feat: add local auth billing and usage management
This commit is contained in:
1 parent
f642b5e71f
commit
196fdde83f
119 files changed
+15695
-2650
No files matched your search
+220
-3
@@ -1,10 +1,10 @@
|
||||
# Task Plan: EvoLink Image Engine Settings
|
||||
# Task Plan: Platform-Owned Account System
|
||||
|
||||
## Goal
|
||||
Add EvoLink GPT Image 2 as a selectable image creation engine in the settings flow, while preserving the existing Jimeng/Volcengine image engine and the current task/asset workflow.
|
||||
Replace the external OAuth2 account dependency with a platform-owned phone/password account system using three roles: super administrator, organization administrator, and ordinary user. Preserve legacy account identity and business history through an import/mapping path while enforcing one account per organization.
|
||||
|
||||
## Current Phase
|
||||
Phase 39 - Task Module Width and Preview Polish complete
|
||||
Phase 67 - Unified Default Billing Multiplier complete
|
||||
|
||||
## Phases
|
||||
|
||||
@@ -366,6 +366,11 @@ Phase 39 - Task Module Width and Preview Polish complete
|
||||
| Running `npm run build` while the dev server was active caused the dev server to miss `.next/server/vendor-chunks/next.js` for the new dynamic template route | 1 | Restarted the dev server, confirmed it rebuilt the route, deleted the temporary verification template, then restarted the server under the normal auth-enabled environment |
|
||||
| Updated `hotelStaff` member-list proxy returned `仅管理员角色允许调用` for the current token | 1 | Classified the upstream permission denial and degraded only the member list to a warning/empty page instead of failing the whole accounts screen |
|
||||
| New account login returned 200 from `/api/auth/password` but was redirected back to `/auth/login?next=/create` | 1 | Added chunked session cookies so larger JWT/authority payloads are preserved across the browser redirect |
|
||||
| Initial Phase 51 planning append did not match the stale task-plan/progress headings | 1 | Read the actual file tails and applied smaller header/append patches against current content |
|
||||
| Existing auth regression tests still asserted external OAuth password grants | 1 | Replaced them with platform phone/password, unified-role, and lockout assertions |
|
||||
| First TypeScript check rejected a test-only import of a non-exported local type | 1 | Imported `PlatformUserRecord` from the shared types module |
|
||||
| A combined zsh HTTP smoke command had a quoting parse error | 1 | Re-ran the smoke checks as small, isolated curl commands |
|
||||
| The old dev process served a corrupted `.next` chunk after the production build | 1 | Stopped the stale process, rebuilt, restarted dev on `127.0.0.1:3000`, and verified health/login pages |
|
||||
|
||||
## Notes
|
||||
- EvoLink docs: submit `POST /v1/images/generations`, query `GET /v1/tasks/{task_id}`, completed task exposes `results[]`.
|
||||
@@ -384,3 +389,215 @@ Phase 39 - Task Module Width and Preview Polish complete
|
||||
- Latest local startup verification used `npm run dev -- --hostname 127.0.0.1 --port 3003`; the server reached Ready and `/` returned a login redirect.
|
||||
- Current status check on 2026-06-09: no `next dev` / `next-server` process is listening on `3003`, so the dev server is not currently running.
|
||||
- Image templates are now account-scoped records exposed through `/api/image-templates`; the image creation page shows and manages them inside the image module.
