merge: integrate Prompt Museum media rendering

This commit is contained in:
2026-08-18 12:43:05 +08:00
parent f8d82e6c19
commit 22bee1dfa4
5 changed files with 49 additions and 60 deletions

View File

@@ -11,6 +11,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
- `4013edc` / `3b799af`: integrated per-user Code/Canvas/Learning/Robot entry policy from Works Square, projected by Electron Main as four booleans and enforced before disabled module routes initialize.
- `01bee31`: enabled AI Learning course catalog/generation/download/playback, Main-owned cloud/runtime bridges, verified external OpenMAIC player-artifact packaging, account profile reuse, removal of the transient `game-engine` Skill, and project-root `planning-with-files` output from the authoritative remote main. The merge hardens this with strict DTO/error projection, account-isolated local state, bounded same-origin downloads/packages, a nonce-protected account-bound player HTTP session, and an exact-source/origin single-document iframe bridge.
- `26b52d7`: Canvas Prompt Museum, editable server-priced generation Quotes, project deletion/task-detail workflow, cloud-default Canvas development entry, and Chinese-only UI consolidation from the authoritative remote main. Its transient bundled `game-engine` Skill is superseded by `01bee31`.
- `f8d82e6`: Prompt Museum media rendering now accepts only the server-controlled relative media route, fetches it through a Main-owned bounded Works-authenticated proxy with one refresh retry, and keeps credential-free HTTPS CDN media direct. Renderer-side validation and card-local placeholders cover invalid or failed media; attribution URLs remain optional.
- `c1326a2`: Guided Hotspot Binding now scans bounded open `Xiaozhi-*` candidates and connects the user-selected hotspot inside the page through Main-owned Windows WLAN and macOS CoreWLAN/CoreLocation adapters; system Wi-Fi remains fallback, exact `=0` rollback and firmware/cloud contracts are unchanged.
- `b78fc07`: Guided Hotspot Binding is enabled by default in Electron Main, with exact environment value `0` as rollback and direct six-digit fallback on capability-read failure; firmware and Host/cloud contracts are unchanged.
- `b7a1590` / `14afe4a`: initial firmware-zero-change Guided Hotspot Binding V1 implementation and decision used a Main-owned default-off capability, fixed portal action, in-memory Renderer journey, and existing six-digit Binding contract; `b78fc07` above supersedes only that default.
@@ -37,7 +38,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
AI 绘画的一个 Workspace 可包含多条 Conversation。消息、Brief、Quote 和 `turnRevision` 随 Conversation 隔离;生成任务和资产保持 Workspace 级共享。图片 Brief 支持文生图,以及从当前项目已完成作品或本地上传中选择一张参考图继续生成;视频复用同一选择器绑定首帧。两条路径都通过现有 Workspace Asset 契约提交一个真实 Asset ID。每条 Conversation 使用服务端持久 Agent Gateway Session;连接正常时命令、Run 与设计事件共用双向 WebSocket,只有发送、断连或 ACK 超时等传输故障才以同一 `client_command_id` 回退 REST,结构化业务错误不重复提交且未知上游文本由 Main 脱敏。确认栏允许编辑服务端最终 Prompt 与 generation options,每次修改都由服务端 Quote 重算设计点,确认时提交最新原值;客户端不推算供应商或积分价格。任务详情可预览/下载结果。侧栏删除项目要求完整输入项目名,删除当前项目后切换到最近更新的剩余项目;服务端删除/结算语义仍由 Works Square 契约负责。确认生成会按 Quote 对账 Workspace 任务;任务已经落库但 Run 随后失败时仍恢复任务列表,内部对账失败不覆盖当前 UI 错误,同时 Conversation 写入继续受 Workspace-load 与 Conversation-selection generation 保护。
Canvas 侧栏提供“获取灵感”进入 Prompt Museum。列表、筛选、分页、详情、作者/来源/许可证和图片地址全部由服务端经 Main-owned Host API 提供,客户端不打包静态数据集;“使用此 Prompt”只把原文带回当前 Canvas 输入框,不自动发送。该模块不是投稿、点赞、评论或排行榜社区。客户端契约已就绪,但不据此宣称 Works Square 内容后台和生产数据已经部署。`pnpm run dev` 现在默认使用云端 Canvas 适配器,本地适配器只能通过显式开发命令启用;产品 UI 只保留中文。
Canvas 侧栏提供“获取灵感”进入 Prompt Museum。列表、筛选、分页、详情、作者/来源/许可证和图片地址全部由服务端经 Main-owned Host API 提供,客户端不打包静态数据集;服务端相对媒体只允许固定 `/api/image-prompt-museum/{entry}/media/{thumbnail|number}` 形状,并由 Main 注入 Works Bearer、执行一次 401 刷新、可信 raster MIME 与 10 MiB 上限后转为 Renderer data URL;credential-free HTTPS CDN 图片保持直连。图片失败只显示卡片内占位,不阻断卡片或详情;缺少来源 URL 时显示纯文本。“使用此 Prompt”只把原文带回当前 Canvas 输入框,不自动发送。该模块不是投稿、点赞、评论或排行榜社区。客户端契约已就绪,但不据此宣称 Works Square 内容后台和生产数据已经部署。`pnpm run dev` 现在默认使用云端 Canvas 适配器,本地适配器只能通过显式开发命令启用;产品 UI 只保留中文。
Makelore 在会话恢复、登录和刷新后由 Electron Main 请求 Works `/api/auth/me`,Renderer 只获得 Code、Canvas、Learning、Robot 四个布尔权限。缺失 `module_access` 或任一字段时默认开启;服务端 `design` 显式映射客户端 `painting`。被关闭的模块卡片置灰且不可点击,根路由、深层路由和别名路由均在 `MainLayout` 或模块初始化前阻断。Code provider 等待认证权限加载完成;权限查询返回终止性 `401` 时同时清理 Main 和 Renderer 会话。`/settings` 是全局设置,不受 Code 入口策略阻断。该机制只是客户端入口策略,不代替服务端 API 授权。
@@ -57,6 +58,7 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
