feat(rectification): anonymous aggregate telemetry + admin summary page

One row per rectification Case, written once when the range card is first
delivered (GET /api/rectification/cases/[caseId], fire-and-forget after the
response is built). Numbers and closed enums only: no user / case / session
id, birth data, names, text or timestamps finer than the ISO week. Dedupe via
a separate case_id ledger that cascades with the Case (and account deletion).

Migration 20260926010000 is additive: two RLS tables with no runtime table
grants, SECURITY DEFINER write (service_role), purge (service_role) and
aggregate-only summary (admin_runtime) functions; 180-day retention.

Admin: 「校正统计」 page + GET /api/admin/rectification-telemetry
(admin.customers.read), aggregates only, no per-row view or export.

TASK-rectification-telemetry-20260926. test:db not run locally (no Docker).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eEAG8HD3mm8gsKXgk8uU8
This commit is contained in:
Jesse_Chen
2026-09-26 15:36:29 +08:00
co-authored by Claude Opus 5.5
parent f74825a27c
commit d0bfc1fc3d
27 changed files with 2422 additions and 6 deletions
+4
View File
@@ -1586,6 +1586,10 @@ def test_capability_audit_scans_registry_and_local_sources() -> None:
'admin/payments',
'admin/pricing-simulator',
'admin/products',
# 原值: admin/products 后面直接是 admin/roles
# 新值: 中间加入 admin/rectification-telemetry
# 原因: 匿名校正统计的后台汇总页(TASK-rectification-telemetry-20260926)是新的 app 路由
'admin/rectification-telemetry',
'admin/roles',
'admin/security',
'admin/subscriptions',