@@ -4,6 +4,16 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Learning project-catalog source commit `38db158` from feature task
`20260819-learning-project-catalog-impl-4e9c71a2` was merged as `d967b0f` by integration task
`20260820-integrate-learning-catalog-a73e91c4`. Learning keeps its login and
`module_access.learning` gate but now contains only a server-driven project list,
safe README detail, controlled mirrored raster media, and a Main-owned verified
native ZIP save path. Course generation, progress, local library, OpenMAIC player,
Agent/ASR/classroom runtime, Learning IPC and player-artifact packaging were removed
without a compatibility read path. Historical course data is left untouched. The
matching Works Square operations/admin/API implementation and real-account package
smoke remain pending.
- Square-auth lifecycle source commit `dc776ff` from feature task
`20260819-square-auth-proxy-client-8c4f2a` was merged as `f52c2c8` and promoted
from verified candidate `e7ec12d` to local `main` by integration task
@@ -39,7 +49,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
-`3b37ac3` / `55e61b7`: macOS Robot hotspot discovery performs one bounded worker-thread rescan after an empty or SSID-redacted CoreWLAN result; persistent SSID redaction maps to the existing permission error instead of a misleading empty-device state, while firmware and the open `Xiaozhi-*` contract remain unchanged.
-`f5d47c8` / `b6148a5`: AI Programming voice capture is available after an Agent is selected but before the lazy first OpenCode session exists; transcription fills the composer draft without creating an empty session, while runtime, loading, transcribing, busy, and recording guards remain unchanged.
-`4013edc` / `3b799af`: integrated per-user Code/Canvas/Learning/Robot entry policy from Works Square, projected by Electron Main as four booleans and enforced before disabled module routes initialize.
-`01bee31`: enabled AI Learning course catalog/generation/download/playback, Main-owned cloud/runtime bridges, verified external OpenMAIC player-artifact packaging, account profile reuse, removal of the transient`game-engine`Skill, and project-root `planning-with-files`output from the authoritative remote main. The merge hardens this with strict DTO/error projection, account-isolated local state, bounded same-origin downloads/packages, a nonce-protected account-bound player HTTP session, and an exact-source/origin single-document iframe bridge.
-`01bee31`: historically enabled the AI Learning course catalog/generation/download/playback architecture. Its Learning course/runtime behavior is superseded by `38db158` above; its unrelated`game-engine`removal and project-root `planning-with-files`behavior remain historical context.
-`26b52d7`: Canvas Prompt Museum, editable server-priced generation Quotes, project deletion/task-detail workflow, cloud-default Canvas development entry, and Chinese-only UI consolidation from the authoritative remote main. Its transient bundled `game-engine` Skill is superseded by `01bee31`.
-`f8d82e6`: Prompt Museum media rendering now accepts only the server-controlled relative media route, fetches it through a Main-owned bounded Works-authenticated proxy with one refresh retry, and keeps credential-free HTTPS CDN media direct. Renderer-side validation and card-local placeholders cover invalid or failed media; attribution URLs remain optional.
-`c1326a2`: Guided Hotspot Binding now scans bounded open `Xiaozhi-*` candidates and connects the user-selected hotspot inside the page through Main-owned Windows WLAN and macOS CoreWLAN/CoreLocation adapters; system Wi-Fi remains fallback, exact `=0` rollback and firmware/cloud contracts are unchanged.
- 2026-08-20: Replaced AI Learning's course generation/player stack with the curated project catalog defined by ADR-005. The authenticated/module-gated client now renders project cards and safe README detail, proxies publish-time mirrored media through Main, and saves verified ZIP archives through the native dialog. Old course/runtime/player packaging was removed; full client verification passed before main promotion, while the external operations backend and real-account package smoke remain pending.
- 2026-08-19: Integrated native password/SMS login, the temporary HTTP/2-disabled diagnostic bootstrap, and the AI Design freeze fix. Workspace JSON calls and shared token refresh now settle within 30 seconds, transport abort is paired with deterministic rejection, and implicit Electron-to-Node fallback no longer replays mutation requests. Installed-client Quote retry/confirm smoke and the final HTTP/2 policy decision remain pending.
- 2026-08-17: Integrated application-side multi-Session isolation for AI Programming. Session A may remain busy while Session B is independently accepted or terminally rejected; errors, startup deadlines and uncertain-failure cleanup stay Session-scoped. Main now fail-closes stale Agent/provider runtime state before execution, applies bounded manager/project FIFO acceptance with revocable timeouts, and never refreshes the shared runtime automatically from ordinary execution paths. Full unit, typecheck, lint, build, focused Electron E2E and independent Sol review passed; a real paid-provider/bundled-runtime concurrency smoke remains pending.
- 2026-08-17: Replaced the temporary coverless-first-create fallback with a required PNG/JPEG/WebP picker, preview, file name, reselect action, Renderer/Main signature and size validation, and one Main-owned multipart metadata-plus-cover create request. Create conflicts fail before version upload; existing project metadata and covers remain unchanged.
