From 88800f92233d329198b03c5cb990d3e0e289d695 Mon Sep 17 00:00:00 2001 From: brother7 <7brother7@gmail.com> Date: Tue, 22 Sep 2026 12:03:43 +0800 Subject: [PATCH] docs: integrate permanent point wallet into main --- .project-docs/10-decisions/decision-index.md | 2 + .project-docs/20-architecture/data-flow.md | 15 ++++- .project-docs/20-architecture/module-map.md | 4 +- .../20-architecture/system-overview.md | 5 +- .project-docs/30-worklog/current-state.md | 15 ++++- ...egrate-permanent-points-client-38f5b921.md | 57 +++++++++++++++++++ .project-docs/40-domain/business-rules.md | 25 ++++---- 7 files changed, 102 insertions(+), 21 deletions(-) create mode 100644 .project-docs/30-worklog/tasks/20260922-integrate-permanent-points-client-38f5b921.md diff --git a/.project-docs/10-decisions/decision-index.md b/.project-docs/10-decisions/decision-index.md index bd5214f9..21a35ee6 100644 --- a/.project-docs/10-decisions/decision-index.md +++ b/.project-docs/10-decisions/decision-index.md @@ -2,6 +2,8 @@ ## Active Decisions +- [永久词元点数账户](../40-domain/business-rules.md#permanent-token-points):2026-09-22 用户确认 / 客户端已集成;移除会员、订阅、周额度与重置卡,新注册一次赠 100 点,旧权益取消且不补送、不折算,1 元兑 50 点且永不过期。本人余额与其他付款方可用性分开,云智能体及 Plugin 原有付款边界保持;依据源 `a1cce42` 与对应集成记录。 + - [桌面智能体接入与微信绑定完成](ADR-2026-09-11-personal-cloud-agents.md):2026-09-20 amended / implemented;移除指定用户分享界面,入口改为“使用与接入”;确认微信绑定后收起二维码并提示下一步,路由和启用仍由用户明确操作。 - [知识文档处理与可用状态](ADR-2026-09-11-personal-cloud-agents.md#知识文档处理与可用状态):2026-09-15 amended / implemented;上传、导入、替换自动解析索引,持续刷新阶段与真实可用性,失败可恢复且保留旧资料。 diff --git a/.project-docs/20-architecture/data-flow.md b/.project-docs/20-architecture/data-flow.md index 7d744230..95ae1943 100644 --- a/.project-docs/20-architecture/data-flow.md +++ b/.project-docs/20-architecture/data-flow.md @@ -1,5 +1,15 @@ # Data Flow +## Permanent wallet and recharge + +账号菜单 / PointWallet → `src/lib/works-billing.ts` → Main 固定 `/api/works/billing/*` 路由 → Works Square 账务 API。Main 持有认证与账号绑定,通过 `shared/works-billing.ts` 的公开 DTO 投影余额、产品、订单及流水;充值沿用 Renderer capability,Renderer 不传付款人、价格、Token 或任意上游地址。账号切换后 Main 与账号绑定的 UI 丢弃迟到结果,打开菜单和窗口 focus 刷新当前账号。 + +本人点数与 AI 编程已选付款来源分开呈现。`shared_available` 为布尔值时只向 Renderer 提供另一付款方的可用性,精确余额置空;为 `null` 时保留本人规范字符串余额,即使 `family_shared=true` 且来源为 `self` / `shared_group`。充值资格来自服务端,不能用旧会员管理权限或共享标记推算。云智能体创建者付款与 Plugin 个人付款不受 AI 编程来源选择改变。 + +明确充值 → 稳定 request identity 创建订单 → 冻结订单金额/点数与支付信息 → GET 恢复/查询原订单 → 服务端确认入账 → 刷新本人余额与流水。请求结果不明时保留原 identity,不自动重放 POST;已有待支付/人工核对订单先恢复,不能另建替代订单。商品改价不改变旧订单,支付二维码或用户声称支付不构成到账证据。网页续付和付款来源管理只打开固定账号页。 + +规则与证据见[永久点数规则](../40-domain/business-rules.md#permanent-token-points)及[集成记录](../30-worklog/tasks/20260922-integrate-permanent-points-client-38f5b921.md)。 + ## Game Audio generation and local delivery Project-enabled optional bundled Game Audio → frozen eligible parent tool → one explicit @@ -55,8 +65,7 @@ Main 在接收带图消息时立即将上传 attachment id 放入 optimistic use | Plugin workspace navigation | Project Configuration `插件` ResourceCard or compatibility URL | `/project-config/plugins` → Project Configuration remains mounted → same-page wide Plugin sheet → unified Plugin stores/Main routes | Code sidebar has no standalone Plugin entry. `/plugins` and old Plugin URLs only preserve query/filter intent while redirecting; embedding does not merge acquisition, install, project enablement, assignment, runtime authorization, or billing lifecycles. | | Hosted Game Resource operation and delivery | Eligible parent `makelore.game-resource` generate call plus one explicit confirmation | frozen Plugin adapter → Main delivery coordinator → one `GameResourceClient` submission → internal status polling → all terminal downloads → `assets/generated/game-resource//` in the frozen original project | Server policy owns pricing、payer、Admission 与 Provider receipt state;Main owns the durable local delivery receipt and filesystem. `submission_unknown` 不会作为新请求重放。重启或重试只恢复下载/保存,共享项目写租约仅在终态落盘期间持有;Agent 只收到一张进度/结果卡片,不暴露 status/save 工具,也不要求第二次确认。 | | 桌面认证生命周期 | Renderer 登录、刷新与注销请求 | Host API → Main Works Session → Works Square `/api/auth/{login,mobile-login,refresh,logout}` → one-feel auth | Main 加密持有并先持久化轮换 token;客户端不携带 OAuth client secret;连续 7 天未使用才清除会话,终止性 `400`/`401` fail closed | -| Account Token Points V2 | 已登录账号菜单、窗口 focus 或重新可见 | Renderer → Main `/api/works/billing/points` → Works Square `/api/billing/points` → safe balance projection | 可管理会员的账号获得规范字符串点数与套餐/周期元数据;非管理者的精确字段全部置空,只投影 `shared_available`、共享/青少年类型和升级责任。旧 rolling-window usage API 与 stale event 不再参与。 | -| Expiring reset-card wallet | 已登录账号展开卡包或明确点击一张可用卡 | Renderer → Main `/api/works/billing/reset-cards[/{card_id}/redeem]` → Works Square `/api/billing/reset-cards[/{card_id}/redeem]` → strict card projection | 卡包延迟加载并显示运营赠卡的可用、已过期、已使用状态;Main 丢弃内部字段和未知错误文本,Renderer 对已到期或共享钱包禁用操作。只有服务端成功或幂等重放后才刷新卡包与 Token Point V2 余额;付费重置卡不经过此库存流。 | +| Permanent Token Point Wallet | 已登录账号菜单、窗口 focus、明确充值或恢复订单 | Renderer → Main `/api/works/billing/*` → Works Square 固定账务 API → safe wallet/order projection | 本人精确余额与另一付款方可用性分开;稳定充值身份、冻结订单、原单恢复与服务端确认入账遵循上方数据流。会员、周额度与重置卡流程已移除。 | | 用户模块入口策略 | 会话恢复 / 登录 / 刷新 | Electron Main → Works `/api/auth/me` → 三布尔安全投影 → Renderer auth store → 卡片/路由/provider gate | 缺失对象或字段默认 `true`;`design` 映射 `painting`;额外旧字段被忽略;终止性 `401` 清理 Main/Renderer 会话;全局 `/settings` 不受 Code gate | | 项目创建 | 新建项目对话框中的目录选择 | Renderer 内部默认 `interactive_ai_app` → Host API → Main 生成 UUID 并原子初始化 | 普通用户不选择类型、模板或项目身份;只生成 `.makelore/project.json` 与 `knowledge/`,随后直接进入 `/chat`。既有 `custom`/历史类型和底层兼容入口仍保留 | | 旧项目身份补齐 | 有效 `.makelore/project.json` 仅缺 `projectId` | Main serialized config read/repair → canonical UUID persisted once | 并发读取共享同一次修复;原始 UUID、bind/independent-copy 控件不进入普通 UI。其他缺失或无效 metadata 仍是配置错误;`initialized` 不阻断有效项目 | @@ -128,4 +137,4 @@ Main 在接收带图消息时立即将上传 attachment id 放入 optimistic use ## Last Updated -2026-09-15 +2026-09-22 diff --git a/.project-docs/20-architecture/module-map.md b/.project-docs/20-architecture/module-map.md index 25daeff0..1bffb3ad 100644 --- a/.project-docs/20-architecture/module-map.md +++ b/.project-docs/20-architecture/module-map.md @@ -16,7 +16,7 @@ | `shared/project-config.ts`, `electron/coding-projects/{project-config,project-service}.ts`, and `src/components/layout/Sidebar.tsx` | 规范 `ProjectType`、Main-owned UUID 与目录式最小项目创建 | 普通新建只要求目录,内部默认 `interactive_ai_app`,Main 自动生成 UUID;有效旧配置仅缺 `projectId` 时串行修复。