docs(integration): record remember password boundary
Electron E2E / Electron E2E (macos-latest) (push) Has been cancelled
Electron E2E / Electron E2E (ubuntu-latest) (push) Has been cancelled
Electron E2E / Electron E2E (windows-latest) (push) Has been cancelled

This commit is contained in:
brother7 committed 2026-08-20 23:45:13 +08:00
1 parent 2b9f84e3eb
commit eedd20d061
5 files changed
+70 -1

No files matched your search

+11
View File
@@ -4,6 +4,15 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Remember-password source commit `990639f` from feature task
`20260820-makelore-remember-password-b63e1c` was merged into local `main` as
`2b9f84e` by integration task `20260820-integrate-remember-password-5d7e3a1c`.
Password login now offers an optional Main-owned remembered credential: packaged
builds encrypt the username and password through OS-protected storage, Renderer
persistence and Works Square never receive that record, and unavailable secure
storage disables the option. Logout and SMS login preserve it; a successful
unchecked password login clears it. Packaged Windows and signed macOS smoke remain
pending.
- OpenCode Session model and partner hot-add source commit `c0163bc` from feature task
`20260820-session-model-agent-hotfix-6e4c9a2f` is integrated on local `main` by task
`20260820-integrate-session-model-hotfix-7b3e91c4`. Page selection and `/models` /
@@ -101,6 +110,8 @@ AI 绘画的一个 Workspace 可包含多条 Conversation。消息、Brief、Quo
Canvas 侧栏提供“获取灵感”进入 Prompt Museum。列表、筛选、分页、详情、作者/来源/许可证和图片地址全部由服务端经 Main-owned Host API 提供,客户端不打包静态数据集;服务端相对媒体只允许固定 `/api/image-prompt-museum/{entry}/media/{thumbnail|number}` 形状,并由 Main 注入 Works Bearer、执行一次 401 刷新、可信 raster MIME 与 10 MiB 上限后转为 Renderer data URL;credential-free HTTPS CDN 图片保持直连。图片失败只显示卡片内占位,不阻断卡片或详情;缺少来源 URL 时显示纯文本。“使用此 Prompt”只把原文带回当前 Canvas 输入框,不自动发送。该模块不是投稿、点赞、评论或排行榜社区。客户端契约已就绪,但不据此宣称 Works Square 内容后台和生产数据已经部署。`pnpm run dev` 现在默认使用云端 Canvas 适配器,本地适配器只能通过显式开发命令启用;产品 UI 只保留中文。
密码登录提供可选“记住密码”。该记录与七天登录会话分离,只在正式安装包且系统安全存储可用时由 Electron Main 加密落盘;Renderer 仅在登录页内存中接收回填,不写 Zustand/localStorage,Works Square 也不持久化桌面密码。退出登录和短信登录不删除记录,成功的未勾选密码登录会清除旧记录。未打包开发版禁用该选项,避免未签名 Electron 调试进程触发 macOS 钥匙串。
Makelore 在会话恢复、登录和刷新后由 Electron Main 请求 Works `/api/auth/me`,Renderer 只获得 Code、Canvas、Learning、Robot 四个布尔权限。缺失 `module_access` 或任一字段时默认开启;服务端 `design` 显式映射客户端 `painting`。被关闭的模块卡片置灰且不可点击,根路由、深层路由和别名路由均在 `MainLayout` 或模块初始化前阻断。Code provider 等待认证权限加载完成;权限查询返回终止性 `401` 时同时清理 Main 和 Renderer 会话。`/settings` 是全局设置,不受 Code 入口策略阻断。该机制只是客户端入口策略,不代替服务端 API 授权。
AI 学习现在是已启用的运营精选项目目录,并继续受登录和 `module_access.learning` 控制。Renderer 通过 Main-owned Host API 获取分页项目卡片和 README 详情;Markdown 支持 GFM、禁用原始 HTML。服务端发布时只校验图片 URL 为无凭据、默认端口、无 fragment 且当前 DNS 结果全部为公网地址的 HTTPS URL,保留地址而不下载、识别格式、转码或镜像;客户端仅为 README 图片节点启用直连,因此 SVG 和 Electron 支持的其他格式可直接显示,单图失败不阻断详情。封面和历史发布媒体继续走受控路径。详情页的下载按钮打开系统保存对话框;Main 将 ZIP 流式写入临时文件,只允许最多五跳同 Works origin 重定向,不校验 `Content-Length`、`archiveBytes`、实际流字节数或客户端大小上限,校验 SHA-256 和 ZIP 签名后原子保存,Renderer 只接收 `saved` 或 `cancelled`。课程生成、进度、本地课程库、OpenMAIC player、Agent、ASR、课堂 runtime、Learning IPC 和 player artifact 打包已删除且没有兼容读取路径;历史课程数据保留但不再读取。服务端和客户端源码契约已完成,不代表生产部署或真实账号安装包联调已经完成。
