Files
makelore/.project-docs/10-decisions/adr-007-ai-design-living-form-v2.md
T

2.7 KiB

ADR-007: AI Design Living Form V2 authority

Status

Accepted / implemented

Date

2026-08-30

Context

ADR-001 modeled a Workspace as multiple independently selected Conversations, each with its own Brief, mutable Quote, and persistent Session. That split made chat, form edits, Quote options, and provider prompts competing representations of the same design. The coordinated Works Square and MakeLore V2 cutover now provides one versioned Design Specification and a persistent form throughout the design flow.

Decision

  • One Workspace exposes one current Direction, one persistent Agent Session, one Current Design Specification, one Living Form projection, one conversation timeline, immutable Quotes, Tasks, and Assets.
  • Chat, direct field edits, decision responses, accepted proposals, lock changes, Asset binding, and restore actions enter the same server-owned reducer. Renderer drafts are temporary buffers and never semantic authority.
  • Every mutation carries stable command and semantic operation identities. An unknown transport result keeps the same command for replay; revision conflicts refresh canonical state without discarding local drafts.
  • Generation is a compile-and-confirm boundary. The server returns an immutable Quote for one exact Specification revision; the client displays the public output plan, warnings, expiry, and Token Point amount and confirms only the Quote ID. Provider prompts, models, routing, storage, safety evidence, and billing atoms stay server-private.
  • Electron Main is the only Canvas network authority. Development and packaged builds use the Works Square V2 contract; there is no V1 DTO adapter, local semantic adapter, mutable Quote PATCH, editable provider Prompt, or cloud-failure fallback.

Rationale

The Living Form makes the current Specification the sole rebuild and generation authority while keeping conversational continuity visible. One reducer removes client/server drift, and immutable Quotes plus stable operation IDs make confirmation and uncertain retries auditable without exposing provider internals.

Consequences

  • Client and server V2 must move together after the stopped deployment passes the server cutover dry-run/apply/validate gate.
  • Existing V1 data remains historical evidence and frozen execution recovery input; old clients and V1 semantic writers receive no compatibility window.
  • Production database cutover, paid Provider activation, and real-account installed client smoke remain separate operator gates.

Supersedes

  • ADR-001: AI 绘画 Workspace / Conversation 状态归属.
  • Client source b0b5a602b501308a23eb27e2f51a5169b9e46b1e
  • Server source b5351d54f595ce8eb873593e462e4a556bea0b05
  • Server ADR ADR-2026-08-28-001