Compare commits
8 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 78beb82c7d | |||
| 7811943178 | |||
| c1476d5c52 | |||
| 68b3536084 | |||
| 97f7607b2b | |||
| bd1d484e74 | |||
| d266380e6d | |||
| 1d200fc3f6 |
File diff suppressed because one or more lines are too long
@@ -0,0 +1,62 @@
|
||||
# SmartAssistant — Architecture (developer reference)
|
||||
|
||||
> Internal developer doc. Not shipped to clients. Customer overview: `README.md`. Security/dead-code findings: `_AUDIT/SmartAssistant/findings.md`.
|
||||
|
||||
**Module:** `SmartAssistant` · **Client module:** `smart-assistant` · **Load order:** 37 · **Requires:** EspoCRM ≥ 8.0.0, PHP ≥ 8.1
|
||||
|
||||
## What it is
|
||||
A floating AI legal assistant. A chat widget (case mode / office mode) sends the user message plus rich context (case data, case memory, behavioral rules, prompt sections, learned skills, user profile) to the **shira-hermes** FastAPI backend via a webhook; shira returns response text + a list of tools, which `ActionExecutor` runs against the CRM (task/call/meeting CRUD, status changes, document + memory ops, rule saving), optionally looping tool results back to shira (agentic loop, max 3). Also computes office-wide alerts. Owns 6 entities (AssistantPrompt, AssistantRule, AssistantSkill, CaseMemory, UserProfile, AssistantConversation) and extends `Note` with 3 timeline note types.
|
||||
|
||||
## File-by-file
|
||||
|
||||
### Lifecycle
|
||||
| File | Purpose |
|
||||
|---|---|
|
||||
| `scripts/AfterInstall.php` | Idempotently seeds 7 default AssistantPrompt sections (`skipAll`; admin edits win). No uninstall script (seeded entities persist). |
|
||||
|
||||
### Controllers
|
||||
| File | Purpose |
|
||||
|---|---|
|
||||
| `Controllers/SmartAssistant.php` | ~30 actions: chat, execute, executeTool, alerts, summary, history, conversations, caseMemory, saveMemory, document read/analyze/upload/generate/rename/list/browse/write/move. (S1–S6 — **ACL fixed 2026-06-20**: `assertCaseAccess()` on chat/caseMemory/saveMemory/history; document-read endpoints require `caseId` + ACL + `isPathWithinCase()` containment.) |
|
||||
| `Controllers/{AssistantRule,AssistantPrompt,AssistantSkill,CaseMemory,UserProfile}.php` | Thin Record CRUD. **AssistantRule has no owner field — S5.** |
|
||||
|
||||
### Services
|
||||
| File | Purpose |
|
||||
|---|---|
|
||||
| `SmartAssistantService.php` | Orchestrator: webhook call, agentic loop, conversation persistence, stream notes (SmartRequest/Response/Action), office drill-down. (**fixed 2026-06-20**: `detectDrillDown` ACL-filters matched cases (S6); dead static `$conversations` removed (D1).) Forwards espocrmApiKey — S9 still open. |
|
||||
| `ConversationRepository.php` | File-based conversation JSON under `data/conversations/`. |
|
||||
| `ActionExecutor.php` | Executes all shira tools. (**ACL fixed 2026-06-20**: resolves the acting user in `execute()`; central `CASE_TOOL_ACCESS` record-ACL gate for case-bound tools (S1); `assertEntityAccess(...,'delete')` on every delete tool (S4); `save_rule` admin-only (S5); plugin tools with a caseId require case edit — also closes LegalAssistance S1.) |
|
||||
| `CaseContextBuilder.php` / `OfficeContextBuilder.php` | Build case / office context dicts. **Case context IDOR S3.** |
|
||||
| `CaseMemoryContextProvider.php`, `AssistantRuleContextProvider.php`, `AssistantPromptContextProvider.php`, `AssistantSkillContextProvider.php`, `UserProfileContextProvider.php` | Load memories/rules/prompts/skills/profile into the prompt. |
|
||||
| `CaseMemoryService.php` | CaseMemory CRUD (category/importance/pinned). **IDOR S3.** |
|
||||
| `DocumentAnalyzer.php` | Text extraction/analysis; uses NetworkStorageIntegration NetworkDocumentService. (**fixed 2026-06-20**: added `isPathWithinCase()` containment helper the controller calls before any read — S2.) |
|
||||
| `CaseFolderManager.php` | Write/rename/move constrained to the case folder (`resolveSafePath`/`sanitizeRelSegments` — safe). |
|
||||
| `GenericTemplateGenerator.php` / `FreeDocumentGenerator.php` | Template-based / free-form document generation. |
|
||||
| `AlertCalculator.php` | Office alerts (inactive cases, overdue tasks, hearings without prep, unassigned new cases, deadlines). |
|
||||
|
||||
### Hooks
|
||||
| File | Trigger |
|
||||
|---|---|
|
||||
| `Hooks/Case/CaseFieldChangeMemory.php` | afterSave — auto-seed CaseMemory on status/judge/court/next-hearing change. |
|
||||
| `Hooks/Meeting/HearingScheduledMemory.php` | afterSave — memory when a hearing Meeting is created. |
|
||||
|
||||
### Resources / client
|
||||
| Path | Purpose |
|
||||
|---|---|
|
||||
| `entityDefs/{AssistantPrompt,AssistantRule,AssistantSkill,CaseMemory,UserProfile,Note,Case}.json` | 6 entities + Note.type extension + Case.caseMemories link. **AssistantRule/UserProfile ACL — S5/S7.** |
|
||||
| `integrations/SmartAssistant.json` | webhookUrl, apiKey, espocrmApiKey, thresholds, agenticLoop. **Keys are varchar — S8.** |
|
||||
| `routes.json` (12), `clientDefs/*`, `scopes/*`, `layouts/*`, `dashlets/SmartAssistant.json`, `i18n/{en_US,fa_IR}/*`, `data/default-prompts.json` | Routes, UI, ACL, dashlet, translations, seed prompts. |
|
||||
| `client/.../src/views/floating-chat.js` | Main chat widget (history, memory browser, mode badge). escape-then-markdown — XSS-safe. |
|
||||
| `client/.../src/views/dashlets/smart-assistant.js` | Alerts card. **Unescaped caseId href S10.** |
|
||||
| `client/.../src/views/{case/modals/add-memory,fields/prompt-editor,site/navbar}.js`, `stream/notes/smart-{request,response,action}.js` | Memory modal, prompt editor, navbar inject, timeline note item views. |
|
||||
|
||||
## Dependencies
|
||||
- **NetworkStorageIntegration (hard):** DocumentAnalyzer document ops.
|
||||
- **shira-hermes (external, hard):** webhook (Integration record `SmartAssistant`). No chat without it.
|
||||
- **KnowledgeBase → SmartAssistant (REVERSE, critical):** KnowledgeBase reuses this extension's Integration record. **Do not uninstall SmartAssistant while KnowledgeBase is installed.**
|
||||
- **LegalCrm (soft):** Note.type extension.
|
||||
|
||||
## Post-install gotchas
|
||||
- Configure the `SmartAssistant` Integration (webhookUrl + apiKey + espocrmApiKey) — scope the espocrmApiKey to a minimal API user (S9).
|
||||
- Known deploy gotchas: a backup-in-modules folder breaks hooks; AfterInstall needs `skipAll`; new role entries need api-key role grant.
|
||||
- shira-hermes `/opt/data` must be a named volume (else skills/profiles/cases wiped on redeploy).
|
||||
@@ -1,120 +1,55 @@
|
||||
# SmartAssistant - עוזר חכם
|
||||
# SmartAssistant — עוזר AI למשרד
|
||||
|
||||
**גרסה:** 2.8.0 | **מחבר:** klear | **EspoCRM:** >= 8.0.0
|
||||
**גרסה:** 2.10.5 | **מחבר:** klear | **EspoCRM:** >= 8.0.0
|
||||
|
||||
## תיאור
|
||||
עוזר AI מאוחד למשרד עורכי דין. מספק ממשק צ'אט צף עם שני מצבי עבודה: **מצב משרד** (סקירה כללית, התראות, סטטיסטיקות) ו**מצב תיק** (סיוע מעמיק בתיק ספציפי). כולל מערכת זיכרון תיק מובנית, ביצוע פעולות באישור המשתמש, ואינטגרציה עם Stream של EspoCRM.
