feat: add admin accounts and image templates

This commit is contained in:
inman
2026-07-03 11:25:25 +08:00
parent d98e58adfa
commit c3ea9f0eb1
61 changed files with 7016 additions and 199 deletions

View File

@@ -4,7 +4,7 @@
Add EvoLink GPT Image 2 as a selectable image creation engine in the settings flow, while preserving the existing Jimeng/Volcengine image engine and the current task/asset workflow.
## Current Phase
Complete - latest update: Standalone Login Page Polish
Phase 39 - Task Module Width and Preview Polish complete
## Phases
@@ -118,6 +118,192 @@ Complete - latest update: Standalone Login Page Polish
- [x] Verify desktop and mobile login layout has no horizontal overflow
- **Status:** complete
### Phase 16: Repository Sync and Local Startup Status
- [x] Overwrite local workspace with the latest `origin/main`
- [x] Confirm the repository is clean at `d98e58a docs: update public api docs`
- [x] Verify the Next.js dev server can start locally on an alternate port
- [x] Record current process/port status after the dev session ended
- **Status:** complete
### Phase 17: Account ID Data Partitioning for Public API
- [x] Trace current owner/client/account boundaries
- [x] Add stable account-owner mapping for API clients
- [x] Route public API jobs/assets through the account owner
- [x] Add focused isolation tests and docs
- **Status:** complete
### Phase 18: Internal RBAC and Account Management Integration
- [x] Inspect current auth/session/nav/admin page boundaries
- [x] Attempt to read operations organization external API guide
- [x] Add admin/ordinary user permission model
- [x] Protect admin pages and admin APIs
- [x] Add account-management integration from the updated organization/user API guide
- [x] Verify tests/build and local behavior
- **Status:** complete
### Phase 19: Account Management Route Compatibility
- [x] Trace `/accounts` 404 from local logs to the upstream member-list route
- [x] Add configurable organization/member path overrides
- [x] Degrade missing member-list routes to page warnings instead of API 404
- [x] Update docs and focused tests
- **Status:** complete
### Phase 20: Account-Scoped Image Generation Templates
- [x] Trace current image generation, settings, auth owner, and data persistence paths
- [x] Design account-scoped template data with prompt presets and preview metadata
- [x] Add backend storage helpers and first-party template API routes
- [x] Add template configuration to settings and template selection to image generation
- [x] Add focused tests and run verification
- **Status:** complete
### Phase 21: Account Management Upstream Permission Degradation
- [x] Confirm the updated member-list path reaches `hotelStaff`
- [x] Identify the current failure as upstream administrator-role denial, not route/configuration miss
- [x] Degrade member-list permission denial to an account-page warning with an empty member list
- [x] Keep organization, role, group, account creation, and password maintenance flows available when configured
- [x] Add focused permission-denial classification test and run verification
- **Status:** complete
### Phase 22: Image Template Placement and In-Module Configuration
- [x] Remove template management from the global settings page
- [x] Move image template selection to the right side of the image generation console
- [x] Add template configuration flow inside the image generation module
- [x] Verify desktop/mobile layout, tests, and build
- **Status:** complete
### Phase 23: Large Auth Session Cookie Compatibility
- [x] Trace new-account login loop from `/api/auth/password` success back to `/auth/login`
- [x] Add chunked session cookie helpers for large JWT/authority payloads
- [x] Read chunked session cookies in middleware and server-side current-user helpers
- [x] Write chunked cookies from password and OAuth login, and clear all chunks on logout
- [x] Add focused session-cookie reassembly test and run verification
- **Status:** complete
### Phase 24: Left Template Rail for Image Generation
- [x] Move template selection into a left vertical scroll rail
- [x] Put the add-template icon button under the template rail heading
- [x] Keep template cards to thumbnail plus name with selected state
- [x] Apply selected template parameters into the right generation console
- [x] Verify layout, tests, and build
- **Status:** complete
### Phase 25: Independent Template Column for Image Generation
- [x] Split template selection out of the generation panel frame
- [x] Render templates as an independent left column panel