既有 `custom` 和历史类型仍兼容,`initialized` 不再是导航 gate | | `resources/coding-plugins/project-scaffold/` and `tests/project-scaffold/` | 官方 bundled Scaffold Plugin、固定六文件模板、确定性 Node 脚本、发布要求参考与回归测试 | 通过既有 Pi `bash` write lease 和 `MAKELORE_NODE_EXECUTABLE` 显式运行;脚本信任来自固定客户端资源,而非下载 artifact;不覆盖、不安装依赖、不联网,也不复制 build/upload/review 实现 | | `src/lib/works-square.ts` | Renderer 侧 Works Square Host API 契约与安全错误映射 | 不接触 Token、ZIP、本地绝对路径或自动部署状态 | -| `electron/api/routes/works.ts`, `src/lib/works-square-token-points.ts`, and `src/components/layout/Sidebar.tsx` | Token Points V2 的 Main-owned 上游代理、安全 DTO 投影、格式化与账号菜单状态 | 管理者可见规范字符串点数与周期;非管理者只见粗粒度可用性。旧 rolling-window usage contract 和 Renderer stale event 已删除。 | +| `electron/api/routes/works-billing.ts`, `shared/works-billing.ts`, `src/lib/works-billing.ts`, `src/components/account/PointWallet.tsx` and `src/components/layout/Sidebar.tsx` | 永久词元点数的 Main-owned 认证与公开 DTO、个人余额、充值/订单恢复、流水及账号菜单 | 本人余额精确可见;另一付款方用 `shared_available` 表示可用性,不以 `family_shared` 或旧会员权限推测。显式充值意图复用请求身份,服务端确认后到账;旧订阅/重置卡入口及 DTO 已移除。 | | `electron/api/routes/works.ts` | Works Host API、Renderer capability 门禁、上游安全投影 | 发布凭据、打包、上传与本地绑定均在 Main 内完成 | | `electron/services/project-release-builder.ts` | Main-owned 安全快照、本地 npm/Vite 构建、source+built 双归档与 v1 contract | 固定 npm 11.6.2;项目 Vite 由 lockfile 决定;Vite config/plugins 以桌面用户权限执行 | | `electron/services/publish-runtime.ts` | 安装包内 npm 闭包定位与 Electron Node 执行 | 不回退全局 npm/PATH;缺失或版本不符 fail closed | @@ -91,4 +91,4 @@ ## Last Updated -2026-09-07 +2026-09-22 diff --git a/.project-docs/20-architecture/system-overview.md b/.project-docs/20-architecture/system-overview.md index 33920bf9..37ed79a7 100644 --- a/.project-docs/20-architecture/system-overview.md +++ b/.project-docs/20-architecture/system-overview.md @@ -28,8 +28,7 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展 | Project Scaffold Skill | 显式生成固定版本的交互式 AI 应用起步文件,并提供发布准备度指导 | 官方 `makelore.project-scaffold` bundled Marketplace Plugin;账号已获取且项目启用后自动提供给每个父 Agent,不需要伙伴分配,child 为空;它不是创建或聊天前置条件。完整预检、不覆盖、受控回滚,不安装依赖、不联网、不构建、不上传、不提审。 | | Project Release Builder | Main-owned 安全快照、本地 npm/Vite 构建、双归档与 artifact contract | 固定 npm 11.6.2;Vite 由项目 lockfile 锁定;产物与预检使用同一内存字节 | | Works Session & Remembered Password | Main-owned 登录、刷新、注销、七天真实活动滑动续期与可选密码回填 | 登录、刷新、注销统一经过 Works Square;轮换凭据由 Main 安全持有和持久化。记住密码使用独立的 packaged-only OS 加密记录,不进入 Renderer 持久状态或 Works Square;客户端不携带 OAuth client secret | -| Token Points V2 | Main-owned `/api/works/billing/points` 安全投影 → Renderer 账号菜单 | 会员管理者可查看套餐、本周与总余额及刷新时间;非管理者只获得 `shared_available` 粗粒度状态,套餐、周期和精确点数统一投影为 `null` | -| Reset Card Wallet | Main-owned `/api/works/billing/reset-cards` list/redeem 安全投影 → Renderer 账号菜单卡包 | 仅展示 Works Square 的 owner-scoped 运营赠卡,客户端派生已到期状态但不计算重置额度、不乐观成功;服务端确认后同步刷新卡包与 Token Point V2 余额。付费重置卡仍由支付成功立即履约,不进入卡包。 | +| Permanent Token Point Wallet | Main-owned `/api/works/billing/*` 固定路由、安全投影 → Renderer 账号菜单与 PointWallet | 本人精确余额、充值、冻结订单恢复与流水;另一付款方仅投影可用性。真实新注册赠 100 点,充值 1 元兑 50 点、永不过期,旧权益取消。