merge: integrate remote project scaffold updates
This commit is contained in:
commit
a2cb07fedc
60 files changed
+2909
-141
No files matched your search
@@ -53,16 +53,25 @@
|
||||
Inspect/preview and a distinct later confirmation precede commit; there is no visible
|
||||
install/source-picker UI. Accepted npm, Git, absolute local Plugin-directory, and loose
|
||||
`SKILL.md` sources become immutable generations and default enabled. Lifecycle scripts
|
||||
never run. Pi extensions execute with desktop-user authority after that fact is shown
|
||||
in confirmation. New and idle parent workers refresh automatically, active parents
|
||||
switch only after settlement, and child workers never inherit Device Package resources.
|
||||
never run. Pi extensions and non-empty standard Skill `scripts/` subtrees are executable
|
||||
code and execute with desktop-user authority only after that fact is disclosed and
|
||||
confirmed. Parent Pi workers and the shared Agent Server receive the non-overridable
|
||||
application Node path as `MAKELORE_NODE_EXECUTABLE`; portable Skills must not fall back
|
||||
to system Node. New and idle parent workers refresh automatically, active parents switch
|
||||
only after settlement, and child workers never inherit Device Package resources.
|
||||
- Device Packages appear as a separate `本机` source beside Official Plugins in the
|
||||
unified `/plugins` workspace and never enter Account Library, Marketplace Package
|
||||
Store, Release, Channel, Admission, project enablement, Agent assignment, or server
|
||||
billing state.
|
||||
- 面向用户的 AI 编程新建流程必须在 `mini_game`、`mini_program`、`custom` 中选择;`ProjectType` 是产品类型,创建后不能通过 UI 或 Host API 修改,未传类型的兼容 API 调用按 `custom` 处理。
|
||||
- 新建小游戏和小程序会生成平台固定版本的受控 Vite 发布模板,并可使用项目配置中的单一“提交审核”入口;`custom` 和缺少类型字段的旧项目不提供一键发布。
|
||||
- `ProjectType` 不等于 `BuildPreset`:第一期两个可发布产品类型都映射到内部受控 Vite preset;本地 `projectType` 不是授权边界,Main-owned 安全打包、Host API 和服务端包体校验仍必须执行。
|
||||
- Code-owned official bundled Plugins may be `platform_hosted` or `skill_only`.
|
||||
`makelore.project-scaffold` retains Account Library, project enablement, Agent
|
||||
assignment, Release, and Admission state while its exact Skill/templates/`.mjs`
|
||||
ship only in the signed client. Downloadable Marketplace artifacts remain P0
|
||||
text/image-only and must reject `.mjs`; official bundled authority is not inferred
|
||||
from provider metadata or an uploaded ZIP.
|
||||
- 面向用户的 AI 编程新建流程必须在 `interactive_ai_app`(“交互式 AI 应用”)和 `custom` 中选择;`ProjectType` 是产品类型,创建后不能通过 UI 或 Host API 修改。历史 `mini_game` / `mini_program` 仅在读取边界归一为 `interactive_ai_app`,读取本身不改写配置;未传类型的兼容 API 调用按 `custom` 处理。
|
||||
- 新建项目只原子生成 `.makelore/project.json` 和 `knowledge/`。交互式 AI 应用的固定六文件 Vite 起步树只能由用户明确调用官方 bundled `makelore.project-scaffold` Plugin 中的 `makelore-project-scaffold` Skill 生成;脚本必须先预检全部目标、不得覆盖已有路径,受控失败只回滚本次创建内容,且不得安装依赖、访问网络、构建、上传或提交审核。
|
||||
- `ProjectType` 不等于 `BuildPreset` 或 Scaffold 状态:规范可发布类型映射到内部受控 Vite preset;本地 `projectType` 和 Skill 检测结果都不是授权边界,Main-owned 安全打包、Host API 和服务端包体校验仍必须执行。
|
||||
- 非专业用户只执行一次“提交审核”;构建通过后由运营审核,审核通过即直接发布。
|
||||
- 创建者发布唯一链路是项目配置“一键提交审核” → Main 本地 npm/Vite 构建 → 最终 built snapshot 的客户端 UX 预检 → source+built+artifact contract 上传 → 服务端校验/固化 → 运营审核;不恢复独立发布上传页、云部署工作台、Compose/deploy-check、自动 watcher/arm/upload 或手工 ZIP 入口。
|
||||
- 本地构建必须由 Main 对安全源码快照使用安装版 Electron Node 和固定 npm 11.6.2 执行 `npm ci --ignore-scripts`,再显式调用项目 `package-lock.json` 安装的 Vite;不得依赖全局 PATH、既有 `node_modules` 或 Renderer 提供的任意路径/origin。
|
||||
|
||||
Reference in new issue
Block a user