|
||||
|
||||
עוזר AI מאוחד למשרד עורכי דין. צ'אט צף עם שני מצבי עבודה: **מצב משרד** (סקירה כללית, התראות,
|
||||
סטטיסטיקות) ו**מצב תיק** (סיוע מעמיק בתיק ספציפי). כולל זיכרון תיק מובנה, ביצוע פעולות באישור המשתמש,
|
||||
התראות משרד (תיקים לא פעילים, משימות באיחור, דיונים קרובים), ואינטגרציה עם ה‑Stream של התיק.
|
||||
|
||||
## תלויות
|
||||
- Webhook חיצוני (n8n או דומה) לעיבוד AI
|
||||
- NetworkStorageIntegration / NextCloudIntegration (אופציונלי — לניתוח מסמכים)
|
||||
|
||||
- **שירות ה‑AI (shira‑hermes)** — נדרש; העוזר מדבר איתו דרך Webhook. בלעדיו הצ'אט אינו פעיל.
|
||||
- **NetworkStorageIntegration** — נדרש לניתוח וקריאת מסמכי התיק.
|
||||
- **הערה:** אם מותקנת גם **KnowledgeBase**, היא משתמשת בהגדרות האינטגרציה של SmartAssistant — **אין להסיר את SmartAssistant כל עוד KnowledgeBase מותקנת.**
|
||||
|
||||
## התקנה
|
||||
1. התקנה דרך Admin > Extensions
|
||||
2. הגדרת Webhook: Admin > Integrations > Smart Assistant
|
||||
|
||||
## הגדרות אינטגרציה
|
||||
1. הורד את `SmartAssistant-2.10.5.zip` והתקן דרך **ניהול → הרחבות**.
|
||||
2. ב**ניהול → אינטגרציות → Smart Assistant** הזן את כתובת ה‑Webhook, מפתח ה‑API, ומפתח ה‑API של EspoCRM.
|
||||
3. בצע Rebuild ורענון קשיח.
|
||||
|
||||
| שדה | תיאור | דוגמה |
|
||||
|------|--------|--------|
|
||||
| webhookUrl | כתובת Webhook לשירות AI | `https://n8n.example.com/webhook/assistant/chat` |
|
||||
| apiKey | מפתח אימות (אופציונלי) | `sk-...` |
|
||||
| maxMessagesPerHour | הגבלת קצב הודעות | `30` |
|
||||
| inactivityWarningDays | סף אזהרה לחוסר פעילות בתיק | `14` |
|
||||
| inactivityCriticalDays | סף קריטי לחוסר פעילות | `30` |
|
||||
| upcomingHearingDays | חלון דיונים קרובים (ימים) | `7` |
|
||||
## הגדרות
|
||||
|
||||
## אנטיטי: CaseMemory — זיכרון תיק
|
||||
| הגדרה | תיאור |
|
||||
|---|---|
|
||||
| webhookUrl | כתובת שירות ה‑AI (shira‑hermes). |
|
||||
| apiKey | מפתח אימות מול שירות ה‑AI. |
|
||||
| espocrmApiKey | מפתח API שבו שירות ה‑AI חוזר לפנות ל‑EspoCRM (מומלץ לשייך למשתמש API עם הרשאות מצומצמות). |
|
||||
| ספי התראה | ימי חוסר‑פעילות לאזהרה/קריטי, חלון דיונים קרובים. |
|
||||
|
||||
מאגר ידע מובנה לכל תיק, מחולק לקטגוריות:
|
||||
## מה מתווסף למערכת
|
||||
|
||||
| קטגוריה | תיאור |
|
||||
|----------|--------|
|
||||
| key_facts | עובדות מפתח |
|
||||
| strategy | אסטרטגיה |
|
||||
| decisions | החלטות |
|
||||
| contacts_notes | הערות על אנשי קשר |
|
||||
| timeline | ציר זמן |
|
||||
| documents_notes | הערות על מסמכים |
|
||||
| billing_notes | הערות חיוב |
|
||||
- **כפתור צ'אט צף** בכל מסך, עם היסטוריית שיחות ועיון בזיכרון התיק.
|
||||
- **זיכרון תיק (CaseMemory):** מאגר ידע מובנה לכל תיק (עובדות מפתח, אסטרטגיה, החלטות, ציר זמן ועוד) — נשמר ידנית, ע"י העוזר, או אוטומטית בשינויי תיק.
|
||||
- **דשבורד התראות** ותצוגות SmartRequest/SmartResponse/SmartAction בציר הזמן של התיק.
|
||||
- **ניהול מהממשק:** עריכת פרומפטים, כללי התנהגות, מיומנויות ופרופילי משתמש.
|
||||
|
||||
**מקורות:** ידני (manual), עוזר AI (assistant), אוטומטי (auto — hooks)
|
||||
## טיפול בעיות נפוצות
|
||||
|
||||
**רמות חשיבות:** low, normal, high, critical
|
||||
| תסמין | סיבה | פתרון |
|
||||
|---|---|---|
|
||||
| הצ'אט לא מגיב | שירות ה‑AI לא מוגדר/לא זמין | בדוק את webhookUrl ושהשירות (shira‑hermes) רץ. |
|
||||
| KnowledgeBase מפסיקה לעבוד | הוסרה/בוטלה אינטגרציית SmartAssistant | החזר את אינטגרציית SmartAssistant — KnowledgeBase תלויה בה. |
|
||||
| ניתוח מסמכים נכשל | NetworkStorageIntegration לא מותקן | התקן את NetworkStorageIntegration. |
|
||||
|
||||
## רכיבים
|
||||
## הרשאות
|
||||
|
||||
### Backend (PHP)
|
||||
העוזר פועל בגבולות ההרשאות של המשתמש: כל פעולה, קריאת מסמך, זיכרון תיק או "צלילה" לתיק במצב משרד
|
||||
מתבצעת רק על תיקים שהמשתמש מורשה לגשת אליהם, וקריאת מסמכים מוגבלת לתיקיית התיק הרלוונטי בלבד.
|
||||
יצירת **כללי עוזר** (כללים החלים על כל המשרד) שמורה למנהל מערכת.
