Compare commits
25 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 59cfbcde6c | |||
| 75b32d959c | |||
| 3659368927 | |||
| 93811f4657 | |||
| 4d57c35b66 | |||
| a5d109d585 | |||
| 331a863288 | |||
| 486e25f86b | |||
| f4bc716789 | |||
| 3cafadba5a | |||
| 122e478894 | |||
| 7b0f269180 | |||
| c7e4a063bf | |||
| fe5d32b451 | |||
| 30fcbaf613 | |||
| e0d4868908 | |||
| e7d5c09e56 | |||
| 475328830a | |||
| 5674d53a64 | |||
| 6250b5989c | |||
| ddb3a330f4 | |||
| 8ac159a5ed | |||
| f6dcf5b14a | |||
| f2d0c99f6c | |||
| 77f1ea8350 |
@@ -0,0 +1,69 @@
|
||||
name: Memind CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: memind-ci-${{ gitea.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
verify:
|
||||
name: Test, build, and release guards
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
|
||||
steps:
|
||||
- name: Check out exact commit
|
||||
run: |
|
||||
git init .
|
||||
git remote add origin https://git.tkmind.cn/tkmind/memind.git
|
||||
git fetch --depth=2 origin "${{ gitea.sha }}"
|
||||
git checkout --detach FETCH_HEAD
|
||||
test "$(git rev-parse HEAD)" = "${{ gitea.sha }}"
|
||||
|
||||
- name: Install system test dependencies
|
||||
run: |
|
||||
apt-get update
|
||||
apt-get install --yes --no-install-recommends sqlite3
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
|
||||
- name: Install locked dependencies
|
||||
run: |
|
||||
npm ci --include=optional
|
||||
SHARP_ARM64_VERSION="$(node -p "require('./package-lock.json').packages['node_modules/@img/sharp-linux-arm64'].version")"
|
||||
LIBVIPS_ARM64_VERSION="$(node -p "require('./package-lock.json').packages['node_modules/@img/sharp-libvips-linux-arm64'].version")"
|
||||
npm install --no-save --package-lock=false \
|
||||
"@img/sharp-linux-arm64@${SHARP_ARM64_VERSION}" \
|
||||
"@img/sharp-libvips-linux-arm64@${LIBVIPS_ARM64_VERSION}"
|
||||
node -e "import('sharp').then((sharp) => sharp.default({ create: { width: 1, height: 1, channels: 4, background: '#000' } }).png().toBuffer())"
|
||||
|
||||
- name: Check patch formatting
|
||||
run: git diff --check HEAD^
|
||||
|
||||
- name: Run full test suite
|
||||
run: npm test
|
||||
|
||||
- name: Build production frontend
|
||||
run: npm run build
|
||||
|
||||
- name: Verify MindSpace publish guards
|
||||
run: npm run verify:mindspace-publish-guards
|
||||
|
||||
- name: Verify MindSpace page sync guards
|
||||
run: npm run verify:mindspace-page-sync-guards
|
||||
|
||||
- name: Verify Page Data delivery
|
||||
run: npm run verify:page-data
|
||||
|
||||
- name: Check published download links
|
||||
run: npm run check:mindspace-public-links
|
||||
+43
-1
@@ -15,6 +15,33 @@ export function resolveSandboxMcpNodeExecPath(overridePath) {
|
||||
return process.execPath;
|
||||
}
|
||||
|
||||
const LOOPBACK_PG_HOSTS = new Set(['127.0.0.1', 'localhost', '::1']);
|
||||
|
||||
export function resolveSandboxMcpUserDataPgUrl({
|
||||
portalUrl,
|
||||
mcpUrl,
|
||||
containerized = false,
|
||||
hostGateway = 'host.docker.internal',
|
||||
} = {}) {
|
||||
const explicitMcpUrl = String(mcpUrl ?? '').trim();
|
||||
if (explicitMcpUrl) return explicitMcpUrl;
|
||||
|
||||
const sourceUrl = String(portalUrl ?? '').trim();
|
||||
if (!sourceUrl || !containerized) return sourceUrl;
|
||||
|
||||
try {
|
||||
const parsed = new URL(sourceUrl);
|
||||
if (LOOPBACK_PG_HOSTS.has(parsed.hostname)) {
|
||||
parsed.hostname = String(hostGateway || 'host.docker.internal').trim();
|
||||
}
|
||||
return parsed.toString();
|
||||
} catch {
|
||||
// Preserve the configured value so the MCP reports the real configuration
|
||||
// error instead of silently falling back to its local Unix socket default.
