Files
makelore/.project-docs/10-decisions/adr-007-ai-design-living-form-v2.md
T

64 lines
2.7 KiB
Markdown

# ADR-007: AI Design Living Form V2 authority
## Status
Accepted / implemented
## Date
2026-08-30
## Context
ADR-001 modeled a Workspace as multiple independently selected Conversations, each
with its own Brief, mutable Quote, and persistent Session. That split made chat,
form edits, Quote options, and provider prompts competing representations of the
same design. The coordinated Works Square and MakeLore V2 cutover now provides one
versioned Design Specification and a persistent form throughout the design flow.
## Decision
- One Workspace exposes one current Direction, one persistent Agent Session, one
Current Design Specification, one Living Form projection, one conversation
timeline, immutable Quotes, Tasks, and Assets.
- Chat, direct field edits, decision responses, accepted proposals, lock changes,
Asset binding, and restore actions enter the same server-owned reducer. Renderer
drafts are temporary buffers and never semantic authority.
- Every mutation carries stable command and semantic operation identities. An
unknown transport result keeps the same command for replay; revision conflicts
refresh canonical state without discarding local drafts.
- Generation is a compile-and-confirm boundary. The server returns an immutable
Quote for one exact Specification revision; the client displays the public output
plan, warnings, expiry, and Token Point amount and confirms only the Quote ID.
Provider prompts, models, routing, storage, safety evidence, and billing atoms stay
server-private.
- Electron Main is the only Canvas network authority. Development and packaged
builds use the Works Square V2 contract; there is no V1 DTO adapter, local semantic
adapter, mutable Quote PATCH, editable provider Prompt, or cloud-failure fallback.
## Rationale
The Living Form makes the current Specification the sole rebuild and generation
authority while keeping conversational continuity visible. One reducer removes
client/server drift, and immutable Quotes plus stable operation IDs make confirmation
and uncertain retries auditable without exposing provider internals.
## Consequences
- Client and server V2 must move together after the stopped deployment passes the
server cutover dry-run/apply/validate gate.
- Existing V1 data remains historical evidence and frozen execution recovery input;
old clients and V1 semantic writers receive no compatibility window.
- Production database cutover, paid Provider activation, and real-account installed
client smoke remain separate operator gates.
## Supersedes
- ADR-001: AI 绘画 Workspace / Conversation 状态归属.
## Related
- Client source `b0b5a602b501308a23eb27e2f51a5169b9e46b1e`
- Server source `b5351d54f595ce8eb873593e462e4a556bea0b05`
- Server ADR `ADR-2026-08-28-001`