Main 持有认证,稳定请求身份避免模糊结果重复下单;只有服务端确认后才显示入账,旧会员/重置卡入口已移除。 | | Module Access Policy | Main-owned `/api/auth/me` projection → Renderer auth state → module chooser/router | Renderer 接收 Code/Canvas/Robot/Agents 四个布尔权限;服务端 `design` 映射客户端 `painting`,云模块两端均为 `cloud_agents`;缺失对象/字段默认开启,额外字段被忽略 | | Submission Binding | 保存云端已接受的精确 app/version/review/hash 绑定 | schema v2 只记录成功提交;旧中间态迁移为 `legacy_retired`,不恢复后台任务 | | Play URL Projection | 校验服务端公共播放地址 | 只接受同源 HTTPS 和精确 `/apps/{app_id}/`;优先 `play_url`,`runtime_url` 仅一版本回退 | @@ -126,4 +125,4 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展 ## Last Updated -2026-09-15 +2026-09-22 diff --git a/.project-docs/30-worklog/current-state.md b/.project-docs/30-worklog/current-state.md index 6d8acd07..3d4e31ce 100644 --- a/.project-docs/30-worklog/current-state.md +++ b/.project-docs/30-worklog/current-state.md @@ -4,6 +4,17 @@ This file is the integrated default-branch snapshot. Feature tasks record progre ## Integrated Through +- 2026-09-22:任务 `20260922-integrate-permanent-points-client-38f5b921` 经用户授权交接主目录登记, + 将永久词元点数客户端源 `a1cce428afcca9b7e32ef043705a25a4685fbbdd` 从 `2f82b9f` 无冲突快进合入本地 `main`。 + 账号菜单改为个人余额、充值、订单及点数流水,移除会员、订阅、周额度与重置卡。 + 新注册一次赠送 100 点,存量账号不补送、不折算,1 元兑 50 点且永不过期;资格与入账均由服务端决定。 + 本人余额精确可见,另一付款方的钱包只显示可用性;AI 编程明确选择付款来源,云智能体创建者付费和 Plugin 个人付款保持。 + Main 持有认证、固定账务路由及安全投影;模糊支付结果复用原请求身份,已有订单恢复不重新下单,只有服务端确认才显示到账。 + 主目录 103 项相关单测及 Renderer 类型检查通过;产品树与源一致,沿用源 scoped lint、Vite 全目标构建、Windows Electron 充值恢复与实际后端内存库契约验证。 + 源全量测试的 Pi v6/v7 旧断言、一次隔离复跑通过的时序失败及 67 项既有 Main 类型诊断保持记录,不宣称全量通过。 + 三份原有未跟踪文档保持;未推送、打包、安装或部署,真实支付与配套 API/0094 迁移仍须发布验收。 + 详见[集成记录](tasks/20260922-integrate-permanent-points-client-38f5b921.md)及[永久点数规则](../40-domain/business-rules.md#permanent-token-points)。下方旧会员/重置卡条目仅保留历史事实。 + - 2026-09-21:任务 `20260921-integrate-game-audio-client-a6c8f241` 集成 Game Audio 产品源 `09e0ce5cf3d113b3bb7b128b2b04bc355d16173b` 与证据 HEAD `938c4b1ed306fa7a45241534cd44817c775cca13`,保留 `b5907e8` 主线的模型切换及项目重开修复。 @@ -979,6 +990,8 @@ This file is the integrated default-branch snapshot. Feature tasks record progre ## Current Focus +账号现采用永久词元点数钱包:真实新注册一次赠送 100 点,存量权益取消且不补送、不折算,充值 1 元兑 50 点、永不过期。账号菜单提供本人余额、充值、订单恢复及流水;付款来源的精确/粗粒度展示与服务端资格保持一致。旧会员、订阅、周额度及重置卡入口已移除,当前规则见[永久点数规则](../40-domain/business-rules.md#permanent-token-points)。 + 客户端面向非专业用户提供“选择目录创建交互式 AI 应用 → 直接进入聊天 → 按项目需要可选调用官方 bundled Project Scaffold Skill → 项目配置中一键提交 → Main 本地 npm/Vite 构建 → Electron 双视口预检最终产物 → 上传 source+built 双归档与 contract → 运营审核”的唯一创建者链路。普通新建不展示类型、模板、原始 UUID、绑定或独立副本选项;Renderer 写入内部默认 `interactive_ai_app`,Main 生成 UUID,并只创建 `.makelore/project.json` 与 `knowledge/`。有效旧配置仅缺 `projectId` 时由 Main 串行补齐;旧 `initialized` 仅保留兼容,不再阻断导航、聊天或首个 Agent。既有 `custom` 和历史类型继续兼容,但不作为普通新建选择。`makelore.project-scaffold` 不是创建前置条件,只负责不覆盖的固定起步树与只读发布准备度说明,不能安装、构建、上传、提审或批准;其 `.mjs` 只从签名客户端固定资源加载,Marketplace 下载 artifact 仍拒绝脚本。Main 对安全源码快照运行安装包内固定 npm 11.6.2 的 `npm ci --ignore-scripts`,再显式调用项目 `package-lock.json` 锁定的 Vite;Vite config/plugins 以当前桌面用户权限执行,因此只适用于用户信任的本地项目,不是 sandbox。预检由 Main 以临时 loopback origin 和 Electron WebContents/CDP 检查与最终 `built_archive` 相同的内存文件字节,覆盖桌面/移动视口、运行错误、白屏和外域访问;不使用 Playwright。