Critical:
- Remove orphaned delegate_form_fill ToolOutput from OrchestratorAgent;
the method didn't exist and OrchestratorAgent(runtime) crashed at boot.
Also drop unused DocumentExtractorAgent import and KnowledgeUpdateResponse
from the OrchestratorResponse union. Form fill stays on its own endpoints
(POST /api/v1/form/ai/*) and is not wired as an orchestrator delegate.
Medium:
- Thread conversation_history through the three form-fill agents.
Contracts: FormAnalysisRequest, FormFillBatchRequest, and
DocumentExtractionRequest now carry conversation_history. Agents call
format_conversation_history() when building prompts, matching the
pattern from PdfQuestionAgent / PdfEditAgent.
- Add input bounds to form-fill contracts (max_length on strings,
min_length/max_length on lists and dicts). Caps: 50 files, 500 fields
per file, 20 documents per request, 500 knowledge entries, 50k chars
per document text, 8k chars per page text. Stops unbounded prompt growth.
- Replace Literal["fill_result"] / Literal["knowledge_update"] etc. with
WorkflowOutcome enum values. Adds KNOWLEDGE_UPDATE, MULTI_PROFILE_EXTRACTION,
and BATCH_FILL_RESULT to both WorkflowOutcome (Python) and
AiWorkflowOutcome (Java) to keep the "must stay in sync" contract honest.
Low:
- Drop duplicate build_test_settings() helper in test_form_fill_agent.py;
use conftest.build_app_settings() like the rest of the suite.
- Add test coverage for extract_multiple -> MultiProfileExtractionResponse
(the two-person detection path).
- ARCHITECTURE.md: clarify where state actually lives
(localStorage keys on the frontend, no user-scoping) and note that form
fill is not an orchestrator delegate.
128 engine tests pass. Lifespan boots cleanly with all four agents.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>