- 2026-08-17: Corrected macOS Robot hotspot discovery after a system-visible `Xiaozhi-*` report. CoreWLAN now gets one bounded retry when its first result is empty or all SSIDs are unavailable; a persistent non-empty redacted result becomes the existing safe permission state. Open-only filtering, firmware, Host/Renderer contracts, exact-current-SSID verification, and the system-Wi-Fi fallback are unchanged; signed-package physical smoke remains pending.
- 2026-08-17: Created merge commit `4013edc` for the reviewed per-user module-entry policy source tip `3b799af`. Main exposes only four booleans from `/api/auth/me`; missing fields remain enabled, `design` maps to `painting`, disabled root/deep/alias routes stop before module initialization, Code provider startup waits for policy hydration, terminal `401` clears both session layers, and global settings remains reachable.
- 2026-08-17: Integrated remote `01bee31`: Learning is enabled with course browsing, strict bounded generation materials, verified atomic course installation, multi-module playback, Main-owned Agent/ASR/runtime bridges, and a manifest-verified external OpenMAIC player artifact. Merge review added account-isolated generation/library/player state, fixed-binding token/fetch/401 guards, passive-only course media with hardened responses, pre-existing active-registration checks before side-effect-free identity resolution, nonce-protected single-document playersessions, and a recoverable deep-link profile error gate. At that integration checkpoint, publishing used a coverless first create, existing draft/published were version-only, and races failed closed without cover/PATCH side effects; project-cover source `145a6ce` and matching server merge `0cedfc4` above supersede only the coverless-first-create limitation. The transient`game-engine` Skill was removed and `planning-with-files`writes its files to the project root. Production Works/player-artifact/signed-package acceptance remains pending.
- 2026-08-17: Integrated remote `01bee31`, which at that checkpoint introduced Learning course browsing/generation/install/playback and its OpenMAIC runtime boundary alongside unrelated repository consolidation. ADR-005 and source `38db158` supersede and remove that Learning course/runtime behavior; historical downloaded data remains untouched. The unrelated`game-engine` removal and project-root `planning-with-files`behavior remain current.
- 2026-08-16: Integrated remote `26b52d7`: Canvas now has server-backed Prompt Museum navigation, editable server-repriced generation Quotes, task result details/downloads, guarded project deletion, cloud-default development, and Chinese-only UI. That tip briefly bundled `game-engine`; authoritative successor `01bee31` removed it. Client integration is verified separately from production Prompt Museum data/backend deployment.
- 2026-08-18: Integrated Prompt Museum media rendering from `f8d82e6`: relative protected media is fetched through Main with bounded trusted-raster validation and one 401 refresh, HTTPS media remains direct, invalid/failed images are card-local placeholders, and missing attribution URLs render without broken links. Focused unit/Electron E2E, typecheck, scoped lint, and Vite build passed; real Works/CDN production smoke remains pending.
- 2026-08-16: Integrated Windows/macOS in-page Robot hotspot discovery, explicit selection, connection, and exact-current-SSID verification behind the existing default-on guided capability. Candidate IDs are bounded and short-lived, native diagnostics stay in Main, system settings remain fallback, and firmware/Portal/Binding contracts are unchanged.
- Base commit: 2cb8a7aef490b118a0968a5a77893f0cf4d3ebea
- Owner: codex
- Status: Ready for integration
## Scope
- Replace AI Learning's course catalog/generation/player product with a curated project catalog, project README detail, controlled README media, and verified user-selected ZIP download.
- Preserve the existing login and `module_access.learning` entry policy while replacing the Learning Renderer/Main contract without a legacy compatibility path.
- Remove obsolete course UI, DTOs, IPC, Main services, OpenMAIC player packaging hooks, and focused tests.
- Update the product README and add the Works Square operations/API contract because that backend source is not present in this repository.
## Intent And Constraints
- Renderer access remains behind `src/lib/host-api.ts`; Works credentials, arbitrary upstream URLs, object-storage credentials, and local filesystem paths stay Main-owned.
- README images must render only through HTTPS or fixed server-controlled project-media paths; server-controlled media is fetched through a bounded Main proxy and projected as a validated data URL.
- Project downloads use a native save dialog, stream to a temporary file, enforce declared byte size, SHA-256, ZIP signature, redirect/origin, and 512 MiB limits, then rename atomically.
- The new client never reads or migrates previously downloaded course data. It does not delete that historical user data automatically.
- Keep the Makelore light visual system and Chinese-only product copy. Do not restore Works gallery, publishing, or client-side upload workbench behavior.
- Operations backend implementation and deployment are external to this repository; do not claim them complete.
## Plan
1. Replace the shared Learning contract and Main Host API routes with project list/detail/media/download endpoints.
2. Rebuild the Learning Renderer as a project card grid plus Markdown detail page and simplify the Learning sidebar.
3. Delete old generation/player/local-library/runtime/IPC/package-artifact code and update app routing/layout.
4. Replace obsolete focused tests, update README and publish a precise Works Square admin/API contract.
5. Run focused tests, typecheck, lint, production build, then the task documentation gate.
## Outcome
- Replaced the Learning course/generation/player surface with an authenticated, permission-gated project catalog and `/learning/project/:projectId` README detail route.