|
||||
|
||||
| רכיב | קובץ | תיאור |
|
||||
|-------|------|--------|
|
||||
| Controller | `Controllers/SmartAssistant.php` | API endpoints |
|
||||
| שירות ראשי | `Services/SmartAssistantService.php` | תזמור צ'אט, שיחות, פעולות |
|
||||
| בונה הקשר תיק | `Services/CaseContextBuilder.php` | אוסף נתוני תיק מלאים (אנשי קשר, משימות, מסמכים, זיכרון) |
|
||||
| בונה הקשר משרד | `Services/OfficeContextBuilder.php` | סטטיסטיקות, התראות, עומס עבודה |
|
||||
| מחשבון התראות | `Services/AlertCalculator.php` | זיהוי תיקים לא פעילים, משימות באיחור, דיונים קרובים |
|
||||
| מבצע פעולות | `Services/ActionExecutor.php` | ביצוע פעולות שאושרו (משימה, פתק, דיון, שינוי סטטוס) |
|
||||
| שירות זיכרון | `Services/CaseMemoryService.php` | CRUD לזיכרון תיק |
|
||||
| ספק הקשר זיכרון | `Services/CaseMemoryContextProvider.php` | הזרקת זיכרון להקשר AI |
|
||||
| מאגר שיחות | `Services/ConversationRepository.php` | שמירה ואחזור שיחות |
|
||||
| מנתח מסמכים | `Services/DocumentAnalyzer.php` | סריקת מסמכים וסיווג |
|
||||
---
|
||||
|
||||
### Hooks
|
||||
|
||||
| Hook | תיאור |
|
||||
|------|--------|
|
||||
| `Case/CaseFieldChangeMemory` | יצירת זיכרון אוטומטית בשינוי שדות תיק (סטטוס, שופט, דיון) |
|
||||
| `Meeting/HearingScheduledMemory` | יצירת זיכרון בקביעת דיון חדש |
|
||||
|
||||
### Frontend (JavaScript)
|
||||
|
||||
| רכיב | תיאור |
|
||||
|-------|--------|
|
||||
| `floating-chat.js` | ממשק צ'אט צף (FAB) עם מגירת היסטוריה וזיכרון |
|
||||
| `dashlets/smart-assistant.js` | דשלט עם מדדים והתראות |
|
||||
| `stream/notes/smart-request.js` | תצוגת הודעת משתמש ב-Stream |
|
||||
| `stream/notes/smart-response.js` | תצוגת תשובת עוזר ב-Stream |
|
||||
| `stream/notes/smart-action.js` | תצוגת פעולה שבוצעה ב-Stream |
|
||||
| `case/modals/add-memory.js` | מודל להוספת זיכרון ידנית |
|
||||
| `site/navbar.js` | אינטגרציית התראות בסרגל ניווט |
|
||||
|
||||
## API Routes
|
||||
|
||||
| נתיב | Method | תיאור |
|
||||
|-------|--------|--------|
|
||||
| `/SmartAssistant/action/chat` | POST | שליחת הודעה לעוזר |
|
||||
| `/SmartAssistant/action/execute` | POST | ביצוע פעולה שאושרה |
|
||||
| `/SmartAssistant/action/summary` | GET | סיכום משרדי + התראות |
|
||||
| `/SmartAssistant/action/alerts` | GET | רשימת התראות |
|
||||
| `/SmartAssistant/action/history` | GET | היסטוריית שיחות |
|
||||
| `/SmartAssistant/action/conversations` | GET | רשימת שיחות אחרונות |
|
||||
| `/SmartAssistant/action/conversationMessages` | GET | הודעות שיחה ספציפית |
|
||||
| `/SmartAssistant/action/searchHistory` | GET | חיפוש בשיחות |
|
||||
| `/SmartAssistant/action/caseMemory` | GET | אחזור זיכרון תיק |
|
||||
| `/SmartAssistant/action/saveMemory` | POST | שמירת זיכרון ידנית |
|
||||
|
||||
## פעולות עוזר
|
||||
|
||||
### פעולות מיידיות (ללא אישור)
|
||||
- `list_documents` — רשימת מסמכים בתיק
|
||||
- `save_memory` — שמירת זיכרון תיק
|
||||
|
||||
### פעולות הדורשות אישור
|
||||
- `create_task` — יצירת משימה
|
||||
- `add_note` — הוספת הערה
|
||||
- `change_status` — שינוי סטטוס תיק
|
||||
- `create_meeting` — יצירת פגישה
|
||||
- `schedule_hearing` — קביעת דיון
|
||||
- `analyze_document` — ניתוח מסמך
|
||||
- `rename_document` — שינוי שם מסמך
|
||||
|
||||
## מערכת התראות
|
||||
|
||||
| סוג | סף ברירת מחדל | חומרה |
|
||||
|------|----------------|--------|
|
||||
| תיק לא פעיל | 14 יום | אזהרה |
|
||||
| תיק לא פעיל | 30 יום | קריטי |
|
||||
| משימה באיחור | תאריך יעד עבר | קריטי |
|
||||
| דיון קרוב | 7 ימים | אזהרה |
|
||||
| תיק ללא שיוך | חדש ללא assignedUser | אזהרה |
|
||||
| משימה בעדיפות גבוהה | 5 ימים | אזהרה |
|
||||
> תיעוד טכני למפתחים (שירותים, פעולות, hooks, זרימת ה‑webhook): `ARCHITECTURE.md`.
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
<?php
|
||||
|
||||
namespace Espo\Modules\SmartAssistant\Controllers;
|
||||
|
||||
/**
|
||||
* Standard CRUD over /api/v1/CaseMemory.
|
||||
*
|
||||
* Until SmartAssistant 2.10.0 the CaseMemory entity was created via
|
||||
* CaseMemoryService::createMemory and listed via Case relation panels —
|
||||
* never via the bare REST endpoint. Flipping `tab: true` exposes the
|
||||
* navbar list view, which uses GET /api/v1/CaseMemory and needs this
|
||||
* Controller class to exist (otherwise EspoCRM returns 404 "Controller
|
||||
* does not exist"). Same pattern as the AssistantRule fix shipped in 2.9.2.
|
||||
*/
|
||||
class CaseMemory extends \Espo\Core\Controllers\Record
|
||||
{
|
||||
}
|
||||
@@ -8,6 +8,8 @@ use Espo\Core\Exceptions\BadRequest;
|
||||
use Espo\Core\Exceptions\Forbidden;
|
||||
use Espo\Core\InjectableFactory;
|
||||
use Espo\Core\Acl;
|
||||
use Espo\Core\Exceptions\NotFound;
|
||||
use Espo\ORM\EntityManager;
|
||||
use Espo\Modules\SmartAssistant\Services\SmartAssistantService;
|
||||
use Espo\Modules\SmartAssistant\Services\ActionExecutor;
|
||||
use Espo\Modules\SmartAssistant\Services\CaseMemoryService;
|
||||
@@ -22,12 +24,14 @@ class SmartAssistant
|
||||
private InjectableFactory $injectableFactory;
|
||||
private Acl $acl;
|
||||
private User $user;
|
||||
private EntityManager $entityManager;
|
||||
|
||||
public function __construct(InjectableFactory $injectableFactory, Acl $acl, User $user)
|
||||
public function __construct(InjectableFactory $injectableFactory, Acl $acl, User $user, EntityManager $entityManager)
|
||||
{
|
||||
$this->injectableFactory = $injectableFactory;
|
||||
$this->acl = $acl;
|
||||
$this->user = $user;
|
||||
$this->entityManager = $entityManager;
|
||||
}
|
||||
|
||||
private function getService(): SmartAssistantService
|
||||
@@ -42,6 +46,24 @@ class SmartAssistant
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Record-level ACL on a specific case. The scope check in checkAccess() is
|
||||
* not enough — without this, any user with Case-scope read could read/write
|
||||
* the data of ANY case by passing its id (findings S2/S3).
