test_business_assistant.py 40 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133
  1. from __future__ import annotations
  2. import json
  3. from datetime import UTC, datetime, timedelta
  4. from types import SimpleNamespace
  5. import pytest
  6. from aiohttp import CookieJar
  7. from aiohttp.test_utils import TestClient, TestServer
  8. from pyrogram.enums import ChatMemberStatus
  9. def connection_payload(connection_id: str = "conn-a", *, can_reply: bool = True) -> dict:
  10. return {
  11. "id": connection_id,
  12. "user": {"id": 900, "username": "owner", "first_name": "店主"},
  13. "user_chat_id": 900,
  14. "date": int(datetime.now(UTC).timestamp()),
  15. "rights": {"can_reply": can_reply, "can_read_messages": True},
  16. "is_enabled": True,
  17. }
  18. def customer_message(
  19. *,
  20. message_id: int,
  21. text: str | None = "营业时间是什么?",
  22. chat_id: int = 501,
  23. sender_id: int = 501,
  24. sent_at: datetime | None = None,
  25. **values,
  26. ) -> dict:
  27. message = {
  28. "business_connection_id": "conn-a",
  29. "message_id": message_id,
  30. "date": int((sent_at or datetime.now(UTC)).timestamp()),
  31. "chat": {"id": chat_id, "type": "private"},
  32. "from": {"id": sender_id, "username": f"user{sender_id}", "first_name": "客户"},
  33. **values,
  34. }
  35. if text is not None:
  36. message["text"] = text
  37. return message
  38. class FakeProvider:
  39. configured = True
  40. def __init__(self, *, error: Exception | None = None) -> None:
  41. self.error = error
  42. self.calls: list[dict] = []
  43. self.extraction_calls: list[dict] = []
  44. async def decide(self, **values):
  45. self.calls.append(values)
  46. if self.error:
  47. raise self.error
  48. entry_id = str(values["knowledge"][0]["entry_id"])
  49. return {
  50. "action": "answer",
  51. "reply": "每天 09:00 至 18:00 营业。",
  52. "handoff_reason": "",
  53. "matched_entry_ids": [entry_id],
  54. "summary": "客户询问营业时间。",
  55. }
  56. async def test_connection(self):
  57. return {"ok": True, "model": "test-model", "response_id": "response-1"}
  58. async def extract_knowledge(self, **values):
  59. self.extraction_calls.append(values)
  60. if self.error:
  61. raise self.error
  62. return [
  63. {
  64. "question": values.get("question_context") or "如何办理?",
  65. "aliases": [],
  66. "keywords": ["办理"],
  67. "answer": values["content"],
  68. "tags": ["自动采集"],
  69. "confidence": 0.92,
  70. }
  71. ]
  72. class FakeBusinessApi:
  73. def __init__(self) -> None:
  74. self.sent: list[dict] = []
  75. self.read: list[tuple[str, int, int]] = []
  76. async def send_message(
  77. self,
  78. chat_id: int,
  79. text: str,
  80. *,
  81. business_connection_id: str = "",
  82. reply_markup: dict | None = None,
  83. ) -> dict:
  84. self.sent.append(
  85. {
  86. "chat_id": chat_id,
  87. "text": text,
  88. "business_connection_id": business_connection_id,
  89. "reply_markup": reply_markup,
  90. }
  91. )
  92. return {
  93. "message_id": 1000 + len(self.sent),
  94. "sender_business_bot": {"id": 999},
  95. }
  96. async def read_business_message(
  97. self, connection_id: str, chat_id: int, message_id: int
  98. ) -> None:
  99. self.read.append((connection_id, chat_id, message_id))
  100. class FakeFeishuWebhook:
  101. def __init__(self) -> None:
  102. self.sent: list[dict] = []
  103. async def send(self, webhook_url: str, text: str, *, signing_secret: str = "") -> None:
  104. self.sent.append(
  105. {
  106. "webhook_url": webhook_url,
  107. "text": text,
  108. "signing_secret": signing_secret,
  109. }
  110. )
  111. async def prepare_runtime(app_modules, *, provider: FakeProvider | None = None):
  112. dbassistant = app_modules.load("wbb.utils.dbassistant")
  113. service = app_modules.load("wbb.services.business_assistant")
  114. await dbassistant.upsert_business_connection(connection_payload())
  115. await dbassistant.update_account_settings("conn-a", {"assistant_enabled": True})
  116. knowledge = await dbassistant.create_knowledge_entry(
  117. "conn-a",
  118. {
  119. "question": "营业时间是什么?",
  120. "aliases": ["几点营业"],
  121. "keywords": ["营业时间", "营业"],
  122. "answer": "每天 09:00 至 18:00 营业。",
  123. "priority": 10,
  124. },
  125. )
  126. selected_provider = provider or FakeProvider()
  127. runtime = service.BusinessAssistantRuntime(
  128. token="123456:" + "A" * 30,
  129. session=SimpleNamespace(),
  130. provider=selected_provider,
  131. )
  132. runtime.api = FakeBusinessApi()
  133. return dbassistant, service, runtime, knowledge
  134. async def test_connection_settings_knowledge_quota_and_bot_scope(app_modules):
  135. dbassistant = app_modules.load("wbb.utils.dbassistant")
  136. await dbassistant.upsert_business_connection(connection_payload("conn-a"))
  137. await dbassistant.upsert_business_connection(connection_payload("conn-b"))
  138. settings = await dbassistant.update_account_settings(
  139. "conn-a",
  140. {
  141. "assistant_enabled": True,
  142. "account_daily_limit": 2,
  143. "customer_daily_limit": 1,
  144. "timezone": "Asia/Shanghai",
  145. },
  146. )
  147. first = await dbassistant.create_knowledge_entry(
  148. "conn-a",
  149. {
  150. "question": "营业时间",
  151. "aliases": ["几点开门"],
  152. "keywords": ["开门"],
  153. "answer": "九点开门。",
  154. "priority": 20,
  155. },
  156. )
  157. await dbassistant.create_knowledge_entry(
  158. "conn-b",
  159. {"question": "营业时间", "keywords": ["开门"], "answer": "十点开门。"},
  160. )
  161. await app_modules.wbb.db.business_assistant_knowledge.insert_one(
  162. {
  163. "bot_id": "foreign-bot",
  164. "entry_id": "foreign-entry",
  165. "connection_id": "conn-a",
  166. "question": "营业时间",
  167. "aliases": [],
  168. "keywords": ["开门"],
  169. "answer": "不应跨 Bot 返回。",
  170. "priority": 1000,
  171. "enabled": True,
  172. "updated_at": datetime.now(UTC),
  173. }
  174. )
  175. matched = await dbassistant.match_knowledge("conn-a", "你们几点开门?")