该检查仍可由非官方客户端绕过,不产生可信 receipt,也不复刻生产 opaque-origin。服务端把源码、构建归档和 contract 视为不可信输入,逐字节重算与校验并固化不可变 Release;人工审核仍不可绕过。历史 `mini_game` / `mini_program` 只在读取边界归一为规范 `interactive_ai_app`。已发布作品优先使用安全投影后的 `play_url`,`runtime_url` 仅保留一个客户端版本的兼容回退。 AI Design Canvas 现在以中央 conversation timeline 加唯一 active 制作方案、右侧 320–340 px 全高 Works rail 的两区布局服务创作者;Canvas 路由不挂载全局左栏,紧凑宽度把同一 Works rail 放进右侧 Sheet。Active 方案的 `content.concept` 直接作为可编辑“创作提示词”,类型、画幅、视频时长和数量保持紧凑直控;已提交、运行中或终止方案折叠进对话历史。Reference 使用稳定 reference ID、真实 Workspace Asset binding 与连续 `@图片N` alias;Prompt 是用途的唯一可见表达,binding row 只管理缩略图、文件、alias、替换与删除。未绑定 alias 提供定点上传并阻止 Quote,Prompt/reference/参数变更产生新 Specification revision 和新 immutable Quote。一个 Workspace 仍只公开一个 current Direction、一个 persistent Agent Session 和一个 Current Specification;conversation timeline 只记录交互历史。Chat、direct edits、decision responses、proposal acceptance、locks、Asset binding 与 restore 都通过 `design.input.apply` 进入同一服务端 reducer,Renderer drafts 在 accepted 前保持本地。Main 持有 Works Token、stream ticket、WebSocket、request deadline、stable command/operation IDs 与错误脱敏;unknown result 只能复用原 identity,结构化业务错误不得重放。Generation 由服务端对 exact Specification revision 编译 immutable Quote,客户端只展示 public output plan、warnings、expiry 与 Token Points,并以 Quote ID 调用 `design.generation.confirm`;Provider Prompt、model、route、storage 和 billing atoms 不进入 Renderer。Task/Asset events 独立收敛 Workspace resources,不改写 Living Form。Development 与 packaged builds 均使用 Works Square V2,V1 DTO、local semantic adapter、mutable Quote PATCH 与 editable provider Prompt 已移除。 @@ -1148,4 +1161,4 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选 ## Last Updated -2026-09-15 +2026-09-22 diff --git a/.project-docs/30-worklog/tasks/20260922-integrate-permanent-points-client-38f5b921.md b/.project-docs/30-worklog/tasks/20260922-integrate-permanent-points-client-38f5b921.md new file mode 100644 index 00000000..efbed363 --- /dev/null +++ b/.project-docs/30-worklog/tasks/20260922-integrate-permanent-points-client-38f5b921.md @@ -0,0 +1,57 @@ +# Task: Integrate permanent point wallet into MakeLore main + +## Identity + +- Task ID: 20260922-integrate-permanent-points-client-38f5b921 +- Mode: Integration +- Branch: main +- Worktree: D:\Datas\OthersProjects\makelore +- Base commit: 2f82b9f79cf72873d75c17a48853292323aa5df5 +- Owner: codex +- Status: Ready for Integration + +## Scope + +- Fast-forward MakeLore main from 2f82b9f to the completed permanent-point wallet source a1cce428afcca9b7e32ef043705a25a4685fbbdd, then promote its accepted account rules and Main-owned billing data flow into canonical project memory. + +## Intent And Constraints + +- User explicitly authorized handing off the completed 20260921-integrate-game-audio-client-a6c8f241 registration and merging a1cce42. Official release/start/status succeeded; this task owns primary main in integration mode with the integration lock. +- Preserve the three pre-existing untracked package-122, package-123 and client-hang-diagnosis task documents exactly; their approved adopted states remain outside this commit. Source task records and other