- 2026-08-17: Created merge commit `4013edc` for the reviewed per-user module-entry policy source tip `3b799af`. Main exposes only four booleans from `/api/auth/me`; missing fields remain enabled, `design` maps to `painting`, disabled root/deep/alias routes stop before module initialization, Code provider startup waits for policy hydration, terminal `401` clears both session layers, and global settings remains reachable.
- 2026-08-17: Integrated remote `01bee31`: Learning is enabled with course browsing, strict bounded generation materials, verified atomic course installation, multi-module playback, Main-owned Agent/ASR/runtime bridges, and a manifest-verified external OpenMAIC player artifact. Merge review added account-isolated generation/library/player state, fixed-binding token/fetch/401 guards, passive-only course media with hardened responses, pre-existing active-registration checks before side-effect-free identity resolution, nonce-protected single-document player sessions, and a recoverable deep-link profile error gate. At that integration checkpoint, publishing used a coverless first create, existing draft/published were version-only, and races failed closed without cover/PATCH side effects; project-cover source `145a6ce` and matching server merge `0cedfc4` above supersede only the coverless-first-create limitation. The transient `game-engine` Skill was removed and `planning-with-files` writes its files to the project root. Production Works/player-artifact/signed-package acceptance remains pending.
- 2026-08-16: Integrated remote `26b52d7`: Canvas now has server-backed Prompt Museum navigation, editable server-repriced generation Quotes, task result details/downloads, guarded project deletion, cloud-default development, and Chinese-only UI. That tip briefly bundled `game-engine`; authoritative successor `01bee31` removed it. Client integration is verified separately from production Prompt Museum data/backend deployment.
- 2026-08-18: Integrated Prompt Museum media rendering from `f8d82e6`: relative protected media is fetched through Main with bounded trusted-raster validation and one 401 refresh, HTTPS media remains direct, invalid/failed images are card-local placeholders, and missing attribution URLs render without broken links. Focused unit/Electron E2E, typecheck, scoped lint, and Vite build passed; real Works/CDN production smoke remains pending.
- 2026-08-16: Integrated Windows/macOS in-page Robot hotspot discovery, explicit selection, connection, and exact-current-SSID verification behind the existing default-on guided capability. Candidate IDs are bounded and short-lived, native diagnostics stay in Main, system settings remain fallback, and firmware/Portal/Binding contracts are unchanged.
- 2026-08-16: Enabled the existing Guided Hotspot Binding journey by default after explicit product confirmation. Exact `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` remains the operational rollback; fixed portal ownership, direct-code fallback, security warnings, firmware-zero-change, and Binding-without-online semantics are preserved.
- 2026-08-16: Initially implemented ADR-002's Robot onboarding V1 without changing firmware, behind a default-off Main capability and fixed portal opener. The later `b78fc07` decision above changes only the default; the same firmware/issuer/native-opener/physical evidence remains outstanding.
@@ -94,6 +96,7 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Risky Areas
- 四模块权限只控制 Makelore 客户端入口和初始化,不是 API 授权边界。不得因卡片置灰或路由阻断而放宽 Works/模块服务端的身份与权限校验;旧服务端缺少对象/字段时默认开启是显式兼容策略。
- Prompt Museum 相对媒体必须保持固定的服务端路径并由 Main 处理;如果服务端增加媒体变体,需同步维护 entry/path 语法、Works Bearer 所有权、单次刷新、10 MiB 限制、可信 raster MIME 白名单与 Renderer data URL 校验。HTTPS 直连媒体必须继续无凭据,图片失败必须局限在卡片/详情视图。
- Learning 的课程目录、生成、Agent、ASR 与 runtime 都依赖真实 Works 权益和服务端契约;本地课程归档与播放器 artifact 必须在信任前完成边界、大小与摘要校验。账号分区/epoch、fixed-binding token+fetch guards、同源重定向、512 MiB 上限、player nonce、exact source/origin 与单文档 bridge 边界不可放宽;不得把模块/场景自报身份当成 aggregate 课程权益,也不得把上游错误、Token、内部 URL 或本地归档路径投影到 Renderer。
- Works Project 首次封面已由服务端源 `407c883`(本地 merge `0cedfc4`)提供单请求原子绑定与失败补偿,客户端源 `145a6ce` 因此要求首次发布上传 PNG/JPEG/WebP 封面;部署、安装包和真实账号/对象存储 smoke 仍未完成。服务端仍没有已有 metadata 的 revision/ETag 与 draft-only 条件写,因此已有 draft/published 继续只允许 version-only,客户端不得以无条件 PATCH 替代。
- Guided Hotspot Binding 默认开启并提供未经认证的热点扫描/显式连接,但当前 Hotspot/portal 仍是开放 SoftAP + 明文 HTTP,且精确出货镜像、激活码发行契约、签名 macOS、Windows 真机与完整整链尚未验证。界面必须保留环境警告,异常发布可用精确环境值 `0` 回滚;不得把 SSID 前缀宣称为可信设备发现、自动认领或在线证明。
@@ -118,4 +121,4 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Last Updated
2026-08-17
2026-08-18

