@@ -5,7 +5,7 @@ description: Free use and licensing terms for MiragenFlow
# MIT License
MiragenFlow is licensed under the [MIT License](https://github.com/basketikun/infinite-canvas/blob/main/LICENSE). Anyone may use it free of charge for personal, academic, internal, SaaS, private deployment, open-source, or closed-source commercial purposes.
MiragenFlow is licensed under the [MIT License](https://git.awaioi.com/awaioi/MiragenFlow/src/branch/main/LICENSE). Anyone may use it free of charge for personal, academic, internal, SaaS, private deployment, open-source, or closed-source commercial purposes.
You may use, copy, modify, merge, publish, distribute, sublicense, and sell copies of the project. You do not need to purchase a commercial license or publish your modifications or application source code.
@@ -5,17 +5,17 @@ description: Frontend-first local development
# Local Development
The main application lives in `web/`. The browser sends AI requests directly to the user's OpenAI-compatible endpoint.
The local application runs `web/`, `admin/`, and `server/` together. The frontend and admin proxy through one public development origin, and the server gateway handles AI requests.
## Start the frontend
```bash
cd web
bun install
bun run dev
bun run dev:all
```
Open `http://localhost:3000`, then enter your `Base URL`, `API Key`, and model names in Settings. AI providers and WebDAV are accessed directly by the browser.
Open `http://localhost:3000`, register a user, and use `/admin/` to configure public products and channels. Users do not enter provider URLs or API keys; WebDAV is only for personal generated data.
# Set PostgreSQL, access-token, admin, MFA, and channel-encryption secrets in .env.
docker compose up -d --build
```
Open `http://localhost:3000`.
The stack builds the frontend/admin bundle and starts the API, PostgreSQL, and
Redis services. After migrations complete, open `http://localhost:3000`.
## Build locally
## Local fixture
```bash
docker compose -f docker-compose.local.yml up -d --build
```
The local fixture uses file persistence and an in-process queue. It is useful for UI work, but it does not validate the PostgreSQL/Redis production profile.
## Documentation image
The documentation in `docs/` is a separate Next.js standalone application with server capabilities.
@@ -37,26 +42,9 @@ cd docs
docker compose -f docker-compose.local.yml up -d --build
```
The main application container only serves the web application. Canvases, My Assets, and API keys are stored in the browser by default. WebDAV can synchronize canvases, assets, and their referenced image or audio files, so no application-managed data volume is required for this data.
The Compose deployment starts the frontend, admin bundle, API gateway, and server. Authentication, balance, tasks, channel routing, and WebSocket events are handled by the server. Canvases and assets remain browser-local by default; media can be synchronized to WebDAV and provider credentials never enter browser business storage.
## Optional analytics
No analytics are enabled by default. A deployment can enable GA4, Baidu Analytics, or both at runtime:
| Variable | Description |
| --- | --- |
| `ANALYTICS_GA4_ID` | Google Analytics 4 measurement ID (`G-XXXX`) |
| `ANALYTICS_BAIDU_ID` | Baidu site ID, the hash after `hm.js?` |
SPA route changes automatically report page views to enabled providers. Only configure analytics IDs on sites you control, and do not commit them to the repository.
The frontend does not inject third-party analytics scripts or send page data to
external analytics providers. Authentication, balances, jobs, queues, and
WebSocket events still require the frontend, server, PostgreSQL, and Redis
@@ -27,9 +27,9 @@ description: Major features available in the current project
- Use image, text, audio, generation-configuration, and group nodes.
- Connect prompts and reference resources to configuration nodes.
- Generate images, text, and audio through user-configured OpenAI-compatible or Gemini-compatible channels.
- Generate images, text, and audio through the same-origin asynchronous task gateway; provider channels are managed by administrators.
- Preserve image ratios by default, organize batch results in one expandable image group, and retry failed outputs independently.
- Configure models, image parameters, text reasoning effort, audio voice, format, speed, and per-model invocation scripts.
- Select published model products, capability schemas, resolutions, quantities, and balance-unit prices.
## Image tools
@@ -40,14 +40,14 @@ description: Major features available in the current project
## Assets
- Store reusable text and image assets in the browser.
- Store reusable text, image, and audio assets in the browser and mirror them to the platform asset API.
- Search, filter, import, export, edit, download, and insert assets into a canvas.
- Insert assets from the canvas side panel without leaving the current project.
## Configuration and synchronization
- Configure multiple model channels and assign image, text, or audio capabilities to each model.
- Import or export local configuration, including credentials and WebDAV settings.
- Configure public model products, channel groups, routes, prices, plans, and balance units in the admin console.
- Keep provider credentials server-side; the browser stores only public settings, local assets, and WebDAV connection status.
- Inspect local IndexedDB usage.
- Synchronize canvases, assets, and their image or audio files through WebDAV.
@@ -57,6 +57,6 @@ The repository retains the node registry, runtime contracts, canvas operation AP
## Current limitations
- The project is frontend-first and does not provide built-in cloud accounts or application-managed cloud storage.
- API keys remain in browser storage and requests are sent directly to configured providers.
- Browser canvas/media remains local-first; the server stores task, billing, asset references, and temporary staging metadata.
- PostgreSQL persistence writes the core V1 relational rows and a revision-fenced compatibility projection in one transaction; Redis queue leases use Lua fencing, and provider reconciliation plus offline WebDAV workers are included in the server runtime. Remaining administrative record mappings and concrete external provider protocols stay deployment-specific.
- Production Docker static-resource paths still require broader deployment verification.
@@ -9,14 +9,15 @@ To try the project, start the `web/` frontend and `admin/` management console th
## Deploy with Vercel
Import the repository into Vercel. The root `vercel.json` builds both `web/` and `admin/`. AI requests are sent directly from the browser to your OpenAI-compatible endpoint, so no additional application server is required.
Production deployment must provide `server/` together with the frontend and admin bundles. Static-only hosting does not provide authentication, balance, task APIs, or the task WebSocket.
@@ -25,17 +26,16 @@ Open the frontend at `http://localhost:3000/` or the admin console at `http://lo
## Run with Docker
The Docker image includes both applications and exposes only port 3000.
Use Compose so the API gateway, server, and dependencies are started with the two applications.
```bash
docker build -t miragenflow .
docker run --rm -p 3000:3000 miragenflow
docker compose -f docker-compose.local.yml up -d --build
```
## First-time setup
- Open Settings and enter your `Base URL`, `API Key`, and model names.
- Assign image, text, or audio capabilities to the models you want to use.
- Configure WebDAV if you want to synchronize canvases, assets, and their image or audio files across devices.
- Register and complete email or phone verification, then choose a public model product and resolution in the workspace.
- Configure channels, model products, prices, balance units, and plans in `/admin/`; users never enter provider URLs or API keys.
- Configure WebDAV in Storage Settings if you want to synchronize canvases, assets, and media across devices.
Canvas projects and My Assets are primarily stored in the browser. The API key is also stored locally and used by the browser to call OpenAI-compatible endpoints directly.
Canvas projects and My Assets are primarily stored in IndexedDB/localForage. Access tokens stay in memory, refresh tokens use an HttpOnly cookie, and provider credentials remain encrypted on the server.
@@ -5,7 +5,7 @@ description: Deploy MiragenFlow with Render
# Deploy on Render
[Deploy to Render](https://render.com/deploy?repo=https://github.com/basketikun/infinite-canvas)
This repository is hosted on a self-managed Git service, so a Render one-click link is not published. To use Render, mirror the repository to GitHub first and configure PostgreSQL, Redis, and the server environment variables described in the deployment guide.
@@ -5,18 +5,279 @@ description: Implemented changes that still need manual verification
# Pending Tests
- Latest regression evidence: `npm run build:all` passed server typecheck, the web production build, and the admin production build; `npm run test:all` passed 102/102 server tests plus web/admin typechecks. Exact forbidden-reference scans found no user-side Ant Design, ProComponents, Radix controls, Lucide, native `<select>`, `.ant-*`, CDN, or WebFont usage; remaining matches are the project-owned TDesign `Select` adapter names and native file-input API types. Existing large-chunk, dynamic-import, and Browserslist warnings remain informational.
- An isolated browser tab at 390x844 verified `/`, `/auth/reset`, `/style-preview`, and `/admin/login`: each rendered Chinese content, had no horizontal overflow, no native `<select>`, and no captured console errors. Authenticated admin workflows, protected user routes, canvas internals, and external provider/WebDAV scenarios remain pending.
- A fresh same-origin administrator session signed in with the documented local credentials and loaded `/admin/dashboard/base`; the overview rendered KPI values, seven-day trend sections, runtime alerts, and the grouped navigation without browser console errors. The first request briefly showed an empty main region before the dashboard data settled; authenticated write flows and the remaining 21 admin pages still require manual verification.
- Admin non-GET requests now reuse the original idempotency key after a 401 session refresh, and channel generation tests translate a selected display model ID through the configured request-model mapping before calling the upstream. Verify a response-lost 401 retry does not duplicate a write and that a mapped model reaches the compatible provider endpoint as the request ID.
- User canvas crop, split, angle, and upscale operations now reject broken image data and time out instead of remaining pending forever; crop failures show a localized retry message. Verify invalid or interrupted image data in each editor and confirm the loading state and editor can be used again.
- User account password and MFA mutations now invalidate stale responses after dialog close or back-navigation, keep errors in the active dialog, and isolate session-revoke errors on the account page. MFA confirmation content scrolls inside short dialogs, and profile dropdown visibility is owned by TDesign with route remount fencing. Verify close/ESC/overlay during delayed requests, retry behavior, focus return, short mobile heights, and reopening the profile menu after navigation.
- Password-reset code requests now retain the channel and normalized target used at submission; editing the identifier or switching channel invalidates the old request and its CAPTCHA. Verify reversed responses, CAPTCHA refresh, target text, and reset submission in a delayed browser session.