  176. assert [item["entry_id"] for item in matched] == [first["entry_id"]]
  177. items, total = await dbassistant.list_knowledge_entries("conn-a")
  178. assert total == 1
  179. assert items[0]["answer"] == "九点开门。"
  180. await app_modules.wbb.db.business_assistant_connections.insert_one(
  181. {
  182. "bot_id": "foreign-bot",
  183. "connection_id": "foreign-connection",
  184. "updated_at": datetime.now(UTC),
  185. }
  186. )
  187. connections, total = await dbassistant.list_business_connections(page_size=100)
  188. assert total == 2
  189. assert {item["connection_id"] for item in connections} == {"conn-a", "conn-b"}
  190. assert await dbassistant.reserve_ai_usage("conn-a", 101, settings) == (True, "")
  191. assert await dbassistant.reserve_ai_usage("conn-a", 101, settings) == (
  192. False,
  193. "customer_daily_limit",
  194. )
  195. assert await dbassistant.reserve_ai_usage("conn-a", 102, settings) == (True, "")
  196. assert await dbassistant.reserve_ai_usage("conn-a", 103, settings) == (
  197. False,
  198. "account_daily_limit",
  199. )
  200. usage = await dbassistant.usage_metrics(connection_id="conn-a")
  201. assert usage["ai_calls"] == 2
  202. assert usage["customers"] == 2
  203. with pytest.raises(dbassistant.AssistantDataError) as error:
  204. dbassistant.normalize_account_settings({"timezone": "invalid/timezone"})
  205. assert error.value.code == "invalid_setting"
  206. async def test_feishu_settings_are_validated_and_never_exposed(app_modules):
  207. dbassistant = app_modules.load("wbb.utils.dbassistant")
  208. await dbassistant.upsert_business_connection(connection_payload())
  209. webhook_url = "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc"
  210. stored = await dbassistant.update_account_settings(
  211. "conn-a",
  212. {
  213. "feishu_webhook_enabled": True,
  214. "feishu_webhook_url": webhook_url,
  215. "feishu_webhook_signing_secret": "signing-secret",
  216. "feishu_message_preview_enabled": True,
  217. },
  218. )
  219. assert stored["feishu_webhook_url"] == webhook_url
  220. assert stored["feishu_webhook_signing_secret"] == "signing-secret"
  221. public = dbassistant.public_account_settings(stored)
  222. assert public["feishu_webhook_url"] == ""
  223. assert public["feishu_webhook_signing_secret"] == ""
  224. assert public["feishu_webhook_configured"] is True
  225. assert public["feishu_signing_secret_configured"] is True
  226. connections, _total = await dbassistant.list_business_connections()
  227. assert connections[0]["settings"]["feishu_webhook_url"] == ""
  228. assert connections[0]["settings"]["feishu_webhook_configured"] is True
  229. with pytest.raises(dbassistant.AssistantDataError):
  230. dbassistant.normalize_account_settings(
  231. {
  232. "feishu_webhook_enabled": True,
  233. "feishu_webhook_url": "https://example.com/internal-hook",
  234. }
  235. )
  236. def test_ai_contract_and_reply_window_validation(app_modules):
  237. service = app_modules.load("wbb.services.business_assistant")
  238. parsed = service.parse_ai_decision(
  239. json.dumps(
  240. {
  241. "action": "answer",
  242. "reply": "标准答案",
  243. "matched_entry_ids": ["entry-1", "foreign"],
  244. "summary": "摘要",
  245. }
  246. ),
  247. allowed_entry_ids={"entry-1"},
  248. )
  249. assert parsed["matched_entry_ids"] == ["entry-1"]
  250. with pytest.raises(service.AssistantProviderError):
  251. service.parse_ai_decision(
  252. '{"action":"answer","reply":"没有引用"}', allowed_entry_ids={"entry-1"}
  253. )
  254. now = datetime.now(UTC)
  255. assert service.business_reply_window_open(
  256. {"date": int((now - timedelta(hours=23)).timestamp())}, now=now
  257. )
  258. assert not service.business_reply_window_open(
  259. {"date": int((now - timedelta(hours=25)).timestamp())}, now=now
  260. )
  261. assert not service.business_reply_window_open({}, now=now)
  262. extracted = service.parse_knowledge_extraction(
  263. json.dumps(
  264. {
  265. "items": [
  266. {
  267. "question": "如何配送?",
  268. "aliases": ["配送范围"],
  269. "keywords": ["配送"],
  270. "answer": "仅支持市区配送。",
  271. "tags": ["配送"],
  272. "confidence": 0.9,
  273. }
  274. ]
  275. }
  276. )
  277. )
  278. assert extracted[0]["confidence"] == 0.9
  279. assert (
  280. service.redact_business_knowledge_text(
  281. "电话 138 0013 8000,邮箱 user@example.com,Telegram @private_user"
  282. )
  283. == "电话 [电话已脱敏],邮箱 [邮箱已脱敏],Telegram [用户名已脱敏]"
  284. )
  285. async def test_source_event_candidates_publish_edit_delete_and_isolate(app_modules):
  286. dbassistant = app_modules.load("wbb.utils.dbassistant")
  287. await dbassistant.upsert_business_connection(connection_payload("conn-a"))
  288. await dbassistant.upsert_business_connection(connection_payload("conn-b"))
  289. source = await dbassistant.create_knowledge_source(
  290. "conn-a",
  291. {
  292. "source_type": "channel",
  293. "chat_id": -100100,
  294. "title": "官方频道",
  295. "publication_mode": "auto",
  296. "author_policy": "admins_or_allowlist",
  297. },
  298. )
  299. event, changed = await dbassistant.record_source_event(
  300. source,
  301. event_key="telegram:-100100:10",
  302. content="每天九点营业。",
  303. metadata={"chat_id": -100100, "message_id": 10, "trusted_author": True},
  304. )
  305. assert changed is True
  306. candidates = await dbassistant.replace_event_candidates(
  307. source,
  308. event,
  309. [
  310. {
  311. "question": "几点营业?",
  312. "aliases": ["营业时间"],
  313. "keywords": ["营业"],
  314. "answer": "每天九点营业。",
  315. "tags": ["营业"],
  316. "confidence": 0.95,
  317. }
  318. ],
  319. auto_publish=True,
  320. )
  321. candidate = candidates[0]
  322. first_entry_id = candidate["knowledge_entry_id"]
  323. first_entry = await app_modules.wbb.db.business_assistant_knowledge.find_one(
  324. {"bot_id": "primary", "entry_id": first_entry_id}
  325. )
  326. assert candidate["status"] == "published"
  327. assert first_entry["enabled"] is True
  328. edited_event, changed = await dbassistant.record_source_event(
  329. source,
  330. event_key="telegram:-100100:10",
  331. content="每天十点营业。",
  332. metadata={"chat_id": -100100, "message_id": 10, "trusted_author": True},
  333. )
  334. assert changed is True
  335. edited = await dbassistant.replace_event_candidates(
  336. source,
  337. edited_event,
  338. [
  339. {
  340. "question": "几点营业?",
  341. "aliases": [],
  342. "keywords": ["营业"],
  343. "answer": "每天十点营业。",
  344. "tags": ["营业"],
  345. "confidence": 0.96,
  346. }
  347. ],
  348. auto_publish=True,
  349. )
  350. assert edited[0]["knowledge_entry_id"] == first_entry_id
  351. updated_entry = await app_modules.wbb.db.business_assistant_knowledge.find_one(
  352. {"bot_id": "primary", "entry_id": first_entry_id}
  353. )
  354. assert updated_entry["answer"] == "每天十点营业。"
  355. assert await dbassistant.mark_source_event_deleted(
  356. source["source_id"], "telegram:-100100:10"
  357. )
  358. stale = await dbassistant.get_knowledge_candidate(candidate["candidate_id"])
  359. disabled_entry = await app_modules.wbb.db.business_assistant_knowledge.find_one(
  360. {"bot_id": "primary", "entry_id": first_entry_id}
  361. )
  362. assert stale["status"] == "stale"
  363. assert disabled_entry["enabled"] is False
  364. sources_a, total_a = await dbassistant.list_knowledge_sources("conn-a")
  365. sources_b, total_b = await dbassistant.list_knowledge_sources("conn-b")
  366. assert total_a == 1 and sources_a[0]["source_id"] == source["source_id"]
  367. assert total_b == 0 and sources_b == []
  368. event_indexes = await app_modules.wbb.db.business_assistant_source_events.index_information()
  369. assert event_indexes["expires_at_1"]["expireAfterSeconds"] == 0
  370. async def test_business_human_reply_learns_only_when_source_enabled(app_modules):
  371. dbassistant, _service, runtime, _knowledge = await prepare_runtime(app_modules)
  372. await runtime.process_update(
  373. {
  374. "update_id": 9,
  375. "business_message": customer_message(
  376. message_id=9, text="配送到哪里?", chat_id=509, sender_id=509
  377. ),
  378. }
  379. )
  380. await runtime.process_update(
  381. {
  382. "update_id": 10,
  383. "business_message": customer_message(
  384. message_id=10, text="仅支持市区配送。", chat_id=509, sender_id=900
  385. ),
  386. }
  387. )
  388. assert runtime.provider.extraction_calls == []
  389. await dbassistant.create_knowledge_source(
  390. "conn-a",
  391. {
  392. "source_type": "business",
  393. "title": "人工接待对话",
  394. "publication_mode": "auto",
  395. },
  396. )
  397. await runtime.process_update(
  398. {
  399. "update_id": 15,
  400. "business_message": customer_message(
  401. message_id=15, text="支持哪些区域?", chat_id=515, sender_id=515
  402. ),
  403. }
  404. )
  405. await runtime.process_update(
  406. {
  407. "update_id": 16,
  408. "business_message": customer_message(
  409. message_id=16, text="仅支持市区配送。", chat_id=515, sender_id=900
  410. ),
  411. }
  412. )
  413. assert len(runtime.provider.extraction_calls) == 1
  414. candidates, total = await dbassistant.list_knowledge_candidates(
  415. "conn-a", status="published"
  416. )
  417. assert total == 1
  418. assert candidates[0]["answer"] == "仅支持市区配送。"
  419. entry_id = candidates[0]["knowledge_entry_id"]
  420. await runtime.process_update(
  421. {
  422. "update_id": 17,
  423. "edited_business_message": customer_message(
  424. message_id=16, text="仅二环内支持配送。", chat_id=515, sender_id=900
  425. ),
  426. }
  427. )
  428. edited = await dbassistant.get_knowledge_candidate(candidates[0]["candidate_id"])
  429. assert edited["answer"] == "仅二环内支持配送。"
  430. assert edited["knowledge_entry_id"] == entry_id
  431. await runtime.process_update(
  432. {
  433. "update_id": 18,
  434. "deleted_business_messages": {
  435. "business_connection_id": "conn-a",
  436. "chat": {"id": 515},
  437. "message_ids": [16],
  438. },
  439. }
  440. )
  441. stale = await dbassistant.get_knowledge_candidate(candidates[0]["candidate_id"])
  442. entry = await app_modules.wbb.db.business_assistant_knowledge.find_one(
  443. {"bot_id": "primary", "entry_id": entry_id}
  444. )
  445. assert stale["status"] == "stale"
  446. assert entry["enabled"] is False
  447. async def test_group_collection_requires_trusted_author_for_auto_publish(app_modules):
  448. dbassistant, _service, runtime, _knowledge = await prepare_runtime(app_modules)
  449. module = app_modules.load("wbb.modules.business_assistant")
  450. module._runtime = runtime
  451. await dbassistant.create_knowledge_source(
  452. "conn-a",
  453. {
  454. "source_type": "group",
  455. "chat_id": -100300,
  456. "title": "运营讨论群",
  457. "publication_mode": "auto",
  458. "author_policy": "admins_or_allowlist",
  459. },
  460. )
  461. def group_message(message_id: int, author_id: int, text: str):
  462. return SimpleNamespace(
  463. id=message_id,
  464. text=text,
  465. caption=None,
  466. outgoing=False,
  467. is_automatic_forward=False,
  468. date=datetime.now(UTC),
  469. chat=SimpleNamespace(id=-100300),
  470. from_user=SimpleNamespace(id=author_id, is_bot=False),
  471. )
  472. ordinary = group_message(1, 301, "市区支持当日配送。")
  473. await module.process_knowledge_source_message(ordinary)
  474. pending, pending_total = await dbassistant.list_knowledge_candidates(
  475. "conn-a", status="pending"
  476. )
  477. assert pending_total == 1
  478. assert pending[0]["status"] == "pending"
  479. app_modules.app.members[(-100300, 302)] = SimpleNamespace(
  480. status=ChatMemberStatus.ADMINISTRATOR
  481. )
  482. admin_message = group_message(2, 302, "每周一至周五提供配送。")
  483. await module.process_knowledge_source_message(admin_message)
  484. published, published_total = await dbassistant.list_knowledge_candidates(
  485. "conn-a", status="published"
  486. )
  487. assert published_total == 1
  488. assert published[0]["source_snapshot"]["author_id"] == 302
  489. extraction_count = len(runtime.provider.extraction_calls)
  490. await module.process_knowledge_source_message(admin_message)
  491. assert len(runtime.provider.extraction_calls) == extraction_count
  492. async def test_business_updates_are_idempotent_and_manual_reply_pauses(app_modules):
  493. dbassistant, _service, runtime, knowledge = await prepare_runtime(app_modules)
  494. update = {
  495. "update_id": 11,
  496. "business_message": customer_message(message_id=1),
  497. }
  498. await runtime.process_update(update)
  499. await runtime.process_update(update)
  500. assert len(runtime.api.sent) == 1
  501. assert runtime.api.sent[0]["business_connection_id"] == "conn-a"
  502. assert runtime.api.read == [("conn-a", 501, 1)]
  503. assert len(runtime.provider.calls) == 1
  504. assert runtime.provider.calls[0]["knowledge"][0]["entry_id"] == knowledge["entry_id"]
  505. conversation = await dbassistant.get_conversation_by_chat("conn-a", 501)
  506. assert conversation["summary"] == "客户询问营业时间。"
  507. messages = await dbassistant.recent_conversation_messages(
  508. conversation["conversation_id"], limit=10
  509. )
  510. assert [item["direction"] for item in messages] == ["incoming", "assistant"]
  511. assert messages[0]["expires_at"] - messages[0]["created_at"] == timedelta(days=30)
  512. message_indexes = await app_modules.wbb.db.business_assistant_messages.index_information()
  513. assert message_indexes["expires_at_1"]["expireAfterSeconds"] == 0
  514. await runtime.process_update(
  515. {
  516. "update_id": 12,
  517. "business_message": customer_message(
  518. message_id=2, text="账号本人回复", sender_id=900
  519. ),
  520. }
  521. )
  522. paused = await dbassistant.get_conversation(conversation["conversation_id"])
  523. assert paused["status"] == "human_paused"
  524. assert paused["handoff_reason"] == "human_reply_detected"
  525. assert paused["customer"]["id"] == 501
  526. await runtime.process_update(
  527. {
  528. "update_id": 13,
  529. "business_message": customer_message(
  530. message_id=3,
  531. sender_business_bot={"id": 999},
  532. ),
  533. }
  534. )
  535. await runtime.process_update(
  536. {
  537. "update_id": 14,
  538. "business_message": customer_message(
  539. message_id=4,
  540. is_from_offline=True,
  541. ),
  542. }
  543. )
  544. assert len(runtime.api.sent) == 1
  545. async def test_every_user_message_notifies_feishu_once(app_modules):
  546. dbassistant, _service, runtime, _knowledge = await prepare_runtime(app_modules)
  547. webhook_url = "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc"
  548. await dbassistant.update_account_settings(
  549. "conn-a",
  550. {
  551. "assistant_enabled": False,
  552. "feishu_webhook_enabled": True,
  553. "feishu_webhook_url": webhook_url,
  554. "feishu_webhook_signing_secret": "secret",
  555. "feishu_message_preview_enabled": False,
  556. },
  557. )
  558. feishu = FakeFeishuWebhook()
  559. runtime.feishu = feishu
  560. await runtime.process_update(
  561. {"update_id": 101, "business_message": customer_message(message_id=1)}
  562. )
  563. await runtime.process_update(
  564. {"update_id": 102, "business_message": customer_message(message_id=1)}
  565. )
  566. assert len(feishu.sent) == 1
  567. assert feishu.sent[0]["webhook_url"] == webhook_url
  568. assert feishu.sent[0]["signing_secret"] == "secret"
  569. assert "营业时间是什么" not in feishu.sent[0]["text"]
  570. assert feishu.sent[0]["text"].startswith("消息提醒\n")
  571. assert "用户:" in feishu.sent[0]["text"]
  572. assert "客户:" not in feishu.sent[0]["text"]
  573. assert "消息标识:" not in feishu.sent[0]["text"]
  574. await dbassistant.update_account_settings(
  575. "conn-a", {"feishu_message_preview_enabled": True}
  576. )
  577. await runtime.process_update(
  578. {
  579. "update_id": 103,
  580. "business_message": customer_message(
  581. message_id=2, text="第二条用户消息"
  582. ),
  583. }
  584. )
  585. assert len(feishu.sent) == 2
  586. assert "第二条用户消息" in feishu.sent[1]["text"]
  587. await runtime.process_update(
  588. {
  589. "update_id": 1030,
  590. "business_message": customer_message(
  591. message_id=20,
  592. text=None,
  593. caption="图片说明",
  594. photo=[{"file_id": "photo"}],
  595. ),
  596. }
  597. )
  598. assert len(feishu.sent) == 3
  599. assert "类型:非文本" in feishu.sent[2]["text"]
  600. assert "内容:图片说明" in feishu.sent[2]["text"]
  601. await runtime.process_update(
  602. {
  603. "update_id": 104,
  604. "business_message": customer_message(
  605. message_id=3, text="账号本人回复", sender_id=900
  606. ),
  607. }
  608. )
  609. await runtime.process_update(
  610. {
  611. "update_id": 105,
  612. "business_message": customer_message(message_id=4, is_from_offline=True),
  613. }
  614. )
  615. await runtime.process_update(
  616. {
  617. "update_id": 106,
  618. "business_message": customer_message(
  619. message_id=5, sender_business_bot={"id": 999}
  620. ),
  621. }
  622. )
  623. assert len(feishu.sent) == 3
  624. conversation = await dbassistant.get_conversation_by_chat("conn-a", 501)
  625. messages = await dbassistant.recent_conversation_messages(
  626. conversation["conversation_id"], limit=10
  627. )
  628. incoming = [item for item in messages if item["telegram_message_id"] == 2][0]
  629. assert incoming["metadata"]["feishu_notification_status"] == "sent"
  630. async def test_handoff_sensitive_non_text_provider_error_and_expired_window(app_modules):
  631. dbassistant, service, runtime, _knowledge = await prepare_runtime(app_modules)
  632. await dbassistant.update_account_settings(
  633. "conn-a",
  634. {
  635. "notification_destination": "both",
  636. "ops_group_id": -100123,
  637. "account_daily_limit": 1,
  638. "customer_daily_limit": 1,
  639. },
  640. )
  641. await runtime.process_update(
  642. {
  643. "update_id": 21,
  644. "business_message": customer_message(
  645. message_id=1, text="我要退款", chat_id=601, sender_id=601
  646. ),
  647. }
  648. )
  649. sensitive = await dbassistant.get_conversation_by_chat("conn-a", 601)
  650. assert sensitive["status"] == "handoff"
  651. assert sensitive["handoff_reason"] == "sensitive_request"
  652. assert runtime.api.sent[-1]["business_connection_id"] == ""
  653. assert "message_id=1" in runtime.api.sent[-1]["text"]
  654. assert {item["chat_id"] for item in runtime.api.sent[-2:]} == {900, -100123}
  655. await runtime.process_update(
  656. {
  657. "update_id": 22,
  658. "business_message": customer_message(
  659. message_id=2, text=None, chat_id=602, sender_id=602, photo=[{"file_id": "x"}]
  660. ),
  661. }
  662. )
  663. unsupported = await dbassistant.get_conversation_by_chat("conn-a", 602)
  664. assert unsupported["handoff_reason"] == "unsupported_message"
  665. runtime.provider = FakeProvider(error=service.AssistantProviderError("模型超时"))
  666. await runtime.process_update(
  667. {
  668. "update_id": 23,
  669. "business_message": customer_message(
  670. message_id=3, chat_id=603, sender_id=603
  671. ),
  672. }
  673. )
  674. provider_failed = await dbassistant.get_conversation_by_chat("conn-a", 603)
  675. assert provider_failed["handoff_reason"] == "provider_error"
  676. await runtime.process_update(
  677. {
  678. "update_id": 230,
  679. "business_message": customer_message(
  680. message_id=30, chat_id=605, sender_id=605
  681. ),
  682. }
  683. )
  684. quota_handoff = await dbassistant.get_conversation_by_chat("conn-a", 605)
  685. assert quota_handoff["handoff_reason"] == "account_daily_limit"
  686. sent_before = len(runtime.api.sent)
  687. await runtime.process_update(
  688. {
  689. "update_id": 24,
  690. "business_message": customer_message(
  691. message_id=4,
  692. chat_id=604,
  693. sender_id=604,
  694. sent_at=datetime.now(UTC) - timedelta(hours=25),
  695. ),
  696. }
  697. )
  698. expired = await dbassistant.get_conversation_by_chat("conn-a", 604)
  699. assert expired["handoff_reason"] == "reply_window_expired"
  700. new_sends = runtime.api.sent[sent_before:]
  701. assert len(new_sends) == 2
  702. assert all(item["business_connection_id"] == "" for item in new_sends)
  703. async def test_failed_update_goes_to_dead_letter_without_blocking(app_modules, monkeypatch):
  704. dbassistant, _service, runtime, _knowledge = await prepare_runtime(app_modules)
  705. async def fail(_message):
  706. raise RuntimeError("persistent failure")
  707. async def no_sleep(_seconds):
  708. return None
  709. runtime._handle_business_message = fail
  710. monkeypatch.setattr("wbb.services.business_assistant.asyncio.sleep", no_sleep)
  711. await runtime.process_update(
  712. {"update_id": 31, "business_message": customer_message(message_id=1)}
  713. )
  714. dead_letter = await app_modules.wbb.db.business_assistant_dead_letters.find_one(
  715. {"bot_id": "primary", "update_id": 31}
  716. )
  717. update = await app_modules.wbb.db.business_assistant_updates.find_one(
  718. {"bot_id": "primary", "update_id": 31}
  719. )
  720. assert dead_letter["error"] == "persistent failure"
  721. assert update["status"] == "done"
  722. assert await dbassistant.claim_update(31) is False
  723. async def test_connection_updates_revoke_permissions_and_persist_offset(app_modules):
  724. service = app_modules.load("wbb.services.business_assistant")
  725. dbassistant = app_modules.load("wbb.utils.dbassistant")
  726. runtime = service.BusinessAssistantRuntime(
  727. token="123456:" + "A" * 30,
  728. session=SimpleNamespace(),
  729. provider=FakeProvider(),
  730. )
  731. runtime.api = FakeBusinessApi()
  732. await runtime.process_update(
  733. {"update_id": 41, "business_connection": connection_payload(can_reply=True)}
  734. )
  735. connected = await dbassistant.get_business_connection("conn-a")
  736. assert connected["is_enabled"] is True
  737. assert connected["rights"]["can_reply"] is True
  738. await dbassistant.update_account_settings("conn-a", {"assistant_enabled": True})
  739. revoked = connection_payload(can_reply=False)
  740. revoked["is_enabled"] = False
  741. await runtime.process_update({"update_id": 42, "business_connection": revoked})
  742. disconnected = await dbassistant.get_business_connection("conn-a")
  743. assert disconnected["is_enabled"] is False
  744. assert "can_reply" not in disconnected["rights"]
  745. await runtime.process_update(
  746. {"update_id": 420, "business_message": customer_message(message_id=20)}
  747. )
  748. assert runtime.api.sent == []
  749. await dbassistant.save_update_offset(43)
  750. assert await dbassistant.load_update_offset() == 43
  751. await dbassistant.save_update_offset(44)
  752. assert await dbassistant.load_update_offset() == 44
  753. class StartupApi:
  754. def __init__(self, *, supported: bool, webhook_url: str = "") -> None:
  755. self.supported = supported
  756. self.webhook_url = webhook_url
  757. async def get_me(self):
  758. return {"username": "business_bot", "can_connect_to_business": self.supported}
  759. async def get_webhook_info(self):
  760. return {"url": self.webhook_url}
  761. async def test_runtime_blocks_webhook_conflict_and_disabled_business_mode(app_modules):
  762. service = app_modules.load("wbb.services.business_assistant")
  763. runtime = service.BusinessAssistantRuntime(
  764. token="123456:" + "A" * 30,
  765. session=SimpleNamespace(),
  766. provider=FakeProvider(),
  767. )
  768. runtime.api = StartupApi(supported=True, webhook_url="https://hooks.example.com/tg")
  769. webhook_status = await runtime.start()
  770. assert webhook_status["polling_state"] == "blocked"
  771. assert webhook_status["webhook_conflict"] is True
  772. assert runtime._poll_task is None
  773. runtime.api = StartupApi(supported=False)
  774. business_status = await runtime.start()
  775. assert business_status["polling_state"] == "blocked"
  776. assert business_status["business_mode_supported"] is False
  777. assert "BotFather" in business_status["last_error"]
  778. class FakeResponse:
  779. def __init__(self, status: int, payload: dict) -> None:
  780. self.status = status
  781. self.payload = payload
  782. self.headers: dict[str, str] = {}
  783. async def __aenter__(self):
  784. return self
  785. async def __aexit__(self, *_args):
  786. return None
  787. async def json(self, **_kwargs):
  788. return self.payload
  789. class RetrySession:
  790. def __init__(self, responses: list[FakeResponse]) -> None:
  791. self.responses = responses
  792. self.calls = 0
  793. def post(self, *_args, **_kwargs):
  794. response = self.responses[self.calls]
  795. self.calls += 1
  796. return response
  797. async def test_telegram_api_retries_429_and_5xx(app_modules, monkeypatch):
  798. service = app_modules.load("wbb.services.business_assistant")
  799. session = RetrySession(
  800. [
  801. FakeResponse(
  802. 429,
  803. {
  804. "ok": False,
  805. "error_code": 429,
  806. "description": "Too Many Requests",
  807. "parameters": {"retry_after": 3},
  808. },
  809. ),
  810. FakeResponse(
  811. 502,
  812. {"ok": False, "error_code": 502, "description": "Bad Gateway"},
  813. ),
  814. FakeResponse(200, {"ok": True, "result": {"id": 999}}),
  815. ]
  816. )
  817. sleeps: list[int] = []
  818. async def record_sleep(seconds):
  819. sleeps.append(seconds)
  820. monkeypatch.setattr("wbb.services.business_assistant.asyncio.sleep", record_sleep)
  821. api = service.TelegramBusinessApi("123456:" + "A" * 30, session)
  822. assert await api.get_me() == {"id": 999}
  823. assert session.calls == 3
  824. assert sleeps == [3, 2]
  825. async def test_feishu_webhook_signature_and_success_contract(app_modules):
  826. service = app_modules.load("wbb.services.business_assistant")
  827. response = FakeResponse(200, {"code": 0, "msg": "success"})
  828. class CaptureSession:
  829. def __init__(self) -> None:
  830. self.payload = None
  831. def post(self, _url, *, json, timeout):
  832. self.payload = json
  833. assert timeout.total == 8
  834. return response
  835. session = CaptureSession()
  836. client = service.FeishuWebhookClient(session)
  837. await client.send(
  838. "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc",
  839. "消息提醒",
  840. signing_secret="secret",
  841. )
  842. assert session.payload["msg_type"] == "text"
  843. assert session.payload["content"]["text"] == "消息提醒"
  844. assert session.payload["timestamp"]
  845. assert session.payload["sign"]
  846. async def _login_and_change_password(client: TestClient) -> str:
  847. login = await client.post(
  848. "/api/admin/v1/auth/login",
  849. json={"username": "admin", "password": "qwe0.123456"},
  850. )
  851. login_data = (await login.json())["data"]
  852. changed = await client.put(
  853. "/api/admin/v1/auth/password",
  854. headers={"X-CSRF-Token": login_data["csrf_token"]},
  855. json={
  856. "current_password": "qwe0.123456",
  857. "new_password": "changed-pass-123",
  858. },
  859. )
  860. return (await changed.json())["data"]["csrf_token"]
  861. async def test_business_assistant_api_permission_csrf_audit_and_clear(app_modules):
  862. dbassistant = app_modules.load("wbb.utils.dbassistant")
  863. await dbassistant.upsert_business_connection(connection_payload())
  864. conversation = await dbassistant.get_or_create_conversation(
  865. "conn-a", 701, customer={"id": 701, "first_name": "待清理客户"}
  866. )
  867. await dbassistant.append_conversation_message(
  868. conversation["conversation_id"],
  869. direction="incoming",
  870. telegram_message_id=1,
  871. text="请清理",
  872. )
  873. await dbassistant.update_conversation_summary(conversation["conversation_id"], "待清理摘要")
  874. admin_api = app_modules.load("wbb.admin.api")
  875. application = admin_api.build_admin_application()
  876. await application["admin_api"].initialize()
  877. client = TestClient(TestServer(application), cookie_jar=CookieJar(unsafe=True))
  878. await client.start_server()
  879. try:
  880. csrf = await _login_and_change_password(client)
  881. app_modules.wbb.BOT_PERMISSIONS = set()
  882. denied = await client.get("/api/admin/v1/business-assistant/status")
  883. assert denied.status == 403
  884. app_modules.wbb.BOT_PERMISSIONS = {"business_assistant.manage"}
  885. no_csrf = await client.put(
  886. "/api/admin/v1/business-assistant/settings",
  887. json={"connection_id": "conn-a", "assistant_enabled": True, "confirm": True},
  888. )
  889. assert no_csrf.status == 403
  890. unconfirmed = await client.put(
  891. "/api/admin/v1/business-assistant/settings",
  892. headers={"X-CSRF-Token": csrf},
  893. json={"connection_id": "conn-a", "assistant_enabled": True},
  894. )
  895. assert unconfirmed.status == 409
  896. saved = await client.put(
  897. "/api/admin/v1/business-assistant/settings",
  898. headers={"X-CSRF-Token": csrf},
  899. json={
  900. "connection_id": "conn-a",
  901. "assistant_enabled": True,
  902. "feishu_webhook_enabled": True,
  903. "feishu_webhook_url": "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc",
  904. "feishu_webhook_signing_secret": "api-secret",
  905. "confirm": True,
  906. },
  907. )
  908. assert saved.status == 200
  909. saved_data = (await saved.json())["data"]
  910. assert saved_data["assistant_enabled"] is True
  911. assert saved_data["feishu_webhook_url"] == ""
  912. assert saved_data["feishu_webhook_signing_secret"] == ""
  913. assert saved_data["feishu_webhook_configured"] is True
  914. stored_settings = await dbassistant.get_account_settings("conn-a")
  915. assert stored_settings["feishu_webhook_signing_secret"] == "api-secret"
  916. listed_connections = await client.get(
  917. "/api/admin/v1/business-assistant/connections?page=1&page_size=100"
  918. )
  919. listed_settings = (await listed_connections.json())["data"]["items"][0][
  920. "settings"
  921. ]
  922. assert listed_settings["feishu_webhook_url"] == ""
  923. assert listed_settings["feishu_webhook_signing_secret"] == ""
  924. class FakeRuntime:
  925. def __init__(self) -> None:
  926. self.calls = []
  927. async def test_feishu_webhook(self, connection_id, overrides):
  928. self.calls.append((connection_id, overrides))
  929. return {"ok": True, "account": "店主"}
  930. module = app_modules.load("wbb.modules.business_assistant")
  931. fake_runtime = FakeRuntime()
  932. module._runtime = fake_runtime
  933. tested = await client.post(
  934. "/api/admin/v1/business-assistant/feishu-webhook/test",
  935. headers={"X-CSRF-Token": csrf},
  936. json={"connection_id": "conn-a", "confirm": True},
  937. )
  938. assert tested.status == 200
  939. assert (await tested.json())["data"]["ok"] is True
  940. assert fake_runtime.calls == [("conn-a", {})]
  941. created = await client.post(
  942. "/api/admin/v1/business-assistant/knowledge",
  943. headers={"X-CSRF-Token": csrf},
  944. json={
  945. "connection_id": "conn-a",
  946. "question": "配送范围",
  947. "keywords": ["配送"],
  948. "answer": "仅限市区。",
  949. "confirm": True,
  950. },
  951. )
  952. assert created.status == 201
  953. listed = await client.get(
  954. "/api/admin/v1/business-assistant/knowledge?connection_id=conn-a"
  955. )
  956. assert (await listed.json())["data"]["total"] == 1
  957. created_source = await client.post(
  958. "/api/admin/v1/business-assistant/knowledge-sources",
  959. headers={"X-CSRF-Token": csrf},
  960. json={
  961. "connection_id": "conn-a",
  962. "source_type": "business",
  963. "title": "人工对话",
  964. "publication_mode": "review",
  965. "confirm": True,
  966. },
  967. )
  968. assert created_source.status == 201
  969. source = (await created_source.json())["data"]
  970. event, _ = await dbassistant.record_source_event(
  971. source,
  972. event_key="business:701:8",
  973. content="市区可配送。",
  974. metadata={"chat_id": 701, "message_id": 8, "trusted_author": True},
  975. )
  976. candidates = await dbassistant.replace_event_candidates(
  977. source,
  978. event,
  979. [
  980. {
  981. "question": "配送范围?",
  982. "keywords": ["配送"],
  983. "answer": "市区可配送。",
  984. "confidence": 0.9,
  985. }
  986. ],
  987. auto_publish=False,
  988. )
  989. candidate_page = await client.get(
  990. "/api/admin/v1/business-assistant/knowledge-candidates"
  991. "?connection_id=conn-a&status=pending"
  992. )
  993. assert candidate_page.status == 200
  994. assert (await candidate_page.json())["data"]["total"] == 1
  995. approved = await client.post(
  996. "/api/admin/v1/business-assistant/knowledge-candidates/"
  997. f"{candidates[0]['candidate_id']}/actions",
  998. headers={"X-CSRF-Token": csrf},
  999. json={"action": "approve", "confirm": True},
  1000. )
  1001. assert approved.status == 200
  1002. assert (await approved.json())["data"]["status"] == "published"
  1003. cleared = await client.post(
  1004. f"/api/admin/v1/business-assistant/conversations/{conversation['conversation_id']}/actions",
  1005. headers={"X-CSRF-Token": csrf},
  1006. json={"action": "clear", "confirm": True},
  1007. )
  1008. assert cleared.status == 200
  1009. detail = await dbassistant.conversation_detail(conversation["conversation_id"])
  1010. assert detail["summary"] == ""
  1011. assert detail["messages"] == []
  1012. audit = await app_modules.wbb.db.admin_audit_logs.find_one(
  1013. {"action": "business_assistant.conversation.clear"}
  1014. )
  1015. assert audit["success"] is True
  1016. finally:
  1017. await client.close()