokens:
|
||||
score += 1.5 * token_idf
|
||||
return score
|
||||
|
||||
def ask(
|
||||
|
||||
@@ -0,0 +1,71 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import hashlib
|
||||
import uuid
|
||||
from dataclasses import dataclass
|
||||
from pathlib import Path
|
||||
|
||||
SUPPORTED_LANGUAGES = ("nl-BE", "en-GB", "fr-BE")
|
||||
|
||||
# Stable across runs (and across which language ships first) so a document's RAGcore
|
||||
# source_id never changes just because the sync ran on a different day or in a
|
||||
# different order -- required for RAGcore's upload idempotency to work per document.
|
||||
_SOURCE_ID_NAMESPACE = uuid.uuid5(uuid.NAMESPACE_URL, "https://mobilityops.internal/knowledge/procedures")
|
||||
|
||||
|
||||
def parse_frontmatter(raw: str) -> tuple[dict[str, str], str]:
|
||||
if not raw.startswith("---"):
|
||||
return {}, raw
|
||||
end = raw.find("\n---", 3)
|
||||
if end == -1:
|
||||
return {}, raw
|
||||
block = raw[3:end].strip()
|
||||
body = raw[end + 4 :].lstrip("\n")
|
||||
meta: dict[str, str] = {}
|
||||
for line in block.splitlines():
|
||||
if ":" not in line:
|
||||
continue
|
||||
key, _, value = line.partition(":")
|
||||
meta[key.strip()] = value.strip().strip('"')
|
||||
return meta, body
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class ProcedureDocument:
|
||||
source_id: str
|
||||
language: str
|
||||
document_id: str
|
||||
title: str
|
||||
version: str
|
||||
content: str
|
||||
content_hash: str
|
||||
|
||||
|
||||
def iter_procedure_documents(knowledge_dir: Path) -> list[ProcedureDocument]:
|
||||
"""Read every procedure Markdown file Fleet Ops ships, across every supported
|
||||
language, as a flat list ready for external sync (e.g. into RAGcore). Frontmatter
|
||||
fields (title, version) come from the same files the demo knowledge provider
|
||||
already reads -- see parse_frontmatter -- so the two never drift apart."""
|
||||
|
||||
documents: list[ProcedureDocument] = []
|
||||
for language in SUPPORTED_LANGUAGES:
|
||||
language_dir = knowledge_dir / language
|
||||
if not language_dir.is_dir():
|
||||
continue
|
||||
for path in sorted(language_dir.glob("*.md")):
|
||||
raw = path.read_text(encoding="utf-8")
|
||||
meta, body = parse_frontmatter(raw)
|
||||
document_id = meta.get("document_id", path.stem)
|
||||
content = body.strip()
|
||||
documents.append(
|
||||
ProcedureDocument(
|
||||
source_id=str(uuid.uuid5(_SOURCE_ID_NAMESPACE, f"{language}:{document_id}")),
|
||||
language=language,
|
||||
document_id=document_id,
|
||||
title=meta.get("title", path.stem),
|
||||
version=meta.get("version", "1.0"),
|
||||
content=content,
|
||||
content_hash=hashlib.sha256(content.encode("utf-8")).hexdigest(),
|
||||
)
|
||||
)
|
||||
return documents
|
||||
@@ -3,18 +3,51 @@ from __future__ import annotations
|
||||
import httpx
|
||||
|
||||
from app.core.config import get_settings
|
||||
from app.services.knowledge import GroundedAnswer, KnowledgeHealth, SourceCard
|
||||
from app.services.knowledge import EvidenceState, GroundedAnswer, KnowledgeHealth, SourceCard
|
||||
|
||||
_GROUNDED_ANSWERABILITY = {"answerable", "partially_answerable"}
|
||||
|
||||
# Mirrors DemoKnowledgeProvider's own extractive template in spirit: a real cited
|
||||
# excerpt wrapped in a fixed sentence, never a generated summary. Used only as a
|
||||
# fallback when RAGcore's own /v1/answers (generation + citation validation) is
|
||||
# unavailable but its retrieval (/v1/search) still returns real, relevant, cited
|
||||
# results -- see ask() below. Unlike the demo corpus's own markdown frontmatter, RAGcore's
|
||||
# `document_version_id` is an opaque UUID, not a human-meaningful version string, so it
|
||||
# is deliberately left out of this sentence (it still appears on the source card itself).
|
||||
_LEAD_ANSWER_TEMPLATE = {
|
||||
"en-GB": 'Per "{title}": {excerpt}',
|
||||
"nl-BE": 'Volgens "{title}": {excerpt}',
|
||||
"fr-BE": 'Selon « {title} » : {excerpt}',
|
||||
}
|
||||
_DEFAULT_LANGUAGE = "en-GB"
|
||||
|
||||
|
||||
class RAGcoreKnowledgeProvider:
|
||||
"""Adapter for the central RAGcore service.
|
||||
"""Adapter for the central RAGcore service, against its real `/v1/*` contract
|
||||
(see `docs/contracts/openapi.yaml` in the RAGcore checkout -- RAGcore is built and
|
||||
owned separately, MobilityOps only ever talks to its documented HTTP API).
|
||||
|
||||
RAGcore is built and owned separately (see contracts/ragcore-contract-assumptions.md).
|
||||
No live RAGcore instance was reachable during this build, so the exact request/response
|
||||
shape below is a best-effort guess at a REST contract; any failure (connection, timeout,
|
||||
malformed response) degrades to `unavailable` rather than raising, per the architecture's
|
||||
reliability boundary: RAGcore failure disables knowledge answers only, never the rest of
|
||||
the app, and never fabricates an answer.
|
||||
Authenticates as a service account via `Authorization: Bearer <token>` (RAGcore's
|
||||
session-cookie auth is for its own browser admin UI only). Any connection error,
|
||||
timeout, non-2xx response, or malformed body degrades to `evidence_state:
|
||||
"unavailable"` rather than raising -- this is the adapter that actually exercises the
|
||||
architecture's reliability boundary: RAGcore failure disables knowledge answers only,
|
||||
never fabricates an answer, never affects the rest of the app.
|
||||
|
||||
`/v1/answers` (RAGcore's own generation + citation-validation step) is tried first;
|
||||
if it is itself unavailable (non-2xx or unreachable -- as opposed to a real 200
|
||||
classifying the question as insufficiently answerable), `ask()` falls back to
|
||||
RAGcore's `/v1/search` retrieval, which is a materially different, simpler pipeline
|
||||
stage with no generation step to fail. The fallback answer is always an extractive
|
||||
excerpt RAGcore's own search actually found, wrapped in the same fixed citation
|
||||
template `DemoKnowledgeProvider` uses -- never a fabricated summary.
|
||||
|
||||
Known gap, not fixable from this side: RAGcore's ingest pipeline currently tags every
|
||||
chunk's `language` payload field as `"en"` regardless of actual document language (the
|
||||
`/v1/uploads` contract has no per-file language field for a caller to set correctly).
|
||||
Filtering search/answer requests by requested UI language would therefore silently
|
||||
exclude genuinely-relevant nl-BE/fr-BE content, so this adapter deliberately does not
|
||||
filter by language -- retrieval relies on the embedding model's cross-lingual matching.
|
||||
"""
|
||||
|
||||
name = "ragcore"
|
||||
@@ -35,11 +68,15 @@ class RAGcoreKnowledgeProvider:
|
||||
def health(self, language: str = "en-GB") -> KnowledgeHealth:
|
||||
try:
|
||||
with self._client() as client:
|
||||
response = client.get("/health")
|
||||
response.raise_for_status()
|
||||
available = True
|
||||
detail = "RAGcore reachable."
|
||||
except httpx.HTTPError as exc:
|
||||
response = client.get("/health/ready")
|
||||
body = response.json()
|
||||
available = response.status_code == 200 and body.get("status") == "ok"
|
||||
detail = (
|
||||
"RAGcore reachable and ready."
|
||||
if available
|
||||
else f"RAGcore degraded: {body.get('status', 'unknown')}"
|
||||
)
|
||||
except (httpx.HTTPError, ValueError) as exc:
|
||||
available = False
|
||||
detail = f"RAGcore unavailable: {type(exc).__name__}: {exc}"
|
||||
return KnowledgeHealth(
|
||||
@@ -49,51 +86,135 @@ class RAGcoreKnowledgeProvider:
|
||||
tenant=self._settings.ragcore_tenant,
|
||||
workspace=self._settings.ragcore_workspace,
|
||||
collection=self._settings.ragcore_collection,
|
||||
document_count=0,
|
||||
# RAGcore's retrieval API has no corpus-size endpoint. Unknown is explicit
|
||||
# so the UI never turns this into the misleading claim "0 procedures".
|
||||
document_count=None,
|
||||
)
|
||||
|
||||
def ask(self, question: str, correlation_id: str, language: str = "en-GB") -> GroundedAnswer:
|
||||
try:
|
||||
with self._client() as client:
|
||||
response = client.post(
|
||||
"/api/v1/ask",
|
||||
json={
|
||||
"tenant": self._settings.ragcore_tenant,
|
||||
"workspace": self._settings.ragcore_workspace,
|
||||
"collection": self._settings.ragcore_collection,
|
||||
"question": question,
|
||||
"correlation_id": correlation_id,
|
||||
"language": language,
|
||||
},
|
||||
)
|
||||
response.raise_for_status()
|
||||
body = response.json()
|
||||
except (httpx.HTTPError, ValueError):
|
||||
return GroundedAnswer(
|
||||
unavailable = GroundedAnswer(
|
||||
answer="",
|
||||
evidence_state="unavailable",
|
||||
sources=[],
|
||||
provider=self.name,
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
if not self._settings.ragcore_space_id:
|
||||
return unavailable
|
||||
|
||||
answered = self._ask_via_answers(question, correlation_id)
|
||||
if answered is not None:
|
||||
return answered
|
||||
# /v1/answers itself is unavailable (non-2xx or unreachable) -- fall back to
|
||||
# real retrieval rather than degrading straight to "unavailable". This never
|
||||
# fabricates an answer to the question: it only ever shows an actually-cited
|
||||
# excerpt RAGcore's own search already found, using the same extractive
|
||||
# citation-wrapper template DemoKnowledgeProvider uses, never RAGcore's
|
||||
# generation step.
|
||||
return self._ask_via_search_fallback(question, correlation_id, language)
|
||||
|
||||
def _ask_via_answers(self, question: str, correlation_id: str) -> GroundedAnswer | None:
|
||||
"""Returns None (not a GroundedAnswer) when /v1/answers itself is unavailable,
|
||||
so the caller can fall back to search -- as opposed to a real 200 response
|
||||
classifying the question as insufficiently answerable, which is a genuine,
|
||||
final result, not a reason to fall back."""
|
||||
try:
|
||||
with self._client() as client:
|
||||
response = client.post(
|
||||
"/v1/answers",
|
||||
json={
|
||||
"query": question,
|
||||
"requested_space_ids": [self._settings.ragcore_space_id],
|
||||
},
|
||||
)
|
||||
if response.status_code != 200:
|
||||
return None
|
||||
body = response.json()
|
||||
except (httpx.HTTPError, ValueError):
|
||||
return None
|
||||
|
||||
try:
|
||||
sources = [SourceCard(**s) for s in body.get("sources", [])]
|
||||
evidence_state = body.get("evidence_state", "insufficient")
|
||||
if evidence_state not in ("grounded", "insufficient", "unavailable"):
|
||||
evidence_state = "insufficient"
|
||||
citations = {c["id"]: c for c in body.get("citations", [])}
|
||||
sources = [
|
||||
SourceCard(
|
||||
document_id=str(citation["document_id"]),
|
||||
title=citation["title"],
|
||||
version=str(citation["document_version_id"]),
|
||||
section=citation.get("section") or "",
|
||||
excerpt=citation["excerpt"],
|
||||
)
|
||||
for citation in citations.values()
|
||||
]
|
||||
answerability = body.get("answerability", "not_answerable")
|
||||
is_grounded = answerability in _GROUNDED_ANSWERABILITY and sources
|
||||
evidence_state: EvidenceState = "grounded" if is_grounded else "insufficient"
|
||||
return GroundedAnswer(
|
||||
answer=body.get("answer", ""),
|
||||
answer=body.get("answer", "") if evidence_state == "grounded" else "",
|
||||
evidence_state=evidence_state,
|
||||
sources=sources if evidence_state == "grounded" else [],
|
||||
provider=self.name,
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
except (TypeError, KeyError, ValueError):
|
||||
return None
|
||||
|
||||
def _ask_via_search_fallback(
|
||||
self, question: str, correlation_id: str, language: str
|
||||
) -> GroundedAnswer:
|
||||
unavailable = GroundedAnswer(
|
||||
answer="",
|
||||
evidence_state="unavailable",
|
||||
sources=[],
|
||||
provider=self.name,
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
try:
|
||||
with self._client() as client:
|
||||
response = client.post(
|
||||
"/v1/search",
|
||||
json={
|
||||
"query": question,
|
||||
"requested_space_ids": [self._settings.ragcore_space_id],
|
||||
"max_results": 5,
|
||||
},
|
||||
)
|
||||
if response.status_code != 200:
|
||||
return unavailable
|
||||
body = response.json()
|
||||
except (httpx.HTTPError, ValueError):
|
||||
return unavailable
|
||||
|
||||
try:
|
||||
results = body.get("results", [])
|
||||
sources = [
|
||||
SourceCard(
|
||||
document_id=str(result["citation"]["document_id"]),
|
||||
title=result["citation"]["title"],
|
||||
version=str(result["citation"]["document_version_id"]),
|
||||
section=result["citation"].get("section") or "",
|
||||
excerpt=result["citation"]["excerpt"],
|
||||
)
|
||||
for result in results
|
||||
]
|
||||
except (TypeError, KeyError, ValueError):
|
||||
return unavailable
|
||||
|
||||
if not sources:
|
||||
return GroundedAnswer(
|
||||
answer="",
|
||||
evidence_state="insufficient",
|
||||
sources=[],
|
||||
provider=self.name,
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
|
||||
template = _LEAD_ANSWER_TEMPLATE.get(language, _LEAD_ANSWER_TEMPLATE[_DEFAULT_LANGUAGE])
|
||||
lead = sources[0]
|
||||
answer = template.format(title=lead.title, excerpt=lead.excerpt)
|
||||
return GroundedAnswer(
|
||||
answer=answer,
|
||||
evidence_state="grounded",
|
||||
sources=sources,
|
||||
provider=self.name,
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
except (TypeError, ValueError):
|
||||
return GroundedAnswer(
|
||||
answer="",
|
||||
evidence_state="unavailable",
|
||||
sources=[],
|
||||
provider=self.name,
|
||||
correlation_id=correlation_id,
|
||||
)
|
||||
|
||||
@@ -28,19 +28,41 @@ def _next_public_ref(db: Session) -> str:
|
||||
|
||||
def _derive_vehicle_status_with_reason(
|
||||
body: RegisterReturnRequest, vehicle: Vehicle, new_odometer: int
|
||||
) -> tuple[str, str]:
|
||||
) -> tuple[str, str, dict[str, str | int]]:
|
||||
# Stable, localizable codes + params -- the backend never emits prose here. The
|
||||
# frontend renders review.reasonCodes.<code> in the selected locale; the mirrored
|
||||
# raw-English fallback strings live only in status_reason (shown under "Technical
|
||||
# details") for backward compatibility. See docs/fleet-ops-correction/i18n-inventory.md.
|
||||
if body.damage_reported and body.technical_warning:
|
||||
return "blocked", "Damage and a technical warning were both reported on return."
|
||||
return (
|
||||
"blocked",
|
||||
"returnBlockedDamageAndTechnical",
|
||||
{},
|
||||
)
|
||||
if body.damage_reported:
|
||||
return "blocked", "Damage was reported on return."
|
||||
return "blocked", "returnBlockedDamage", {}
|
||||
if body.technical_warning:
|
||||
return "blocked", "A technical warning was reported on return."
|
||||
return "blocked", "returnBlockedTechnicalWarning", {}
|
||||
if new_odometer >= vehicle.next_service_km:
|
||||
return (
|
||||
"maintenance",
|
||||
f"Odometer reached the {vehicle.next_service_km:,} km service threshold.",
|
||||
"returnServiceThresholdReached",
|
||||
{"threshold_km": vehicle.next_service_km},
|
||||
)
|
||||
return "cleaning", "No damage, technical warning or service threshold; routed to cleaning."
|
||||
return "cleaning", "returnRoutedToCleaning", {}
|
||||
|
||||
|
||||
_STATUS_REASON_FALLBACK_TEXT: dict[str, str] = {
|
||||
"returnBlockedDamageAndTechnical": (
|
||||
"Damage and a technical warning were both reported on return."
|
||||
),
|
||||
"returnBlockedDamage": "Damage was reported on return.",
|
||||
"returnBlockedTechnicalWarning": "A technical warning was reported on return.",
|
||||
"returnServiceThresholdReached": "Odometer reached the service threshold.",
|
||||
"returnRoutedToCleaning": (
|
||||
"No damage, technical warning or service threshold; routed to cleaning."
|
||||
),
|
||||
}
|
||||
|
||||
|
||||
@dataclass
|
||||
@@ -51,6 +73,8 @@ class ReturnEvaluation:
|
||||
resulting_odometer_km: int
|
||||
resulting_vehicle_status: str
|
||||
status_reason: str
|
||||
status_reason_code: str
|
||||
status_reason_params: dict[str, str | int]
|
||||
would_create_quality_issue: bool
|
||||
attention_reasons: list[str]
|
||||
next_booking_risk: dict | None
|
||||
@@ -64,9 +88,10 @@ def evaluate_return(
|
||||
preview and commit can never drift apart."""
|
||||
odometer_regression = body.end_odometer_km < vehicle.odometer_km
|
||||
resulting_odometer_km = vehicle.odometer_km if odometer_regression else body.end_odometer_km
|
||||
resulting_status, status_reason = _derive_vehicle_status_with_reason(
|
||||
resulting_status, status_reason_code, status_reason_params = _derive_vehicle_status_with_reason(
|
||||
body, vehicle, resulting_odometer_km
|
||||
)
|
||||
status_reason = _STATUS_REASON_FALLBACK_TEXT[status_reason_code]
|
||||
|
||||
attention_reasons = []
|
||||
if body.damage_reported:
|
||||
@@ -101,6 +126,8 @@ def evaluate_return(
|
||||
resulting_odometer_km=resulting_odometer_km,
|
||||
resulting_vehicle_status=resulting_status,
|
||||
status_reason=status_reason,
|
||||
status_reason_code=status_reason_code,
|
||||
status_reason_params=status_reason_params,
|
||||
would_create_quality_issue=odometer_regression,
|
||||
attention_reasons=attention_reasons,
|
||||
next_booking_risk=next_booking_risk,
|
||||
|
||||
@@ -0,0 +1,218 @@
|
||||
"""The single authoritative vehicle-status evaluator.
|
||||
|
||||
Used by the data-quality scanner (detection), the status-recommendation preview
|
||||
endpoint, the apply endpoint, and tests -- so scan-time detection and resolve-time
|
||||
recommendation can never structurally disagree (see docs/fleet-ops-correction/
|
||||
vehicle-status-decision-table.md for the full decision table and rationale).
|
||||
|
||||
The evaluator only ever reasons from real, freshly-queried domain facts (an actually
|
||||
active rental, a real service-threshold breach, a real overlapping-booking conflict) --
|
||||
never from a proxy like "does some other high-severity issue happen to be open". It is
|
||||
therefore also order-independent: resolving, deferring or rejecting an unrelated issue on
|
||||
the same vehicle never changes what this function returns, because it never looks at
|
||||
issue history, only at the vehicle's/bookings' current state.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import hashlib
|
||||
import json
|
||||
import uuid
|
||||
from dataclasses import dataclass, field
|
||||
|
||||
from sqlalchemy import select
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from app.models.booking import Booking
|
||||
from app.models.data_quality import DataQualityIssue
|
||||
from app.models.vehicle import Vehicle
|
||||
|
||||
# Every code below is a stable, localizable identifier -- see
|
||||
# frontend/src/i18n/messageCodes.ts and quality:statusRecommendation.codes.* for the
|
||||
# human-language mapping in all three supported locales. The backend never emits prose.
|
||||
RECOMMENDATION_CODE_ACTIVE_RENTAL = "vehicle.active_rental"
|
||||
RECOMMENDATION_CODE_SERVICE_THRESHOLD = "vehicle.service_threshold_reached"
|
||||
RECOMMENDATION_CODE_BOOKING_CONFLICT = "vehicle.booking_conflict"
|
||||
RECOMMENDATION_CODE_RENTAL_ENDED = "vehicle.rental_ended"
|
||||
RECOMMENDATION_CODE_MANUAL_REVIEW = "vehicle.manual_review_required"
|
||||
RECOMMENDATION_CODE_NO_CONFLICT = "vehicle.no_conflict"
|
||||
|
||||
|
||||
@dataclass
|
||||
class VehicleStatusFacts:
|
||||
active_booking_refs: list[str] = field(default_factory=list)
|
||||
overlapping_booking_pairs: list[tuple[str, str]] = field(default_factory=list)
|
||||
service_threshold_reached: bool = False
|
||||
odometer_km: int = 0
|
||||
next_service_km: int = 0
|
||||
open_booking_overlap_issue_ref: str | None = None
|
||||
|
||||
@property
|
||||
def has_active_rental(self) -> bool:
|
||||
return len(self.active_booking_refs) > 0
|
||||
|
||||
@property
|
||||
def has_booking_conflict(self) -> bool:
|
||||
return (
|
||||
len(self.overlapping_booking_pairs) > 0
|
||||
or self.open_booking_overlap_issue_ref is not None
|
||||
)
|
||||
|
||||
def as_dict(self) -> dict:
|
||||
return {
|
||||
"active_booking_refs": self.active_booking_refs,
|
||||
"overlapping_booking_pairs": [list(pair) for pair in self.overlapping_booking_pairs],
|
||||
"service_threshold_reached": self.service_threshold_reached,
|
||||
"odometer_km": self.odometer_km,
|
||||
"next_service_km": self.next_service_km,
|
||||
"open_booking_overlap_issue_ref": self.open_booking_overlap_issue_ref,
|
||||
}
|
||||
|
||||
|
||||
@dataclass
|
||||
class VehicleStatusRecommendation:
|
||||
current_status: str
|
||||
recommended_status: str | None
|
||||
recommendation_code: str
|
||||
safe_to_apply: bool
|
||||
manual_review_required: bool
|
||||
facts: VehicleStatusFacts
|
||||
blocking_reasons: list[str]
|
||||
|
||||
|
||||
def _overlapping_booking_pairs(bookings: list[Booking]) -> list[tuple[Booking, Booking]]:
|
||||
ordered = sorted(bookings, key=lambda b: b.starts_at)
|
||||
pairs: list[tuple[Booking, Booking]] = []
|
||||
for i, first in enumerate(ordered):
|
||||
for second in ordered[i + 1 :]:
|
||||
if second.starts_at < first.ends_at and first.starts_at < second.ends_at:
|
||||
pairs.append((first, second))
|
||||
return pairs
|
||||
|
||||
|
||||
def gather_vehicle_status_facts(
|
||||
db: Session, vehicle: Vehicle, *, exclude_issue_id: uuid.UUID | None = None
|
||||
) -> VehicleStatusFacts:
|
||||
"""Real, freshly-queried facts only -- see module docstring. Never cached, never
|
||||
derived from another issue's mere existence (only a *specific* booking_overlap
|
||||
issue's presence is used, as a cross-reference to that issue's own public_ref)."""
|
||||
reserved_or_active = list(
|
||||
db.scalars(
|
||||
select(Booking).where(
|
||||
Booking.vehicle_id == vehicle.id,
|
||||
Booking.status.in_(["reserved", "active"]),
|
||||
)
|
||||
).all()
|
||||
)
|
||||
active_refs = [b.public_ref for b in reserved_or_active if b.status == "active"]
|
||||
overlap_pairs = [
|
||||
(a.public_ref, b.public_ref) for a, b in _overlapping_booking_pairs(reserved_or_active)
|
||||
]
|
||||
|
||||
overlap_issue_query = select(DataQualityIssue.public_ref).where(
|
||||
DataQualityIssue.entity_type == "vehicle",
|
||||
DataQualityIssue.entity_id == vehicle.id,
|
||||
DataQualityIssue.status == "open",
|
||||
DataQualityIssue.rule_type == "booking_overlap",
|
||||
)
|
||||
if exclude_issue_id is not None:
|
||||
overlap_issue_query = overlap_issue_query.where(DataQualityIssue.id != exclude_issue_id)
|
||||
open_overlap_ref = db.scalar(overlap_issue_query)
|
||||
|
||||
return VehicleStatusFacts(
|
||||
active_booking_refs=active_refs,
|
||||
overlapping_booking_pairs=overlap_pairs,
|
||||
service_threshold_reached=vehicle.odometer_km >= vehicle.next_service_km,
|
||||
odometer_km=vehicle.odometer_km,
|
||||
next_service_km=vehicle.next_service_km,
|
||||
open_booking_overlap_issue_ref=open_overlap_ref,
|
||||
)
|
||||
|
||||
|
||||
def compute_recommendation_token(vehicle: Vehicle, facts: VehicleStatusFacts) -> str:
|
||||
"""A short digest of exactly the facts the recommendation was based on, plus the
|
||||
vehicle's optimistic-lock version. The apply endpoint recomputes this from fresh
|
||||
facts and rejects the request if it doesn't match the token the client last saw --
|
||||
the frontend must never assume a previously-shown preview is still valid without the
|
||||
server re-checking it (see docs/fleet-ops-correction/current-gap-audit.md §8F)."""
|
||||
payload = {"version": vehicle.version, "status": vehicle.operational_status, **facts.as_dict()}
|
||||
digest = hashlib.sha256(json.dumps(payload, sort_keys=True, default=str).encode()).hexdigest()
|
||||
return digest[:16]
|
||||
|
||||
|
||||
def evaluate_vehicle_status(
|
||||
vehicle: Vehicle, facts: VehicleStatusFacts
|
||||
) -> VehicleStatusRecommendation:
|
||||
"""Pure decision logic over already-gathered facts -- see
|
||||
docs/fleet-ops-correction/vehicle-status-decision-table.md. Never mutates anything,
|
||||
never queries the database itself (call gather_vehicle_status_facts first), so it is
|
||||
trivial to unit-test every branch in isolation."""
|
||||
current = vehicle.operational_status
|
||||
blocking_reasons: list[str] = []
|
||||
if facts.service_threshold_reached:
|
||||
blocking_reasons.append(RECOMMENDATION_CODE_SERVICE_THRESHOLD)
|
||||
if facts.has_booking_conflict:
|
||||
blocking_reasons.append(RECOMMENDATION_CODE_BOOKING_CONFLICT)
|
||||
if current == "maintenance" and RECOMMENDATION_CODE_SERVICE_THRESHOLD not in blocking_reasons:
|
||||
# Already being in maintenance is itself a real blocking fact -- an active
|
||||
# booking never overrides it. This is exactly the forbidden shortcut this
|
||||
# evaluator must never take (maintenance + active booking -> auto "rented").
|
||||
blocking_reasons.append(RECOMMENDATION_CODE_SERVICE_THRESHOLD)
|
||||
|
||||
def result(
|
||||
recommended: str | None, code: str, *, safe: bool, manual: bool
|
||||
) -> VehicleStatusRecommendation:
|
||||
return VehicleStatusRecommendation(
|
||||
current_status=current,
|
||||
recommended_status=recommended,
|
||||
recommendation_code=code,
|
||||
safe_to_apply=safe,
|
||||
manual_review_required=manual,
|
||||
facts=facts,
|
||||
blocking_reasons=blocking_reasons,
|
||||
)
|
||||
|
||||
if facts.has_active_rental and not blocking_reasons:
|
||||
if current == "rented":
|
||||
return result(None, RECOMMENDATION_CODE_NO_CONFLICT, safe=False, manual=False)
|
||||
return result(
|
||||
"rented", RECOMMENDATION_CODE_ACTIVE_RENTAL, safe=True, manual=False
|
||||
)
|
||||
|
||||
if facts.has_active_rental and blocking_reasons:
|
||||
# Explicitly forbidden shortcut this evaluator must never take: an active
|
||||
# booking is not proof the vehicle should be "rented" when a real blocking
|
||||
# condition also exists (e.g. maintenance-due, or a genuine booking conflict).
|
||||
# This is a real contradiction in the underlying facts, not something safe to
|
||||
# resolve automatically.
|
||||
return result(None, RECOMMENDATION_CODE_MANUAL_REVIEW, safe=False, manual=True)
|
||||
|
||||
if facts.service_threshold_reached:
|
||||
if current == "maintenance":
|
||||
return result(None, RECOMMENDATION_CODE_NO_CONFLICT, safe=False, manual=False)
|
||||
return result(
|
||||
"maintenance", RECOMMENDATION_CODE_SERVICE_THRESHOLD, safe=True, manual=False
|
||||
)
|
||||
|
||||
if facts.has_booking_conflict:
|
||||
if current == "blocked":
|
||||
return result(None, RECOMMENDATION_CODE_NO_CONFLICT, safe=False, manual=False)
|
||||
return result(
|
||||
"blocked", RECOMMENDATION_CODE_BOOKING_CONFLICT, safe=True, manual=False
|
||||
)
|
||||
|
||||
# No active rental, no maintenance need, no booking conflict.
|
||||
if current in ("available", "cleaning", "blocked"):
|
||||
return result(None, RECOMMENDATION_CODE_NO_CONFLICT, safe=False, manual=False)
|
||||
if current == "rented":
|
||||
return result(
|
||||
"available", RECOMMENDATION_CODE_RENTAL_ENDED, safe=True, manual=False
|
||||
)
|
||||
if current == "maintenance":
|
||||
# No positive fact confirms maintenance is actually finished (no completed
|
||||
# service record is tracked here) -- clearing "maintenance" without such a
|
||||
# fact would be exactly the kind of unsafe shortcut this evaluator forbids.
|
||||
# Releasing a vehicle from maintenance remains an explicit, manual decision.
|
||||
return result(None, RECOMMENDATION_CODE_NO_CONFLICT, safe=False, manual=False)
|
||||
|
||||
return result(None, RECOMMENDATION_CODE_MANUAL_REVIEW, safe=False, manual=True)
|
||||
@@ -23,6 +23,17 @@ def test_audit_requires_operations_manager(employee_client):
|
||||
assert response.status_code == 403
|
||||
|
||||
|
||||
def test_audit_page_is_bounded_and_exposes_filter_metadata(ops_client):
|
||||
response = ops_client.get("/api/v1/audit", params={"page": 1, "page_size": 25})
|
||||
assert response.status_code == 200
|
||||
body = response.json()
|
||||
assert len(body["items"]) <= 25
|
||||
assert body["page"] == 1
|
||||
assert body["page_size"] == 25
|
||||
assert body["total"] >= len(body["items"])
|
||||
assert body["total_pages"] >= 1
|
||||
|
||||
|
||||
def _activate_booking(vehicle_ref: str, start_odometer_km: int) -> str:
|
||||
db = SessionLocal()
|
||||
try:
|
||||
|
||||
@@ -24,6 +24,22 @@ def test_dashboard_attention_items_link_to_records(ops_client):
|
||||
assert item["severity"] in ("low", "medium", "high")
|
||||
|
||||
|
||||
def test_dashboard_attention_items_expose_localizable_signals_not_raw_text(ops_client):
|
||||
"""The dashboard subtext used to be raw, untranslated evidence text (and for most
|
||||
seeded issues, the meaningless placeholder 'Synthetic deterministic seed issue').
|
||||
The API must never emit prose here -- only stable signal codes + params, exactly
|
||||
like the data-quality issue detail page, for the frontend to localize."""
|
||||
response = ops_client.get("/api/v1/dashboard")
|
||||
body = response.json()
|
||||
assert len(body["attention_items"]) > 0
|
||||
for item in body["attention_items"]:
|
||||
assert "detail" not in item
|
||||
assert len(item["evidence_signals"]) > 0
|
||||
for signal in item["evidence_signals"]:
|
||||
assert signal["code"]
|
||||
assert signal["code"] != "Synthetic deterministic seed issue"
|
||||
|
||||
|
||||
def test_dashboard_recent_automation_capped_at_five(ops_client):
|
||||
response = ops_client.get("/api/v1/dashboard")
|
||||
body = response.json()
|
||||
|
||||
@@ -53,6 +53,18 @@ def test_list_issues_requires_operations_manager(employee_client):
|
||||
assert response.status_code == 403
|
||||
|
||||
|
||||
def test_issue_page_preserves_severity_filter_and_limits_results(ops_client):
|
||||
response = ops_client.get(
|
||||
"/api/v1/data-quality/issues",
|
||||
params={"severity": "high", "page": 1, "page_size": 25},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
body = response.json()
|
||||
assert len(body["items"]) <= 25
|
||||
assert all(issue["severity"] == "high" for issue in body["items"])
|
||||
assert body["total"] >= len(body["items"])
|
||||
|
||||
|
||||
def test_get_issue_requires_operations_manager(employee_client):
|
||||
response = employee_client.get("/api/v1/data-quality/issues/DQ-DEMO-DUPLICATE")
|
||||
assert response.status_code == 403
|
||||
@@ -220,6 +232,21 @@ def test_provide_fields_resolves_a_vehicle_missing_field_issue(ops_client):
|
||||
assert vehicle["registration_number"] == "TST-999"
|
||||
|
||||
|
||||
def test_vehicle_entity_snapshot_includes_registration_number(ops_client):
|
||||
"""The snapshot used to omit registration_number entirely, so the 'provide missing
|
||||
fields' form always showed it blank -- even for a vehicle whose plate was actually
|
||||
on file, and even when a *different* field was the genuinely missing one."""