worktrees are read-only. +- Concurrent Task Gate and Planning Gate Passed. Read entry/own task, memory index, positioning, current state, decisions/auth ADR, architecture/module/data-flow, domain/glossary/success criteria and relevant evidence/reflection/commitment/stale context. Canonical memory is unchanged from the source base; reuse the source task's prior context and inspect the account sections being promoted. +- Assessed 122 peer scopes, intents and promotion candidates. Historical undefined scopes remain unknown/read-only. The isolated coding-teacher task may overlap Sidebar/README but does not contradict the wallet behavior; preserve that task for its later integration. Old membership/reset-card policy is superseded by the user's explicit accepted change. +- Confirmed policy: genuine registration 100 points once, no old-account gift/conversion, CNY 1 = 50 permanent points, parent recharges only their own wallet, youth own balance exact and another payer's balance coarse. Explicit AI-programming funding selection, cloud creator-pays and Plugin personal-payer boundaries remain. +- Preserve Code/Canvas/Robot/cloud Agents, Main-owned authentication and existing module restrictions. No subagents, push, packaging, installation, deployment or real payment. Merge consent does not authorize worktree removal. + +## Plan + +1. Fast-forward the verified source into main without altering product files or source records. +2. Replace superseded account rules and architecture descriptions, recording the exact source under Integrated Through. +3. Verify source parity, focused tests and Renderer typecheck in primary; reuse unchanged-source lint/build/Electron and baseline evidence where applicable. +4. Record the result, run the official documentation gate, commit integration documentation and complete task registration. Offer eligible source worktree cleanup separately. + +## Outcome + +- Fast-forwarded main from 2f82b9f79cf72873d75c17a48853292323aa5df5 to a1cce428afcca9b7e32ef043705a25a4685fbbdd with no conflicts. Product files and the imported source task record are unchanged from that source. +- Promoted the user-confirmed permanent-point policy into current-state, business-rules and decision-index; replaced obsolete membership/reset-card descriptions in system-overview, module-map and data-flow. Recorded actual source provenance under Integrated Through; historical task records remain intact. +- Official drift validation confirms the three adopted foreign task documents remain at their approved original states. They remain untracked and excluded from the integration commit. +- Source worktree remains clean, managed and ready_for_integration, with its latest a1cce42 included in main. Only that just-integrated source is eligible for the required separate cleanup offer; primary and other task worktrees are retained. +- Local merge only: no push, packaging, installation, deployment, real payment or subagent use. + +## Verification + +- In primary main after the merge: 8 focused files / 103 tests passed; pnpm run typecheck passed (Renderer). These cover