|
||||
|
||||
### Phase 51: Platform-Owned Account System
|
||||
- [x] Establish platform user, organization, role, account-status, archive, and migration data models
|
||||
- [x] Replace external OAuth2 password/authorization-code login with local phone/password authentication and signed sessions
|
||||
- [x] Implement super-admin, organization-admin, and ordinary-user permission boundaries
|
||||
- [x] Add organization-scoped account management, password changes/resets, disable/delete/archive behavior, and bootstrap super-admin initialization
|
||||
- [x] Add legacy account/owner mapping import path keyed by old phone/account identity
|
||||
- [x] Add brute-force protection, focused tests, migration documentation, and runtime verification
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 52: Enterprise Billing and Organization Wallet
|
||||
- [x] Confirm billing unit, pricing precision, and insufficient-balance behavior
|
||||
- [x] Trace current generation submission, usage event, role boundaries, persistence, and UI entry points
|
||||
- [x] Design and implement provider cost catalog, markup snapshots, organization wallet, recharge requests, and immutable ledger
|
||||
- [x] Integrate atomic pre-charge/refund/settlement behavior into image and video generation, retry, cancellation, deletion, and public API paths
|
||||
- [x] Add super-admin billing management, organization wallet/recharge management, and user/organization usage views
|
||||
- [x] Add migration/backward compatibility for existing usage records and local/Supabase stores
|
||||
- [x] Verify focused tests, full tests, production build, and authenticated route flows
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 53: Provider Pricing Catalog and Variant Matching
|
||||
- [x] Add official-source base pricing for the connected Bailian, EvoLink, Jimeng, and Seedance routes
|
||||
- [x] Add source metadata, fixed FX conversion, model keys, and resolution variants to price rules and billing snapshots
|
||||
- [x] Seed defaults without overwriting existing administrator rules and expose base/user prices in `/billing`
|
||||
- [x] Extend local/Supabase persistence and migration indexes for price variants and source metadata
|
||||
- [x] Verify focused tests, full tests, TypeScript, production build, and diff hygiene
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 54: Billing Center Taste Redesign
|
||||
- [x] Audit the current billing page hierarchy across super-admin and member actions
|
||||
- [x] Rebuild the billing center around balance-first organization context and compact finance lists
|
||||
- [x] Separate member recharge actions from super-admin pricing, account, wallet, and review controls
|
||||
- [x] Add responsive, accessible, loading, focus, and reduced-motion states
|
||||
- [x] Verify desktop/mobile visual smoke, TypeScript, full tests, production build, and diff hygiene
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 55: Tabbed Billing Operations
|
||||
- [x] Replace the long billing stack with role-specific keyboard-accessible task tabs
|
||||
- [x] Add super-admin inline corporate account configuration from the billing center
|
||||
- [x] Add organization wallet manual credit/debit adjustments with immutable ledger attribution
|
||||
- [x] Expose organization members and per-user net consumption for quick ledger attribution
|
||||
- [x] Verify responsive tab behavior, API payloads, tests, TypeScript, production build, and diff hygiene
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 56: Billing Error Recovery
|
||||
- [x] Trace the reported `Internal Server Error` against local page/API responses and runtime logs
|
||||
- [x] Make missing Supabase billing schema errors actionable instead of returning an opaque server failure
|
||||
- [x] Safely handle non-JSON 500 responses in billing actions and add a billing route error boundary
|
||||
- [x] Verify the recovery changes with TypeScript, tests, production build, and browser smoke
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 57: Super-Admin Billing Blank State
|
||||
- [x] Reproduce the blank super-admin billing page with an unbound super-admin account
|
||||
- [x] Render a platform-wide billing overview from the super-admin payload without requiring personal organization membership
|
||||
- [x] Verify all super-admin tabs render in a production build
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 58: Parameterized Billing Rules
|
||||
- [x] Extend billing rules with structured request conditions and quantity sources while preserving legacy `variantKey` rules
|
||||
- [x] Normalize image/video request parameters and deterministically select the most specific matching rule
|
||||
- [x] Add a server-side quote endpoint and use the same matcher during task submission
|
||||
- [x] Upgrade the super-admin price editor to configure parameter conditions and show match scope
|
||||
- [x] Snapshot normalized parameters, matched rule, quantity, and final amount in billing quotes/ledger metadata
|
||||
- [x] Verify focused pricing tests, full tests, TypeScript, production build, and browser smoke
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 59: Task Detail Modal and Result Directory Consolidation
|
||||
- [x] Confirm that only the visible `/assets` result page/navigation is removed; physical result storage remains intact
|
||||