- User canvas crop/mask editors, asset image/audio/cover selection, and verification/reset CAPTCHA loading now fence async results to the current input. Stale image metadata, earlier file uploads, or older CAPTCHA responses cannot overwrite the current draft, and file read/upload failures show localized errors. Browser verification is still needed by delaying the first image metadata result, reversing two file uploads, and reversing two CAPTCHA requests to confirm the final preview, dimensions, title, question, and submitted challenge ID belong to the latest selection.
- User canvas upscale and split editors now also discard stale image-dimension results when the image URL or open state changes, preventing a previous image's target size, ratio, or split grid from leaking into the current editor. Authenticated canvas verification is still needed by switching quickly between differently sized images while delaying the first metadata result.
- The latest clean-browser gate check visited all 22 admin business deep links and each settled on `/admin/login` without exposing business content; desktop width remained within the viewport and no console errors were captured. This confirms unauthenticated route protection only; authenticated admin rendering, permissions, writes, persistence, and error/retry behavior remain pending.
- The default admin login shell exposes only the email and password fields while administrator CAPTCHA/MFA are disabled; no verification, one-time-code, or recovery-code input is rendered. Its page-settings drawer exposes accessible theme/layout radio groups, closes on Escape, unmounts after the transition, and returns focus to the `页面设置` trigger without console errors. Authenticated settings and business-shell behavior remain pending.
- An isolated local server using a fresh temporary store and `MIRAGENFLOW_DEMO_DATA=false` returned ready status and allowed the configured administrator to sign in; authenticated counts were users 0, channels 0, payment providers 0, message providers/templates/outbox 0, tasks 0, recharge orders 0, and payment events 0. The default catalog still exposed five built-in public products and one empty channel group, as intended for the unconfigured development shell. The existing long-lived preview store was not modified; explicit test-mode fixture behavior still needs a separate check.
- Latest command regression passed: `npm run test:all` completed 102/102 server tests plus web/admin typechecks, and `npm run build:all` completed server typecheck, web production build, and admin production build. Existing large-chunk, dynamic-import, deprecation, and stale Browserslist warnings remain informational; authenticated browser workflows are still pending.
- Latest unauthenticated browser regression verified the user homepage, login, registration, verification, password reset, component preview, user 404, and admin login shell at desktop and 390px widths: all rendered Chinese content, had no native `<select>`, no horizontal overflow, and no captured console errors. At 390px the user Select opened with Enter, moved with ArrowDown, committed `风格模型` with Enter, and closed with Escape with `aria-expanded=false` and a hidden popup. Authenticated admin pages and all write/error/retry flows remain pending.
- Image creation and admin reconciliation now use project Button controls for visible file-upload triggers; hidden file inputs remain only as the browser file API exception. Verify file chooser focus, invalid type/size feedback, preview replacement, cancel, and submit behavior in authenticated desktop and 390px sessions.
- Narrow-screen overlay closing is now wired for the admin settings/detail/attempt drawers and the user asset/mobile navigation surfaces; admin drawers use a viewport-bounded width so a clickable mask remains visible at 390px. Browser checks confirmed admin settings mask close with focus returned to the settings trigger, user sidebar mask close, no horizontal overflow, and no console errors. Authenticated business drawers and their async failure/retry behavior still need verification.
- Authentication bootstrap now recovers legacy user/admin refresh sessions that lack a CSRF cookie and issues the missing CSRF cookie on successful rotation; ordinary browser-backed business writes still require the double-submit token. Server regression coverage passes for the administrator path. Verify a real browser hard refresh after an older login, then confirm an unprotected business write is still rejected and authenticated writes continue to work.
- Current browser evidence: in temporary same-origin tabs, the desktop user homepage and public authentication/404 routes loaded without horizontal overflow; the 390px homepage and mobile navigation also passed, including Escape close and light/dark theme toggling. All six protected user routes settled on `/login?redirect=...`. After logging into the local preview administrator, all 22 admin business deep links loaded with their expected Chinese page titles, default administrator CAPTCHA/MFA fields remained hidden, the user-creation drawer retained invalid drafts after Chinese validation errors, and the channel editor exposed only the three required tabs with separate display/request model IDs and retained an invalid URL draft. The user-side themed Select opened from Enter, exposed its listbox options, and closed on Escape. This verifies route/page-shell loading and a few low-risk control paths only; authenticated writes, permission matrices, error/retry flows, canvas internals, and external provider/WebDAV scenarios remain pending.
- Follow-up authenticated 390px evidence covered `/assets`, `/tasks`, `/account`, `/settings`, `/tools/image`, and `/tools/audio`: each route retained the login shell, rendered its key content, and stayed within the 390px viewport without horizontal overflow. The task status Select opened with Enter, selected an option with ArrowDown/Enter, and closed with Escape. The account revoke flow showed the confirmation dialog, preserved the session after cancel, and closed on Escape with focus returned. Settings showed validation feedback for an invalid WebDAV test and updated local-storage usage from `--` to `0 MB`; image advanced settings toggled correctly, and audio generation became enabled after text input. The user-side imperative confirmation implementation was changed from `DialogPlugin.confirm` to a controlled TDesign Dialog because the plugin path rendered no dialog under the current React 19 runtime; web typecheck and `git diff --check` pass. Failure/retry mutations, real generation, WebDAV, detailed canvas interaction, and desktop authenticated visual review remain pending.
- The shared TDesign Button adapter now forces ordinary buttons to render as native `button` elements even when disabled, while leaving link buttons on their normal anchor path. A desktop 1440px image-tool check confirmed the disabled generation control is `BUTTON[disabled]`, the page has no horizontal overflow, and a dark-to-light theme switch updates the TDesign page variable without layout overflow. Verify disabled/loading semantics across the admin and user applications, including any custom `href` or `tag` callers.
- Admin generic confirmation actions now have an exception fallback for freeze/unfreeze, message retry, and task cancel/retry entries; failed requests keep the confirmation dialog open and show a Chinese error message. Verify authenticated 409/422/503 and offline/recovery responses, including that the action can be retried without duplicate submission.
- The user-side confirmation-dialog adapter now catches rejected async callbacks, keeps the dialog open, and shows a Chinese error by default, with an optional caller error handler for session revoke, task cancel, and result deletion. Verify failure/retry, loading reset, focus return, and no unhandled Promise in authenticated desktop and 390px flows.
- The user settings page now handles local storage usage read failures with a Chinese error message and a loading state instead of leaving an unhandled click promise. Verify the disabled/loading state and recovery after IndexedDB or browser-storage permission errors in an authenticated desktop and 390px session.
- Admin edit, approval, balance-adjustment, refund, and reconciliation dialogs now catch asynchronous request failures in the shared confirmation flow, keep the draft open, and show a Chinese error message so a failed mutation can be retried. Verify authenticated 409/422/503 and network-failure responses across these mutation types, including that the form values remain intact and no unhandled browser error is emitted.
- The user homepage carousel no longer displays legacy product or out-of-scope 3D promotional banners. It now uses the existing character, scene, and asset reference images with MiragenFlow-specific Chinese overlay labels while preserving arrow, dot, and responsive behavior. Independent same-origin checks verified the next-slide transform, no legacy banner text, no horizontal overflow at desktop and 390px, light/dark theme rendering, and no browser warnings; review the final image crop and visual contrast in the authenticated shell.
- Normal development store startup no longer seeds the mock payment adapter; payment fixtures are limited to `NODE_ENV=test` or explicit `MIRAGENFLOW_TEST_MODE=true`, while production remains empty until a real adapter is configured. Verify a clean development store shows an empty payment-adapter list and that explicit test mode still exercises the payment contract.
- The unauthenticated admin-route smoke test revisited all 22 visible business routes (`/admin/dashboard/base`, users, auth messages, MFA security, channels, channel health/groups, model products, pricing, billing, plans, recharges, payments, payment providers, approvals, tasks, WS metrics, storage, settings, and both audit routes) in a clean browser tab. Each route settled on the admin login surface without exposing business content; authenticated rendering, permissions, writes, and error/retry states remain pending.
- The shared user-side TDesign Switch no longer renders nested `label` elements; labeled switches now expose a named `role="switch"` control and clicking the visible label text toggles the state. The component-center browser check verified no nested labels, `aria-checked` changed from `true` to `false`, and no console errors; verify labeled switches again in canvas image-tool settings and light/dark authenticated layouts.
- Admin audit dashboard and detailed-log pages now show a fixed right-side “view log details” action column when the current administrator has audit scope and rows have detail IDs; verify action-column visibility, detail loading/error/retry, permission-hidden behavior, fixed columns, and 390px horizontal scrolling.
- User canvas project cards are now focusable links that open with Enter, and the admin brand logo now uses the shared TDesign Button while preserving the home navigation. Verify visible focus, keyboard opening, nested checkbox/action behavior, rename mode, and desktop/390px layouts in guest and authenticated states.
- The user workbench header now exposes a light/dark theme toggle sharing the canvas theme store, TDesign Button adapter, and animated transition logic. Guest homepage checks at desktop and 390px verified button visibility, dark-theme activation, the updated accessible label, persistence after reload, no horizontal overflow, and no console errors. Authenticated-shell behavior, contrast review, and broader page states remain to verify.
- The user-side TDesign TextInput and TextArea adapters now bridge native input events for controlled values while retaining the TDesign uncontrolled path and clear behavior. Web typecheck and production build pass; verify real keyboard, IME, paste, clear, validation, and controlled-draft behavior across authentication, assets, settings, and canvas at desktop and 390px.
- The developer-only component center no longer presents a planned 3D rendering card, matching the V1 exclusion of real 3D. Verify the business preview contains only retained homepage, AI creation, canvas, assets, and account areas.