billing auth/capability/privacy, stable payment intent, pending/review order recovery, frozen prices, own/family/youth balance contracts, account switching, menu refresh and retained Works routes. +- Product parity: git diff a1cce42 -- src electron shared tests README.md package.json pnpm-lock.yaml was empty. The integration changed only canonical documentation and this task record; source record provenance is preserved. +- Reused the identical source's passing scoped ESLint, Vite Renderer/Main/Preload/utility build, Windows Electron wallet E2E and actual backend in-memory API contract acceptance. The Electron flow verifies zero balance, original pending-order recovery after reload/repricing, exactly one POST and server-confirmed credit/ledger; it is not a real payment. +- Source limitations remain: full suite had the unchanged Pi runtime-v6 assertion against runtime-v7 and a timing failure that passed in isolation; extended Main typecheck has the same 67 baseline diagnostics, with no added/removed diagnostics. No claim that all repository tests or Main type checks pass. +- Reviewed source-to-main diff and canonical rule changes; git diff --check and official task-aware check_doc_drift passed before the final documentation commit. + +## Follow-ups + +- Source checkout cleanup awaiting explicit confirmation: task 20260922-permanent-points-client-7f4c9a2e at D:\Datas\OthersProjects\.codex-worktrees\makelore\20260922-permanent-points-client-7f4c9a2e, branch codex/20260922-permanent-points-client-7f4c9a2e-permanent-points-client. If approved, use official retire from primary; preserve the branch/commit. Merge/handoff consent does not cover removal. No response keeps the worktree and does not block the completed merge. +- Before release, deploy matching Works Square permanent-points API / 0094 migration and verify genuine registration, actual payment callbacks and configured desktop payment payload. PostgreSQL upgrade/concurrency and non-Windows packaged acceptance remain release work. +- Track the existing Pi v6/v7 test assertion and Main typecheck baseline independently. + +## Promotion Candidates + +- Accepted source promotions were applied to current-state, business-rules, decision-index, system-overview, module-map and data-flow under this integration lock. No unresolved semantic conflict or additional product decision remains. diff --git a/.project-docs/40-domain/business-rules.md b/.project-docs/40-domain/business-rules.md index fa564974..da33bcc5 100644 --- a/.project-docs/40-domain/business-rules.md +++ b/.project-docs/40-domain/business-rules.md @@ -1,5 +1,16 @@ # Business Rules +## Permanent Token Points + +- 账号不再具有会员或订阅等级、周额度或重置卡。真实新注册一次赠送 100 点;旧账号不补送、不折算,存量旧权益直接取消。充值 1 元人民币兑换 50 点,点数永不过期。所有资格、价格、余额、赠送和入账以 Works Square 为权威,客户端不以首次登录推测新注册或自行补点。 +- 家长只给本人钱包充值。青少年可以看本人精确余额;另一付款方的共享钱包只展示可用性,不展示金额、点数或其账本。付款资格与余额可见性分别来自服务端,不再依赖旧会员管理权限。 +- `family_shared=true` 不足以判定是否隐藏余额:付款方自己的钱包也可能带此标记。`shared_available` 为布尔值时投影另一付款方的粗粒度余额;为 `null` 时保留本人精确余额,包括 `entitlement_source=self` 或 `shared_group` 的本人家庭钱包。 +- AI 编程明确选择付款来源,余额不足时不静默切换。