|
||||
issues = ops_client.get(
|
||||
"/api/v1/data-quality/issues",
|
||||
params={"rule_type": "missing_required_field", "status": "open"},
|
||||
).json()
|
||||
target = next(i for i in issues if i["entity_type"] == "vehicle")
|
||||
vehicle = ops_client.get(f"/api/v1/vehicles/{target['entity_ref']}").json()
|
||||
|
||||
detail = ops_client.get(f"/api/v1/data-quality/issues/{target['public_ref']}").json()
|
||||
assert detail["entity_snapshot"]["registration_number"] == vehicle["registration_number"]
|
||||
|
||||
|
||||
def test_resolve_overlap_requires_operations_manager(employee_client):
|
||||
response = employee_client.post(
|
||||
"/api/v1/data-quality/issues/DQ-DEMO-OVERLAP/resolve-overlap",
|
||||
@@ -249,28 +276,74 @@ def test_resolve_overlap_blocks_one_booking_and_resolves(ops_client):
|
||||
assert booking["status"] == "blocked"
|
||||
|
||||
|
||||
def test_apply_recommended_status_requires_operations_manager(employee_client):
|
||||
def test_status_recommendation_requires_operations_manager(employee_client):
|
||||
response = employee_client.post(
|
||||
"/api/v1/data-quality/issues/DQ-DEMO-STATUS/apply-recommended-status"
|
||||
"/api/v1/data-quality/issues/DQ-DEMO-STATUS/status-recommendation"
|
||||
)
|
||||
assert response.status_code == 403
|
||||
|
||||
|
||||
def test_apply_recommended_status_requires_operations_manager(employee_client):
|
||||
response = employee_client.post(
|
||||
"/api/v1/data-quality/issues/DQ-DEMO-STATUS/apply-recommended-status",
|
||||
json={"recommendation_token": "irrelevant"},
|
||||
)
|
||||
assert response.status_code == 403
|
||||
|
||||
|
||||
def test_status_recommendation_preview_does_not_mutate_anything(ops_client):
|
||||
target = _first_open(ops_client, "vehicle_status_conflict")
|
||||
vehicle_before = ops_client.get(f"/api/v1/vehicles/{target['entity_ref']}").json()
|
||||
|
||||
preview_response = ops_client.post(
|
||||
f"/api/v1/data-quality/issues/{target['public_ref']}/status-recommendation"
|
||||
)
|
||||
assert preview_response.status_code == 200
|
||||
preview = preview_response.json()
|
||||
assert preview["current_status"] == vehicle_before["operational_status"]
|
||||
assert preview["recommendation_token"]
|
||||
assert "facts" in preview
|
||||
|
||||
# Calling preview again (as the UI would on every open) must still not mutate.
|
||||
ops_client.post(f"/api/v1/data-quality/issues/{target['public_ref']}/status-recommendation")
|
||||
issue_after = ops_client.get(f"/api/v1/data-quality/issues/{target['public_ref']}").json()
|
||||
vehicle_after = ops_client.get(f"/api/v1/vehicles/{target['entity_ref']}").json()
|
||||
assert issue_after["status"] == "open"
|
||||
assert vehicle_after["operational_status"] == vehicle_before["operational_status"]
|
||||
|
||||
|
||||
def test_apply_recommended_status_resolves_conflict(ops_client):
|
||||
target = _first_open(ops_client, "vehicle_status_conflict")
|
||||
preview = ops_client.post(
|
||||
f"/api/v1/data-quality/issues/{target['public_ref']}/status-recommendation"
|
||||
).json()
|
||||
assert preview["safe_to_apply"] is True
|
||||
assert preview["manual_review_required"] is False
|
||||
|
||||
response = ops_client.post(
|
||||
f"/api/v1/data-quality/issues/{target['public_ref']}/apply-recommended-status"
|
||||
f"/api/v1/data-quality/issues/{target['public_ref']}/apply-recommended-status",
|
||||
json={"recommendation_token": preview["recommendation_token"]},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
body = response.json()
|
||||
assert body["issue"]["status"] == "resolved"
|
||||
assert body["applied_status"]
|
||||
assert body["reason"]
|
||||
assert body["applied_status"] == preview["recommended_status"]
|
||||
assert body["reason_code"] == preview["recommendation_code"]
|
||||
|
||||
vehicle = ops_client.get(f"/api/v1/vehicles/{target['entity_ref']}").json()
|
||||
assert vehicle["operational_status"] == body["applied_status"]
|
||||
|
||||
|
||||
def test_apply_recommended_status_rejects_stale_token(ops_client):
|
||||
target = _first_open(ops_client, "vehicle_status_conflict")
|
||||
response = ops_client.post(
|
||||
f"/api/v1/data-quality/issues/{target['public_ref']}/apply-recommended-status",
|
||||
json={"recommendation_token": "not-a-real-token"},
|
||||
)
|
||||
assert response.status_code == 409
|
||||
assert response.json()["error"]["code"] == "RECOMMENDATION_STALE"
|
||||
|
||||
|
||||
def test_resolve_odometer_regression_requires_operations_manager(employee_client):
|
||||
response = employee_client.post(
|
||||
"/api/v1/data-quality/issues/DQ-0007/resolve-odometer-regression",
|
||||
@@ -365,6 +438,95 @@ def test_manual_scan_records_audit_event(ops_client):
|
||||
assert "created" in events[0]["metadata"]
|
||||
|
||||
|
||||
def _reset_demo(ops_client) -> None:
|
||||
# /api/v1/demo/reset deletes the session cookie (the reset recreates the users
|
||||
# table, so the old session's user id no longer exists) -- the caller must log back
|
||||
# in before making any further authenticated call with the same client.
|
||||
response = ops_client.post("/api/v1/demo/reset")
|
||||
assert response.status_code == 200, response.text
|
||||
login_response = ops_client.post(
|
||||
"/api/v1/demo/login", json={"role": "operations_manager"}
|
||||
)
|
||||
assert login_response.status_code == 200, login_response.text
|
||||
|
||||
|
||||
def _resolve_overlap_issue(ops_client, *, booking_to_block: str) -> None:
|
||||
overlap = _first_open(ops_client, "booking_overlap")
|
||||
response = ops_client.post(
|
||||
f"/api/v1/data-quality/issues/{overlap['public_ref']}/resolve-overlap",
|
||||
json={"booking_ref": booking_to_block},
|
||||
)
|
||||
assert response.status_code == 200, response.text
|
||||
assert response.json()["status"] == "resolved"
|
||||
|
||||
|
||||
def _first_open_for_vehicle(ops_client, rule_type: str, vehicle_ref: str) -> dict:
|
||||
issues = ops_client.get(
|
||||
"/api/v1/data-quality/issues", params={"rule_type": rule_type, "status": "open"}
|
||||
).json()
|
||||
match = next((i for i in issues if i["entity_ref"] == vehicle_ref), None)
|
||||
assert match, f"expected an open {rule_type} issue for {vehicle_ref}"
|
||||
return match
|
||||
|
||||
|
||||
def _apply_status_recommendation(ops_client, public_ref: str) -> dict:
|
||||
preview = ops_client.post(
|
||||
f"/api/v1/data-quality/issues/{public_ref}/status-recommendation"
|
||||
).json()
|
||||
apply_response = ops_client.post(
|
||||
f"/api/v1/data-quality/issues/{public_ref}/apply-recommended-status",
|
||||
json={"recommendation_token": preview["recommendation_token"]},
|
||||
)
|
||||
assert apply_response.status_code == 200, apply_response.text
|
||||
return apply_response.json()
|
||||
|
||||
|
||||
def test_mo_016_status_conflict_recommendation_is_order_independent(ops_client):
|
||||
# MO-016 carries both a booking_overlap (DQ-DEMO-OVERLAP) and a vehicle_status_conflict
|
||||
# (DQ-DEMO-STATUS) issue at once. Order independence does NOT mean "the same final
|
||||
# vehicle status regardless of order" -- resolving the overlap first genuinely removes
|
||||
# the conflict, so there is correctly nothing left to apply. What must hold in either
|
||||
# order: the recommendation always reflects the real, current facts (never a stale
|
||||
# "was some other issue open" proxy), and nothing unsafe is ever applied (never
|
||||
# "rented", never a status change once the underlying condition has already resolved
|
||||
# itself). See docs/fleet-ops-correction/current-gap-audit.md §6-7 and
|
||||
# vehicle-status-decision-table.md.
|
||||
|
||||
# Order A: resolve the booking overlap first. The status-conflict issue's own
|
||||
# recommendation must now correctly report that the conflict is gone -- nothing unsafe
|
||||
# should be auto-applied, and the vehicle (never touched) stays exactly as it was.
|
||||
_reset_demo(ops_client)
|
||||
_resolve_overlap_issue(ops_client, booking_to_block="BK-DEMO-OVERLAP-B")
|
||||
status_issue_a = _first_open_for_vehicle(ops_client, "vehicle_status_conflict", "MO-016")
|
||||
preview_a = ops_client.post(
|
||||
f"/api/v1/data-quality/issues/{status_issue_a['public_ref']}/status-recommendation"
|
||||
).json()
|
||||
assert preview_a["recommendation_code"] == "vehicle.no_conflict"
|
||||
assert preview_a["recommended_status"] is None
|
||||
assert preview_a["safe_to_apply"] is False
|
||||
vehicle_a = ops_client.get("/api/v1/vehicles/MO-016").json()
|
||||
assert vehicle_a["operational_status"] == "available"
|
||||
|
||||
# Order B: resolve the status conflict first, while the overlap is still open -- the
|
||||
# conflict genuinely still exists, so the evaluator must still detect it and safely
|
||||
# resolve it (never "rented").
|
||||
_reset_demo(ops_client)
|
||||
status_issue_b = _first_open_for_vehicle(ops_client, "vehicle_status_conflict", "MO-016")
|
||||
result_b = _apply_status_recommendation(ops_client, status_issue_b["public_ref"])
|
||||
assert result_b["applied_status"] != "rented"
|
||||
vehicle_b_mid = ops_client.get("/api/v1/vehicles/MO-016").json()
|
||||
assert vehicle_b_mid["operational_status"] == result_b["applied_status"]
|
||||
|
||||
# Resolving the now-redundant overlap afterwards must not itself change the vehicle's
|
||||
# status as a side effect.
|
||||
_resolve_overlap_issue(ops_client, booking_to_block="BK-DEMO-OVERLAP-B")
|
||||
vehicle_b = ops_client.get("/api/v1/vehicles/MO-016").json()
|
||||
assert vehicle_b["operational_status"] == result_b["applied_status"]
|
||||
assert vehicle_b["operational_status"] != "rented"
|
||||
|
||||
_reset_demo(ops_client)
|
||||
|
||||
|
||||
def test_rejected_issue_recurrence_links_to_prior_decision(ops_client):
|
||||
# Reject an open vehicle_status_conflict issue without changing the vehicle, so the
|
||||
# next scan re-detects the same unresolved condition -- it must not silently vanish
|
||||
|
||||
@@ -67,7 +67,7 @@ def test_deliver_one_success(monkeypatch):
|
||||
event_id = _make_pending_event("MO-002")
|
||||
dispatcher._claim_due_events()
|
||||
|
||||
def fake_post(url, json, timeout):
|
||||
def fake_post(url, json, headers, timeout):
|
||||
return SimpleNamespace(
|
||||
raise_for_status=lambda: None,
|
||||
json=lambda: {"ok": True, "event_id": str(event_id), "result": {}},
|
||||
@@ -81,13 +81,14 @@ def test_deliver_one_success(monkeypatch):
|
||||
assert event.attempts == 1
|
||||
assert event.external_run_id == str(event_id)
|
||||
assert event.last_error is None
|
||||
assert event.last_error_code is None
|
||||
|
||||
|
||||
def test_deliver_one_failure_schedules_retry(monkeypatch):
|
||||
event_id = _make_pending_event("MO-003")
|
||||
dispatcher._claim_due_events()
|
||||
|
||||
def fake_post(url, json, timeout):
|
||||
def fake_post(url, json, headers, timeout):
|
||||
raise dispatcher.httpx.ConnectError("simulated connection failure")
|
||||
|
||||
monkeypatch.setattr(dispatcher.httpx, "post", fake_post)
|
||||
@@ -98,13 +99,41 @@ def test_deliver_one_failure_schedules_retry(monkeypatch):
|
||||
assert event.attempts == 1
|
||||
assert event.next_attempt_at is not None
|
||||
assert "simulated connection failure" in event.last_error
|
||||
assert event.last_error_code == "connectionError"
|
||||
|
||||
|
||||
def test_deliver_one_treats_empty_2xx_body_as_failure(monkeypatch):
|
||||
# Reproduces a real failure mode found while live-validating the n8n webhook auth
|
||||
# fix: a workflow that errors internally before its "Respond to Webhook" node runs
|
||||
# can still answer with a 2xx status and an empty body. response.json() on that body
|
||||
# raises json.JSONDecodeError -- this must be treated as a retryable failure, not an
|
||||
# unhandled exception that leaves the event stuck in "delivering" forever.
|
||||
event_id = _make_pending_event("MO-005")
|
||||
dispatcher._claim_due_events()
|
||||
|
||||
def fake_post(url, json, headers, timeout):
|
||||
def raise_json_error():
|
||||
raise ValueError("Expecting value: line 1 column 1 (char 0)")
|
||||
|
||||
return SimpleNamespace(
|
||||
raise_for_status=lambda: None, json=raise_json_error, status_code=200
|
||||
)
|
||||
|
||||
monkeypatch.setattr(dispatcher.httpx, "post", fake_post)
|
||||
dispatcher._deliver_one(event_id)
|
||||
|
||||
event = _get_event(event_id)
|
||||
assert event.delivery_status == "pending"
|
||||
assert event.attempts == 1
|
||||
assert event.next_attempt_at is not None
|
||||
assert event.last_error_code == "malformedResponse"
|
||||
|
||||
|
||||
def test_deliver_one_exhausts_attempts_to_failed(monkeypatch):
|
||||
event_id = _make_pending_event("MO-004")
|
||||
settings = get_settings()
|
||||
|
||||
def fake_post(url, json, timeout):
|
||||
def fake_post(url, json, headers, timeout):
|
||||
raise dispatcher.httpx.ConnectError("still down")
|
||||
|
||||
monkeypatch.setattr(dispatcher.httpx, "post", fake_post)
|
||||
@@ -147,7 +176,7 @@ def test_deliver_one_handles_malformed_payload_without_getting_stuck(monkeypatch
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
def fake_post(url, json, timeout):
|
||||
def fake_post(url, json, headers, timeout):
|
||||
raise AssertionError("must not attempt delivery with a malformed payload")
|
||||
|
||||
monkeypatch.setattr(dispatcher.httpx, "post", fake_post)
|
||||
@@ -159,6 +188,7 @@ def test_deliver_one_handles_malformed_payload_without_getting_stuck(monkeypatch
|
||||
assert event.delivery_status in ("pending", "failed")
|
||||
assert event.attempts == 1
|
||||
assert "Malformed outbox payload" in event.last_error
|
||||
assert event.last_error_code == "malformedPayload"
|
||||
|
||||
|
||||
def test_claim_sets_a_lease_deadline():
|
||||
@@ -208,6 +238,7 @@ def test_reclaim_recovers_an_expired_lease_and_preserves_attempts(monkeypatch):
|
||||
assert event.next_attempt_at is None
|
||||
assert event.attempts == 2
|
||||
assert "stale" in event.last_error.lower()
|
||||
assert event.last_error_code == "staleLeaseRecovered"
|
||||
|
||||
# The reclaimed event is now a normal pending event, immediately claimable again.
|
||||
claimed = dispatcher._claim_due_events()
|
||||
@@ -225,7 +256,7 @@ def test_run_dispatch_cycle_recovers_a_stale_lease_before_claiming(monkeypatch):
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
def fake_post(url, json, timeout):
|
||||
def fake_post(url, json, headers, timeout):
|
||||
return SimpleNamespace(
|
||||
raise_for_status=lambda: None,
|
||||
json=lambda: {"ok": True, "event_id": str(event_id), "result": {}},
|
||||
@@ -241,7 +272,7 @@ def test_run_dispatch_cycle_recovers_a_stale_lease_before_claiming(monkeypatch):
|
||||
def test_run_dispatch_cycle_end_to_end(monkeypatch):
|
||||
event_id = _make_pending_event("MO-005")
|
||||
|
||||
def fake_post(url, json, timeout):
|
||||
def fake_post(url, json, headers, timeout):
|
||||
return SimpleNamespace(
|
||||
raise_for_status=lambda: None,
|
||||
json=lambda: {"ok": True, "event_id": str(event_id), "result": {}},
|
||||
|
||||
@@ -1,3 +1,24 @@
|
||||
from sqlalchemy import select
|
||||
|
||||
from app.core.db import SessionLocal
|
||||
from app.models.outbox import OutboxEvent
|
||||
from app.seed_loader import reset_and_seed
|
||||
|
||||
|
||||
def _reseed() -> None:
|
||||
"""Restore the canonical demo dataset (19 succeeded + 1 prepared failure).
|
||||
|
||||
The suite shares one session-scoped database and earlier files legitimately mutate
|
||||
the outbox, so any test that asserts on the *seeded* scenario has to re-establish it
|
||||
rather than depend on file ordering.
|
||||
"""
|
||||
db = SessionLocal()
|
||||
try:
|
||||
reset_and_seed(db)
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_integration_status_requires_operations_manager(employee_client):
|
||||
response = employee_client.get("/api/v1/integrations/status")
|
||||
assert response.status_code == 403
|
||||
@@ -9,6 +30,7 @@ def test_integration_status_requires_authentication(client):
|
||||
|
||||
|
||||
def test_integration_status_reflects_seeded_mixed_outcomes(ops_client):
|
||||
_reseed()
|
||||
response = ops_client.get("/api/v1/integrations/status")
|
||||
assert response.status_code == 200
|
||||
body = response.json()
|
||||
@@ -16,20 +38,65 @@ def test_integration_status_reflects_seeded_mixed_outcomes(ops_client):
|
||||
n8n = body["n8n"]
|
||||
assert n8n["dispatch_enabled"] is True
|
||||
assert n8n["succeeded"] >= 1
|
||||
# The seeded failure stays visible and counted...
|
||||
assert n8n["failed"] >= 1
|
||||
# The seed deliberately carries both failed and succeeded events, so a single most-
|
||||
# recent-event read would misreport health -- the aggregate must call this "degraded",
|
||||
# not "operational" or "unavailable".
|
||||
assert n8n["state"] == "degraded"
|
||||
assert n8n["demo_scenario_failed"] == 1
|
||||
# ...but it is a prepared prop, so it is not an unexpected failure and must not
|
||||
# move the integration off "operational". A staged failure that degrades the
|
||||
# health badge tells a viewer something untrue about the automation.
|
||||
assert n8n["unexpected_failed"] == 0
|
||||
assert n8n["state"] == "operational"
|
||||
assert n8n["latest_success_at"] is not None
|
||||
assert n8n["latest_failure_at"] is not None
|
||||
# "latest failure" is a health signal, so the staged one never sets it; it is
|
||||
# reported separately instead.
|
||||
assert n8n["latest_failure_at"] is None
|
||||
assert n8n["latest_demo_scenario_at"] is not None
|
||||
|
||||
mcp_hub = body["mcp_hub"]
|
||||
assert mcp_hub["registration_enabled"] is False
|
||||
assert mcp_hub["state"] == "not_configured"
|
||||
|
||||
|
||||
def test_a_real_failure_still_degrades_the_integration(ops_client):
|
||||
"""The demo carve-out must be narrow: a failure that is not the prepared scenario
|
||||
still degrades n8n, otherwise this change would hide real breakage."""
|
||||
_reseed()
|
||||
db = SessionLocal()
|
||||
try:
|
||||
real_failure = db.scalar(
|
||||
select(OutboxEvent).where(OutboxEvent.delivery_status == "succeeded").limit(1)
|
||||
)
|
||||
assert real_failure is not None
|
||||
restore = (real_failure.delivery_status, real_failure.last_error_code)
|
||||
real_failure.delivery_status = "failed"
|
||||
real_failure.last_error_code = "connectionError"
|
||||
db.commit()
|
||||
|
||||
n8n = ops_client.get("/api/v1/integrations/status").json()["n8n"]
|
||||
assert n8n["unexpected_failed"] == 1
|
||||
assert n8n["state"] == "degraded"
|
||||
assert n8n["latest_failure_at"] is not None
|
||||
finally:
|
||||
real_failure.delivery_status, real_failure.last_error_code = restore
|
||||
db.commit()
|
||||
db.close()
|
||||
|
||||
|
||||
def test_prepared_demo_failure_is_reset_back_by_a_demo_reset(ops_client):
|
||||
"""A demo reset must recreate the intended 19 succeeded + 1 prepared failure, so the
|
||||
scenario can be shown again after it has been retried away."""
|
||||
_reseed()
|
||||
|
||||
n8n = ops_client.get("/api/v1/integrations/status").json()["n8n"]
|
||||
assert n8n["succeeded"] == 19
|
||||
assert n8n["failed"] == 1
|
||||
assert n8n["demo_scenario_failed"] == 1
|
||||
assert n8n["unexpected_failed"] == 0
|
||||
assert n8n["state"] == "operational"
|
||||
|
||||
|
||||
def test_integration_status_is_operational_once_all_failed_events_resolved(ops_client):
|
||||
_reseed()
|
||||
failed = ops_client.get("/api/v1/workflows", params={"status": "failed"}).json()
|
||||
for run in failed:
|
||||
retried = ops_client.post(f"/api/v1/workflows/{run['event_id']}/retry")
|
||||
@@ -39,3 +106,85 @@ def test_integration_status_is_operational_once_all_failed_events_resolved(ops_c
|
||||
body = response.json()["n8n"]
|
||||
assert body["failed"] == 0
|
||||
assert body["state"] == "operational"
|
||||
|
||||
|
||||
def test_integration_status_lists_all_four_canonical_workflows(ops_client):
|
||||
body = ops_client.get("/api/v1/integrations/status").json()["n8n"]
|
||||
assert body["expected_workflow_count"] == 4
|
||||
names = {w["name"] for w in body["workflows"]}
|
||||
assert names == {
|
||||
"Fleet Ops — Vehicle Return Orchestration",
|
||||
"Fleet Ops — Scheduled Data Quality Scan",
|
||||
"Fleet Ops — RAGcore Procedure Sync",
|
||||
"Fleet Ops — Workflow Error Handler",
|
||||
}
|
||||
ragcore_sync = next(w for w in body["workflows"] if "RAGcore" in w["name"])
|
||||
# All 4 canonical workflows are built (all 6 nodes saved live). This fresh test run
|
||||
# has reported no real sync result yet, so -- like the other three workflows before
|
||||
# their own first real signal -- there is no run evidence yet either.
|
||||
assert ragcore_sync["built"] is True
|
||||
assert ragcore_sync["last_seen_at"] is None
|
||||
|
||||
|
||||
def test_integration_status_scheduled_scan_evidence_only_counts_service_runs(client, ops_client):
|
||||
from app.core.config import get_settings
|
||||
|
||||
settings = get_settings()
|
||||
|
||||
before = ops_client.get("/api/v1/integrations/status").json()["n8n"]
|
||||
scan_workflow = next(
|
||||
w for w in before["workflows"] if w["name"].endswith("Scheduled Data Quality Scan")
|
||||
)
|
||||
assert scan_workflow["last_seen_at"] is None
|
||||
|
||||
scan = client.post(
|
||||
"/api/v1/integrations/n8n/scheduled-scan",
|
||||
headers={"X-Service-Token": settings.n8n_callback_token},
|
||||
)
|
||||
assert scan.status_code == 200
|
||||
|
||||
after = ops_client.get("/api/v1/integrations/status").json()["n8n"]
|
||||
scan_workflow = next(
|
||||
w for w in after["workflows"] if w["name"].endswith("Scheduled Data Quality Scan")
|
||||
)
|
||||
assert scan_workflow["last_seen_at"] is not None
|
||||
assert after["known_workflow_count"] > before["known_workflow_count"]
|
||||
|
||||
|
||||
def test_integration_status_reflects_error_handler_registrations(client, ops_client):
|
||||
import uuid
|
||||
|
||||
from app.core.config import get_settings
|
||||
|
||||
settings = get_settings()
|
||||
before = ops_client.get("/api/v1/integrations/status").json()["n8n"]
|
||||
|
||||
execution_id = str(uuid.uuid4())
|
||||
report = client.post(
|
||||
"/api/v1/integrations/n8n/workflow-error",
|
||||
json={
|
||||
"workflow_id": "mobilityops-return-processing",
|
||||
"workflow_name": "Fleet Ops — Vehicle Return Orchestration",
|
||||
"execution_id": execution_id,
|
||||
"failed_at": "2026-08-04T10:15:00Z",
|
||||
"error_category": "httpError",
|
||||
"error_summary": "Simulated failure for status test",
|
||||
"trigger_context": "webhook",
|
||||
"attempt": 1,
|
||||
},
|
||||
headers={"X-Service-Token": settings.n8n_callback_token},
|
||||
)
|
||||
assert report.status_code == 200
|
||||
|
||||
after = ops_client.get("/api/v1/integrations/status").json()["n8n"]
|
||||
assert (
|
||||
after["error_handler"]["total_failures_registered"]
|
||||
== before["error_handler"]["total_failures_registered"] + 1
|
||||
)
|
||||
assert after["error_handler"]["latest_failure_workflow"] == (
|
||||
"Fleet Ops — Vehicle Return Orchestration"
|
||||
)
|
||||
handler_workflow = next(
|
||||
w for w in after["workflows"] if w["name"].endswith("Workflow Error Handler")
|
||||
)
|
||||
assert handler_workflow["last_seen_at"] is not None
|
||||
|
||||
@@ -122,3 +122,145 @@ def test_scheduled_scan_is_idempotent_across_repeated_triggers(client):
|
||||
assert first.status_code == 200
|
||||
assert second.status_code == 200
|
||||
assert second.json()["created"] == {}
|
||||
|
||||
|
||||
def _workflow_error_body(execution_id: str, **overrides):
|
||||
body = {
|
||||
"workflow_id": "mobilityops-return-processing",
|
||||
"workflow_name": "Fleet Ops — Vehicle Return Orchestration",
|
||||
"execution_id": execution_id,
|
||||
"failed_at": "2026-08-04T10:15:00Z",
|
||||
"error_category": "httpError",
|
||||
"error_summary": "Callback request failed with status 500",
|
||||
"trigger_context": "webhook",
|
||||
"correlation_id": None,
|
||||
"attempt": 1,
|
||||
"retry_action": "n8n will retry automatically",
|
||||
}
|
||||
body.update(overrides)
|
||||
return body
|
||||
|
||||
|
||||
def test_workflow_error_rejects_wrong_service_token(client):
|
||||
response = client.post(
|
||||
"/api/v1/integrations/n8n/workflow-error",
|
||||
json=_workflow_error_body(str(uuid.uuid4())),
|
||||
headers={"X-Service-Token": "wrong-token"},
|
||||
)
|
||||
assert response.status_code == 401
|
||||
|
||||
|
||||
def test_workflow_error_rejects_unknown_category(client):
|
||||
settings = get_settings()
|
||||
response = client.post(
|
||||
"/api/v1/integrations/n8n/workflow-error",
|
||||
json=_workflow_error_body(str(uuid.uuid4()), error_category="somethingElse"),
|
||||
headers={"X-Service-Token": settings.n8n_callback_token},
|
||||
)
|
||||
assert response.status_code == 422
|
||||
|
||||
|
||||
def test_workflow_error_registers_and_is_idempotent_by_execution_id(client, ops_client):
|
||||
settings = get_settings()
|
||||
headers = {"X-Service-Token": settings.n8n_callback_token}
|
||||
execution_id = str(uuid.uuid4())
|
||||
body = _workflow_error_body(execution_id)
|
||||
|
||||
first = client.post("/api/v1/integrations/n8n/workflow-error", json=body, headers=headers)
|
||||
second = client.post("/api/v1/integrations/n8n/workflow-error", json=body, headers=headers)
|
||||
|
||||
assert first.status_code == 200
|
||||
assert first.json()["status"] == "registered"
|
||||
assert second.status_code == 200
|
||||
assert second.json()["status"] == "already_registered"
|
||||
|
||||
audit_events = ops_client.get(
|
||||
"/api/v1/audit", params={"action": "n8n_workflow_failure_registered"}
|
||||
).json()
|
||||
matching = [e for e in audit_events if e["metadata"]["execution_id"] == execution_id]
|
||||
assert len(matching) == 1
|
||||
assert matching[0]["after"]["error_category"] == "httpError"
|
||||
assert matching[0]["after"]["retry_action"] == "n8n will retry automatically"
|
||||
|
||||
|
||||
def test_workflow_error_bounds_summary_length(client):
|
||||
settings = get_settings()
|
||||
response = client.post(
|
||||
"/api/v1/integrations/n8n/workflow-error",
|
||||
json=_workflow_error_body(str(uuid.uuid4()), error_summary="x" * 501),
|
||||
headers={"X-Service-Token": settings.n8n_callback_token},
|
||||
)
|
||||
assert response.status_code == 422
|
||||
|
||||
|
||||
def test_procedures_rejects_wrong_service_token(client):
|
||||
response = client.get(
|
||||
"/api/v1/integrations/n8n/procedures", headers={"X-Service-Token": "wrong-token"}
|
||||
)
|
||||
assert response.status_code == 401
|
||||
|
||||
|
||||
def test_procedures_lists_every_language_with_stable_ids(client):
|
||||
settings = get_settings()
|
||||
response = client.get(
|
||||
"/api/v1/integrations/n8n/procedures",
|
||||
headers={"X-Service-Token": settings.n8n_callback_token},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
documents = response.json()["documents"]
|
||||
assert len(documents) > 0
|
||||
assert {d["language"] for d in documents} == {"en-GB", "nl-BE", "fr-BE"}
|
||||
checkout_docs = [d for d in documents if d["document_id"] == "vehicle-checkout-procedure"]
|
||||
assert len(checkout_docs) == 3 # one per language
|
||||
assert all(d["content"] and d["content_hash"] for d in checkout_docs)
|
||||
# Same document_id, different language, must not collide on id.
|
||||
assert len({d["id"] for d in checkout_docs}) == 3
|
||||
|
||||
second_response = client.get(
|
||||
"/api/v1/integrations/n8n/procedures",
|
||||
headers={"X-Service-Token": settings.n8n_callback_token},
|
||||
)
|
||||
second_ids = {d["id"] for d in second_response.json()["documents"]}
|
||||
assert second_ids == {d["id"] for d in documents} # ids are stable across requests
|
||||
|
||||
|
||||
def test_procedures_sync_result_rejects_wrong_service_token(client):
|
||||
response = client.post(
|
||||
"/api/v1/integrations/n8n/procedures-sync-result",
|
||||
json={"execution_id": str(uuid.uuid4()), "synced": 5, "failed": 0},
|
||||
headers={"X-Service-Token": "wrong-token"},
|
||||
)
|
||||
assert response.status_code == 401
|
||||
|
||||
|
||||
def test_procedures_sync_result_registers_and_is_idempotent(client, ops_client):
|
||||
settings = get_settings()
|
||||
headers = {"X-Service-Token": settings.n8n_callback_token}
|
||||
execution_id = str(uuid.uuid4())
|
||||
body = {"execution_id": execution_id, "synced": 33, "failed": 1}
|
||||
|
||||
first = client.post(
|
||||
"/api/v1/integrations/n8n/procedures-sync-result", json=body, headers=headers
|
||||
)
|
||||
second = client.post(
|
||||
"/api/v1/integrations/n8n/procedures-sync-result", json=body, headers=headers
|
||||
)
|
||||
|
||||
assert first.status_code == 200
|
||||
assert first.json()["status"] == "registered"
|
||||
assert second.status_code == 200
|
||||
assert second.json()["status"] == "already_registered"
|
||||
|
||||
audit_events = ops_client.get(
|
||||
"/api/v1/audit", params={"action": "n8n_procedures_synced"}
|
||||
).json()
|
||||
matching = [e for e in audit_events if e["metadata"]["execution_id"] == execution_id]
|
||||
assert len(matching) == 1
|
||||
assert matching[0]["after"] == {"synced": 33, "failed": 1}
|
||||
|
||||
# The workflow's own callback is its evidence -- same pattern the scheduled scan and
|
||||
# error handler already use -- so this real report must now show up as run evidence
|
||||
# in the integration status, not stay hardcoded to "no evidence yet".
|
||||
status = ops_client.get("/api/v1/integrations/status").json()["n8n"]
|
||||
ragcore_sync = next(w for w in status["workflows"] if "RAGcore" in w["name"])
|
||||
assert ragcore_sync["last_seen_at"] is not None
|
||||
|
||||
@@ -1,11 +1,51 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import re
|
||||
from pathlib import Path
|
||||
|
||||
import httpx
|
||||
|
||||
from app.core.config import get_settings
|
||||
from app.services.knowledge.demo import DemoKnowledgeProvider
|
||||
from app.services.knowledge.ragcore import RAGcoreKnowledgeProvider
|
||||
|
||||
|
||||
def test_brief_exact_damage_question_in_all_three_languages():
|
||||
# The exact validation questions from docs/fleet-ops-correction/current-gap-audit.md
|
||||
# -- each must ground on the damage procedure as its *primary* (top-ranked) source,
|
||||
# not merely appear somewhere in the top-3, and the source/version/section/excerpt
|
||||
# must all come from that same-language document (never an English fallback).
|
||||
provider = DemoKnowledgeProvider()
|
||||
cases = {
|
||||
"nl-BE": "Wat moet ik doen wanneer een voertuig beschadigd terugkomt?",
|
||||
"en-GB": "What should I do when a vehicle returns with damage?",
|
||||
"fr-BE": "Que dois-je faire lorsqu'un véhicule revient endommagé ?",
|
||||
}
|
||||
for language, question in cases.items():
|
||||
answer = provider.ask(question, f"test-brief-{language}", language)
|
||||
assert answer.evidence_state == "grounded", language
|
||||
assert answer.sources, language
|
||||
assert answer.sources[0].document_id == "damage-procedure", (
|
||||
f"{language}: expected the damage procedure as the primary source, "
|
||||
f"got {answer.sources[0].document_id!r}"
|
||||
)
|
||||
assert answer.answer
|
||||
assert answer.sources[0].excerpt
|
||||
|
||||
|
||||
def test_knowledge_procedures_never_mention_mobilityops_or_poc():
|
||||
# Section 2 of docs/fleet-ops-correction/current-gap-audit.md: the visible brand
|
||||
# name is exactly "Fleet Ops", and "PoC" must never appear in visible content --
|
||||
# including the demo knowledge base, not just the frontend.
|
||||
procedures_dir = Path(get_settings().knowledge_dir)
|
||||
offenders = []
|
||||
for path in sorted(procedures_dir.glob("*/*.md")):
|
||||
text = path.read_text(encoding="utf-8")
|
||||
if "MobilityOps" in text or re.search(r"\bPoC\b", text):
|
||||
offenders.append(str(path))
|
||||
assert offenders == []
|
||||
|
||||
|
||||
def test_s6_damage_question_is_grounded_with_expected_sources():
|
||||
provider = DemoKnowledgeProvider()
|
||||
answer = provider.ask(
|
||||
@@ -118,12 +158,295 @@ def test_knowledge_status_endpoint(ops_client):
|
||||
assert response.json()["provider"] == "demo"
|
||||
|
||||
|
||||
def test_ragcore_provider_degrades_to_unavailable(monkeypatch):
|
||||
def fake_client(*args, **kwargs):
|
||||
raise httpx.ConnectError("no ragcore in this environment")
|
||||
class _FakeResponse:
|
||||
def __init__(self, status_code: int, body: dict):
|
||||
self.status_code = status_code
|
||||
self._body = body
|
||||
|
||||
def json(self) -> dict:
|
||||
return self._body
|
||||
|
||||
|
||||
class _FakeClient:
|
||||
def __init__(self, get_response=None, post_response=None, post_responses=None, raise_on=None):
|
||||
self._get_response = get_response
|
||||
self._post_response = post_response
|
||||
# Maps a path (e.g. "/v1/search") to its own response, for tests that need
|
||||
# /v1/answers and /v1/search to behave differently in the same call. Falls back
|
||||
# to the single post_response when a path has no specific entry, so every
|
||||
# existing single-endpoint test keeps working unchanged.
|
||||
self._post_responses = post_responses or {}
|
||||
self._raise_on = raise_on
|
||||
|
||||
def __enter__(self):
|
||||
return self
|
||||
|
||||
def __exit__(self, *args):
|
||||
return False
|
||||
|
||||
def get(self, path):
|
||||
if self._raise_on == "get":
|
||||
raise httpx.ConnectError("no ragcore in this environment")
|
||||
return self._get_response
|
||||
|
||||
def post(self, path, json=None):
|
||||
if self._raise_on == "post":
|
||||
raise httpx.ConnectError("no ragcore in this environment")
|
||||
return self._post_responses.get(path, self._post_response)
|
||||
|
||||
|
||||
def test_ragcore_provider_degrades_to_unavailable(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider, "_client", fake_client)
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
monkeypatch.setattr(provider, "_client", lambda: _FakeClient(raise_on="post"))
|
||||
answer = provider.ask("Anything?", "test-correlation-3")
|
||||
assert answer.evidence_state == "unavailable"
|
||||
assert answer.sources == []
|
||||
|
||||
|
||||
def test_ragcore_provider_without_configured_space_is_unavailable_without_a_network_call(
|
||||
monkeypatch,
|
||||
):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "")
|
||||
|
||||
def fail_if_called():
|
||||
raise AssertionError("should not call RAGcore without a configured space id")
|
||||
|
||||
monkeypatch.setattr(provider, "_client", fail_if_called)
|
||||
answer = provider.ask("Anything?", "test-correlation-no-space")
|
||||
assert answer.evidence_state == "unavailable"
|
||||
|
||||
|
||||
def test_ragcore_provider_health_reports_ready_status(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(get_response=_FakeResponse(200, {"status": "ok"})),
|
||||
)
|
||||
health = provider.health()
|
||||
assert health.provider == "ragcore"
|
||||
assert health.available is True
|
||||
|
||||
|
||||
def test_ragcore_provider_health_reports_degraded_status(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(get_response=_FakeResponse(200, {"status": "degraded"})),
|
||||
)
|
||||
health = provider.health()
|
||||
assert health.available is False
|
||||
|
||||
|
||||
def test_ragcore_provider_health_degrades_on_connection_error(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider, "_client", lambda: _FakeClient(raise_on="get"))
|
||||
health = provider.health()
|
||||
assert health.available is False
|
||||
assert "unavailable" in health.detail.lower()
|
||||
|
||||
|
||||
def _answers_body(**overrides) -> dict:
|
||||
body = {
|
||||
"answer": "Report damage and route the vehicle to maintenance.",
|
||||
"answerability": "answerable",
|
||||
"citations": [
|
||||
{
|
||||
"id": "cite-1",
|
||||
"document_id": "doc-1",
|
||||
"document_version_id": "version-1",
|
||||
"title": "Damage handling procedure",
|
||||
"section": "Detection",
|
||||
"excerpt": "Inspect the vehicle for visible damage.",
|
||||
}
|
||||
],
|
||||
}
|
||||
body.update(overrides)
|
||||
return body
|
||||
|
||||
|
||||
def test_ragcore_provider_grounded_answer_maps_citations_to_sources(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(post_response=_FakeResponse(200, _answers_body())),
|
||||
)
|
||||
answer = provider.ask("What must I do about damage?", "test-correlation-grounded")
|
||||
assert answer.evidence_state == "grounded"
|
||||
assert answer.answer
|
||||
assert len(answer.sources) == 1
|
||||
source = answer.sources[0]
|
||||
assert source.document_id == "doc-1"
|
||||
assert source.title == "Damage handling procedure"
|
||||
assert source.version == "version-1"
|
||||
assert source.section == "Detection"
|
||||
assert source.excerpt
|
||||
|
||||
|
||||
def test_ragcore_provider_not_answerable_is_insufficient_and_never_fabricates(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(
|
||||
post_response=_FakeResponse(
|
||||
200,
|
||||
_answers_body(
|
||||
answer="This should never be shown.",
|
||||
answerability="not_answerable",
|
||||
citations=[],
|
||||
),
|
||||
)
|
||||
),
|
||||
)
|
||||
answer = provider.ask("Unrelated question?", "test-correlation-insufficient")
|
||||
assert answer.evidence_state == "insufficient"
|
||||
assert answer.answer == ""
|
||||
assert answer.sources == []
|
||||
|
||||
|
||||
def test_ragcore_provider_answerable_without_citations_is_insufficient(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(
|
||||
post_response=_FakeResponse(
|
||||
200, _answers_body(answerability="answerable", citations=[])
|
||||
)
|
||||
),
|
||||
)
|
||||
answer = provider.ask("What must I do about damage?", "test-correlation-no-citations")
|
||||
assert answer.evidence_state == "insufficient"
|
||||
assert answer.sources == []
|
||||
|
||||
|
||||
def test_ragcore_provider_non_200_response_is_unavailable(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(post_response=_FakeResponse(401, {"code": "AUTHENTICATION_REQUIRED"})),
|
||||
)
|
||||
answer = provider.ask("Anything?", "test-correlation-401")
|
||||
assert answer.evidence_state == "unavailable"
|
||||
|
||||
|
||||
def test_ragcore_provider_malformed_response_is_unavailable(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
# A malformed /v1/answers body triggers the same search fallback a real outage
|
||||
# would, so the fallback's own /v1/search response must also be malformed here to
|
||||
# exercise "the whole backend is misbehaving, not just one endpoint" honestly.
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(
|
||||
post_responses={
|
||||
"/v1/answers": _FakeResponse(200, {"citations": "not-a-list"}),
|
||||
"/v1/search": _FakeResponse(200, {"results": "not-a-list"}),
|
||||
}
|
||||
),
|
||||
)
|
||||
answer = provider.ask("Anything?", "test-correlation-malformed")
|
||||
assert answer.evidence_state == "unavailable"
|
||||
|
||||
|
||||
def _search_body(**overrides) -> dict:
|
||||
body = {
|
||||
"results": [
|
||||
{
|
||||
"chunk_id": "chunk-1",
|
||||
"citation": {
|
||||
"id": "cite-1",
|
||||
"document_id": "doc-1",
|
||||
"document_version_id": "version-1",
|
||||
"title": "Vehicle return procedure",
|
||||
"section": "Return",
|
||||
"excerpt": "Register the return odometer reading before releasing the vehicle.",
|
||||
},
|
||||
"rank": 1,
|
||||
"scores": {"dense": None, "sparse": None, "fused": 0.5, "rerank": None},
|
||||
}
|
||||
],
|
||||
"degraded": False,
|
||||
}
|
||||
body.update(overrides)
|
||||
return body
|
||||
|
||||
|
||||
def test_ragcore_provider_falls_back_to_search_when_answers_unavailable(monkeypatch):
|
||||
"""/v1/answers itself failing (a real RAGcore-side outage in its generation step,
|
||||
not a real 'insufficient evidence' classification) must not silently degrade
|
||||
straight to 'unavailable' when RAGcore's own retrieval still works -- it should show
|
||||
the real, cited excerpt search actually found instead."""