View File

@@ -0,0 +1,42 @@
# Task: Integrate Prompt Museum media fix
## Identity
- Task ID: 20260818-museum-media-integration-6b7e
- Mode: Integration
- Branch: codex/20260818-museum-media-integration-6b7e-prompt-museum-media
- Worktree: D:\mk-integration-6b7e
- Base commit: 11b19832a35477d2136c6ea953dd9c408fd84816
- Owner: developer
- Status: Completed
## Scope
- Fast-forward the completed Prompt Museum media-rendering source task `f8d82e6` from the current `main` tip `11b1983` into the integration line.
- Promote the accepted durable media-boundary facts into `current-state.md`, `50-evidence/evidence-index.md`, and the existing Prompt Museum release commitment without changing the source task record.
## Intent And Constraints
- Preserve Main ownership of Works credentials, the fixed relative media path, one 401 refresh retry, 10 MiB/trusted-raster limits, Renderer data-URL validation, direct HTTPS behavior, and card-local failure handling.
- Do not claim production Works/CDN availability, real-account behavior, or signed-package acceptance from local automation.
## Outcome
- Fast-forwarded `11b1983` to source commit `f8d82e6`, carrying the Main proxy, shared DTO, Renderer API/page behavior, focused regressions, and source task record.
- Promoted the source task's current-state, evidence, and commitment candidates; no semantic conflicts or human decision were required.
## Verification
- `git merge --ff-only f8d82e6`: PASS; merge-base confirmed `11b1983` is an ancestor.
- Source verification reviewed as read-only: 27 focused unit tests, typecheck, scoped ESLint, Vite build, targeted Electron E2E 1/1, `git diff --check`, and final Sol review PASS.
- Integration worktree remains clean after documentation updates; task-aware drift check will run before release.
## Follow-ups
- Real Works account, deployed media endpoint/CDN, and signed-package smoke remain release follow-ups.
## Promotion Candidates
- `current-state.md`: record `f8d82e6` and the Main-owned bounded media boundary.
- `50-evidence/evidence-index.md`: record focused 27-test/build/E2E evidence and its production limitation.
- `80-commitments/commitments.md`: extend the existing Prompt Museum production acceptance to cover relative media proxy behavior.

