john
fde6503bdf
feat(mindspace): add SEO/GEO delivery, page template catalog, and admin hooks
...
Memind CI / Test, build, and release guards (push) Has been cancelled
Enable optional SEO/GEO injection and discovery routes for confirmed public pages while keeping private pages noindex. Add premium page template skills, portal catalog API, template shop UI, and Baidu push gated by memind_adm config.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-08-10 08:06:12 +08:00
john
933466c8ab
fix: preserve chat order and published page scripts
2026-07-15 14:05:09 +08:00
john
eea14c1855
Add page data delivery and publication guards
2026-07-08 21:10:47 +08:00
john
ac520d8ae5
fix(mindspace-public): 公开页区分作者与访客视图 + 图片加载自动重试
...
工作区直链 /MindSpace/<userId>/public/*.html 此前对所有人(含匿名访客、
转发链接收到的其他登录用户)展示完全相同的悬浮操作按钮,导致非作者也能
看到"发布 Plaza"入口——而 Plaza 发布会把内容归属到操作者自己的账号下,
必须只对作者开放。
- server.mjs: serveUserPublishFile 用现有 session/cookie 鉴权判断访问者是
否等于 URL 中的 ownerKey,结果透传给 sendPublishFile;该响应内容因人
而异,显式加 Cache-Control: private, no-store(原来未设置任何缓存头)
- mindspace-public-share-widget.mjs: injectPublicFileShareButton 新增
isOwner 参数(默认 true 保持兼容),非作者时隐藏"发布 Plaza"按钮与确认
弹窗,"保存长图"/"公开分享"对所有访客保留
- mindspace-public-delivery.mjs: 透传 isOwner,并注入图片重试脚本
- mindspace-public-image-retry.mjs(新增): 页面级 onerror 之前用捕获阶段
监听拦截 mindspace 资产图片的加载失败,带退避自动重试 3 次,避免刚生成
页面时的资产物化竞态被"永久占位符"放大成显示故障
本地起服务用 owner / 非 owner 已登录用户 / 匿名访客三种身份实测验证。
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-07-07 10:56:26 +08:00
john
29d9a87d4f
feat: split h5 direct chat from goosed tasks
2026-07-04 14:02:18 +08:00
john
f543a91cc4
fix: allow inline page scripts in MindSpace public page CSP
...
Collect sha256 hashes from all inline scripts in published HTML so agent-generated
fade-in animations are not blocked while keeping the share-button CSP model.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-07-03 22:42:29 +08:00
john
ec5b1a6e3f
feat: finalize mindspace service extraction phase a
2026-07-03 08:40:28 +08:00