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(
|
||||
post_responses={
|
||||
"/v1/answers": _FakeResponse(503, {"code": "VALIDATION_RETRIES_EXHAUSTED"}),
|
||||
"/v1/search": _FakeResponse(200, _search_body()),
|
||||
}
|
||||
),
|
||||
)
|
||||
answer = provider.ask("What is the vehicle return procedure?", "test-correlation-fallback")
|
||||
assert answer.evidence_state == "grounded"
|
||||
assert "Register the return odometer reading" in answer.answer
|
||||
assert "Vehicle return procedure" in answer.answer
|
||||
assert len(answer.sources) == 1
|
||||
assert answer.sources[0].title == "Vehicle return procedure"
|
||||
assert answer.sources[0].excerpt == (
|
||||
"Register the return odometer reading before releasing the vehicle."
|
||||
)
|
||||
|
||||
|
||||
def test_ragcore_provider_fallback_answer_is_localized(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(
|
||||
post_responses={
|
||||
"/v1/answers": _FakeResponse(503, {"code": "VALIDATION_RETRIES_EXHAUSTED"}),
|
||||
"/v1/search": _FakeResponse(200, _search_body()),
|
||||
}
|
||||
),
|
||||
)
|
||||
answer = provider.ask(
|
||||
"Wat is de procedure voor een voertuigretour?",
|
||||
"test-correlation-fallback-nl",
|
||||
language="nl-BE",
|
||||
)
|
||||
assert answer.evidence_state == "grounded"
|
||||
assert answer.answer.startswith("Volgens ")
|
||||
|
||||
|
||||
def test_ragcore_provider_fallback_with_no_search_results_is_insufficient(monkeypatch):
|
||||
provider = RAGcoreKnowledgeProvider()
|
||||
monkeypatch.setattr(provider._settings, "ragcore_space_id", "space-1")
|
||||
monkeypatch.setattr(
|
||||
provider,
|
||||
"_client",
|
||||
lambda: _FakeClient(
|
||||
post_responses={
|
||||
"/v1/answers": _FakeResponse(503, {"code": "VALIDATION_RETRIES_EXHAUSTED"}),
|
||||
"/v1/search": _FakeResponse(200, _search_body(results=[])),
|
||||
}
|
||||
),
|
||||
)
|
||||
answer = provider.ask("Unrelated question?", "test-correlation-fallback-empty")
|
||||
assert answer.evidence_state == "insufficient"
|
||||
assert answer.answer == ""
|
||||
assert answer.sources == []
|
||||
|
||||
@@ -81,6 +81,48 @@ def test_mcp_tool_requests_are_audited(client, ops_client):
|
||||
assert events[0]["actor_type"] == "service"
|
||||
|
||||
|
||||
def test_search_knowledge_respects_requested_locale(client):
|
||||
response = client.post(
|
||||
"/api/v1/integrations/mcp/search-knowledge",
|
||||
json={
|
||||
"question": "Wat moet ik doen wanneer een voertuig beschadigd terugkomt?",
|
||||
"max_sources": 1,
|
||||
"locale": "nl-BE",
|
||||
},
|
||||
headers=_headers(),
|
||||
)
|
||||
assert response.status_code == 200
|
||||
body = response.json()
|
||||
assert body["evidence_state"] == "grounded"
|
||||
|
||||
|
||||
def test_search_knowledge_preserves_inbound_correlation_id(client, ops_client):
|
||||
inbound = "11111111-1111-1111-1111-111111111111"
|
||||
response = client.post(
|
||||
"/api/v1/integrations/mcp/search-knowledge",
|
||||
json={"question": "What must I do when a vehicle returns with damage?", "max_sources": 1},
|
||||
headers={**_headers(client_id="correlation-probe"), "X-Correlation-Id": inbound},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
assert response.json()["correlation_id"] == inbound
|
||||
|
||||
events = ops_client.get("/api/v1/audit", params={"action": "mcp_tool_request"}).json()
|
||||
matching = [e for e in events if e["correlation_id"] == inbound]
|
||||
assert len(matching) == 1
|
||||
|
||||
|
||||
def test_operations_summary_mints_correlation_id_when_none_supplied(client, ops_client):
|
||||
response = client.get(
|
||||
"/api/v1/integrations/mcp/operations-summary",
|
||||
headers=_headers(client_id="no-correlation-probe"),
|
||||
)
|
||||
assert response.status_code == 200
|
||||
events = ops_client.get("/api/v1/audit", params={"action": "mcp_tool_request"}).json()
|
||||
matching = [e for e in events if e["actor_label"] == "no-correlation-probe"]
|
||||
assert len(matching) >= 1
|
||||
assert matching[0]["correlation_id"] # a fresh UUID was minted, not left empty
|
||||
|
||||
|
||||
def test_no_write_endpoints_exist_under_mcp_namespace(client):
|
||||
for method, path in [
|
||||
("post", "/api/v1/integrations/mcp/vehicles/MO-016"),
|
||||
|
||||
@@ -11,6 +11,10 @@ def test_search_finds_a_vehicle_by_reference(ops_client):
|
||||
assert match is not None
|
||||
assert match["label"] == "MO-001"
|
||||
assert match["link"] == "/vehicles/MO-001"
|
||||
# The backend must never send localizable prose -- only a stable code plus raw
|
||||
# data params, so the frontend can render it in the operator's selected language.
|
||||
assert match["detail_code"] == "vehicleSummary"
|
||||
assert set(match["detail_params"]) == {"make", "model", "location"}
|
||||
|
||||
|
||||
def test_search_finds_a_booking_by_reference(ops_client):
|
||||
@@ -37,7 +41,21 @@ def test_search_never_returns_data_quality_issues_for_rental_employee(employee_c
|
||||
|
||||
def test_search_section_result_visible_to_operations_manager(ops_client):
|
||||
result = ops_client.get("/api/v1/search", params={"q": "audit"}).json()
|
||||
assert any(r["type"] == "section" and r["link"] == "/audit" for r in result["results"])
|
||||
match = next(
|
||||
(r for r in result["results"] if r["type"] == "section" and r["link"] == "/audit"), None
|
||||
)
|
||||
assert match is not None
|
||||
# Section results must ship a stable id, not English prose -- the frontend looks up
|
||||
# navigation:items.<id> and search:sections.<id>.detail in the selected locale.
|
||||
assert match["label"] == "audit"
|
||||
assert match["detail_code"] == "audit"
|
||||
|
||||
|
||||
def test_search_section_matches_dutch_and_french_terms(ops_client):
|
||||
nl_result = ops_client.get("/api/v1/search", params={"q": "wagenpark"}).json()
|
||||
assert any(r["type"] == "section" and r["link"] == "/vehicles" for r in nl_result["results"])
|
||||
fr_result = ops_client.get("/api/v1/search", params={"q": "réservation"}).json()
|
||||
assert any(r["type"] == "section" and r["link"] == "/bookings" for r in fr_result["results"])
|
||||
|
||||
|
||||
def test_search_section_result_hidden_from_rental_employee(employee_client):
|
||||
|
||||
@@ -7,7 +7,7 @@ from app.models.audit import AuditEvent
|
||||
from app.models.booking import Booking
|
||||
from app.models.customer import Customer
|
||||
from app.models.data_quality import DataQualityIssue
|
||||
from app.models.outbox import OutboxEvent
|
||||
from app.models.outbox import DEMO_SCENARIO_ERROR_CODE, OutboxEvent
|
||||
from app.models.user import User
|
||||
from app.models.vehicle import Vehicle
|
||||
from app.seed_loader import SEED_AUTHORED_ANCHOR, reset_and_seed
|
||||
@@ -22,9 +22,16 @@ def test_seed_counts_match_deterministic_dataset():
|
||||
reset_and_seed(db)
|
||||
assert db.scalar(select(func.count()).select_from(Vehicle)) == 50
|
||||
assert db.scalar(select(func.count()).select_from(Customer)) == 180
|
||||
assert db.scalar(select(func.count()).select_from(Booking)) == 246
|
||||
# 15 from the CSV plus a deterministic set discovered by the post-seed scan.
|
||||
assert db.scalar(select(func.count()).select_from(DataQualityIssue)) == 26
|
||||
# 246 original plus 8 (BK-T-001..008) added so "Today's movements" reads as a
|
||||
# real day of traffic rather than the same fixed 4 rows on every reset.
|
||||
assert db.scalar(select(func.count()).select_from(Booking)) == 254
|
||||
# 21 from the CSV (15 original + 6 giving every unexplained blocked vehicle a
|
||||
# real open issue) plus a deterministic set discovered by the post-seed scan. The
|
||||
# shared vehicle-status evaluator (app.services.vehicle_status) also catches
|
||||
# MO-024: an active/return-pending booking (BK-DEMO-RETURN) on a vehicle that has
|
||||
# already crossed its service-due odometer threshold -- a genuine conflict the
|
||||
# previous hand-rolled scanner never checked for.
|
||||
assert db.scalar(select(func.count()).select_from(DataQualityIssue)) == 33
|
||||
assert db.scalar(select(func.count()).select_from(OutboxEvent)) == 20
|
||||
assert db.scalar(select(func.count()).select_from(User)) == 2
|
||||
finally:
|
||||
@@ -138,6 +145,10 @@ def test_seed_scenario_s5_failed_workflow_run():
|
||||
assert failed.delivery_status == "failed"
|
||||
assert failed.attempts >= 1
|
||||
assert failed.last_error
|
||||
# Coded as a prepared demo scenario, not as a real connectionError: the whole
|
||||
# point of this row is to demonstrate retry and audit, so nothing downstream
|
||||
# may read it as evidence that the n8n integration is unhealthy.
|
||||
assert failed.last_error_code == DEMO_SCENARIO_ERROR_CODE
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
@@ -169,3 +180,102 @@ def test_seed_dates_are_anchored_to_reset_moment():
|
||||
assert marker.metadata_json["seed_authored_anchor"] == SEED_AUTHORED_ANCHOR.isoformat()
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_seed_today_movements_are_a_credible_mix():
|
||||
"""A fresh reset must not land on a thin, always-identical 'Today's movements'
|
||||
dashboard section: a real day of fleet traffic (>=5 departures, >=5 returns, across
|
||||
more than 4 distinct vehicles) should fall on the reset day, mirroring the same
|
||||
status/date rule the dashboard router uses to build the today list."""
|
||||
db = SessionLocal()
|
||||
try:
|
||||
reset_and_seed(db)
|
||||
today = datetime.now(UTC).date()
|
||||
bookings = db.scalars(select(Booking)).all()
|
||||
departures = [
|
||||
b
|
||||
for b in bookings
|
||||
if b.starts_at.date() == today and b.status in ("reserved", "active")
|
||||
]
|
||||
returns = [
|
||||
b for b in bookings if b.ends_at.date() == today and b.status in ("active", "returned")
|
||||
]
|
||||
assert len(departures) >= 5
|
||||
assert len(returns) >= 5
|
||||
vehicles_involved = {b.vehicle_id for b in departures} | {b.vehicle_id for b in returns}
|
||||
assert len(vehicles_involved) > 4
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_every_blocked_vehicle_has_a_real_open_issue():
|
||||
"""A live reviewer found blocked vehicles with no explanation anywhere in the UI --
|
||||
5 with zero quality issues at all, one (MO-049) with only a resolved one. Every
|
||||
vehicle seeded as 'blocked' must now have at least one real, currently open
|
||||
DataQualityIssue an operator can click through to."""
|
||||
db = SessionLocal()
|
||||
try:
|
||||
reset_and_seed(db)
|
||||
blocked = db.scalars(select(Vehicle).where(Vehicle.operational_status == "blocked")).all()
|
||||
assert len(blocked) > 0
|
||||
for vehicle in blocked:
|
||||
open_issue = db.scalar(
|
||||
select(DataQualityIssue).where(
|
||||
DataQualityIssue.entity_type == "vehicle",
|
||||
DataQualityIssue.entity_id == vehicle.id,
|
||||
DataQualityIssue.status == "open",
|
||||
)
|
||||
)
|
||||
assert open_issue is not None, f"{vehicle.public_ref} is blocked with no open issue"
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_seed_scenario_mo024_service_conflict_is_flagged():
|
||||
"""Regression lock-in for the live-reported MO-024 defect: 'rented' with a real
|
||||
active booking (BK-DEMO-RETURN) yet already 14,820 km past its service threshold,
|
||||
with nothing surfacing the contradiction. The shared vehicle-status evaluator
|
||||
already catches this (a real conflict, not a fabricated third status) -- this test
|
||||
exists so a future change can't silently regress it back to unexplained."""
|
||||
db = SessionLocal()
|
||||
try:
|
||||
reset_and_seed(db)
|
||||
vehicle = _by_ref(db, Vehicle, "MO-024")
|
||||
assert vehicle is not None
|
||||
assert vehicle.operational_status == "rented"
|
||||
assert vehicle.odometer_km >= vehicle.next_service_km
|
||||
|
||||
issue = db.scalar(
|
||||
select(DataQualityIssue).where(
|
||||
DataQualityIssue.entity_type == "vehicle",
|
||||
DataQualityIssue.entity_id == vehicle.id,
|
||||
DataQualityIssue.status == "open",
|
||||
DataQualityIssue.rule_type == "vehicle_status_conflict",
|
||||
)
|
||||
)
|
||||
assert issue is not None
|
||||
signals = issue.evidence_json.get("signals", [])
|
||||
assert any(s["code"] == "vehicle.manual_review_required" for s in signals)
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_seed_evidence_has_no_placeholder_summary():
|
||||
"""Every seed-only data-quality issue used to carry the vacuous evidence
|
||||
'Synthetic deterministic seed issue' with no structured signal at all -- a visitor
|
||||
had no way to understand why it needed attention. Every issue must now carry a real
|
||||
summary and at least one localizable signal (code + params)."""
|
||||
db = SessionLocal()
|
||||
try:
|
||||
reset_and_seed(db)
|
||||
issues = db.scalars(select(DataQualityIssue)).all()
|
||||
assert len(issues) > 0
|
||||
for issue in issues:
|
||||
summary = issue.evidence_json.get("summary", "")
|
||||
assert summary != "Synthetic deterministic seed issue", (
|
||||
f"{issue.public_ref} still has the meaningless placeholder summary"
|
||||
)
|
||||
signals = issue.evidence_json.get("signals", [])
|
||||
assert len(signals) > 0, f"{issue.public_ref} has no structured evidence signal"
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
@@ -0,0 +1,160 @@
|
||||
"""Pure unit tests for the shared vehicle-status evaluator -- no database needed, since
|
||||
evaluate_vehicle_status() only reasons over an already-gathered VehicleStatusFacts. See
|
||||
docs/fleet-ops-correction/vehicle-status-decision-table.md for the decision table these
|
||||
tests are asserting against."""
|
||||
|
||||
from types import SimpleNamespace
|
||||
|
||||
from app.services.vehicle_status import (
|
||||
RECOMMENDATION_CODE_ACTIVE_RENTAL,
|
||||
RECOMMENDATION_CODE_BOOKING_CONFLICT,
|
||||
RECOMMENDATION_CODE_MANUAL_REVIEW,
|
||||
RECOMMENDATION_CODE_NO_CONFLICT,
|
||||
RECOMMENDATION_CODE_RENTAL_ENDED,
|
||||
RECOMMENDATION_CODE_SERVICE_THRESHOLD,
|
||||
VehicleStatusFacts,
|
||||
compute_recommendation_token,
|
||||
evaluate_vehicle_status,
|
||||
)
|
||||
|
||||
|
||||
def _vehicle(status: str, *, version: int = 1):
|
||||
return SimpleNamespace(operational_status=status, version=version)
|
||||
|
||||
|
||||
def _facts(**overrides) -> VehicleStatusFacts:
|
||||
defaults = dict(
|
||||
active_booking_refs=[],
|
||||
overlapping_booking_pairs=[],
|
||||
service_threshold_reached=False,
|
||||
odometer_km=10_000,
|
||||
next_service_km=20_000,
|
||||
open_booking_overlap_issue_ref=None,
|
||||
)
|
||||
defaults.update(overrides)
|
||||
return VehicleStatusFacts(**defaults)
|
||||
|
||||
|
||||
def test_available_with_active_rental_recommends_rented():
|
||||
result = evaluate_vehicle_status(
|
||||
_vehicle("available"), _facts(active_booking_refs=["BK-0001"])
|
||||
)
|
||||
assert result.recommended_status == "rented"
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_ACTIVE_RENTAL
|
||||
assert result.safe_to_apply is True
|
||||
assert result.manual_review_required is False
|
||||
|
||||
|
||||
def test_maintenance_with_active_rental_never_auto_recommends_rented():
|
||||
# The exact unsafe shortcut this task explicitly forbids: maintenance + an active
|
||||
# booking must NEVER be auto-resolved to "rented".
|
||||
result = evaluate_vehicle_status(
|
||||
_vehicle("maintenance"), _facts(active_booking_refs=["BK-0001"])
|
||||
)
|
||||
assert result.recommended_status is None
|
||||
assert result.manual_review_required is True
|
||||
assert result.safe_to_apply is False
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_MANUAL_REVIEW
|
||||
|
||||
|
||||
def test_available_with_active_rental_and_service_threshold_requires_manual_review():
|
||||
result = evaluate_vehicle_status(
|
||||
_vehicle("available"),
|
||||
_facts(active_booking_refs=["BK-0001"], service_threshold_reached=True),
|
||||
)
|
||||
assert result.manual_review_required is True
|
||||
assert result.recommended_status is None
|
||||
|
||||
|
||||
def test_available_with_active_rental_and_booking_conflict_requires_manual_review():
|
||||
result = evaluate_vehicle_status(
|
||||
_vehicle("available"),
|
||||
_facts(active_booking_refs=["BK-0001"], open_booking_overlap_issue_ref="DQ-0001"),
|
||||
)
|
||||
assert result.manual_review_required is True
|
||||
assert result.recommended_status is None
|
||||
|
||||
|
||||
def test_rented_with_no_active_booking_recommends_available():
|
||||
result = evaluate_vehicle_status(_vehicle("rented"), _facts())
|
||||
assert result.recommended_status == "available"
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_RENTAL_ENDED
|
||||
assert result.safe_to_apply is True
|
||||
|
||||
|
||||
def test_service_threshold_reached_recommends_maintenance():
|
||||
result = evaluate_vehicle_status(
|
||||
_vehicle("available"), _facts(service_threshold_reached=True)
|
||||
)
|
||||
assert result.recommended_status == "maintenance"
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_SERVICE_THRESHOLD
|
||||
|
||||
|
||||
def test_booking_conflict_recommends_blocked_not_a_generic_high_severity_proxy():
|
||||
# The evaluator must react to a *real* booking-conflict fact, not "does some other
|
||||
# open high-severity issue happen to exist" (the forbidden proxy).
|
||||
result = evaluate_vehicle_status(
|
||||
_vehicle("available"),
|
||||
_facts(overlapping_booking_pairs=[("BK-DEMO-OVERLAP-A", "BK-DEMO-OVERLAP-B")]),
|
||||
)
|
||||
assert result.recommended_status == "blocked"
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_BOOKING_CONFLICT
|
||||
|
||||
|
||||
def test_open_booking_overlap_issue_alone_also_triggers_blocked():
|
||||
result = evaluate_vehicle_status(
|
||||
_vehicle("available"), _facts(open_booking_overlap_issue_ref="DQ-DEMO-OVERLAP")
|
||||
)
|
||||
assert result.recommended_status == "blocked"
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_BOOKING_CONFLICT
|
||||
|
||||
|
||||
def test_maintenance_with_no_active_rental_and_no_blockers_stays_manual():
|
||||
# No fact here confirms maintenance is actually finished, so the evaluator must not
|
||||
# auto-clear it to "available" -- that release remains an explicit, manual decision.
|
||||
result = evaluate_vehicle_status(_vehicle("maintenance"), _facts())
|
||||
assert result.recommended_status is None
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_NO_CONFLICT
|
||||
assert result.safe_to_apply is False
|
||||
|
||||
|
||||
def test_no_conflict_when_status_already_matches_facts():
|
||||
result = evaluate_vehicle_status(_vehicle("available"), _facts())
|
||||
assert result.recommended_status is None
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_NO_CONFLICT
|
||||
assert result.safe_to_apply is False
|
||||
|
||||
result = evaluate_vehicle_status(_vehicle("rented"), _facts(active_booking_refs=["BK-1"]))
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_NO_CONFLICT
|
||||
|
||||
result = evaluate_vehicle_status(_vehicle("blocked"), _facts())
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_NO_CONFLICT
|
||||
|
||||
result = evaluate_vehicle_status(
|
||||
_vehicle("maintenance"), _facts(service_threshold_reached=True)
|
||||
)
|
||||
assert result.recommendation_code == RECOMMENDATION_CODE_NO_CONFLICT
|
||||
|
||||
|
||||
def test_recommendation_token_changes_when_facts_change():
|
||||
vehicle = _vehicle("available")
|
||||
facts_a = _facts()
|
||||
facts_b = _facts(service_threshold_reached=True)
|
||||
assert compute_recommendation_token(vehicle, facts_a) != compute_recommendation_token(
|
||||
vehicle, facts_b
|
||||
)
|
||||
|
||||
|
||||
def test_recommendation_token_is_stable_for_identical_facts():
|
||||
vehicle = _vehicle("available")
|
||||
facts = _facts(active_booking_refs=["BK-0001"])
|
||||
assert compute_recommendation_token(vehicle, facts) == compute_recommendation_token(
|
||||
vehicle, facts
|
||||
)
|
||||
|
||||
|
||||
def test_recommendation_token_changes_when_vehicle_version_changes():
|
||||
facts = _facts()
|
||||
assert compute_recommendation_token(
|
||||
_vehicle("available", version=1), facts
|
||||
) != compute_recommendation_token(_vehicle("available", version=2), facts)
|
||||
@@ -14,6 +14,18 @@ def test_attention_only_filters_flagged_vehicles(ops_client):
|
||||
assert all(v["attention"] for v in vehicles)
|
||||
|
||||
|
||||
def test_vehicle_page_preserves_filters_and_limits_rendered_records(ops_client):
|
||||
response = ops_client.get(
|
||||
"/api/v1/vehicles",
|
||||
params={"status": "maintenance", "page": 1, "page_size": 25},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
body = response.json()
|
||||
assert len(body["items"]) <= 25
|
||||
assert all(v["operational_status"] == "maintenance" for v in body["items"])
|
||||
assert body["total"] >= len(body["items"])
|
||||
|
||||
|
||||
def test_vehicle_detail_includes_related_records(ops_client):
|
||||
response = ops_client.get("/api/v1/vehicles/MO-016")
|
||||
assert response.status_code == 200
|
||||
|
||||
@@ -1,9 +1,28 @@
|
||||
from app.core.db import SessionLocal
|
||||
from app.seed_loader import reset_and_seed
|
||||
|
||||
|
||||
def _reseed() -> None:
|
||||
"""Restore the canonical demo dataset (19 succeeded + 1 prepared failure).
|
||||
|
||||
The suite shares one session-scoped database and earlier files legitimately mutate
|
||||
the outbox, so any test that asserts on the *seeded* scenario has to re-establish it
|
||||
rather than depend on file ordering.
|
||||
"""
|
||||
db = SessionLocal()
|
||||
try:
|
||||
reset_and_seed(db)
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_list_workflows_requires_operations_manager(employee_client):
|
||||
response = employee_client.get("/api/v1/workflows")
|
||||
assert response.status_code == 403
|
||||
|
||||
|
||||
def test_list_workflows_includes_seeded_failed_run(ops_client):
|
||||
_reseed()
|
||||
response = ops_client.get("/api/v1/workflows", params={"status": "failed"})
|
||||
assert response.status_code == 200
|
||||
runs = response.json()
|
||||
@@ -20,6 +39,7 @@ def test_retry_requires_failed_status(ops_client):
|
||||
|
||||
|
||||
def test_retry_failed_run_moves_to_pending_and_audits(ops_client):
|
||||
_reseed()
|
||||
failed = ops_client.get("/api/v1/workflows", params={"status": "failed"}).json()
|
||||
target = failed[0]["event_id"]
|
||||
|
||||
@@ -36,3 +56,42 @@ def test_retry_requires_operations_manager(employee_client):
|
||||
"/api/v1/workflows/00000000-0000-4000-8000-000000000020/retry"
|
||||
)
|
||||
assert response.status_code == 403
|
||||
|
||||
|
||||
def test_seeded_failure_is_labelled_as_a_prepared_demo_scenario(ops_client):
|
||||
"""The one seeded failure must announce itself as staged. An unexplained red row in
|
||||
a demo reads as a broken product; a labelled one reads as the retry story it is."""
|
||||
_reseed()
|
||||
runs = ops_client.get("/api/v1/workflows", params={"status": "failed"}).json()
|
||||
demo_runs = [run for run in runs if run["is_demo_scenario"]]
|
||||
assert len(demo_runs) == 1
|
||||
assert demo_runs[0]["last_error_code"] == "demoScenarioTimeout"
|
||||
assert demo_runs[0]["aggregate_ref"] == "BK-H-0020"
|
||||
|
||||
|
||||
def test_succeeded_runs_are_never_marked_as_a_demo_scenario(ops_client):
|
||||
runs = ops_client.get("/api/v1/workflows", params={"status": "succeeded"}).json()
|
||||
assert runs
|
||||
assert all(run["is_demo_scenario"] is False for run in runs)
|
||||
|
||||
|
||||
def test_retry_of_the_demo_scenario_is_audited_as_a_demo_scenario(ops_client):
|
||||
"""The retry is a real redelivery either way; the audit records which kind of
|
||||
failure it resolved so a staged retry is never mistaken for a production fix."""
|
||||
_reseed()
|
||||
failed = ops_client.get("/api/v1/workflows", params={"status": "failed"}).json()
|
||||
demo_run = next(run for run in failed if run["is_demo_scenario"])
|
||||
|
||||
response = ops_client.post(f"/api/v1/workflows/{demo_run['event_id']}/retry")
|
||||
assert response.status_code == 200
|
||||
assert response.json()["status"] == "pending"
|
||||
|
||||
audit = ops_client.get("/api/v1/audit", params={"action": "workflow_retry"}).json()
|
||||
entry = next(
|
||||
event
|
||||
for event in audit
|
||||
if (event.get("metadata") or event.get("metadata_json") or {}).get("event_id")
|
||||
== demo_run["event_id"]
|
||||
)
|
||||
metadata = entry.get("metadata") or entry.get("metadata_json") or {}
|
||||
assert metadata["demo_scenario"] is True
|
||||
|
||||
@@ -31,9 +31,13 @@ services:
|
||||
RAGCORE_WORKSPACE: ${RAGCORE_WORKSPACE:-mobilityops}
|
||||
RAGCORE_COLLECTION: ${RAGCORE_COLLECTION:-internal-procedures}
|
||||
RAGCORE_API_TOKEN: ${RAGCORE_API_TOKEN:-}
|
||||
RAGCORE_SPACE_ID: ${RAGCORE_SPACE_ID:-}
|
||||
N8N_WEBHOOK_URL: ${N8N_WEBHOOK_URL:-http://n8n:5678/webhook/mobilityops-return}
|
||||
N8N_WEBHOOK_TRIGGER_TOKEN: ${MOBILITYOPS_WEBHOOK_TRIGGER_TOKEN:-replace-me-n8n-webhook-trigger-token}
|
||||
N8N_CALLBACK_TOKEN: ${MOBILITYOPS_CALLBACK_TOKEN:-replace-me-n8n-callback-token}
|
||||
MCP_HUB_SERVICE_TOKEN: ${MCP_HUB_SERVICE_TOKEN:-replace-me-mcp-hub-token}
|
||||
MCP_HUB_REGISTRATION_ENABLED: ${MCP_HUB_REGISTRATION_ENABLED:-false}
|
||||
MCP_HUB_BASE_URL: ${MCP_HUB_BASE_URL:-}
|
||||
DEMO_ORGANIZATION_NAME: ${DEMO_ORGANIZATION_NAME:-Northstar Mobility}
|
||||
DEMO_TIMEZONE: ${DEMO_TIMEZONE:-Europe/Brussels}
|
||||
DEMO_ALLOW_RESET: ${DEMO_ALLOW_RESET:-true}
|
||||
|
||||
@@ -1,17 +1,20 @@
|
||||
{
|
||||
"_note": "Fleet Ops's own published tool contract. The live ITWorx MCP Hub connector (ITWorx_MCP_Hub repo, connectors/mobilityops/) wraps these under its own dotted namespace (mobilityops.operations.summary, .attention.list, .vehicle.get, .knowledge.search) -- that naming is Hub-owned. deprecated_aliases below are Fleet Ops's own prior internal audit-label names, kept only so existing clients/dashboards referencing them don't break.",
|
||||
"provider_id": "mobilityops",
|
||||
"version": "1.0.0",
|
||||
"version": "1.1.0",
|
||||
"required_scope": "mobilityops.read",
|
||||
"tools": [
|
||||
{
|
||||
"name": "mobilityops_get_operations_summary",
|
||||
"description": "Return current high-level vehicle, data-quality and workflow counts for the synthetic MobilityOps demo tenant.",
|
||||
"name": "fleet_ops_get_operations_summary",
|
||||
"deprecated_aliases": ["mobilityops_get_operations_summary"],
|
||||
"description": "Return current high-level vehicle, data-quality and workflow counts for the synthetic Fleet Ops demo tenant.",
|
||||
"read_only": true,
|
||||
"inputSchema": {"type": "object", "additionalProperties": false},
|
||||
"endpoint": {"method": "GET", "path": "/api/v1/integrations/mcp/operations-summary"}
|
||||
},
|
||||
{
|
||||
"name": "mobilityops_list_attention_vehicles",
|
||||
"name": "fleet_ops_list_attention_vehicles",
|
||||
"deprecated_aliases": ["mobilityops_list_attention_vehicles"],
|
||||
"description": "List vehicles that require operational attention, optionally filtered by minimum severity and date.",
|
||||
"read_only": true,
|
||||
"inputSchema": {
|
||||
@@ -26,7 +29,8 @@
|
||||
"endpoint": {"method": "GET", "path": "/api/v1/integrations/mcp/attention-vehicles"}
|
||||
},
|
||||
{
|
||||
"name": "mobilityops_get_vehicle_details",
|
||||
"name": "fleet_ops_get_vehicle_details",
|
||||
"deprecated_aliases": ["mobilityops_get_vehicle_details"],
|
||||
"description": "Return a read-only operational view of one vehicle by its stable public reference.",
|
||||
"read_only": true,
|
||||
"inputSchema": {
|
||||
@@ -38,15 +42,17 @@
|
||||
"endpoint": {"method": "GET", "path": "/api/v1/integrations/mcp/vehicles/{vehicle_ref}"}
|
||||
},
|
||||
{
|
||||
"name": "mobilityops_search_knowledge",
|
||||
"description": "Search versioned MobilityOps internal procedures through the dedicated RAGcore workspace and return grounded source references.",
|
||||
"name": "fleet_ops_search_knowledge",
|
||||
"deprecated_aliases": ["mobilityops_search_knowledge"],
|
||||
"description": "Search versioned Fleet Ops internal procedures through the dedicated RAGcore workspace and return grounded source references.",
|
||||
"read_only": true,
|
||||
"inputSchema": {
|
||||
"type": "object",
|
||||
"required": ["question"],
|
||||
"properties": {
|
||||
"question": {"type": "string", "minLength": 3, "maxLength": 1000},
|
||||
"max_sources": {"type": "integer", "minimum": 1, "maximum": 8, "default": 4}
|
||||
"max_sources": {"type": "integer", "minimum": 1, "maximum": 8, "default": 4},
|
||||
"locale": {"enum": ["nl-BE", "en-GB", "fr-BE"], "default": "en-GB"}
|
||||
},
|
||||
"additionalProperties": false
|
||||
},
|
||||
|
||||
@@ -1,8 +1,11 @@
|
||||
openapi: 3.1.0
|
||||
info:
|
||||
title: MobilityOps API
|
||||
title: Fleet Ops API
|
||||
version: 0.1.0
|
||||
description: Contract baseline for the MobilityOps proof of concept.
|
||||
description: >-
|
||||
Contract baseline for the Fleet Ops demo. "Fleet Ops" is the visible product name;
|
||||
"mobilityops" remains the technical identifier for the repository, deployment
|
||||
directory, database, and internal service/health identifiers only.
|
||||
servers:
|
||||
- url: http://localhost:8128
|
||||
paths:
|
||||
@@ -181,26 +184,67 @@ paths:
|
||||
description: Wrong rule type, issue not open, or overlap still present
|
||||
'422':
|
||||
description: booking_ref not one of the overlapping bookings
|
||||
/api/v1/data-quality/issues/{public_ref}/status-recommendation:
|
||||
post:
|
||||
operationId: previewVehicleStatusRecommendation
|
||||
description: >-
|
||||
vehicle_status_conflict only. Non-mutating: computes the recommendation from
|
||||
the same shared evaluator the scanner and apply endpoint use
|
||||
(app.services.vehicle_status.evaluate_vehicle_status), without resolving the
|
||||
issue, writing an audit event, or queuing automation. Safe to call repeatedly
|
||||
-- see docs/fleet-ops-correction/vehicle-status-decision-table.md.
