Files
makelore/.project-docs/10-decisions/ADR-2026-09-11-personal-cloud-agents.md
T
brother7 9c79eeca25
Electron E2E / Electron E2E (macos-latest) (push) Has been cancelled
Electron E2E / Electron E2E (ubuntu-latest) (push) Has been cancelled
Electron E2E / Electron E2E (windows-latest) (push) Has been cancelled
docs(wechat): 合入扫码账号渠道简化
2026-09-14 12:18:05 +08:00

66 lines
9.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 个人云智能体平台
## Status
Accepted / implemented,2026-09-11 集成。产品范围、三端分工、创建者付费与预算范围均已获用户确认。历史提案保留原样,本文表达已接受规则。
## Decision
- MakeLore Agents 面向个人创作者,支持配置试用、发布、指定账号分享、应用 API 与主动/定时任务;不引入组织、团队钱包或小智平台。
- Works Square 拥有账号、模块/模型资格、短期授权和唯一 Token Points 账本;Yuxi 拥有云配置、不可变版本、访问授权、原生 Request/FIFO/Run、worker、checkpoint、调度及资源;MakeLore Main 拥有凭据、网络、文件传输与账号隔离的本机恢复记录,Renderer 使用 typed Host API。
- 创建者为自用、分享、API、定时、预览和知识模型调用付款;调用者独享会话/文件,应用是独立主体。创建者只查看应用调用状态、版本、时间及费用元数据,付款不增加内容权限。
- 接受请求时固化身份、版本和配置;恢复与子调用沿用根 Request。每次真实模型调用重新准入,预算是当前服务端政策。
- 每 Agent 可设根请求/每日上限;空值不增加限制,0 阻止新收费调用。北京时间零点划日,按模型准入日归属;原钱包锁内统计结算与未决预占。降低上限影响后续调用。未知用量继续预占,供应商异常超预占按原 pending_review 核对,不宣称供应商账单绝对封顶。
- 日程建议只保存建议;手动/建议新建均默认停用,创建者核对能力、限制、结果和费用后启用。Agent 归档停用,恢复后保持停用;排队、运行或等待回答/审批的会话不能归档,活动状态取原生最新顶层 Run。旧版恢复只创建新草稿。
- 个人 MCP/Skill/子智能体与知识复用原生资源所有权。知识替换先完成新索引,成功后移除旧文档;失败保留旧资料。本人附件导入不借用付款者权限。客户端未确认操作在重启后由用户明确重试或丢弃。
## Consequences
云执行沿用 Yuxi 原生运行体系,WS 既有 Code/Canvas Gateway 和 MakeLore Code/Pi 保持各自范围。复用现有钱包避免重复账本。部署需兼容三端版本、WS 0088/0089、Yuxi 正式 schema 迁移及身份/服务凭据配置。
## Desktop Workspace(2026-09-12 accepted / implemented)
- Agents 使用账号级全高桌面工作区,配置与试用独立滚动;分栏可调整、展开及恢复,小窗口切换配置/试用面板。编辑配置分为指令、能力、知识、限制,正式对话和自动任务保留独立入口。
- 编辑草稿、已保存配置与当前试用修订分别持有状态。明确保存及页内切换保留未发送内容、附件、历史和未确认请求;最新草稿经用户明确选择后开始新试用并保留未发送文字。旧请求重试继续使用原请求身份及修订,不能因保存而重新创建收费请求。隐藏但继续运行的对话不提前标记已读或覆盖最近访问位置。
- 费用上限位于限制分类并独立保存,仍是服务端即时政策。首版不包含自动保存或离线草稿同步;退出工作区仍提示未完成输入。
- 实现源 `dca6deab292028c9f3cfd097a8c52ba0d43b35a9`,见[源任务](../30-worklog/tasks/20260912-agent-draft-design-9d82c9b4.md)。最终 65 项相关测试、类型检查、scoped ESLint(无错误)、Vite 构建与 Windows Electron 验收通过;覆盖大小窗口和 Electron 125%/150% 内容缩放。云端使用 Host API fixture,不等于真实收费链路或 macOS/OS DPI 验收。
## Personal WeChat Publication(2026-09-13 accepted / implemented)
- The native Channels page owns account creation, local QR rendering, login verification, direct use by the scanning account, enable/pause, route switch, disconnect, safe activity and failed-file retry. Agent publication provides a linked-account summary. Pairing codes, contact invitations, audience configuration and caller management are removed.
- Renderer uses typed Host operations. Main owns credentials, network, per-account durable original operations and file saving. Verification codes never enter the recovery journal; uncertain mutations require explicit recovery.
- QR payloads are encoded locally. Account or Provider-generation changes clear transient state. Each selected account exposes its connection and current target; budgets remain the existing Agent policy.
- Own WeChat conversations use dedicated Yuxi session endpoints for approval, stop/new session, complete history pagination and automatically refreshed deliverables. The creator cannot browse invited callers' content.
- The scanning owner's first message establishes their history and available notification conversation. Scheduled result notification requires an explicitly selected self target. Execution completion and WeChat delivery status remain distinct; retrying a failed file part does not run the model again.
