chore(sync): zsy_developcc 全量同步至 qyqy_develop(W27 口径)

- 分支内容对齐 qyqy_develop 3e24033,树完全一致(同步后 git diff 为空)
- 覆盖本轮 W27 交付:L0 表层判定层 + 出口 E6 行情 + 收益过滤槽位白名单
  + 免责声明分档 + 金标扩容至 55 条(全绿)+ 配置版本 244 已发布
- 新增 app/core/exit_codes.py、app/service/fund_trend_service.py 及 3 个测试文件
- 新增 开发文档\D3.9-客服Agent智能路由与行情出口设计-2026-09-21.md
- 基线:e239eb7(2026-09-17 品牌口径统一快照),本提交为其直接后继
This commit is contained in:
张胜宇
2026-09-21 22:33:09 +08:00
parent 9675df8453
commit da1d14cb31
27 changed files with 3542 additions and 1041 deletions
+12 -1
View File
@@ -260,7 +260,18 @@ def test_visitor_role_can_run_but_only_with_public_scope() -> None:
"""
from app.core.actor import VISITOR_DATA_SCOPE, VISITOR_PERMISSIONS
assert set(VISITOR_PERMISSIONS) == {"agent:run", "knowledge:query"}
# 逐项列出**允许**的权限码,而不是"只要不含个人数据前缀就放行":
# 白名单式才能拦住"新增了一个我们没想到的公开权限面"。
# `fund:quote:read` 是 `W27` / `DEC-W27-11` 批准的**唯一新增项** ——
# 净值走势是公开事实(`fin_product` 的场内产品 + `fin_nav_history`),
# 不读任何个人数据、也不读画像;对应的出口是 `E6`。
assert set(VISITOR_PERMISSIONS) == {"agent:run", "knowledge:query", "fund:quote:read"}
# ⚠️ 逆向守卫:`fund:` 前缀里**只允许** `fund:quote:read` 这一个码。
# 将来若有人顺手加上 `fund:order:read`(成交明细=个人数据),上面那条
# 个人数据前缀判据抓不到(前缀是 `fund:` 不是 `customer:`),但这一条会立刻变红。
assert {name for name in VISITOR_PERMISSIONS if name.startswith("fund:")} == {
"fund:quote:read"
}
assert VISITOR_DATA_SCOPE == "public"
personal_prefixes = ("customer:", "profile:", "memory:", "handover:", "conversation:")
assert [