feat(threshold): Implement customer loss threshold configuration and notification system
- Added `ThresholdRepository` for managing customer loss threshold configurations and notifications. - Introduced `threshold_service` to handle loss threshold alerts based on customer portfolio performance. - Enhanced `customer_prompts` to include new intent for querying product net values. - Updated `customer_service` to integrate new threshold alert functionality into existing workflows. - Implemented `sanitize_postprocess` for improved compliance handling in customer interactions. - Enhanced course documentation to reflect updates in advisor training modules and interactive elements. This update significantly improves the customer experience by providing proactive loss threshold notifications and enhancing the overall service framework.
This commit is contained in:
@@ -1,12 +1,12 @@
|
||||
<section class="module" id="module-3">
|
||||
<div class="module-inner">
|
||||
<p class="eyebrow animate-in">模块 3 · 防护与审计</p>
|
||||
<h1 class="module-title animate-in">input_guard 限流注入、<br>audit_middleware 留痕</h1>
|
||||
<h1 class="module-title animate-in">input_guard 限流注入、<br>审计中间件(audit_middleware.py)留痕</h1>
|
||||
<p class="module-lead animate-in">
|
||||
用户消息进 LLM 前要经过
|
||||
<span class="term" data-definition="input_guard = 输入防护:检查注入短语、超长、频率限制,命中就拒答并写 input_guard_log。">input_guard</span>;
|
||||
每个 HTTP 请求经过
|
||||
<span class="term" data-definition="middleware = 请求进业务代码前的统一关卡,像机场安检,所有人都要过一遍。">audit_middleware</span>
|
||||
<span class="term" data-definition="审计中间件(audit_middleware.py)= 请求进业务代码前的统一关卡,像机场安检,所有人都要过一遍;写 audit_log 访问审计。">审计中间件(audit_middleware.py)</span>
|
||||
写访问审计。鉴权 403 还会双写 audit_log + input_guard_log(平台线部分跳过 ENUM 限制)。
|
||||
</p>
|
||||
|
||||
@@ -56,7 +56,7 @@
|
||||
<div class="chat-message" data-msg="3" data-sender="api" style="display:none">
|
||||
<div class="chat-avatar" style="background: #2D8B55">🚪</div>
|
||||
<div class="chat-bubble">
|
||||
<span class="chat-sender" style="color: #2D8B55">chat.py</span>
|
||||
<span class="chat-sender" style="color: #2D8B55">对话 HTTP 入口(chat.py)</span>
|
||||
<p>返回 400 + 友好拒答文案;trace_id 可对照审计</p>
|
||||
</div>
|
||||
</div>
|
||||
@@ -79,7 +79,7 @@
|
||||
<div class="screen animate-in">
|
||||
<div class="translation-block">
|
||||
<div class="translation-code">
|
||||
<span class="translation-label">chat.py + audit_middleware</span>
|
||||
<span class="translation-label">对话 HTTP 入口(chat.py)+ 审计中间件(audit_middleware.py)</span>
|
||||
<pre><code><span class="code-line"><span class="code-keyword">if not</span> input_guard.check_rate_limit(agent_type, auth.actor_id):</span>
|
||||
<span class="code-line"> insert_input_guard_log(..., guard_type=GUARD_RATE_LIMIT)</span>
|
||||
<span class="code-line"> raise ApiError(...)</span>
|
||||
@@ -88,7 +88,7 @@
|
||||
<span class="code-line"><span class="code-keyword">if</span> verdict.reject:</span>
|
||||
<span class="code-line"> insert_input_guard_log(..., guard_type=verdict.guard_type)</span>
|
||||
<span class="code-line"></span>
|
||||
<span class="code-line"><span class="code-comment"># main.py 挂载</span></span>
|
||||
<span class="code-line"><span class="code-comment"># 应用入口(main.py)挂载</span></span>
|
||||
<span class="code-line">async <span class="code-keyword">def</span> <span class="code-function">audit_middleware</span>(request, call_next):</span>
|
||||
<span class="code-line"> <span class="code-comment"># INSERT audit_log 单请求访问记录</span></span></code></pre>
|
||||
</div>
|
||||
@@ -97,8 +97,8 @@
|
||||
<div class="translation-lines">
|
||||
<p class="tl">先发消息前查频率:同 actor 刷太快就拒,并记限流日志。</p>
|
||||
<p class="tl">再扫内容:注入/超长命中就不调 LLM,直接拒答+留痕。</p>
|
||||
<p class="tl">audit_middleware 包在更外层:每个 HTTP 进来都记一条访问审计。</p>
|
||||
<p class="tl">deps.deny 鉴权失败也会双写——平台 agent_type 时 input_guard_log 可能跳过 ENUM 限制。</p>
|
||||
<p class="tl">审计中间件(audit_middleware.py)包在更外层:每个 HTTP 进来都记一条访问审计。</p>
|
||||
<p class="tl">模块鉴权(deps.py).deny 鉴权失败也会双写——平台 agent_type 时 input_guard_log 可能跳过 ENUM 限制。</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
@@ -124,12 +124,12 @@
|
||||
</div>
|
||||
<div class="quiz-question-block"
|
||||
data-correct="option-a"
|
||||
data-explanation-right="audit_middleware 记录每个请求的访问轨迹;input_guard_log 专记输入防护命中。"
|
||||
data-explanation-wrong="两者不同表、不同触发点;middleware 不替 guard 做注入检测。">
|
||||
<h3 class="quiz-question">audit_middleware 和 input_guard 的关系?</h3>
|
||||
data-explanation-right="审计中间件(audit_middleware.py)记录每个请求的访问轨迹;input_guard_log 专记输入防护命中。"
|
||||
data-explanation-wrong="两者不同表、不同触发点;审计中间件(audit_middleware.py)不替 guard 做注入检测。">
|
||||
<h3 class="quiz-question">审计中间件(audit_middleware.py)和 input_guard 的关系?</h3>
|
||||
<div class="quiz-options">
|
||||
<button class="quiz-option" data-value="option-a" onclick="selectOption(this)">
|
||||
<div class="quiz-option-radio"></div><span>middleware 记访问;guard 在 chat 业务里拦恶意输入</span>
|
||||
<div class="quiz-option-radio"></div><span>审计中间件(audit_middleware.py)记访问;guard 在对话 HTTP 入口(chat.py)业务里拦恶意输入</span>
|
||||
</button>
|
||||
<button class="quiz-option" data-value="option-b" onclick="selectOption(this)">
|
||||
<div class="quiz-option-radio"></div><span>同一个函数,名字不同</span>
|
||||
|
||||
Reference in New Issue
Block a user