64 lines
2.7 KiB
Markdown
64 lines
2.7 KiB
Markdown
# ADR-007: AI Design Living Form V2 authority
|
|
|
|
## Status
|
|
|
|
Accepted / implemented
|
|
|
|
## Date
|
|
|
|
2026-08-30
|
|
|
|
## Context
|
|
|
|
ADR-001 modeled a Workspace as multiple independently selected Conversations, each
|
|
with its own Brief, mutable Quote, and persistent Session. That split made chat,
|
|
form edits, Quote options, and provider prompts competing representations of the
|
|
same design. The coordinated Works Square and MakeLore V2 cutover now provides one
|
|
versioned Design Specification and a persistent form throughout the design flow.
|
|
|
|
## Decision
|
|
|
|
- One Workspace exposes one current Direction, one persistent Agent Session, one
|
|
Current Design Specification, one Living Form projection, one conversation
|
|
timeline, immutable Quotes, Tasks, and Assets.
|
|
- Chat, direct field edits, decision responses, accepted proposals, lock changes,
|
|
Asset binding, and restore actions enter the same server-owned reducer. Renderer
|
|
drafts are temporary buffers and never semantic authority.
|
|
- Every mutation carries stable command and semantic operation identities. An
|
|
unknown transport result keeps the same command for replay; revision conflicts
|
|
refresh canonical state without discarding local drafts.
|
|
- Generation is a compile-and-confirm boundary. The server returns an immutable
|
|
Quote for one exact Specification revision; the client displays the public output
|
|
plan, warnings, expiry, and Token Point amount and confirms only the Quote ID.
|
|
Provider prompts, models, routing, storage, safety evidence, and billing atoms stay
|
|
server-private.
|
|
- Electron Main is the only Canvas network authority. Development and packaged
|
|
builds use the Works Square V2 contract; there is no V1 DTO adapter, local semantic
|
|
adapter, mutable Quote PATCH, editable provider Prompt, or cloud-failure fallback.
|
|
|
|
## Rationale
|
|
|
|
The Living Form makes the current Specification the sole rebuild and generation
|
|
authority while keeping conversational continuity visible. One reducer removes
|
|
client/server drift, and immutable Quotes plus stable operation IDs make confirmation
|
|
and uncertain retries auditable without exposing provider internals.
|
|
|
|
## Consequences
|
|
|
|
- Client and server V2 must move together after the stopped deployment passes the
|
|
server cutover dry-run/apply/validate gate.
|
|
- Existing V1 data remains historical evidence and frozen execution recovery input;
|
|
old clients and V1 semantic writers receive no compatibility window.
|
|
- Production database cutover, paid Provider activation, and real-account installed
|
|
client smoke remain separate operator gates.
|
|
|
|
## Supersedes
|
|
|
|
- ADR-001: AI 绘画 Workspace / Conversation 状态归属.
|
|
|
|
## Related
|
|
|
|
- Client source `b0b5a602b501308a23eb27e2f51a5169b9e46b1e`
|
|
- Server source `b5351d54f595ce8eb873593e462e4a556bea0b05`
|
|
- Server ADR `ADR-2026-08-28-001`
|