- [x] Replace the task-module result-page link with an in-place task detail modal
|
||||
- [x] Show prompt, input elements/materials, generation parameters, task metadata, status/error, and available outputs in the modal
|
||||
- [x] Add a direct download action to each completed task card without requiring the result page
|
||||
- [x] Preserve result storage and download APIs while keeping `/assets` as a compatibility redirect to `/create`
|
||||
- [x] Verify the desktop layout, full tests, TypeScript, production build, and browser behavior
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 60: Direct Billing Top-ups
|
||||
- [x] Trace all recharge-request and review dependencies
|
||||
- [x] Remove the user-submitted recharge/review workflow and pending-review UI
|
||||
- [x] Keep administrator balance adjustments as the current direct top-up path
|
||||
- [x] Make the billing payload and documentation describe direct posting and future automatic posting
|
||||
- [x] Verify type checks, tests, production build, and local billing routes
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 61: Simplified Billing Price Controls
|
||||
- [x] Inspect the current price catalog editor and admin price API
|
||||
- [x] Replace multi-field rule creation/editing with read-only standards and multiplier-only updates
|
||||
- [x] Prevent super-admin price APIs from changing provider costs, parameters, or rule structure
|
||||
- [x] Verify the compact billing UI, type checks, tests, production build, and local server
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 63: Parameterized Billing Catalog
|
||||
- [x] Define platform-owned parameter dimensions and factor-based quote semantics
|
||||
- [x] Extend billing catalog/storage/API to expose parameter tiers with standard costs and editable multipliers
|
||||
- [x] Seed provider/model parameter tiers from the existing catalog and documented provider options
|
||||
- [x] Replace the flat price list with grouped service and parameter-tier controls
|
||||
- [x] Verify quote matching, admin multiplier updates, type checks, tests, production build, and browser behavior
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 64: Inline Generation Cost Estimate
|
||||
- [x] Move the generation cost preview beside the live parameter controls
|
||||
- [x] Reuse the server quote path and expose loading, unavailable, quantity, multiplier, and matched-tier states
|
||||
- [x] Align the parameter bar and estimate card with a container-aware desktop layout and safe narrow-width stacking
|
||||
- [x] Verify quote changes, video duration estimates, type checks, tests, production build, and document overflow
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 65: Billing UI Alignment and Native Multiplier Dialog
|
||||
- [x] Align price-source actions and notes on a shared baseline without adding maintenance fields
|
||||
- [x] Tighten the generation estimate card title and parameter-row composition at desktop width
|
||||
- [x] Replace browser prompt editing with an accessible in-app multiplier dialog, validation, preview, and Escape dismissal
|
||||
- [x] Verify desktop browser behavior, quote refresh, type checks, tests, production build, and local-server health
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 66: Fixed EvoLink 1K Quote and User-Facing Estimate
|
||||
- [x] Fix the hidden EvoLink resolution to the platform-approved 1K request and billing baseline
|
||||
- [x] Keep visible quality pricing consistent: standard ¥0.51/image and high-quality ¥2.04/image at the configured multiplier
|
||||
- [x] Reduce the ordinary-user estimate card to the final amount only, removing internal multiplier, tier, quantity, and helper copy
|
||||
- [x] Verify the live standard/high quote, stale-copy removal, type checks, tests, and diff hygiene
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 67: Unified Default Billing Multiplier
|
||||
- [x] Change the platform default markup multiplier from 1.50× to 1.20× across all built-in services and parameter tiers
|
||||
- [x] Synchronize the local initialized billing catalog so existing default rules charge at 1.20×
|
||||
- [x] Update built-in quote expectations and billing documentation
|
||||
- [x] Verify image/video quote amounts, type checks, tests, production build, and server health
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 68: Cross-Provider Pricing Audit
|
||||
- [x] Compare every active provider's standard cost and billing unit with its current official pricing source
|
||||
- [x] Verify parameter-dependent cost dimensions, quantity extraction, and one-time platform markup application
|
||||
- [x] Record confirmed matches, approximation boundaries, and any provider pricing gaps before proposing changes
|
||||
- [x] Present the audit result and obtain confirmation before making material pricing-model changes
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 69: Seedance Native Usage Settlement
|
||||
- [x] Add official Seedance token-price dimensions for resolution and input-video presence
|
||||
- [x] Freeze a conservative estimate at submission, including the maximum input-video duration when metadata is absent
|
||||
- [x] Extract `usage.completion_tokens` from provider responses and settle the final amount exactly once
|
||||
- [x] Refund or charge only the difference; preserve the frozen amount when upstream usage is absent
|
||||
