Commit Graph

2 Commits

Author SHA1 Message Date
Claude 9041dc9b64
에스컬레이션 하드게이트 우회 구멍 차단 + 서버 측 삭제 플로우 추가
발견한 문제: POST /conversations/:id/messages가 sender_mode=twin을
검증 없이 그대로 저장·브로드캐스트하고 있었음 -- 에스컬레이션 게이트는
초안 생성(/draft) 경로에만 있었고 실제 발송 경로엔 없어서, 클라이언트가
/draft를 거치지 않고 바로 twin 메시지를 보내면 안전선을 완전히
우회할 수 있었다.

- ai-service: /draft와 별개인 POST /escalate/check 하드게이트 엔드포인트 추가
- core-backend: AIServiceClient.checkEscalation 추가, 메시지 저장 직전에
  twin 발송이면 무조건 호출하도록 해서 발송이 실제로 일어나는 단
  하나의 지점에서 막음. AI 서비스 응답 불가 시 fail-safe로 발송 차단.
  에스컬레이션되면 저장/브로드캐스트 없이 escalation_logs에만 기록.
  사람이 직접 보내는 메시지는 게이트 대상 아님
- core-backend: DELETE /users/:id 추가 -- 유저가 걸린 모든 행(트윈 설정·
  화이트리스트·연락처·대화참여·메시지·에스컬레이션로그·유저 본인)을
  트랜잭션으로 삭제 (tech-design.md §5 "사용자가 언제든 초기화 가능")
- 온디바이스 암호화·데이터 흐름 대시보드는 Flutter 클라이언트 책임이라
  이 환경에서는 보류, roadmap.md에 근거 남김
2026-07-30 02:26:02 +00:00
Claude e8cf48074f
Promote PoC scripts to the AI service (item 2.2)
ai-service/ wraps generate_draft/escalation_filter/retrieve_style
behind a single POST /draft endpoint that the Go core will call
internally. poc/tone-corpus/ stays untouched for corpus experiments
and blind-eval; this is the promoted copy meant for the real service.

Verified with TestClient: style_examples path, history/retrieval
path (confirms the earlier scoring fix still ranks the on-topic
exemplar first), escalation short-circuit, and 422 validation when
zero or both of style_examples/history are given.

Still missing: the Go core's actual HTTP client calling this service.
2026-07-30 02:09:19 +00:00