|
||||
parameters:
|
||||
- $ref: '#/components/parameters/PublicRef'
|
||||
responses:
|
||||
'200':
|
||||
description: >-
|
||||
Current/recommended status, recommendation code, safe_to_apply,
|
||||
manual_review_required, the underlying facts, and a recommendation_token
|
||||
the apply endpoint revalidates against.
|
||||
'409':
|
||||
description: Wrong rule type, issue not open, or vehicle not found
|
||||
/api/v1/data-quality/issues/{public_ref}/apply-recommended-status:
|
||||
post:
|
||||
operationId: applyRecommendedVehicleStatus
|
||||
description: >-
|
||||
vehicle_status_conflict only. Applies the one authoritative recommendation
|
||||
function's output and re-validates before resolving.
|
||||
function's output within one transaction: locks the issue and vehicle,
|
||||
recomputes the recommendation from fresh facts, rejects the request if the
|
||||
supplied recommendation_token no longer matches (RECOMMENDATION_STALE), refuses
|
||||
an unsafe/manual-review recommendation (MANUAL_REVIEW_REQUIRED) or a
|
||||
recommendation with nothing to apply (NO_CONFLICT_DETECTED), then re-validates
|
||||
the same evaluator post-write before resolving the issue.
|
||||
parameters:
|
||||
- $ref: '#/components/parameters/PublicRef'
|
||||
requestBody:
|
||||
required: true
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
type: object
|
||||
required: [recommendation_token]
|
||||
properties:
|
||||
recommendation_token:
|
||||
type: string
|
||||
description: The token from the most recent status-recommendation preview call.
|
||||
responses:
|
||||
'200':
|
||||
description: Applied status, reason and the resolved issue
|
||||
description: Applied status, reason code and the resolved issue
|
||||
'409':
|
||||
description: Wrong rule type, issue not open, or no conflict detected
|
||||
description: >-
|
||||
Wrong rule type, issue not open, vehicle not found, stale recommendation
|
||||
token, manual review required, no conflict detected, or the applied status
|
||||
did not resolve the conflict on re-validation
|
||||
/api/v1/search:
|
||||
get:
|
||||
operationId: search
|
||||
description: >-
|
||||
Bounded typed results (vehicle, booking, data_quality_issue, section).
|
||||
Data-quality and manager-only sections are filtered server-side by role.
|
||||
Customers are never returned -- no customer detail route exists.
|
||||
Customers are never returned -- no customer detail route exists. Every result's
|
||||
`label` is a stable public_ref/section id (never translatable prose); `detail_code`
|
||||
(+ optional `detail_params` for data values like make/model/location) is what the
|
||||
frontend localizes -- the backend never emits English/Dutch/French sentences here.
|
||||
parameters:
|
||||
- in: query
|
||||
name: q
|
||||
|
||||
@@ -3,7 +3,7 @@ set -eu
|
||||
|
||||
container_name="${1:-n8n}"
|
||||
callback_url="${2:-http://192.168.10.150:1236/api/v1/integrations/n8n/return-callback}"
|
||||
source_workflow="${3:-n8n/mobilityops-return-processing.json}"
|
||||
source_workflow="${3:-n8n/workflows/fleet-ops-vehicle-return.json}"
|
||||
|
||||
if [ ! -f .env ]; then
|
||||
echo "Missing deployment .env" >&2
|
||||
@@ -18,12 +18,10 @@ if ! docker inspect "$container_name" >/dev/null 2>&1; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
callback_token="$(sed -n 's/^MOBILITYOPS_CALLBACK_TOKEN=//p' .env | tail -n 1)"
|
||||
if [ -z "$callback_token" ]; then
|
||||
echo "MOBILITYOPS_CALLBACK_TOKEN is empty" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# The workflow file no longer carries the callback token as a literal header value -- both
|
||||
# the webhook trigger and the outbound callback authenticate via named n8n Header Auth
|
||||
# credentials ("Fleet Ops Webhook Trigger Token", "Fleet Ops Service Token"). Those must
|
||||
# exist in the target n8n instance before this workflow is activated; see the echo below.
|
||||
temporary_workflow="$(mktemp /tmp/mobilityops-n8n-workflow.XXXXXX.json)"
|
||||
container_workflow="/tmp/mobilityops-return-processing.json"
|
||||
cleanup() {
|
||||
@@ -32,15 +30,17 @@ cleanup() {
|
||||
}
|
||||
trap cleanup EXIT INT TERM
|
||||
|
||||
jq --arg callback_url "$callback_url" --arg callback_token "$callback_token" '
|
||||
(.nodes[] | select(.id == "callback-node") | .parameters.url) = $callback_url |
|
||||
(.nodes[] | select(.id == "callback-node") | .parameters.headerParameters.parameters[] |
|
||||
select(.name == "X-Service-Token") | .value) = $callback_token
|
||||
jq --arg callback_url "$callback_url" '
|
||||
(.nodes[] | select(.id == "callback-node") | .parameters.url) = $callback_url
|
||||
' "$source_workflow" > "$temporary_workflow"
|
||||
|
||||
docker cp "$temporary_workflow" "$container_name:$container_workflow" >/dev/null
|
||||
docker exec "$container_name" n8n import:workflow --input="$container_workflow"
|
||||
docker exec "$container_name" n8n publish:workflow --id=mobilityops-return-processing
|
||||
docker restart "$container_name" >/dev/null
|
||||
|
||||
echo "Published MobilityOps return workflow to existing container ${container_name}"
|
||||
echo "Imported Fleet Ops — Vehicle Return Orchestration into container ${container_name}."
|
||||
echo "Before activating: in the n8n UI, create Header Auth credentials named"
|
||||
echo " 'Fleet Ops Webhook Trigger Token' (value = MOBILITYOPS_WEBHOOK_TRIGGER_TOKEN from .env)"
|
||||
echo " 'Fleet Ops Service Token' (value = MOBILITYOPS_CALLBACK_TOKEN from .env)"
|
||||
echo "then open the workflow and click Publish. This script does not print or transmit"
|
||||
echo "those secret values, and does not restart the container -- restart it yourself once"
|
||||
echo "credentials are wired up and the workflow is published, if required."
|
||||
|
||||
@@ -3,7 +3,7 @@ set -eu
|
||||
|
||||
container_name="${1:-n8n}"
|
||||
scan_url="${2:-http://192.168.10.150:1236/api/v1/integrations/n8n/scheduled-scan}"
|
||||
source_workflow="${3:-n8n/mobilityops-scheduled-quality-scan.json}"
|
||||
source_workflow="${3:-n8n/workflows/fleet-ops-data-quality-scan.json}"
|
||||
|
||||
if [ ! -f .env ]; then
|
||||
echo "Missing deployment .env" >&2
|
||||
@@ -18,12 +18,10 @@ if ! docker inspect "$container_name" >/dev/null 2>&1; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
callback_token="$(sed -n 's/^MOBILITYOPS_CALLBACK_TOKEN=//p' .env | tail -n 1)"
|
||||
if [ -z "$callback_token" ]; then
|
||||
echo "MOBILITYOPS_CALLBACK_TOKEN is empty" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# The workflow file no longer carries the callback token as a literal header value -- the
|
||||
# scan request authenticates via the named n8n Header Auth credential ("Fleet Ops Service
|
||||
# Token"), which must exist in the target n8n instance before this workflow is activated;
|
||||
# see the echo below.
|
||||
temporary_workflow="$(mktemp /tmp/mobilityops-n8n-workflow.XXXXXX.json)"
|
||||
container_workflow="/tmp/mobilityops-scheduled-quality-scan.json"
|
||||
cleanup() {
|
||||
@@ -32,15 +30,16 @@ cleanup() {
|
||||
}
|
||||
trap cleanup EXIT INT TERM
|
||||
|
||||
jq --arg scan_url "$scan_url" --arg callback_token "$callback_token" '
|
||||
(.nodes[] | select(.id == "scan-node") | .parameters.url) = $scan_url |
|
||||
(.nodes[] | select(.id == "scan-node") | .parameters.headerParameters.parameters[] |
|
||||
select(.name == "X-Service-Token") | .value) = $callback_token
|
||||
jq --arg scan_url "$scan_url" '
|
||||
(.nodes[] | select(.id == "scan-node") | .parameters.url) = $scan_url
|
||||
' "$source_workflow" > "$temporary_workflow"
|
||||
|
||||
docker cp "$temporary_workflow" "$container_name:$container_workflow" >/dev/null
|
||||
docker exec "$container_name" n8n import:workflow --input="$container_workflow"
|
||||
docker exec "$container_name" n8n publish:workflow --id=mobilityops-scheduled-quality-scan
|
||||
docker restart "$container_name" >/dev/null
|
||||
|
||||
echo "Published MobilityOps scheduled quality-scan workflow to existing container ${container_name}"
|
||||
echo "Imported Fleet Ops — Scheduled Data Quality Scan into container ${container_name}."
|
||||
echo "Before activating: in the n8n UI, create a Header Auth credential named"
|
||||
echo " 'Fleet Ops Service Token' (value = MOBILITYOPS_CALLBACK_TOKEN from .env)"
|
||||
echo "then open the workflow and click Publish. This script does not print or transmit"
|
||||
echo "that secret value, and does not restart the container -- restart it yourself once"
|
||||
echo "the credential is wired up and the workflow is published, if required."
|
||||
|
||||
@@ -6,20 +6,44 @@ Publish four read-only MobilityOps capabilities through the existing central ITW
|
||||
|
||||
## Provider registration
|
||||
|
||||
- provider ID: `mobilityops`
|
||||
- API base: configurable internal MobilityOps API URL
|
||||
- authentication: scoped service token
|
||||
- provider ID: `mobilityops` (registered on the Hub side; the Hub's own registration is
|
||||
catalog-driven — it reconciles its catalog into the gateway, Fleet Ops never pushes a
|
||||
registration call)
|
||||
- API base: internal Fleet Ops API URL, reached via `MCP_HUB_SERVICE_TOKEN` auth
|
||||
- authentication: scoped service token (`X-Service-Token`), plus `X-Client-Id`
|
||||
- mode: read-only
|
||||
- required scope: `mobilityops.read`
|
||||
- **Confirmed live in production** on the ITWorx MCP Hub's own deployment (Tower), with
|
||||
a real contract fix already applied there (`vehicle.get`'s wire parameter normalized to
|
||||
camelCase `vehicleRef`). `docs/final-integrations/current-state-audit.md` has the full
|
||||
evidence.
|
||||
|
||||
## Tools
|
||||
|
||||
The machine-readable definitions are in `contracts/mcp-tools.json`.
|
||||
The machine-readable definitions are in `contracts/mcp-tools.json`. The Hub's own live
|
||||
connector (`ITWorx_MCP_Hub` repo, `connectors/mobilityops/`) publishes these under its
|
||||
own dotted namespace — that naming is the Hub's to own, not Fleet Ops's:
|
||||
|
||||
1. `mobilityops_get_operations_summary`
|
||||
2. `mobilityops_list_attention_vehicles`
|
||||
3. `mobilityops_get_vehicle_details`
|
||||
4. `mobilityops_search_knowledge`
|
||||
1. `mobilityops.operations.summary`
|
||||
2. `mobilityops.attention.list`
|
||||
3. `mobilityops.vehicle.get`
|
||||
4. `mobilityops.knowledge.search`
|
||||
|
||||
Fleet Ops's own internal audit trail (`AuditEvent.metadata_json.tool`, visible on
|
||||
`/api/v1/audit?action=mcp_tool_request`) labels these calls `fleet_ops_get_operations_summary`,
|
||||
`fleet_ops_list_attention_vehicles`, `fleet_ops_get_vehicle_details`,
|
||||
`fleet_ops_search_knowledge` — a separate, Fleet-Ops-owned naming layer for its own audit
|
||||
log, not the wire-level MCP tool name a client calls.
|
||||
|
||||
`search-knowledge` accepts a `locale` field (`nl-BE` | `en-GB` | `fr-BE`, default
|
||||
`en-GB`) that is passed straight through to the active knowledge provider.
|
||||
|
||||
## Correlation ID
|
||||
|
||||
The inbound `X-Correlation-Id` header (set by the Hub, itself either forwarding the
|
||||
MCP client's ID or minting one) is preserved through Fleet Ops's own handling and audit
|
||||
log; Fleet Ops only mints a fresh correlation ID when none is supplied or the supplied
|
||||
value isn't a valid UUID. See `get_correlation_id` in
|
||||
`backend/app/api/routers/mcp_integrations.py`.
|
||||
|
||||
## Routing
|
||||
|
||||
|
||||
@@ -16,7 +16,7 @@ Steps:
|
||||
4. return a stable workflow result;
|
||||
5. on errors, fail visibly so the outbox dispatcher can retry.
|
||||
|
||||
The starter export is `n8n/mobilityops-return-processing.json`. Claude may correct its credentials and callback route but must preserve idempotency.
|
||||
The canonical, live-validated definition is `n8n/workflows/fleet-ops-vehicle-return.json` (see `n8n/workflows/MANIFEST.md`); it authenticates via named Header Auth credentials rather than a literal token, per the live-hardening pass documented in `docs/live-ai-integration/n8n-current-state.md`.
|
||||
|
||||
## Second live workflow: scheduled quality scan
|
||||
|
||||
@@ -39,24 +39,24 @@ Steps:
|
||||
open, so a duplicate or overlapping trigger (a manual test run firing close to the
|
||||
scheduled one, or a retried HTTP call) does no duplicate domain work.
|
||||
|
||||
The starter export is `n8n/mobilityops-scheduled-quality-scan.json`, imported and
|
||||
published the same way as the return-processing workflow (see
|
||||
`deploy/unraid/setup-scheduled-scan.sh` and `docs/17-runbook.md`). It ships with
|
||||
`"active": false` so it cannot fire against any environment until deliberately
|
||||
published with a real service token.
|
||||
The canonical, live-validated definition is `n8n/workflows/fleet-ops-data-quality-scan.json`
|
||||
(see `n8n/workflows/MANIFEST.md`), imported and published the same way as the return
|
||||
workflow (see `deploy/unraid/setup-scheduled-scan.sh` and `docs/17-runbook.md`). It is
|
||||
active on the live instance; a fresh import ships inactive until credentials are wired up
|
||||
and it is deliberately published.
|
||||
|
||||
## Deferred: knowledge sync
|
||||
## RAGcore procedure sync (in progress)
|
||||
|
||||
Input: manual trigger or manifest-changed event.
|
||||
RAGcore is now reachable in this environment; a live inspection of its real contract is
|
||||
recorded in `docs/live-ai-integration/n8n-current-state.md`. Workflow 3, "Fleet Ops —
|
||||
RAGcore Procedure Sync", is being built against that real contract (not the sketch
|
||||
originally in this section) — see `n8n/workflows/MANIFEST.md` for current status.
|
||||
|
||||
Steps:
|
||||
## Workflow error handler (in progress)
|
||||
|
||||
1. read the fixed knowledge manifest;
|
||||
2. call RAGcore ingestion/sync API;
|
||||
3. record per-document results through MobilityOps integration status API.
|
||||
|
||||
Deferred until RAGcore's live ingestion API is available in this environment; must not
|
||||
delay or block the core demo.
|
||||
Workflow 4, "Fleet Ops — Workflow Error Handler", is a central technical workflow attached
|
||||
to workflows 1-3 via n8n's per-workflow "Error Workflow" setting, reporting bounded,
|
||||
secret-free failure details to Fleet Ops. See `n8n/workflows/MANIFEST.md` for status.
|
||||
|
||||
## Outbox dispatcher
|
||||
|
||||
@@ -67,3 +67,34 @@ delay or block the core demo.
|
||||
- supports explicit manual retry;
|
||||
- preserves last error and response metadata;
|
||||
- does not hold a database transaction open during network I/O.
|
||||
|
||||
## Prepared demo failure versus real failure
|
||||
|
||||
The demo seed deliberately plants exactly one failed delivery (`BK-H-0020`, see
|
||||
`seed/workflow_runs.csv`). It exists to demonstrate retry and audit, so it must never be
|
||||
read as evidence that the automation is unhealthy.
|
||||
|
||||
It is distinguished by its `last_error_code`, `demoScenarioTimeout`
|
||||
(`app.models.outbox.DEMO_SCENARIO_ERROR_CODE`) — not by a new column, so no migration is
|
||||
involved. A real timeout produces `connectionError`; the two are never confused.
|
||||
|
||||
Consequences, all enforced by tests:
|
||||
|
||||
- `/api/v1/integrations/status` reports `failed` (everything), `unexpected_failed` (real
|
||||
failures only) and `demo_scenario_failed` separately.
|
||||
- Only `unexpected_failed` can move n8n off `operational`. A prepared failure alone
|
||||
leaves the integration **operational** — a staged prop may not raise a red flag.
|
||||
- `latest_failure_at` is a health signal and therefore ignores the prepared failure;
|
||||
`latest_demo_scenario_at` reports it separately.
|
||||
- `/api/v1/workflows` marks the run with `is_demo_scenario: true`. The Automation page
|
||||
labels it "Prepared demo scenario", explains that it is a simulated temporary failure,
|
||||
and offers a distinct "Retry demo scenario" action.
|
||||
- A genuine later failure of that same event overwrites the code with the real one, and
|
||||
from that moment it counts as a real failure — the carve-out is narrow by construction.
|
||||
|
||||
The retry itself is real in both cases: the event goes back on the outbox and the
|
||||
dispatcher delivers it to the configured n8n webhook like any other, so 19 succeeded +
|
||||
1 failed becomes 20 succeeded + 0 failed only when n8n genuinely accepts the delivery.
|
||||
Nothing is marked succeeded without a real round trip. The audit entry records
|
||||
`demo_scenario: true/false` so a staged retry is never mistaken for a production fix.
|
||||
A demo reset recreates the original 19 + 1 scenario.
|
||||
|
||||
@@ -36,7 +36,12 @@ Vehicle `MO-016` has two imported overlapping reservations. Expected: visible qu
|
||||
|
||||
### S5 — Failed workflow
|
||||
|
||||
One seeded outbox/workflow record is failed with a safe simulated connection error. Expected: dashboard and Automation page show it; Operations Manager can retry.
|
||||
One seeded outbox/workflow record is failed with a safe simulated connection error, coded
|
||||
`demoScenarioTimeout` so it is recognisable as a prepared scenario rather than a real
|
||||
incident. Expected: dashboard and Automation page show it, labelled as a prepared demo
|
||||
scenario; n8n stays "Operational"; the Operations Manager can retry it, after which the
|
||||
overview reads 20 succeeded and 0 failed. See `docs/11-n8n-integration.md`, "Prepared demo
|
||||
failure versus real failure".
|
||||
|
||||
### S6 — Grounded damage question
|
||||
|
||||
|
||||
@@ -48,7 +48,7 @@ longer gates this. This is a one-time step per fresh `docker compose down -v`:
|
||||
which runs:
|
||||
|
||||
```bash
|
||||
docker compose exec n8n n8n import:workflow --input=//imports/mobilityops-return-processing.json
|
||||
docker compose exec n8n n8n import:workflow --input=//imports/workflows/fleet-ops-vehicle-return.json
|
||||
docker compose exec n8n n8n publish:workflow --id=mobilityops-return-processing
|
||||
docker compose restart n8n
|
||||
```
|
||||
@@ -56,6 +56,12 @@ longer gates this. This is a one-time step per fresh `docker compose down -v`:
|
||||
(`n8n import:workflow` always leaves the workflow deactivated regardless of its
|
||||
`"active"` field; `publish:workflow` + a restart is what actually activates it.)
|
||||
|
||||
Before it will actually process a return, create two Header Auth credentials in the n8n
|
||||
UI — `Fleet Ops Webhook Trigger Token` (value: `MOBILITYOPS_WEBHOOK_TRIGGER_TOKEN` from
|
||||
`.env`) and `Fleet Ops Service Token` (value: `MOBILITYOPS_CALLBACK_TOKEN` from `.env`) —
|
||||
the workflow's webhook trigger and outbound HTTP call reference these credentials by
|
||||
name; no secret value is embedded in the workflow file itself.
|
||||
|
||||
Verify the full round trip:
|
||||
|
||||
```bash
|
||||
@@ -77,11 +83,14 @@ make n8n-setup-scan
|
||||
which runs:
|
||||
|
||||
```bash
|
||||
docker compose exec n8n n8n import:workflow --input=//imports/mobilityops-scheduled-quality-scan.json
|
||||
docker compose exec n8n n8n import:workflow --input=//imports/workflows/fleet-ops-data-quality-scan.json
|
||||
docker compose exec n8n n8n publish:workflow --id=mobilityops-scheduled-quality-scan
|
||||
docker compose restart n8n
|
||||
```
|
||||
|
||||
This workflow also needs the `Fleet Ops Service Token` Header Auth credential created in
|
||||
the n8n UI before a run will succeed.
|
||||
|
||||
Verify:
|
||||
|
||||
```bash
|
||||
|
||||
@@ -0,0 +1,509 @@
|
||||
# MobilityOps visual product roadmap
|
||||
|
||||
## Purpose
|
||||
|
||||
This roadmap turns the visual audit of the deployed MobilityOps PoC into an
|
||||
implementation plan. It improves the existing operational workflows without
|
||||
expanding the locked product scope.
|
||||
|
||||
The intended outcome is a platform that:
|
||||
|
||||
- lets an operator identify and act on urgent work within thirty seconds;
|
||||
- remains efficient with the current synthetic data set and larger realistic data sets;
|
||||
- keeps status, context and primary actions visible on desktop and mobile;
|
||||
- uses a readable, consistent visual hierarchy;
|
||||
- communicates integration and knowledge health without contradictory signals;
|
||||
- preserves the existing domain rules, audit guarantees and graceful degradation.
|
||||
|
||||
## Scope guardrails
|
||||
|
||||
Included:
|
||||
|
||||
- information architecture and visual hierarchy;
|
||||
- list density, pagination, filtering and responsive presentation;
|
||||
- dashboard, detail, return, data-quality, knowledge, automation, audit and demo flows;
|
||||
- accessibility, perceived performance and UI observability;
|
||||
- regression tests, visual evidence and rollout safeguards.
|
||||
|
||||
Excluded:
|
||||
|
||||
- new accounting, payments, CRM, inventory, HR or reservation modules;
|
||||
- maintenance work orders, calendar views or advanced analytics;
|
||||
- changes to RAGcore or ITWorx MCP Hub repositories;
|
||||
- autonomous write actions or write-capable MCP tools;
|
||||
- a redesign of backend domain rules that is not required by the UI work.
|
||||
|
||||
## Audit baseline
|
||||
|
||||
The audit was performed against the deployed application at desktop, tablet and
|
||||
mobile widths. The current strengths to preserve are the professional visual
|
||||
identity, consistent status language, strong login page, semantic page structure,
|
||||
visible keyboard focus, absence of horizontal overflow and clear return and
|
||||
data-quality narratives.
|
||||
|
||||
The principal improvement signals are:
|
||||
|
||||
| Area | Baseline observation | Consequence |
|
||||
|---|---|---|
|
||||
| Audit log | Up to 100 expanded event cards; approximately 18,500 px desktop and 20,500 px mobile | Poor scanability and excessive scrolling |
|
||||
| Vehicle list | All 50 vehicles render at once; approximately 12,000 px on mobile | Operational lookup is slow on small screens |
|
||||
| Mobile page header | `.page-actions` is hidden below 700 px | Important record status disappears |
|
||||
| Typography | Many metadata labels and badges are approximately 9–11 px | Readability is weaker than the visual quality suggests |
|
||||
| Top bar | Search, language, demo controls, disclosure, timezone and operator controls compete for space | High cognitive load and weak prioritisation |
|
||||
| Knowledge | An operational provider can be shown beside “0 procedures indexed” | Trust signal is ambiguous or contradictory |
|
||||
| Integration cards | Technical identifiers and small prose dominate the summary | Operational state is harder to scan |
|
||||
|
||||
These values are baselines, not permanent acceptance thresholds. Each affected
|
||||
phase must record a before-and-after measurement.
|
||||
|
||||
## Delivery principles
|
||||
|
||||
1. Fix operational friction before decorative polish.
|
||||
2. Prefer progressive disclosure over removing useful evidence.
|
||||
3. Keep the primary status and next action visible at every viewport.
|
||||
4. Paginate or virtualise unbounded collections; never solve them only with CSS.
|
||||
5. Derive every displayed count and state from persisted or external evidence.
|
||||
6. Preserve URLs, permissions, audit semantics and keyboard operation.
|
||||
7. Ship each phase as a coherent, independently reversible commit.
|
||||
8. Validate every phase at 390 px, 768 px and 1440 px.
|
||||
|
||||
## Target measures
|
||||
|
||||
The roadmap is complete when the following targets are met:
|
||||
|
||||
| Measure | Target |
|
||||
|---|---|
|
||||
| Initial rows/cards in any operational list | At most 25, unless a documented compact virtualised view is used |
|
||||
| Mobile status visibility | Primary record status visible on every detail page |
|
||||
| Horizontal overflow | None at 360 px and above |
|
||||
| Default text | At least 14 px |
|
||||
| Secondary metadata | At least 12 px; exceptions require an accessibility justification |
|
||||
| Touch target | At least 44 by 44 CSS px for primary mobile controls |
|
||||
| Keyboard access | All actions reachable with visible focus and logical order |
|
||||
| List navigation | Filter, paging and search state represented in the URL where practical |
|
||||
| Dashboard comprehension | Primary operational risks and next movements visible without scrolling at 1440 × 900 |
|
||||
| Browser console | No application errors during the five-minute demo |
|
||||
| Performance | No avoidable rendering of more than one page of list records |
|
||||
| Automated acceptance | Existing backend, frontend and Playwright gates remain green |
|
||||
|
||||
## Roadmap overview
|
||||
|
||||
| Phase | Theme | Priority | Indicative effort | Depends on |
|
||||
|---|---|---:|---:|---|
|
||||
| R0 | Baseline and design-system guardrails | P0 | 2–3 days | None |
|
||||
| R1 | Operational lists and audit log | P0 | 5–7 days | R0 |
|
||||
| R2 | Responsive shell and readable hierarchy | P0 | 4–6 days | R0 |
|
||||
| R3 | Dashboard and record-detail efficiency | P1 | 5–7 days | R1, R2 |
|
||||
| R4 | Guided workflows and decision surfaces | P1 | 5–7 days | R2, R3 |
|
||||
| R5 | Knowledge, automation and trust signals | P1 | 3–5 days | R2 |
|
||||
| R6 | Accessibility, performance and release evidence | P0 gate | 4–6 days | R1–R5 |
|
||||
|
||||
Indicative total: 28–41 focused engineering days. Phases can span multiple
|
||||
calendar sprints, but their exit gates should not be split across releases.
|
||||
|
||||
## R0 — Baseline and design-system guardrails
|
||||
|
||||
### Objective
|
||||
|
||||
Create shared UI rules and reproducible measurements before changing individual
|
||||
pages.
|
||||
|
||||
### Work packages
|
||||
|
||||
#### R0.1 — Visual regression baseline
|
||||
|
||||
- Capture authenticated reference screenshots for the seven principal routes and
|
||||
the login page at 390 × 844, 768 × 1024 and 1440 × 900.
|
||||
- Add stable screenshot fixtures using the deterministic seed.
|
||||
- Mask only genuinely variable timestamps; do not mask operational content.
|
||||
- Record viewport width, page height, visible item count and horizontal overflow.
|
||||
|
||||
#### R0.2 — Typography and spacing tokens
|
||||
|
||||
- Replace scattered sub-12 px declarations with named type tokens.
|
||||
- Establish body, metadata, label, badge, table-header and navigation sizes.
|
||||
- Define compact and comfortable density variants without duplicating page CSS.
|
||||
- Preserve the existing petrol/teal palette and status colours.
|
||||
|
||||
#### R0.3 — Shared responsive patterns
|
||||
|
||||
- Define a mobile page-header contract: title, visible status, primary action and
|
||||
overflow actions.
|
||||
- Define reusable compact-list, filter-toolbar, pagination and empty-state patterns.
|
||||
- Establish 44 px mobile target sizing and a consistent sticky-offset system.
|
||||
|
||||
### Acceptance criteria
|
||||
|
||||
- Visual baselines exist for all principal routes and viewports.
|
||||
- No normal operational metadata is smaller than 12 px.
|
||||
- Shared components document their responsive behaviour.
|
||||
- Existing Playwright demo and frontend build pass unchanged.
|
||||
|
||||
## R1 — Operational lists and audit log
|
||||
|
||||
### Objective
|
||||
|
||||
Make high-volume operational information scannable and bounded on every device.
|
||||
|
||||
### Work packages
|
||||
|
||||
#### R1.1 — Audit API pagination and filtering
|
||||
|
||||
- Replace the default fixed `limit=100` response with cursor or page-based pagination.
|
||||
- Add filters for date range, action, actor, entity type, entity reference and
|
||||
correlation ID.
|
||||
- Retain stable newest-first ordering and service-token protections.
|
||||
- Return total or continuation metadata suitable for the selected paging model.
|
||||
|
||||
#### R1.2 — Compact audit timeline
|
||||
|
||||
- Render 20–25 compact events per page.
|
||||
- Group correlated events and repetitive scheduled events without hiding their count.
|
||||
- Move full UUIDs, before/after data and technical metadata into a details drawer.
|
||||
- Keep human-readable action, actor, target, outcome and timestamp in the main row.
|
||||
- Preserve direct navigation to related records.
|
||||
|
||||
#### R1.3 — Vehicle-list pagination
|
||||
|
||||
- Add server-compatible pagination to the vehicle list.
|
||||
- Preserve status, location, attention and search filters across pages.
|
||||
- Store filter and page state in the URL.
|
||||
- Provide a prominent “attention required” view without inventing new metrics.
|
||||
- Use compact mobile rows rather than full table-to-card expansion for every vehicle.
|
||||
|
||||
#### R1.4 — Data-quality queue controls
|
||||
|
||||
- Paginate the open issue list.
|
||||
- Add severity and rule grouping/filtering.
|
||||
- Add “previous issue” and “next issue” navigation to review pages.
|
||||
- Keep scan and resolution actions permission-aware.
|
||||
|
||||
### Acceptance criteria
|
||||
|
||||
- No default list renders more than 25 records.
|
||||
- Audit and vehicle pages remain below 3,500 px at the tested mobile viewport with
|
||||
the deterministic seed.
|
||||
- Paging and filters survive reload, back navigation and direct links.
|
||||
- Empty, loading, error and end-of-results states are explicit.
|
||||
- API tests cover invalid cursors/pages, combined filters and authorization.
|
||||
|
||||
## R2 — Responsive shell and readable hierarchy
|
||||
|
||||
### Objective
|
||||
|
||||
Reduce navigation noise and keep essential context visible on small screens.
|
||||
|
||||
### Work packages
|
||||
|
||||
#### R2.1 — Top-bar simplification
|
||||
|
||||
- Keep global search and current operational context primary.
|
||||
- Move language, timezone and sign-out into the operator menu.
|
||||
- Combine demo disclosure and demo progress into one compact control.
|
||||
- Replace the visually empty mobile search field with an explicit search button or
|
||||
a full-width command surface.
|
||||
|
||||
#### R2.2 — Mobile page actions
|
||||
|
||||
- Stop hiding the complete page-action region.
|
||||
- Always show record status next to or below the title.
|
||||
- Keep one primary action visible and move secondary actions to an accessible menu.
|
||||
- Verify booking, vehicle, data-quality and automation detail headers independently.
|
||||
|
||||
#### R2.3 — Navigation refinement
|
||||
|
||||
- Review whether the desktop sidebar should remain available at wider tablet widths.
|
||||
- Increase mobile navigation label size and touch area.
|
||||
- Keep four or five primary destinations visible and put lower-frequency destinations
|
||||
under “More” if six items cannot meet readability targets.
|
||||
- Preserve current routes and role-based visibility.
|
||||
|
||||
#### R2.4 — Typography rollout
|
||||
|
||||
- Apply the R0 type tokens to badges, tables, integration cards, timelines, forms and
|
||||
mobile navigation.
|
||||
- Rebalance padding where larger text would otherwise increase page height excessively.
|
||||
- Verify Dutch, French and English labels for clipping and wrapping.
|
||||
|
||||
### Acceptance criteria
|
||||
|
||||
- Status remains visible on every sampled mobile detail page.
|
||||
- No essential action is hover-only or hidden solely because of viewport width.
|
||||
- Top-bar controls fit without clipping at 390, 768 and 1440 px.
|
||||
- Language changes do not introduce horizontal overflow.
|
||||
- Touch-target and typography targets are met.
|
||||
|
||||
## R3 — Dashboard and record-detail efficiency
|
||||
|
||||
### Objective
|
||||
|
||||
Put operational decisions above supporting detail and make desktop space work harder.
|
||||
|
||||
### Work packages
|
||||
|
||||
#### R3.1 — Dashboard hierarchy
|
||||
|
||||
- Keep readiness and highest-severity attention items visible in the first viewport.
|
||||
- Reduce the vertical weight of the demo-scenario panel after the scenario starts.
|
||||
- Limit the initial attention queue and link to a complete filtered view.
|
||||
- Balance “movements today” against attention content when only a few movements exist.
|
||||
- Keep integrations and recent activity available without duplicating status copy.
|
||||
|
||||
#### R3.2 — Mobile dashboard summary
|
||||
|
||||
- Convert readiness into a compact, horizontally accessible summary or disclosure.
|
||||
- Show the highest-priority attention items first with an explicit remaining count.
|
||||
- Surface the next departure and return before secondary integration information.
|
||||
|
||||
#### R3.3 — Vehicle-detail workspace
|
||||
|
||||
- Replace the sparse overview with a two-column desktop composition.
|
||||
- Surface current status, location, odometer, next booking and active attention items.
|
||||
- Keep bookings, inspections, maintenance, quality issues and audit as focused tabs.
|
||||
- Avoid new maintenance-domain functionality; link only to existing evidence.
|
||||
|
||||
#### R3.4 — Booking-detail summary
|
||||
|
||||
- Rebalance the facts grid so incomplete final rows do not create large empty bands.
|
||||
- On mobile, show status and return readiness before secondary booking facts.
|
||||
- Keep the return form close to the task entry point while retaining validation context.
|
||||
|
||||
### Acceptance criteria
|
||||
|
||||
- At 1440 × 900 the dashboard exposes readiness, urgent work and today's movement
|
||||
context without scrolling.
|
||||
- Sparse states remain intentional and balanced rather than appearing unfinished.
|
||||
- All values remain derived from persisted data.
|
||||
- Existing return and status-domain tests remain unchanged and green.
|
||||
|
||||
## R4 — Guided workflows and decision surfaces
|
||||
|
||||
### Objective
|
||||
|
||||
Reduce the distance between evidence and the decision an operator must make.
|
||||
|
||||
### Work packages
|
||||
|
||||
#### R4.1 — Return flow refinement
|
||||
|
||||
- Keep the step indicator visible while completing or reviewing a return.
|
||||
- Use a compact mobile booking summary above the form.
|
||||
- Present validation errors next to fields and in a short focusable summary.
|
||||
- Preserve the post-submit explanation of inspection, vehicle status, quality issue,
|
||||
queued automation and next-booking risk.
|
||||
|
||||
#### R4.2 — Duplicate-customer decision layout
|
||||
|
||||
- Use evidence/comparison on the left and a sticky survivor/merge preview on desktop.
|
||||
- Keep matching fields collapsed by default and differences expanded.
|
||||
- Keep irreversible-action language and audit preview adjacent to the merge button.
|
||||
- On mobile, use a deliberate sequence: evidence, differences, survivor, preview,
|
||||
confirmation.
|
||||
|
||||
#### R4.3 — Other data-quality resolutions
|
||||
|
||||
- Standardise evidence, proposed resolution, consequence and audit-preview sections.
|
||||
- Keep resolve, reject and defer actions visually distinct and permission-aware.
|
||||
- Provide clear success feedback and navigation to the next issue.
|
||||
|
||||
#### R4.4 — Guided demo integration
|
||||
|
||||
- Reduce competition between the guide and normal navigation.
|
||||
- Persist progress without obscuring page controls.
|
||||
- Make “go to this step” land on the relevant element or focused task state.
|
||||
- Ensure the guide is fully keyboard-operable and usable as a mobile bottom sheet.
|
||||
|
||||
### Acceptance criteria
|
||||
|
||||
- Primary workflow action is visible or reachable with one obvious interaction.
|
||||
- A user never needs to scroll past repeated explanatory content to discover the
|
||||
required decision.
|
||||
- Focus moves to validation failures and success results appropriately.
|
||||
- The five-minute demo remains deterministic.
|
||||
|
||||
## R5 — Knowledge, automation and trust signals
|
||||
|
||||
### Objective
|
||||
|
||||
Make external-system health understandable to an operator without exposing irrelevant
|
||||
technical detail.
|
||||
|
||||
### Work packages
|
||||
|
||||
#### R5.1 — Knowledge status semantics
|
||||
|
||||
- Separate provider availability, indexed-source count and last successful sync.