|
||||
return sourceUrl;
|
||||
}
|
||||
}
|
||||
|
||||
export function resolveMindSearchMcpServerPath(overridePath) {
|
||||
const normalized = String(overridePath ?? '').trim();
|
||||
if (normalized) return normalized;
|
||||
@@ -311,6 +338,21 @@ function sandboxMcpEnvs(sandboxMcp, mcpTools) {
|
||||
if (sandboxMcp.workspaceRoot || localRoot) envs.MINDSPACE_WORKSPACE_ROOT = sandboxMcp.workspaceRoot || localRoot;
|
||||
if (sandboxMcp.workspaceRef) envs.MINDSPACE_WORKSPACE_REF = sandboxMcp.workspaceRef;
|
||||
if (sandboxMcp.userId) envs.PRIVATE_DATA_USER_ID = sandboxMcp.userId;
|
||||
if (mcpTools.includes('private_data_info')) {
|
||||
const userDataPgUrl = resolveSandboxMcpUserDataPgUrl({
|
||||
portalUrl: sandboxMcp.userDataPgUrl ?? process.env.MINDSPACE_USERDATA_PG_URL,
|
||||
mcpUrl: sandboxMcp.userDataMcpPgUrl ?? process.env.MINDSPACE_USERDATA_MCP_PG_URL,
|
||||
containerized: Boolean(sandboxMcp.containerized),
|
||||
hostGateway:
|
||||
sandboxMcp.userDataPgHostGateway ?? process.env.MINDSPACE_USERDATA_MCP_PG_HOST ?? 'host.docker.internal',
|
||||
});
|
||||
envs.MINDSPACE_USERDATA_BACKEND = sandboxMcp.userDataBackend ?? process.env.MINDSPACE_USERDATA_BACKEND ?? 'postgres';
|
||||
if (userDataPgUrl) envs.MINDSPACE_USERDATA_PG_URL = userDataPgUrl;
|
||||
const autoProvision = sandboxMcp.userDataAutoProvision ?? process.env.MINDSPACE_USERDATA_AUTO_PROVISION;
|
||||
if (autoProvision != null && String(autoProvision).trim()) {
|
||||
envs.MINDSPACE_USERDATA_AUTO_PROVISION = String(autoProvision).trim();
|
||||
}
|
||||
}
|
||||
for (const key of [
|
||||
'DATABASE_URL',
|
||||
'MYSQL_HOST',
|
||||
@@ -356,7 +398,7 @@ export function buildAgentExtensionPolicy(
|
||||
type: 'stdio',
|
||||
name: 'sandbox-fs',
|
||||
description:
|
||||
'工作区沙箱文件系统与用户私有数据空间。用户私有数据空间是当前用户唯一的 SQLite 数据库,适合问卷、表单、清单、调研数据和分析中间表;不要用于账号、计费、权限、审计、公开平台数据或跨用户数据。',
|
||||
'工作区沙箱文件系统与用户私有数据空间。用户私有数据空间是当前用户隔离的 PostgreSQL schema,适合问卷、表单、清单、调研数据和分析中间表;不要用于账号、计费、权限、审计、公开平台数据或跨用户数据。',
|
||||
display_name: 'sandbox-fs',
|
||||
bundled: false,
|
||||
cmd: resolveSandboxMcpNodeExecPath(sandboxMcp.nodeExecPath),
|
||||
|
||||
@@ -10,6 +10,7 @@ import {
|
||||
normalizeCapabilityPatch,
|
||||
resolveSandboxMcpNodeExecPath,
|
||||
resolveSandboxMcpServerPath,
|
||||
resolveSandboxMcpUserDataPgUrl,
|
||||
sandboxDeveloperTools,
|
||||
sandboxMcpTools,
|
||||
} from './capabilities.mjs';
|
||||
@@ -28,6 +29,30 @@ test('resolveSandboxMcpServerPath honors container-path override without host fs
|
||||
);
|
||||
});
|
||||
|
||||
test('resolveSandboxMcpUserDataPgUrl rewrites a portal loopback URL for container MCP access', () => {
|
||||
const resolved = resolveSandboxMcpUserDataPgUrl({