|
||||
*/
|
||||
private function assertCaseAccess(string $caseId, string $action = 'read'): void
|
||||
{
|
||||
$case = $this->entityManager->getEntityById('Case', $caseId);
|
||||
|
||||
if (!$case) {
|
||||
throw new NotFound('Case not found.');
|
||||
}
|
||||
|
||||
if (!$this->acl->checkEntity($case, $action)) {
|
||||
throw new Forbidden('No access to this case.');
|
||||
}
|
||||
}
|
||||
|
||||
public function getActionStatus(Request $request, Response $response): array
|
||||
{
|
||||
return $this->getService()->getStatus();
|
||||
@@ -63,6 +85,10 @@ class SmartAssistant
|
||||
throw new BadRequest('caseId is required for case mode.');
|
||||
}
|
||||
|
||||
if ($mode === 'case') {
|
||||
$this->assertCaseAccess($caseId, 'read');
|
||||
}
|
||||
|
||||
return $this->getService()->chat(
|
||||
trim($data->message),
|
||||
$mode,
|
||||
@@ -103,6 +129,11 @@ class SmartAssistant
|
||||
{
|
||||
$this->checkAccess();
|
||||
$caseId = $request->getQueryParam('caseId');
|
||||
|
||||
if (!empty($caseId)) {
|
||||
$this->assertCaseAccess($caseId, 'read');
|
||||
}
|
||||
|
||||
return $this->getService()->getHistory($caseId);
|
||||
}
|
||||
|
||||
@@ -146,6 +177,8 @@ class SmartAssistant
|
||||
throw new BadRequest('caseId is required.');
|
||||
}
|
||||
|
||||
$this->assertCaseAccess($caseId, 'read');
|
||||
|
||||
$category = $request->getQueryParam('category');
|
||||
$includeArchived = (bool) $request->getQueryParam('includeArchived');
|
||||
|
||||
@@ -162,6 +195,8 @@ class SmartAssistant
|
||||
throw new BadRequest('caseId and content are required.');
|
||||
}
|
||||
|
||||
$this->assertCaseAccess($data->caseId, 'edit');
|
||||
|
||||
$service = $this->injectableFactory->create(CaseMemoryService::class);
|
||||
$entry = $service->createMemory(
|
||||
$data->caseId,
|
||||
@@ -206,9 +241,20 @@ class SmartAssistant
|
||||
throw new BadRequest('filePath is required.');
|
||||
}
|
||||
|
||||
$caseId = $data->caseId ?? null;
|
||||
if (empty($caseId)) {
|
||||
throw new BadRequest('caseId is required.');
|
||||
}
|
||||
$this->assertCaseAccess($caseId, 'read');
|
||||
|
||||
$maxLength = isset($data->maxLength) ? (int) $data->maxLength : null;
|
||||
|
||||
$analyzer = $this->injectableFactory->create(DocumentAnalyzer::class);
|
||||
|
||||
if (!$analyzer->isPathWithinCase($filePath, $caseId)) {
|
||||
throw new Forbidden('File is outside the case folder.');
|
||||
}
|
||||
|
||||
$text = $analyzer->extractFullText($filePath, $maxLength);
|
||||
|
||||
return [
|
||||
@@ -229,7 +275,18 @@ class SmartAssistant
|
||||
throw new BadRequest('filePath is required.');
|
||||
}
|
||||
|
||||
$caseId = $data->caseId ?? null;
|
||||
if (empty($caseId)) {
|
||||
throw new BadRequest('caseId is required.');
|
||||
}
|
||||
$this->assertCaseAccess($caseId, 'read');
|
||||
|
||||
$analyzer = $this->injectableFactory->create(DocumentAnalyzer::class);
|
||||
|
||||
if (!$analyzer->isPathWithinCase($filePath, $caseId)) {
|
||||
throw new Forbidden('File is outside the case folder.');
|
||||
}
|
||||
|
||||
return $analyzer->getDocumentBytes($filePath);
|
||||
}
|
||||
|
||||
@@ -243,9 +300,22 @@ class SmartAssistant
|
||||
throw new BadRequest('filePaths is required (array of file paths).');
|
||||
}
|
||||
|
||||
$caseId = $data->caseId ?? null;
|
||||
if (empty($caseId)) {
|
||||
throw new BadRequest('caseId is required.');
|
||||
}
|
||||
$this->assertCaseAccess($caseId, 'read');
|
||||
|
||||
$maxPerFile = isset($data->maxCharsPerFile) ? (int) $data->maxCharsPerFile : 50000;
|
||||
|
||||
$analyzer = $this->injectableFactory->create(DocumentAnalyzer::class);
|
||||
|
||||
foreach ((array) $filePaths as $fp) {
|
||||
if (!$analyzer->isPathWithinCase($fp, $caseId)) {
|
||||
throw new Forbidden('One or more files are outside the case folder.');
|
||||
}
|
||||
}
|
||||
|
||||
$results = $analyzer->extractMultipleDocuments((array) $filePaths, $maxPerFile);
|
||||
|
||||
return [
|
||||
|
||||
+10
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"controller": "controllers/record",
|
||||
"color": "#5e8c61",
|
||||
"iconClass": "fas fa-list-check",
|
||||
"boolFilterList": ["onlyMy"],
|
||||
"filterList": [
|
||||
{"name": "active"},
|
||||
{"name": "inactive"}
|
||||
]
|
||||
}
|
||||
+10
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"controller": "controllers/record",
|
||||
"color": "#9b59b6",
|
||||
"iconClass": "fas fa-brain",
|
||||
"boolFilterList": ["onlyMy"],
|
||||
"filterList": [
|
||||
{"name": "pinned"},
|
||||
{"name": "byCategory"}
|
||||
]
|
||||
}
|
||||
+3
-1
@@ -7,5 +7,7 @@
|
||||
"aclLevelList": ["all", "team", "own", "no"],
|
||||
"stream": false,
|
||||
"tab": true,
|
||||
"disabled": false
|
||||
"disabled": false,
|
||||
"importable": false,
|
||||
"customizable": true
|
||||
}
|
||||
|
||||
@@ -3,8 +3,11 @@
|
||||
namespace Espo\Modules\SmartAssistant\Services;
|
||||
|
||||
use Espo\Core\Exceptions\Error;
|
||||
use Espo\Core\Exceptions\Forbidden;
|
||||
use Espo\Core\Exceptions\NotFound;
|
||||
use Espo\Core\InjectableFactory;
|
||||
use Espo\Core\AclManager;
|
||||
use Espo\ORM\Entity;
|
||||
use Espo\ORM\EntityManager;
|
||||
use Espo\Core\Utils\Log;
|
||||
use Espo\Core\Utils\Metadata;
|
||||
@@ -15,13 +18,52 @@ class ActionExecutor
|
||||
private InjectableFactory $injectableFactory;
|
||||
private Log $log;
|
||||
private Metadata $metadata;
|
||||
private AclManager $aclManager;
|
||||
|
||||
public function __construct(EntityManager $entityManager, InjectableFactory $injectableFactory, Log $log, Metadata $metadata)
|
||||
/** The user on whose behalf the current tool batch runs (set in execute()). */
|
||||
private ?Entity $actingUser = null;
|
||||
|
||||
public function __construct(EntityManager $entityManager, InjectableFactory $injectableFactory, Log $log, Metadata $metadata, AclManager $aclManager)
|
||||
{
|
||||
$this->entityManager = $entityManager;
|
||||
$this->injectableFactory = $injectableFactory;
|
||||
$this->log = $log;
|
||||
$this->metadata = $metadata;
|
||||
$this->aclManager = $aclManager;
|
||||
}
|
||||
|
||||
/**
|
||||
* Tools that act within a Case context, and the ACL action each requires on
|
||||
* that Case. EspoCRM does NOT auto-ACL agent tools, so executeTool would
|
||||
* otherwise let any user with Case-scope read create/modify/read data on
|
||||
* ANY case by passing its id. The central gate in execute() closes that.
|
||||
*/
|
||||
private const CASE_TOOL_ACCESS = [
|
||||
'create_task' => 'edit',
|
||||
'add_note' => 'edit',
|
||||
'change_status' => 'edit',
|
||||
'create_meeting' => 'edit',
|
||||
'create_call' => 'edit',
|
||||
'schedule_hearing' => 'edit',
|
||||
'save_memory' => 'edit',
|
||||
'upload_document' => 'edit',
|
||||
'generate_document' => 'edit',
|
||||
'merge_documents' => 'edit',
|
||||
'list_documents' => 'read',
|
||||
'analyze_document' => 'read',
|
||||
'read_document' => 'read',
|
||||
'read_multiple_documents' => 'read',
|
||||
];
|
||||
|
||||
/**
|
||||
* Resolve the acting user and assert record-level access on the entity.
|
||||
* Used by the delete tools, which key off an entityId rather than a caseId.
|
||||
*/
|
||||
private function assertEntityAccess(Entity $entity, string $action): void
|
||||
{
|
||||
if (!$this->actingUser || !$this->aclManager->checkEntity($this->actingUser, $entity, $action)) {
|
||||
throw new Forbidden('No access to the requested record.');
|
||||
}
|
||||
}
|
||||
|
||||
public const VALID_STATUSES = [
|
||||
@@ -36,6 +78,32 @@ class ActionExecutor
|
||||
{
|
||||
$this->log->debug("SmartAssistant: Executing tool={$tool} for case={$caseId}");
|
||||
|
||||
// Resolve the acting user once; every ACL check below is on their behalf.