- User canvas crop-ratio, generation-mode, grid-style, lens, upscale-target, and upscale-algorithm controls now use `group` containers matching their TDesign `aria-pressed` buttons instead of invalid `radiogroup` semantics. Verify the selected visual state and keyboard activation remain unchanged in the authenticated canvas/editor flows.
- User canvas resource-mention menus now support Home/End navigation and expose vertical listbox semantics while keeping the focused editor synchronized through `aria-activedescendant`. Verify image, audio, text, and config-resource mention flows with IME input, filtering, selection, Escape, and narrow-screen positioning.
- Admin channel-group model-product and provider-channel multi-select lists now use a single roving-focus option per list, support Arrow/Home/End navigation while skipping disabled choices, and preserve Enter/Space toggling without double-changing nested checkboxes. Verify the authenticated group editor with real enabled, disabled, selected, mode-mismatched, and cross-group-owned choices at desktop and 390px.
- Admin page-settings color, theme-mode, and navigation-layout controls now expose radio semantics with roving focus, Arrow-key navigation, Home/End navigation, and keyboard access to the custom color picker. The login-route smoke test verified the groups and selected-state updates; verify the same behavior after authentication and across desktop/390px light and dark layouts.
- The admin theme-color selector now uses an explicit controlled `value`, so reopening settings follows the current theme color instead of an initial-value prop. Verify preset and custom colors, close/reopen behavior, selected borders, and custom-panel readback after authentication.
- The admin page-settings drawer now restores focus to its trigger after closing; desktop and 390px checks verified Escape close, drawer unmount, light-theme restoration, no horizontal overflow, and no console errors. Verify overlay and close-button behavior, plus focus continuity after layout changes, in the authenticated admin shell.
- The full-page admin login route now mounts the page-settings drawer without inheriting the `Layout/Content` shell. Desktop and 390px checks confirmed opening, `light/dark` theme switching, `radiogroup/radio` semantics, no horizontal overflow, and Escape close. Verify that the settings continue to affect navigation layout, theme color, and element toggles after an authenticated page is mounted.
- The shared UI package now exposes the `@miragenflow/ui/button` subpath and resolves it to the local Button adapter; the export-integrity check and web/admin typechecks pass. Verify the standalone subpath import in development and production builds.
- The latest same-origin read-only smoke test covered the user home, login, registration, public previews, protected entries, and `/admin/` at desktop and 390px viewports. Public/auth pages had no horizontal overflow or console errors, protected routes settled on login, and the admin entry settled on `/admin/login`. Authenticated business pages, all 22 admin entries, and write operations still require authorized page-by-page verification.
- The user task-history page now uses the shared TDesign Table with columns for task links, type, public model, status, credits, creation time, and view actions, while retaining the narrow-screen horizontal scroll. Verify the authenticated status filter, timed refresh, status tags, task links, empty state, and 390px table scrolling.
- User-side Select call sites now pass structured `options` data, and focus traps no longer include a native `select` branch. The shared adapter renders the same TDesign combobox/listbox contract; the component center verified zero native `select`/`option` elements, Enter-to-open, Escape-to-close, focus retention, no horizontal overflow, and no console errors. Authenticated image/audio/task/asset workflows still need their full visual and value-selection review.
- Management-console structured detail values now render only fields with registered Chinese labels, so unknown nested response keys are omitted instead of appearing as unmapped content. Verify representative nested objects, empty-after-filter objects, and sensitive-key responses in detail drawers and audit payloads.
- User-detail tab tables now apply the same registered-label filter as detail drawers, omitting unknown response keys instead of creating an “other information” column. Verify account, sessions, tasks, ledger, entitlements, and audit tabs with partial and extended responses.
- The admin login submit button now uses a plain layout container instead of an unnamed `FormItem`, keeping dynamic CAPTCHA/MFA fields as the only form-managed controls. Verify Enter submission, validation errors, loading/disabled state, and the desktop/390px layout.
- Asset ZIP import now clears the hidden file input immediately after capturing the selected file, so selecting the same package again during or after an import can trigger another change event. Verify repeated same-file import, invalid packages, cancellation, and concurrent import feedback.
- Local file persistence now uses one atomic write path for synchronous/asynchronous saves and unique temporary names for concurrent repository saves. Verify repeated requests and service reloads keep `/api/ready` ready, preserve the latest valid snapshot, and leave no corrupted snapshot after an interrupted save.
- Channel-group task-mode options now show only Chinese labels such as “图片” and “文本”; the underlying `image`/`text` values remain unchanged for API submission. Verify the displayed labels and saved capability values in the authenticated channel-group editor.
- Public-route browser regression now covers `/`, `/login`, `/register`, `/auth/verify`, `/auth/reset`, `/components`, `/style-preview`, and the 404 route at desktop and 390px widths with no horizontal overflow or console errors. The protected routes `/assets`, `/tools/image`, `/tools/audio`, `/tasks`, `/account`, `/settings`, and `/canvas` first show the Chinese auth-loading state and then redirect to `/login` with the requested `redirect`; the same-origin `/admin/` entry is also gated and settles on `/admin/login` without credentials. The admin login page renders at desktop and 390px without horizontal overflow or console errors, while authenticated admin pages and user-business-flow verification remain pending. The migration architecture HTML was regenerated from the current JSON and passed Archify showcase validation (9/9 checks), desktop light/dark containment, and the 1440px visual spot-check.
- Shared UI now exposes `Form`, `Table`, `Tabs`, `Menu`, `Layout`, and `Row/Col` subpaths and root exports. The admin login, business tables, navigation shells, settings grid, and page layouts now use the shared entries while admin retains permission checks, route guards, dynamic table columns/drag sorting, and form instance behavior. Verify composite static members, table pagination/horizontal scrolling/drag sorting, dynamic CAPTCHA and MFA fields, menu permissions, and desktop/390px light/dark rendering page by page.
- The user-side themed Select adapter now exposes a combobox/listbox ARIA relationship, supports Enter/Space opening and selection, Arrow/Home/End navigation, Escape close with focus return, disabled-option skipping, and active-option feedback. The admin low-risk Dropdown, Space, Breadcrumb, Popup, date-range picker, and color-picker usage now enters through `@miragenflow/ui`; verify keyboard selection, selected/active announcements, overlay/backdrop/Escape behavior, date value preservation, popup positioning, and desktop/390px light/dark rendering.
- The shared UI root and subpath exports now include the existing Dropdown, Pagination, Slider, and Tooltip adapters plus Space, Breadcrumb, Popup, date-picker, color-picker, `Form`, `Table`, `Tabs`, `Menu`, `Layout`, and `Row/Col` adapters. Admin login, business tables, navigation shells, settings grid, and page layouts now enter through these shared boundaries while retaining admin-owned state and permissions. Verify package resolution in dev/build, static-member compatibility, and the remaining high-risk controls before changing the cleanup checklist.
- The shared UI package now exports Card and Statistic adapters, and admin board, business charts, and statistics use them without changing the existing TDesign card DOM contract. Verify card headers, chart sizing, zero/empty statistics, light/dark themes, and 390px layouts across dashboard, business, and finance pages.
- The admin error page, login form, headers, mobile menu backdrop, and business-page actions now use the shared TDesign Button adapter. The adapter adds explicit outline and danger-outline semantics while keeping native submit behavior under `htmlType`; verify navigation, login validation and Enter submission, popup actions, loading/disabled states, danger styling, and the business page at desktop and 390px widths.
- The shared UI package now exports TDesign `Alert` and `Loading` adapters, and the admin business page uses the shared entry for alerts, detail errors, and loading states. The admin Vite development config also pre-bundles `prop-types` and `react-transition-group` so TDesign Alert's ESM/CommonJS interop does not blank the development page. The same-origin admin dashboard has been checked at desktop and 390px widths for rendered content, an alert node, no horizontal overflow, and no console errors; the remaining 22 admin entries still need page-by-page loading, error, empty-state, and light/dark review.
- The admin page-settings drawer now makes the theme and navigation-layout previews and labels one clickable selection area, exposes `radiogroup`/`radio` semantics with visible focus, and supports Enter/Space selection. Controlled state follows Redux updates immediately, and “follow system” now applies correctly when the OS prefers light mode. Verify the full option click target, Tab/Enter/Space behavior, light/dark/system switching, layout switching, and close behavior through the header button, backdrop, and Escape at desktop and 390px widths.
- Channel groups now follow the explicit `task mode -> upper model product -> lower request channel pool` relationship. The list separates model ID, product name, base price, and a compact resolution matrix; the editor provides visible checkable product and channel choices with mode compatibility, ownership, health, and selection counts. Saving a group refreshes both the group rows and the product/channel candidate relationships. The group ID no longer occupies a list column, and product publication state is not mixed into the product-name column. The API rejects incompatible capabilities, silent cross-group moves, and mode-only updates that would leave invalid bindings, while explicitly unbound published products are taken offline. Verify create/edit backfill, Chinese conflict feedback, explicit unbind/rebind, refresh persistence, fallback ordering, desktop table scrolling, compact resolution rows, and the 390px dialog.
- Admin model product, membership plan, balance unit, storage policy, and message provider forms now validate numeric boundaries and endpoint URLs before submitting. Invalid values keep the draft open with a Chinese message, and a blank endpoint during provider editing preserves the saved endpoint. Verify valid and invalid values on each page, confirm no request is sent for invalid input, and reload after a successful save.
- The admin login mobile breakpoint now reuses the desktop transparent left-side content rail; the title, form, and footer share the `5%` left offset without an extra full-width content container. Verify background cropping, scrolling, and login error states at 390px, 320px, landscape, and short viewports.
- Admin user list/detail responses now include a resource `version`; freeze, unfreeze, security edits, and administrator password resets run inside a transaction with `If-Match` checks and increment the version. A stale submission returns a Chinese 409 without changing the current state. Verify refresh readback, concurrent stale conflicts, freeze/unfreeze persistence, and failed-form/detail retention.