|
||||
portalUrl: 'postgresql://mindspace:secret@127.0.0.1:5433/mindspace_userdata_prod',
|
||||
containerized: true,
|
||||
});
|
||||
const parsed = new URL(resolved);
|
||||
assert.equal(parsed.hostname, 'host.docker.internal');
|
||||
assert.equal(parsed.port, '5433');
|
||||
assert.equal(parsed.pathname, '/mindspace_userdata_prod');
|
||||
});
|
||||
|
||||
test('resolveSandboxMcpUserDataPgUrl preserves native URLs and honors an explicit MCP URL', () => {
|
||||
const portalUrl = 'postgresql://mindspace:secret@127.0.0.1:5433/mindspace_userdata_prod';
|
||||
assert.equal(resolveSandboxMcpUserDataPgUrl({ portalUrl }), portalUrl);
|
||||
assert.equal(
|
||||
resolveSandboxMcpUserDataPgUrl({
|
||||
portalUrl,
|
||||
mcpUrl: 'postgresql://mindspace:secret@pg-proxy.internal:6432/mindspace_userdata_prod',
|
||||
containerized: true,
|
||||
}),
|
||||
'postgresql://mindspace:secret@pg-proxy.internal:6432/mindspace_userdata_prod',
|
||||
);
|
||||
});
|
||||
|
||||
test('resolveSandboxMcpNodeExecPath honors container-path override without host fs checks', () => {
|
||||
assert.equal(resolveSandboxMcpNodeExecPath('/usr/local/bin/node'), '/usr/local/bin/node');
|
||||
assert.equal(resolveSandboxMcpNodeExecPath(''), process.execPath);
|
||||
@@ -274,11 +299,18 @@ test('private_data_space alone exposes private data tools through sandbox MCP',
|
||||
serverPath: '/opt/h5/mindspace-sandbox-mcp.mjs',
|
||||
sandboxRoot: '/opt/h5/MindSpace/user-1',
|
||||
userId: 'user-1',
|
||||
containerized: true,
|
||||
userDataBackend: 'postgres',
|
||||
userDataPgUrl: 'postgresql://mindspace:secret@127.0.0.1:5433/mindspace_userdata_prod',
|
||||
userDataAutoProvision: '1',
|
||||
},
|
||||
});
|
||||
const sandboxExt = policy.extensionOverrides.find((ext) => ext.name === 'sandbox-fs');
|
||||
assert.ok(sandboxExt);
|
||||
assert.equal(sandboxExt.envs.PRIVATE_DATA_USER_ID, 'user-1');
|
||||
assert.equal(new URL(sandboxExt.envs.MINDSPACE_USERDATA_PG_URL).hostname, 'host.docker.internal');
|
||||
assert.equal(sandboxExt.envs.MINDSPACE_USERDATA_BACKEND, 'postgres');
|
||||
assert.equal(sandboxExt.envs.MINDSPACE_USERDATA_AUTO_PROVISION, '1');
|
||||
assert.deepEqual(sandboxExt.available_tools, [
|
||||
'private_data_info',
|
||||
'private_data_schema',
|
||||
|
||||
@@ -361,6 +361,17 @@ export function stripKnownChatSkillPrompt(text) {
|
||||
break;
|
||||
}
|
||||
}
|
||||
// Older persisted Page Data messages can contain a prompt from a previous
|
||||
// template revision. Keep this compatibility path anchored to the stable
|
||||
// skill header and final delivery sentence so the user's request is not
|
||||
// mistaken for executor-only instructions.
