merge: require cover for first project submission
This commit is contained in:
@@ -4,6 +4,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
|
||||
## Integrated Through
|
||||
|
||||
- Project-cover source commit `145a6ce571d646325092d1e722282babea503954` from feature task `20260817-project-cover-upload-a6a98e56`, integrated by task `20260813-sync-push-main-9c2f71`. First submission now requires a bounded PNG/JPEG/WebP cover, shows preview/file/reselect feedback, and sends metadata plus cover through Main-owned `POST /api/projects/with-cover`; conflicts stop before version upload and existing draft/published projects remain version-only. The matching Works Square server source is `407c883` (local merge `0cedfc4`). No client package, production deployment, or real-account smoke occurred.
|
||||
- `3b37ac3` / `55e61b7`: macOS Robot hotspot discovery performs one bounded worker-thread rescan after an empty or SSID-redacted CoreWLAN result; persistent SSID redaction maps to the existing permission error instead of a misleading empty-device state, while firmware and the open `Xiaozhi-*` contract remain unchanged.
|
||||
- `f5d47c8` / `b6148a5`: AI Programming voice capture is available after an Agent is selected but before the lazy first OpenCode session exists; transcription fills the composer draft without creating an empty session, while runtime, loading, transcribing, busy, and recording guards remain unchanged.
|
||||
- `4013edc` / `3b799af`: integrated per-user Code/Canvas/Learning/Robot entry policy from Works Square, projected by Electron Main as four booleans and enforced before disabled module routes initialize.
|
||||
@@ -49,9 +50,10 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
|
||||
|
||||
## Recently Completed
|
||||
|
||||
- 2026-08-17: Replaced the temporary coverless-first-create fallback with a required PNG/JPEG/WebP picker, preview, file name, reselect action, Renderer/Main signature and size validation, and one Main-owned multipart metadata-plus-cover create request. Create conflicts fail before version upload; existing project metadata and covers remain unchanged.
|
||||
- 2026-08-17: Corrected macOS Robot hotspot discovery after a system-visible `Xiaozhi-*` report. CoreWLAN now gets one bounded retry when its first result is empty or all SSIDs are unavailable; a persistent non-empty redacted result becomes the existing safe permission state. Open-only filtering, firmware, Host/Renderer contracts, exact-current-SSID verification, and the system-Wi-Fi fallback are unchanged; signed-package physical smoke remains pending.
|
||||
- 2026-08-17: Created merge commit `4013edc` for the reviewed per-user module-entry policy source tip `3b799af`. Main exposes only four booleans from `/api/auth/me`; missing fields remain enabled, `design` maps to `painting`, disabled root/deep/alias routes stop before module initialization, Code provider startup waits for policy hydration, terminal `401` clears both session layers, and global settings remains reachable.
|
||||
- 2026-08-17: Integrated remote `01bee31`: Learning is enabled with course browsing, strict bounded generation materials, verified atomic course installation, multi-module playback, Main-owned Agent/ASR/runtime bridges, and a manifest-verified external OpenMAIC player artifact. Merge review added account-isolated generation/library/player state, fixed-binding token/fetch/401 guards, passive-only course media with hardened responses, pre-existing active-registration checks before side-effect-free identity resolution, nonce-protected single-document player sessions, and a recoverable deep-link profile error gate. Publishing now reflects the actual Works contract: first create is coverless, existing draft/published are version-only, and races fail closed without cover/PATCH side effects. The transient `game-engine` Skill was removed and `planning-with-files` writes its files to the project root. Production Works/player-artifact/signed-package acceptance remains pending.
|
||||
- 2026-08-17: Integrated remote `01bee31`: Learning is enabled with course browsing, strict bounded generation materials, verified atomic course installation, multi-module playback, Main-owned Agent/ASR/runtime bridges, and a manifest-verified external OpenMAIC player artifact. Merge review added account-isolated generation/library/player state, fixed-binding token/fetch/401 guards, passive-only course media with hardened responses, pre-existing active-registration checks before side-effect-free identity resolution, nonce-protected single-document player sessions, and a recoverable deep-link profile error gate. At that integration checkpoint, publishing used a coverless first create, existing draft/published were version-only, and races failed closed without cover/PATCH side effects; project-cover source `145a6ce` and matching server merge `0cedfc4` above supersede only the coverless-first-create limitation. The transient `game-engine` Skill was removed and `planning-with-files` writes its files to the project root. Production Works/player-artifact/signed-package acceptance remains pending.