- [x] Keep the right panel dedicated to generation inputs and settings
- [x] Verify desktop and narrow viewport geometry
- [x] Run tests and production build
- **Status:** complete
### Phase 26: Generation Console Owns Mode Switch
- [x] Move the image/video/edit mode switch into the generation console panel
- [x] Keep the template module as the far-left independent module
- [x] Remove global/sticky mode-switch styling that visually spans modules
- [x] Verify the mode switch is contained by the generation panel, not the template panel
- [x] Run tests and production build
- **Status:** complete
### Phase 27: Template Upload Placeholders
- [x] Reuse the existing asset upload/OSS flow for template preview images
- [x] Remove template category/remark UI and expose an intro field instead
- [x] Parse `@图片1` style prompt placeholders into visible required upload slots
- [x] Keep selected-template parameters flowing into the generation console
- [x] Verify tests, build, and local server restart
- **Status:** complete
### Phase 28: Add Template Modal UX Polish
- [x] Apply UI/UX skill recommendations to the add-template modal
- [x] Reorganize the modal into preview, form, and action regions
- [x] Show parsed placeholder chips while editing preset prompt
- [x] Verify responsive layout, tests, build, and local server status
- **Status:** complete
### Phase 29: Template Engine-Specific Parameters
- [x] Add image generation engine and engine-specific parameters to template settings
- [x] Allow per-request image engine override when submitting image jobs
- [x] Add engine selection and conditional parameter controls to the add-template modal
- [x] Apply selected template engine/parameters into the generation console
- [x] Verify tests, build, browser layout, and local server restart
- **Status:** complete
### Phase 30: Template Rail Editing and Placeholder Confirmation
- [x] Tighten material placeholder parsing so unfinished `@图片` text is not treated as a completed token
- [x] Add explicit placeholder insertion controls in template prompt editing
- [x] Support editing existing templates through the in-module modal and PATCH API
- [x] Widen the left template module and split image preview, selection, and edit actions
- [x] Verify tests, build, browser layout, and local server restart
- **Status:** complete
### Phase 31: Confirmed Material Draft Slot
- [x] Open a temporary material slot when a user types `@`
- [x] Confirm the slot into prompt text only on Enter/explicit selection
- [x] Keep invalid long text out of the prompt body and placeholder chips
- [x] Render confirmed tokens through the existing independent token/chip UI
- [x] Verify tests, build, browser interaction, mobile layout, and local server restart
- **Status:** complete
### Phase 32: Inline Floating Material Draft Slot
- [x] Float the temporary material draft slot inside the prompt editor surface
- [x] Add the same token overlay to template preset prompts
- [x] Keep confirmed `@图片1` / `@视频1` placeholders visibly colored inside the input area
- [x] Verify main prompt and template prompt interactions in the browser
- [x] Run tests, production build, and normal server restart checks
- **Status:** complete
### Phase 33: Wider Template Rail and Explicit Select Button
- [x] Widen the image template selection column another 1.5x on desktop and tablet layouts
- [x] Keep 9:16 and 16:9 template reference images visible without cropping
- [x] Make template application require a dedicated `选择模板` button instead of clicking the card text
- [x] Verify desktop/mobile geometry, click behavior, focused tests, and production build
- **Status:** complete
### Phase 34: Fixed Template Cards and Internal Rail Scroll
- [x] Make each template card a smaller fixed-size item
- [x] Match the template rail height to the right generation panel height
- [x] Keep the `模板选择` header and `添加模板` button fixed while only the template list scrolls
- [x] Verify desktop/mobile geometry, internal scroll behavior, focused tests, and production build
- **Status:** complete
### Phase 35: Full-Bleed Glass Template Cards
- [x] Use the template image as the full-card visual surface
- [x] Move title, description, and select action into a translucent glass panel floating at the card bottom
- [x] Remove the zoom icon while keeping the edit action at the top right
- [x] Add a stronger elevated selected-card shadow
- [x] Verify browser geometry, focused tests, and production build
- **Status:** complete
### Phase 36: Template Toggle Cancel and No Intro Field
- [x] Remove the template intro field from the template card and editor UI