|
||||
if (/^请使用\s+page-data-collect\s+技能[::]/u.test(next)) {
|
||||
const legacyEndMarker = '并说明后台入口与口令。';
|
||||
const markerIndex = next.indexOf(legacyEndMarker);
|
||||
if (markerIndex >= 0) {
|
||||
next = next.slice(markerIndex + legacyEndMarker.length);
|
||||
}
|
||||
}
|
||||
return next.trim();
|
||||
}
|
||||
|
||||
|
||||
@@ -25,6 +25,26 @@ test('deriveUserFacingText removes routing hint and skill preface from agent pay
|
||||
assert.equal(deriveUserFacingText(agentPayload), userText);
|
||||
});
|
||||
|
||||
test('deriveUserFacingText removes page-data prompt persisted as display text', () => {
|
||||
const userText = '帮我做一个日记页面,可以每天写日记,其他人可以评价';
|
||||
const persistedDisplayText = `${buildAutoChatSkillPrefix(userText, ['page-data-collect'])}${userText}`;
|
||||
assert.match(persistedDisplayText, /page-data-collect/);
|
||||
assert.equal(deriveUserFacingText(persistedDisplayText), userText);
|
||||
});
|
||||
|
||||
test('deriveUserFacingText removes a legacy page-data prompt after the template changes', () => {
|
||||
const userText = '帮我做一个日记页面,可以每天写日记,其他人可以评价';
|
||||
const persistedDisplayText = [
|
||||
'请使用 page-data-collect 技能:在 MindSpace 页面中实现可提交、可持久化的数据收集。',
|
||||
'流程:loadskill → privatedataexecute 建表 → privatedataregisterdataset → writefile/editfile。',
|
||||
'完成后只返回 workspaceUrl,并说明后台入口与口令。',
|
||||
userText,
|
||||
].join('');
|
||||
|
||||
assert.equal(stripKnownChatSkillPrompt(persistedDisplayText), userText);
|
||||
assert.equal(deriveUserFacingText(persistedDisplayText), userText);
|
||||
});
|
||||
|
||||
test('deriveUserFacingText removes Memind task orchestration prefix', () => {
|
||||
const userText = '帮我生成深度搜索报告';
|
||||
const agentPayload = [
|
||||
|
||||
@@ -26,3 +26,13 @@ npm run verify:mindspace-page-sync-guards
|
||||
```
|
||||
|
||||
涉及 H5 交付时,还必须验证:未注册 dataset 时不产生可用 Page Data policy,且最终链接交付被拒绝或进入明确 repair 状态。
|
||||
|
||||
## PostgreSQL 用户空间角色守卫
|
||||
|
||||
生产用户空间 PostgreSQL(独立于 Goose session PostgreSQL)通过 `SET LOCAL ROLE ms_u_*_agent` 隔离每个用户。必须保留以下约束:
|
||||
|
||||
1. provisioning 必须显式授予运行连接用户 agent role 的 `SET` 权限。
|
||||
2. agent role 保持 `INHERIT FALSE`;只允许显式 `SET ROLE` 后访问用户 schema,不能让连接用户默认继承全部用户权限。
|
||||
3. 已存在的用户空间在首次访问时必须幂等检查并修复缺失的 `SET` 权限,不能只修复新注册用户。
|
||||
4. 验收必须使用与生产等价的非超级用户连接完成 `SET LOCAL ROLE`、建表、dataset 注册和读写;超级用户会绕过角色切换限制,不能作为该问题的验收依据。
|
||||
5. 修复角色授权时禁止修改用户 schema、表和数据;生产操作前保留用户空间 PG dump、角色授权快照和回滚 SQL。
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
|
||||
1. 构建只发生在本机 Mac:`node scripts/build-portal-runtime.mjs`。
|
||||
2. 103 只接收 `.runtime/portal/` 打出来的 artifact,不直接覆盖源码树。
|
||||
- 所有由 goosed 以 stdio 启动的 Portal MCP 入口都必须打进 artifact,并同时加入发布脚本的必需文件和容器可见性检查;当前包括 `mindspace-sandbox-mcp.mjs` 与 `tkmind-search-mcp.mjs`。
|
||||
3. 103 在切换前必须做 `Memind` 全量备份,并单独备份持久目录。
|
||||
4. 103 **禁止** `npm install`、`npm run build`、在线改源码后继续运行。
|
||||
5. 切换后必须通过 Portal 健康检查;失败立即回滚。
|
||||
|
||||
@@ -140,6 +140,7 @@ function publicationResponse(row) {
|
||||
viewCount: Number(row.view_count ?? 0),
|
||||
publishedAt: Number(row.published_at),
|
||||