|
||||
- 2026-08-16: Integrated remote `26b52d7`: Canvas now has server-backed Prompt Museum navigation, editable server-repriced generation Quotes, task result details/downloads, guarded project deletion, cloud-default development, and Chinese-only UI. That tip briefly bundled `game-engine`; authoritative successor `01bee31` removed it. Client integration is verified separately from production Prompt Museum data/backend deployment.
|
||||
- 2026-08-16: Integrated Windows/macOS in-page Robot hotspot discovery, explicit selection, connection, and exact-current-SSID verification behind the existing default-on guided capability. Candidate IDs are bounded and short-lived, native diagnostics stay in Main, system settings remain fallback, and firmware/Portal/Binding contracts are unchanged.
|
||||
- 2026-08-16: Enabled the existing Guided Hotspot Binding journey by default after explicit product confirmation. Exact `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` remains the operational rollback; fixed portal ownership, direct-code fallback, security warnings, firmware-zero-change, and Binding-without-online semantics are preserved.
|
||||
@@ -91,7 +93,7 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
|
||||
|
||||
- 四模块权限只控制 Makelore 客户端入口和初始化,不是 API 授权边界。不得因卡片置灰或路由阻断而放宽 Works/模块服务端的身份与权限校验;旧服务端缺少对象/字段时默认开启是显式兼容策略。
|
||||
- Learning 的课程目录、生成、Agent、ASR 与 runtime 都依赖真实 Works 权益和服务端契约;本地课程归档与播放器 artifact 必须在信任前完成边界、大小与摘要校验。账号分区/epoch、fixed-binding token+fetch guards、同源重定向、512 MiB 上限、player nonce、exact source/origin 与单文档 bridge 边界不可放宽;不得把模块/场景自报身份当成 aggregate 课程权益,也不得把上游错误、Token、内部 URL 或本地归档路径投影到 Renderer。
|
||||
- Works Project 服务当前没有 metadata revision/ETag、draft-only 条件写或封面删除/原子绑定合同;首次发布暂不上传封面,已有 draft/published 只允许 version-only。恢复封面或已有资料编辑前必须先扩展并真实验证服务端原子合同,客户端不得以无条件 PATCH 或孤立上传替代。
|
||||
- Works Project 首次封面已由服务端源 `407c883`(本地 merge `0cedfc4`)提供单请求原子绑定与失败补偿,客户端源 `145a6ce` 因此要求首次发布上传 PNG/JPEG/WebP 封面;部署、安装包和真实账号/对象存储 smoke 仍未完成。服务端仍没有已有 metadata 的 revision/ETag 与 draft-only 条件写,因此已有 draft/published 继续只允许 version-only,客户端不得以无条件 PATCH 替代。
|
||||
- Guided Hotspot Binding 默认开启并提供未经认证的热点扫描/显式连接,但当前 Hotspot/portal 仍是开放 SoftAP + 明文 HTTP,且精确出货镜像、激活码发行契约、签名 macOS、Windows 真机与完整整链尚未验证。界面必须保留环境警告,异常发布可用精确环境值 `0` 回滚;不得把 SSID 前缀宣称为可信设备发现、自动认领或在线证明。
|
||||
- 一键提交已成功但本机 submission binding 落盘失败时必须保持提交成功、显示固定 `binding_warning` 并继续轮询,避免用户误判上传失败。
|
||||
- 公共 `play_url` 必须满足 Works Square 同源 HTTPS、无 userinfo/loopback、精确 `/apps/{app_id}/` 路径、无 query/fragment、版本非空且上游标记可播放。
|
||||
|
||||
@@ -309,6 +309,10 @@ Gate result:
|
||||
|
||||
## Outcome
|
||||
|
||||
- Prepared a normal no-ff merge of project-cover source `145a6ce571d646325092d1e722282babea503954` onto local `main` `da376b0bf37cdd0b5eabe7efc9f1141ae5645411` with no textual conflicts; the source feature task record remains only on the source branch.
|
||||
- Reconciled the obsolete coverless-first-create rule into required first-cover atomic submission while retaining existing-project version-only behavior and the unfulfilled conditional metadata-editing commitment.
|
||||
- Final project-cover merge commit is pending independent read-only review.
|
||||
|
||||
- Created local main merge commit `3b37ac318782de5ee6f3338c9744ec66df14f674` with exact parents `7e8d9e38114158992c03e589de32535274796d04` and reviewed source `55e61b7d8f9caccdad54dc9a42092fc7960fb394`. The source is now a `main` ancestor, and its task record remains absent from the integrated tree.