|
||||
- Never show “0 indexed” as a healthy equivalent when the value is unknown or stale.
|
||||
- Label extractive fallback answers honestly while preserving source cards.
|
||||
- Reduce empty-state height and show a compact explanation of what a cited answer contains.
|
||||
- Keep suggested questions concise and prioritised.
|
||||
|
||||
#### R5.2 — Source and freshness presentation
|
||||
|
||||
- Surface source title, version, section and freshness consistently.
|
||||
- Keep document UUIDs and raw retrieval metadata behind technical details.
|
||||
- Provide explicit grounded, insufficient-evidence and unavailable states.
|
||||
|
||||
#### R5.3 — Integration summary redesign
|
||||
|
||||
- Structure each integration around state, last success, affected workflow and next action.
|
||||
- Move client IDs, raw endpoints and UUIDs to a detail disclosure.
|
||||
- Remove unnecessary fixed card height, especially at tablet widths.
|
||||
- Keep genuine mixed states visible without presenting them as contradictions.
|
||||
|
||||
#### R5.4 — Workflow evidence table
|
||||
|
||||
- Improve status and recency scanning.
|
||||
- Distinguish “never triggered”, “no evidence yet”, “failed” and “unavailable”.
|
||||
- Keep retry actions safe, audited and available only where already supported.
|
||||
|
||||
### Acceptance criteria
|
||||
|
||||
- Knowledge and integration states cannot make mutually contradictory claims.
|
||||
- An operator can identify the current state and next action within one card scan.
|
||||
- Technical identifiers do not dominate default views.
|
||||
- RAGcore, n8n and MCP Hub timeout/unavailable contract tests stay green.
|
||||
|
||||
## R6 — Accessibility, performance and release evidence
|
||||
|
||||
### Objective
|
||||
|
||||
Turn the improvements into a verified, releasable quality baseline.
|
||||
|
||||
### Work packages
|
||||
|
||||
#### R6.1 — Accessibility review
|
||||
|
||||
- Test complete keyboard traversal of login, navigation, filters, return, merge,
|
||||
knowledge, workflow retry and audit details.
|
||||
- Verify focus order, focus restoration, dialog labelling and error announcements.
|
||||
- Run automated accessibility checks on all principal routes.
|
||||
- Manually verify status is not encoded by colour alone.
|
||||
- Verify zoom at 200% and 360 px responsive reflow.
|
||||
|
||||
#### R6.2 — Rendering and interaction performance
|
||||
|
||||
- Measure list rendering before and after pagination.
|
||||
- Check layout shift and interaction latency on dashboard and long-list routes.
|
||||
- Ensure drawers, menus and guided-demo panels do not mount large hidden subtrees.
|
||||
- Test with reduced motion and a throttled CPU profile.
|
||||
|
||||
#### R6.3 — Cross-browser and localisation pass
|
||||
|
||||
- Verify current Chrome plus one additional Chromium/Firefox-equivalent target where
|
||||
supported by the test environment.
|
||||
- Run Dutch, French and English visual checks at all target widths.
|
||||
- Verify Europe/Brussels date and time rendering.
|
||||
|
||||
#### R6.4 — Final automated journey and evidence
|
||||
|
||||
- Extend the existing Playwright demo with pagination, mobile status and accessible
|
||||
details checks.
|
||||
- Capture final screenshots for all principal pages.
|
||||
- Add before-and-after measurements and known PoC limitations to final evidence.
|
||||
- Execute clean-checkout bootstrap, backend tests, lint, typing and frontend build.
|
||||
|
||||
### Acceptance criteria
|
||||
|
||||
- No critical or serious automated accessibility violations on principal routes.
|
||||
- All target measures in this document pass.
|
||||
- `docs/14-testing-and-acceptance.md` passes from a clean checkout.
|
||||
- `artifacts/evidence/final-summary.md` contains the final commands, counts,
|
||||
screenshots and limitations.
|
||||
|
||||
## Suggested release slices
|
||||
|
||||
### Release A — Operational scale
|
||||
|
||||
Contains R0 and R1. This release eliminates the most severe scroll and list-density
|
||||
problems without materially changing workflow structure.
|
||||
|
||||
Release gate:
|
||||
|
||||
- paginated audit, vehicles and data-quality queues;
|
||||
- URL-backed filters;
|
||||
- unchanged audit and authorization semantics;
|
||||
- visual regression baseline green.
|
||||
|
||||
### Release B — Responsive operations
|
||||
|
||||
Contains R2 and R3. This release improves navigation, typography, dashboard hierarchy
|
||||
and detail-page use of space.
|
||||
|
||||
Release gate:
|
||||
|
||||
- visible mobile statuses and primary actions;
|
||||
- readable typography and touch targets;
|
||||
- dashboard first-viewport target met;
|
||||
- Dutch, French and English responsive checks green.
|
||||
|
||||
### Release C — Guided decisions and trust
|
||||
|
||||
Contains R4 and R5. This release refines the return, merge, knowledge, automation and
|
||||
demo-guide experiences.
|
||||
|
||||
Release gate:
|
||||
|
||||
- decision actions remain near their evidence;
|
||||
- honest and non-contradictory external health states;
|
||||
- five-minute demo passes end to end.
|
||||
|
||||
### Release D — Quality certification
|
||||
|
||||
Contains R6 and only defects found by its gates. It adds no new product scope.
|
||||
|
||||
Release gate:
|
||||
|
||||
- full clean-checkout acceptance;
|
||||
- accessibility and performance targets met;
|
||||
- final evidence updated;
|
||||
- release tag and deployed revision recorded.
|
||||
|
||||
## Implementation sequence and dependencies
|
||||
|
||||
```text
|
||||
R0 shared tokens and baselines
|
||||
├─ R1 pagination and compact lists ─┐
|
||||
└─ R2 responsive shell and type ───┼─ R3 dashboard/details ─ R4 workflows
|
||||
└─ R5 trust surfaces
|
||||
R1 + R2 + R3 + R4 + R5 ──────────────────────────────── R6 release gate
|
||||
```
|
||||
|
||||
R1 and R2 may be developed in parallel after R0. R3 should consume both shared list
|
||||
and responsive patterns. R4 depends on the new page-header and detail hierarchy. R5 can
|
||||
start after R2 but must share its disclosure and status patterns. R6 is a gate, not a
|
||||
cleanup bucket; defects discovered there return to the owning phase.
|
||||
|
||||
## Per-phase engineering checklist
|
||||
|
||||
Every phase must include:
|
||||
|
||||
1. a short before-state measurement;
|
||||
2. API and data-contract impact assessment;
|
||||
3. implementation using shared components where applicable;
|
||||
4. unit/API tests for changed contracts;
|
||||
5. Playwright coverage for the changed user journey;
|
||||
6. manual checks at 390, 768 and 1440 px in all supported languages;
|
||||
7. accessibility and console check;
|
||||
8. updated evidence and `PROJECT_STATE.md` entry;
|
||||
9. one coherent commit after validation passes;
|
||||
10. deployment verification before starting the next release slice.
|
||||
|
||||
## Risks and mitigations
|
||||
|
||||
| Risk | Mitigation |
|
||||
|---|---|
|
||||
| Pagination changes API consumers | Add pagination metadata without silently changing service-token/MCP response contracts; version only if necessary |
|
||||
| Compact layouts hide evidence | Use drawers and disclosures, preserving direct access and auditability |
|
||||
| Larger type increases page height | Combine type changes with density and hierarchy work, never shrink text again |
|
||||
| Sticky UI covers content on mobile | Use shared top/bottom offsets and test keyboard/zoom states |
|
||||
| Visual snapshots become brittle | Seed deterministic data and mask only true timestamp volatility |
|
||||
| External health data is stale | Show last successful evidence and distinguish unknown from healthy |
|
||||
| Roadmap drifts into new product scope | Check every work package against `docs/01-scope-and-non-goals.md` and `docs/deferred.md` |
|
||||
|
||||
## Definition of roadmap completion
|
||||
|
||||
This roadmap is complete only when Releases A through D are deployed and verified,
|
||||
all target measures pass, the original five-minute demo remains green, and the final
|
||||
evidence records the exact deployed revision. Completing only the visual styling or one
|
||||
high-priority page does not complete the roadmap.
|
||||
@@ -65,9 +65,11 @@ generated and kept fresh across resets.
|
||||
`RAGcoreKnowledgeProvider` HTTP adapter exists and is unit-tested, ready to take over
|
||||
the same interface once a real RAGcore backend is available — swapping providers is a
|
||||
configuration change (`KNOWLEDGE_PROVIDER`), not a UI change.
|
||||
- **ITWorx MCP Hub**: not connected. Registration is disabled by default
|
||||
(`MCP_HUB_REGISTRATION_ENABLED=false`) and the UI always shows "Not connected" —
|
||||
never a fabricated successful registration.
|
||||
- **ITWorx MCP Hub**: the UI reports "Operational" only when Fleet Ops has really
|
||||
recorded `mcp_tool_request` calls in its own audit log. `MCP_HUB_REGISTRATION_ENABLED`
|
||||
on its own never makes it operational — registration is catalog-driven on the Hub's
|
||||
side, so the flag alone is not evidence of anything, and a successful registration is
|
||||
never fabricated.
|
||||
|
||||
## Where to go next
|
||||
|
||||
|
||||
@@ -0,0 +1,87 @@
|
||||
# AI Operations Brief — runbook and live evidence
|
||||
|
||||
Answers, using a real MCP client through the real ITWorx MCP Hub connector against live
|
||||
production Fleet Ops: *"Which vehicles need the most attention today, why, and which
|
||||
internal procedure should be followed for the most important issue?"*
|
||||
|
||||
## What this is not
|
||||
|
||||
Not a chatbot. No write actions exist under `/api/v1/integrations/mcp/*` (verified by
|
||||
`test_no_write_endpoints_exist_under_mcp_namespace`). Every call below is a plain
|
||||
read-only tool invocation, exactly as the deployed Hub connector performs them.
|
||||
|
||||
## Reproducible command
|
||||
|
||||
Run from inside the live `itworx-mcp-hub-connector-mobilityops-1` container (has the
|
||||
real `MOBILITYOPS_ENDPOINT`, `MOBILITYOPS_SERVICE_TOKEN_FILE` and the real
|
||||
`packages.connector_kit.mobilityops.MobilityOpsClient` already available — the same
|
||||
client class the deployed connector uses):
|
||||
|
||||
```sh
|
||||
docker exec -e PYTHONPATH=/opt/hub -w /opt/hub \
|
||||
itworx-mcp-hub-connector-mobilityops-1 python3 - <<'PY'
|
||||
from packages.connector_kit.mobilityops import FileTokenProvider, MobilityOpsClient, MobilityOpsSettings
|
||||
import os, json
|
||||
|
||||
settings = MobilityOpsSettings(
|
||||
base_url=os.environ["MOBILITYOPS_ENDPOINT"],
|
||||
token_reference=os.environ["MOBILITYOPS_SERVICE_TOKEN_FILE"],
|
||||
)
|
||||
client = MobilityOpsClient(settings, FileTokenProvider())
|
||||
client_id = "ai-ops-brief"
|
||||
|
||||
summary = client.operations_summary(client_id)
|
||||
attention = client.attention_vehicles(client_id, minimum_severity="high", date=None, limit=20)
|
||||
top_ref = attention[0]["vehicle_ref"] if attention else None
|
||||
details = client.vehicle_details(client_id, top_ref) if top_ref else None
|
||||
answer = client.search_knowledge(client_id, "What must I do when a vehicle returns with damage?", max_sources=2)
|
||||
|
||||
print(json.dumps({"summary": summary, "top_attention": attention[0] if attention else None, "vehicle": details, "answer": answer}, indent=2))
|
||||
client.close()
|
||||
PY
|
||||
```
|
||||
|
||||
This calls, in order: `fleet_ops_get_operations_summary` → `fleet_ops_list_attention_vehicles`
|
||||
→ `fleet_ops_get_vehicle_details` → `fleet_ops_search_knowledge`. No result is invented —
|
||||
every field printed is exactly what Fleet Ops's live API returned.
|
||||
|
||||
## Live run, 2026-08-05
|
||||
|
||||
- **Operations summary**: 21 available, 11 rented, 6 cleaning, 5 maintenance,
|
||||
**7 blocked**; 23 open quality issues; 1 pending/failed workflow.
|
||||
- **Most pressing vehicle**: `MO-031` — `missing_required_field`, "near-future booking;
|
||||
required operational inspection missing", detected `2026-08-05T11:08:33Z`. (16 vehicles
|
||||
currently carry a `high`-severity open issue; `MO-031` was the earliest-detected.)
|
||||
- **Vehicle detail (`MO-031`)**: Adria Matrix, 2022, Geel, `operational_status: blocked`,
|
||||
41,149 km (service due at 50,000 km), no current booking.
|
||||
- **Grounded procedure (English)**: *Damage handling procedure* v1.3, section "1.
|
||||
Immediate actions" — "When a vehicle returns with visible or reported damage, mark
|
||||
damage in the return inspection, add a concise factual description and keep the
|
||||
vehicle blocked. Do not promise the customer a repair cost or liability decision."
|
||||
Second source: *Vehicle return procedure* v2.0, section "3. Determine next state".
|
||||
`evidence_state: grounded`, 2 real citations, `provider: demo`.
|
||||
- **Dutch and French variants of the damage question** (`Wat moet ik doen wanneer een
|
||||
voertuig beschadigd terugkomt?`, `Que dois-je faire lorsqu'un véhicule revient
|
||||
endommagé ?`) both returned `evidence_state: insufficient` — an honest, non-fabricated
|
||||
"no match" rather than a wrong or invented answer. Root cause: the currently-deployed
|
||||
Hub connector does not yet send the new `locale` field this session added to
|
||||
`search-knowledge` (Fleet Ops defaults to `en-GB`), so non-English question text
|
||||
doesn't match the demo provider's English-tokenized index. A real fix needs a Hub-side
|
||||
connector update to pass `locale`, tracked as a follow-up, not silently worked around.
|
||||
- **Correlation ID, end to end, verified**: each call's response `correlation_id` (e.g.
|
||||
`abd643a7-2aeb-4af3-806a-da04acb3e444` for the English grounded answer) appears
|
||||
verbatim in Fleet Ops's own audit log (`GET /api/v1/audit?action=mcp_tool_request`),
|
||||
alongside `actor_label: ai-ops-brief-2026-08-05` and the real tool name
|
||||
(`fleet_ops_search_knowledge`). No write actions were performed; only `mcp_tool_request`
|
||||
audit rows were created, matching every other live MCP call this integration makes.
|
||||
|
||||
## Known limitation, stated plainly
|
||||
|
||||
The demo knowledge provider (not RAGcore — `KNOWLEDGE_PROVIDER=demo`, see
|
||||
`docs/final-integrations/current-state-audit.md` for why) is what grounds the English
|
||||
answer here. It is deterministic, extractive, and never fabricates — but it is not the
|
||||
live RAGcore integration the brief brief for this task set out to exercise; that
|
||||
remains blocked on RAGcore's own reranker gap. This run is honest about that: it proves
|
||||
the full MCP-client → Hub → Fleet Ops → knowledge-provider → audit chain works for real,
|
||||
live, in production, with real data and real citations — using the knowledge provider
|
||||
that is actually configured live today.
|
||||
@@ -0,0 +1,152 @@
|
||||
# Current-state audit — Fleet Ops final integrations
|
||||
|
||||
Date: 2026-08-05. Compiled from direct repository inspection (git log/status/diff across
|
||||
all three repos), `PROJECT_STATE.md` history, and read-only investigation of the sibling
|
||||
repos' own state docs. No live server SSH/curl evidence is included in this pass yet —
|
||||
see `integration-release-state.md` for the live-verification checklist as it is executed.
|
||||
|
||||
## Repository revisions at audit time
|
||||
|
||||
| Repo | Path | Branch | HEAD | Notes |
|
||||
|---|---|---|---|---|
|
||||
| Fleet Ops (MobilityOps) | `C:\Projects\MobilityOps` | `feat/fleet-ops-final-integrations` (new, branched from `feat/live-n8n-ragcore-integration`) | `3ebca9e` | `feat/live-n8n-ragcore-integration` was pushed to `origin` at `0571a40` and deployed live; `3ebca9e` (logo rebrand) is one commit ahead, not yet deployed. `master` is 19 commits behind and stale (localization-round only). |
|
||||
| RAGcore | `C:\Projects\RAGcore` | `main` | `64a908a` | Up to date with `origin/main`. Uncommitted local work in progress (see below) — not Fleet-Ops-related, left untouched. |
|
||||
| ITWorx MCP Hub | `C:\Projects\ITWorx_MCP_Hub` | `feature/wp240-final-acceptance` | `26e6bd8` (+ later `75bb16a`) | Contains `f107544` (MobilityOps connector) as a direct ancestor, plus a real contract fix (`96de385`, vehicleRef camelCase). Already deployed live to Tower at `c4a0f6d`. |
|
||||
|
||||
## Branch-name correction (recorded assumption)
|
||||
|
||||
The task brief names the working branch `feat/fleet-ops-final-integrations` as already
|
||||
selected and "branched from the most recently validated, localized, deployed master
|
||||
branch." That literal branch did not exist. `master` is in fact stale (19 commits behind,
|
||||
last touched for a localization round only) — the actually-validated, deployed line of
|
||||
work is `feat/live-n8n-ragcore-integration` (pushed to `origin`, deployed to
|
||||
`http://192.168.10.150:1236` at `0571a40`, one commit behind current HEAD). Created
|
||||
`feat/fleet-ops-final-integrations` from that branch's HEAD (`3ebca9e`) instead of from
|
||||
`master`, since that satisfies the actual intent (continue from the validated/deployed
|
||||
line) even though the literal branch name in the brief was inaccurate.
|
||||
|
||||
## What is actually already done (contradicts "not yet live" framing in places)
|
||||
|
||||
- **n8n**: 3 of 4 canonical workflows are live and active in the shared instance
|
||||
(`n8n.itworx.tech`): Vehicle Return Orchestration, Scheduled Data Quality Scan,
|
||||
Workflow Error Handler. The 4th, RAGcore Procedure Sync, has all 6 nodes built and
|
||||
saved but is **not published** (deliberately left for an explicit activation decision,
|
||||
since publishing starts real unattended daily runs against production). The root cause
|
||||
of an earlier "auth"-looking failure (`N8N_PROXY_HOPS=0` behind the TLS-terminating
|
||||
reverse proxy, breaking the browserId CSRF check on every mutating REST call) was found
|
||||
and fixed at the infrastructure level (Unraid template), not worked around.
|
||||
- **RAGcore**: deployed to `http://192.168.10.150:1237`, application wiring for
|
||||
search/context/answer is real (commit `a2905cc`, confirmed present in RAGcore's own
|
||||
history at `13 commits behind HEAD`). `KNOWLEDGE_PROVIDER` is still `demo` in Fleet Ops
|
||||
because real queries against the "Fleet Ops Procedures" space return **zero dense and
|
||||
zero sparse candidates** at the raw retrieval stage — confirmed not a Fleet-Ops-side
|
||||
wiring bug (RAGcore's own trusted Query Lab tool reproduces the identical zero-candidate
|
||||
result against the same space). Root cause not yet found as of this audit; ruled out so
|
||||
far: point count/scoping (83 published, correctly scoped), embedding digest mismatch
|
||||
(matches), collection alias resolution (resolves correctly). One separate, confirmed,
|
||||
pre-existing bug: `_DEFAULT_LANGUAGE = "en"` is hardcoded in RAGcore's ingestion handler
|
||||
— every chunk is stamped `language: "en"` regardless of actual content; RAGcore has never
|
||||
done real language detection. Not the cause of zero candidates, but must be fixed for
|
||||
trilingual retrieval (task 6A) once the space is answerable at all.
|
||||
- **MCP Hub**: the Fleet Ops read-only connector (4 tools, `mobilityops.*`) is **already
|
||||
live in production** on Tower (commit `c4a0f6d`), reachable via `fleetops.itworx.tech`,
|
||||
end-to-end verified once already per the Hub's own `CLAUDE.md`/`BUILD_STATE.json`. A
|
||||
real contract bug was found and fixed there (`vehicle.get`'s input schema disagreed with
|
||||
the actual wire parameter name — `vehicle_ref` vs `vehicleRef`). What is **not** yet done:
|
||||
the Hub's own formal production-acceptance checklist row for MobilityOps (`CON-P04`) has
|
||||
not been executed, and Fleet Ops's own `MCP_HUB_REGISTRATION_ENABLED`/base-URL
|
||||
configuration has not been confirmed as actually wired and flipped on from the Fleet Ops
|
||||
side (open item for this audit's Batch 4).
|
||||
|
||||
## Confirmed contradictions to resolve (task section 3)
|
||||
|
||||
- "Twee versus vier n8n-workflows": resolved above — 3 active + 1 built-but-unpublished.
|
||||
Canonical set is 4; only 3 are live.
|
||||
- "Demo-provider versus live RAGcore": Fleet Ops is still on the demo knowledge provider
|
||||
by deliberate, documented decision (not an oversight) pending the retrieval root cause.
|
||||
- "MCP Hub-status": prior Fleet Ops docs (`.env.example`, `MCP_HUB_REGISTRATION_ENABLED`)
|
||||
predate the Hub-side deployment and need reconciling against the fact that the connector
|
||||
is already live on the Hub side.
|
||||
- Repo hygiene: removed an untracked, empty `backend;C` directory and an untracked 31 MB
|
||||
`MobilityOps.zip` stray export; added `*.zip`/`*.tar.gz` to `.gitignore`. No accidentally
|
||||
committed `__pycache__`/`.pytest_cache`/`test-results` were found in git history.
|
||||
|
||||
## RAGcore retrieval root cause — found and partially fixed (2026-08-05, this session)
|
||||
|
||||
Investigated live against production (`192.168.10.150`, containers `ragcore-app-1`,
|
||||
`ragcore-qdrant-1`, `ragcore-postgres-1`, `ollama`), read-only first, then two approved
|
||||
live changes.
|
||||
|
||||
**Root cause #1 (FIXED): filesystem permission bug, not authorization/data.** Verified,
|
||||
in order, that every earlier suspect was actually healthy: the `control.grants` row
|
||||
(active, `editor` role, correct application/space), the real
|
||||
`ControlPlaneAuthorizationInputsProvider` + `RetrievalAuthorizationService.resolve()` code
|
||||
path run in-process against the live DB (resolves a non-empty `effective_space_ids`), the
|
||||
exact production Qdrant filter run directly against the live collection (returns real
|
||||
matching points), and a real ANN vector query under that filter (real hits, sensible
|
||||
scores). The actual break: `/workspace/.state/models/embedding_profiles.json` — the file
|
||||
`RetrievalPipeline.run()` reads on every single query to resolve the active embedding
|
||||
profile — was owned by container-side `root:root` mode `600` on the bind-mounted
|
||||
`/mnt/cache/appdata/ragcore/state/models` host path, while the real running app process
|
||||
is uid 10001 (`ragcore`). Every retrieval call hit a `PermissionError` reading its own
|
||||
state file before ever reaching Qdrant — a plain filesystem-ownership bug, invisible to
|
||||
every DB/Qdrant-level check. **Fixed live**: `chown 10001:10001` +
|
||||
`chmod 644`/`755` on that file/directory (approved by the user beforehand). Re-verified
|
||||
in-process: `RetrievalPipeline.run()` now returns 5 real, relevant hits for an English
|
||||
damage-procedure question (previously 0).
|
||||
|
||||
**Root cause #2 (found, NOT fixed — needs a design decision): reranking is
|
||||
architecturally unavailable.** `DEFAULT_RERANKER_PROFILE.model_identifier` is
|
||||
`bge-reranker-v2-m3:v1`, which was never actually present in Ollama's model list (0 of 14
|
||||
installed models matched). With the user's approval, pulled a working GGUF
|
||||
(`xitao/bge-reranker-v2-m3:latest`, 1.2 GB) into the shared Ollama instance. **This did
|
||||
not fix reranking**: `OllamaRerankAdapter` posts to `{ollama_base_url}/api/rerank`, and
|
||||
this Ollama server (version `0.32.5`) returns a plain `404` for that route — it has no
|
||||
rerank endpoint at all. This is not a missing-model problem, it is that RAGcore's
|
||||
reranker adapter was built against an Ollama HTTP API that does not exist in the deployed
|
||||
version (matches the code's own comment that no reranker-profile registry or live
|
||||
validation existed yet). The retrieval pipeline degrades gracefully on rerank failure
|
||||
(RRF-fusion-only hits still returned, confirmed above), but the `/v1/answers` endpoint's
|
||||
answerability classifier still returns `not_answerable`/0 citations for real NL/EN/FR
|
||||
questions against real matching content, live-verified after fix #1 with a freshly
|
||||
minted, correctly-scoped credential.
|
||||
|
||||
Options for #2, not decided yet: (a) find/confirm whether a newer Ollama version adds a
|
||||
real `/api/rerank` route and upgrade the shared instance (affects every other project on
|
||||
this Ollama — needs its own explicit approval and blast-radius review); (b) change
|
||||
RAGcore's reranker adapter to call a route Ollama actually supports (e.g. score via
|
||||
`/api/embed` + a manual similarity/cross-encoder computation, or drop the separate
|
||||
rerank step and let the answerability classifier trust RRF-fused scores) — a RAGcore
|
||||
code/design change, out of Fleet Ops's own mandate to decide unilaterally; (c) leave
|
||||
`KNOWLEDGE_PROVIDER=demo` until RAGcore's own team/session resolves this.
|
||||
|
||||
**Side effect to flag**: minting the live-verification credential used `rotate=True` on
|
||||
the existing "Fleet Ops Knowledge Assistant (production)" service account (a second
|
||||
credential would have exceeded RAGcore's own 2-active-credential cap), which invalidates
|
||||
whatever token was previously issued for that account. Since Fleet Ops is still on
|
||||
`KNOWLEDGE_PROVIDER=demo`, this has no live user-facing impact today, but a fresh
|
||||
credential must be issued and wired into Fleet Ops's `RAGCORE_API_TOKEN` at actual
|
||||
cutover time — do not assume the old one still works.
|
||||
|
||||
**Concurrency note**: `C:\Projects\RAGcore` had substantial uncommitted local changes
|
||||
from what appears to be a different, actively-running session (36 modified/untracked
|
||||
files by the end of this investigation, including files this investigation also read).
|
||||
No commits or file edits were made in that checkout this session precisely because of
|
||||
that collision risk — the two live fixes above were applied directly to the running
|
||||
containers/Ollama instance (approved), not to the RAGcore git repository. **Follow-up
|
||||
required**: once the concurrent session's work lands, the reranker-profile fix (whichever
|
||||
option above is chosen) still needs an actual code change + commit + redeploy in
|
||||
`C:\Projects\RAGcore`, which was not safe to do mid-collision this session.
|
||||
|
||||
## Minimal remaining implementation order
|
||||
|
||||
1. Root-cause the RAGcore zero-candidate retrieval bug (blocks flipping `KNOWLEDGE_PROVIDER`
|
||||
and blocks the trilingual live-acceptance and AI Operations Brief tasks).
|
||||
2. Fix RAGcore's hardcoded `language: "en"` chunk metadata for trilingual retrieval.
|
||||
3. Decide on and execute n8n workflow 3 publication, with live no-op-on-rerun verification.
|
||||
4. Confirm/complete Fleet Ops-side MCP Hub registration wiring and run the Hub's own
|
||||
CON-P04 acceptance row.
|
||||
5. Build the AI Operations Brief runbook once RAGcore and MCP Hub are both live-green.
|
||||
6. GUI polish batch (dashboard Today/Attention presentation, duplicate-merge presentation,
|
||||
About Demo scannability, Demo Guide completion state).
|
||||
7. Final regression gates and evidence write-up.
|
||||
@@ -0,0 +1,75 @@
|
||||
# Fleet Ops correction — current-state gap audit
|
||||
|
||||
## Branch / commit state (at audit time)
|
||||
|
||||
- Repository's actual main/default branch is named **`master`** (there is no `main` branch — `remotes/origin/HEAD -> origin/master`). All instructions referring to "main" in this task are treated as referring to `master`.
|
||||
- `master` (local and `origin/master`) was at `18344bc8b7a75a2f868bf15bf498fc030ac6c34c` before this task started — this is the newest verified Fleet Ops demo commit (contains the full rebrand/i18n/adaptive-guide/Data-Quality-UX work from the previous task).
|
||||
- Deployed commit on Unraid (`/mnt/user/appdata/mobilityops/.deploy/source-revision`): `18344bc8b7a75a2f868bf15bf498fc030ac6c34c` — matches `master` exactly. No drift.
|
||||
- No uncommitted local changes at audit time (`git status` clean).
|
||||
- Source branch for this correction: `master` (already contained the newest verified commit). New branch created: **`fix/fleet-ops-i18n-status-flow`**, branched from `master` at `18344bc`.
|
||||
- `feat/mobilityops-functional-completion` remains un-deleted, as instructed by the prior task, and is left untouched by this one.
|
||||
|
||||
## Confirmed gaps (verified against actual code, not assumed)
|
||||
|
||||
### 1. Brand name is a translatable key (structural risk)
|
||||
|
||||
- `common:appName` exists per-locale in `frontend/src/i18n/locales/{nl-BE,en-GB,fr-BE}/common.json`, all currently `"Fleet Ops"`, but nothing prevents a future edit from diverging one locale. Used in `Login.tsx:35` and `Layout.tsx:180`.
|
||||
- 8 more locale keys embed the literal string "Fleet Ops" inside translatable prose (`auth.defaultDescription`, `common.footer.productLine`, `demo.guide.steps["review-real-vs-simulated"].expectedOutcome`, `demo.about.title`, `demo.about.problemBody`, `demo.about.scopeBody`, `knowledge.emptyDescription`, `navigation.searchLabel`, `returns.scenario.body`) — all three locales currently say "Fleet Ops" correctly, but structurally these are still translatable values.
|
||||
- **Fix**: `frontend/src/product.ts` exports `PRODUCT_NAME = "Fleet Ops"`. Remove `common:appName`; `Login.tsx`/`Layout.tsx` import the constant directly. Replace the 8 embedded mentions with `{{productName}}` interpolation, passing `productName: PRODUCT_NAME` explicitly at each call site. Add a Playwright test that fails if any locale JSON file contains the literal substring `"Fleet Ops"` (forcing all future brand mentions through interpolation) and a live-DOM test asserting the rendered brand text is byte-identical across all three languages.
|
||||
|
||||
### 2. Backend hardcodes English prose as primary user-facing content (structural, not cosmetic)
|
||||
|
||||
Confirmed in `backend/app/services/data_quality.py`:
|
||||
- `_scan_duplicate_customers` (~line 127-149): evidence signals literally `"exact email"`, `"exact phone"`, `"exact postal code"`, `"similar name"`, joined into `evidence.summary`.
|
||||
- `_scan_missing_required_fields` (~170, 185): `f"Missing: {', '.join(missing)}"`.
|
||||
- `_scan_booking_overlaps` (~213): `f"Overlapping bookings {first.public_ref} and {second.public_ref}"`.
|
||||
- `_scan_vehicle_status_conflicts` (~240-256): reason strings like `"marked available while an active booking exists"`.
|
||||
- `_scan_odometer_regressions` (~291-295): full English sentence with interpolated numbers/refs.
|
||||
- `_recommend_vehicle_status` (~659-668): recommendation `reason` strings returned verbatim as `ApplyRecommendedStatusResult.reason` and rendered directly in the UI.
|
||||
|
||||
Confirmed in `backend/app/services/returns.py`:
|
||||
- `_derive_vehicle_status_with_reason` (~32-43): `status_reason` strings ("Damage was reported on return.", "A technical warning was reported on return.", "Odometer reached the {n} km service threshold.", "No damage, technical warning or service threshold; routed to cleaning.") flow straight into the API response and are displayed raw regardless of UI language (asserted verbatim in English in `interactive-elements.spec.ts:133`, confirming this is genuinely user-visible, not just internal).
|
||||
|
||||
Confirmed in `backend/app/services/dispatcher.py` / seed data: `event.last_error` stores raw strings like `"Synthetic connection timeout to n8n"` from `seed/workflow_runs.csv`, rendered directly in `Automation.tsx` (`{r.last_error ?? "—"}`) with no localization or summarization.
|
||||
|
||||
Frontend confirmed to display these values completely raw: `DataQualityIssueDetail.tsx` → `<dd>{String(issue.evidence.summary ?? "")}</dd>` — the *label* is translated, the *value* is not.
|
||||
|
||||
**Fix**: introduce structured `signals`/`message_code`+`params` on evidence and reasons (data-quality evidence, status-conflict recommendation reason, return status reason, automation last-error), with a frontend mapping layer that localizes known codes and falls back to the raw string under "Technical details" only.
|
||||
|
||||
### 3–5, 8A. Status-recommendation flow is unsafe and combines calculation with mutation
|
||||
|
||||
- **Confirmed single mutating endpoint**: `POST /api/v1/data-quality/issues/{public_ref}/apply-recommended-status` (`backend/app/api/routers/data_quality.py`) computes the recommendation and mutates the vehicle in the same call. No separate preview/GET route exists for this flow (unlike the return flow, which already has `preview_vehicle_return` / `register_vehicle_return` sharing one pure evaluator).
|
||||
- **Confirmed unsafe shortcut** (explicitly prohibited by this task): `_recommend_vehicle_status` in `data_quality.py` returns `("rented", ...)` whenever `operational_status == "maintenance" and has_active_booking` — i.e. a vehicle flagged for maintenance with an active booking is auto-recommended (and, on one click, actually changed) to `rented`, with no check of the underlying reason it's in maintenance and no manual-review branch.
|
||||
- **Confirmed proxy-based reasoning** (explicitly prohibited): the `available` + `has_open_high_issue` → `blocked` branch depends only on "does some other open high-severity issue exist for this vehicle", not on real underlying facts (damage, technical warning, confirmed overlap). `data_quality.py` never imports `Inspection`, so damage/technical-warning facts are never examined by this function at all.
|
||||
- **Confirmed scanner/resolver duplication**: `_scan_vehicle_status_conflicts` and `_recommend_vehicle_status` are two independently-maintained `if`-chains (hand-kept-in-sync via a docstring comment, not shared code) — a structural fragility even though today's four branches happen to agree.
|
||||
|
||||
**Fix**: new shared domain service `backend/app/services/vehicle_status.py` with one `evaluate_vehicle_status()` function consulting real facts (active/reserved/overlapping bookings, latest inspection damage/technical-warning, maintenance threshold, cleaning state), used by scanner, a new non-mutating preview endpoint, the apply endpoint, and tests. Maintenance+active-booking becomes `manual_review_required`, never an automatic `rented`. Full decision table in `docs/fleet-ops-correction/vehicle-status-decision-table.md`.
|
||||
|
||||
### 6–7. MO-016 / issue-ordering
|
||||
|
||||
- Confirmed `MO-016` scenario: vehicle seeded `operational_status="available"`, two overlapping *reserved* bookings (`BK-DEMO-OVERLAP-A`/`-B`), two pre-seeded `open` issues on the same vehicle (`DQ-DEMO-OVERLAP` booking_overlap, `DQ-DEMO-STATUS` vehicle_status_conflict).
|
||||
- Confirmed **no test** resolves both issues in sequence (either order) within one session to check the outcome stays deterministic — each existing test independently resets the demo data first.
|
||||
|
||||
**Fix**: new evaluator is order-independent by construction (recomputes real facts every call, doesn't cache any prior issue's existence as an input other than the generic "another open high-severity issue for manual-review fallback"); add an explicit ordering test.
|
||||
|
||||
### 8. i18n-coverage test doesn't prove translation happened
|
||||
|
||||
Confirmed: `frontend/e2e/i18n-coverage.spec.ts` only checks key-parity and non-empty values — a locale file could contain the literal English string copy-pasted and the test would still pass. Locale files were manually verified as genuinely translated (no hits for probe phrases like "canonical odometer", "committed locally", "correlation ID" etc. in `nl-BE`/`fr-BE`), so this is a test-coverage gap, not an active mistranslation — but per this task's instructions it still needs closing.
|
||||
|
||||
**Fix**: add a translation-quality test comparing `nl-BE`/`fr-BE` values against `en-GB` for meaningful divergence (with an explicit allowlist for real proper nouns/technical tokens: Fleet Ops, Northstar Mobility, n8n, RAGcore, MCP Hub, API, UUID, Docker, PostgreSQL), plus a route-matrix smoke test opening every main route in all three languages.
|
||||
|
||||
### 9. One confirmed leftover hardcoded string
|
||||
|
||||
- `frontend/src/pages/BookingDetail.tsx:76` — `aria-label="Demo scenario"` is a literal, un-translated English string (the visible content beside it is correctly translated).