- System overview statistic cards now distinguish a real numeric zero from a missing field by showing “暂无数据” for missing values; trend, model, channel, message, payment, and audit charts filter malformed array entries, and loading includes a Chinese status. Verify empty responses, partial fields, all-zero data, malformed entries, retry failures, and light/dark themes.
- The shared user-side Tabs adapter now moves real focus with Arrow, Home, and End navigation and clears stale focus requests when a controlled value does not change. Verify disabled-tab navigation, delayed controlled updates, mouse activation, and focus return across desktop and 390px routes.
- Canvas image/media/project file inputs now clear their value immediately after taking a FileList, so selecting the same file again can trigger another import. Verify repeated same-file selection, invalid files, cancellation, and an interrupted upload/import.
- User-side imperative confirmation dialogs now add dialog semantics, move focus into the dialog, trap Tab, and restore focus after close. Verify cancel, close, overlay, Escape, async confirm success/failure, and stacked confirmations in desktop and 390px sessions.
- Canvas image, audio, and text settings popovers now expose trigger state and dialog relationships, move focus into the panel, trap Tab, and restore the trigger after close. Verify each popover with mouse/keyboard, nested TDesign Select popups, outside/Escape close, canvas pan/zoom, desktop, and 390px.
- Canvas settings popovers now ignore their themed TDesign select overlays when deciding whether a pointer is outside. Verify selecting an option in image/audio/text settings does not close the parent popover, while real outside clicks still close it.
- Canvas node and connection create menus now use roving focus for Arrow Up/Down, Home, and End and initially focus the first menu item instead of the close control. Verify wraparound, activation, Escape/outside close, focus return, dynamic plugin items, and edge positioning.
- The shared user-side Field wrapper now supports a labelled group mode for compound fields, so mention menus and buttons are not nested inside a label while simple fields keep their implicit label association. Verify accessible names and click/focus behavior for simple inputs, Selects, switches, and the image prompt mention list.
- Saving admin authentication settings now refreshes the current administrator profile, so the MFA page no longer makes enable/disable decisions from stale policy state. In one session, toggle the administrator two-step policy and immediately open the security page; verify the action guard matches the server policy and a profile-refresh failure does not roll back the saved settings.
- The dashboard now renders when a dashboard object is present even if an optional metric is missing; each KPI and chart keeps its own numeric or empty-state fallback instead of hiding the whole overview. Verify empty, partial, and real zero-value responses separately.
- The user Select adapter now exposes select-like `multiple`, `options`, `selectedOptions`, `selectedIndex`, and event cancellation methods while keeping the themed TDesign popup and an accessible empty state. Verify a future multi-select caller and the existing single-select pages after keyboard selection and Escape.
- Protected user routes now keep the user shell out of the tree until authentication hydration settles; the guard renders a full-viewport Chinese loading state before redirecting unauthenticated visitors. Verify direct `/tools/image`, `/assets`, `/tasks`, `/account`, `/settings`, and `/canvas` navigation at desktop and 390px during slow refresh/session expiry, confirming no stale navigation flash and no console errors.
- Store reloads now wait for queued persistence writes, serialize concurrent reloads, and retry when a write starts during the read; PostgreSQL snapshot reads run in one repeatable-read transaction. Fake-repository regressions cover both in-flight write orderings; verify against real PostgreSQL with concurrent admin writes, task creation, worker updates, restart recovery, and two instances to confirm revision fencing and mixed-generation reads remain impossible.
- The admin task center now keeps the task-attempt drawer open when its request fails, shows a Chinese error, and exposes a retry action before restoring the attempts table. Verify 403, 5xx, offline, and recovery flows, including stale-request protection and close/overlay/Escape dismissal.
- Canvas asset overlays, side-panel hover feedback, and image/audio/text settings triggers now use the active canvas theme tokens; shortcut labels and live-task connection failures are localized, and legacy `Copy` suffixes normalize to the Chinese duplicate suffix. Verify contrast, focus, and titles in authenticated light/dark, 390px, keyboard, and asset-hover scenarios.
- User task details now show only the snapshot public model ID and fall back to “平台模型”; revoking a login session from Account requires confirmation; the homepage “我的资产” tab now renders real local image assets with a matching empty state. Verify authenticated snapshots with and without public IDs, confirm/cancel behavior, and asset create/delete/filter flows.
- Homepage carousel arrows stay visible and vertically centered on touch screens, artwork actions expose a visible keyboard focus state, negative letter spacing was removed from login/account/task/create/preview styles, and modal backdrops use theme tokens. Verify desktop/390px light/dark and keyboard Tab paths.
- The standalone home example now uses a local real artwork asset instead of gradient-orb decoration; it is not a production route and still needs a development-entry visual check for cropping, narrow screens, and theme contrast.
- Latest command regression: all 100 server tests pass; web/admin typechecks, web/admin builds, admin lint, `npm run build:all`, and `git diff --check` pass. Builds retain only the existing large-chunk and dynamic-import notices; authenticated writes and in-canvas menu interaction remain pending below.
- This turn's 390px core-route smoke covered `/`, `/login`, `/register`, `/components`, `/style-preview`, plus canvas, assets, tasks, account, settings, and image/audio creation entries: public pages had no captured console errors, protected entries redirected to login after auth hydration, and every route had no horizontal overflow.
- The admin page-settings drawer now closes through an idempotent state setter, and the custom theme-color panel is controlled so repeated close events cannot reopen the drawer or leave a stale color. Verify rapid repeated clicks, overlay/Escape/close-button dismissal, and reopening the custom color panel after selecting a preset.
- The regular canvas prompt editor and node resource textarea mention menus now expose `listbox/option` semantics, active-item associations, and localized labels in both languages. Verify keyboard arrows, Enter, Escape, mouse selection, focus, and inserted references in an authenticated canvas.
- This turn's independent browser smoke used `http://localhost:3008/` and `http://localhost:3009/admin/login`: desktop and 390×844 user home plus admin login had no horizontal overflow or captured console errors, and the admin mobile layout had no extra card container. Unauthenticated `/canvas` showed a Chinese loading state before redirecting to login. Screenshots are saved at `/tmp/miragenflow-web-home-desktop.png`, `/tmp/miragenflow-web-home-mobile.png`, `/tmp/miragenflow-admin-login-desktop.png`, and `/tmp/miragenflow-admin-login-mobile.png`; authenticated canvas-menu, dark-theme, and write-flow checks still require user-authorized credentials.
- Canvas node/connection creation menus now render in an untransformed viewport overlay, keeping a stable screen size and applying viewport translation/zoom only once with edge clamping. Verify in an authenticated canvas at desktop, 320px, and 390px sizes after pan/zoom, including edge placement, keyboard navigation, Escape/outside dismissal, and focus return.
- The production home inspiration list no longer injects prototype artwork records, authors, or popularity counts; it is built only from real local assets and exposes a Chinese empty state when the library is empty. Audit status charts now distinguish HTTP < 400 from HTTP >= 400 or business errors, and message provider/template writes are persisted in the store snapshot. Verify asset create/edit/delete and newest/oldest sorting in an authenticated browser, then restart a local service to confirm message configuration survives.
- The admin login page now uses a locally optimized `admin-login-background.webp`; the login route mounts the full-screen login surface directly, so desktop and mobile share the left-side content rail without inheriting the admin `Layout/Content` shell or adding a card container/top blur strip. The form keeps the desktop width until the viewport requires proportional reduction with symmetric side spacing, and short screens can scroll vertically. Verify crop, contrast, login-error states, and scrolling across aspect ratios and light/dark themes.
- Admin user, task, message, and audit detail drawers now stay open on request failure and expose a Chinese error with a retry action; the settings and task-attempt drawers explicitly enable close button, overlay dismissal, and Escape. Verify offline, 403, 404, and recovery retries without stale-route overwrites.
- Canvas audio/text settings popovers now shrink to the viewport, while create and context menus add menu semantics, Escape/outside dismissal, and narrow-screen width limits. Verify 320px/390px placement, theme changes, keyboard navigation, and focus return near canvas edges.
- The user account menu now uses the shared TDesign Dropdown adapter while preserving the custom profile visual, guest/login branch, and signed-in account actions. Verify the signed-in options, focus return, Escape/outside-click close, theme contrast, and 390px placement.
- Protected user routes now show a visible Chinese loading status during authentication hydration before redirecting or rendering the page. Verify slow refresh/session-expiry transitions do not leave only the shell navigation visible.
- Channel-group ordering now uses TDesign's supported full-row drag mode, updating the failover draft and save field after a reorder. Verify dragging multiple rows in the edit dialog, saving, and refreshing to confirm persistence.
- Admin detail and task-attempt drawers now show a loading state and cancel/invalidate in-flight requests on close. Verify under a slow network by opening user, task, and audit details then immediately closing them; confirm no drawer reopens and Escape/overlay close work.
- The user routes now show a visible Chinese loading state and a controlled error page with reload/home actions. Device identification falls back to an in-memory value when `localStorage` is unavailable. Verify slow loading, refresh, and restricted-storage scenarios do not produce a blank page.
- User shell navigation and developer preview isolation were hardened: `/components` and `/style-preview` are explicitly excluded from `UserLayout`, preview menus use left-start alignment at every breakpoint, and account/settings/task detail lists wrap on narrow screens instead of forcing a 560px row. Verify desktop and 390px screenshots, direct preview URLs, and keyboard navigation.
- The image creation page now uses a themed controlled disclosure for advanced settings instead of the browser-native `details` control. Verify expand/collapse, keyboard focus, and mobile spacing in light and dark themes.
- User asset sync failures now keep the edit dialog and local draft open, and retrying a new asset reuses the same pending local record. Image/audio task waits now have a ten-minute ceiling, attempt cancellation on timeout, and tell the user to inspect task history for the final state. Verify retry behavior, cancellation races, and task-history status with an authenticated session.
