docs: integrate permanent point wallet into main

This commit is contained in:
brother7 committed 2026-09-22 12:03:43 +08:00
1 parent a1cce428af
commit 88800f9223
7 files changed
+102 -21

No files matched your search

+13 -12
View File
@@ -1,5 +1,16 @@
# Business Rules
## Permanent Token Points
- 账号不再具有会员或订阅等级、周额度或重置卡。真实新注册一次赠送 100 点;旧账号不补送、不折算,存量旧权益直接取消。充值 1 元人民币兑换 50 点,点数永不过期。所有资格、价格、余额、赠送和入账以 Works Square 为权威,客户端不以首次登录推测新注册或自行补点。
- 家长只给本人钱包充值。青少年可以看本人精确余额;另一付款方的共享钱包只展示可用性,不展示金额、点数或其账本。付款资格与余额可见性分别来自服务端,不再依赖旧会员管理权限。
- `family_shared=true` 不足以判定是否隐藏余额:付款方自己的钱包也可能带此标记。`shared_available` 为布尔值时投影另一付款方的粗粒度余额;为 `null` 时保留本人精确余额,包括 `entitlement_source=self` 或 `shared_group` 的本人家庭钱包。
- AI 编程明确选择付款来源,余额不足时不静默切换。云智能体仍由创建者付费,Plugin 仍用个人付款;共享付款不授予其他账号内容、订单或流水权限。
- 充值必须由用户明确发起,Renderer 不传付款人、价格或认证凭据。一次意图复用原请求身份;结果不明时只允许同身份重试,待支付或人工核对订单先恢复原订单。订单创建时冻结金额和点数,商品改价不改变旧单,服务端确认前不展示到账。
- Main 代理固定账务路由并投影公开字段,切换账号后丢弃旧结果;重新打开账号菜单或窗口获得焦点时刷新余额。移除旧重置卡卡包与兑换流程,历史任务记录不再定义当前权益。
依据:用户确认的永久点数政策、源 `a1cce42` 与[集成记录](../30-worklog/tasks/20260922-integrate-permanent-points-client-38f5b921.md)。
## Code conversation titles and archive
- 新建自动命名会话使用首条真实、完整、非空用户消息的首行,合并空白并截取最多 32 个 Unicode 字符;纯图片消息使用“附件对话”。斜杠命令、乐观消息和助手输出不触发命名;不调用模型生成标题。
@@ -20,16 +31,6 @@
- Marketplace Release A is curated: only Operations publishes packages. Users may
acquire an eligible Plugin for free; only server-declared metered operations may
later consume Token Points, and system-included Data Service remains zero-charge.
- Operations-granted reset cards are owner-scoped, expiring inventory and are distinct
from paid reset-card checkout, which Works Square fulfills immediately without
inventory. Renderer may display only the strict public card projection, derive an
elapsed available card as expired, and request redemption for the signed-in owner;
it must not calculate the reset allowance, expose internal grant/audit fields, treat
a shared wallet as redeemable, or claim success before Works Square confirms it.
Confirmed fulfillment refreshes both the card list and authoritative Token Point V2
balance. The account-menu inventory omits redeemed cards, including immediately
after confirmed redemption, and shows 暂无未使用的重置卡。 when no visible cards remain.
Available and expired cards keep their existing behavior; server history is retained.
- Account Library, Device Installation, project enablement, Agent assignment, runtime
authorization, and billing are separate states. No read, install, acquisition, or
assignment may silently advance another state. The code-owned project-wide identities
@@ -144,7 +145,7 @@
- 已发布作品优先读取 `play_url`,只有字段缺失时才使用一个客户端版本的 `runtime_url` 回退。公共播放 URL 必须是 Works Square 同源 HTTPS、无 userinfo/loopback、精确 `/apps/{encodeURIComponent(app_id)}/`、无 query/fragment,且上游明确 `playable === true` 并提供非空版本名;否则按不可播放处理。
- `works-cloud-deploy.json` 仅是已安装客户端的数据兼容文件名,不表示客户端仍提供 cloud deployment coordinator。
- Works Square 会话按真实键盘、鼠标或触摸活动滑动续期,连续 7 天未使用才要求重新授权。
- 账号词元点数只能通过 Main-owned Works Square V2 余额路由投影。只有 `can_manage_membership=true` 的账号可向 Renderer 暴露套餐、周期、本周/永久/总点数;其他账号的这些字段必须统一为 `null`,并只以 `shared_available` 表达是否可用。格式或枚举不符合闭合 DTO 时整份响应 fail closed。
- 账号词元点数通过 Main-owned Works Square 账务路由投影;本人精确余额与另一付款方的粗粒度余额遵循上述永久点数规则。格式或枚举不符合闭合 DTO 时整份响应 fail closed,不透传上游内部账务字段。
- “记住密码”是独立于七天会话的可选桌面凭据记录:只能由 Electron Main 在正式安装包中通过可用的系统安全存储加密落盘,账号密码不得进入 Renderer 持久状态、日志或 Works Square 持久化。退出登录和短信登录保留记录;只有成功的未勾选密码登录清除旧记录。系统安全存储不可用或未打包开发版必须禁用该选项。
- 运营端可按用户关闭 Code、Canvas 或 Robot 客户端入口,默认全开。Makelore 通过 Main-owned `/api/auth/me` 只消费三布尔安全投影;缺失 `module_access` 或字段按开启处理,服务端 `design` 对应现有客户端 `painting`,额外旧字段被忽略。
- 关闭的模块卡片必须置灰且无法点击;其根路由、深层路由和别名路由必须在 `MainLayout` 或模块初始化前阻断。Code provider 只能在 auth policy hydration 完成且 Code 已开启时初始化;`/settings` 是全局设置,不得随 Code 关闭而失去访问。
@@ -211,4 +212,4 @@
## Last Reviewed
2026-09-07
2026-09-22