云智能体仍由创建者付费,Plugin 仍用个人付款;共享付款不授予其他账号内容、订单或流水权限。 +- 充值必须由用户明确发起,Renderer 不传付款人、价格或认证凭据。一次意图复用原请求身份;结果不明时只允许同身份重试,待支付或人工核对订单先恢复原订单。订单创建时冻结金额和点数,商品改价不改变旧单,服务端确认前不展示到账。 +- Main 代理固定账务路由并投影公开字段,切换账号后丢弃旧结果;重新打开账号菜单或窗口获得焦点时刷新余额。移除旧重置卡卡包与兑换流程,历史任务记录不再定义当前权益。 + +依据:用户确认的永久点数政策、源 `a1cce42` 与[集成记录](../30-worklog/tasks/20260922-integrate-permanent-points-client-38f5b921.md)。 + ## Code conversation titles and archive - 新建自动命名会话使用首条真实、完整、非空用户消息的首行,合并空白并截取最多 32 个 Unicode 字符;纯图片消息使用“附件对话”。斜杠命令、乐观消息和助手输出不触发命名;不调用模型生成标题。 @@ -20,16 +31,6 @@ - Marketplace Release A is curated: only Operations publishes packages. Users may acquire an eligible Plugin for free; only server-declared metered operations may later consume Token Points, and system-included Data Service remains zero-charge. -- Operations-granted reset cards are owner-scoped, expiring inventory and are distinct - from paid reset-card checkout, which Works Square fulfills immediately without - inventory. Renderer may display only the strict public card projection, derive an - elapsed available card as expired, and request redemption for the signed-in owner; - it must not calculate the reset allowance, expose internal grant/audit fields, treat - a shared wallet as redeemable, or claim success before Works Square confirms it. - Confirmed fulfillment refreshes both the card list and authoritative Token Point V2 - balance. The account-menu inventory omits redeemed cards, including immediately - after confirmed redemption, and shows 暂无未使用的重置卡。 when no visible cards remain. - Available and expired cards keep their existing behavior; server history is retained. - Account Library, Device Installation, project enablement, Agent assignment, runtime authorization, and billing are separate states. No read, install, acquisition, or assignment may silently advance another state. The code-owned project-wide identities @@ -144,7 +145,7 @@ - 已发布作品优先读取 `play_url`,只有字段缺失时才使用一个客户端版本的 `runtime_url` 回退。公共播放 URL 必须是 Works Square 同源 HTTPS、无 userinfo/loopback、精确 `/apps/{encodeURIComponent(app_id)}/`、无 query/fragment,且上游明确 `playable === true` 并提供非空版本名;否则按不可播放处理。 - `works-cloud-deploy.json` 仅是已安装客户端的数据兼容文件名,不表示客户端仍提供 cloud deployment coordinator。 - Works Square 会话按真实键盘、鼠标或触摸活动滑动续期,连续 7 天未使用才要求重新授权。 -- 账号词元点数只能通过 Main-owned Works Square V2 余额路由投影。只有 `can_manage_membership=true` 的账号可向 Renderer 暴露套餐、周期、本周/永久/总点数;其他账号的这些字段必须统一为 `null`,并只以 `shared_available` 表达是否可用。格式或枚举不符合闭合 DTO 时整份响应 fail closed。 +- 账号词元点数通过 Main-owned Works Square 账务路由投影;本人精确余额与另一付款方的粗粒度余额遵循上述永久点数规则。格式或枚举不符合闭合 DTO 时整份响应 fail closed,不透传上游内部账务字段。 - “记住密码”是独立于七天会话的可选桌面凭据记录:只能由 Electron Main 在正式安装包中通过可用的系统安全存储加密落盘,账号密码不得进入 Renderer 持久状态、日志或 Works Square 持久化。退出登录和短信登录保留记录;只有成功的未勾选密码登录清除旧记录。系统安全存储不可用或未打包开发版必须禁用该选项。 - 运营端可按用户关闭 Code、Canvas 或 Robot 客户端入口,默认全开。Makelore 通过 Main-owned `/api/auth/me` 只消费三布尔安全投影;缺失 `module_access` 或字段按开启处理,服务端 `design` 对应现有客户端 `painting`,额外旧字段被忽略。 - 关闭的模块卡片必须置灰且无法点击;其根路由、深层路由和别名路由必须在 `MainLayout` 或模块初始化前阻断。Code provider 只能在 auth policy hydration 完成且 Code 已开启时初始化;`/settings` 是全局设置,不得随 Code 关闭而失去访问。 @@ -211,4 +212,4 @@ ## Last Reviewed -2026-09-07 +2026-09-22