- Added strict shared DTOs plus Main-owned Host API projection for project list, detail, bounded media proxy, and native ZIP download. Downloads are streamed to a temporary file and checked for account ownership, origin/redirect policy, size, ZIP signature, and SHA-256 before atomic rename.
- Added Markdown rendering with raw HTML disabled. README images are restricted to server-controlled project media paths; the external server contract requires operations to mirror remote HTTPS images at publish time.
- Removed the obsolete course library, generation, speech, runtime bridge, player server, package consumer, Learning IPC/preload channels, player artifact scripts, packaging resources, CI artifact steps, routes, and tests. Historical downloaded course data is neither read nor automatically deleted.
- Updated the product README and added `docs/learning-project-catalog-server-contract.md` for the external Works Square operations menu, upload fields, publishing validation, image mirroring, and API contract. That external backend/admin implementation is intentionally not claimed as complete in this repository.
## Verification
-`pnpm exec vitest run tests/unit/learning-client.test.ts tests/unit/learning-route.test.ts tests/unit/learning-project-download.test.ts tests/unit/learning-page.test.tsx tests/unit/learning-sidebar.test.tsx tests/unit/main-layout-module-gate.test.tsx tests/unit/app-module-provider-gate.test.tsx` — passed, 7 files / 47 tests after the final path-hardening change.
-`pnpm run typecheck` — passed.
-`pnpm test` — passed, 175 files / 2057 tests.
-`pnpm run lint:check` — passed with 0 errors and 6 pre-existing warnings outside this change.
-`pnpm run build:vite` — passed after the final change; existing bundle-size and mixed static/dynamic import warnings remain.
-`pnpm run test:e2e -- tests/e2e/main-navigation.spec.ts` — passed, 3 tests.
- Implement and deploy the operations admin/API contract in the external Works Square backend, then smoke-test list, README media, and ZIP download with a real account and published project.
- Decide separately whether a future maintenance release should offer an explicit user-controlled cleanup of historical downloaded course data; this task intentionally preserves it for recoverability.
## Promotion Candidates
- Target: `.project-docs/20-architecture/system-overview.md` and `.project-docs/20-architecture/data-flow.md`. Proposal: replace the Learning course/player architecture with the project catalog, bounded media proxy, and verified native download boundary. Evidence: implementation and focused/full verification above. Future impact: future Learning work must use the Host API and must not restore Renderer-held Works credentials or arbitrary download URLs. Semantic conflict: existing canonical Learning architecture still describes the removed player path. Human confirmation required: yes, during integration.
- Target: `.project-docs/40-domain/business-rules.md` and `.project-docs/00-brief/success-criteria.md`. Proposal: record Learning as a curated project catalog whose README images are mirrored by the server and whose downloads are user-selected ZIP files. Evidence: `README.md`, `docs/learning-project-catalog-server-contract.md`, and the new tests. Future impact: operations/backend and client changes share one publish/download contract. Semantic conflict: existing course-oriented rules are superseded. Human confirmation required: yes, during integration.
- Target: `.project-docs/80-commitments/commitments.md`. Proposal: record the external Works Square backend/admin implementation and real-account smoke test as an open integration commitment. Evidence: backend source is absent from this repository. Future impact: prevents treating the client-only delivery as an end-to-end production rollout. Semantic conflict: none known. Human confirmation required: yes, during integration.
- Base commit: 2cb8a7aef490b118a0968a5a77893f0cf4d3ebea
- Owner: codex
- Status: Planning
- Status: Completed
## Scope
@@ -27,16 +27,27 @@
## Outcome
-Not completed.
-Committed the verified feature work as `38db158` and merged it without conflicts as `d967b0f`.
- Promoted the confirmed product direction into accepted ADR-005, canonical architecture/data-flow/module maps, domain glossary/rules, success criteria, current state/history, and the release commitment ledger.
- Canonical Learning state now describes only the authenticated, `module_access.learning`-gated project catalog, safe README/media boundary, and Main-owned verified native ZIP save. The prior course-generation/OpenMAIC architecture is retained only as explicitly superseded history.
- Preserved the external Works Square operations/admin/API implementation and real-account Windows/signed-macOS smoke as pending work. Historical local course data remains untouched and unread by the new client.
-`pnpm run lint:check` — passed with 0 errors and the same 6 existing warnings.
-`pnpm run build:vite` — passed; existing mixed-import and chunk-size warnings remain.
-`pnpm run test:e2e -- tests/e2e/main-navigation.spec.ts` — passed, 3 tests.
-`git diff --check` — passed; only repository line-ending conversion warnings were emitted.
## Follow-ups
-None recorded.
-Implement and deploy `docs/learning-project-catalog-server-contract.md` in the external Works Square operations/backend repository before releasing this client.
- Perform real-account publication, README-media, archive-failure, native-save, Windows, and signed-macOS smoke before production rollout.
- Consider a separate explicit user-controlled cleanup feature if historical downloaded course data should later be removed.
## Promotion Candidates
- None recorded.
- None. The accepted source-task candidates were promoted in this integration task through ADR-005 and the canonical documents listed in Outcome.
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.