- 用户端画布资源提及输入已迁移到共享 TDesign `TextArea`,并保留真实文本框引用、@ 提及菜单、选区/光标、滚动同步和输入法行为;画布节点、侧栏、图片创作、资产入口、参数选项和主题切换的可见按钮,以及管理台移动菜单遮罩也统一使用共享 TDesign `Button`。`npm --prefix web run typecheck` 与 `npm --prefix web run build` 已通过;需登录后在画布编辑、图片提及、批量操作、深浅主题和 390px 视口下确认视觉与焦点行为。
- In the authenticated same-origin development session at `http://localhost:3008`, all 22 admin entry routes rendered with zero captured console errors; real writes, permission/error paths, and narrow-screen visuals still require page-by-page verification.
- A 390×844 same-origin regression covered the homepage, login, dashboard, channels, and users pages with no horizontal overflow or captured console errors; the collapsed admin sidebar is absent from the accessibility tree. Authenticated canvas, assets, and creation flows remain pending.
- The user task history now assigns a request sequence to status filters, manual refreshes, and polling refreshes, so stale responses cannot overwrite the current rows, loading state, or error message. Verify rapid status changes while requests overlap.
- 本轮新增代码证据:`npm --prefix web run typecheck`、`npm --prefix web run build`、`npm --prefix admin run typecheck`、`npm --prefix admin run build`、`npm --prefix server test`(101/101)和 `git diff --check` 均通过;管理台 `Business/index.tsx` 与图表文件的安静 lint 检查通过。全量页面和管理员登录后的人工验收仍未完成。
- Frontend analytics is now a local no-op and the runtime `config.js` injection was removed, so Google/Baidu scripts are no longer loaded; verify production static preview and container startup have no third-party scripts or extra outbound requests. The local brand font remains an intentional visual asset.
- The first TDesign unification slice is now wired through `packages/ui`: both applications use the shared TDesign Provider, the user client maps its light/dark custom tokens to TDesign variables, and the canvas project library uses the shared button adapter. Verify user-console visual parity, TDesign popup stacking, locale switching, React 19 behavior, and the unchanged admin baseline after a fresh browser load.
- User-side TDesign controls now use `@miragenflow/ui/*` component subpath exports: input, select, switch, textarea, dialog, drawer, dropdown, tooltip, slider, input-number, pagination, tag, and message no longer import `tdesign-react/es/*` directly; subpaths preserve tree-shaking. Verify control visuals, themed popups, and React 19 behavior across user pages.
- Simple text areas in the image tool, audio tool, authentication enrollment, and account MFA flow now use the shared TDesign `TextArea` adapter. The adapter forwards its `textareaElement` ref so image mentions keep selection and caret placement. Verify the generated field height, focus/selection behavior, read-only enrollment content, and light/dark styling after a fresh browser load.
- Canvas image dimension/count fields and the audio settings speed field now use the shared TDesign `InputNumber` adapter. Dimension blur/Enter commits still align to the optional 16-pixel step, count and speed keep their min/max and empty-value behavior, and themed wrapper styles remain local to the canvas. Verify keyboard entry, blur/Enter commits, range correction, disabled resolution fields, and light/dark popup styling.
- Canvas project selection now uses a shared TDesign `Checkbox` subpath with canvas theme tokens. Native file inputs remain limited to hidden upload triggers, and the mention editor keeps its native textarea because selection, scroll, IME, and overlay highlighting depend on the real DOM node. Verify checkbox selection/bubbling, keyboard focus, and the documented native-control exceptions.
- Canvas node title editing now uses the shared TDesign `TextInput` adapter with its real `inputElement` ref. Auto-focus/select, Enter/Escape, blur commit, outside-pointer detection, compact width, and dashed underline styling need browser verification in both themes.
- The local component center verified the shared controls after this migration: the themed select opens and hides on Escape, the example dialog opens and closes from its close button, and the page has no runtime console errors; remaining page dialogs and drawers still require authenticated review.
- This slice also migrated the image/audio/auth/account text areas, canvas image/audio numeric inputs, project checkbox, and canvas-node title input to shared TDesign adapters. `npm --prefix web run typecheck`, `npm --prefix web run build`, `npm --prefix server test` (101/101), `npm --prefix admin run typecheck`, `npm --prefix admin run lint`, and `npm run build:all` pass; public login/component-center browser smoke has no runtime errors. Authenticated canvas settings still need visual and interaction review.
- Finance ledger, recharge-order, and payment-event pages now derive statistic cards and ECharts from real rows and share a date-range filter. Batch channel health checks retain the request path, attempted flag, and test time, while health checks and image-generation tests use distinct labels; admin requests now report timeout, cancellation, and network failures in Chinese. Verify populated/empty states, narrow layouts, date selection, and an upstream timeout.
- Canvas project roots, workspaces, and loading placeholders now use one dynamic viewport height without conflicting `vh/svh` minimum constraints. Catalog synchronization is isolated from the canvas page effects, no-op config writes are skipped, and malformed legacy viewports are normalized. Verify complete top-to-bottom visibility and no update-depth errors at 1280×720, 390×844, during viewport switches, and in projects with persisted nodes.
- The admin settings permission explanation now reports the security-management scope accurately; storage-policy edits use `If-Match` version protection; empty numeric inputs remain empty instead of displaying 0. Verify concurrent-edit conflicts, the settings permission message, and empty-value validation.
- Canvas project pages now keep every root/flex canvas layer at the dynamic viewport height, merge resize observations per animation frame, and ignore no-op viewport/node updates that could cause a React update loop. The user console shell also uses a shrinkable dynamic-viewport content area, and image-tool preview measurements ignore unchanged values. Client bootstrap requests are deduplicated under StrictMode. On narrow screens the side panel opens as an overlay without covering the bottom toolbar, the minimap moves to the upper-right, and the main toolbar is separated from the zoom dock. A signed-in browser smoke verified 1440×900 and 390×844 sizes, text/config node creation, no body overflow, and no console errors; verify image/audio/group interactions and a real project with persisted nodes after a fresh login.
- Switching canvas projects now cancels the previous project's resource restore and generation requests, clears pending timers, and fences persistence/viewport saves to the project that actually finished loading. Verify rapid A-to-B navigation, a generation in flight during navigation, and that each project's nodes and viewport remain isolated.
- Asset platform synchronization now skips no-op replacements and keeps the notification API out of the initialization effect dependencies. Verify opening `/assets` after hydration does not repeatedly request or replace the same list, and that a failed sync leaves local assets usable.
- Editing a model product now explicitly clears a stale channel-group binding when the product is disabled and the group field is emptied; publishing still requires a valid enabled group. Verify unbinding, republishing validation, and version-conflict feedback.
- The account center now labels login devices as “Current browser” / “Device N” instead of exposing device UUIDs; session revocation still uses the server-side identifier. Verify multi-device ordering, current-device detection, and list refresh after revocation.
- The admin sidebar now disappears completely when collapsed instead of retaining an icon rail. On narrow screens it opens above the page with a backdrop and closes after navigation or backdrop dismissal. Business lists remain compact tables with horizontal touch scrolling, while page and card side spacing is reduced. Verify collapse/restore on desktop, backdrop behavior at 390px, and horizontal scrolling across every admin list.
- AI creation panels, result/reference containers, and asset previews/placeholders now use the shared theme surfaces instead of hard-coded near-black or Stone backgrounds. Guests no longer see “Profile” or “Log out” in the lower-left sidebar, while authenticated users retain both actions. Verify `/tools/image`, `/tools/audio`, and `/assets` in both themes, then compare guest and signed-in sidebar states.
- Shared panels, stat cards, and dialogs on the user account, task, and sync-settings pages now use theme surfaces as well, so light mode no longer shows dark containers. Verify populated and empty states on each page.
- Canvas crop and split previews now follow the active canvas theme, and the node information dialog no longer exposes a raw JSON tab; it keeps fielded ID, type, size, position, and status details. Non-essential English on the homepage, style preview, and component verification route is translated, and showcase buttons now have explicit demo navigation/dialog behavior. Verify these surfaces in both themes and development routes.
- The user client and admin now use localized Lineicons subsets instead of Lucide or direct TDesign business-icon imports. Common user-client glyphs render at 22px with at least a 36px hit area; admin menu, header, and primary action glyphs render at 24px with 40px hit areas. Undo, redo, stop, sidebar, grouping, text, generation, and favorite states use distinct semantic shapes, and no CDN, webfont, or full icon catalog is loaded. Verify all routes, dark theme, collapsed navigation, canvas rotation/undo controls, dropdowns, dense action columns, and 390px layout.
- User-facing model, task, image-parameter, and canvas image-setting dropdowns now use the shared styled popup rather than native browser `<select>` controls. The outer popup and TDesign content surface share the user theme, with consistent hover, selected, and disabled states. The adapter preserves the existing controlled `onChange(event.target.value)` contract, supports keyboard selection, outside/Escape dismissal, disabled and empty states, and keeps portal menus inside the canvas popover interaction boundary. Verify each dropdown in light/dark themes, keyboard navigation, mobile widths, and selection persistence after reopening.
- User management, the dedicated balance page, and user details now place separate add-coins and deduct-coins icon actions beside the balance. The amount and reason labels are associated with their controls; the dialog accepts only a positive integer amount, shows the current and projected available balance, and requires a reason. Local super administrators automatically execute the recorded approval and refresh the visible balance after confirmation; if automatic execution fails, the saved request opens in the approval center instead of inviting a duplicate submission. Production still requires a second finance administrator. Verify both directions, MFA-enabled local execution, failure recovery, subsequent task spending, stale-version/replay rejection, insufficient-balance prevention, dialog closing, and the approval-center actions.