offlineAt: row.offline_at == null ? null : Number(row.offline_at),
|
||||
userConfirmedAt: row.user_confirmed_at == null ? null : Number(row.user_confirmed_at),
|
||||
};
|
||||
}
|
||||
|
||||
@@ -982,6 +983,7 @@ export function createPublicationService(pool, options = {}) {
|
||||
const [pubRows] = await pool.query(
|
||||
`SELECT pr.id, pr.url_slug, pr.public_url, pr.page_version_id, pr.access_mode,
|
||||
pr.status, pr.view_count, pr.published_at, pr.offline_at, pr.expires_at,
|
||||
pr.user_confirmed_at,
|
||||
pv.bundle_asset_id, av.id AS asset_version_id, av.storage_key
|
||||
FROM h5_publish_records pr
|
||||
JOIN h5_page_records p ON p.id = pr.page_id AND p.user_id = pr.user_id
|
||||
@@ -1371,7 +1373,7 @@ export function createPublicationService(pool, options = {}) {
|
||||
const cleanupExpiredUnconfirmedPublications = async (now = Date.now()) => {
|
||||
const [result] = await pool.query(
|
||||
`UPDATE h5_publish_records
|
||||
SET access_mode = 'private', expires_at = NULL, updated_at = ?
|
||||
SET access_mode = 'owner_only', expires_at = NULL, updated_at = ?
|
||||
WHERE access_mode = 'public'
|
||||
AND expires_at IS NOT NULL
|
||||
AND expires_at <= ?
|
||||
|
||||
@@ -34,6 +34,72 @@ test('accepts all documented access modes', () => {
|
||||
);
|
||||
});
|
||||
|
||||
test('getCurrent exposes whether the owner confirmed publication visibility', async () => {
|
||||
const service = createPublicationService({
|
||||
async query(sql, params) {
|
||||
assert.match(sql, /SELECT pr\.\*/);
|
||||
assert.deepEqual(params, ['page-1', 'user-1']);
|
||||
return [[{
|
||||
id: 'pub-1',
|
||||
page_id: 'page-1',
|
||||
page_version_id: 'version-1',
|
||||
url_slug: 'journal',
|
||||
public_url: '/u/john/pages/journal',
|
||||
access_mode: 'public',
|
||||
expires_at: null,
|
||||
status: 'online',
|
||||
view_count: 2,
|
||||
published_at: 1000,
|
||||
offline_at: null,
|
||||
user_confirmed_at: 2000,
|
||||
}]];
|
||||
},
|
||||
});
|
||||
|
||||
const publication = await service.getCurrent('user-1', 'page-1');
|
||||
assert.equal(publication.userConfirmedAt, 2000);
|
||||
});
|
||||
|
||||
test('getCurrent returns null confirmation for an unconfirmed publication', async () => {
|
||||
const service = createPublicationService({
|
||||
async query() {
|
||||
return [[{
|
||||
id: 'pub-1',
|
||||
page_id: 'page-1',
|
||||
page_version_id: 'version-1',
|
||||
url_slug: 'journal',
|
||||
public_url: '/u/john/pages/journal',
|
||||
access_mode: 'public',
|
||||
expires_at: null,
|
||||
status: 'online',
|
||||
view_count: 0,
|
||||
published_at: 1000,
|
||||
offline_at: null,
|
||||
user_confirmed_at: null,
|
||||
}]];
|
||||
},
|
||||
});
|
||||
|
||||
const publication = await service.getCurrent('user-1', 'page-1');
|
||||
assert.equal(publication.userConfirmedAt, null);
|
||||
});
|
||||
|
||||
test('cleanupExpiredUnconfirmedPublications falls back to owner-only access', async () => {
|
||||
let executedSql = '';
|
||||
const service = createPublicationService({
|
||||
async query(sql, params) {
|
||||
executedSql = sql;
|
||||
assert.deepEqual(params, [3000, 3000]);