- [x] Move the template edit icon into the frosted-glass card overlay
- [x] Make the selected template button toggle off on a second click
- [x] Restore the right-side generation prompt and image parameters when canceling template selection
- [x] Verify browser interaction, focused tests, and production build
- **Status:** complete
### Phase 37: Template Card UI Density Polish
- [x] Reduce the fixed template card size while preserving full-bleed image previews
- [x] Let the widened desktop rail fit three compact template cards per row
- [x] Reflow the frosted-glass footer so the title owns the first row and select/edit controls share the second row
- [x] Remove the remaining frontend template description field from the create-studio type surface
- [x] Verify geometry, focused tests, and production build
- **Status:** complete
### Phase 38: Right-Side Create Task Module
- [x] Add an independent right-side task module to the creation console
- [x] Show generated asset thumbnail, task name, status, elapsed time, and detail entry
- [x] Link detail entry to the results task page with the matching task expanded
- [x] Add responsive desktop/tablet/mobile layout behavior
- [x] Verify focused tests, TypeScript, production build, and browser layout
- **Status:** complete
### Phase 39: Task Module Width and Preview Polish
- [x] Widen the right-side task module up to roughly double the original width on wide screens
- [x] Keep task card information on one horizontal row without wrapping status/time/action
- [x] Show a `生成中` placeholder thumbnail for queued/running tasks without output assets
- [x] Allow completed image thumbnails to open a large preview directly from the create page
- [x] Verify TypeScript, build, focused tests, and browser desktop/mobile behavior
- **Status:** complete
## Key Questions
1. How should the selected image engine be stored and exposed in settings?
2. Which current capabilities should EvoLink handle first?
@@ -143,6 +329,21 @@ Complete - latest update: Standalone Login Page Polish
| Keep `/api/v1/*` outside SSO middleware | Existing partner integrations authenticate with API keys and must not be redirected to browser login |
| Add password grant login as a first-class browser login path | The provided auth service currently accepts `customPC` password login with image captcha while `/oauth2/authorize` returns 400 for the local callback |
| Hide the unified-auth/SSO entry from the login page | The user wants a focused branded login screen with only logo, platform name, and the account login form |
| Use an alternate local dev port when `3000` is occupied | Existing local Next processes may already bind common ports; startup verification should use a free port and record the actual URL |
| Partition public API records by an owner id derived from the API account id | Avoids storing all partner API jobs/assets under `demo-merchant` and makes account boundaries explicit in the data layer |
| Use JWT authorities as the RBAC source of truth | Auth center already issues authorities; this keeps ordinary/admin access controlled by the organization identity system |
| Add image templates as account-owned app data instead of environment settings | Templates include business prompts and preview metadata, so they should follow the authenticated owner boundary rather than global deployment config |
| Keep image template configuration inside the image generation module instead of global settings | Templates are part of the image creation workflow, and users should configure them where they select and apply them |
| Split oversized auth sessions across multiple cookies | Some real accounts can receive larger JWT/authority payloads; chunking avoids successful password login immediately losing the browser session |
| Use a left template rail for image mode | The user expects template selection to behave like a vertical picker beside the generation console, with the generation controls on the right reflecting the selected template |
| Make the image template rail its own panel | The user clarified the template picker should be an independent column, not merged inside the generation console frame |
| Keep the mode switch inside the generation console | The user clarified the image/video filter belongs to the generation console, while templates should remain a separate far-left module |
| Reuse `/api/assets/upload` for template preview images | The existing upload route already stores assets through the configured OSS/local storage layer under the authenticated owner boundary |
