fix(feishu): bind card decisions to the actor and reject stale cards

Address review feedback on the interaction cards:

1. Bind card decisions to the initiating actor. The card-action operator
   (operatorOpenId) is now passed into the approval and question handlers:
   - submitByApprovalId receives { actor } so another allowed group member
     cannot approve/reject someone else's approval;
   - the answer branch requires pending.actor === operator.

2. Include the question index in the answer button action and validate it
   against the current pending question, so a stale card from an earlier
   question in a multi-question interaction cannot be applied to the next one.

3. When both the card send and the plain-text fallback fail, the error is no
   longer swallowed: it propagates so the interaction is not marked as
   presented and the existing retry/reconnect behaviour can run.

Adds regression tests for all three cases.
This commit is contained in:
C3H3-AI 2026-09-01 17:42:10 +08:00
parent 0b42ea9889
commit b5378500ca
4 changed files with 244 additions and 21 deletions

View file

@ -1721,7 +1721,7 @@ export class FeishuHarnessBridge {
return;
}
}
await this.#handleCardAction(resolvedAction, entry);
await this.#handleCardAction(resolvedAction, { ...entry, actor: entry.operatorOpenId });
}, {
lane: isStop || isRealSteer ? 'control' : 'regular',
coalesceStop: isStop,
@ -1878,6 +1878,7 @@ export class FeishuHarnessBridge {
sessionWorkspace = null,
sessionPage = 0,
selections = [],
actor = null,
}) {
// Confirmations triggered by a card interaction stay anchored to the
// card's message so they land inside the same Feishu topic.
@ -1887,22 +1888,32 @@ export class FeishuHarnessBridge {
const sep = action.indexOf(':');
const approvalId = action.slice(sep + 1);
const outcome = action.startsWith('approve:') ? 'allowed-once' : 'rejected';
const submitted = await this.#approvals.submitByApprovalId(approvalId, outcome);
// Bind the decision to the operator so another allowed group member
// cannot decide someone else's approval.
const submitted = await this.#approvals.submitByApprovalId(approvalId, outcome, { actor });
if (!submitted) {
await reply(t('该审批已处理或不存在,无需重复操作。')).catch(() => undefined);
}
return;
}
// Question option buttons: answer:<interactionId>:<optionLabel>
// Question option buttons: answer:<interactionId>:<index>:<optionLabel>
if (action.startsWith('answer:')) {
const rest = action.slice('answer:'.length);
const sep = rest.indexOf(':');
if (sep !== -1) {
const interactionId = rest.slice(0, sep);
const optionLabel = rest.slice(sep + 1);
const firstSep = rest.indexOf(':');
if (firstSep !== -1) {
const interactionId = rest.slice(0, firstSep);
const afterId = rest.slice(firstSep + 1);
const indexSep = afterId.indexOf(':');
const indexText = indexSep === -1 ? afterId : afterId.slice(0, indexSep);
const optionLabel = indexSep === -1 ? '' : afterId.slice(indexSep + 1);
const qKey = this.#interactionKeys.get(interactionId);
const pending = qKey ? this.#pendingInteractions.get(qKey) : null;
if (pending && pending.kind === 'question' && !pending.submitting) {
// Only the actor who started the interaction may answer it, and the
// card must still target the current question (a stale card from an
// earlier question in a multi-question interaction must not submit).
if (pending && pending.kind === 'question' && !pending.submitting
&& pending.actor === actor
&& Number(indexText) === pending.index) {
await this.#submitQuestionAnswer(pending, optionLabel, { chatId });
} else {
await reply(INTERACTION_RESOLVED_TEXT()).catch(() => undefined);
@ -3705,9 +3716,12 @@ export class FeishuHarnessBridge {
approvalId: pending.approvalId,
}),
{ key, replyTo: replyToMessageId },
).catch(() => {
// Fall back to the plain-text approval if the card cannot be sent.
return this.#send(chatId, pending.text, { replyTo: replyToMessageId }).catch(() => undefined);
).catch(async () => {
// Fall back to the plain-text approval if the card cannot be
// sent. If the text send also fails, let the error propagate so
// the pending approval is not marked as presented and the
// existing retry/reconnect logic can run.
await this.#send(chatId, pending.text, { replyTo: replyToMessageId });
});
},
}
@ -3827,15 +3841,17 @@ export class FeishuHarnessBridge {
total: pending.questions.length,
}),
{ key: pending.key, replyTo: pending.replyToMessageId },
).catch(() => {
).catch(async () => {
// Fall back to the plain-text question if the card cannot be sent.
return this.#send(
// If the text send also fails, let the error propagate so the pending
// question is not marked as presented and the existing retry logic runs.
await this.#send(
pending.chatId,
harnessQuestionText(question, pending.index, pending.questions.length, {
requiresMention: pending.requiresMention,
}),
{ replyTo: pending.replyToMessageId },
).catch(() => undefined);
);
});
} else {
// Multi-select or free-text questions keep the plain-text reply flow.

View file

@ -925,7 +925,9 @@ export function questionCard({ interactionId, header, question, detail, options,
// Include the option description in the button so the user sees the full
// meaning (mirrors the text form "1. label — description").
const buttonText = description ? `${label}\n${description}` : label;
elements.push(button(buttonText, `answer:${interactionId}:${label}`));
// Action carries the question index so a stale card from a previous
// question cannot be applied to the current one: answer:<interactionId>:<index>:<label>
elements.push(button(buttonText, `answer:${interactionId}:${index}:${label}`));
}
}
return cardWith(t('❓ 请补充信息{progress}', { progress }), elements);