|
||||
return [{ affectedRows: 1 }];
|
||||
},
|
||||
});
|
||||
|
||||
const result = await service.cleanupExpiredUnconfirmedPublications(3000);
|
||||
assert.deepEqual(result, { cleaned: 1 });
|
||||
assert.match(executedSql, /SET access_mode = 'owner_only'/);
|
||||
assert.doesNotMatch(executedSql, /SET access_mode = 'private'/);
|
||||
});
|
||||
|
||||
test('hashes access passwords with a random salt', () => {
|
||||
const first = publicationInternals.hashPassword('Publish-Password-2026');
|
||||
const second = publicationInternals.hashPassword('Publish-Password-2026');
|
||||
|
||||
@@ -18,6 +18,25 @@ export function quotePgIdentifier(value) {
|
||||
return `"${String(value).replaceAll('"', '""')}"`;
|
||||
}
|
||||
|
||||
function quotePgLiteral(value) {
|
||||
return `'${String(value).replaceAll("'", "''")}'`;
|
||||
}
|
||||
|
||||
export function buildEnsureCurrentUserCanSetRoleSql(roleName) {
|
||||
const role = String(roleName);
|
||||
const roleLiteral = quotePgLiteral(role);
|
||||
return `DO $$ BEGIN
|
||||
IF NOT EXISTS (
|
||||
SELECT 1 FROM pg_auth_members am
|
||||
JOIN pg_roles r ON r.oid = am.roleid
|
||||
JOIN pg_roles m ON m.oid = am.member
|
||||
WHERE r.rolname = ${roleLiteral} AND m.rolname = CURRENT_USER AND am.set_option
|
||||
) THEN
|
||||
EXECUTE format('GRANT %I TO %I WITH INHERIT FALSE, SET TRUE', ${roleLiteral}, CURRENT_USER);
|
||||
END IF;
|
||||
END $$`;
|
||||
}
|
||||
|
||||
export function deriveUserSpaceNames(value) {
|
||||
const userId = assertUserId(value);
|
||||
const compact = userId.replaceAll('-', '');
|
||||
@@ -118,6 +137,7 @@ export function buildProvisionUserSql(userId, { sourceSqlitePath = null, quotaBy
|
||||
EXECUTE format('GRANT %I TO %I', '${names.ownerRole}', CURRENT_USER);
|
||||
END IF;
|
||||
END $$`,
|
||||
buildEnsureCurrentUserCanSetRoleSql(names.agentRole),
|
||||
`CREATE SCHEMA IF NOT EXISTS ${schema} AUTHORIZATION ${owner}`,
|
||||
`REVOKE ALL ON SCHEMA ${schema} FROM PUBLIC`,
|
||||
`GRANT USAGE, CREATE ON SCHEMA ${schema} TO ${agent}`,
|
||||
|
||||
@@ -5,6 +5,7 @@ import path from 'node:path';
|
||||
import test from 'node:test';
|
||||
import {
|
||||
buildControlSchemaSql,
|
||||
buildEnsureCurrentUserCanSetRoleSql,
|
||||
buildPostgresTableSql,
|
||||
buildPostgresCheckSql,
|
||||
buildPostgresForeignKeySql,
|
||||
@@ -44,12 +45,21 @@ test('provision SQL creates isolated no-login roles and safety limits', () => {
|
||||
assert.match(sql, /CREATE ROLE "ms_u_ecc1c649fff7_owner" NOLOGIN/);
|
||||
assert.match(sql, /CREATE ROLE "ms_u_ecc1c649fff7_agent" NOLOGIN NOSUPERUSER NOCREATEDB NOCREATEROLE/);
|
||||
assert.match(sql, /pg_auth_members/);
|
||||
assert.match(sql, /r\.rolname = 'ms_u_ecc1c649fff7_agent'.*am\.set_option/s);
|
||||
assert.match(sql, /GRANT %I TO %I WITH INHERIT FALSE, SET TRUE/);
|
||||
assert.match(sql, /REVOKE ALL ON SCHEMA "u_ecc1c649fff74361a243a69b460cc407" FROM PUBLIC/);
|
||||
assert.match(sql, /statement_timeout = '30s'/);
|
||||
assert.match(sql, /NOSUPERUSER NOCREATEDB NOCREATEROLE NOREPLICATION/);
|
||||