- Admin create/edit fields now use a single controlled state source instead of unnamed TDesign `FormItem` state, so persisted values are no longer replaced by empty internal form values. Channel base information, model-list and model-mapping backfill, tab preservation, cancel closing, and an error-free console were browser-verified; verify the remaining resource editors.
- Channel models are now persisted independently from optional display-to-request mappings. Upstream discovery renders a checkbox list and “Add selected models” action; it never creates mappings. Manual model entry remains available when discovery is not used, and development startup no longer seeds display-only mock channels. Verify create/edit backfill, selection, removal, an empty mapping list, and a fresh development store.
- Channel probing now marks a request as attempted only immediately before the upstream `fetch` call. Generic providers no longer infer health from a configured API key, and protocol, private-network, or DNS validation failures are reported as not attempted. Closing and reopening the dialog cannot be overwritten by an old probe; create/edit save no longer probes implicitly, and the independent loading state is only shown after clicking the model-list button. Verify these success, failure, and race paths.
- Channel model probing now has an independent loading state and reports the actual request path (for example `/v1/models`), whether an upstream request was attempted, and a Chinese reason for DNS, HTTP, empty-list, or network failures. Editing the URL or API key clears stale results; verify success, upstream failure, and unresolvable hosts while confirming the form remains open after failure.
- Channel forms now show complete request URL examples (`https://example.com` and `https://example.com/v1`). API keys are trimmed and only required to be non-empty; the former 16-character minimum is removed consistently for probing, creation, editing, and rotation. Verify a short but valid upstream key through each flow.
- The admin channel dialog uses consistent tabs for base information, model discovery, and model mapping. Tabs are freely switchable, and the dialog-level draft keeps base fields, probe results, and mappings when panels change; the footer always uses Save/Cancel. The model map explicitly separates the platform display model ID from the provider request model ID. Local development enables private provider URLs only through an explicit launcher flag; production keeps the SSRF restriction. Verify free tab switching, failed probes preserving the form, unified save/edit backfill, and a real local-compatible endpoint.
- The admin create-user dialog now contains only username, email, phone, and initial password; status defaults to active, while plans, allowed models, welcome messages, concurrency, and daily limits are configured separately after creation. Verify the minimal form and the existing email/phone requirement.
- The full server regression suite now passes all 101 tests, and web/admin typechecks plus admin lint pass; only existing formatting warnings remain. Browser-based page-by-page acceptance is still required for the checklist below.
- The OpenAI image ratio matrix now covers 1.91:1, 2.35:1, and 21:9 across 1K/2K/4K sizes, and the server accepts the documented wide 1K sizes; new image products use a 3840×2160 4K default preset. Verify every wide ratio in the standalone image page and canvas, including displayed size, actual output dimensions, and billing tier.
- The server now has 69 OpenAI image endpoint regression tests covering ratio conversion, expired/revoked/missing staging references, invalid image URLs, capability schema generation, idempotency headers, and real image metadata during manual reconciliation. A live compatible endpoint is still needed to verify URL outputs, transparent PNG/WebP, and long-running 4K tasks.
- OpenAI image, text, and audio requests now send the standard `Idempotency-Key`; when a provider transport result is unknown, the user image tool keeps the task as “待对账” and links to task history instead of showing a generic failure. Verify the header with a compatible endpoint and the unknown-result browser flow.
- The OpenAI image adapter now fails closed for invalid reference sequences, missing `@图片X` references, oversized reference objects, and more than 16 references, and adds the documented default reference instruction when only images are supplied. Verify these boundaries through both the task API and the internal adapter path.
- The admin security menu now points to a valid settings route, logout is isolated from the generic menu navigation handler, approval actions reject self-approval by administrator ID/email/name, and audit category/actor fallbacks remain Chinese. Verify with multiple administrator identities and sparse audit records.
- Admin pagination no longer shows an unnecessary total-count summary, and create/edit dialogs explicitly enable overlay, Escape, cancel, and close-button dismissal. Verify every write dialog closes on each path and closes automatically after a successful async save.
- The admin channel editor now uses one consistent OpenAI Images form for both creation and editing. The provider selector, generic-provider branch, and step wizard are removed; the form contains the HTTPS base URL, bearer API key, base model ID, optional 1K/2K/4K model mapping, priority, and `/v1/models` probing. Verify that no generic/provider-choice fields appear, both dialogs use the same layout, and generation/edit requests work against a real compatible endpoint.
- PNG/JPEG/WebP uploads now use the multipart endpoint so a single image can reach the 50 MB limit without the JSON body cap; Chinese reference mentions match longer names first (for example `@图片十一`), canvas base aspect ratios are stored as `ratio`, and reference-image fidelity defaults to high. Verify large uploads, images eleven through sixteen, aspect switching, and legacy canvas settings.
- The user image tool now supports up to 16 ordered reference images, 50 MB per image, Chinese reference names, and `@图片一` mentions. Verify ordering, removal, missing-reference validation, structured output metadata, and manual reconciliation behavior for unknown provider results.
- Admin success reconciliation now uploads the real PNG/JPEG/WebP output as multipart and validates image magic bytes; channel edits can probe `/v1/models` with the stored credential, and model-product creation includes a graphical resolution matrix. Verify large files, existing-output reconciliation, invalid-file rejection, and retained form state after failed probes.
- The development launcher reserves distinct ports before starting the three processes. Verify the printed frontend `/admin/` proxy URL remains correct when the default ports are occupied.
- Admin visualization now uses ECharts for the system overview, channel health, task center, realtime metrics, and audit dashboard. Audit is split into a log dashboard and detailed logs; the dashboard shows category share, normal HTTP 200 versus error 4xx/5xx share, and time trend, while detailed logs add a status column. Verify populated and empty states, narrow screens, dark theme, readable Chinese labels, and note that realtime metrics are a short frontend polling sample rather than durable history.
- The admin sidebar now uses distinct semantic icons for business entries; groups with one visible page render that page directly, while the Audit group exposes both a dashboard and detailed-log entry and other multi-page groups remain expandable. Verify icon contrast, current-route highlighting, role-filtered menus, collapsed mode, and narrow-screen behavior.
- Admin business lists and detail drawers now use Chinese field labels and structured values throughout: balances show available/reserved coins, nested objects are no longer rendered as raw JSON, and credential/hash/idempotency fields are hidden. Only the user list renders its `ID` column as 1, 2, 3 in current-list order; model, plan, and channel identifiers keep their real values, while allowed models use readable names. Verify every admin route has no “other information” columns, raw JSON, untranslated action/status values, or unintended English.
- Audit logs now use fixed time, category, behavior, actor, object, identifier, request, and source columns, with newest records first. The server supplies Chinese behavior mappings and readable actors: administrator email, ordinary-user name, system, or payment callback; verify role/action coverage and that no empty Actions column or raw action code is visible.
- The admin system overview now falls back to safe values for missing statistic fields instead of crashing TDesign Statistic; verify `/admin/dashboard/base` with an empty task history and after session refresh.
- The admin system overview now renders a loading state and a Chinese empty-data panel with a refresh action when the dashboard response has no row, while request errors retain the retry alert. Verify the empty response and recovery path in `/admin/dashboard/base` after an authenticated session.
- Desktop authentication pages now use symmetric vertical padding so the bilingual brand heading and form sit closer to the viewport center with less top whitespace; verify login and registration at common desktop heights while preserving the mobile spacing.
- The user profile dropdown now remains visible for guests with a refined visual placeholder slot, a login prompt, and future artwork space; signed-in users see identity details and account/task/logout actions. Verify hover/focus behavior, light/dark contrast, and narrow-screen fit.
- The notification popover now uses a responsive short height with a viewport-based maximum while preserving its rounded corners; verify empty and populated states at desktop, tablet, and narrow viewport heights.
- The user-console sidebar is now 224px wide on desktop and mobile, with nav rows and lower links slightly shorter; verify the wider drawer, content offset, and label fit at desktop and narrow-screen widths.
- Password login now uses a single “Account” field; verify that email, phone (including spaced or hyphenated input), and username values are detected and accepted without showing separate email/phone/username tabs.
- 管理台入口现在会把绝对站点 base URL 规范化为 React Router 的路径 basename;请在 `/admin/dashboard/base` 直达、刷新和 site 静态构建预览下确认页面不再白屏,并确认未登录时会落到 `/admin/login`。
- The login reward entry no longer renders the oversized floating reward card or transparent hit overlay. The GIF sweep is replaced with a CSS gradient border on a transparent background; verify that the label remains readable in the light theme without crowding the avatar/navigation.
- The gradient border now uses a masked border layer so the button center stays fully transparent; verify that no fill appears inside the rounded frame.
- The reward label now follows the “作品灵感” tab typography with a lighter brand weight while keeping only “免费” highlighted; verify that all three text groups fit on desktop and mobile.
- The canvas and one-click-draft entries now use full-card image surfaces instead of the former CSS-only gradient cards; verify image cropping, overlay readability, and the existing navigation targets across desktop and mobile.
- The two mobile tool cards below the carousel now use the same aspect ratio as the two banners above; verify aligned edges and consistent image/text cropping on narrow screens.
- The visitor avatar artwork and “加入设计交流群” sidebar card are temporarily removed; the mobile header hides the left brand logo while keeping the collapse-menu button. Verify that guest avatars no longer open a large image, signed-in profile links still work, and the mobile drawer/side links remain usable.
## V1 Current Verification
- The `MiragenFlow-front` visual foundation is copied under `web/src/user-console/`; verify desktop/mobile shell spacing, the removed search/model-square navigation, compact-brand component-center login/register/reset/verify screens (brand text above the form title without the MF icon/container), the “登录免费送积分” login reward copy with “免费” highlighted and its original visual treatment, same-ratio mobile/desktop advertising images without crop, AI image/audio creation cards, and that real canvas/assets/tools routes remain functional after navigation.