|
||||
$this->actingUser = $this->entityManager->getEntityById('User', $userId);
|
||||
|
||||
if (!$this->actingUser) {
|
||||
throw new Forbidden('Invalid user context.');
|
||||
}
|
||||
|
||||
// Central record-level ACL gate for every case-bound tool. Without this,
|
||||
// a generic "Case read" scope check (in the controller) transitively
|
||||
// authorised writing to and reading from ANY case (findings S1/S3).
|
||||
if (isset(self::CASE_TOOL_ACCESS[$tool])) {
|
||||
if (!$caseId) {
|
||||
throw new Error("Tool {$tool} requires a case context.");
|
||||
}
|
||||
|
||||
$case = $this->entityManager->getEntityById('Case', $caseId);
|
||||
|
||||
if (!$case) {
|
||||
throw new NotFound('Case not found.');
|
||||
}
|
||||
|
||||
if (!$this->aclManager->checkEntity($this->actingUser, $case, self::CASE_TOOL_ACCESS[$tool])) {
|
||||
throw new Forbidden('No access to this case.');
|
||||
}
|
||||
}
|
||||
|
||||
return match ($tool) {
|
||||
'create_task' => $this->createTask($params, $caseId, $userId),
|
||||
'add_note' => $this->addNote($params, $caseId, $userId),
|
||||
@@ -91,6 +159,14 @@ class ActionExecutor
|
||||
|
||||
private function saveRule(array $params, string $userId): array
|
||||
{
|
||||
// AssistantRule rows are injected into the system prompt for other users
|
||||
// (case/office/global scope), so creating them is an admin-only operation.
|
||||
// Without this, any user could plant firm-wide instructions (stored
|
||||
// prompt injection — finding S5).
|
||||
if (!$this->actingUser || !$this->actingUser->get('isAdmin')) {
|
||||
throw new Forbidden('Only an administrator can create assistant rules.');
|
||||
}
|
||||
|
||||
$name = $params['name'] ?? '';
|
||||
$rule = $params['rule'] ?? '';
|
||||
if (!$name || !$rule) {
|
||||
@@ -237,6 +313,8 @@ class ActionExecutor
|
||||
}
|
||||
|
||||
$name = $entity->get('name') ?? '';
|
||||
$this->assertEntityAccess($entity, 'delete');
|
||||
|
||||
$this->entityManager->removeEntity($entity);
|
||||
|
||||
return [
|
||||
@@ -260,6 +338,8 @@ class ActionExecutor
|
||||
}
|
||||
|
||||
$name = $entity->get('name') ?? '';
|
||||
$this->assertEntityAccess($entity, 'delete');
|
||||
|
||||
$this->entityManager->removeEntity($entity);
|
||||
|
||||
return [
|
||||
@@ -282,6 +362,8 @@ class ActionExecutor
|
||||
throw new NotFound("Note {$entityId} not found.");
|
||||
}
|
||||
|
||||
$this->assertEntityAccess($entity, 'delete');
|
||||
|
||||
$this->entityManager->removeEntity($entity);
|
||||
|
||||
return [
|
||||
@@ -305,6 +387,8 @@ class ActionExecutor
|
||||
}
|
||||
|
||||
$name = $entity->get('name') ?? '';
|
||||
$this->assertEntityAccess($entity, 'delete');
|
||||
|
||||
$this->entityManager->removeEntity($entity);
|
||||
|
||||
return [
|
||||
@@ -604,6 +688,22 @@ class ActionExecutor
|
||||
throw new Error("Unknown tool: {$tool}");
|
||||
}
|
||||
|
||||
// Plugin tools (e.g. LegalAssistance's report generator) act on a case
|
||||
// when one is supplied. Enforce record-level edit ACL here so a plugin
|
||||
// tool can't be driven against a case the user can't access — this is
|
||||
// the central gate that also closes LegalAssistance finding S1.
|
||||
if ($caseId) {
|
||||
$case = $this->entityManager->getEntityById('Case', $caseId);
|
||||
|
||||
if (!$case) {
|
||||
throw new NotFound('Case not found.');
|
||||
}
|
||||
|
||||
if (!$this->actingUser || !$this->aclManager->checkEntity($this->actingUser, $case, 'edit')) {
|
||||
throw new Forbidden('No access to this case.');
|
||||
}
|
||||
}
|
||||
|
||||
$this->log->debug("SmartAssistant: Executing plugin tool={$tool} handler={$handlerClass}");
|
||||
|
||||
$handler = $this->injectableFactory->create($handlerClass);
|
||||
|
||||
@@ -11,6 +11,7 @@ use Espo\Core\Utils\Log;
|
||||
use Espo\ORM\EntityManager;
|
||||
use Espo\Entities\User;
|
||||
use Espo\Modules\NetworkStorageIntegration\Services\NetworkDocumentService;
|
||||
use Espo\Modules\NetworkStorageIntegration\Classes\LocalFilesystemClient;
|
||||
|
||||
/**
|
||||
* Wraps NetworkDocumentService and constrains every operation to the case's
|
||||
@@ -34,14 +35,32 @@ class CaseFolderManager
|
||||
*/
|
||||
public function writeFile(string $caseId, string $relPath, string $content): array
|
||||
{
|
||||
$absInsideStorage = $this->resolveSafePath($caseId, $relPath, requireExists: false);
|
||||
$client = $this->getNds()->getClient();
|
||||
|
||||
$parent = $this->dirnameRel($absInsideStorage);
|
||||
if ($parent !== '') {
|
||||
$client->createFolderRecursive($parent);
|
||||
// Split the (LLM-provided) relPath into folder + filename. Subfolders
|
||||
// are allowed, but the final filename is sanitized and de-duplicated by
|
||||
// the canonical namer (rule N1) — never trust the model to name files.
|
||||
$normalized = $this->normalize($relPath);
|
||||
if ($normalized === '') {
|
||||
throw new BadRequest('Path is required.');
|
||||
}
|
||||
|
||||
$slash = strrpos($normalized, '/');
|
||||
$dirRel = $slash === false ? '' : substr($normalized, 0, $slash);
|
||||
$baseName = $slash === false ? $normalized : substr($normalized, $slash + 1);
|
||||
|
||||
$ext = pathinfo($baseName, PATHINFO_EXTENSION) ?: 'bin';
|
||||
$subject = pathinfo($baseName, PATHINFO_FILENAME);
|
||||
|
||||
$parentAbs = $dirRel === ''
|
||||
? $this->getCaseRoot($caseId)
|
||||
: $this->resolveSafePath($caseId, $this->sanitizeRelSegments($dirRel), requireExists: false);
|
||||
|
||||
$client->createFolderRecursive($parentAbs);
|
||||
|
||||
$storedName = LocalFilesystemClient::buildStoredFileName($client, $parentAbs, $subject, $ext);
|
||||
$absInsideStorage = $parentAbs . '/' . $storedName;
|
||||
|
||||
$ok = $client->uploadFile($absInsideStorage, $content);
|
||||
if (!$ok) {
|
||||
throw new Error("Failed to write file: {$absInsideStorage}");
|
||||
@@ -61,7 +80,12 @@ class CaseFolderManager
|
||||
*/
|
||||
public function createFolder(string $caseId, string $relPath): array
|
||||
{
|
||||
$abs = $this->resolveSafePath($caseId, $relPath, requireExists: false);
|
||||
$cleanRel = $this->sanitizeRelSegments($this->normalize($relPath));
|
||||
if ($cleanRel === '') {
|
||||
throw new BadRequest('A valid folder name is required.');
|
||||
}
|
||||
|
||||
$abs = $this->resolveSafePath($caseId, $cleanRel, requireExists: false);
|
||||
$client = $this->getNds()->getClient();
|
||||
|
||||
$alreadyExisted = $client->exists($abs);
|
||||
@@ -91,6 +115,12 @@ class CaseFolderManager
|
||||
throw new BadRequest('newName must be a plain file/folder name without slashes.');
|
||||
}
|
||||
|
||||
// Sanitize the model-chosen name (rule N1).