Source `2e710db0fb512f276fda8ae8a3939d366b34a972`, [source task](../30-worklog/tasks/20260913-agentbus-channels-ml-3ec75b90.md). Final 81 focused tests, typecheck, production build and 2 Electron scenarios passed, with independent review PASS. Tests use local Host fixtures; real WeChat, billing, packaging and deployment acceptance remain pending.
## User-Owned WeChat Accounts(2026-09-14 accepted / implemented)
- 用户在 MakeLore 的“渠道 > 微信”统一管理多个个人微信账号;账号可以先创建、扫码连接,再选择自己已发布的智能体。每个账号只有一个可选当前目标,多个账号可路由到同一智能体。
- AgentBus Core 的 ChannelAccount 继续拥有账号、当前路由、代次和操作回执;无目标创建默认停用,请求体不增加 `enabled` 字段。清空目标必须停用,切换或清空路由保留微信登录凭据与 Provider generation。
- Yuxi 提供用户级 `/api/makelore/channel-accounts` 与按操作 ID 恢复的接口。已有 Agent binding 仅索引当前路由,历史 caller/session 保留;旧渠道与无目标账号均按 Core 账号清单呈现。多个账号分别保留通知目标和会话隔离。
- MakeLore Main 继续拥有凭据、请求与持久恢复,Renderer 只消费 typed Host API。智能体发布页改为关联渠道摘要与跳转;活动记录及微信对话定位到明确选中的账号。
- 已完成操作优先读取既有回执,再处理首次操作才需要的发布/归档及 Worker 条件;恢复不能重放旧路由或重新调用模型。账号与目标始终限定在可信创建者身份内;原创建者计费、受邀调用者内容隔离及扫码本人免配对规则保持。
- 本节取代此前将创建、连接与路由都放在智能体发布页的入口设计。先更新 AgentBus Core 与 Yuxi API/worker,再使用新版客户端;本批没有新环境变量、数据库迁移,也不要求修改 Works Square 或微信 Adapter。
源提交 `b7d8b1298f02e4b10b6d0089594d48720efc03e7`,见[已审查源任务](../30-worklog/tasks/20260913-user-channels-ml-8d61e4a9.md)。独立 Reviewer 最终 Standards/Spec PASS;本地测试证据与线上验收分开,真实微信、生产部署及收费模型未因这次合并视为通过。
## Scan-Bound WeChat Accounts(2026-09-14 accepted / implemented)
- 谁扫码就绑定谁。一个账号只接受经过 Adapter/Core 验证的扫码身份;其他微信通过各自扫码连接,可分别选择同一个已发布智能体。
- 移除使用范围、邀请码、邀请兑换和单个调用者管理。账号级连接、路由、启停/解绑、活动、微信对话、文件和既有控制流程保留;Main 仍拥有凭据与恢复,创建者继续付款。
- 历史 invited caller/session 不更改内容归属,不允许新的入站、内部恢复或待发结果继续交付;旧邀请码回执取消。服务端保留历史表,不需要新增 schema 迁移。
- MakeLore 已删除相应 typed Host 操作与界面;旧恢复记录只能在本机显式丢弃,不请求已删除 API、不阻塞其他账号。定时通知仍从隔离的扫码账号会话选择目标。
- 本节取代上述旧章节中的邀请、受众配置和单 caller 撤销规则;历史源任务与已发生的集成记录保留。部署需配套更新 MakeLore 与 Yuxi API/worker,本批不修改 AgentBus/Works Square,不新增环境变量。
源 `21e707d`,见[源任务](../30-worklog/tasks/20260914-wechat-scan-owner-ml-b4169ea9.md)。独立 Reviewer Standards/Spec PASS,测试与生产边界以源记录为准;真实微信与收费模型仍需发布环境验收。
## Evidence And Limits
The creator no-code change explicitly replaces the earlier pairing step. See [reviewed source task](../30-worklog/tasks/20260913-wechat-auto-self-ml-3679bce2.md): 64 focused tests, typecheck, build, scoped lint and an inspected Electron scenario passed; independent review passed. Main remains the network boundary and Yuxi/AgentBus establish identity. Compatible backend and client deployment is required; historical connections missing scanning identity need one reconnect. No real WeChat acceptance or installer was produced by this change.
源:WS `0f1fb8af`、Yuxi `1df0142`、MakeLore `303f262`;本仓库见 [源任务](../30-worklog/tasks/20260910-personal-agent-platform-d15b2559.md)。本批独立 Reviewer 最终 PASS。源验证包含 WS 113 passed / 1 skipped 和预算 PG 4 passed,Yuxi 1985 non-slow unit / 19 HTTP-存储 integration 及归档最后补丁 3 integration,MakeLore 39 unit / Renderer tsc / build / Electron 1 passed。模型授权/供应商及沙盒释放有明确替身;MakeLore Main 全仓保留 61 项既有类型诊断。
真实收费模型对账、完整服务/ARQ/provisioner 与重启、安装包/协议/跨设备、生产迁移和部署仍待验收。并行 OSS 替换与远程 Milvus 部署由各任务集成和验收;本决策不接受其尚未合入的存储实现。