- A `/style-preview` page now compares four candidate palettes—Twilight Blue-Gray, Warm Paper Cobalt, Mist Glass, and Turquoise Graphite—without changing production tokens; compare the four cards on desktop and narrow screens, then select one direction before applying it across the user-facing pages.
- The confirmed Mist Glass direction is now applied to the user client: lavender backgrounds, translucent white surfaces, violet primary actions, and coral accents cover the homepage, authentication, creation, canvas, and assets surfaces; verify contrast, TDesign overlays, narrow-screen scrolling, and the readable dark violet variant after toggling the theme.
- Authentication now separates password login (email/phone/username) from SMS code login; registration has email and phone paths with independent admin switches for registration-email and registration-phone verification. Verify disabled direct registration, enabled code-first registration/password confirmation, SMS send/resend/rate-limit errors, and MFA chaining.
- Authentication switches now control independent admin CAPTCHA, stale MFA challenge invalidation, refresh-session state, and audit retention; verify browser forms hide CAPTCHA/MFA/recovery fields when disabled and admin login accepts email/password only.
- Admin list pages now provide section-specific facet/date filters, the dashboard includes a seven-day task trend and runtime alerts, and API-level 403 responses navigate to the recoverable permission page with roles, required scope, and request ID; verify filters preserve pagination and both login recovery buttons clear the correct session state.
- PostgreSQL dispatch can hydrate a task claimed by another instance before publishing it; verify a worker with an empty local task map eventually enqueues and executes a task created by a different instance.
- PostgreSQL snapshot saves now fence against the revision captured when the snapshot was taken; verify a queued stale snapshot cannot overwrite a direct lease/outbox update under concurrent workers.
- Queue claim, Redis active leases, PostgreSQL task-heartbeat/expiry recovery, verification snapshot loading, and message dead-letter boundaries were hardened; verify worker ownership, stale ack/nack rejection, retries, and restart recovery with PostgreSQL/Redis multi-instance deployment.
- PostgreSQL message outbox leases renew while provider requests are in flight and completion remains owner/expiry fenced; real provider timeout and two-instance duplicate-send verification is still pending.
- Message enqueue accepts a caller idempotency key and forwards a stable `Idempotency-Key` to providers; verify the semantics with each real email/SMS provider.
- The task center now exposes a redacted task-detail drawer and approvals support version-guarded rejection with a reason; verify timeline/output redaction and stale-version retry behavior.
- Unknown tasks now offer success/failure reconciliation with an optional charged-coin amount, balance-unit configuration preserves precision and rounding, and channel creation probes the channel before saving; verify settlement, release, credential validation, and probe feedback.
- Finance administrators now have a dedicated user-balance adjustment page backed by a minimal user target list containing only redacted identity and balance fields. Approval requesters no longer see self-approval actions, and detailed audit logs expose a closable detail drawer; verify finance-role visibility, adjustment approval, action-column visibility, and all drawer close paths.
- Management console refactor pending browser verification: grouped `/admin/` navigation, scope-hidden menu items, recoverable 403/404 buttons, user creation drawer, channel/group/model/price creation dialogs, fixed-width tables, Chinese health/capability labels, and authentication-message detail/retry.
- Channel, channel-group, and model-product edit drawers are available, channel health supports probing all channels, and message lists no longer return target hashes. Verify If-Match conflicts, batch-probe failures/retries, Chinese status labels, and fixed columns in narrow windows.
- Management console user workbench now includes one-time admin password reset, verification-message resend, session/entitlement detail, dashboard P50/P95 and channel/message/payment anomaly metrics; verify these actions in a browser with a non-super-admin scope matrix.
- Management console user details now expose account, sessions, tasks, ledger, entitlements, and audit tabs; the independent `/api/v1/admin/settings` resource persists security switches and applies authentication policy changes immediately. Verify tab data, If-Match conflicts, switch-off cleanup, and retry states in a browser.
- Current service checks: `npm run typecheck:server`, `npm run test:server` (101 tests, all passing), `npm run typecheck:web`, `npm run typecheck:admin`, `npm --prefix web run build`, `npm --prefix admin run build`, `npm --prefix admin run lint`, `npm run build:all`, and `git diff --check`; admin lint has no errors and only existing formatting warnings.
- Local preview defaults to administrator `admin@admin.com` with password `admin`; administrator MFA and CAPTCHA remain off by default and can be re-enabled through environment variables.
- Authentication: ordinary users default to email/password only; email/phone verification, CAPTCHA, and user MFA remain switchable enhancements, alongside the independent admin audience, multi-admin roles, admin MFA setup/disable, and refresh reuse.
- Account APIs: user plan entitlements and session listing/revocation should preserve ownership checks and revoke the selected refresh-session family.
- Authentication/privacy: the admin MFA CAPTCHA exemption is bound to the current admin session, user/admin MFA secrets and payment-adapter credentials remain encrypted and restart-persistent server-side, and user-facing payment responses do not expose adapter identifiers or provider keys.
- Billing: pending user recharge orders, signed mock/adapter webhook contracts for recharge and plan orders, payment failure/refund transitions, refund idempotency against the original balance bucket, plan purchase/entitlement snapshots, approval-only manual recharge, reserve allocation, partial settle, release, refund, and idempotency conflict.
- Billing invariants: expired buckets must append idempotent adjustment entries, and plan entitlement availability must follow the actual plan credit bucket after task reserve/settle/release.
- Balance expiry accounting clamps each expiration adjustment to the remaining aggregate balance so the ledger and account projection stay consistent.
- Storage: upload MIME/magic validation and scanner quarantine, private staging/GC, retention-aware output objects, local browser assets, WebDAV encrypted credentials, manifest ETags/version, conflict jobs, tombstones, archive queue, and sync UI.
- WebDAV retention: manifest retention status is persisted and users can extend it within the configured policy limit.
- Asset ownership: saving a task output must reject another user's task/output and return the existing asset on repeated saves.
- V1 exclusions: no video, animation, real 3D, training, teams, content governance, Local Agent, remote Prompt, or plugin marketplace routes/menu entries.
The current scope reduction needs manual verification in these areas:
- The homepage, browser title, configuration storage, export files, WebDAV default directory, and internal plugin SDK use the new MiragenFlow / 元境幻生 naming.
- The `web/` frontend and `admin/` console start together with `bun run dev:all` and both load through port 3000; the production build serves `/` and `/admin/` correctly.
- The top-right navigation no longer shows a GitHub entry; documentation, settings, locale, theme, and version controls remain available.
- Navigation exposes only the homepage, canvas library, canvas project, My Assets, and Settings; removed routes should show the not-found page.
- The top-right navigation no longer shows a GitHub entry; documentation, storage settings, locale, and theme controls remain available. Frontend release/version controls are not part of the user surface.
- Navigation exposes only the homepage, AI creation, canvas library, My Assets, and account/task actions; removed model-square and search routes should show the not-found page.
- No independent image workspace, video workspace or video node, Prompt Center, remote prompt source, local Agent connection, or remote plugin marketplace remains in the interface.
- Canvas projects can still be created, renamed, duplicated, imported, exported, and deleted without losing their nodes, connections, viewport, or appearance settings.
- Image, text, audio, generation-configuration, and group nodes can still be created, connected, edited, generated, retried, copied, grouped, and exported.
- Image generation, reference-image editing, text generation, and audio generation use the selected channel and model; cancellation and failure states remain usable.
- Reverse prompt, multi-angle generation, crop, mask edit, split, and local upscale create the expected connected result nodes.
- My Assets still supports text and image records, including import/export, search, editing, canvas insertion, copying, downloading, and deletion.
- Settings contains Channels, Preferences, WebDAV, and Local Storage only. Configuration import/export and local storage statistics should still work.
- WebDAV synchronizes canvases, assets, and referenced image/audio files while leaving AI credentials local.
- English and Simplified Chinese remain complete across retained navigation, settings, canvas controls, messages, and Ant Design components.
- My Assets still supports text, image, and audio records, including import/export, search, editing, canvas insertion, copying, downloading, and deletion.
- `/settings` contains only WebDAV and local storage; provider channels, model preferences, and custom scripts are managed by the service and are not exposed to users.
- The user client no longer exposes provider channels, Base URLs, API keys, custom scripts, or remote plugin configuration; `/settings` contains only local storage and WebDAV controls.
- WebDAV synchronizes canvases, assets, and referenced image/audio files while leaving AI credentials local; the settings page reloads saved WebDAV connection status from the server after refresh.
- English and Simplified Chinese remain complete across retained navigation, settings, canvas controls, messages, and TDesign components.
- The new `server/` process starts with `npm run dev:server`, exposes the shared contracts version through `GET /api/health`, and passes its typecheck and health test.
- During local development `/api` and task WebSocket traffic are proxied to port 3100 instead of the TDesign template's Tencent example API.
- Registration, verification, password login, public model catalog, balance, task idempotency, and event history still need end-to-end browser verification; 3D requests must return `CAPABILITY_NOT_ENABLED`.
- Unknown tasks without a provider request ID now release expired reservations; live staging objects are protected from TTL cleanup, and production Compose refuses to start without explicit secrets. A production-profile smoke with temporary PostgreSQL and Redis verified `/api/ready`, all eighteen migrations, canonical user/balance/ledger/channel/task/attempt/event rows, task snapshots, dispatch outbox, payment fingerprints, message outbox lease fields, PostgreSQL write/read-after-reload, final `sent` outbox dispatch state, revision fencing, and Redis lease claim/renew/ack/nack; the temporary dependencies were removed after verification.
- Same-origin route smoke verified `/`, `/admin/`, `/api/v1/`, and `/api/ready` through the development origin; unauthenticated `/api/v1/ws/tasks` is rejected as expected. Full browser interaction remains a manual UI check.
- The admin console now exposes a create-after-publish switch for model products, per-channel batch-probe results, read-only task details/call records, and session-clearing recovery actions on error pages; verify each drawer, permission state, retained form, and 409 retry in a browser.