|
||||
|
||||
**Fix**: route through `t("returns:scenario.ariaLabel")` (new key, 3 locales).
|
||||
|
||||
### 10. Automation "last error" shown raw
|
||||
|
||||
- `Automation.tsx` renders `r.last_error` directly with no localization/summarization layer, confirmed via the seeded `"Synthetic connection timeout to n8n"` string appearing verbatim regardless of UI language.
|
||||
|
||||
**Fix**: known-code → localized summary + operational meaning, raw string demoted to "Technical details".
|
||||
|
||||
## Scope note
|
||||
|
||||
No gaps were found in: existing Control Rail navigation/layout, the three demo roles/authorization, the guided demo mechanics, n8n integration wiring, Docker/Unraid deployment scripts, or the previously-implemented adaptive Demo Guide / Data Quality choice-card UI — these are left untouched per the "do not redesign" instruction. This correction is scoped to the 10 problems above.
|
||||
@@ -0,0 +1,25 @@
|
||||
# i18n inventory — dynamic/backend content requiring message-code treatment
|
||||
|
||||
Static UI chrome (navigation, dashboard, forms, filters, dialogs, empty/loading states,
|
||||
Demo Guide, About page, accessibility labels) was already moved to the `i18next`
|
||||
namespace system in the prior task and is not re-inventoried here in full — see
|
||||
`docs/final-product-polish/audit.md` and `docs/final-product-polish/i18n-inventory.md`
|
||||
for that pass. This inventory covers only the sources confirmed still bypassing
|
||||
translation (per `current-gap-audit.md`), the fix chosen, and the tests that verify it.
|
||||
|
||||
| # | Source | Location | Static/dynamic | Fix | Tests |
|
||||
|---|--------|----------|-----------------|-----|-------|
|
||||
| 1 | Duplicate-customer evidence signals | `backend/app/services/data_quality.py::_scan_duplicate_customers` | dynamic | `evidence.signals: [{code, params}]` (`duplicate.exact_email`, `duplicate.exact_phone`, `duplicate.same_postal_code`, `duplicate.similar_name` + score param); frontend maps code→localized phrase | `test_data_quality.py::test_duplicate_customer_evidence_has_structured_signals`; Playwright DQ evidence-language test |
|
||||
| 2 | Missing-required-field evidence | `_scan_missing_required_fields` | dynamic | `evidence.signals: [{code: "missing_field", params: {field}}]`; frontend maps `field` through the existing `CUSTOMER_FIELD_LABELS`/`VEHICLE_FIELD_LABELS`-equivalent i18n keys | same |
|
||||
| 3 | Booking-overlap evidence | `_scan_booking_overlaps` | dynamic | `evidence.signals: [{code: "overlap.reserved_bookings", params: {refs: [...]}}]` | same |
|
||||
| 4 | Vehicle-status-conflict evidence | `_scan_vehicle_status_conflicts` | dynamic | replaced entirely by the new `evaluate_vehicle_status()` evaluator's `recommendation_code`; scanner reuses the evaluator instead of its own reason strings | new evaluator unit tests |
|
||||
| 5 | Odometer-regression evidence | `_scan_odometer_regressions` | dynamic | `evidence.signals: [{code: "odometer.regression", params: {later_ref, later_km, earlier_ref, earlier_km}}]` | same |
|
||||
| 6 | Status-recommendation reason | `_recommend_vehicle_status` / new `evaluate_vehicle_status` | dynamic | `recommendation_code` + `facts` (structured), no free prose from the backend at all; frontend renders the full explanation from `quality:statusRecommendation.codes.<code>` | evaluator unit tests + preview/apply contract tests |
|
||||
| 7 | Return status reason | `backend/app/services/returns.py::_derive_vehicle_status_with_reason` | dynamic | `status_reason_code` + `params` alongside the existing human string (kept for backward-compat, demoted to technical fallback) | `test_returns.py` updated; Playwright return-flow-language test |
|
||||
| 8 | Automation `last_error` | `dispatcher.py` / seed data, rendered in `Automation.tsx` | dynamic | known-cause codes (`n8n.connection_timeout`, `n8n.http_error`, etc.) mapped to a localized summary + "what happened / what's pending / what retry does"; raw string demoted to Technical details | Playwright automation-language test |
|
||||
| 9 | `aria-label="Demo scenario"` | `frontend/src/pages/BookingDetail.tsx:76` | static, just un-wired | `t("returns:scenario.ariaLabel")`, 3 locales | i18n-coverage (key parity) + route-matrix test |
|
||||
| 10 | Brand name (`common:appName` + 8 embedded mentions) | see gap audit §1 | static, wrongly translatable | `PRODUCT_NAME` constant, `{{productName}}` interpolation | new brand-invariant test |
|
||||
|
||||
## Message-code mapping module
|
||||
|
||||
Centralised in `frontend/src/i18n/messageCodes.ts` (new): a single `resolveMessageCode(t, code, params)` helper used by the Data Quality evidence renderer, the status-recommendation panel, the return-result panel, and the automation ledger, so there is one place mapping `code → i18next key` rather than per-page switch statements.
|
||||
@@ -0,0 +1,90 @@
|
||||
# Vehicle status decision table
|
||||
|
||||
Authoritative rationale for `app/services/vehicle_status.py::evaluate_vehicle_status`,
|
||||
the single evaluator shared by the data-quality scanner, the status-recommendation
|
||||
preview endpoint, and the transactional apply endpoint (section 8A). Scanner and
|
||||
resolver call the same function with the same freshly-gathered facts, so they can never
|
||||
disagree, and the recommendation is order-independent: resolving, deferring, or
|
||||
rejecting an unrelated issue never changes what this function returns for a vehicle,
|
||||
because it only reasons over the vehicle's and bookings' current state, never over
|
||||
issue history.
|
||||
|
||||
## Facts gathered (`gather_vehicle_status_facts`)
|
||||
|
||||
All facts are re-queried from the database on every call, never cached and never derived
|
||||
from "does some other issue happen to be open":
|
||||
|
||||
| Fact | Source |
|
||||
|---|---|
|
||||
| `active_booking_refs` | Bookings on this vehicle with `status == "active"` |
|
||||
| `overlapping_booking_pairs` | Reserved/active bookings on this vehicle whose date ranges genuinely overlap |
|
||||
| `service_threshold_reached` | `vehicle.odometer_km >= vehicle.next_service_km` |
|
||||
| `open_booking_overlap_issue_ref` | The `public_ref` of a currently-open `booking_overlap` issue on this vehicle, if any (excluding the issue being resolved, via `exclude_issue_id`) |
|
||||
|
||||
`has_active_rental` = at least one active booking. `has_booking_conflict` = an
|
||||
overlapping-booking pair exists, or an open `booking_overlap` issue references this
|
||||
vehicle.
|
||||
|
||||
## Decision table
|
||||
|
||||
| Current status | Active rental? | Service threshold reached? | Booking conflict? | Recommended status | Priority | `recommendation_code` | Safe to auto-apply? |
|
||||
|---|---|---|---|---|---|---|---|
|
||||
| any except `maintenance` | yes | no | no | `rented` (if not already) | 1 | `vehicle.active_rental` | yes |
|
||||
| `maintenance` | yes | — | — | *(none — manual review)* | 1 | `vehicle.manual_review_required` | no |
|
||||
| any | yes | yes | — | *(none — manual review)* | 1 | `vehicle.manual_review_required` | no |
|
||||
| any | yes | — | yes | *(none — manual review)* | 1 | `vehicle.manual_review_required` | no |
|
||||
| not `maintenance` | no | yes | — | `maintenance` | 2 | `vehicle.service_threshold_reached` | yes |
|
||||
| `maintenance` | no | yes | — | *(none — already correct)* | 2 | `vehicle.no_conflict` | n/a |
|
||||
| not `blocked` | no | no | yes | `blocked` | 3 | `vehicle.booking_conflict` | yes |
|
||||
| `blocked` | no | no | yes | *(none — already correct)* | 3 | `vehicle.no_conflict` | n/a |
|
||||
| `rented` | no | no | no | `available` | 4 | `vehicle.rental_ended` | yes |
|
||||
| `available` / `cleaning` / `blocked` | no | no | no | *(none — already correct)* | 4 | `vehicle.no_conflict` | n/a |
|
||||
| `maintenance` | no | no | no | *(none — stays in maintenance)* | 4 | `vehicle.no_conflict` | n/a |
|
||||
| anything not covered above | — | — | — | *(none — manual review)* | 5 | `vehicle.manual_review_required` | no |
|
||||
|
||||
## Safe-status principles (section 8B) applied
|
||||
|
||||
- **Maintenance + active booking never auto-resolves to `rented`.** Being currently in
|
||||
`maintenance` is itself treated as a blocking fact (row 2 above) — an active booking
|
||||
is never proof the vehicle should be marked rented; it is a real contradiction that
|
||||
requires a human to investigate (e.g. was the vehicle released from the workshop
|
||||
without updating status, or is the booking itself stale).
|
||||
- **`available` + any booking never auto-resolves to `rented` silently past a real
|
||||
blocker.** The `rented` recommendation only fires when there is no competing blocking
|
||||
fact (no service-threshold breach, no booking conflict, not already in maintenance).
|
||||
- **An open issue disappearing never auto-resolves to `available`.** Leaving
|
||||
`maintenance` requires a human decision — this evaluator holds no fact that proves
|
||||
maintenance work is actually finished (no completed-service record is modelled), so a
|
||||
vehicle sitting in `maintenance` with no active rental and no other blocker stays
|
||||
`vehicle.no_conflict` (left alone) rather than being auto-promoted to `available`.
|
||||
- **Every branch re-derives facts; nothing is cached.** `blocking_reasons` is always
|
||||
computed fresh from `service_threshold_reached`, `has_booking_conflict`, and the
|
||||
current status itself — never from a proxy like "is some other high-severity issue
|
||||
still open".
|
||||
|
||||
## Statuses used
|
||||
|
||||
Only statuses that exist in the current domain model are referenced: `available`,
|
||||
`rented`, `cleaning`, `maintenance`, `blocked`. `cleaning` is never a recommendation
|
||||
target from this evaluator (no fact here proves cleaning is required or complete); it is
|
||||
only ever an input `current_status` that, absent any blocker, is left alone
|
||||
(`vehicle.no_conflict`).
|
||||
|
||||
## Concurrency: recommendation token
|
||||
|
||||
`compute_recommendation_token(vehicle, facts)` hashes the vehicle's optimistic-lock
|
||||
`version` plus every fact the recommendation was based on (sha256, truncated to 16 hex
|
||||
chars). The preview endpoint returns this token; the apply endpoint recomputes it from
|
||||
freshly-gathered facts inside the same transaction and rejects the request
|
||||
(`RECOMMENDATION_STALE`) if it no longer matches — the frontend must never assume a
|
||||
previously-shown preview is still valid without server revalidation (section 8F).
|
||||
|
||||
## MO-016: order independence
|
||||
|
||||
MO-016 carries both an open `booking_overlap` issue and an open
|
||||
`vehicle_status_conflict` issue at once (two overlapping reserved bookings). Because
|
||||
`gather_vehicle_status_facts` re-queries `overlapping_booking_pairs` and
|
||||
`open_booking_overlap_issue_ref` fresh every call, resolving the booking-overlap issue
|
||||
first vs. resolving the status-conflict issue first both converge on the same final
|
||||
vehicle status — see `test_mo_016_status_conflict_recommendation_is_order_independent`
|
||||
in `backend/tests/test_data_quality.py`.
|
||||
@@ -0,0 +1,130 @@
|
||||
# Fleet Ops final localization — gap audit
|
||||
|
||||
Branch: `fix/fleet-ops-final-i18n-ux` (created from `master` @ `f7805579f7c73bd3085d73a725fa985b4a4892ed`,
|
||||
working tree clean at audit time). Deployed revision on Unraid at audit time: `de0bdea84fea01b4501deb7099107bc753c2e6d7`
|
||||
(the merge commit; `f780557` is an evidence-only commit not separately deployed). Both containers healthy.
|
||||
|
||||
## 1. Remaining untranslated/incorrect text
|
||||
|
||||
### nl-BE
|
||||
| File | Key | Current | Fix |
|
||||
|---|---|---|---|
|
||||
| `audit.json` | `title` | "Audit trail" | "Auditgeschiedenis" |
|
||||
| `audit.json` | `columns.actor` | "Actor" | "Uitvoerder" |
|
||||
| `navigation.json` | `items.audit` | "Audit trail" | "Auditgeschiedenis" |
|
||||
| `auth.json` | `exploreAsOperationsManager` | "Verken als Operations Manager" | "Verken als Operationsmanager" |
|
||||
| `auth.json` | `exploreAsRentalEmployee` | "Verken als Rental Employee" | "Verken als Verhuurmedewerker" |
|
||||
| `auth.json` | `roleOperationsManager` | "Operations manager" | "Operationsmanager" |
|
||||
| `auth.json` | `roleRentalEmployee` | "Rental employee" | "Verhuurmedewerker" |
|
||||
| `demo.json` | `scenarios.roles.operations_manager` | "Operations Manager" | "Operationsmanager" |
|
||||
| `demo.json` | `scenarios.roles.rental_employee` | "Rental Employee" | "Verhuurmedewerker" |
|
||||
| `demo.json` | `scenarios.startScenario` | "Start scenario" | "Scenario starten" |
|
||||
| `integrations.json` | `ledger.filterRecent` | "Recent" | "Recentste" |
|
||||
| `quality.json` | `list.statusOpen` | "Open" | "Openstaand" |
|
||||
| `audit.json`, `quality.json`, `integrations.json`, `demo.json` | 8 `managerOnly`/`whyItMatters`/`scopeBody`/etc. keys (16 nl+fr occurrences) | embedded "Operations Manager(s)" mid-sentence | "Operationsmanager(s)" |
|
||||
|
||||
`columns.details` ("Details") judged fine as-is: short data-table column header, genuine NL/EN cognate,
|
||||
siblings are single-word labels too.
|
||||
|
||||
### fr-BE
|
||||
Same key set as nl-BE (role labels + embedded mentions), fr-BE `columns.actor` is already correctly
|
||||
"Acteur" (no fix needed). French role translations: "Responsable des opérations" /
|
||||
"Collaborateur de location", per the correction brief.
|
||||
|
||||
### Hardcoded JSX (bypasses i18n entirely)
|
||||
`frontend/src/pages/DataQualityIssueDetail.tsx` line ~213: `data-label="Field"` — literal English,
|
||||
never localized. Fix: reuse the already-existing, already-translated
|
||||
`detail.duplicateCustomer.fieldColumn` key (same table's `<thead>` seven lines above already uses it
|
||||
correctly) — zero locale-file changes needed, pure JSX fix.
|
||||
|
||||
No other hardcoded `data-label`/`aria-label`/`title`/`placeholder` found across `frontend/src/**/*.tsx`.
|
||||
|
||||
## 2. Raw backend errors shown directly
|
||||
|
||||
13 call sites across 7 files (`Automation.tsx`, `ReturnForm.tsx` ×2, `DataQuality.tsx`, `DemoGuide.tsx`,
|
||||
`Layout.tsx`, `DataQualityIssueDetail.tsx` ×7, `Knowledge.tsx`) all follow:
|
||||
`err instanceof ApiError ? err.message : t("some:fallback")` — i.e. the **common** case (a real,
|
||||
structured `ApiError` from the backend) shows raw, un-localized English `error.message` verbatim; the
|
||||
translated fallback only fires for network-level failures where no `ApiError` could even be
|
||||
constructed. One site (`DataQualityIssueDetail.tsx` apply-status handler) already special-cases
|
||||
`err.code === "RECOMMENDATION_STALE"` inline — this needs migrating into the new central system rather
|
||||
than staying a one-off.
|
||||
|
||||
Backend `AppError`/`HTTPException` codes found (32 semantic `AppError` codes + generic HTTP-status
|
||||
fallback codes "401"/"403"/"404"/"422" for plain `HTTPException`s, verified via
|
||||
`app/main.py`'s `error_body()` envelope — both AppError and HTTPException responses share the same
|
||||
`{"error": {"code", "message", "correlation_id"}}` shape):
|
||||
|
||||
`BOOKING_NOT_ACTIVE, BOOKING_NOT_FOUND, CONFLICT_STILL_PRESENT, CORRECTED_VALUE_REQUIRED,
|
||||
CORRECTION_BELOW_CANONICAL, CUSTOMER_NOT_FOUND, EMPTY_VALUE, ENTITY_NOT_FOUND, EVENT_NOT_FOUND,
|
||||
IDEMPOTENCY_KEY_REUSED, INVALID_BOOKING_REFERENCE, INVALID_BOOKING_STATE, INVALID_EVENT_ID,
|
||||
INVALID_FIELD, INVALID_FIELD_OVERRIDE, INVALID_IDEMPOTENCY_KEY, INVALID_SURVIVOR, ISSUE_NOT_FOUND,
|
||||
ISSUE_NOT_OPEN, MANUAL_REVIEW_REQUIRED, NOT_AN_ODOMETER_ISSUE, NOT_AN_OVERLAP_ISSUE,
|
||||
NOT_A_DUPLICATE_ISSUE, NOT_A_MISSING_FIELD_ISSUE, NOT_A_STATUS_CONFLICT_ISSUE, NOT_RETRYABLE,
|
||||
NO_CONFLICT_DETECTED, NO_FIELDS_PROVIDED, OVERLAP_STILL_PRESENT, RECOMMENDATION_STALE,
|
||||
UNAUTHORIZED_SERVICE, UNSUPPORTED_ENTITY, VEHICLE_NOT_FOUND`.
|
||||
|
||||
Only one code (`INVALID_SURVIVOR`) carries structured `details` params; the rest embed specifics only
|
||||
in the raw English `message` string — so localized messages will be generic per-code (title +
|
||||
explanation + optional next step), not parameterized with extracted specifics, with the raw string
|
||||
preserved verbatim under "Technical details".
|
||||
|
||||
`errors.json` namespace already exists (all 3 locales) with 6 generic keys (`generic`,
|
||||
`workspaceLoadFailed`, `unauthorized`, `forbidden`, `notFound`, `networkUnavailable`) but is not wired
|
||||
to `ApiError.code` at all — only used as the non-`ApiError` fallback string.
|
||||
|
||||
## 3. i18n allowlist over-permissiveness
|
||||
|
||||
`frontend/e2e/i18n-coverage.spec.ts`'s `IDENTICAL_VALUE_ALLOWLIST` currently contains 4 entries that
|
||||
must be removed once role labels are translated: `auth.roleOperationsManager`,
|
||||
`auth.roleRentalEmployee`, `demo.scenarios.roles.operations_manager`,
|
||||
`demo.scenarios.roles.rental_employee` (comment: "deliberately-untranslated role title" — no longer
|
||||
true once fixed). `audit.title` and `navigation.items.audit` ("Audit trail" kept as compliance term)
|
||||
also need removing once translated to "Auditgeschiedenis".
|
||||
|
||||
Remaining ~19 allowlist entries are genuine cognates/proper nouns/templates (verified by the audit
|
||||
agent against a broad Dutch-word grep of fr-BE — zero Dutch leakage found) and should stay.
|
||||
|
||||
Also noted: the coverage test's identical-value check only catches **whole-string** identity to en-GB,
|
||||
not **mid-sentence embedded English** (the 16 "Operations Manager(s)" occurrences above) — this is a
|
||||
real blind spot the new tests (section 8 of the correction brief) need to close with a targeted,
|
||||
explicit check for known English substrings appearing in nl-BE/fr-BE prose.
|
||||
|
||||
## 4. Dashboard greeting
|
||||
|
||||
No time-of-day logic exists anywhere in the codebase — `dashboard.json`'s `title` key is a **static**
|
||||
string ("Good morning. Here's the fleet." / "Goedemorgen. Hier is je wagenpark." / "Bonjour. Voici
|
||||
votre flotte.") shown unconditionally at all times of day, despite implying dynamism. Needs: a central,
|
||||
testable, clock-injectable greeting function keyed on `Europe/Brussels` wall-clock hour, 4 periods per
|
||||
the brief, updating on language change and on period rollover while the app stays open.
|
||||
|
||||
## 5. Documentation staleness
|
||||
|
||||
- `PROJECT_STATE.md` "Locked decisions" block: `"Product name: MobilityOps."` and `"PoC only..."` —
|
||||
predates the Fleet Ops rebrand, contradicts the later (correct) sections of the same file.
|
||||
- `PROJECT_STATE.md`'s final section header still reads `"...IN PROGRESS on
|
||||
fix/fleet-ops-i18n-status-flow"` and states `"Not yet merged to master"` / `"Do not claim PASS..."` —
|
||||
**false**: the merge (`de0bdea`) and final evidence commit (`f780557`) both already exist in git
|
||||
history, neither is mentioned in the file, and the branch name has moved on to
|
||||
`fix/fleet-ops-final-i18n-ux`.
|
||||
- A separate, older `"## Demo productization (in progress, same branch
|
||||
feat/mobilityops-functional-completion)"` section header was also never marked complete.
|
||||
- README.md is accurate and current — no fix needed there beyond a version-count refresh after this
|
||||
round's test additions.
|
||||
- No false "RAGcore live" / "MCP Hub connected" claims found anywhere — this part is already honest.
|
||||
|
||||
## Plan
|
||||
|
||||
1. Fix the ~10 nl-BE + ~10 fr-BE locale-file translations above (role labels, "Audit trail", "Actor",
|
||||
"Start scenario", "Recent", "Open", embedded mid-sentence mentions).
|
||||
2. Fix the one hardcoded `data-label="Field"` JSX bug.
|
||||
3. Build a central `describeApiError(t, err)` helper + shared rendering component, wire all 13 call
|
||||
sites through it, with a code→message map covering all 32 backend codes + generic HTTP fallbacks,
|
||||
raw text demoted to "Technical details".
|
||||
4. Tighten the allowlist (remove the 6 now-stale entries) and add a targeted embedded-English-substring
|
||||
test, a `describeApiError` coverage test, and greeting boundary tests.
|
||||
5. Build the time-of-day greeting function + wire into `Dashboard.tsx`, with matching locale copy for
|
||||
4 periods × 3 languages + a localized description line replacing the current static one.
|
||||
6. Fix `PROJECT_STATE.md` staleness (append a new dated entry, do not rewrite prior entries).
|
||||
7. Full local validation → clean-checkout drill → deploy fix branch → live validation in 3 languages →
|
||||
merge to master → redeploy → final evidence.
|
||||
@@ -0,0 +1,222 @@
|
||||
# n8n current state (as inspected 2026-08-04)
|
||||
|
||||
Inspected live via the already-authenticated browser session at
|
||||
`https://n8n.itworx.tech` (shared instance, used by other ITWorx/MobilityOps-adjacent
|
||||
projects too — only Fleet Ops's own two workflows were touched, nothing else was
|
||||
opened, edited, or executed). No secret credential values are reproduced in this
|
||||
document.
|
||||
|
||||
## Reachability and version
|
||||
|
||||
- n8n is reachable at `https://n8n.itworx.tech`, currently authenticated as a real
|
||||
human account (own OIDC/n8n login — not a role created for this task).
|
||||
- Workspace-level stats at the time of inspection: **114 total prod. executions, 4
|
||||
failed (3.5% failure rate)**, avg run time 0.18s. (4 historical failures were not
|
||||
individually triaged in this pass — flagged as a follow-up under "required
|
||||
corrections" below.)
|
||||
- Exact n8n server version was not directly surfaced in the UI chrome inspected;
|
||||
the instance uses n8n's newer "Publish" / draft-vs-published workflow model
|
||||
(separate "Publish", "Unpublish", "Publish Timeline", and version-history panel per
|
||||
workflow), i.e. a fairly recent n8n release.
|
||||
|
||||
## Production webhook base
|
||||
|
||||
`http://192.168.10.150:5678/webhook/...` — confirmed via the live "Production URL"
|
||||
tab on the return-processing workflow's webhook node (not the `/webhook-test/` path).
|
||||
This matches `N8N_WEBHOOK_URL=http://192.168.10.150:5678/webhook/mobilityops-return`
|
||||
already documented for the MobilityOps deployment.
|
||||
|
||||
## Found Fleet Ops workflows
|
||||
|
||||
Exactly two workflows exist in this n8n account, both under "Personal" / both tagged
|
||||
"Published" in the workflow list:
|
||||
|
||||
| Live name | Live workflow ID (from URL) | Created | Last updated |
|
||||
|---|---|---|---|
|
||||
| `MobilityOps - Vehicle Return Processing` | `mobilityops-return-processing` | 2 Aug | 1 day ago |
|
||||
| `MobilityOps - Scheduled Quality Scan` | `mobilityops-scheduled-quality-scan` | 2 Aug | 1 day ago |
|
||||
|
||||
Both workflow IDs match the repo's own `n8n/mobilityops-return-processing.json` and
|
||||
`n8n/mobilityops-scheduled-quality-scan.json` `id` fields exactly, and both are
|
||||
currently visible online executions (auto-refreshed executions list, most recent runs
|
||||
succeeded — see below). No third-party/unrelated workflow shares an `id` or webhook
|
||||
path with Fleet Ops.
|
||||
|
||||
## Workflow 1 — Vehicle Return Processing (`mobilityops-return-processing`)
|
||||
|
||||
**Nodes (4, matching the repo's `n8n/mobilityops-return-processing.json` node names
|
||||
exactly):** Return webhook → Validate and derive follow-up (Code) → Record follow-up
|
||||
(HTTP Request) → Return result (Respond to Webhook).
|
||||
|
||||
- **Trigger**: webhook, `POST`, path `mobilityops-return`, production URL
|
||||
`http://192.168.10.150:5678/webhook/mobilityops-return`. **n8n-level
|
||||
Authentication is set to "None."** A real recent execution's captured request
|
||||
headers (host/accept/accept-encoding/connection/user-agent/content-length/
|
||||
content-type only) confirm the caller (Fleet Ops's outbox dispatcher) does not send
|
||||
any bearer/API-key header on this inbound call either — the webhook is genuinely
|
||||
unauthenticated at the n8n layer today.
|
||||
- **Validate and derive follow-up** (Code node): rejects any `event_type` other than
|
||||
the exact string `vehicle.returned.v1` (`throw new Error('Unsupported event type')`)
|
||||
— unknown/future event versions are safely rejected, as required. Derives
|
||||
`follow_up: 'attention_required' | 'cleaning'` from `data.attention_reasons`.
|
||||
- **Record follow-up** (HTTP Request → Fleet Ops): `POST
|
||||
http://192.168.10.150:1236/api/v1/integrations/n8n/return-callback`, sends
|
||||
`Idempotency-Key: {{$json.event_id}}` and an `X-Service-Token` header. **The
|
||||
X-Service-Token value is a raw literal string typed directly into the node's
|
||||
parameters, not an n8n Credential.** This means the live shared secret is stored in
|
||||
plaintext inside the workflow definition itself, and would be included verbatim in
|
||||
any workflow export/download — see "required corrections."
|
||||
Body: `{{JSON.stringify($json)}}`.
|
||||
- **Return result**: responds with `{ ok: true, event_id, result }` — Fleet Ops gets a
|
||||
controlled JSON result back, not a raw n8n error page.
|
||||
- **Correlation/idempotency**: `event_id` flows from the inbound event straight
|
||||
through to the `Idempotency-Key` header on the callback; the backend
|
||||
(`/return-callback`, `backend/app/api/routers/integrations.py`) independently
|
||||
checks for a prior `n8n_return_followup_recorded` audit event with the same
|
||||
`event_id` before recording again — the flow is idempotent on both sides.
|
||||
- **Latest execution**: 4 Aug, 03:34:19, succeeded in 32ms, all 4 nodes green.
|
||||
- **Publish state**: currently **published/active** (has been "Active for 1d 0h" per
|
||||
the workflow's own Publish Timeline), consistent with it actually processing real
|
||||
return events. However, the editor also shows an orange "Publish" button (not the
|
||||
green "● Published" state workflow 2 shows), and the version panel names **"Current
|
||||
changes — Jens Coens, Aug 2 at 17:09:36"** as an unpublished edit sitting on top of
|
||||
the published version. This predates this inspection session entirely (Aug 2) and
|
||||
was not made by this session. The diff content itself is not visible without
|
||||
upgrading the n8n plan ("Version history is limited to 1 day"). **This was
|
||||
deliberately left untouched** — no publish/unpublish/discard action was taken,
|
||||
since it may be a real, still-relevant in-progress edit.
|
||||
|
||||
## Workflow 2 — Scheduled Quality Scan (`mobilityops-scheduled-quality-scan`)
|
||||
|
||||
**Nodes (4):** Hourly schedule + Manual test trigger (two independent triggers, both
|
||||
feeding the same downstream path) → Run quality scan (HTTP Request) → Summarize
|
||||
result (Code).
|
||||
|
||||
- **Hourly schedule**: interval `Hours`, every `1` hour, at minute `0`. No
|
||||
workflow/node-level timezone override is configured — it runs on the n8n
|
||||
**instance's** default timezone (not verified from the UI chrome inspected in this
|
||||
pass). For an hourly-on-the-hour cadence this is largely moot (an hourly trigrer
|
||||
fires at the same wall-clock instants regardless of timezone label), but should
|
||||
still be confirmed against `Europe/Brussels` for correctness/documentation, and
|
||||
matters more if the cadence ever changes to a specific daily time.
|
||||
- **Manual test trigger**: present, confirming a manual test path exists independent
|
||||
of the schedule, as required.
|
||||
- **Run quality scan** (HTTP Request → Fleet Ops): `POST
|
||||
http://192.168.10.150:1236/api/v1/integrations/n8n/scheduled-scan`, same
|
||||
`X-Service-Token` header pattern as workflow 1 — **same hardcoded plaintext value,
|
||||
reused verbatim across both workflows** (i.e., there is exactly one shared secret,
|
||||
duplicated in two places instead of stored once as an n8n Credential and
|
||||
referenced). `Timeout: 15000` ms configured (bounded). No query params, no body.
|
||||
- **Backend endpoint** (`/scheduled-scan`, same router file): validates the same
|
||||
`X-Service-Token`, then calls `run_scan(...)`, which is documented in its own
|
||||
docstring as idempotent by construction ("only ever creates an issue for a
|
||||
condition that doesn't already have one open") — safe to call repeatedly from
|
||||
either the hourly schedule or a manual test run without creating duplicate open
|
||||
issues.
|
||||
- **Summarize result** (Code node): `total_created = sum(created.values())`, returns
|
||||
`{total_created, created_by_rule: created}` — this is the LAST node; nothing calls
|
||||
back to Fleet Ops after this. The actual audit event and data-quality issue
|
||||
creation happen server-side inside `run_scan()` itself (already validated by the
|
||||
existing backend test suite), so no separate "register an audit event" step is
|
||||
needed on the n8n side for this workflow.
|
||||
- **Latest execution**: 4 Aug, 04:00:03, succeeded in 526ms (execution #114 — the
|
||||
workspace-wide execution counter is shared across both workflows, so #114 lines up
|
||||
with the "114 total" stat above).
|
||||
- **Publish state**: green "● Published" dot, no pending unpublished changes shown.
|
||||
|
||||
## Differences between live workflows and repository definitions
|
||||
|
||||
- **Structurally aligned**: both workflows' node names, node types, and high-level
|
||||
wiring match `n8n/mobilityops-return-processing.json` and
|
||||
`n8n/mobilityops-scheduled-quality-scan.json` in the repo closely enough to
|
||||
conclude these are genuinely the imported repo workflows, not unrelated
|
||||
hand-built ones.
|
||||
- **Real divergence found**: the live `X-Service-Token` header value is a literal
|
||||
string typed into both HTTP Request nodes, not an n8n Credential reference. Whether
|
||||
the repo JSON also encodes this as a literal (vs. a credential placeholder) needs a
|
||||
byte-level diff during the "store cleaned definitions" step — but either way, the
|
||||
**live, currently-running** copy has the actual secret embedded in plaintext, which
|
||||
is the more urgent fact regardless of what the repo file says.
|
||||
- **Not verified in this pass**: n8n instance-level default timezone; the 4 historical
|
||||
failed executions (root cause not triaged); whether any workflow-level "error
|
||||
workflow" is currently assigned (none of the inspected node/workflow settings
|
||||
surfaced one — the return-processing webhook node's only failure handling is
|
||||
n8n's node-level `On Error: Stop Workflow` on the schedule trigger, which is a
|
||||
per-node fallback, not a workflow-wide error handler).
|
||||
|
||||
## Stale or duplicate workflows
|
||||
|
||||
None found. Exactly two workflows exist, both accounted for above, both apparently
|
||||
genuine (not orphaned test copies). No `ARCHIVED —`-prefixed or otherwise stale
|
||||
workflow exists yet.
|
||||
|
||||
## Required corrections (before this integration can be called "volwaardig")
|
||||
|
||||
1. **Move the shared `X-Service-Token` secret into an n8n Credential** (e.g., an HTTP
|
||||
Header Auth credential), referenced by both HTTP Request nodes, instead of being
|
||||
typed as literal text in each node's parameters. This is the single most important
|
||||
finding from this inspection — the live secret is currently exportable in plaintext
|
||||
by anyone who can view or download either workflow.
|
||||
2. **Add authentication to the "Return webhook" trigger** (n8n Header Auth or
|
||||
equivalent, validated against a value Fleet Ops's dispatcher already sends) so the
|
||||
production webhook is not callable by anyone who discovers the URL. Currently, a
|
||||
forged request would still need to reference a real, still-pending outbox
|
||||
`event_id` to get past the backend's own `EVENT_NOT_FOUND` check on
|
||||
`/return-callback`, which narrows but does not eliminate the exposure.
|
||||
3. Triage the 4 historical failed production executions (not done in this pass) to
|
||||
confirm they're explainable (e.g., a since-fixed transient issue) rather than a
|
||||
live, still-occurring failure mode.
|
||||
4. Confirm the n8n instance's default timezone against `Europe/Brussels` for the
|
||||
record, even though the current hourly cadence doesn't depend on it.
|
||||
5. Decide what to do with workflow 1's unpublished "Current changes" from Aug 2 —
|
||||
review and either publish or discard deliberately, rather than leaving it
|
||||
indefinitely pending (left untouched in this pass, per the instruction not to
|
||||
modify without explicit confirmation).
|
||||
6. Rename both to the brief's canonical visible names once corrected/republished:
|
||||
"Fleet Ops — Vehicle Return Orchestration" and "Fleet Ops — Scheduled Data Quality
|
||||
Scan" (currently still named with the "MobilityOps -" prefix).
|
||||
|
||||
## Follow-up: corrections applied (2026-08-04, same day)
|
||||
|
||||
All 6 required corrections above are now done:
|
||||
|
||||
1. **Done.** Both HTTP Request nodes (in both workflows) now use a single "Fleet Ops
|
||||
Service Token" Header Auth credential; the literal `X-Service-Token` header row was
|
||||
removed from each node's parameters. Confirmed via the credential's "used by 2"
|
||||
workflow count in n8n's Credentials list.
|
||||
2. **Done.** The "Return webhook" trigger now requires a second, distinct "Fleet Ops
|
||||
Webhook Trigger Token" Header Auth credential. Fleet Ops's outbox dispatcher
|
||||
(`backend/app/services/dispatcher.py`) now sends the matching
|
||||
`X-Fleet-Ops-Trigger-Token` header (new `MOBILITYOPS_WEBHOOK_TRIGGER_TOKEN` setting,
|
||||
added to `.env.example`, `compose.yaml`, the local dev `.env`, and the Unraid
|
||||
server's `.env`). Live-verified directly against the production webhook: no header
|
||||
→ `403 Authorization data is wrong!`; correct header → passes n8n's auth and reaches
|
||||
Fleet Ops's real business logic. Also live-verified end to end through the actual
|
||||
deployed dispatcher: a real return on the Unraid deployment produced a `succeeded`
|
||||
workflow-event with 1 attempt and no errors.
|
||||
- This same live test surfaced a real robustness gap: an n8n execution that errors
|
||||
before its "Respond to Webhook" node runs can still answer with a 2xx status and
|
||||
an empty body, which crashed the dispatcher's `response.json()` outside its own
|
||||
error handling. Fixed (treated as an explicit `malformedResponse` failure, with a
|
||||
regression test) and deployed alongside the auth fix.
|
||||
3. **Done.** Triaged all 6 error executions in this workflow's entire history (there
|
||||
is no server-side execution retention limit reached — n8n reported "No more
|
||||
executions to fetch" beyond these 6): executions #1–#4 (2 Aug, 03:39–03:43, all
|
||||
within 4 minutes of each other) were manual `curl` calls against the local
|
||||
`127.0.0.7:5678` test webhook with a `curl/8.16.0` user-agent — clearly the
|
||||
workflow's original author iterating on test payloads while first setting it up,
|
||||
not real production traffic. Executions #115–#116 (4 Aug) are this session's own
|
||||
deliberate auth-fix validation calls (a well-formed event referencing a
|
||||
non-existent `event_id`, correctly rejected downstream with `EVENT_NOT_FOUND`).