|
||||
$newName = LocalFilesystemClient::sanitizeFileName($newName);
|
||||
if ($newName === '') {
|
||||
throw new BadRequest('newName is empty after sanitization.');
|
||||
}
|
||||
|
||||
$absCurrent = $this->resolveSafePath($caseId, $currentRelPath, requireExists: true);
|
||||
|
||||
$parent = $this->dirnameRel($absCurrent);
|
||||
@@ -124,7 +154,11 @@ class CaseFolderManager
|
||||
public function moveItem(string $caseId, string $sourceRelPath, string $targetRelPath): array
|
||||
{
|
||||
$absSource = $this->resolveSafePath($caseId, $sourceRelPath, requireExists: true);
|
||||
$absTarget = $this->resolveSafePath($caseId, $targetRelPath, requireExists: false);
|
||||
$absTarget = $this->resolveSafePath(
|
||||
$caseId,
|
||||
$this->sanitizeRelSegments($this->normalize($targetRelPath)),
|
||||
requireExists: false
|
||||
);
|
||||
|
||||
$client = $this->getNds()->getClient();
|
||||
|
||||
@@ -297,6 +331,26 @@ class CaseFolderManager
|
||||
return implode('/', $out);
|
||||
}
|
||||
|
||||
/**
|
||||
* Sanitize every segment of an already-normalized storage-relative path
|
||||
* with the canonical file-name rules (rule N1). Empty segments are dropped.
|
||||
*/
|
||||
private function sanitizeRelSegments(string $normalizedPath): string
|
||||
{
|
||||
if ($normalizedPath === '') {
|
||||
return '';
|
||||
}
|
||||
|
||||
$segments = array_map(
|
||||
static fn (string $seg): string => LocalFilesystemClient::sanitizeFileName($seg),
|
||||
explode('/', $normalizedPath)
|
||||
);
|
||||
|
||||
$segments = array_filter($segments, static fn (string $seg): bool => $seg !== '');
|
||||
|
||||
return implode('/', $segments);
|
||||
}
|
||||
|
||||
private function dirnameRel(string $path): string
|
||||
{
|
||||
$pos = strrpos($path, '/');
|
||||
|
||||
@@ -346,6 +346,36 @@ class DocumentAnalyzer
|
||||
* @return array{path: ?string, source: string, error: ?string, caseExists: bool}
|
||||
* source: 'stored' | 'computed' | 'none'
|
||||
*/
|
||||
/**
|
||||
* Containment check: is $filePath inside the given case's storage folder?
|
||||
* Used to stop a user with access to one case from reading another case's
|
||||
* files by passing a raw absolute/relative path (finding S2). Rejects any
|
||||
* path containing '..' and requires a resolvable case folder.
|
||||
*/
|
||||
public function isPathWithinCase(string $filePath, string $caseId): bool
|
||||
{
|
||||
$normalized = str_replace('\\', '/', (string) $filePath);
|
||||
|
||||
if ($normalized === '' || str_contains($normalized, '..')) {
|
||||
return false;
|
||||
}
|
||||
|
||||
$caseFolder = $this->describeCaseFolderPath($caseId)['path'] ?? null;
|
||||
|
||||
if (!$caseFolder) {
|
||||
return false;
|
||||
}
|
||||
|
||||
$needle = ltrim(rtrim(str_replace('\\', '/', $caseFolder), '/'), '/');
|
||||
$candidate = ltrim($normalized, '/');
|
||||
|
||||
if ($needle === '') {
|
||||
return false;
|
||||
}
|
||||
|
||||
return $candidate === $needle || str_starts_with($candidate, $needle . '/');
|
||||
}
|
||||
|
||||
public function describeCaseFolderPath(string $caseId): array
|
||||
{
|
||||
$case = $this->entityManager->getEntityById('Case', $caseId);
|
||||
|
||||
@@ -9,6 +9,7 @@ use Espo\Core\Utils\Log;
|
||||
use Espo\ORM\EntityManager;
|
||||
use Espo\Entities\User;
|
||||
use Espo\Modules\NetworkStorageIntegration\Services\NetworkDocumentService;
|
||||
use Espo\Modules\NetworkStorageIntegration\Classes\LocalFilesystemClient;
|
||||
use PhpOffice\PhpWord\PhpWord;
|
||||
use PhpOffice\PhpWord\IOFactory;
|
||||
|
||||
@@ -50,9 +51,16 @@ class FreeDocumentGenerator
|
||||
|
||||
$docxBinary = $this->buildDocx($title, $body, $recipient);
|
||||
|
||||
$sanitizedTitle = $this->sanitizeFileName($title);
|
||||
$today = date('Y-m-d');
|
||||
$fileName = "{$today} - {$sanitizedTitle}.docx";
|
||||
// Subject-only naming (rule N1): no date prefix. The canonical stored
|
||||
// name (+ "-{NNN}" on collision) is produced by NetworkDocumentService
|
||||
// on upload; we then align the Espo Document/Attachment to it so the
|
||||
// CRM, the attachment and the file on disk never disagree.
|
||||
$baseName = LocalFilesystemClient::sanitizeFileName($title);
|
||||
if ($baseName === '') {
|
||||
$baseName = 'document';
|
||||
}
|
||||
$fileName = $baseName . '.docx';
|
||||
$documentName = $title;
|
||||
|
||||
$attachment = $this->entityManager->getNewEntity('Attachment');
|
||||
$attachment->set([
|
||||
@@ -67,23 +75,71 @@ class FreeDocumentGenerator
|
||||
|
||||
$document = $this->entityManager->getNewEntity('Document');
|
||||
$document->set([
|
||||
'name' => $title,
|
||||
'name' => $documentName,
|
||||
'fileId' => $attachment->getId(),
|
||||
'fileName' => $fileName,
|
||||
'assignedUserId' => $this->user->getId(),
|
||||
]);
|
||||
$this->entityManager->saveEntity($document);
|
||||
// Suppress the NSI upload hook: it fires on this save, before the Case
|
||||
// link below exists, so it would file the document in the fallback
|
||||
// folder. We upload explicitly (with the Case) right after.
|
||||
$this->entityManager->saveEntity($document, ['skipNetworkUpload' => true]);
|
||||
|
||||
$this->entityManager->getRDBRepository('Case')
|
||||
->getRelation($case, 'documents')
|
||||
->relate($document);
|
||||
|
||||
// CaseFiles backend: place the Document in the case "מסמכים" folder.
|
||||
$caseFilesServiceClass = 'Espo\\Modules\\CaseFilesCore\\Services\\CaseFolderService';
|
||||
if (class_exists($caseFilesServiceClass)) {
|
||||
try {
|
||||
$cfFolder = $this->injectableFactory->create($caseFilesServiceClass)
|
||||
->getOrCreateSubfolder('Case', $caseId, 'מסמכים');
|
||||
$document->set('folderId', $cfFolder->getId());
|
||||
$this->entityManager->saveEntity($document, ['skipNetworkUpload' => true, 'silent' => true]);
|
||||
} catch (\Throwable $e) {
|
||||
$this->log->warning('FreeDocumentGenerator: CaseFiles folder placement failed: ' . $e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
$networkPath = null;
|
||||
try {
|
||||
$nds = $this->injectableFactory->create(NetworkDocumentService::class);
|
||||
if ($nds->isEnabled()) {
|
||||
$result = $nds->uploadDocument($document, $attachment, 'Case', $caseId);
|
||||
$networkPath = $result['path'] ?? null;
|
||||
|
||||
if (!empty($result['success'])) {
|
||||
$networkPath = $result['path'] ?? null;
|
||||
$storedName = $result['fileName'] ?? $fileName;
|
||||
$storedBase = pathinfo($storedName, PATHINFO_FILENAME) ?: $documentName;
|
||||
|
||||
// Align DB names to the canonical stored name.