- Administrator MFA setup/verification is now gated by the system enhancement switch; verify that the login page, security page, and recovery-code fields stay hidden while disabled and appear only after enabling the switch.
- PostgreSQL WebDAV completion now commits file/manifest, retention/archive state, and conflict-copy jobs with the owner-fenced job update; retention scanning now uses a row-locked PostgreSQL transaction and retries terminal jobs. Verify restart recovery, conflict retry, expired-lease fencing, and two-worker behavior against real PostgreSQL/WebDAV.
- Isolated browser smoke verified default account/password registration and login, canvas library, account sessions, plan purchase, settings, desktop navigation labels, mobile navigation, and removed-route 404 behavior. Enhanced CAPTCHA/MFA switches and external WebDAV/provider interaction remain deployment-environment work.
- Docker Compose interpolation and healthcheck configuration were verified; the image build itself was blocked by the current environment's Docker Hub TLS certificate mismatch, so production image delivery still needs a registry/network retry.
- CAPTCHA responses only expose the human challenge, never the answer or reversible plaintext; WS refresh-cookie family revocation, invalid WebDAV paths, readiness failures, 3D catalog filtering, public model IDs, and WebDAV checksum/conflict handling have regression coverage.
- The V1 regression suite now also covers explicit MFA recovery, user session listing/revocation, `/me/plans`, separate-admin approval execution, asset ownership/deduplication, WebDAV manifest retention limits and valid writes, expired bucket ledger entries, and channel-group route ordering.
- Access tokens now carry a session-family binding; revoking a session invalidates its bearer token and WebSocket subscriptions immediately. The documented admin singleton/detail method aliases have regression coverage.
- Admin create forms now omit blank resource IDs so the server generates stable identifiers; plan, user, and model forms validate server-side constraints before submission, finance configuration is restricted to finance scope, and provider/template edits enforce version matching. Verify invalid-form feedback, role visibility, publish prerequisites, and stale-edit conflicts in the browser.
- 用户端画布裁剪/蒙版编辑、资产图片/音频/封面选择和验证/重置页人机验证已增加当前输入代次保护;过期图片元数据、较早文件上传或旧验证码响应不会覆盖当前草稿,文件读取/上传失败会显示中文错误。需通过延迟第一份图片元数据、反转两次文件上传和反转两次验证码请求的浏览器场景,确认最终预览、尺寸、标题、验证码题目和提交 ID 始终属于最后一次选择。
- 用户端画布资源提及输入已迁移到共享 TDesign `TextArea`,并保留真实文本框引用、@ 提及菜单、选区/光标、滚动同步和输入法行为;画布节点、侧栏、图片创作、资产入口、参数选项和主题切换的可见按钮,以及管理台移动菜单遮罩也统一使用共享 TDesign `Button`。`npm --prefix web run typecheck` 与 `npm --prefix web run build` 已通过;需登录后在画布编辑、图片提及、批量操作、深浅主题和 390px 视口下确认视觉与焦点行为。
- 本轮新增代码证据:`npm --prefix web run typecheck`、`npm --prefix web run build`、`npm --prefix admin run typecheck`、`npm --prefix admin run build`、`npm --prefix server test`(101/101)和 `git diff --check` 均通过;管理台 `Business/index.tsx` 与图表文件的安静 lint 检查通过。全量页面和管理员登录后的人工验收仍未完成。
- 本轮还将图片/音频/认证/账户文本域、画布图片宽高与数量、音频语速、项目复选框和画布节点标题输入迁移到共享 TDesign 适配器。`npm --prefix web run typecheck`、`npm --prefix web run build`、`npm --prefix server test`(101/101)、`npm --prefix admin run typecheck`、`npm --prefix admin run lint` 和 `npm run build:all` 均通过;未登录浏览器的登录页和组件中心无运行时错误。登录后的画布设置仍需人工检查视觉和交互。
- AI 创作面板、结果/参考图容器和资产预览/占位区域已统一使用主题语义色,不再硬编码近黑色或 Stone 背景;游客左下角不再显示“个人主页”和“退出登录”,登录用户仍保留这两个入口。需在浅色/深色主题下验证 `/tools/image`、`/tools/audio`、`/assets`,并分别确认游客与登录状态。
- 管理台所有业务列表和详情已统一使用中文字段与结构化展示:余额显示可用/预留金币,嵌套对象不再直接输出 JSON,内部凭证/哈希/幂等标识会隐藏;仅用户列表的 ID 按当前列表显示为 1、2、3 等纯数字,模型、套餐、渠道等其他 ID 保留真实值,可用模型显示名称。需逐页确认无“其他信息”、原始 JSON、未翻译动作或异常英文。
- 已执行 `npm run typecheck:server`、`npm run test:server`(101 项全部通过)、`npm run typecheck:web`、`npm run typecheck:admin`、`npm --prefix web run build`、`npm --prefix admin run build`、`npm --prefix admin run lint` 和 `npm run build:all`;`git diff --check` 通过,管理台 lint 仅有既有格式化警告、无错误。
@@ -5,4 +5,31 @@ description: Planned follow-up work
# TODO
No follow-up item is currently confirmed. New work should stay within the retained image, text, audio, canvas, asset, WebDAV, and internal-extension scope.
- Planned: unify `web/` and `admin/` on one locked TDesign component runtime while preserving the user-console custom visual system and the admin visual baseline. The single canonical long-task scope and copyable goal prompt are recorded in `docs/miragenflow-long-task-goal-prompt.md`; component migration details, shared-boundary rules, deletion/retention list, and acceptance gates remain in `docs/miragenflow-tdesign-unification-goal.md`. Implementation must remain phased until Ant Design, ProComponents, Radix controls, and `.ant-*` behavior dependencies are fully migrated and browser-verified.
## Long-task execution checklist
This is an index for `docs/miragenflow-long-task-goal-prompt.md`. Check an item only when code, command, or browser evidence exists; unchecked work must not be described as complete.
- [x] P0: confirm `tdesign-react@1.15.1`, the shared Provider, theme-variable bridge, and local Lineicons subset while keeping `web/` and `admin/` route, permission, state, and API boundaries separate; package entrypoints, source scans, typechecks, and production builds provide current evidence.
- [ ] P1: migrate ordinary controls, themed dropdowns, feedback, overlays, and forms; remove native `<select>` and verify keyboard, backdrop, Escape, focus return, and controlled fields.
- [ ] P2: complete real read/write, persistence, permission, error, and retry flows across all 22 admin entries, covering users, coins, channels, models, billing, tasks, settings, and audit.
- [ ] P3: regress the user homepage, authentication, AI creation, canvas, assets, tasks, account, and mobile layouts, including dynamic viewport height, theme surfaces, left-aligned titles, guest menu, and compact lists.
- [ ] P4: remove the user-side `web/` Ant Design, ProComponents, Radix controls, reset CSS, and remaining `.ant-*` dependencies only after references are clear, builds pass, and browser regression is complete; keep the admin TDesign baseline unchanged.
### Acceptance matrix
| Scope | Current status | Required evidence |
| --- | --- | --- |
| Eight core user routes | Public/protected route shells and desktop/390px theme smoke verified; authenticated page review pending | Authenticated desktop/390px, light/dark, refresh, and clean console |
| 22 admin pages | All business deep links load after local administrator login; authenticated interactions remain pending | Screenshots, write results, persistence after reopening, permission/error/retry paths |
| Five ECharts areas and audit dashboard | Implemented; populated/empty/error review pending | Charts, theme switch, narrow layout, category counts and ratios |
| Component and dependency cleanup | In progress by phase | Typecheck/build/lint, static scans, and `git diff --check` |
### External dependencies or out-of-scope blockers
- [ ] Production email, SMS, and payment adapters: waiting for provider contracts; do not replace them with display-only mocks.
- [ ] Horizontal production scaling: incremental domain-table SQL, task row-level CAS, and remote WebDAV/message race verification remain outstanding.
The management-console shell and first P1 interactions are now implemented from `goal.md` and `admin-plan.md`: grouped navigation, recoverable permission pages, local admin credential reset, ordinary-user creation, modal-based channel/group/model/price creation, fixed-width Chinese status/capability rendering, authentication-message detail/retry, and user detail tabs. The independent versioned `/api/v1/admin/settings` resource now controls authentication enhancements and rate-limit values at runtime. The user-console visual foundation from `MiragenFlow-front` is now copied under `web/src/user-console/` and wired to real asset/catalog/routes; its static demo data and unsupported feature placeholders are intentionally not used as production data. Remaining work is full browser verification of all 22 admin pages and the migrated user shell, deeper domain-table/CAS migration before horizontal production scaling, plus connecting production email/SMS/provider adapters after their documentation is supplied. Task creation/reserve, settlement/release/reconciliation, and payment callbacks execute inside Store transaction boundaries with PostgreSQL snapshot atomicity; replacing the snapshot projection with incremental domain-table SQL and cross-instance worker claims/CAS remains required.
@@ -5,7 +5,7 @@ description: Security reporting and responsible disclosure
# Report a Vulnerability
See [SECURITY.md](https://github.com/basketikun/infinite-canvas/blob/main/SECURITY.md). Do not post exploit details, private API keys, sensitive screenshots, or real user data in a public issue.
See [SECURITY.md](https://git.awaioi.com/awaioi/MiragenFlow/src/branch/main/SECURITY.md). Do not post exploit details, private API keys, sensitive screenshots, or real user data in a public issue.
Use GitHub private vulnerability reporting or a Security Advisory. If unavailable, email [1844025705@qq.com](mailto:1844025705@qq.com) with `[MiragenFlow security]` in the subject.
请不要在公开 Issue 中直接发布漏洞细节、可利用代码、私密 API Key、截图中的敏感信息或真实用户数据。
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.