merge: integrate remote learning module safely
Electron E2E / Electron E2E (macos-latest) (push) Has been cancelled
Electron E2E / Electron E2E (ubuntu-latest) (push) Has been cancelled
Electron E2E / Electron E2E (windows-latest) (push) Has been cancelled

This commit is contained in:
brother7 committed 2026-08-17 01:05:49 +08:00
commit f7171a471a
125 files changed
+11451 -12132

No files matched your search

@@ -23,6 +23,8 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展
| AI Design Gateway Routing | Main 云端适配器 ↔ Conversation WebSocket;Main → Host API/SSE → Renderer store | 命令、Run 与设计事件共用双向 WebSocket;Conversation 更新按 Workspace + Conversation 路由,任务更新按 Workspace 归并 |
| AI Design Quote & Task Controls | 当前 Conversation Quote 与 Workspace 任务 | 最终 Prompt/generation options 每次修改由服务端重新计价;任务结果在详情中预览并经 Main-owned asset download 保存 |
| Prompt Museum | Canvas “获取灵感”页面 → Main Host API → Works Square | 服务端驱动的审核内容、筛选和分页;Renderer 不持有 Works Token 或内置数据集,“使用此 Prompt”只回填输入框 |
| Learning Workspace | 课程广场、生成工作台与本地课程播放器 | Renderer 只持有安全课程/进度/任务状态;材料字节、课程归档、播放器产物和云端凭据由 Main 持有 |
| Learning Main Boundary | Host API + bounded IPC services → Works Square / account-partitioned verified local course library | 课程 API、生成、下载、Agent、ASR 与固定 runtime capability 由 Main 执行;课程包和 production Stage artifact 在使用前校验,账号切换使旧本地库、player registration 与迟到结果失效 |
| Robot Workspace | Account-scoped agent configuration, device activation/binding, assignment, and credential-recovery UI | Renderer receives only safe Works Square projections. Configuration choices come from the USER-scoped safe catalog; unavailable current values remain editable without exposing provider credentials or configuration internals. |
| AI Hardware Main Route | Fixed `/api/works/ai-hardware` Host API to Works Square proxy | Main owns Bearer auth, stable operation IDs, bounded retry, ETag/If-Match, request/response limits, error redaction, and the fixed no-store configuration-catalog proxy. Versioned responses accept only canonical strong or weak numeric ETags that equal the DTO revision; mutations always emit strong `If-Match`. It never forwards Renderer authorization headers. |
@@ -31,10 +33,11 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展
## Important Boundaries
- Robot is the single enabled hardware product module; there is no separate Hardware card. Learning remains disabled.
- Code、Canvas、Learning 与 Robot 是四个已启用顶层产品模块;Robot 仍是唯一硬件产品模块,不存在单独 Hardware 卡片。
- Product UI language is Chinese-only. Unsupported system or persisted language values normalize to `zh`; removed locale files are not runtime fallbacks.
- Packaged Canvas remains cloud-only with no local fallback. `pnpm run dev` now uses the cloud adapter; the local Workspace adapter requires the explicit development command and remains unpackaged-only.
- Prompt Museum is a read-only curated inspiration surface, not a user-content community. Main owns Works authentication and forwards only the bounded list/detail routes; the client never bundles museum content or automatically submits a selected Prompt.
- Learning uses a Main-owned cloud and local-package boundary. Renderer does not receive Works credentials, archive paths, provider/model configuration, or an arbitrary network proxy. Main derives an opaque account partition from the authenticated identity, bounds same-origin archive redirects and package extraction, and serves registered course assets only from an account-bound loopback player with exact-origin and nonce checks; classroom runtime is limited to explicit capabilities and aggregate-course identity.
- AI hardware network access is Main-owned. Renderer cannot hold Works Square or Xiaozhi credentials and cannot select arbitrary upstream paths or headers.
- Robot model, language, and voice choices are dynamically projected from the Xiaozhi USER catalog through Works Square and Electron Main; the catalog is bounded, account-scoped, and `private, no-store` at each public hop.
- One local account maps to one server-side Xiaozhi account binding. Agents and devices are resources beneath that account binding, not separate Xiaozhi users.