| Treat `@图片N` as a required upload placeholder | Template prompts should make missing source images visible in the generation console before users submit a job |
| Use a preview-first add-template modal layout | UI/UX skill guidance favors a focused form with a strong preview and clear submit action for this kind of template creation flow |
| Store engine-specific image template parameters in template settings | Jimeng and EvoLink Image2 use different request parameters, so templates must preserve the intended engine and the matching tuning option |
| Require numbered material placeholder tokens | `@图片1` is an explicit completed placeholder; bare `@图片` remains ordinary text/search state so later Chinese input is not swallowed as the placeholder name |
| Keep the temporary material draft slot inside prompt editor bounds | The user expects `@` entry to feel like an inline input affordance, while confirmed placeholders should remain visually distinct inside the same input surface |
## Errors Encountered
| Error | Attempt | Resolution |
@@ -158,6 +359,13 @@ Complete - latest update: Standalone Login Page Polish
| White transparent logo was invisible on the light top bar unless wrapped in a dark frame | 1 | Switched to the black/blue logo variant, generated a cropped transparent PNG, and removed frame/background styling |
| Current local machine does not expose Docker CLI | 1 | Verified script syntax, Next build, tests, and health locally; Docker build should be run on the deployment server |
| Docker CLI is still unavailable while validating Phase 10 | 1 | Verified npm tests, production build, local health, API v1 calls, and worker tick locally; Compose container startup should be validated on the deployment server |
| Local ports `3000`, `3001`, and `3002` were already occupied during startup verification | 1 | Started the current project on `127.0.0.1:3003` and verified it redirected to `/auth/login?next=%2F` |
| zsh expanded unquoted `[id]` API route paths during Phase 17 inspection | 1 | Re-read those dynamic route files with quoted paths |
| `/Users/inmanx/Desktop/organization-external-api.md` was not present | 1 | User provided updated `/Users/inmanx/Desktop/organization-external-api(1).md`; wired the account-management endpoints from that version |
| Logged-in `/api/admin/accounts` returned 404 for `organizationMember/organizationMemberList` | 1 | Added `ZHINIAN_ORG_MEMBER_LIST_PATH` override support and degraded missing member-list routes to a warning so `/accounts` returns 200 |
| Running `npm run build` while the dev server was active caused the dev server to miss `.next/server/vendor-chunks/next.js` for the new dynamic template route | 1 | Restarted the dev server, confirmed it rebuilt the route, deleted the temporary verification template, then restarted the server under the normal auth-enabled environment |
| Updated `hotelStaff` member-list proxy returned `仅管理员角色允许调用` for the current token | 1 | Classified the upstream permission denial and degraded only the member list to a warning/empty page instead of failing the whole accounts screen |
| New account login returned 200 from `/api/auth/password` but was redirected back to `/auth/login?next=/create` | 1 | Added chunked session cookies so larger JWT/authority payloads are preserved across the browser redirect |
## Notes
- EvoLink docs: submit `POST /v1/images/generations`, query `GET /v1/tasks/{task_id}`, completed task exposes `results[]`.
@@ -170,4 +378,9 @@ Complete - latest update: Standalone Login Page Polish
- Server one-command deployment entrypoint is `bash scripts/deploy.sh`.
- Docker Compose persists local uploads/results/state through the bind mount `./.runtime:/app/.runtime`.
- Public API v1 endpoints are under `/api/v1` and require `ZHINIAN_API_KEYS`.
- Public API account data is partitioned by the API key account id as `ownerId = api:<accountId>`.
- Task processing is handled by `npm run worker` or the `zhinian-worker` Compose service through `/api/internal/worker/tick`.
- Latest repository sync status: `main` tracks `origin/main` and is clean at `d98e58a docs: update public api docs`.
- Latest local startup verification used `npm run dev -- --hostname 127.0.0.1 --port 3003`; the server reached Ready and `/` returned a login redirect.
- Current status check on 2026-06-09: no `next dev` / `next-server` process is listening on `3003`, so the dev server is not currently running.
- Image templates are now account-scoped records exposed through `/api/image-templates`; the image creation page shows and manages them inside the image module.