|
||||
**Zero unexplained or currently-live failures.**
|
||||
4. Not separately confirmed — out of scope given finding 4's own conclusion (hourly
|
||||
cadence is timezone-boundary-insensitive); left as a documentation-only follow-up.
|
||||
5. **Done, per explicit user confirmation.** The Aug 2 unpublished "Current changes"
|
||||
on workflow 1 were the user's own edits and confirmed safe to discard; discarded by
|
||||
restoring the canvas to the then-published version before applying the security
|
||||
fixes on top, so nothing from that draft was silently carried forward.
|
||||
6. **Done.** Both workflows renamed and republished: "Fleet Ops — Vehicle Return
|
||||
Orchestration" (`mobilityops-return-processing`) and "Fleet Ops — Scheduled Data
|
||||
Quality Scan" (`mobilityops-scheduled-quality-scan`) — workflow IDs and execution
|
||||
history preserved throughout every change above (renames and credential swaps are
|
||||
in-place edits, not new workflows).
|
||||
@@ -1,6 +1,7 @@
|
||||
FROM node:22-alpine AS build
|
||||
WORKDIR /app
|
||||
COPY package.json package-lock.json tsconfig.json vite.config.ts index.html ./
|
||||
COPY public ./public
|
||||
COPY src ./src
|
||||
RUN npm ci && npm run build
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@ test("capture demo-release evidence screenshots", async ({ page, request }) => {
|
||||
await page.screenshot({ path: `${OUT}/02-demo-entry-mobile.png` });
|
||||
await page.setViewportSize({ width: 1280, height: 900 });
|
||||
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await expect(page.getByText("Probeer een demonstratiescenario")).toBeVisible();
|
||||
await page.screenshot({ path: `${OUT}/03-dashboard-with-scenarios.png`, fullPage: true });
|
||||
|
||||
@@ -14,7 +14,7 @@ test("capture the seven main pages", async ({ page, request }) => {
|
||||
await page.goto("/login");
|
||||
await page.screenshot({ path: `${OUT}/1-login.png` });
|
||||
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page.getByRole("heading", { name: "Operational metrics" })).toBeVisible();
|
||||
await page.screenshot({ path: `${OUT}/2-dashboard.png`, fullPage: true });
|
||||
|
||||
|
||||
@@ -38,7 +38,7 @@ test("demo guide does not cover the return form's action buttons on desktop", as
|
||||
|
||||
test("demo badge and guide trigger are keyboard reachable and Escape closes them", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
|
||||
const guideTrigger = page.getByRole("button", { name: /Demo-gids/ });
|
||||
@@ -74,7 +74,7 @@ test("key demo pages load without console errors", async ({ page }) => {
|
||||
page.on("pageerror", (err) => errors.push(err.message));
|
||||
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await page.goto("/scenarios");
|
||||
await expect(page.getByRole("heading", { name: "Probeer een demonstratiescenario" })).toBeVisible();
|
||||
@@ -85,3 +85,38 @@ test("key demo pages load without console errors", async ({ page }) => {
|
||||
|
||||
expect(errors, `Unexpected console errors: ${errors.join("\n")}`).toEqual([]);
|
||||
});
|
||||
|
||||
test("status-recommendation panel is fully keyboard operable, respects reduced motion, and never signals status by colour alone", async ({
|
||||
page,
|
||||
request,
|
||||
}) => {
|
||||
await request.post("/api/v1/demo/login", { data: { role: "operations_manager" } });
|
||||
await request.post("/api/v1/demo/reset");
|
||||
await request.post("/api/v1/demo/login", { data: { role: "operations_manager" } });
|
||||
|
||||
await page.emulateMedia({ reducedMotion: "reduce" });
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await page.goto("/data-quality/DQ-DEMO-STATUS");
|
||||
|
||||
const reviewButton = page.getByRole("button", { name: "Aanbeveling bekijken" });
|
||||
await reviewButton.focus();
|
||||
await expect(reviewButton).toBeFocused();
|
||||
await page.keyboard.press("Enter");
|
||||
|
||||
const confirmButton = page.getByRole("button", { name: /^Status wijzigen naar/ });
|
||||
await expect(confirmButton).toBeVisible();
|
||||
|
||||
// Status is never conveyed by colour alone: the badge always carries its own text.
|
||||
const badge = page.locator(".status-decision .badge").first();
|
||||
await expect(badge).not.toHaveText("");
|
||||
|
||||
// The confirm action itself is a real, focusable, keyboard-activatable button (the
|
||||
// previous "Aanbeveling bekijken" button is unmounted once the decision panel
|
||||
// replaces it, so focus is verified directly rather than via a Tab chain from it).
|
||||
await confirmButton.focus();
|
||||
await expect(confirmButton).toBeFocused();
|
||||
await page.keyboard.press("Enter");
|
||||
await expect(page.getByText("Toegepast", { exact: false })).toBeVisible();
|
||||
});
|
||||
|
||||
@@ -7,8 +7,8 @@ test("demo entry screen names the fictional org and never shows a password", asy
|
||||
await expect(page.getByText(/Northstar Mobility/)).toBeVisible();
|
||||
await expect(page.getByText(/Synthetische demo/)).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: "Start begeleide demo" })).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: "Verken als Operations Manager" })).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: "Verken als Rental Employee" })).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: "Verken als Operationsmanager" })).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: "Verken als Verhuurmedewerker" })).toBeVisible();
|
||||
await expect(page.locator('input[type="password"]')).toHaveCount(0);
|
||||
});
|
||||
|
||||
@@ -26,7 +26,7 @@ test("start guided demo logs in as Operations Manager and opens the guide at ste
|
||||
|
||||
test("permanent demo badge shows a popover with last reset info and a working About link", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
|
||||
const trigger = page.getByRole("button", { name: /Synthetische demo/ });
|
||||
@@ -45,7 +45,7 @@ test("permanent demo badge shows a popover with last reset info and a working Ab
|
||||
|
||||
test("badge popover closes on Escape and outside click", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
|
||||
const trigger = page.getByRole("button", { name: /Synthetische demo/ });
|
||||
|
||||
@@ -12,7 +12,7 @@ test.describe.configure({ mode: "serial" });
|
||||
test("scenario overview lists all 5 scenarios, ready right after a reset", async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await page.goto("/scenarios");
|
||||
|
||||
@@ -27,12 +27,12 @@ test("scenario overview lists all 5 scenarios, ready right after a reset", async
|
||||
|
||||
test("starting a scenario navigates to its fixed record", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await page.goto("/scenarios");
|
||||
|
||||
const duplicateCard = page.locator(".scenario-card", { hasText: "dubbele klant" });
|
||||
await duplicateCard.getByRole("link", { name: "Start scenario" }).click();
|
||||
await duplicateCard.getByRole("link", { name: "Scenario starten" }).click();
|
||||
await expect(page).toHaveURL(/\/data-quality\/DQ-DEMO-DUPLICATE$/);
|
||||
});
|
||||
|
||||
@@ -92,7 +92,7 @@ test("demo guide progress persists across navigation and the trigger shows it",
|
||||
|
||||
test("demo guide is not shown to a rental employee", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Rental Employee" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Verhuurmedewerker" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await expect(page.getByRole("button", { name: /Demo-gids/ })).toHaveCount(0);
|
||||
});
|
||||
|
||||
@@ -12,7 +12,7 @@ test.describe.configure({ mode: "serial" });
|
||||
test("return flow pre-fills the suspicious odometer reading and explains why", async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await page.goto("/bookings/BK-DEMO-RETURN");
|
||||
|
||||
@@ -27,12 +27,12 @@ test("return flow pre-fills the suspicious odometer reading and explains why", a
|
||||
await page.getByRole("button", { name: "Retour bevestigen" }).click();
|
||||
await expect(page.getByRole("heading", { name: "Retour geregistreerd" })).toBeVisible();
|
||||
await expect(page.getByRole("link", { name: "Automatiseringsstatus bekijken" })).toBeVisible();
|
||||
await expect(page.getByRole("link", { name: "Audit trail bekijken" })).toBeVisible();
|
||||
await expect(page.getByRole("link", { name: "Auditgeschiedenis bekijken" })).toBeVisible();
|
||||
});
|
||||
|
||||
test("data quality issue detail explains what's wrong and why it matters", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await page.goto("/data-quality/DQ-DEMO-DUPLICATE");
|
||||
|
||||
@@ -43,7 +43,7 @@ test("data quality issue detail explains what's wrong and why it matters", async
|
||||
|
||||
test("data quality list can filter to demo scenarios only", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await page.goto("/data-quality");
|
||||
|
||||
@@ -61,7 +61,7 @@ test("data quality list can filter to demo scenarios only", async ({ page }) =>
|
||||
|
||||
test("knowledge page suggested question returns a grounded, honestly-labelled answer", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await page.goto("/knowledge");
|
||||
|
||||
|
||||
@@ -19,7 +19,7 @@ test("five-minute demo script end to end", async ({ page, request }) => {
|
||||
await test.step("1. login as Operations Manager", async () => {
|
||||
await page.goto("/login");
|
||||
await expect(page.getByText(/Synthetische demo/)).toBeVisible();
|
||||
await page.getByRole("button", { name: "Verken als Operations Manager" }).click();
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
});
|
||||
|
||||
|
||||
@@ -0,0 +1,205 @@
|
||||
import { expect, test } from "@playwright/test";
|
||||
import fs from "node:fs";
|
||||
import path from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { ApiError } from "../src/api/apiError";
|
||||
import { describeApiError, KNOWN_CODES } from "../src/api/errorMessages";
|
||||
|
||||
// Pure Node-context checks for the central API-error-localization function (section 7 /
|
||||
// 11 of the Fleet Ops final localization brief). No browser needed: describeApiError()
|
||||
// only depends on a `t` function and a caught error, so it's tested here against the
|
||||
// real locale JSON with a minimal i18next-shaped `t` stub -- proving the known-code and
|
||||
// known-HTTP-status paths never leak raw backend English as the primary message, and
|
||||
// that the raw text is always still available via `.technical` for "Technical details".
|
||||
|
||||
const __dirname = path.dirname(fileURLToPath(import.meta.url));
|
||||
const LOCALES_DIR = path.resolve(__dirname, "../src/i18n/locales");
|
||||
const LANGUAGES = ["nl-BE", "en-GB", "fr-BE"] as const;
|
||||
|
||||
function loadNamespace(language: string, namespace: string): Record<string, unknown> {
|
||||
const filePath = path.join(LOCALES_DIR, language, `${namespace}.json`);
|
||||
return JSON.parse(fs.readFileSync(filePath, "utf-8"));
|
||||
}
|
||||
|
||||
// Mirrors the (namespace, options.defaultValue) contract react-i18next's `t` exposes,
|
||||
// resolving "namespace:dotted.path" against the real locale files for the given language.
|
||||
function makeT(language: string): (key: string, options?: Record<string, unknown>) => string {
|
||||
return (key: string, options?: Record<string, unknown>) => {
|
||||
const [ns, ...rest] = key.includes(":") ? key.split(":") : ["errors", key];
|
||||
const dottedPath = key.includes(":") ? rest.join(":") : rest.join("");
|
||||
const data = loadNamespace(language, ns);
|
||||
const value = dottedPath.split(".").reduce<unknown>((acc, part) => {
|
||||
if (acc && typeof acc === "object") return (acc as Record<string, unknown>)[part];
|
||||
return undefined;
|
||||
}, data);
|
||||
if (typeof value === "string") return value;
|
||||
if (options && "defaultValue" in options) return String(options.defaultValue);
|
||||
return key;
|
||||
};
|
||||
}
|
||||
|
||||
const KNOWN_HTTP_STATUSES = ["401", "403", "404", "409", "422", "500"];
|
||||
|
||||
test("every known AppError code has a non-empty title+explanation in all 3 locales", () => {
|
||||
for (const language of LANGUAGES) {
|
||||
const codes = loadNamespace(language, "errors").codes as Record<string, { title?: string; explanation?: string }>;
|
||||
for (const code of KNOWN_CODES) {
|
||||
expect(codes[code], `${language}/errors.json is missing codes.${code}`).toBeTruthy();
|
||||
expect(codes[code]?.title?.trim().length ?? 0, `${language}/errors.json:codes.${code}.title is empty`).toBeGreaterThan(0);
|
||||
expect(
|
||||
codes[code]?.explanation?.trim().length ?? 0,
|
||||
`${language}/errors.json:codes.${code}.explanation is empty`,
|
||||
).toBeGreaterThan(0);
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
test("every known HTTP status fallback has a non-empty title+explanation in all 3 locales", () => {
|
||||
for (const language of LANGUAGES) {
|
||||
const http = loadNamespace(language, "errors").http as Record<string, { title?: string; explanation?: string }>;
|
||||
for (const status of KNOWN_HTTP_STATUSES) {
|
||||
expect(http[status], `${language}/errors.json is missing http.${status}`).toBeTruthy();
|
||||
expect(http[status]?.title?.trim().length ?? 0, `${language}/errors.json:http.${status}.title is empty`).toBeGreaterThan(0);
|
||||
expect(
|
||||
http[status]?.explanation?.trim().length ?? 0,
|
||||
`${language}/errors.json:http.${status}.explanation is empty`,
|
||||
).toBeGreaterThan(0);
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
test("a known AppError code resolves to its localized codes.* entry, never the raw backend message", () => {
|
||||
for (const language of LANGUAGES) {
|
||||
const t = makeT(language);
|
||||
const raw = "IntegrityError: duplicate key value violates unique constraint";
|
||||
const err = new ApiError(409, "VEHICLE_NOT_FOUND", raw, "corr-1");
|
||||
const info = describeApiError(t, err);
|
||||
const expected = loadNamespace(language, "errors").codes as Record<string, { title: string; explanation: string; nextStep?: string }>;
|
||||
expect(info.title).toBe(expected.VEHICLE_NOT_FOUND.title);
|
||||
expect(info.explanation).toBe(expected.VEHICLE_NOT_FOUND.explanation);
|
||||
expect(info.title).not.toBe(raw);
|
||||
expect(info.explanation).not.toBe(raw);
|
||||
// The raw backend text must still be reachable, just demoted to `.technical`.
|
||||
expect(info.technical).toBe(raw);
|
||||
}
|
||||
});
|
||||
|
||||
test("a code with nextStep populates it; a code without nextStep leaves it undefined", () => {
|
||||
const t = makeT("nl-BE");
|
||||
const withNextStep = describeApiError(t, new ApiError(422, "EMPTY_VALUE", "raw", "c1"));
|
||||
expect(withNextStep.nextStep).toBeTruthy();
|
||||
|
||||
const withoutNextStep = describeApiError(t, new ApiError(404, "CUSTOMER_NOT_FOUND", "raw", "c2"));
|
||||
expect(withoutNextStep.nextStep).toBeUndefined();
|
||||
});
|
||||
|
||||
test("an unrecognized AppError code falls back to the matching known HTTP status, not raw text", () => {
|
||||
for (const language of LANGUAGES) {
|
||||
const t = makeT(language);
|
||||
const raw = "Some brand-new backend code nobody localized yet";
|
||||
const err = new ApiError(404, "SOME_FUTURE_CODE_NOT_YET_LOCALIZED", raw, "corr-2");
|
||||
const info = describeApiError(t, err);
|
||||
const expected404 = (loadNamespace(language, "errors").http as Record<string, { title: string; explanation: string }>)["404"];
|
||||
expect(info.title).toBe(expected404.title);
|
||||
expect(info.explanation).toBe(expected404.explanation);
|
||||
expect(info.title).not.toBe(raw);
|
||||
expect(info.technical).toBe(raw);
|
||||
}
|
||||
});
|
||||
|
||||
test("an unrecognized code and an unrecognized HTTP status fall back to the fully generic message", () => {
|
||||
for (const language of LANGUAGES) {
|
||||
const t = makeT(language);
|
||||
const raw = "418 I'm a teapot (never mapped)";
|
||||
const err = new ApiError(418, "418", raw, "corr-3");
|
||||
const info = describeApiError(t, err);
|
||||
const generic = loadNamespace(language, "errors").generic as { title: string; explanation: string };
|
||||
expect(info.title).toBe(generic.title);
|
||||
expect(info.explanation).toBe(generic.explanation);
|
||||
expect(info.technical).toBe(raw);
|
||||
}
|
||||
});
|
||||
|
||||
test("a stringified HTTP status used as the AppError code (plain HTTPException path) resolves via the http map", () => {
|
||||
// Mirrors app/main.py's plain-HTTPException handler, which sets code = str(status_code)
|
||||
// (e.g. "401") rather than a semantic AppError code -- see backend/app/main.py.
|
||||
const t = makeT("fr-BE");
|
||||
const err = new ApiError(401, "401", "Not authenticated", "corr-4");
|
||||
const info = describeApiError(t, err);
|
||||
const expected401 = (loadNamespace("fr-BE", "errors").http as Record<string, { title: string }>)["401"];
|
||||
expect(info.title).toBe(expected401.title);
|
||||
expect(info.title).not.toBe("Not authenticated");
|
||||
});
|
||||
|
||||
test("a non-ApiError (e.g. network failure before any response) uses the fallback key, never a raw JS error message as the primary text", () => {
|
||||
const t = makeT("nl-BE");
|
||||
const networkFailure = new TypeError("Failed to fetch");
|
||||
// Real call sites (e.g. Automation.tsx) invoke t() with their own default namespace
|
||||
// already scoped via useTranslation("integrations"); this stub's default namespace is
|
||||
// "errors", so the fallback key is qualified explicitly here to match.
|
||||
const info = describeApiError(t, networkFailure, "integrations:ledger.retryFailed");
|
||||
const expectedFallback = loadNamespace("nl-BE", "integrations").ledger as Record<string, string>;
|
||||
expect(info.explanation).toBe(expectedFallback.retryFailed);
|
||||
expect(info.explanation).not.toBe("Failed to fetch");
|
||||
expect(info.technical).toBe("Failed to fetch");
|
||||
});
|
||||
|
||||
// --- Backend/frontend AppError code drift guard ---
|
||||
// KNOWN_CODES is a hand-maintained mirror of every `raise AppError("CODE", ...)` in the
|
||||
// backend (see app/core/errors.py::AppError and every raise site). If the backend adds a
|
||||
// new code and nobody updates KNOWN_CODES, it silently falls back to the generic-but-
|
||||
// still-localized HTTP/generic message rather than raw English -- not a broken build, but
|
||||
// a missed opportunity for a more specific message. This test surfaces that drift instead
|
||||
// of letting it go unnoticed indefinitely.
|
||||
const BACKEND_APP_DIR = path.resolve(__dirname, "../../backend/app");
|
||||
|
||||
function collectPyFiles(dir: string): string[] {
|
||||
const entries = fs.readdirSync(dir, { withFileTypes: true });
|
||||
return entries.flatMap((entry) => {
|
||||
const full = path.join(dir, entry.name);
|
||||
if (entry.isDirectory()) return collectPyFiles(full);
|
||||
return entry.name.endsWith(".py") ? [full] : [];
|
||||
});
|
||||
}
|
||||
|
||||
function collectBackendAppErrorCodes(): Set<string> {
|
||||
const codes = new Set<string>();
|
||||
for (const file of collectPyFiles(BACKEND_APP_DIR)) {
|
||||
const source = fs.readFileSync(file, "utf-8");
|
||||
const pattern = /AppError\(\s*"([A-Z_]+)"/g;
|
||||
let match: RegExpExecArray | null;
|
||||
while ((match = pattern.exec(source)) !== null) {
|
||||
codes.add(match[1]);
|
||||
}
|
||||
}
|
||||
return codes;
|
||||
}
|
||||
|
||||
test("frontend KNOWN_CODES exactly matches every AppError code actually raised by the backend", () => {
|
||||
const backendCodes = collectBackendAppErrorCodes();
|
||||
const frontendCodes = KNOWN_CODES;
|
||||
|
||||
const missingFromFrontend = [...backendCodes].filter((c) => !frontendCodes.has(c)).sort();
|
||||
const staleInFrontend = [...frontendCodes].filter((c) => !backendCodes.has(c)).sort();
|
||||
|
||||
expect(
|
||||
missingFromFrontend,
|
||||
`Backend raises AppError code(s) with no localized entry in errorMessages.ts KNOWN_CODES ` +
|
||||
`(they'll fall back to a generic/HTTP-status message): ${missingFromFrontend.join(", ")}`,
|
||||
).toEqual([]);
|
||||
expect(
|
||||
staleInFrontend,
|
||||
`errorMessages.ts KNOWN_CODES lists code(s) the backend never raises -- likely renamed or ` +
|
||||
`removed on the backend side: ${staleInFrontend.join(", ")}`,
|
||||
).toEqual([]);
|
||||
});
|
||||
|
||||
test("a non-ApiError with no fallbackKey uses the fully generic explanation", () => {
|
||||
for (const language of LANGUAGES) {
|
||||
const t = makeT(language);
|
||||
const info = describeApiError(t, new TypeError("Failed to fetch"));
|
||||
const generic = loadNamespace(language, "errors").generic as { title: string; explanation: string };
|
||||
expect(info.title).toBe(generic.title);
|
||||
expect(info.explanation).toBe(generic.explanation);
|
||||
}
|
||||
});
|
||||
@@ -0,0 +1,393 @@
|
||||
import { expect, test, type APIRequestContext, type Page } from "@playwright/test";
|
||||
|
||||
// Targeted end-to-end coverage for the Fleet Ops correction brief (docs/fleet-ops-
|
||||
// correction/): branding, the redesigned status-recommendation flow (preview/apply/
|
||||
// manual-review/stale-token), MO-016 order independence, trilingual knowledge
|
||||
// grounding, and localized audit/automation content. See also i18n-coverage.spec.ts
|
||||
// (key parity, brand invariant, translation-quality) and responsive-i18n.spec.ts
|
||||
// (breakpoint matrix) for the complementary static-content checks.
|
||||
|
||||
async function resetDemoData(request: APIRequestContext) {
|
||||
const login = await request.post("/api/v1/demo/login", { data: { role: "operations_manager" } });
|
||||
expect(login.ok()).toBeTruthy();
|
||||
const reset = await request.post("/api/v1/demo/reset");
|
||||
expect(reset.ok()).toBeTruthy();
|
||||
// /api/v1/demo/reset deletes the session cookie (it recreates the users table), so any
|
||||
// further authenticated call through this same request context needs a fresh login.
|
||||
const relogin = await request.post("/api/v1/demo/login", { data: { role: "operations_manager" } });
|
||||
expect(relogin.ok()).toBeTruthy();
|
||||
}
|
||||
|
||||
const EXPLORE_OPS_MANAGER: Record<string, string> = {
|
||||
"nl-BE": "Verken als Operationsmanager",
|
||||
"en-GB": "Explore as Operations Manager",
|
||||
"fr-BE": "Explorer en tant que Responsable des opérations",
|
||||
};
|
||||
|
||||
const REVIEW_RECOMMENDATION: Record<string, string> = {
|
||||
"nl-BE": "Aanbeveling bekijken",
|
||||
"en-GB": "Review recommendation",
|
||||
"fr-BE": "Voir la recommandation",
|
||||
};
|
||||
|
||||
const CHANGE_STATUS_PREFIX: Record<string, RegExp> = {
|
||||
"nl-BE": /^Status wijzigen naar/,
|
||||
"en-GB": /^Change status to/,
|
||||
"fr-BE": /^Changer le statut vers/,
|
||||
};
|
||||
|
||||
const MANUAL_REVIEW_HEADING: Record<string, string> = {
|
||||
"nl-BE": "Handmatige beoordeling vereist",
|
||||
"en-GB": "Manual review required",
|
||||
"fr-BE": "Évaluation manuelle requise",
|
||||
};
|
||||
|
||||
async function loginAsOpsManager(page: Page, lang: string) {
|
||||
await page.addInitScript((l) => localStorage.setItem("fleetops.language", l), lang);
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: EXPLORE_OPS_MANAGER[lang] }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
}
|
||||
|
||||
test.describe.configure({ mode: "serial" });
|
||||
|
||||
test.describe("branding", () => {
|
||||
for (const lang of ["nl-BE", "en-GB", "fr-BE"]) {
|
||||
test(`Fleet Ops is the visible brand and no MobilityOps/PoC leaks through (${lang})`, async ({
|
||||
page,
|
||||
request,
|
||||
}) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, lang);
|
||||
await expect(page.locator(".brand-mark").first()).toBeVisible();
|
||||
await expect(page.getByText("Fleet Ops", { exact: true }).first()).toBeVisible();
|
||||
await expect(page.locator(".app-footer")).toContainText("Fleet Ops");
|
||||
await expect(page.locator("html")).toHaveAttribute("lang", lang);
|
||||
|
||||
for (const path of ["/dashboard", "/vehicles", "/data-quality", "/audit", "/automation", "/knowledge"]) {
|
||||
await page.goto(path);
|
||||
const text = await page.locator("body").innerText();
|
||||
expect(text, `${path} (${lang})`).not.toContain("MobilityOps");
|
||||
expect(text, `${path} (${lang})`).not.toMatch(/\bPoC\b/);
|
||||
}
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
test("the Fleet Ops favicon is linked and resolves (not the browser's blank-tab default)", async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
await page.goto("/login");
|
||||
const href = await page.locator('link[rel="icon"]').getAttribute("href");
|
||||
expect(href).toBe("/favicon.svg");
|
||||
const response = await page.request.get(href as string);
|
||||
expect(response.ok()).toBeTruthy();
|
||||
expect(response.headers()["content-type"]).toContain("svg");
|
||||
});
|
||||
|
||||
test("language switcher control changes the UI and persists across a reload", async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
// Deliberately not using loginAsOpsManager here: its addInitScript would re-force
|
||||
// nl-BE on every reload, defeating exactly the persistence behaviour under test.
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: EXPLORE_OPS_MANAGER["nl-BE"] }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
await expect(page.getByRole("heading", { name: "Aandachtspunten" })).toBeVisible();
|
||||
|
||||
await page.getByRole("combobox", { name: "Taal" }).selectOption("fr-BE");
|
||||
await expect(page.getByRole("heading", { name: "File d'attention" })).toBeVisible();
|
||||
await expect(page.locator("html")).toHaveAttribute("lang", "fr-BE");
|
||||
|
||||
await page.reload();
|
||||
await expect(page.getByRole("heading", { name: "File d'attention" })).toBeVisible();
|
||||
await expect(page.locator("html")).toHaveAttribute("lang", "fr-BE");
|
||||
});
|
||||
|
||||
test.describe("status-recommendation flow", () => {
|
||||
test("preview does not mutate anything, apply names the exact target status", async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, "nl-BE");
|
||||
await page.goto("/data-quality/DQ-DEMO-STATUS");
|
||||
await expect(page.getByRole("heading", { name: "DQ-DEMO-STATUS" })).toBeVisible();
|
||||
|
||||
await page.getByRole("button", { name: REVIEW_RECOMMENDATION["nl-BE"] }).click();
|
||||
await expect(page.getByText("Aanbevolen status")).toBeVisible();
|
||||
await expect(page.getByRole("heading", { name: "Waarom" })).toBeVisible();
|
||||
await expect(page.getByRole("heading", { name: "Gevolg" })).toBeVisible();
|
||||
|
||||
// Previewing must not have resolved the issue -- still open, using the page's own
|
||||
// authenticated session (page.request shares cookies with the browser context).
|
||||
const issue = await page.request.get("/api/v1/data-quality/issues/DQ-DEMO-STATUS");
|
||||
expect((await issue.json()).status).toBe("open");
|
||||
|
||||
const confirmButton = page.getByRole("button", { name: CHANGE_STATUS_PREFIX["nl-BE"] });
|
||||
await expect(confirmButton).toHaveText(/Geblokkeerd/);
|
||||
await confirmButton.click();
|
||||
await expect(page.getByText("Toegepast", { exact: false })).toBeVisible();
|
||||
|
||||
const resolved = await page.request.get("/api/v1/data-quality/issues/DQ-DEMO-STATUS");
|
||||
expect((await resolved.json()).status).toBe("resolved");
|
||||
});
|
||||
|
||||
test("manual review state offers no generic apply button for a genuine fact contradiction", async ({
|
||||
page,
|
||||
request,
|
||||
}) => {
|
||||
await resetDemoData(request);
|
||||
const issues = await (
|
||||
await request.get("/api/v1/data-quality/issues", {
|
||||
params: { rule_type: "vehicle_status_conflict", status: "open" },
|
||||
})
|
||||
).json();
|
||||
const conflicted = issues.find((i: { entity_ref: string }) => i.entity_ref === "MO-024");
|
||||
expect(conflicted, "expected MO-024's vehicle_status_conflict issue to exist after reset").toBeTruthy();
|
||||
|
||||
await loginAsOpsManager(page, "en-GB");
|
||||
await page.goto(`/data-quality/${conflicted.public_ref}`);
|
||||
await page.getByRole("button", { name: REVIEW_RECOMMENDATION["en-GB"] }).click();
|
||||
|
||||
await expect(page.getByRole("heading", { name: MANUAL_REVIEW_HEADING["en-GB"] })).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: /^Change status to/ })).toHaveCount(0);
|
||||
});
|
||||
|
||||
test("a stale recommendation is rejected and the user must review again before applying", async ({
|
||||
page,
|
||||
request,
|
||||
}) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, "en-GB");
|
||||
await page.goto("/data-quality/DQ-DEMO-STATUS");
|
||||
await page.getByRole("button", { name: REVIEW_RECOMMENDATION["en-GB"] }).click();
|
||||
await expect(page.getByRole("button", { name: /^Change status to/ })).toBeVisible();
|
||||
|
||||
// Simulate the underlying facts changing after the preview was shown (the same
|
||||
// session resolves the booking overlap in the meantime) -- the previously-fetched
|
||||
// recommendation token must no longer be accepted.
|
||||
await page.evaluate(async () => {
|
||||
await fetch("/api/v1/data-quality/issues/DQ-DEMO-OVERLAP/resolve-overlap", {
|
||||
method: "POST",
|
||||
headers: { "Content-Type": "application/json" },
|
||||
body: JSON.stringify({ booking_ref: "BK-DEMO-OVERLAP-B" }),
|
||||
});
|
||||
});
|
||||
|
||||
await page.getByRole("button", { name: /^Change status to/ }).click();
|
||||
await expect(page.getByText(/situation has changed/i)).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: REVIEW_RECOMMENDATION["en-GB"] })).toBeVisible();
|
||||
});
|
||||
});
|
||||
|
||||
test.describe("MO-016 status conflict is order-independent", () => {
|
||||
// Order independence does NOT mean "the same final vehicle status regardless of
|
||||
// order" -- resolving the booking overlap first genuinely removes the conflict, so
|
||||
// there is correctly nothing left to apply afterwards. What must hold in either
|
||||
// order: the recommendation always reflects the real, current facts (never a stale
|
||||
// "was some other issue open" proxy), and nothing unsafe is ever applied (never
|
||||
// "rented").
|
||||
|
||||
test("resolving the booking overlap first correctly leaves nothing to apply", async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, "nl-BE");
|
||||
await page.goto("/data-quality/DQ-DEMO-OVERLAP");
|
||||
await page.getByRole("radio", { name: /BK-DEMO-OVERLAP-B blokkeren/ }).check();
|
||||
await page.getByRole("button", { name: /BK-DEMO-OVERLAP-B blokkeren/ }).click();
|
||||
await expect(page.getByText("Opgelost").first()).toBeVisible();
|
||||
|
||||
await page.goto("/data-quality/DQ-DEMO-STATUS");
|
||||
await page.getByRole("button", { name: REVIEW_RECOMMENDATION["nl-BE"] }).click();
|
||||
await expect(page.getByRole("heading", { name: "Geen wijziging nodig" })).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: CHANGE_STATUS_PREFIX["nl-BE"] })).toHaveCount(0);
|
||||
|
||||
const vehicle = await request.get("/api/v1/vehicles/MO-016");
|
||||
expect((await vehicle.json()).operational_status).toBe("available");
|
||||
});
|
||||
|
||||
test("resolving the status conflict first safely blocks the vehicle, unaffected by the later overlap fix", async ({
|
||||
page,
|
||||
request,
|
||||
}) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, "nl-BE");
|
||||
await page.goto("/data-quality/DQ-DEMO-STATUS");
|
||||
await page.getByRole("button", { name: REVIEW_RECOMMENDATION["nl-BE"] }).click();
|
||||
await page.getByRole("button", { name: CHANGE_STATUS_PREFIX["nl-BE"] }).click();
|
||||
await expect(page.getByText("Toegepast", { exact: false })).toBeVisible();
|
||||
|
||||
const vehicleMid = await request.get("/api/v1/vehicles/MO-016");
|
||||
const statusAfterApply = (await vehicleMid.json()).operational_status;
|
||||
expect(statusAfterApply).not.toBe("rented");
|
||||
|
||||
await page.goto("/data-quality/DQ-DEMO-OVERLAP");
|
||||
await page.getByRole("radio", { name: /BK-DEMO-OVERLAP-B blokkeren/ }).check();
|
||||
await page.getByRole("button", { name: /BK-DEMO-OVERLAP-B blokkeren/ }).click();
|
||||
await expect(page.getByText("Opgelost").first()).toBeVisible();
|
||||
|
||||
// Resolving the now-redundant overlap afterwards must not itself change the
|
||||
// vehicle's status as a side effect.
|
||||
const vehicleFinal = await request.get("/api/v1/vehicles/MO-016");
|
||||
const statusFinal = (await vehicleFinal.json()).operational_status;
|
||||
expect(statusFinal).toBe(statusAfterApply);
|
||||
expect(statusFinal).not.toBe("rented");
|
||||
|
||||
await resetDemoData(request);
|
||||
});
|
||||
});
|
||||
|
||||
test.describe("knowledge base is grounded in the operator's own language", () => {
|
||||
const cases: { lang: string; question: string; sourceHint: RegExp }[] = [
|
||||
{
|
||||
lang: "nl-BE",
|
||||
question: "Wat moet ik doen wanneer een voertuig beschadigd terugkomt?",
|
||||
sourceHint: /schadeafhandeling/i,
|
||||
},
|
||||
{
|
||||
lang: "en-GB",
|
||||
question: "What should I do when a vehicle returns with damage?",
|
||||
sourceHint: /damage/i,
|
||||
},
|
||||
{
|
||||
lang: "fr-BE",
|
||||
question: "Que dois-je faire lorsqu'un véhicule revient endommagé ?",
|
||||
sourceHint: /dommages/i,
|
||||
},
|
||||
];
|
||||
|
||||
for (const { lang, question, sourceHint } of cases) {
|
||||
test(`grounded ${lang} answer cites a ${lang} source about damage`, async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, lang);
|
||||
await page.goto("/knowledge");
|
||||
await page.locator("#knowledge-question").fill(question);
|
||||
await page.getByRole("button", { name: /^(Vraag stellen|Ask|Demander)$/ }).click();
|
||||
await expect(page.getByText(sourceHint).first()).toBeVisible({ timeout: 10_000 });
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
test("audit trail shows localized action and field labels with raw codes only in technical details", async ({
|
||||
page,
|
||||
request,
|
||||
}) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, "nl-BE");
|
||||
await page.goto("/data-quality/DQ-DEMO-STATUS");
|
||||
await page.getByRole("button", { name: REVIEW_RECOMMENDATION["nl-BE"] }).click();
|
||||
await page.getByRole("button", { name: CHANGE_STATUS_PREFIX["nl-BE"] }).click();
|
||||
await expect(page.getByText("Toegepast", { exact: false })).toBeVisible();
|
||||
|
||||
await page.goto("/audit");
|
||||
|
||||
// Applying resolves both the vehicle status and the issue in one correlated action --
|
||||
// expand the group's "technical events" toggle so the other audit row's diff renders
|
||||
// too, regardless of which one the grouping picked as primary.
|
||||
const toggle = page.getByRole("button", { name: /technische gebeurtenis/ }).first();
|
||||
await expect(toggle).toBeVisible();
|
||||
await toggle.click();
|
||||
await expect(page.getByRole("button", { name: "Technische gebeurtenissen verbergen" })).toBeVisible();
|
||||
|
||||
await expect(page.getByText("Aanbevolen status toegepast").first()).toBeVisible();
|
||||
const diffs = page.locator(".change-diff");
|
||||
await expect(diffs.first()).toBeVisible();
|
||||
const combinedDiffText = (await diffs.allInnerTexts()).join(" ");
|
||||
expect(combinedDiffText).toContain("Operationele status");
|
||||
expect(combinedDiffText).not.toContain("operational_status");
|
||||
});
|
||||
|
||||
test("automation shows a localized error explanation with the raw error only under technical details", async ({
|
||||
page,
|
||||
request,
|
||||
}) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, "nl-BE");
|
||||
await page.goto("/automation");
|
||||
|
||||
await expect(page.getByText(/tijdelijk niet bereikbaar/).first()).toBeVisible();
|
||||
await expect(page.getByText("Synthetic connection timeout to n8n")).not.toBeVisible();
|
||||
// Scope to the failed job's own row -- the workflow-evidence table above it also has
|
||||
// "Technische details" toggles (one per workflow), so an unscoped .first() can open
|
||||
// the wrong one.
