feat(canvas): cut over design agent to living form v2

This commit is contained in:
2026-08-30 17:00:31 +08:00
parent f245603923
commit b0b5a602b5
35 changed files with 5729 additions and 13986 deletions

View File

@@ -0,0 +1,77 @@
# Proposal: Supersede AI Design multi-Conversation ownership with Living Form V2
## Source
- Task: `20260830-design-v2-client-cutover-4e7b9a2c`
- Mode: Feature
- Status: Proposed for Integration Gate review
## Decision Proposed
Supersede ADR-001. One AI Design Workspace owns one current Direction, one
persistent Agent Gateway Session, one Current Design Specification, its
conversation timeline, immutable generation Quotes, generation Tasks, and
Assets. Conversation remains an interaction history, not a separately created
or selected authority object.
The Living Form is a server projection of the Current Design Specification. A
chat turn, direct field edit, decision-prompt response, Agent proposal
acceptance, lock change, and restore action are inputs to the same reducer.
Renderer drafts are temporary buffers only. Scalar fields update explicitly;
identity-bearing collections are replaced atomically. Canonical revisions,
field decision resolution, provenance, locks, blockers, and recent changes come
only from the accepted server projection.
Generation is a separate compile-and-confirm boundary. The server compiles a
professional image or video instruction and returns an immutable Quote tied to
one exact Specification revision. The client displays the customer-facing
output plan, warnings, expiry, and design points, then confirms only the Quote
identity. Provider Prompt, model, route, storage location, safety evidence,
compiler internals, and billing atoms remain server-private.
Every mutation carries stable command and semantic operation identities. A
transport-unknown result keeps the exact command for safe replay; it is not
treated as a failed write and does not authorize a fresh generation operation.
Revision conflict refreshes canonical Workspace state while preserving local
drafts. Accepted writes have no client expiry. Event cursors are resumable, but
event transport order and Task progress never become Specification truth.
Canvas has one production authority: the Works Square V2 boundary owned by
Electron Main. There is no V1 DTO adapter, nested design-Conversation UI, local
semantic adapter, editable final Prompt, mutable Quote, or cloud-failure
fallback.
## Evidence
- Shared V2 contract: `shared/image-workspace.ts`.
- Main adapter and Host boundary:
`electron/image-workspace/works-square-workspace.ts` and
`electron/api/routes/image-workspace.ts`.
- Renderer authority and interaction model: `src/stores/image-workspace.ts` and
`src/pages/ImageCanvas/`.
- V1 local authority removed:
`electron/image-workspace/local-workspace.ts` and both image-workspace dev
mode scripts are deleted.
- Verification recorded in the source task: full typecheck, lint with zero
errors, 1,425 passing unit tests, production Vite/Electron build, and two
passing Electron Canvas E2E tests.
## Canonical Updates Requested
- Mark ADR-001 superseded and add an accepted Living Form V2 ADR.
- Replace AI Design ownership, routing, Quote, task, asset, and local-adapter
sections in `20-architecture/system-overview.md`, `data-flow.md`, and
`module-map.md`.
- Reconcile the AI Design integrated snapshot, constraints, and follow-ups in
`30-worklog/current-state.md` after the matching server and client commits are
integrated.
## Conflict And Confirmation
This proposal intentionally reverses ADR-001 and canonical documentation that
requires one Workspace to contain multiple independent Conversations and lets
the client edit the final Prompt before mutable re-quoting. The user explicitly
approved the complete Living Form hard cutover, no low-version compatibility,
and customer-first generation confirmation in the source task. Integration
must preserve that provenance by superseding ADR-001 explicitly, not by editing
its historical decision in place.