feat(merge): 完成 AL-09 合并接线,整合风控模块与宿主 Wave 0

- 合并 `risk-control-agent` 分支至 `merger`,实现 JWT 统一与模块 API 恢复。
- 更新 `auth_service` 和 `auth_adapter`,确保对外登录/token 统一。
- 增强 chat 模块,支持会话管理与流式对话(SSE)。
- 测试基线更新至 502 passed, 1 skipped,确保系统稳定性。

此更新标志着风控模块的成功集成,提升了系统的整体功能与可维护性。
This commit is contained in:
2026-09-08 20:00:39 +08:00
parent 6d780d45c3
commit f87e11f104
12 changed files with 100 additions and 80 deletions
+5 -5
View File
@@ -34,11 +34,11 @@
| 模块 | 职责 | 依赖 | 代码状态 |
| --- | --- | --- | --- |
| Agent Gateway / Auth SDK | JWT、RBAC、归属校验 | Redis、MySQL customer_advisor_rel | **已实现(T-01,2026-09-07)**:`service/auth_service.py`(验签/吊销)+ `api/deps.py`(Bearer 全环境优先 + dev debug 头兜底 + AGENT_ACCESS_MATRIX 准入) |
| Agent Gateway / Auth SDK | JWT、RBAC、归属校验 | Redis、MySQL customer_advisor_rel | **已实现(T-01 + AL-09)**:模块 `service/auth_service.py` + `api/deps.py`;宿主 `gateway/` 四件套并存;`/api/auth/login` 统一走 `issue_dev_token`;S2 接缝 `auth_adapter.module_auth_from_host` |
| 客户财富 Agent | L1 画像、事实查询、阈值提醒 | Core RO、Milvus 产品库 | 空壳 service(chat 骨架已通) |
| 代理人助手 Agent | L2 画像、RAG、草稿 | L1 只读、Milvus | 空壳 service(chat 骨架已通) |
| 数据分析 Agent | NL→SQL→解读 | Core RO、画像只读 | 空壳 service(chat 骨架已通) |
| 风控监测 Agent | 预警、L3、R-02 适当性 | 交易事件、AML 名单 | **已实现 B1~B7 + C1~C3(对话线四 Tool + risk 分支 StateGraph,A-6 验收)**;追加 FR-8/9/10(C4~C6:集中度/时效升级/行为链)方案已定稿待编码 |
| 风控监测 Agent | 预警、L3、R-02 适当性 | 交易事件、AML 名单 | **已实现 B1~B9b + C1~C6(FR-1~10)**:事件线 + 对话线 + 集中度/时效升级/代理人行为链;**AL-09 已并入 `merger` 分支** |
| Core 只读层 | L0 事实查询 | `jinrong_core` | **已实现 + 已接对话 Tool(T-04)**:core_ro 经 app/tool/core_tools.py 三只读 Tool(L0/持仓/流水)进 chat;风控扩展查询照旧 |
| 共用底座 | 会话、审计、输入防护 | MySQL 11 表 + Redis | **已接入(2026-09-07)**:会话(T-06 session_repository + memory_service 窗口)、审计中间件(T-02 http_access + input_guard_log 双写)、agent_tool_call Tool 留痕(T-04)、输入防护(T-03 input_guard:注入词表纯函数检测 + oversize + Redis 固定窗口限流,chat 链路 限流→注入/超长→归属) |
| 对话编排 | LangGraph StateGraph + DeepSeek | langgraph/langchain-openai | **已实现(T-07 骨架 + T-04 Tool 节点 + C1 风控四 Tool + C2 risk 分支,2026-09-07)**:tool(分组关键词意图→Tool,customer/advisor/risk)→llm→guard(免责声明);analyst 分支与 LLM intent 待后续 |
@@ -49,7 +49,7 @@
## 3. 后端分层(app/)
```text
api/ → risk / simulate / chat / deps / audit_middleware 已实现;knowledge、admin 空壳 【大部分】
api/ → auth / risk / simulate / chat(含 sessions/stream)/ deps / auth_adapter / audit_middleware 已实现;knowledge、admin 空壳 【大部分】
service/ → risk/*(rules/alert/aml/engine/l3/scoring/locks/redis_gateway/chat_tools)+ suitability +
auth_service(T-01 JWT)+ agent_service(T-07 图 + T-04 tool 节点 + C2 risk 分支)+ memory_service(T-06)+
tool_service(T-04 对话 Tool 编排:意图/归属校验/run_tool 落库)+ input_guard(T-03)+
@@ -63,7 +63,7 @@ gateway/ → 模拟交易网关(trade_gateway + gateway_repository 仅 IN
model/ → schemas(Pydantic)、entities(ORM) 【占位】(风控暂用 dict,收敛待后续)
config/ → settings(双库 + risk_* 阈值 + JWT 配置)、database 【settings 已实现】
utils/ → trace(trace_id+request_id)/ desensitize / db(引擎工厂)/ response(统一错误体)/ exceptions 【基本就绪;logger 占位】
main.py → 路由挂载 + trace 中间件(双 ID 贯通 + 500 兜底)+ audit 中间件 + lifespan(B7/T-02) 【已集成】
main.py → 宿主 TraceMiddleware + 模块 audit/trace 中间件 + 路由挂载 + lifespan(AL-09);trace 对 ApiError 等 re-raise 【已集成】
允许:api → service → tool / repository / model / config
禁止:api 直连 Milvus/MySQL 写复杂逻辑;tool 写业务流程;repository 写 Core
@@ -80,7 +80,7 @@ scripts/demo/ → 演示数据准备(prepare_risk_demo.sql,reset 后
scripts/sync/ → sync_advisor_rel.py、sync_neo4j.py
scripts/dev/ → issue_dev_token.py(JWT 签发)+ rbac-seed-reference.md(联调账号)
scripts/kb/ → build_kb.py(知识库入库,T-21)
scripts/cron/ → (C5/C6 规划)escalation_scan.py / agent_behavior_scan.py 定时任务
scripts/cron/ → escalation_scan.py / agent_behavior_scan.py(C5/C6 定时任务,独立脚本非 lifespan 内嵌)
```
------