assert.doesNotMatch(sql, /temp_file_limit/);
|
||||
});
|
||||
|
||||
test('agent role reconciliation requires SET without inherited privileges', () => {
|
||||
const sql = buildEnsureCurrentUserCanSetRoleSql('ms_u_ecc1c649fff7_agent');
|
||||
assert.match(sql, /m\.rolname = CURRENT_USER AND am\.set_option/);
|
||||
assert.match(sql, /WITH INHERIT FALSE, SET TRUE/);
|
||||
assert.doesNotMatch(sql, /WITH INHERIT TRUE/);
|
||||
});
|
||||
|
||||
test('SQLite types and defaults map to conservative PostgreSQL equivalents', () => {
|
||||
assert.equal(mapSqliteTypeToPostgres({ type: 'INTEGER', pk: 1 }), 'bigint GENERATED BY DEFAULT AS IDENTITY');
|
||||
assert.equal(mapSqliteTypeToPostgres({ type: 'REAL', pk: 0 }), 'double precision');
|
||||
|
||||
Generated
+8
-8
@@ -13,7 +13,7 @@
|
||||
"debug": "^4.4.3",
|
||||
"express": "^4.21.2",
|
||||
"framer-motion": "^12.42.0",
|
||||
"http-proxy-middleware": "^3.0.3",
|
||||
"http-proxy-middleware": "^3.0.7",
|
||||
"jsonrepair": "^3.14.0",
|
||||
"lucide-react": "^1.21.0",
|
||||
"mysql2": "^3.22.5",
|
||||
@@ -25,7 +25,7 @@
|
||||
"react-router-dom": "^7.13.1",
|
||||
"redis": "^4.7.1",
|
||||
"sharp": "^0.35.2",
|
||||
"undici": "^6.26.0"
|
||||
"undici": "^6.27.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/react": "^19.0.10",
|
||||
@@ -3343,9 +3343,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/http-proxy-middleware": {
|
||||
"version": "3.0.6",
|
||||
"resolved": "https://registry.npmjs.org/http-proxy-middleware/-/http-proxy-middleware-3.0.6.tgz",
|
||||
"integrity": "sha512-jhO3QfahaHWfQjEnyGW0vpYIYaXcnA6FEfehrBthOokGppvmI6zcV+1yb6TWn3vyeh8yQUoEqH51DNHOCjivxg==",
|
||||
"version": "3.0.7",
|
||||
"resolved": "https://registry.npmjs.org/http-proxy-middleware/-/http-proxy-middleware-3.0.7.tgz",
|
||||
"integrity": "sha512-iwbQltVlx8bCrqePUM8C+hllHvdawVhQJaLrj1X7qllkvFQdXFsr16pW/mo9+JDVjN+QO2XUx9jd8SmoFkE5qw==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@types/http-proxy": "^1.17.15",
|
||||
@@ -4691,9 +4691,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/undici": {
|
||||
"version": "6.26.0",
|
||||
"resolved": "https://registry.npmjs.org/undici/-/undici-6.26.0.tgz",
|
||||
"integrity": "sha512-4yqz8a3n5HmGTlsbADNtr/dJlhkh/55Rq798G6ibiULcXbDtaLpTl1pvdqcbFfeoj3iSi52lePFM7h9H21cw/A==",
|
||||
"version": "6.27.0",
|
||||
"resolved": "https://registry.npmjs.org/undici/-/undici-6.27.0.tgz",
|
||||
"integrity": "sha512-YmfV3YnEDzXRC5lZ2jWtWWHKGUm1zIt8AhesR1tens+HTNv+YZlN/dp6G727LOvMJ8xjP9Be7Y2Sdr96LDm+pg==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=18.17"
|
||||
|
||||
+4
-4
@@ -58,7 +58,7 @@
|
||||
"test:scenario": "node scripts/run-scenario-test.mjs",
|
||||
"verify:children-hobby-diet-survey": "node scripts/verify-children-hobby-diet-survey.mjs",
|
||||
"test:scenario:john4-diet": "node scripts/run-scenario-test.mjs --scenario john4-children-hobby-diet-update",
|
||||