|
||||
- On 2026-08-17, staged a normal no-ff merge of reviewed macOS Robot hotspot source `55e61b7` onto clean local `main` at `7e8d9e3`; Git reported no textual conflicts. The source task record remains reachable on its source commit/branch and is excluded from the integrated tree.
|
||||
- The staged tree performs exactly one 250 ms worker-thread rescan when the first macOS CoreWLAN result is empty or every returned SSID is unavailable. A recovered candidate continues through the unchanged open/printable `Xiaozhi-*` Module filter; two empty scans remain an empty result; a second non-empty fully redacted result becomes the existing fixed permission error.
|
||||
@@ -326,7 +330,7 @@ Gate result:
|
||||
- Added a real Electron Learning navigation smoke and corrected three OpenCode slash-command E2E setup races by entering Code through the module chooser after setup. Production behavior was unchanged by the OpenCode test correction.
|
||||
- Fixed the repository E2E script to invoke the declared `@playwright/test@1.59.0` CLI directly. The prior `pnpm playwright test` path selected a transitive alpha `playwright` CLI from `@playwright/mcp`, producing a false version-mismatch failure.
|
||||
- The first independent final Learning merge review returned `FAIL` on four P1, three P2 and one P3 findings: Renderer-self-asserted course identity, account-switch token TOCTOU, old player/progress/form reuse, same-origin navigation bridge recovery, overlay-only profile gating, non-authoritative published status, premature documentation claims, and direct Renderer event IPC. The merge now revalidates installed/registered course identity in Main, threads captured binding guards through token/fetch/401 boundaries, closes and rotates player sessions, partitions/clears Renderer state, permanently disables a navigated iframe bridge, blocks Learning Outlet execution until profile readiness, re-reads strict project status after 409, corrects canonical nonce wording, and routes events through an allowlisted API-client seam.
|
||||
- The second independent Learning merge review returned `FAIL` on two P1 and four P2 findings: Agent/runtime could register the requested course before checking active-player identity; executable same-origin course assets could message before a second iframe load; profile sync errors could leave an empty deep link; Works cover/metadata lacked atomic concurrency; material-generation IPC was not fully strict; and canonical evidence overclaimed closure. The final code separates side-effect-free `resolveClassroom` from explicit player registration, validates pre-existing active registration before Agent/runtime resolution, restricts course media to exact passive MIME/extension pairs with nosniff/sandbox CSP, renders a retryable profile error gate, strictly projects generation upload DTOs before auth/network, and adopts an honest coverless-first-create / existing-version-only Works workflow whose races fail closed without cover or PATCH side effects.
|
||||
- The second independent Learning merge review returned `FAIL` on two P1 and four P2 findings: Agent/runtime could register the requested course before checking active-player identity; executable same-origin course assets could message before a second iframe load; profile sync errors could leave an empty deep link; Works cover/metadata lacked atomic concurrency; material-generation IPC was not fully strict; and canonical evidence overclaimed closure. The final code separates side-effect-free `resolveClassroom` from explicit player registration, validates pre-existing active registration before Agent/runtime resolution, restricts course media to exact passive MIME/extension pairs with nosniff/sandbox CSP, renders a retryable profile error gate, strictly projects generation upload DTOs before auth/network, and at that checkpoint adopted a coverless-first-create / existing-version-only Works workflow whose races failed closed without cover or PATCH side effects. The current project-cover resumption supersedes only that coverless-first-create checkpoint.
|
||||
- The third independent Learning merge review returned `FAIL` on one P2 integration mismatch: the package consumer admitted `fonts/*`, while the player server only routed `audio|media`, so a declared playable font would install and then 404. Consumer and server now share the exact root/module `audio|media|fonts` directory contract and passive extension/MIME set; unsupported directories fail installation/HTTP lookup, and real registered ZIP-to-HTTP tests verify root WOFF and module WOFF2 with the expected MIME and security headers.
|
||||
- The fourth independent Learning merge review returned `FAIL` on one remaining P2 composition bug: allowing a manifest-relative `modules/<id>/...` path caused the authoritative module root to be prepended twice. Manifest media paths now begin only with relative `audio|media|fonts`; the module prefix comes solely from `location.root`. A consumer-to-classroom-URL-to-registered-ZIP-to-real-HTTP test proves exactly one module prefix, correct WOFF2 bytes/MIME/security headers, and rejection of manifest-supplied `modules/` or other directories.