View File

@@ -1,57 +0,0 @@
# Task: Fix Makelore Prompt Museum media rendering
## Identity
- Task ID: 20260818-prompt-museum-client-4f7a
- Mode: Feature
- Branch: codex/20260818-prompt-museum-client-4f7a-prompt-museum-client
- Worktree: D:\mk-4f7a
- Base commit: 11b19832a35477d2136c6ea953dd9c408fd84816
- Owner: developer
- Status: Ready for integration
## Scope
- Permit the server-controlled Prompt Museum media URL shape in strict list/detail DTO projection.
- Add an authenticated, fixed-path Main proxy for bounded Prompt Museum raster media.
- Resolve relative media through Main in the Renderer while keeping absolute HTTPS images direct and image failures card-local.
- Preserve real attribution sources whose optional URL is missing or null without creating an undefined Renderer link.
- Cover list, detail, media, invalid-path/response, API conversion, and page success/failure behavior.
## Intent And Constraints
- The only relative media URL allowed is `/api/image-prompt-museum/{entry}/media/{thumbnail|number}`, with entry IDs matching `[A-Za-z0-9][A-Za-z0-9._:-]{0,127}`.
- Works Bearer credentials remain Main-owned; the existing Host API IPC JSON protocol is unchanged.
- Media is limited to 10 MiB and trusted raster MIME types; upstream payloads and errors are not exposed directly.
- Absolute credential-free HTTPS images remain directly renderable. A failed image displays a placeholder without failing its card or detail view.
- Attribution source URLs are optional: undefined is omitted, null is retained, and present strings remain strict credential-free HTTPS.
## Outcome
- Main now accepts controlled relative media URLs in projected cards/details and proxies only the mirrored fixed local media route with Works Bearer refresh behavior.
- Main rejects non-raster or oversized responses and returns only `dataBase64` plus normalized trusted `mimeType` for successful media.
- Renderer converts relative media responses into data URLs, validates the JSON again, and preserves direct HTTPS rendering.
- Museum images load independently; pending and failed images use an accessible placeholder and do not affect card interaction.
- Source attribution without a URL renders as plain text; valid HTTPS sources remain links.
## Verification
- `pnpm vitest run tests/unit/image-prompt-museum-route.test.ts tests/unit/image-prompt-museum-api.test.ts tests/unit/image-prompt-museum-page.test.tsx`: PASS, 3 files / 27 tests, including missing/null source URL projection and no-link rendering.
- `pnpm typecheck`: PASS.
- Scoped ESLint across the eight owned source/test files: PASS.
- `pnpm build:vite`: PASS; existing dynamic-import and chunk-size warnings only.
- Targeted Electron E2E `tests/e2e/image-workspace-conversations.spec.ts --grep "keeps Prompt Museum cards usable when relative media fails"`: PASS, 1/1. The local fixture returned a controlled relative thumbnail and invalid media MIME; the failed-image placeholder remained visible, the card stayed enabled, and its detail sheet opened.
- `git diff --check`: PASS; Git emitted only existing LF-to-CRLF checkout warnings.
## Follow-ups
- Production validation still requires a real Works account and deployed media endpoint; local automation does not prove production content availability.
## Promotion Candidates
- Target: `.project-docs/30-worklog/current-state.md` and Prompt Museum evidence/commitment entries during integration.
- Proposal: record that protected relative Prompt Museum media is fetched through a Main-owned bounded authenticated proxy while HTTPS CDN media remains direct.
- Evidence: focused 27 tests, typecheck, scoped lint, and Vite/Main/Preload build passed.
- Future impact: future Prompt Museum media URL or MIME additions must update the server validator, Main proxy, and Renderer validator together.
- Semantic conflicts: none identified; this implements the existing Main-owned Museum boundary.
- Human confirmation required: no for integration of this behavior; production deployment/smoke remains an external release decision.