@@ -0,0 +1,51 @@
# Task: Integrate remember password into main
## Identity
- Task ID: 20260820-integrate-remember-password-5d7e3a1c
- Mode: Integration
- Branch: main
- Worktree: D:\Datas\OthersProjects\makelore
- Base commit: 460268586bddbbf75a557012ec872851fca555a5
- Owner: codex
- Status: Blocked
## Scope
- Integrate verified remember-password source commit `990639f` into local `main`.
- Reconcile the source task's accepted authentication promotion candidates into canonical current-state, architecture, ADR, and domain documents.
- Preserve the pre-existing untracked packaging task record without modifying or committing it.
## Intent And Constraints
- Keep remembered credentials separate from the existing seven-day Works Square session.
- Keep password persistence Main-owned and OS-encrypted in packaged builds; do not persist passwords in Renderer or Works Square.
- Preserve logout/SMS retention and successful unchecked-password-login clearing semantics.
- Merge only to local `main`; do not push.
## Outcome
- Source feature commit `990639f` was created from the completed isolated feature worktree.
- Merged the source branch into local `main` as merge commit `2b9f84e` without conflicts; README auto-merged with the already integrated Session-model documentation.
- Promoted the accepted remembered-password boundary into `current-state.md`, `system-overview.md`, ADR-004, and `business-rules.md`.
- Preserved `.project-docs/30-worklog/tasks/20260819-package-learning-off-115-9c4d.md` untouched and untracked.
## Verification
- Source verification: 79 focused tests, typecheck, scoped ESLint, and Vite Renderer/Main/Preload/utility build passed.
- Integrated local `main`: 4 focused test files / 79 tests passed.
- Integrated local `main`: `pnpm run typecheck` passed.
- Integrated local `main`: scoped ESLint passed with zero errors.
- Integrated local `main`: Renderer/Main/Preload/utility `pnpm run build:vite` passed with existing dynamic-import and large-chunk advisory warnings only.
- `git diff --check` passed with line-ending conversion notices only.
- Required project-docs structure check passed.
- Task-aware documentation drift is blocked by two read-only foreign task records: the pre-existing, explicitly preserved untracked `.project-docs/30-worklog/tasks/20260819-package-learning-off-115-9c4d.md`, and the source task record `.project-docs/30-worklog/tasks/20260820-makelore-remember-password-b63e1c.md` introduced unchanged by merge commit `2b9f84e`. The integration did not modify either record. The checker also lists the expected merged source files as non-document changes.
## Follow-ups
- Run packaged Windows and signed macOS smoke for OS-protected save, restart prefill, successful unchecked-login clear, and no development Keychain prompt.
- Resolve the repository's integration drift-check handling for unchanged source task records and decide the separately owned untracked packaging record before this integration ownership can be completed and released cleanly.
## Promotion Candidates
- Applied all accepted source candidates; none remain pending.