chore(sync): zsy_developcc 全量同步至 qyqy_develop(W26 口径)

- 分支内容对齐 qyqy_develop b6ec3aa,树完全一致(同步后 git diff 为空)
- 覆盖本轮全部交付:客服 Agent 重构(安全路由 / 五出口 / 记忆与画像 / RAG 全链路)
  + 开发文档 62 份编号体系(D1.1 v1.17 索引)
  + 新增 D2.10-客服Agent端到端答辩文档-2026-09-21.html
- 基线:e239eb7(2026-09-17 品牌口径统一快照),本提交为其直接后继
This commit is contained in:
张胜宇
2026-09-21 21:26:30 +08:00
parent e239eb778b
commit 9675df8453
330 changed files with 111939 additions and 8681 deletions
@@ -44,6 +44,30 @@ def test_missing_body_fields_use_unified_envelope() -> None:
assert body["meta"] == {"trace_id": "val-trace"}
def test_blank_message_is_rejected_at_the_gateway() -> None:
"""纯空白消息 → 422 信封,**不是 500**。
回归自实测缺口:`min_length=1` 挡不住 `" "`(长度 3),它会穿透入口、被领域层
`AgentRequest` 的 `message must not be blank` 拒掉,而领域层的 `ValidationError`
不属于请求校验异常 ⇒ 客户端拿到的是 500 Internal Server Error(无 code、无 trace)。
"""
with _authenticated_client() as client:
response = client.post(
AGENT_RUNS,
json={
"agent_type": "customer_service", "message": " ",
"session_id": "blank-msg-session", "idempotency_key": "k" * 32,
},
headers={"X-Trace-ID": "blank-trace"},
)
assert response.status_code == 422, f"空白消息应被入口拦下,实际 {response.status_code}"
body = response.json()
assert set(body) == {"error", "meta"}
assert body["error"]["code"] == "AGENT_INPUT_INVALID"
assert "body.message" in {item["field"] for item in body["error"]["field_errors"]}
def test_validation_handler_does_not_hijack_authentication() -> None:
"""未带令牌 + 参数也不合法:必须仍是 401,参数校验不得掩盖鉴权失败。"""
with TestClient(create_app()) as client: