test_business_assistant.py 43 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226
  1. from __future__ import annotations
  2. import json
  3. from datetime import UTC, datetime, timedelta
  4. from types import SimpleNamespace
  5. import pytest
  6. from aiohttp import CookieJar
  7. from aiohttp.test_utils import TestClient, TestServer
  8. from pyrogram.enums import ChatMemberStatus
  9. def connection_payload(connection_id: str = "conn-a", *, can_reply: bool = True) -> dict:
  10. return {
  11. "id": connection_id,
  12. "user": {"id": 900, "username": "owner", "first_name": "店主"},
  13. "user_chat_id": 900,
  14. "date": int(datetime.now(UTC).timestamp()),
  15. "rights": {"can_reply": can_reply, "can_read_messages": True},
  16. "is_enabled": True,
  17. }
  18. def customer_message(
  19. *,
  20. message_id: int,
  21. text: str | None = "营业时间是什么?",
  22. chat_id: int = 501,
  23. sender_id: int = 501,
  24. sent_at: datetime | None = None,
  25. **values,
  26. ) -> dict:
  27. message = {
  28. "business_connection_id": "conn-a",
  29. "message_id": message_id,
  30. "date": int((sent_at or datetime.now(UTC)).timestamp()),
  31. "chat": {"id": chat_id, "type": "private"},
  32. "from": {"id": sender_id, "username": f"user{sender_id}", "first_name": "客户"},
  33. **values,
  34. }
  35. if text is not None:
  36. message["text"] = text
  37. return message
  38. class FakeProvider:
  39. configured = True
  40. def __init__(self, *, error: Exception | None = None) -> None:
  41. self.error = error
  42. self.calls: list[dict] = []
  43. self.extraction_calls: list[dict] = []
  44. async def decide(self, **values):
  45. self.calls.append(values)
  46. if self.error:
  47. raise self.error
  48. entry_id = str(values["knowledge"][0]["entry_id"])
  49. return {
  50. "action": "answer",
  51. "reply": "每天 09:00 至 18:00 营业。",
  52. "handoff_reason": "",
  53. "matched_entry_ids": [entry_id],
  54. "summary": "客户询问营业时间。",
  55. }
  56. async def test_connection(self):
  57. return {"ok": True, "model": "test-model", "response_id": "response-1"}
  58. async def extract_knowledge(self, **values):
  59. self.extraction_calls.append(values)
  60. if self.error:
  61. raise self.error
  62. return [
  63. {
  64. "question": values.get("question_context") or "如何办理?",
  65. "aliases": [],
  66. "keywords": ["办理"],
  67. "answer": values["content"],
  68. "tags": ["自动采集"],
  69. "confidence": 0.92,
  70. }
  71. ]
  72. class FakeBusinessApi:
  73. def __init__(self) -> None:
  74. self.sent: list[dict] = []
  75. self.read: list[tuple[str, int, int]] = []
  76. async def send_message(
  77. self,
  78. chat_id: int,
  79. text: str,
  80. *,
  81. business_connection_id: str = "",
  82. reply_markup: dict | None = None,
  83. ) -> dict:
  84. self.sent.append(
  85. {
  86. "chat_id": chat_id,
  87. "text": text,
  88. "business_connection_id": business_connection_id,
  89. "reply_markup": reply_markup,
  90. }
  91. )
  92. return {
  93. "message_id": 1000 + len(self.sent),
  94. "sender_business_bot": {"id": 999},
  95. }
  96. async def read_business_message(
  97. self, connection_id: str, chat_id: int, message_id: int
  98. ) -> None:
  99. self.read.append((connection_id, chat_id, message_id))
  100. class FakeFeishuWebhook:
  101. def __init__(self) -> None:
  102. self.sent: list[dict] = []
  103. async def send(self, webhook_url: str, text: str, *, signing_secret: str = "") -> None:
  104. self.sent.append(
  105. {
  106. "webhook_url": webhook_url,
  107. "text": text,
  108. "signing_secret": signing_secret,
  109. }
  110. )
  111. async def send_card(
  112. self,
  113. webhook_url: str,
  114. *,
  115. title: str,
  116. lines: list[str],
  117. link_url: str = "",
  118. signing_secret: str = "",
  119. ) -> None:
  120. self.sent.append(
  121. {
  122. "webhook_url": webhook_url,
  123. "title": title,
  124. "lines": lines,
  125. "text": "\n".join(lines),
  126. "link_url": link_url,
  127. "signing_secret": signing_secret,
  128. }
  129. )
  130. async def prepare_runtime(app_modules, *, provider: FakeProvider | None = None):
  131. dbassistant = app_modules.load("wbb.utils.dbassistant")
  132. service = app_modules.load("wbb.services.business_assistant")
  133. await dbassistant.upsert_business_connection(connection_payload())
  134. await dbassistant.update_account_settings("conn-a", {"assistant_enabled": True})
  135. knowledge = await dbassistant.create_knowledge_entry(
  136. "conn-a",
  137. {
  138. "question": "营业时间是什么?",
  139. "aliases": ["几点营业"],
  140. "keywords": ["营业时间", "营业"],
  141. "answer": "每天 09:00 至 18:00 营业。",
  142. "priority": 10,
  143. },
  144. )
  145. selected_provider = provider or FakeProvider()
  146. runtime = service.BusinessAssistantRuntime(
  147. token="123456:" + "A" * 30,
  148. session=SimpleNamespace(),
  149. provider=selected_provider,
  150. )
  151. runtime.api = FakeBusinessApi()
  152. return dbassistant, service, runtime, knowledge
  153. async def test_connection_settings_knowledge_quota_and_bot_scope(app_modules):
  154. dbassistant = app_modules.load("wbb.utils.dbassistant")
  155. await dbassistant.upsert_business_connection(connection_payload("conn-a"))
  156. await dbassistant.upsert_business_connection(connection_payload("conn-b"))
  157. settings = await dbassistant.update_account_settings(
  158. "conn-a",
  159. {
  160. "assistant_enabled": True,
  161. "account_daily_limit": 2,
  162. "customer_daily_limit": 1,
  163. "timezone": "Asia/Shanghai",
  164. },
  165. )
  166. first = await dbassistant.create_knowledge_entry(
  167. "conn-a",
  168. {
  169. "question": "营业时间",
  170. "aliases": ["几点开门"],
  171. "keywords": ["开门"],
  172. "answer": "九点开门。",
  173. "priority": 20,
  174. },
  175. )
  176. await dbassistant.create_knowledge_entry(
  177. "conn-b",
  178. {"question": "营业时间", "keywords": ["开门"], "answer": "十点开门。"},
  179. )
  180. await app_modules.wbb.db.business_assistant_knowledge.insert_one(
  181. {
  182. "bot_id": "foreign-bot",
  183. "entry_id": "foreign-entry",
  184. "connection_id": "conn-a",
  185. "question": "营业时间",
  186. "aliases": [],
  187. "keywords": ["开门"],
  188. "answer": "不应跨 Bot 返回。",
  189. "priority": 1000,
  190. "enabled": True,
  191. "updated_at": datetime.now(UTC),
  192. }
  193. )
  194. matched = await dbassistant.match_knowledge("conn-a", "你们几点开门?")
  195. assert [item["entry_id"] for item in matched] == [first["entry_id"]]
  196. items, total = await dbassistant.list_knowledge_entries("conn-a")
  197. assert total == 1
  198. assert items[0]["answer"] == "九点开门。"
  199. await app_modules.wbb.db.business_assistant_connections.insert_one(
  200. {
  201. "bot_id": "foreign-bot",
  202. "connection_id": "foreign-connection",
  203. "updated_at": datetime.now(UTC),
  204. }
  205. )
  206. connections, total = await dbassistant.list_business_connections(page_size=100)
  207. assert total == 2
  208. assert {item["connection_id"] for item in connections} == {"conn-a", "conn-b"}
  209. assert await dbassistant.reserve_ai_usage("conn-a", 101, settings) == (True, "")
  210. assert await dbassistant.reserve_ai_usage("conn-a", 101, settings) == (
  211. False,
  212. "customer_daily_limit",
  213. )
  214. assert await dbassistant.reserve_ai_usage("conn-a", 102, settings) == (True, "")
  215. assert await dbassistant.reserve_ai_usage("conn-a", 103, settings) == (
  216. False,
  217. "account_daily_limit",
  218. )
  219. usage = await dbassistant.usage_metrics(connection_id="conn-a")
  220. assert usage["ai_calls"] == 2
  221. assert usage["customers"] == 2
  222. with pytest.raises(dbassistant.AssistantDataError) as error:
  223. dbassistant.normalize_account_settings({"timezone": "invalid/timezone"})
  224. assert error.value.code == "invalid_setting"
  225. async def test_feishu_settings_are_validated_and_never_exposed(app_modules):
  226. dbassistant = app_modules.load("wbb.utils.dbassistant")
  227. await dbassistant.upsert_business_connection(connection_payload())
  228. webhook_url = "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc"
  229. stored = await dbassistant.update_account_settings(
  230. "conn-a",
  231. {
  232. "feishu_webhook_enabled": True,
  233. "feishu_webhook_url": webhook_url,
  234. "feishu_webhook_signing_secret": "signing-secret",
  235. "feishu_message_preview_enabled": True,
  236. },
  237. )
  238. assert stored["feishu_webhook_url"] == webhook_url
  239. assert stored["feishu_webhook_signing_secret"] == "signing-secret"
  240. public = dbassistant.public_account_settings(stored)
  241. assert public["feishu_webhook_url"] == ""
  242. assert public["feishu_webhook_signing_secret"] == ""
  243. assert public["feishu_webhook_configured"] is True
  244. assert public["feishu_signing_secret_configured"] is True
  245. connections, _total = await dbassistant.list_business_connections()
  246. assert connections[0]["settings"]["feishu_webhook_url"] == ""
  247. assert connections[0]["settings"]["feishu_webhook_configured"] is True
  248. with pytest.raises(dbassistant.AssistantDataError):
  249. dbassistant.normalize_account_settings(
  250. {
  251. "feishu_webhook_enabled": True,
  252. "feishu_webhook_url": "https://example.com/internal-hook",
  253. }
  254. )
  255. def test_ai_contract_and_reply_window_validation(app_modules):
  256. service = app_modules.load("wbb.services.business_assistant")
  257. parsed = service.parse_ai_decision(
  258. json.dumps(
  259. {
  260. "action": "answer",
  261. "reply": "标准答案",
  262. "matched_entry_ids": ["entry-1", "foreign"],
  263. "summary": "摘要",
  264. }
  265. ),
  266. allowed_entry_ids={"entry-1"},
  267. )
  268. assert parsed["matched_entry_ids"] == ["entry-1"]
  269. with pytest.raises(service.AssistantProviderError):
  270. service.parse_ai_decision(
  271. '{"action":"answer","reply":"没有引用"}', allowed_entry_ids={"entry-1"}
  272. )
  273. now = datetime.now(UTC)
  274. assert service.business_reply_window_open(
  275. {"date": int((now - timedelta(hours=23)).timestamp())}, now=now
  276. )
  277. assert not service.business_reply_window_open(
  278. {"date": int((now - timedelta(hours=25)).timestamp())}, now=now
  279. )
  280. assert not service.business_reply_window_open({}, now=now)
  281. extracted = service.parse_knowledge_extraction(
  282. json.dumps(
  283. {
  284. "items": [
  285. {
  286. "question": "如何配送?",
  287. "aliases": ["配送范围"],
  288. "keywords": ["配送"],
  289. "answer": "仅支持市区配送。",
  290. "tags": ["配送"],
  291. "confidence": 0.9,
  292. }
  293. ]
  294. }
  295. )
  296. )
  297. assert extracted[0]["confidence"] == 0.9
  298. assert (
  299. service.redact_business_knowledge_text(
  300. "电话 138 0013 8000,邮箱 user@example.com,Telegram @private_user"
  301. )
  302. == "电话 [电话已脱敏],邮箱 [邮箱已脱敏],Telegram [用户名已脱敏]"
  303. )
  304. async def test_source_event_candidates_publish_edit_delete_and_isolate(app_modules):
  305. dbassistant = app_modules.load("wbb.utils.dbassistant")
  306. await dbassistant.upsert_business_connection(connection_payload("conn-a"))
  307. await dbassistant.upsert_business_connection(connection_payload("conn-b"))
  308. source = await dbassistant.create_knowledge_source(
  309. "conn-a",
  310. {
  311. "source_type": "channel",
  312. "chat_id": -100100,
  313. "title": "官方频道",
  314. "publication_mode": "auto",
  315. "author_policy": "admins_or_allowlist",
  316. },
  317. )
  318. event, changed = await dbassistant.record_source_event(
  319. source,
  320. event_key="telegram:-100100:10",
  321. content="每天九点营业。",
  322. metadata={"chat_id": -100100, "message_id": 10, "trusted_author": True},
  323. )
  324. assert changed is True
  325. candidates = await dbassistant.replace_event_candidates(
  326. source,
  327. event,
  328. [
  329. {
  330. "question": "几点营业?",
  331. "aliases": ["营业时间"],
  332. "keywords": ["营业"],
  333. "answer": "每天九点营业。",
  334. "tags": ["营业"],
  335. "confidence": 0.95,
  336. }
  337. ],
  338. auto_publish=True,
  339. )
  340. candidate = candidates[0]
  341. first_entry_id = candidate["knowledge_entry_id"]
  342. first_entry = await app_modules.wbb.db.business_assistant_knowledge.find_one(
  343. {"bot_id": "primary", "entry_id": first_entry_id}
  344. )
  345. assert candidate["status"] == "published"
  346. assert first_entry["enabled"] is True
  347. edited_event, changed = await dbassistant.record_source_event(
  348. source,
  349. event_key="telegram:-100100:10",
  350. content="每天十点营业。",
  351. metadata={"chat_id": -100100, "message_id": 10, "trusted_author": True},
  352. )
  353. assert changed is True
  354. edited = await dbassistant.replace_event_candidates(
  355. source,
  356. edited_event,
  357. [
  358. {
  359. "question": "几点营业?",
  360. "aliases": [],
  361. "keywords": ["营业"],
  362. "answer": "每天十点营业。",
  363. "tags": ["营业"],
  364. "confidence": 0.96,
  365. }
  366. ],
  367. auto_publish=True,
  368. )
  369. assert edited[0]["knowledge_entry_id"] == first_entry_id
  370. updated_entry = await app_modules.wbb.db.business_assistant_knowledge.find_one(
  371. {"bot_id": "primary", "entry_id": first_entry_id}
  372. )
  373. assert updated_entry["answer"] == "每天十点营业。"
  374. assert await dbassistant.mark_source_event_deleted(
  375. source["source_id"], "telegram:-100100:10"
  376. )
  377. stale = await dbassistant.get_knowledge_candidate(candidate["candidate_id"])
  378. disabled_entry = await app_modules.wbb.db.business_assistant_knowledge.find_one(
  379. {"bot_id": "primary", "entry_id": first_entry_id}
  380. )
  381. assert stale["status"] == "stale"
  382. assert disabled_entry["enabled"] is False
  383. sources_a, total_a = await dbassistant.list_knowledge_sources("conn-a")
  384. sources_b, total_b = await dbassistant.list_knowledge_sources("conn-b")
  385. assert total_a == 1 and sources_a[0]["source_id"] == source["source_id"]
  386. assert total_b == 0 and sources_b == []
  387. event_indexes = await app_modules.wbb.db.business_assistant_source_events.index_information()
  388. assert event_indexes["expires_at_1"]["expireAfterSeconds"] == 0
  389. async def test_business_human_reply_learns_only_when_source_enabled(app_modules):
  390. dbassistant, _service, runtime, _knowledge = await prepare_runtime(app_modules)
  391. await runtime.process_update(
  392. {
  393. "update_id": 9,
  394. "business_message": customer_message(
  395. message_id=9, text="配送到哪里?", chat_id=509, sender_id=509
  396. ),
  397. }
  398. )
  399. await runtime.process_update(
  400. {
  401. "update_id": 10,
  402. "business_message": customer_message(
  403. message_id=10, text="仅支持市区配送。", chat_id=509, sender_id=900
  404. ),
  405. }
  406. )
  407. assert runtime.provider.extraction_calls == []
  408. await dbassistant.create_knowledge_source(
  409. "conn-a",
  410. {
  411. "source_type": "business",
  412. "title": "人工接待对话",
  413. "publication_mode": "auto",
  414. },
  415. )
  416. await runtime.process_update(
  417. {
  418. "update_id": 15,
  419. "business_message": customer_message(
  420. message_id=15, text="支持哪些区域?", chat_id=515, sender_id=515
  421. ),
  422. }
  423. )
  424. await runtime.process_update(
  425. {
  426. "update_id": 16,
  427. "business_message": customer_message(
  428. message_id=16, text="仅支持市区配送。", chat_id=515, sender_id=900
  429. ),
  430. }
  431. )
  432. assert len(runtime.provider.extraction_calls) == 1
  433. candidates, total = await dbassistant.list_knowledge_candidates(
  434. "conn-a", status="published"
  435. )
  436. assert total == 1
  437. assert candidates[0]["answer"] == "仅支持市区配送。"
  438. entry_id = candidates[0]["knowledge_entry_id"]
  439. await runtime.process_update(
  440. {
  441. "update_id": 17,
  442. "edited_business_message": customer_message(
  443. message_id=16, text="仅二环内支持配送。", chat_id=515, sender_id=900
  444. ),
  445. }
  446. )
  447. edited = await dbassistant.get_knowledge_candidate(candidates[0]["candidate_id"])
  448. assert edited["answer"] == "仅二环内支持配送。"
  449. assert edited["knowledge_entry_id"] == entry_id
  450. await runtime.process_update(
  451. {
  452. "update_id": 18,
  453. "deleted_business_messages": {
  454. "business_connection_id": "conn-a",
  455. "chat": {"id": 515},
  456. "message_ids": [16],
  457. },
  458. }
  459. )
  460. stale = await dbassistant.get_knowledge_candidate(candidates[0]["candidate_id"])
  461. entry = await app_modules.wbb.db.business_assistant_knowledge.find_one(
  462. {"bot_id": "primary", "entry_id": entry_id}
  463. )
  464. assert stale["status"] == "stale"
  465. assert entry["enabled"] is False
  466. async def test_group_collection_requires_trusted_author_for_auto_publish(app_modules):
  467. dbassistant, _service, runtime, _knowledge = await prepare_runtime(app_modules)
  468. module = app_modules.load("wbb.modules.business_assistant")
  469. module._runtime = runtime
  470. await dbassistant.create_knowledge_source(
  471. "conn-a",
  472. {
  473. "source_type": "group",
  474. "chat_id": -100300,
  475. "title": "运营讨论群",
  476. "publication_mode": "auto",
  477. "author_policy": "admins_or_allowlist",
  478. },
  479. )
  480. def group_message(message_id: int, author_id: int, text: str):
  481. return SimpleNamespace(
  482. id=message_id,
  483. text=text,
  484. caption=None,
  485. outgoing=False,
  486. is_automatic_forward=False,
  487. date=datetime.now(UTC),
  488. chat=SimpleNamespace(id=-100300),
  489. from_user=SimpleNamespace(id=author_id, is_bot=False),
  490. )
  491. ordinary = group_message(1, 301, "市区支持当日配送。")
  492. await module.process_knowledge_source_message(ordinary)
  493. pending, pending_total = await dbassistant.list_knowledge_candidates(
  494. "conn-a", status="pending"
  495. )
  496. assert pending_total == 1
  497. assert pending[0]["status"] == "pending"
  498. app_modules.app.members[(-100300, 302)] = SimpleNamespace(
  499. status=ChatMemberStatus.ADMINISTRATOR
  500. )
  501. admin_message = group_message(2, 302, "每周一至周五提供配送。")
  502. await module.process_knowledge_source_message(admin_message)
  503. published, published_total = await dbassistant.list_knowledge_candidates(
  504. "conn-a", status="published"
  505. )
  506. assert published_total == 1
  507. assert published[0]["source_snapshot"]["author_id"] == 302
  508. extraction_count = len(runtime.provider.extraction_calls)
  509. await module.process_knowledge_source_message(admin_message)
  510. assert len(runtime.provider.extraction_calls) == extraction_count
  511. async def test_business_updates_are_idempotent_and_manual_reply_pauses(app_modules):
  512. dbassistant, _service, runtime, knowledge = await prepare_runtime(app_modules)
  513. update = {
  514. "update_id": 11,
  515. "business_message": customer_message(message_id=1),
  516. }
  517. await runtime.process_update(update)
  518. await runtime.process_update(update)
  519. assert len(runtime.api.sent) == 1
  520. assert runtime.api.sent[0]["business_connection_id"] == "conn-a"
  521. assert runtime.api.read == [("conn-a", 501, 1)]
  522. assert len(runtime.provider.calls) == 1
  523. assert runtime.provider.calls[0]["knowledge"][0]["entry_id"] == knowledge["entry_id"]
  524. conversation = await dbassistant.get_conversation_by_chat("conn-a", 501)
  525. assert conversation["summary"] == "客户询问营业时间。"
  526. messages = await dbassistant.recent_conversation_messages(
  527. conversation["conversation_id"], limit=10
  528. )
  529. assert [item["direction"] for item in messages] == ["incoming", "assistant"]
  530. assert messages[0]["expires_at"] - messages[0]["created_at"] == timedelta(days=30)
  531. message_indexes = await app_modules.wbb.db.business_assistant_messages.index_information()
  532. assert message_indexes["expires_at_1"]["expireAfterSeconds"] == 0
  533. await runtime.process_update(
  534. {
  535. "update_id": 12,
  536. "business_message": customer_message(
  537. message_id=2, text="账号本人回复", sender_id=900
  538. ),
  539. }
  540. )
  541. paused = await dbassistant.get_conversation(conversation["conversation_id"])
  542. assert paused["status"] == "human_paused"
  543. assert paused["handoff_reason"] == "human_reply_detected"
  544. assert paused["customer"]["id"] == 501
  545. await runtime.process_update(
  546. {
  547. "update_id": 13,
  548. "business_message": customer_message(
  549. message_id=3,
  550. sender_business_bot={"id": 999},
  551. ),
  552. }
  553. )
  554. await runtime.process_update(
  555. {
  556. "update_id": 14,
  557. "business_message": customer_message(
  558. message_id=4,
  559. is_from_offline=True,
  560. ),
  561. }
  562. )
  563. assert len(runtime.api.sent) == 1
  564. async def test_every_user_message_notifies_feishu_once(app_modules):
  565. dbassistant, _service, runtime, _knowledge = await prepare_runtime(app_modules)
  566. webhook_url = "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc"
  567. await dbassistant.update_account_settings(
  568. "conn-a",
  569. {
  570. "assistant_enabled": False,
  571. "feishu_webhook_enabled": True,
  572. "feishu_webhook_url": webhook_url,
  573. "feishu_webhook_signing_secret": "secret",
  574. "feishu_message_preview_enabled": False,
  575. },
  576. )
  577. feishu = FakeFeishuWebhook()
  578. runtime.feishu = feishu
  579. await runtime.process_update(
  580. {
  581. "update_id": 101,
  582. "business_message": customer_message(
  583. message_id=1,
  584. sent_at=datetime(2026, 8, 24, 2, 3, 4, tzinfo=UTC),
  585. ),
  586. }
  587. )
  588. await runtime.process_update(
  589. {"update_id": 102, "business_message": customer_message(message_id=1)}
  590. )
  591. assert len(feishu.sent) == 1
  592. assert feishu.sent[0]["webhook_url"] == webhook_url
  593. assert feishu.sent[0]["signing_secret"] == "secret"
  594. assert "营业时间是什么" not in feishu.sent[0]["text"]
  595. assert feishu.sent[0]["title"] == "消息提醒"
  596. assert "用户:" in feishu.sent[0]["text"]
  597. assert "客户:" not in feishu.sent[0]["text"]
  598. assert "消息标识:" not in feishu.sent[0]["text"]
  599. assert feishu.sent[0]["link_url"] == "https://t.me/user501"
  600. assert "时间(北京时间):2026-08-24 10:03:04" in feishu.sent[0]["lines"]
  601. assert "点击卡片打开 Telegram 对话" in feishu.sent[0]["lines"]
  602. await dbassistant.update_account_settings(
  603. "conn-a", {"feishu_message_preview_enabled": True}
  604. )
  605. await runtime.process_update(
  606. {
  607. "update_id": 103,
  608. "business_message": customer_message(
  609. message_id=2, text="第二条用户消息"
  610. ),
  611. }
  612. )
  613. assert len(feishu.sent) == 2
  614. assert "第二条用户消息" in feishu.sent[1]["text"]
  615. await runtime.process_update(
  616. {
  617. "update_id": 1030,
  618. "business_message": customer_message(
  619. message_id=20,
  620. text=None,
  621. caption="图片说明",
  622. photo=[{"file_id": "photo"}],
  623. ),
  624. }
  625. )
  626. assert len(feishu.sent) == 3
  627. assert "类型:非文本" in feishu.sent[2]["text"]
  628. assert "内容:图片说明" in feishu.sent[2]["text"]
  629. await runtime.process_update(
  630. {
  631. "update_id": 1031,
  632. "business_message": customer_message(
  633. message_id=21,
  634. chat_id=502,
  635. sender_id=502,
  636. **{"from": {"id": 502, "first_name": "无用户名用户"}},
  637. ),
  638. }
  639. )
  640. assert len(feishu.sent) == 4
  641. assert "用户:无用户名用户" in feishu.sent[3]["lines"]
  642. assert feishu.sent[3]["link_url"] == ""
  643. assert "点击卡片打开 Telegram 对话" not in feishu.sent[3]["lines"]
  644. await runtime.process_update(
  645. {
  646. "update_id": 104,
  647. "business_message": customer_message(
  648. message_id=3, text="账号本人回复", sender_id=900
  649. ),
  650. }
  651. )
  652. await runtime.process_update(
  653. {
  654. "update_id": 105,
  655. "business_message": customer_message(message_id=4, is_from_offline=True),
  656. }
  657. )
  658. await runtime.process_update(
  659. {
  660. "update_id": 106,
  661. "business_message": customer_message(
  662. message_id=5, sender_business_bot={"id": 999}
  663. ),
  664. }
  665. )
  666. assert len(feishu.sent) == 4
  667. conversation = await dbassistant.get_conversation_by_chat("conn-a", 501)
  668. messages = await dbassistant.recent_conversation_messages(
  669. conversation["conversation_id"], limit=10
  670. )
  671. incoming = [item for item in messages if item["telegram_message_id"] == 2][0]
  672. assert incoming["metadata"]["feishu_notification_status"] == "sent"
  673. async def test_handoff_sensitive_non_text_provider_error_and_expired_window(app_modules):
  674. dbassistant, service, runtime, _knowledge = await prepare_runtime(app_modules)
  675. await dbassistant.update_account_settings(
  676. "conn-a",
  677. {
  678. "notification_destination": "both",
  679. "ops_group_id": -100123,
  680. "account_daily_limit": 1,
  681. "customer_daily_limit": 1,
  682. },
  683. )
  684. await runtime.process_update(
  685. {
  686. "update_id": 21,
  687. "business_message": customer_message(
  688. message_id=1, text="我要退款", chat_id=601, sender_id=601
  689. ),
  690. }
  691. )
  692. sensitive = await dbassistant.get_conversation_by_chat("conn-a", 601)
  693. assert sensitive["status"] == "handoff"
  694. assert sensitive["handoff_reason"] == "sensitive_request"
  695. assert runtime.api.sent[-1]["business_connection_id"] == ""
  696. assert "message_id=1" in runtime.api.sent[-1]["text"]
  697. assert {item["chat_id"] for item in runtime.api.sent[-2:]} == {900, -100123}
  698. await runtime.process_update(
  699. {
  700. "update_id": 22,
  701. "business_message": customer_message(
  702. message_id=2, text=None, chat_id=602, sender_id=602, photo=[{"file_id": "x"}]
  703. ),
  704. }
  705. )
  706. unsupported = await dbassistant.get_conversation_by_chat("conn-a", 602)
  707. assert unsupported["handoff_reason"] == "unsupported_message"
  708. runtime.provider = FakeProvider(error=service.AssistantProviderError("模型超时"))
  709. await runtime.process_update(
  710. {
  711. "update_id": 23,
  712. "business_message": customer_message(
  713. message_id=3, chat_id=603, sender_id=603
  714. ),
  715. }
  716. )
  717. provider_failed = await dbassistant.get_conversation_by_chat("conn-a", 603)
  718. assert provider_failed["handoff_reason"] == "provider_error"
  719. await runtime.process_update(
  720. {
  721. "update_id": 230,
  722. "business_message": customer_message(
  723. message_id=30, chat_id=605, sender_id=605
  724. ),
  725. }
  726. )
  727. quota_handoff = await dbassistant.get_conversation_by_chat("conn-a", 605)
  728. assert quota_handoff["handoff_reason"] == "account_daily_limit"
  729. sent_before = len(runtime.api.sent)
  730. await runtime.process_update(
  731. {
  732. "update_id": 24,
  733. "business_message": customer_message(
  734. message_id=4,
  735. chat_id=604,
  736. sender_id=604,
  737. sent_at=datetime.now(UTC) - timedelta(hours=25),
  738. ),
  739. }
  740. )
  741. expired = await dbassistant.get_conversation_by_chat("conn-a", 604)
  742. assert expired["handoff_reason"] == "reply_window_expired"
  743. new_sends = runtime.api.sent[sent_before:]
  744. assert len(new_sends) == 2
  745. assert all(item["business_connection_id"] == "" for item in new_sends)
  746. async def test_failed_update_goes_to_dead_letter_without_blocking(app_modules, monkeypatch):
  747. dbassistant, _service, runtime, _knowledge = await prepare_runtime(app_modules)
  748. async def fail(_message):
  749. raise RuntimeError("persistent failure")
  750. async def no_sleep(_seconds):
  751. return None
  752. runtime._handle_business_message = fail
  753. monkeypatch.setattr("wbb.services.business_assistant.asyncio.sleep", no_sleep)
  754. await runtime.process_update(
  755. {"update_id": 31, "business_message": customer_message(message_id=1)}
  756. )
  757. dead_letter = await app_modules.wbb.db.business_assistant_dead_letters.find_one(
  758. {"bot_id": "primary", "update_id": 31}
  759. )
  760. update = await app_modules.wbb.db.business_assistant_updates.find_one(
  761. {"bot_id": "primary", "update_id": 31}
  762. )
  763. assert dead_letter["error"] == "persistent failure"
  764. assert update["status"] == "done"
  765. assert await dbassistant.claim_update(31) is False
  766. async def test_connection_updates_revoke_permissions_and_persist_offset(app_modules):
  767. service = app_modules.load("wbb.services.business_assistant")
  768. dbassistant = app_modules.load("wbb.utils.dbassistant")
  769. runtime = service.BusinessAssistantRuntime(
  770. token="123456:" + "A" * 30,
  771. session=SimpleNamespace(),
  772. provider=FakeProvider(),
  773. )
  774. runtime.api = FakeBusinessApi()
  775. await runtime.process_update(
  776. {"update_id": 41, "business_connection": connection_payload(can_reply=True)}
  777. )
  778. connected = await dbassistant.get_business_connection("conn-a")
  779. assert connected["is_enabled"] is True
  780. assert connected["rights"]["can_reply"] is True
  781. await dbassistant.update_account_settings("conn-a", {"assistant_enabled": True})
  782. revoked = connection_payload(can_reply=False)
  783. revoked["is_enabled"] = False
  784. await runtime.process_update({"update_id": 42, "business_connection": revoked})
  785. disconnected = await dbassistant.get_business_connection("conn-a")
  786. assert disconnected["is_enabled"] is False
  787. assert "can_reply" not in disconnected["rights"]
  788. await runtime.process_update(
  789. {"update_id": 420, "business_message": customer_message(message_id=20)}
  790. )
  791. assert runtime.api.sent == []
  792. await dbassistant.save_update_offset(43)
  793. assert await dbassistant.load_update_offset() == 43
  794. await dbassistant.save_update_offset(44)
  795. assert await dbassistant.load_update_offset() == 44
  796. class StartupApi:
  797. def __init__(self, *, supported: bool, webhook_url: str = "") -> None:
  798. self.supported = supported
  799. self.webhook_url = webhook_url
  800. async def get_me(self):
  801. return {"username": "business_bot", "can_connect_to_business": self.supported}
  802. async def get_webhook_info(self):
  803. return {"url": self.webhook_url}
  804. async def test_runtime_blocks_webhook_conflict_and_disabled_business_mode(app_modules):
  805. service = app_modules.load("wbb.services.business_assistant")
  806. runtime = service.BusinessAssistantRuntime(
  807. token="123456:" + "A" * 30,
  808. session=SimpleNamespace(),
  809. provider=FakeProvider(),
  810. )
  811. runtime.api = StartupApi(supported=True, webhook_url="https://hooks.example.com/tg")
  812. webhook_status = await runtime.start()
  813. assert webhook_status["polling_state"] == "blocked"
  814. assert webhook_status["webhook_conflict"] is True
  815. assert runtime._poll_task is None
  816. runtime.api = StartupApi(supported=False)
  817. business_status = await runtime.start()
  818. assert business_status["polling_state"] == "blocked"
  819. assert business_status["business_mode_supported"] is False
  820. assert "BotFather" in business_status["last_error"]
  821. class FakeResponse:
  822. def __init__(self, status: int, payload: dict) -> None:
  823. self.status = status
  824. self.payload = payload
  825. self.headers: dict[str, str] = {}
  826. async def __aenter__(self):
  827. return self
  828. async def __aexit__(self, *_args):
  829. return None
  830. async def json(self, **_kwargs):
  831. return self.payload
  832. class RetrySession:
  833. def __init__(self, responses: list[FakeResponse]) -> None:
  834. self.responses = responses
  835. self.calls = 0
  836. def post(self, *_args, **_kwargs):
  837. response = self.responses[self.calls]
  838. self.calls += 1
  839. return response
  840. async def test_telegram_api_retries_429_and_5xx(app_modules, monkeypatch):
  841. service = app_modules.load("wbb.services.business_assistant")
  842. session = RetrySession(
  843. [
  844. FakeResponse(
  845. 429,
  846. {
  847. "ok": False,
  848. "error_code": 429,
  849. "description": "Too Many Requests",
  850. "parameters": {"retry_after": 3},
  851. },
  852. ),
  853. FakeResponse(
  854. 502,
  855. {"ok": False, "error_code": 502, "description": "Bad Gateway"},
  856. ),
  857. FakeResponse(200, {"ok": True, "result": {"id": 999}}),
  858. ]
  859. )
  860. sleeps: list[int] = []
  861. async def record_sleep(seconds):
  862. sleeps.append(seconds)
  863. monkeypatch.setattr("wbb.services.business_assistant.asyncio.sleep", record_sleep)
  864. api = service.TelegramBusinessApi("123456:" + "A" * 30, session)
  865. assert await api.get_me() == {"id": 999}
  866. assert session.calls == 3
  867. assert sleeps == [3, 2]
  868. async def test_feishu_webhook_signature_and_success_contract(app_modules):
  869. service = app_modules.load("wbb.services.business_assistant")
  870. response = FakeResponse(200, {"code": 0, "msg": "success"})
  871. class CaptureSession:
  872. def __init__(self) -> None:
  873. self.payload = None
  874. def post(self, _url, *, json, timeout):
  875. self.payload = json
  876. assert timeout.total == 8
  877. return response
  878. session = CaptureSession()
  879. client = service.FeishuWebhookClient(session)
  880. await client.send(
  881. "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc",
  882. "消息提醒",
  883. signing_secret="secret",
  884. )
  885. assert session.payload["msg_type"] == "text"
  886. assert session.payload["content"]["text"] == "消息提醒"
  887. assert session.payload["timestamp"]
  888. assert session.payload["sign"]
  889. card_lines = ["账号:店主", "用户:测试用户"]
  890. await client.send_card(
  891. "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc",
  892. title="消息提醒",
  893. lines=card_lines,
  894. link_url="https://t.me/test_user",
  895. )
  896. assert session.payload == {
  897. "msg_type": "interactive",
  898. "card": {
  899. "config": {"wide_screen_mode": True},
  900. "header": {
  901. "template": "blue",
  902. "title": {"tag": "plain_text", "content": "消息提醒"},
  903. },
  904. "elements": [
  905. {
  906. "tag": "div",
  907. "text": {"tag": "plain_text", "content": line},
  908. }
  909. for line in card_lines
  910. ],
  911. "card_link": {"url": "https://t.me/test_user"},
  912. },
  913. }
  914. await client.send_card(
  915. "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc",
  916. title="消息提醒",
  917. lines=["无链接"],
  918. )
  919. assert session.payload == {
  920. "msg_type": "interactive",
  921. "card": {
  922. "config": {"wide_screen_mode": True},
  923. "header": {
  924. "template": "blue",
  925. "title": {"tag": "plain_text", "content": "消息提醒"},
  926. },
  927. "elements": [
  928. {
  929. "tag": "div",
  930. "text": {"tag": "plain_text", "content": "无链接"},
  931. }
  932. ],
  933. },
  934. }
  935. async def _login_and_change_password(client: TestClient) -> str:
  936. login = await client.post(
  937. "/api/admin/v1/auth/login",
  938. json={"username": "admin", "password": "qwe0.123456"},
  939. )
  940. login_data = (await login.json())["data"]
  941. changed = await client.put(
  942. "/api/admin/v1/auth/password",
  943. headers={"X-CSRF-Token": login_data["csrf_token"]},
  944. json={
  945. "current_password": "qwe0.123456",
  946. "new_password": "changed-pass-123",
  947. },
  948. )
  949. return (await changed.json())["data"]["csrf_token"]
  950. async def test_business_assistant_api_permission_csrf_audit_and_clear(app_modules):
  951. dbassistant = app_modules.load("wbb.utils.dbassistant")
  952. await dbassistant.upsert_business_connection(connection_payload())
  953. conversation = await dbassistant.get_or_create_conversation(
  954. "conn-a", 701, customer={"id": 701, "first_name": "待清理客户"}
  955. )
  956. await dbassistant.append_conversation_message(
  957. conversation["conversation_id"],
  958. direction="incoming",
  959. telegram_message_id=1,
  960. text="请清理",
  961. )
  962. await dbassistant.update_conversation_summary(conversation["conversation_id"], "待清理摘要")
  963. admin_api = app_modules.load("wbb.admin.api")
  964. application = admin_api.build_admin_application()
  965. await application["admin_api"].initialize()
  966. client = TestClient(TestServer(application), cookie_jar=CookieJar(unsafe=True))
  967. await client.start_server()
  968. try:
  969. csrf = await _login_and_change_password(client)
  970. app_modules.wbb.BOT_PERMISSIONS = set()
  971. denied = await client.get("/api/admin/v1/business-assistant/status")
  972. assert denied.status == 403
  973. app_modules.wbb.BOT_PERMISSIONS = {"business_assistant.manage"}
  974. no_csrf = await client.put(
  975. "/api/admin/v1/business-assistant/settings",
  976. json={"connection_id": "conn-a", "assistant_enabled": True, "confirm": True},
  977. )
  978. assert no_csrf.status == 403
  979. unconfirmed = await client.put(
  980. "/api/admin/v1/business-assistant/settings",
  981. headers={"X-CSRF-Token": csrf},
  982. json={"connection_id": "conn-a", "assistant_enabled": True},
  983. )
  984. assert unconfirmed.status == 409
  985. saved = await client.put(
  986. "/api/admin/v1/business-assistant/settings",
  987. headers={"X-CSRF-Token": csrf},
  988. json={
  989. "connection_id": "conn-a",
  990. "assistant_enabled": True,
  991. "feishu_webhook_enabled": True,
  992. "feishu_webhook_url": "https://open.feishu.cn/open-apis/bot/v2/hook/12345678-abcd-4321-abcd-123456789abc",
  993. "feishu_webhook_signing_secret": "api-secret",
  994. "confirm": True,
  995. },
  996. )
  997. assert saved.status == 200
  998. saved_data = (await saved.json())["data"]
  999. assert saved_data["assistant_enabled"] is True
  1000. assert saved_data["feishu_webhook_url"] == ""
  1001. assert saved_data["feishu_webhook_signing_secret"] == ""
  1002. assert saved_data["feishu_webhook_configured"] is True
  1003. stored_settings = await dbassistant.get_account_settings("conn-a")
  1004. assert stored_settings["feishu_webhook_signing_secret"] == "api-secret"
  1005. listed_connections = await client.get(
  1006. "/api/admin/v1/business-assistant/connections?page=1&page_size=100"
  1007. )
  1008. listed_settings = (await listed_connections.json())["data"]["items"][0][
  1009. "settings"
  1010. ]
  1011. assert listed_settings["feishu_webhook_url"] == ""
  1012. assert listed_settings["feishu_webhook_signing_secret"] == ""
  1013. class FakeRuntime:
  1014. def __init__(self) -> None:
  1015. self.calls = []
  1016. async def test_feishu_webhook(self, connection_id, overrides):
  1017. self.calls.append((connection_id, overrides))
  1018. return {"ok": True, "account": "店主"}
  1019. module = app_modules.load("wbb.modules.business_assistant")
  1020. fake_runtime = FakeRuntime()
  1021. module._runtime = fake_runtime
  1022. tested = await client.post(
  1023. "/api/admin/v1/business-assistant/feishu-webhook/test",
  1024. headers={"X-CSRF-Token": csrf},
  1025. json={"connection_id": "conn-a", "confirm": True},
  1026. )
  1027. assert tested.status == 200
  1028. assert (await tested.json())["data"]["ok"] is True
  1029. assert fake_runtime.calls == [("conn-a", {})]
  1030. created = await client.post(
  1031. "/api/admin/v1/business-assistant/knowledge",
  1032. headers={"X-CSRF-Token": csrf},
  1033. json={
  1034. "connection_id": "conn-a",
  1035. "question": "配送范围",
  1036. "keywords": ["配送"],
  1037. "answer": "仅限市区。",
  1038. "confirm": True,
  1039. },
  1040. )
  1041. assert created.status == 201
  1042. listed = await client.get(
  1043. "/api/admin/v1/business-assistant/knowledge?connection_id=conn-a"
  1044. )
  1045. assert (await listed.json())["data"]["total"] == 1
  1046. created_source = await client.post(
  1047. "/api/admin/v1/business-assistant/knowledge-sources",
  1048. headers={"X-CSRF-Token": csrf},
  1049. json={
  1050. "connection_id": "conn-a",
  1051. "source_type": "business",
  1052. "title": "人工对话",
  1053. "publication_mode": "review",
  1054. "confirm": True,
  1055. },
  1056. )
  1057. assert created_source.status == 201
  1058. source = (await created_source.json())["data"]
  1059. event, _ = await dbassistant.record_source_event(
  1060. source,
  1061. event_key="business:701:8",
  1062. content="市区可配送。",
  1063. metadata={"chat_id": 701, "message_id": 8, "trusted_author": True},
  1064. )
  1065. candidates = await dbassistant.replace_event_candidates(
  1066. source,
  1067. event,
  1068. [
  1069. {
  1070. "question": "配送范围?",
  1071. "keywords": ["配送"],
  1072. "answer": "市区可配送。",
  1073. "confidence": 0.9,
  1074. }
  1075. ],
  1076. auto_publish=False,
  1077. )
  1078. candidate_page = await client.get(
  1079. "/api/admin/v1/business-assistant/knowledge-candidates"
  1080. "?connection_id=conn-a&status=pending"
  1081. )
  1082. assert candidate_page.status == 200
  1083. assert (await candidate_page.json())["data"]["total"] == 1
  1084. approved = await client.post(
  1085. "/api/admin/v1/business-assistant/knowledge-candidates/"
  1086. f"{candidates[0]['candidate_id']}/actions",
  1087. headers={"X-CSRF-Token": csrf},
  1088. json={"action": "approve", "confirm": True},
  1089. )
  1090. assert approved.status == 200
  1091. assert (await approved.json())["data"]["status"] == "published"
  1092. cleared = await client.post(
  1093. f"/api/admin/v1/business-assistant/conversations/{conversation['conversation_id']}/actions",
  1094. headers={"X-CSRF-Token": csrf},
  1095. json={"action": "clear", "confirm": True},
  1096. )
  1097. assert cleared.status == 200
  1098. detail = await dbassistant.conversation_detail(conversation["conversation_id"])
  1099. assert detail["summary"] == ""
  1100. assert detail["messages"] == []
  1101. audit = await app_modules.wbb.db.admin_audit_logs.find_one(
  1102. {"action": "business_assistant.conversation.clear"}
  1103. )
  1104. assert audit["success"] is True
  1105. finally:
  1106. await client.close()