Files
cc-web/.planning/2026-08-24-gitea-webhook-docs/findings.md

22 lines
1.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 发现记录
## 现状
- `docs/gitea-workflow/PRD.md` 与 `ARCHITECTURE.md` 已存在,已约定 MVP 为单
Gitea 实例、`ccweb-bot`、同仓库串行、全局并发 2、线程级 `gitea-mcp`。
- 当前仓库没有 Gitea 业务实现入口;本轮脚本必须测试协议/状态机纯函数,不应
假设或改写 `server.js`。
- `package.json` 只有 `npm run regression`;新增脚本应提供独立 `node` 入口,
便于实现接入阶段先运行夹具回归。
## 交付设计
- `DEPLOYMENT.md`:配置分层、Webhook 反向代理、凭据、目录权限、启动顺序、
健康检查、暂停/恢复、备份恢复、故障处置、日志脱敏和容量基线。
- `TESTING.md`:测试金字塔、fixtures 协议、场景矩阵、故障注入、恢复/重试
断言、MCP `thread/start.config.mcp_servers.gitea` 契约与安全测试。
- `scripts/gitea-webhook-regression.js`:零依赖 Node 脚本,加载 fixtures,
对原始 body 做 HMAC-SHA256 常量时间校验,验证事件过滤、delivery 去重、
队列恢复/并发互斥、回执补发/REST 兜底、线程级 MCP 配置、路径边界以及敏感
信息不泄漏。