- [x] Verify idempotency, persistence compatibility, docs, type checks, tests, and production build
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 70: Unbound Account Quote Preview
|
||||
- [x] Trace the empty estimate state for the current super-admin session
|
||||
- [x] Allow quote-only requests without an organization while keeping real submission organization-gated
|
||||
- [x] Add regression coverage for the preview/charge boundary
|
||||
- [x] Verify the exact Image2 / 9:16 / high-quality quote in the browser and run full checks
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 61: Account Directory and Password Settings Consolidation
|
||||
- [x] Audit the current account directory, settings password flow, account APIs, roles, and existing visual tokens
|
||||
- [x] Move password change into the account directory while preserving the password API contract and admin API permissions
|
||||
- [x] Redesign the account directory with a modern, restrained desktop-first layout using the taste-skill audit principles
|
||||
- [x] Preserve account management actions, loading/error/empty states, keyboard access, and existing API contracts
|
||||
- [x] Verify desktop browser behavior, settings separation, type checks, tests, production build, and diff hygiene
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 62: Account Workspace Information Architecture Correction
|
||||
- [x] Remove duplicate identity surfaces and consolidate current-user information into one header summary
|
||||
- [x] Replace scattered account/profile/admin cards with one continuous account workspace
|
||||
- [x] Keep the ordered flow of security, administrator operations, and member directory without changing API behavior
|
||||
- [x] Verify the desktop screenshot, identity duplication, document width, type checks, production build, and diff hygiene
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 70: Organization-Only Billing Top-ups
|
||||
- [x] Remove personal attribution from administrator recharge and balance-adjustment inputs
|
||||
- [x] Keep generation charge/refund actor attribution for member consumption reporting, while making all new organization balance entries organization-owned
|
||||
- [x] Remove member selection and “归属上账” actions from the billing center
|
||||
- [x] Update billing tests and documentation to state the shared organization quota model
|
||||
- [x] Verify focused/full tests, TypeScript, production build, and diff hygiene
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 71: Frontend Encoding Diagnosis
|
||||
- [x] Check source-file encoding and response charset
|
||||
- [x] Check rendered text in the login page and billing page with headless browser automation
|
||||
- [ ] Reproduce the user's exact garbled page/browser state and apply a targeted fix
|
||||
- **Status:** awaiting reproduction details
|
||||
|
||||
### Phase 72: Autofilled Login Submission
|
||||
- [x] Trace the login button disabled condition and browser autofill interaction
|
||||
- [x] Read phone/password from native form controls at submit time
|
||||
- [x] Keep required-field and server-side validation in place
|
||||
- [x] Verify focused/full tests, TypeScript, production build, and browser click behavior
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 73: Next Development Cache Recovery
|
||||
- [x] Confirm the missing `9971.js` module is absent from the active `.next` cache
|
||||
- [x] Stop duplicate Next development servers for this workspace
|
||||
- [x] Move the corrupted cache to a recoverable backup and start one clean dev server
|
||||
- [x] Verify the login page, login request path, and core page compilation
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 74: Dev/Production Cache Isolation
|
||||
- [x] Separate Next development output into `.next-dev` while retaining `.next` for production builds
|
||||
- [x] Move the partially generated `.next-dev` cache to a recoverable backup before restarting
|
||||
- [x] Start one clean development server and verify login rendering, health, and protected-route behavior
|
||||
- [x] Run TypeScript and diff checks after the configuration change
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 75: Local Super-Admin Credential Recovery
|
||||
- [x] Confirm the requested account is the local super administrator
|
||||
- [x] Replace the unreadable password hash with a generated strong password through the admin password API
|
||||
- [x] Save the credential in the project browser vault without writing the password into source or tracking files
|
||||
- [x] Verify the saved credential can log in and reaches the protected creation workspace
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 76: Quota Guard and Super-Admin Billing Exemption
|
||||
- [x] Thread the super-admin role through the generation usage context and billing snapshot
|
||||
- [x] Reject ordinary generation submissions before provider dispatch when the organization balance is insufficient
|
||||
- [x] Let super-admins calculate and record generation cost without checking, freezing, or refunding organization quota
|
||||
- [x] Add regression coverage for insufficient balance, unbound super-admin submission, and Seedance settlement without a wallet ledger
|
||||
- [x] Verify focused/full tests, TypeScript, production build, and diff hygiene
|
||||
- **Status:** complete
|
||||
Reference in new issue
Block a user