|
||||
$document->set([
|
||||
'name' => $storedBase,
|
||||
'fileName' => $storedName,
|
||||
'storageType' => 'network',
|
||||
'networkStoragePath' => $networkPath,
|
||||
'networkStorageFileName' => $storedName,
|
||||
'networkStorageSize' => $result['size'] ?? strlen($docxBinary),
|
||||
'networkStorageModifiedAt' => date('Y-m-d H:i:s'),
|
||||
]);
|
||||
$this->entityManager->saveEntity($document, [
|
||||
'skipNetworkUpload' => true,
|
||||
'silent' => true,
|
||||
]);
|
||||
|
||||
$attachment->set('name', $storedName);
|
||||
$this->entityManager->saveEntity($attachment, ['silent' => true]);
|
||||
|
||||
// The file now lives in network storage; drop the local copy.
|
||||
$sourcePath = 'data/upload/' . $attachment->getSourceId();
|
||||
if (file_exists($sourcePath)) {
|
||||
@unlink($sourcePath);
|
||||
}
|
||||
|
||||
$fileName = $storedName;
|
||||
$documentName = $storedBase;
|
||||
}
|
||||
}
|
||||
} catch (\Throwable $e) {
|
||||
// Document is safely persisted in Espo; the network-storage copy is best-effort.
|
||||
@@ -94,10 +150,10 @@ class FreeDocumentGenerator
|
||||
}
|
||||
|
||||
$this->log->info(
|
||||
"FreeDocumentGenerator: Created '{$title}' (type={$documentType}) for Case {$caseId}"
|
||||
"FreeDocumentGenerator: Created '{$documentName}' (type={$documentType}) for Case {$caseId}"
|
||||
);
|
||||
|
||||
$message = "✅ המסמך \"{$title}\" נוצר בהצלחה וצורף לתיק";
|
||||
$message = "✅ המסמך \"{$documentName}\" נוצר בהצלחה וצורף לתיק";
|
||||
if ($networkPath) {
|
||||
$message .= " ולתיקיית הרשת";
|
||||
}
|
||||
@@ -106,7 +162,7 @@ class FreeDocumentGenerator
|
||||
return [
|
||||
'success' => true,
|
||||
'documentId' => $document->getId(),
|
||||
'documentName' => $title,
|
||||
'documentName' => $documentName,
|
||||
'fileName' => $fileName,
|
||||
'networkPath' => $networkPath,
|
||||
'message' => $message,
|
||||
@@ -265,11 +321,4 @@ class FreeDocumentGenerator
|
||||
$year = $dt->format('Y');
|
||||
return "{$day} ב{$month} {$year}";
|
||||
}
|
||||
|
||||
private function sanitizeFileName(string $name): string
|
||||
{
|
||||
$name = preg_replace('/[\\/:*?"<>|]/', '', $name);
|
||||
$name = preg_replace('/\s+/', ' ', $name);
|
||||
return trim(mb_substr($name, 0, 100));
|
||||
}
|
||||
}
|
||||
|
||||
@@ -10,6 +10,7 @@ use Espo\ORM\EntityManager;
|
||||
use Espo\Entities\User;
|
||||
use Espo\Modules\NetworkStorageIntegration\Services\DocumentTemplateService;
|
||||
use Espo\Modules\NetworkStorageIntegration\Services\NetworkDocumentService;
|
||||
use Espo\Modules\NetworkStorageIntegration\Classes\LocalFilesystemClient;
|
||||
use PhpOffice\PhpWord\TemplateProcessor;
|
||||
|
||||
class GenericTemplateGenerator
|
||||
@@ -72,14 +73,23 @@ class GenericTemplateGenerator
|
||||
@unlink($outputPath);
|
||||
@unlink($localTemplatePath);
|
||||
|
||||
// Step 6: Build document name
|
||||
$contactName = $this->getContactName($case);
|
||||
$docName = $documentSubject ?? "{$templateName} — {$contactName}";
|
||||
// Step 6: Build subject-only document name (rule N1) — no contact,
|
||||
// no em-dash. Defaults to the template name when no subject given.
|
||||
$subject = trim((string) ($documentSubject ?? ''));
|
||||
if ($subject === '') {
|
||||
$subject = (string) $templateName;
|
||||
}
|
||||
$docName = $subject;
|
||||
$baseName = LocalFilesystemClient::sanitizeFileName($subject);
|
||||
if ($baseName === '') {
|
||||
$baseName = 'document';
|
||||
}
|
||||
$fileName = $baseName . '.docx';
|
||||
|
||||
// Step 7: Create Attachment + Document
|
||||
$attachment = $this->entityManager->getNewEntity('Attachment');
|
||||
$attachment->set([
|
||||
'name' => $docName . '.docx',
|
||||
'name' => $fileName,
|
||||
'type' => 'application/vnd.openxmlformats-officedocument.wordprocessingml.document',
|
||||
'role' => 'Attachment',
|
||||
'size' => strlen($content),
|
||||
@@ -92,16 +102,74 @@ class GenericTemplateGenerator
|
||||
$document->set([
|
||||
'name' => $docName,
|
||||
'fileId' => $attachment->getId(),
|
||||
'fileName' => $docName . '.docx',
|
||||
'fileName' => $fileName,
|
||||
'assignedUserId' => $this->user->getId(),
|
||||
]);
|
||||
$this->entityManager->saveEntity($document);
|
||||
// Suppress the NSI upload hook (fires before the Case link below);
|
||||
// we upload explicitly with the Case so it lands in the case folder.
|
||||
$this->entityManager->saveEntity($document, ['skipNetworkUpload' => true]);
|
||||
|
||||
// Link to Case
|
||||
$this->entityManager->getRDBRepository('Case')
|
||||
->getRelation($case, 'documents')
|
||||
->relate($document);
|
||||
|
||||
// CaseFiles backend: place the Document in the case "מסמכים" folder.
|
||||
$caseFilesServiceClass = 'Espo\\Modules\\CaseFilesCore\\Services\\CaseFolderService';
|
||||
if (class_exists($caseFilesServiceClass)) {
|
||||
try {
|
||||
$cfFolder = $this->injectableFactory->create($caseFilesServiceClass)
|
||||
->getOrCreateSubfolder('Case', $caseId, 'מסמכים');
|
||||
$document->set('folderId', $cfFolder->getId());
|
||||
$this->entityManager->saveEntity($document, ['skipNetworkUpload' => true, 'silent' => true]);
|
||||
} catch (\Throwable $e) {
|
||||
$this->log->warning('GenericTemplateGenerator: CaseFiles folder placement failed: ' . $e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
// Upload to the case folder; align DB names to the canonical stored name.
|
||||
try {
|
||||
$nds = $this->injectableFactory->create(NetworkDocumentService::class);
|
||||
if ($nds->isEnabled()) {
|
||||
$result = $nds->uploadDocument($document, $attachment, 'Case', $caseId);
|
||||
|
||||
if (!empty($result['success'])) {
|
||||
$storedName = $result['fileName'] ?? $fileName;
|
||||
$storedBase = pathinfo($storedName, PATHINFO_FILENAME) ?: $docName;
|
||||
|
||||
$document->set([
|
||||
'name' => $storedBase,
|
||||
'fileName' => $storedName,
|
||||
'storageType' => 'network',
|
||||
'networkStoragePath' => $result['path'] ?? null,
|
||||
'networkStorageFileName' => $storedName,
|
||||
'networkStorageSize' => $result['size'] ?? strlen($content),
|
||||
'networkStorageModifiedAt' => date('Y-m-d H:i:s'),
|
||||
]);
|
||||
$this->entityManager->saveEntity($document, [
|
||||
'skipNetworkUpload' => true,
|
||||
'silent' => true,
|
||||
]);
|
||||
|
||||
$attachment->set('name', $storedName);
|
||||
$this->entityManager->saveEntity($attachment, ['silent' => true]);
|
||||
|
||||
$sourcePath = 'data/upload/' . $attachment->getSourceId();
|
||||
if (file_exists($sourcePath)) {
|
||||
@unlink($sourcePath);
|
||||
}
|
||||
|
||||
$docName = $storedBase;
|
||||
}
|
||||
}
|
||||
} catch (\Throwable $e) {
|
||||
// Document is safely persisted in Espo; the network copy is best-effort.