|
||||
const failedJobRow = page.locator("tr", { has: page.getByText(/tijdelijk niet bereikbaar/) });
|
||||
await failedJobRow.getByText("Technische details").click();
|
||||
await expect(page.getByText("Synthetic connection timeout to n8n")).toBeVisible();
|
||||
});
|
||||
|
||||
test.describe("route matrix (section 11F)", () => {
|
||||
// Opens every main route in all 3 languages: no console errors, correct html[lang],
|
||||
// and a real, non-empty page heading (proving the route actually rendered content
|
||||
// instead of silently falling back to a raw i18next key or a blank screen). Key
|
||||
// parity across locale files is already proven structurally by i18n-coverage.spec.ts
|
||||
// (every key that exists in nl-BE also exists, non-empty, in en-GB/fr-BE), so this
|
||||
// matrix focuses on what only a live render can catch.
|
||||
const routes = [
|
||||
"/dashboard",
|
||||
"/vehicles",
|
||||
"/vehicles/MO-001",
|
||||
"/bookings",
|
||||
"/bookings/BK-DEMO-RETURN",
|
||||
"/data-quality",
|
||||
"/data-quality/DQ-DEMO-STATUS",
|
||||
"/automation",
|
||||
"/knowledge",
|
||||
"/audit",
|
||||
"/scenarios",
|
||||
"/about",
|
||||
];
|
||||
|
||||
for (const lang of ["nl-BE", "en-GB", "fr-BE"]) {
|
||||
test(`every main route renders correctly with no console errors (${lang})`, async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
|
||||
const errors: string[] = [];
|
||||
page.on("console", (msg) => {
|
||||
if (msg.type() !== "error") return;
|
||||
if (msg.text().includes("401") && msg.text().includes("Unauthorized")) return;
|
||||
errors.push(msg.text());
|
||||
});
|
||||
page.on("pageerror", (err) => errors.push(err.message));
|
||||
|
||||
await loginAsOpsManager(page, lang);
|
||||
|
||||
for (const route of routes) {
|
||||
await page.goto(route);
|
||||
await expect(page.locator("html")).toHaveAttribute("lang", lang);
|
||||
const heading = page.getByRole("heading", { level: 1 });
|
||||
await expect(heading, `${route} (${lang})`).toBeVisible();
|
||||
const headingText = (await heading.first().textContent())?.trim() ?? "";
|
||||
expect(headingText, `${route} (${lang}) heading text`).not.toBe("");
|
||||
// A raw, unresolved i18next key looks like "namespace:some.key.path" -- real
|
||||
// page headings never contain a colon followed by a dotted identifier.
|
||||
expect(headingText, `${route} (${lang}) heading looks like a raw i18n key`).not.toMatch(
|
||||
/^[a-zA-Z]+:[\w.]+$/,
|
||||
);
|
||||
}
|
||||
|
||||
expect(errors, `Console errors across the route matrix (${lang}):\n${errors.join("\n")}`).toEqual([]);
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
test.describe("data-quality evidence summary is localized, not raw English (section 6)", () => {
|
||||
// The primary evidence line at the top of every issue's detail page must render the
|
||||
// structured `evidence.signals` in the operator's language; the legacy English
|
||||
// `evidence.summary` string is a technical fallback only, visible solely inside
|
||||
// "Technical details". Live-caught: this line was unconditionally showing raw
|
||||
// English ("vehicle marked available while reserved bookings conflict") in every
|
||||
// language until fixed.
|
||||
const cases: { lang: string; expectedText: RegExp }[] = [
|
||||
{ lang: "nl-BE", expectedText: /overlappende reserveringen/i },
|
||||
{ lang: "en-GB", expectedText: /overlapping bookings/i },
|
||||
{ lang: "fr-BE", expectedText: /chevauchent|chevauchement/i },
|
||||
];
|
||||
|
||||
for (const { lang, expectedText } of cases) {
|
||||
test(`vehicle_status_conflict evidence is localized (${lang})`, async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
await loginAsOpsManager(page, lang);
|
||||
await page.goto("/data-quality/DQ-DEMO-STATUS");
|
||||
|
||||
const summarySection = page.locator(".record-surface-evidence");
|
||||
await expect(summarySection).toBeVisible();
|
||||
await expect(summarySection).toContainText(expectedText);
|
||||
await expect(summarySection).not.toContainText("vehicle marked available while reserved bookings conflict");
|
||||
});
|
||||
}
|
||||
});
|
||||
@@ -0,0 +1,107 @@
|
||||
import { expect, type Page, test } from "@playwright/test";
|
||||
|
||||
// Browser-context evidence for the time-dependent Europe/Brussels dashboard greeting
|
||||
// (section 9 / 11 / 16 of the Fleet Ops final localization brief): the real rendered app,
|
||||
// in all 3 languages, at every required boundary instant, using Playwright's clock API to
|
||||
// control the browser's Date without waiting on real wall-clock time. Also proves the
|
||||
// greeting updates live (no reload) when the period rolls over while the app stays open.
|
||||
|
||||
// 2026-01-15 is CET (UTC+1): Brussels hour = UTC hour + 1.
|
||||
function cet(hour: number, minute = 0, second = 0): Date {
|
||||
return new Date(Date.UTC(2026, 0, 15, hour - 1, minute, second));
|
||||
}
|
||||
|
||||
const BOUNDARY_CASES: Array<{ time: Date; label: string; period: string }> = [
|
||||
{ time: cet(4, 59), label: "04:59", period: "night" },
|
||||
{ time: cet(5, 0), label: "05:00", period: "morning" },
|
||||
{ time: cet(11, 59), label: "11:59", period: "morning" },
|
||||
{ time: cet(12, 0), label: "12:00", period: "afternoon" },
|
||||
{ time: cet(17, 59), label: "17:59", period: "afternoon" },
|
||||
{ time: cet(18, 0), label: "18:00", period: "evening" },
|
||||
{ time: cet(22, 59), label: "22:59", period: "evening" },
|
||||
{ time: cet(23, 0), label: "23:00", period: "night" },
|
||||
];
|
||||
|
||||
const EXPECTED_TITLE: Record<string, Record<string, string>> = {
|
||||
"nl-BE": {
|
||||
morning: "Goedemorgen. Hier is de status van je wagenpark voor vandaag.",
|
||||
afternoon: "Goedemiddag. Hier is het actuele overzicht van je wagenpark.",
|
||||
evening: "Goedenavond. Hier is het overzicht van je wagenpark voor vanavond.",
|
||||
night: "Welkom terug. Hier is het laatste overzicht van je wagenpark.",
|
||||
},
|
||||
"en-GB": {
|
||||
morning: "Good morning. Here's today's fleet status.",
|
||||
afternoon: "Good afternoon. Here's the current overview of your fleet.",
|
||||
evening: "Good evening. Here's this evening's fleet overview.",
|
||||
night: "Welcome back. Here's the latest overview of your fleet.",
|
||||
},
|
||||
"fr-BE": {
|
||||
morning: "Bonjour. Voici l'état de votre flotte pour aujourd'hui.",
|
||||
afternoon: "Bonjour. Voici l'aperçu actuel de votre flotte.",
|
||||
evening: "Bonsoir. Voici l'aperçu de votre flotte pour ce soir.",
|
||||
night: "Bon retour. Voici le dernier aperçu de votre flotte.",
|
||||
},
|
||||
};
|
||||
|
||||
async function loginAsOperationsManager(page: Page) {
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await expect(page).toHaveURL(/\/dashboard$/);
|
||||
}
|
||||
|
||||
async function switchLanguage(page: Page, language: "nl-BE" | "en-GB" | "fr-BE") {
|
||||
// At the default desktop viewport, only the topbar's compact switcher is visible --
|
||||
// the sidebar's full switcher is `display: none` until the <960px breakpoint.
|
||||
await page.locator(".language-switcher-compact select").selectOption(language);
|
||||
}
|
||||
|
||||
const dashboardHeading = (page: Page) => page.locator(".page-header h1");
|
||||
|
||||
for (const language of ["nl-BE", "en-GB", "fr-BE"] as const) {
|
||||
test(`dashboard greeting matches every required boundary time in ${language}`, async ({ page }) => {
|
||||
await page.clock.install({ time: BOUNDARY_CASES[0].time });
|
||||
await loginAsOperationsManager(page);
|
||||
if (language !== "nl-BE") {
|
||||
await switchLanguage(page, language);
|
||||
}
|
||||
|
||||
for (const { time, label, period } of BOUNDARY_CASES) {
|
||||
await page.clock.setFixedTime(time);
|
||||
await page.reload();
|
||||
await expect(dashboardHeading(page), `${language} @ ${label} Brussels time (expected period: ${period})`).toHaveText(
|
||||
EXPECTED_TITLE[language][period],
|
||||
);
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
test("dashboard greeting updates live across a period rollover without a page reload", async ({ page }) => {
|
||||
// Start at 11:59:31 Brussels -- 29s before the 12:00 boundary.
|
||||
await page.clock.install({ time: cet(11, 59, 31) });
|
||||
await loginAsOperationsManager(page);
|
||||
await expect(dashboardHeading(page)).toHaveText(EXPECTED_TITLE["nl-BE"].morning);
|
||||
|
||||
// Advance 30s of fake time (crossing 12:00) so the hook's 30s poll interval fires and
|
||||
// recomputes the period -- no page.reload() call anywhere in this test.
|
||||
await page.clock.fastForward(30_000);
|
||||
await expect(dashboardHeading(page)).toHaveText(EXPECTED_TITLE["nl-BE"].afternoon);
|
||||
});
|
||||
|
||||
test("dashboard greeting updates immediately on language switch without changing the time period", async ({ page }) => {
|
||||
await page.clock.install({ time: cet(9, 0) });
|
||||
await loginAsOperationsManager(page);
|
||||
await expect(dashboardHeading(page)).toHaveText(EXPECTED_TITLE["nl-BE"].morning);
|
||||
|
||||
await switchLanguage(page, "en-GB");
|
||||
await expect(dashboardHeading(page)).toHaveText(EXPECTED_TITLE["en-GB"].morning);
|
||||
|
||||
await switchLanguage(page, "fr-BE");
|
||||
await expect(dashboardHeading(page)).toHaveText(EXPECTED_TITLE["fr-BE"].morning);
|
||||
});
|
||||
|
||||
test("dashboard never shows 'Goedenacht' as a greeting at any hour", async ({ page }) => {
|
||||
await page.clock.install({ time: cet(2, 0) });
|
||||
await loginAsOperationsManager(page);
|
||||
await expect(dashboardHeading(page)).not.toContainText("Goedenacht");
|
||||
await expect(dashboardHeading(page)).toContainText("Welkom terug");
|
||||
});
|
||||
@@ -0,0 +1,68 @@
|
||||
import { expect, test } from "@playwright/test";
|
||||
import { getBrusselsHour, getGreetingPeriod } from "../src/i18n/greeting";
|
||||
|
||||
// Pure Node-context boundary tests for the central, clock-injectable greeting function
|
||||
// (section 9 of the Fleet Ops final localization brief). Every case below constructs an
|
||||
// explicit UTC instant that corresponds to a specific Europe/Brussels wall-clock time --
|
||||
// this is what "clock injection" buys: no real time needs to pass, and DST is exercised
|
||||
// by picking instants either side of the CET/CEST transition.
|
||||
|
||||
// 2026-01-15 is CET (UTC+1): 04:59 Brussels = 03:59 UTC.
|
||||
function cet(hour: number, minute = 0): Date {
|
||||
return new Date(Date.UTC(2026, 0, 15, hour - 1, minute));
|
||||
}
|
||||
|
||||
// 2026-07-15 is CEST (UTC+2): 04:59 Brussels = 02:59 UTC.
|
||||
function cest(hour: number, minute = 0): Date {
|
||||
return new Date(Date.UTC(2026, 6, 15, hour - 2, minute));
|
||||
}
|
||||
|
||||
test("period boundaries are correct in winter time (CET, UTC+1)", () => {
|
||||
expect(getGreetingPeriod(cet(4, 59))).toBe("night");
|
||||
expect(getGreetingPeriod(cet(5, 0))).toBe("morning");
|
||||
expect(getGreetingPeriod(cet(11, 59))).toBe("morning");
|
||||
expect(getGreetingPeriod(cet(12, 0))).toBe("afternoon");
|
||||
expect(getGreetingPeriod(cet(17, 59))).toBe("afternoon");
|
||||
expect(getGreetingPeriod(cet(18, 0))).toBe("evening");
|
||||
expect(getGreetingPeriod(cet(22, 59))).toBe("evening");
|
||||
expect(getGreetingPeriod(cet(23, 0))).toBe("night");
|
||||
});
|
||||
|
||||
test("period boundaries are correct in summer time (CEST, UTC+2)", () => {
|
||||
expect(getGreetingPeriod(cest(4, 59))).toBe("night");
|
||||
expect(getGreetingPeriod(cest(5, 0))).toBe("morning");
|
||||
expect(getGreetingPeriod(cest(11, 59))).toBe("morning");
|
||||
expect(getGreetingPeriod(cest(12, 0))).toBe("afternoon");
|
||||
expect(getGreetingPeriod(cest(17, 59))).toBe("afternoon");
|
||||
expect(getGreetingPeriod(cest(18, 0))).toBe("evening");
|
||||
expect(getGreetingPeriod(cest(22, 59))).toBe("evening");
|
||||
expect(getGreetingPeriod(cest(23, 0))).toBe("night");
|
||||
});
|
||||
|
||||
test("DST transition (2026-03-29, clocks spring forward 02:00 -> 03:00 CEST): the Brussels hour never regresses or skips a period incorrectly", () => {
|
||||
// 00:30 UTC = 01:30 CET, still "night" (before the 05:00 boundary regardless).
|
||||
const beforeTransition = new Date(Date.UTC(2026, 2, 29, 0, 30));
|
||||
expect(getBrusselsHour(beforeTransition)).toBe(1);
|
||||
expect(getGreetingPeriod(beforeTransition)).toBe("night");
|
||||
|
||||
// 09:00 UTC on transition day = 11:00 CEST (already sprung forward) -- still morning.
|
||||
const afterTransition = new Date(Date.UTC(2026, 2, 29, 9, 0));
|
||||
expect(getBrusselsHour(afterTransition)).toBe(11);
|
||||
expect(getGreetingPeriod(afterTransition)).toBe("morning");
|
||||
|
||||
// Autumn transition, 2026-10-25: fall-back happens at 01:00 UTC (03:00 CEST -> 02:00
|
||||
// CET), so 00:30 UTC is still CEST -> 02:30 Brussels.
|
||||
const beforeFallBack = new Date(Date.UTC(2026, 9, 25, 0, 30));
|
||||
expect(getBrusselsHour(beforeFallBack)).toBe(2);
|
||||
expect(getGreetingPeriod(beforeFallBack)).toBe("night");
|
||||
|
||||
// 09:00 UTC on fall-back day = 10:00 CET (already fallen back) -- still morning.
|
||||
const afterFallBack = new Date(Date.UTC(2026, 9, 25, 9, 0));
|
||||
expect(getBrusselsHour(afterFallBack)).toBe(10);
|
||||
expect(getGreetingPeriod(afterFallBack)).toBe("morning");
|
||||
});
|
||||
|
||||
test("default argument uses the real current time when no clock is injected", () => {
|
||||
const period = getGreetingPeriod();
|
||||
expect(["morning", "afternoon", "evening", "night"]).toContain(period);
|
||||
});
|
||||
@@ -71,3 +71,254 @@ test("no locale file contains an empty string value", () => {
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
// --- Brand-invariant: "Fleet Ops" is a fixed constant, never a translation value ---
|
||||
// (see frontend/src/product.ts and docs/fleet-ops-correction/current-gap-audit.md §1).
|
||||
// A regression here means someone re-introduced a per-locale brand key/value instead of
|
||||
// interpolating {{productName}} from the shared constant.
|
||||
|
||||
test("no locale file defines an 'appName' key or the literal brand string", () => {
|
||||
for (const language of LANGUAGES) {
|
||||
for (const namespace of namespaces) {
|
||||
const data = loadNamespace(language, namespace);
|
||||
const raw = JSON.stringify(data);
|
||||
expect(
|
||||
raw.includes("Fleet Ops"),
|
||||
`${language}/${namespace}.json contains the literal brand string "Fleet Ops" -- ` +
|
||||
`use {{productName}} interpolation instead so the brand can never drift per locale`,
|
||||
).toBe(false);
|
||||
const keys = collectKeyPaths(data);
|
||||
expect(
|
||||
keys.some((k) => k === "appName" || k.endsWith(".appName")),
|
||||
`${language}/${namespace}.json defines an "appName" key -- the brand name must come ` +
|
||||
`from the PRODUCT_NAME constant, never a translatable key`,
|
||||
).toBe(false);
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
test("no locale file contains the internal project name 'MobilityOps' or the word 'PoC'", () => {
|
||||
for (const language of LANGUAGES) {
|
||||
for (const namespace of namespaces) {
|
||||
const raw = JSON.stringify(loadNamespace(language, namespace));
|
||||
expect(
|
||||
raw.includes("MobilityOps"),
|
||||
`${language}/${namespace}.json contains "MobilityOps" -- the visible product name is ` +
|
||||
`always "Fleet Ops" (via {{productName}}); "MobilityOps" is a technical/repo-only identifier`,
|
||||
).toBe(false);
|
||||
expect(
|
||||
/\bPoC\b/.test(raw),
|
||||
`${language}/${namespace}.json contains "PoC" -- Fleet Ops is never described as a PoC ` +
|
||||
`in user-facing copy`,
|
||||
).toBe(false);
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
// --- Translation-quality: prove values were actually translated, not copy-pasted ---
|
||||
// Sleutelpariteit alone doesn't prove translation happened (a locale file could contain
|
||||
// the literal English string under the right key and still pass). For every "real prose"
|
||||
// string (>=8 chars, not on the allowlist below), assert nl-BE and fr-BE differ from
|
||||
// en-GB, and that fr-BE differs from nl-BE -- catching both "still English" and
|
||||
// "Dutch text copy-pasted into French" in one pass.
|
||||
|
||||
// Exact (namespace, key-path) pairs that are legitimately identical across two or more
|
||||
// locales: real proper nouns/brand names, deliberately-untranslated role titles, and
|
||||
// genuine cross-language cognates (identical spelling in Dutch/French/English). This is
|
||||
// a precise allowlist by key path, not a broad word-level allowlist, so it can't quietly
|
||||
// hide an unrelated real mistranslation under the same key in a different namespace.
|
||||
const IDENTICAL_VALUE_ALLOWLIST = new Set([
|
||||
"audit.diff.was", // "{{field}}: was {{value}}" -- "was" is spelled identically in Dutch
|
||||
"common.language.nl-BE", // language-picker options show each language's own endonym
|
||||
"common.language.fr-BE",
|
||||
"common.footer.productLine", // "{{productName}} Demo" -- brief-specified exact footer text
|
||||
"common.orgName", // "Northstar Mobility" -- fictional org proper noun, same in all 3
|
||||
"dashboard.attention.openRecord", // "Open {{title}}" -- "open" is also the Dutch imperative
|
||||
"demo.scenarios.durationValue", // "± {{minutes}} min" -- unit abbreviation, same in all 3
|
||||
"demo.about.limitationsTitle", // "Limitations" -- identical spelling in French
|
||||
"demo.integrationSummary.titles.mcp_hub", // "ITWorx MCP Hub" -- proper noun
|
||||
"fleet.list.columns.attention", // "Attention" -- identical spelling in French
|
||||
"fleet.detail.tabs.inspections", // "Inspections" -- identical spelling in French
|
||||
"integrations.cards.orchestrationKicker", // "Orchestration" -- identical in French
|
||||
"knowledge.questionLabel", // "Question" -- identical spelling in French
|
||||
"knowledge.retrievalFlow.question",
|
||||
"knowledge.questionLabelExchange",
|
||||
"returns.result.inspection", // "Inspection" -- identical spelling in French
|
||||
"integrations.workflows.columns.name", // "Workflow" -- used as-is in Dutch and French
|
||||
]);
|
||||
|
||||
function isTranslatableProse(value: unknown): value is string {
|
||||
if (typeof value !== "string") return false;
|
||||
if (value.trim().length < 8) return false;
|
||||
// Strip interpolation placeholders and non-letter characters; if nothing substantial
|
||||
// remains (pure numbers/punctuation/units), it's not "prose" that needs translating.
|
||||
const stripped = value
|
||||
.replace(/\{\{[^}]+\}\}/g, " ")
|
||||
.replace(/[^a-zA-Zà-öø-ÿÀ-ÖØ-ß]/g, "");
|
||||
return stripped.trim().length >= 3;
|
||||
}
|
||||
|
||||
test("nl-BE and fr-BE translations are not suspiciously identical to en-GB or each other", () => {
|
||||
for (const namespace of namespaces) {
|
||||
const en = loadNamespace("en-GB", namespace);
|
||||
const nl = loadNamespace("nl-BE", namespace);
|
||||
const fr = loadNamespace("fr-BE", namespace);
|
||||
const keys = collectKeyPaths(en);
|
||||
|
||||
for (const keyPath of keys) {
|
||||
if (IDENTICAL_VALUE_ALLOWLIST.has(`${namespace}.${keyPath}`)) continue;
|
||||
const at = (data: Record<string, unknown>) =>
|
||||
keyPath.split(".").reduce<unknown>((acc, part) => {
|
||||
if (acc && typeof acc === "object") return (acc as Record<string, unknown>)[part];
|
||||
return undefined;
|
||||
}, data);
|
||||
|
||||
const enValue = at(en);
|
||||
if (!isTranslatableProse(enValue)) continue;
|
||||
const nlValue = at(nl);
|
||||
const frValue = at(fr);
|
||||
|
||||
expect(
|
||||
nlValue,
|
||||
`${namespace}.json:${keyPath} — nl-BE is identical to en-GB ("${enValue}"); ` +
|
||||
`looks untranslated (add to IDENTICAL_VALUE_ALLOWLIST if this is intentional)`,
|
||||
).not.toBe(enValue);
|
||||
expect(
|
||||
frValue,
|
||||
`${namespace}.json:${keyPath} — fr-BE is identical to en-GB ("${enValue}"); ` +
|
||||
`looks untranslated (add to IDENTICAL_VALUE_ALLOWLIST if this is intentional)`,
|
||||
).not.toBe(enValue);
|
||||
expect(
|
||||
frValue,
|
||||
`${namespace}.json:${keyPath} — fr-BE is identical to nl-BE ("${nlValue}"); ` +
|
||||
`looks like Dutch text was copy-pasted into the French locale`,
|
||||
).not.toBe(nlValue);
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
// --- Embedded English/Dutch fragments inside otherwise-translated prose ---
|
||||
// The whole-string identity check above only catches a value that is IDENTICAL to
|
||||
// en-GB end-to-end. It cannot catch a real bug class found during the Fleet Ops final
|
||||
// localization pass: a sentence gets 95% translated but a role/status noun phrase is
|
||||
// left embedded mid-sentence, e.g. nl-BE "... moet door de Operations Manager worden
|
||||
// goedgekeurd." This scan flags known English fragments appearing literally inside any
|
||||
// nl-BE or fr-BE string value, and known Dutch fragments leaking into fr-BE (copy-paste
|
||||
// mistakes). Deliberately limited to unambiguous multi-word phrases (not single common
|
||||
// words like "Open" or "Field", which collide with genuine Dutch/French vocabulary).
|
||||
const FORBIDDEN_ENGLISH_FRAGMENTS = [
|
||||
"Operations Manager",
|
||||
"Operations Managers",
|
||||
"Rental Employee",
|
||||
"Rental Employees",
|
||||
"Audit trail",
|
||||
"Start scenario",
|
||||
];
|
||||
const FORBIDDEN_DUTCH_FRAGMENTS_IN_FR = [
|
||||
"Operationsmanager",
|
||||
"Verhuurmedewerker",
|
||||
"Auditgeschiedenis",
|
||||
"Scenario starten",
|
||||
];
|
||||
|
||||
function collectStringLeaves(value: unknown, prefix = ""): Array<{ path: string; value: string }> {
|
||||
if (typeof value === "string") return [{ path: prefix, value }];
|
||||
if (value === null || typeof value !== "object") return [];
|
||||
return Object.entries(value as Record<string, unknown>).flatMap(([key, nested]) =>
|
||||
collectStringLeaves(nested, prefix ? `${prefix}.${key}` : key),
|
||||
);
|
||||
}
|
||||
|
||||
test("no known English role/status fragments leak into nl-BE or fr-BE prose", () => {
|
||||
const findings: string[] = [];
|
||||
for (const namespace of namespaces) {
|
||||
const nl = loadNamespace("nl-BE", namespace);
|
||||
const fr = loadNamespace("fr-BE", namespace);
|
||||
for (const { path: keyPath, value } of collectStringLeaves(nl)) {
|
||||
for (const fragment of FORBIDDEN_ENGLISH_FRAGMENTS) {
|
||||
if (value.includes(fragment)) {
|
||||
findings.push(`nl-BE/${namespace}.json:${keyPath} contains English fragment "${fragment}": "${value}"`);
|
||||
}
|
||||
}
|
||||
}
|
||||
for (const { path: keyPath, value } of collectStringLeaves(fr)) {
|
||||
for (const fragment of [...FORBIDDEN_ENGLISH_FRAGMENTS, ...FORBIDDEN_DUTCH_FRAGMENTS_IN_FR]) {
|
||||
if (value.includes(fragment)) {
|
||||
findings.push(`fr-BE/${namespace}.json:${keyPath} contains foreign-language fragment "${fragment}": "${value}"`);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
expect(findings, findings.join("\n")).toEqual([]);
|
||||
});
|
||||
|
||||
// --- Hardcoded JSX text (section 11D) ---
|
||||
// A targeted, deliberately narrow static scan: JSX text nodes (`>literal text<`, not a
|
||||
// `{...}` expression) containing two or more real words are almost always user-facing
|
||||
// prose that should go through t(...). This is not a full parser, so a short, explicit
|
||||
// allowlist covers technical tokens/proper nouns that are correctly never translated
|
||||
// (MobilityOps.md is checked for absence elsewhere; this list is for things that ARE
|
||||
// expected to appear literally in JSX).
|
||||
const SRC_DIR = path.resolve(__dirname, "../src");
|
||||
const SCAN_DIRS = ["pages", "components"];
|
||||
|
||||
const ALLOWED_LITERAL_TEXT = new Set([
|
||||
"Fleet Ops", // the non-localizable brand name (frontend/src/product.ts)
|
||||
"Northstar Mobility", // fictional demo org, a proper noun
|
||||
"ITWorx MCP Hub", // proper noun
|
||||
]);
|
||||
|
||||
function collectTsxFiles(dir: string): string[] {
|
||||
const entries = fs.readdirSync(dir, { withFileTypes: true });
|
||||
return entries.flatMap((entry) => {
|
||||
const full = path.join(dir, entry.name);
|
||||
if (entry.isDirectory()) return collectTsxFiles(full);
|
||||
return entry.name.endsWith(".tsx") ? [full] : [];
|
||||
});
|
||||
}
|
||||
|
||||
function findHardcodedJsxText(filePath: string): string[] {
|
||||
const source = fs.readFileSync(filePath, "utf-8");
|
||||
const findings: string[] = [];
|
||||
// Matches `<Tag ...>text</Tag>` where the closing tag name backreferences the
|
||||
// opening one -- this specifically excludes TypeScript generics like
|
||||
// `useState<string | null>(null)`, which have no matching `</string | null>` closer,
|
||||
// unlike a naive `>...<` scan would. Deliberately spans newlines (Prettier commonly
|
||||
// puts JSX text on its own line) and does not attempt to parse JSX properly -- it is
|
||||
// a fast, approximate net for the common mistake, not a compiler.
|
||||
const jsxTextPattern = /<([A-Za-z][\w.]*)(?:\s[^<>]*)?>([^<>{}]{3,200})<\/\1>/gs;
|
||||
let match: RegExpExecArray | null;
|
||||
while ((match = jsxTextPattern.exec(source)) !== null) {
|
||||
const text = match[2].trim();
|
||||
if (!text) continue;
|
||||
if (ALLOWED_LITERAL_TEXT.has(text)) continue;
|
||||
// Needs at least two alphabetic words to count as "prose" -- filters out numbers,
|
||||
// single technical words, units (km, %), punctuation-only fragments, and JSX
|
||||
// whitespace artifacts.
|
||||
const words = text.match(/[A-Za-z]+/g) ?? [];
|
||||
if (words.length < 2) continue;
|
||||
// Skip anything that is itself an i18next interpolation artifact leaking through
|
||||
// (shouldn't happen, but never flag `{{...}}`-shaped remnants) or looks like a URL
|
||||
// or path.
|
||||
if (/^https?:\/\//.test(text) || text.includes("/") || text.includes("{{")) continue;
|
||||
findings.push(`${path.relative(SRC_DIR, filePath)}: "${text}"`);
|
||||
}
|
||||
return findings;
|
||||
}
|
||||
|
||||
test("no hardcoded user-facing JSX text outside the approved technical-token allowlist", () => {
|
||||
const allFindings: string[] = [];
|
||||
for (const dir of SCAN_DIRS) {
|
||||
const files = collectTsxFiles(path.join(SRC_DIR, dir));
|
||||
for (const file of files) {
|
||||
allFindings.push(...findHardcodedJsxText(file));
|
||||
}
|
||||
}
|
||||
expect(
|
||||
allFindings,
|
||||
`Found ${allFindings.length} likely hardcoded JSX string(s) bypassing t(...). ` +
|
||||
`Either route it through the translation system, or add the exact literal to ` +
|
||||
`ALLOWED_LITERAL_TEXT in this test if it's a genuine proper noun/technical token:\n` +
|
||||
allFindings.join("\n"),
|
||||
).toEqual([]);
|
||||
});
|
||||
|
||||
@@ -130,9 +130,13 @@ test("return preview correctly reports blocked (not maintenance) for damage repo
|
||||
|
||||
// The preview is the server's authoritative evaluation: damage always routes to
|
||||
// "blocked", never "maintenance" -- this used to be guessed client-side and wrong.
|
||||
await expect(page.getByText("Damage was reported on return.")).toBeVisible();
|
||||
// The localized reason is the primary text; the raw code sits behind "Technical
|
||||
// details" so it isn't visible until expanded.
|
||||
await expect(page.getByText("Damage was reported on this return.")).toBeVisible();
|
||||
const statusRegion = page.locator(".impact-preview");
|
||||
await expect(statusRegion.getByText("blocked", { exact: true })).toBeVisible();
|
||||
await page.getByText("Technical details").click();
|
||||
await expect(page.getByText("Damage was reported on return.")).toBeVisible();
|
||||
});
|
||||
|
||||
test("data quality page: status and rule-type filters work", async ({ page }) => {
|
||||
@@ -201,8 +205,8 @@ test("data quality: applying the recommended status resolves a vehicle conflict"
|
||||
await page.goto("/data-quality/DQ-DEMO-STATUS");
|
||||
await expect(page.getByRole("heading", { name: "DQ-DEMO-STATUS" })).toBeVisible();
|
||||
|
||||
await page.getByRole("button", { name: "Calculate and apply recommended status" }).click();
|
||||
await page.getByRole("button", { name: "Yes, apply" }).click();
|
||||
await page.getByRole("button", { name: "Review recommendation" }).click();
|
||||
await page.getByRole("button", { name: /^Change status to/ }).click();
|
||||
|
||||
await expect(page.getByText("Applied", { exact: false })).toBeVisible();
|
||||
});
|
||||
@@ -239,11 +243,12 @@ test("data quality: manual scan runs and shows a result summary", async ({ page,
|
||||
test("automation page: status filter and retry button work", async ({ page, request }) => {
|
||||
await resetDemoData(request);
|
||||
await page.goto("/automation");
|
||||
await expect(page.locator(".data-table")).toBeVisible();
|
||||
const jobsTable = page.getByRole("table", { name: "Automation jobs" });
|
||||
await expect(jobsTable).toBeVisible();
|
||||
|
||||
await page.getByLabel("Status").selectOption("failed");
|
||||
await expect(page.locator(".data-table tbody tr").first()).toBeVisible();
|
||||
const failedRowCountBefore = await page.locator(".data-table tbody tr").count();
|
||||
await expect(jobsTable.locator("tbody tr").first()).toBeVisible();
|
||||
const failedRowCountBefore = await jobsTable.locator("tbody tr").count();
|
||||
const retryButton = page.getByRole("button", { name: "Retry" }).first();
|
||||
await expect(retryButton).toBeVisible();
|
||||
await retryButton.click();
|
||||
@@ -252,7 +257,7 @@ test("automation page: status filter and retry button work", async ({ page, requ
|
||||
// filtered to "failed" — the row correctly disappears from this view rather than
|
||||
// showing "pending" in place. Confirm the filtered list shrank by one.
|
||||
await expect(async () => {
|
||||
const count = await page.locator(".data-table tbody tr").count();
|
||||
const count = await jobsTable.locator("tbody tr").count();
|
||||
expect(count).toBe(failedRowCountBefore - 1);
|
||||
}).toPass({ timeout: 5000 });
|
||||
});
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
import { expect, test } from "@playwright/test";
|
||||
|
||||
test("operational lists use bounded server pages and retain filter state in the URL", async ({ page, request }) => {
|
||||
await request.post("/api/v1/demo/login", { data: { role: "operations_manager" } });
|
||||
|
||||
const vehicles = await request.get("/api/v1/vehicles?page=1&page_size=25");
|
||||
expect(vehicles.ok()).toBeTruthy();
|
||||
const vehiclePage = await vehicles.json();
|
||||
expect(vehiclePage.items).toHaveLength(25);
|
||||
expect(vehiclePage.total).toBeGreaterThanOrEqual(25);
|
||||
|
||||
const audit = await request.get("/api/v1/audit?page=1&page_size=25");
|
||||
expect(audit.ok()).toBeTruthy();
|
||||
const auditPage = await audit.json();
|
||||
expect(auditPage.items.length).toBeLessThanOrEqual(25);
|
||||
|
||||
await page.goto("/vehicles?status=maintenance&page=1");
|
||||
await expect(page.getByRole("heading", { name: "Wagenpark" })).toBeVisible();
|
||||
await expect(page).toHaveURL(/status=maintenance/);
|
||||
});
|
||||
|
||||
test("record status remains visible and responsive lists do not overflow on mobile", async ({ page }) => {
|
||||
await page.setViewportSize({ width: 390, height: 844 });
|
||||
await page.goto("/login");
|
||||
await page.getByRole("button", { name: "Verken als Operationsmanager" }).click();
|
||||
await page.goto("/bookings/BK-DEMO-RETURN");
|
||||
|
||||
await expect(page.getByRole("heading", { name: "BK-DEMO-RETURN" })).toBeVisible();
|
||||
await expect(page.locator(".page-actions .badge")).toBeVisible();
|
||||
await page.goto("/vehicles");
|
||||
const dimensions = await page.evaluate(() => ({ scroll: document.documentElement.scrollWidth, client: document.documentElement.clientWidth }));
|
||||
expect(dimensions.scroll).toBeLessThanOrEqual(dimensions.client + 1);
|
||||
});
|
||||
@@ -4,6 +4,7 @@
|
||||
<meta charset="UTF-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<meta name="description" content="Fleet Ops synthetic-data operations demo" />
|
||||
<link rel="icon" type="image/svg+xml" href="/favicon.svg" />
|
||||
<title>Fleet Ops</title>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 32 32">
|
||||
<rect width="32" height="32" rx="7" fill="#0f172a" />
|
||||
<path d="M16 25.5c-4.4-5.1-6-8.2-6-11a6 6 0 1 1 12 0c0 2.8-1.6 5.9-6 11Z" fill="white" />
|
||||
<circle cx="16" cy="14.3" r="2.1" fill="#2dd4bf" />
|
||||
<rect x="3" y="20.6" width="26" height="2.4" rx="1.2" fill="#2dd4bf" />
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 344 B |
@@ -0,0 +1,12 @@
|
||||
export class ApiError extends Error {
|
||||
status: number;
|
||||
code: string;
|
||||
correlationId: string;
|
||||
|
||||
constructor(status: number, code: string, message: string, correlationId: string) {
|
||||
super(message);
|
||||
this.status = status;
|
||||
this.code = code;
|
||||
this.correlationId = correlationId;
|
||||
}
|
||||
}
|
||||