|
||||
- The fifth and final independent Learning merge review returned `PASS` on Standards and Spec with no P0-P3 findings. It confirmed the consumer-generated modular font URL traverses the registered ZIP and real player HTTP response with one module prefix, and found no regression in registration, media safety, profile recovery, Works version-only behavior, generation DTOs, identity guards, canonical documents, packaging, Robot/Canvas, or the lock graph.
|
||||
@@ -442,6 +446,10 @@ Gate result:
|
||||
|
||||
## Verification
|
||||
|
||||
- Project-cover source verification: 3 focused Vitest files / 76 tests, typecheck, scoped ESLint, Vite production build, focused Electron E2E 1/1, and cross-repository Sol review all passed.
|
||||
- Project-cover merged tree: 3 focused Vitest files / 76 tests, `tsc --noEmit`, scoped ESLint, Renderer/Main/Preload Vite production build, and focused Electron E2E 1/1 all passed; build emitted only the existing dynamic-import and chunk-size warnings.
|
||||
- `check_project_docs.py`, task-aware `check_doc_drift.py`, and `git diff --cached --check` passed for the prepared project-cover merge.
|
||||
|
||||
- Post-commit topology confirms merge `3b37ac3` has exact parents `7e8d9e3` and `55e61b7`, the source tip is a `main` ancestor, the source task record is absent from `main`, and the product worktree was clean before this evidence-only documentation update.
|
||||
- 2026-08-17 independent final macOS Robot hotspot staged-merge review — Standards `PASS`, Spec `PASS`, overall `PASS`, with no P0-P3 findings. It confirmed exact staged topology/scope, source-record exclusion, bounded worker-only retry, retained 8s abort/termination, unchanged filtering/connect contracts, and honest signed-macOS physical-smoke residual risk.
|
||||
- 2026-08-17 macOS Robot hotspot staged-merge regression — `tests/unit/robot-hotspot-module.test.ts` passed 14/14, covering first-scan recovery, persistent SSID redaction, bounded double-empty behavior, security filtering, RSSI/current-SSID projection, worker termination, candidate expiry, exclusivity, and exact-current-SSID verification.
|
||||
@@ -589,7 +597,7 @@ Gate result:
|
||||
|
||||
- Before releasing the per-user module-entry policy, deploy the Works `module_access` migration and `/api/auth/me` contract, build and install a new Makelore package, then use a real account to disable Code, Canvas, Learning and Robot one at a time and smoke chooser/root/deep/alias behavior, global settings, terminal `401`, and independent server-side API authorization.
|
||||
- Before releasing Learning, run a real Works account through catalog, generation/material/cancel-resume, bounded download, offline multi-module playback, progress, Agent, ASR and PBL/scoring using the exact production Stage artifact. Validate packaged loopback cookie/nonce behavior on Windows and a signed macOS build; current automation is not that acceptance.
|
||||
- Before restoring project cover upload or editing metadata on an existing draft/published project, add and verify a server-owned revision/ETag plus draft-only conditional write and atomic cover attachment or cleanup. Until then the client intentionally creates new projects without a cover and treats existing projects as version-only.
|
||||
- First-project cover upload is implemented by client source `145a6ce` and server source `407c883` / local merge `0cedfc4`; before release, deploy the server, package the client, and verify a real account/object-store flow including create conflict, cover failure, and version-upload blocking. Editing metadata on an existing draft/published project still requires a server-owned revision/ETag plus draft-only conditional write; until then existing projects remain version-only.
|
||||
- Complete the visible Git Credential Manager/PowerShell authentication prompt, then fetch and verify `origin/main` equals the local tip before recording push completion and releasing this Integration task.
|
||||
- Packaging audit follow-ups outside this merge remain: verify macOS/Linux OpenCode multi-architecture staging, remove any unsupported Windows ARM64 advertising, pin the uv installer by digest, and replace unauthenticated curl-style installer paths before those release lanes are trusted.
|
||||
- Before releasing Prompt Museum and the expanded Canvas deletion/repricing workflow, use a real Works account to validate Museum list/detail/pagination/attribution/CDN content, latest Quote pricing/confirmation, project soft-delete visibility, queued reservation release, and running-task settlement. Client tests do not prove the content backend or production billing/deletion semantics are deployed.
|
||||
|
||||
Reference in New Issue
Block a user