|
||||
$this->log->warning(
|
||||
"GenericTemplateGenerator: failed to copy to network storage for Case {$caseId}: " .
|
||||
$e->getMessage()
|
||||
);
|
||||
}
|
||||
|
||||
$this->log->info("GenericTemplateGenerator: Created '{$docName}' from template '{$templateName}' for Case {$caseId}");
|
||||
|
||||
return [
|
||||
@@ -190,24 +258,4 @@ class GenericTemplateGenerator
|
||||
|
||||
$processor->saveAs($outputPath);
|
||||
}
|
||||
|
||||
private function getContactName($case): string
|
||||
{
|
||||
$contactId = $case->get('contactId');
|
||||
if (!$contactId) {
|
||||
$ids = $case->getLinkMultipleIdList('contacts');
|
||||
if (!empty($ids)) {
|
||||
$contactId = $ids[0];
|
||||
}
|
||||
}
|
||||
|
||||
if ($contactId) {
|
||||
$contact = $this->entityManager->getEntityById('Contact', $contactId);
|
||||
if ($contact) {
|
||||
return trim($contact->get('firstName') . ' ' . $contact->get('lastName'));
|
||||
}
|
||||
}
|
||||
|
||||
return $case->get('name') ?? '';
|
||||
}
|
||||
}
|
||||
|
||||
@@ -5,6 +5,7 @@ namespace Espo\Modules\SmartAssistant\Services;
|
||||
use Espo\Core\Exceptions\Error;
|
||||
use Espo\Core\Exceptions\NotFound;
|
||||
use Espo\Core\InjectableFactory;
|
||||
use Espo\Core\AclManager;
|
||||
use Espo\Core\Utils\Config;
|
||||
use Espo\Core\Utils\Log;
|
||||
use Espo\ORM\EntityManager;
|
||||
@@ -35,21 +36,22 @@ class SmartAssistantService
|
||||
private Config $config;
|
||||
private Log $log;
|
||||
private User $user;
|
||||
|
||||
private static array $conversations = [];
|
||||
private AclManager $aclManager;
|
||||
|
||||
public function __construct(
|
||||
EntityManager $entityManager,
|
||||
InjectableFactory $injectableFactory,
|
||||
Config $config,
|
||||
Log $log,
|
||||
User $user
|
||||
User $user,
|
||||
AclManager $aclManager
|
||||
) {
|
||||
$this->entityManager = $entityManager;
|
||||
$this->injectableFactory = $injectableFactory;
|
||||
$this->config = $config;
|
||||
$this->log = $log;
|
||||
$this->user = $user;
|
||||
$this->aclManager = $aclManager;
|
||||
}
|
||||
|
||||
private function getConversationRepo(): ConversationRepository
|
||||
@@ -486,6 +488,13 @@ class SmartAssistantService
|
||||
|
||||
foreach ($cases as $case) {
|
||||
if (mb_stripos($message, $case->get('name')) !== false) {
|
||||
// Record-level ACL: only drill into a case the user may read.
|
||||
// Without this, naming any case in office-mode chat would surface
|
||||
// its data regardless of access (finding S6).
|
||||
if (!$this->aclManager->checkEntity($this->user, $case, 'read')) {
|
||||
continue;
|
||||
}
|
||||
|
||||
$contextBuilder = $this->injectableFactory->create(OfficeContextBuilder::class);
|
||||
return $contextBuilder->buildCaseDrillDown($case->get('id'), $this->user);
|
||||
}
|
||||
|
||||
+2
-2
@@ -3,11 +3,11 @@
|
||||
"module": "SmartAssistant",
|
||||
"description": "Unified AI Assistant for Legal CRM — floating chat with case memory, office alerts, and AI Gateway integration",
|
||||
"author": "klear",
|
||||
"version": "2.10.0",
|
||||
"version": "2.11.0",
|
||||
"acceptableVersions": [
|
||||
">=8.0.0"
|
||||
],
|
||||
"releaseDate": "2026-05-27",
|
||||
"releaseDate": "2026-06-21",
|
||||
"php": [
|
||||
">=8.1"
|
||||
]
|
||||
|
||||
+20
-24
@@ -1,16 +1,19 @@
|
||||
<?php
|
||||
|
||||
namespace Espo\Modules\SmartAssistant\Scripts;
|
||||
/**
|
||||
* AfterInstall script for SmartAssistant extension 2.10.x.
|
||||
*
|
||||
* Idempotently seeds the AssistantPrompt entity with 7 default prompt
|
||||
* sections (tool_rules, writing_style, legal_assistance, personality_case,
|
||||
* personality_office, other_rules_case, other_rules_office). If a row with
|
||||
* the same `key` already exists it is left alone — admin edits win.
|
||||
*
|
||||
* Class must be named `AfterInstall` with NO namespace — that's what the
|
||||
* EspoCRM extension installer looks for in scripts/AfterInstall.php.
|
||||
* See application/Espo/Core/Upgrades/ExtensionManager.php scriptNames map.
|
||||
*/
|
||||
|
||||
use Espo\Core\Container;
|
||||
|
||||
/**
|
||||
* Runs after the extension is installed/upgraded.
|
||||
*
|
||||
* Idempotent: only inserts AssistantPrompt rows whose `key` doesn't exist yet.
|
||||
* If the row exists (even with edits), we leave it alone — the user's
|
||||
* customizations win.
|
||||
*/
|
||||
class AfterInstall
|
||||
{
|
||||
public function run(Container $container, $params = null): void
|
||||
@@ -18,21 +21,11 @@ class AfterInstall
|
||||
$entityManager = $container->get('entityManager');
|
||||
$log = $container->get('log');
|
||||
|
||||
$resourceFile = __DIR__ . '/../files/custom/Espo/Modules/SmartAssistant/Resources/data/default-prompts.json';
|
||||
// The JSON file lives inside the installed module resources at runtime.
|
||||
$resourceFile = 'custom/Espo/Modules/SmartAssistant/Resources/data/default-prompts.json';
|
||||
|
||||
if (!is_file($resourceFile)) {
|
||||
// Fall back to the module Resources path when the extension is
|
||||
// installed (Resources/ is the canonical location at runtime).
|
||||
$resourceFile = dirname(__DIR__) . '/files/custom/Espo/Modules/SmartAssistant/Resources/data/default-prompts.json';
|
||||
}
|
||||
|
||||
if (!is_file($resourceFile)) {
|
||||
// Final fallback: the module's installed Resources path.
|
||||
$resourceFile = 'custom/Espo/Modules/SmartAssistant/Resources/data/default-prompts.json';
|
||||
}
|
||||
|
||||
if (!is_file($resourceFile)) {
|
||||
$log->warning("[SmartAssistant] AfterInstall: default-prompts.json not found, skipping seed");
|
||||
$log->warning("[SmartAssistant] AfterInstall: $resourceFile not found, skipping seed");
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -40,7 +33,7 @@ class AfterInstall
|
||||
$defaults = json_decode($json, true);
|
||||
|
||||
if (!is_array($defaults)) {
|
||||
$log->warning("[SmartAssistant] AfterInstall: default-prompts.json invalid JSON");
|
||||
$log->warning("[SmartAssistant] AfterInstall: invalid JSON in $resourceFile");
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -72,7 +65,10 @@ class AfterInstall
|
||||
'content' => $row['content'] ?? '',
|
||||
'isActive' => true,
|
||||
]);
|
||||
$entityManager->saveEntity($entity);
|
||||
// skipAll bypasses beforeSave hooks that require a logged-in user
|
||||
// service (installer runs without an HTTP session) and ACL checks
|
||||
// (we're seeding firm-wide defaults; no user is implicated).
|
||||
$entityManager->saveEntity($entity, ['skipAll' => true]);
|
||||
$created++;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user