docs: integrate static frontend architecture

This commit is contained in:
brother7 committed 2026-08-16 21:02:42 +08:00
1 parent b14b4fced7
commit bb50d06d1d
13 files changed
+243 -82

No files matched your search

+5 -2
View File
@@ -9,9 +9,12 @@
- Super administrators calculate and record generation cost without checking, freezing, or refunding organization quota.
- All new organization balance entries are organization-owned; generation charge/refund entries keep member attribution for consumption reporting.
- Logged-in users may change their own password; account management and organization member actions require admin roles.
- Public `/api/v1` access authenticates with API keys and stays outside browser SSO middleware; API data is partitioned by the API account owner.
- Public `/api/v1` access authenticates with API keys rather than the browser
session Cookie; API data is partitioned by the API account owner.
- Database schema changes stay versioned and checksummed in `database/migrations/`; the initial production schema is created by manually executing the SQL files plus application-role grants (no migration Job pod), and schema changes must never run inside long-lived pod startup.
- Generated and uploaded assets remain runtime/object-storage state; PostgreSQL does not make them shared for horizontal scaling.
- Client-side route guards are navigation/UI behavior only; Go authorizes every
protected API and file request.
## Open Questions
@@ -19,4 +22,4 @@
## Last Reviewed
2026-08-14
2026-08-16
+4 -3
View File
@@ -9,8 +9,9 @@
| Ledger | Append-only record of wallet movements (charge, refund, settlement, adjustment). | Replayable for reconciliation. |
| Quote | Server-side estimate for a generation request using the matched billing rule and parameter tiers. | Preview is quote-only; submission is balance-gated. |
| Engine / Provider | External generation service: 即梦 (Jimeng), EvoLink GPT Image 2, Seedance 2.0, Bailian. | Adapters isolate provider payloads and status mapping. |
| Worker | Process that periodically calls the internal Worker tick endpoint to claim and execute jobs. | Node Worker has no RDS credentials; Go embeds a WorkerLoop after cutover. |
| WorkerLoop | Embedded async task loop inside the Go backend. | Replaces the HTTP-polling Node Worker only after drain and verification. |
| Cutover | Single-writer routing of `/api`, `/uploads`, `/generated-results` to Go, Node Worker drain, then Next Route Handler deletion. | Must stay reversible; ACK-001 remains truth until it passes. |
| Worker | Legacy Node process that polled an internal HTTP tick endpoint to claim and execute jobs. | No longer shipped or deployed in the accepted static Web + Go architecture. |
| WorkerLoop | Embedded async task loop inside the Go backend. | The production job-execution path; it uses Go application/module seams without a Web tick endpoint. |
| Static Web | Next.js static export (`out/`) served by unprivileged Nginx. | Has no SSR, Route Handlers, Middleware, runtime application configuration, database access, or session Secret. |
| Cutover | Historical migration from Next-owned runtime routes and the Node Worker to Go-owned routes and WorkerLoop. | The first production rollout now deploys the static Web and Go revisions directly; no legacy drain sequence is required. |
| Contract fixture | Language-neutral JSON contract under `contracts/` for HTTP, Cookie, auth, jobs, billing, storage, Webhook behavior. | Executable by both TypeScript and Go consumers. |
| `zhinian_session` | Signed (HMAC-SHA256), chunked (3000 chars, up to 20 chunks) session cookie. | `HttpOnly`, `SameSite=Lax`, `Path=/`, production `Secure`. |