"test": "node --test auth.test.mjs asr-proxy.test.mjs billing.test.mjs billing-token-state.test.mjs billing-recharge.test.mjs wechat-pay.test.mjs wechat-oauth.test.mjs wechat-mp.test.mjs schedule-intent.test.mjs schedule-reminder-worker.test.mjs capabilities.test.mjs policies.test.mjs chat-skills.test.mjs chat-intent-router.test.mjs chat-finish-sync.test.mjs chat-agent-run-gate.test.mjs conversation-display.test.mjs user-publish.test.mjs user-memory-profile.test.mjs skills-registry.test.mjs agent-run-gateway.test.mjs agent-run-routes.test.mjs session-broker.test.mjs sse-event-taxonomy.test.mjs goosed-proxy-boundary.test.mjs agent-run-stream.test.mjs mindspace-h5-html-finish-guard.test.mjs admin-routes.test.mjs direct-chat-service.test.mjs tool-gateway.test.mjs mindspace.test.mjs mindspace-scan.test.mjs mindspace-assets.test.mjs mindspace-local-runtime-services.test.mjs mindspace-local-server-adapter.test.mjs mindspace-public-asset-token.test.mjs mindspace-remote-server-adapter.test.mjs mindspace-server-adapter.test.mjs mindspace-pages.test.mjs mindspace-page-sync-service.test.mjs public-site-bases.test.mjs mindspace-html-download-links.test.mjs mindspace-page-purge.test.mjs mindspace-public-delivery.test.mjs mindspace-public-page-context.test.mjs mindspace-published-page-csp.test.mjs mindspace-published-script-localize.test.mjs agent-run-deliverable-check.test.mjs mindspace-public-route.test.mjs mindspace-publications.test.mjs mindspace-public-links.test.mjs mindspace-chat-save.test.mjs mindspace-chat-docx-package.test.mjs mindspace-public-finish-sync.test.mjs mindspace-chat-context.test.mjs mindspace-canonical-url.test.mjs mindspace-conversation-package.test.mjs mindspace-conversation-package-backfill.test.mjs mindspace-conversation-package-public-html.test.mjs mindspace-conversation-package-verify.test.mjs mindspace-conversation-package-registry.test.mjs mindspace-conversation-package-routes.test.mjs mindspace-conversation-package-store.test.mjs mindspace-conversation-schema.test.mjs mindspace-runtime-config.test.mjs mindspace-config.test.mjs mindspace-analytics.test.mjs mindspace-service.test.mjs mindspace-storage-adapter.test.mjs mindspace-content-scan.test.mjs mindspace-html-localize.test.mjs mindspace-visual-editor.test.mjs mindspace-cleanup.test.mjs mindspace-thumbnails.test.mjs mindspace-workspace-thumbnails.test.mjs mindspace-workspace-sync.test.mjs mindspace-asset-preview.test.mjs mindspace-agent-jobs.test.mjs mindspace-agent-runner.test.mjs mindspace-sandbox-mcp.test.mjs user-data-space-service.test.mjs page-data-routes.test.mjs page-access-policy.test.mjs page-access-visitor.test.mjs page-data-public-service.test.mjs page-data-integration.test.mjs page-data-log-store.test.mjs page-data-ops.test.mjs page-data-session-store.test.mjs page-data-browser-client.test.mjs page-data-policy-index.test.mjs message-stream.test.mjs mindspace-service/mindspace-rpc-server.test.mjs plaza-posts.test.mjs plaza-interactions.test.mjs plaza-algorithm.test.mjs plaza-seo.test.mjs plaza-ops.test.mjs user-auth.test.mjs llm-providers.test.mjs admin-guard.test.mjs user-feedback.test.mjs memory-v2.test.mjs memory-v2-admin-config.test.mjs memory-v2-lifecycle.test.mjs memory-v2-adapter-scaffold.test.mjs memory-v2-backend-contract.test.mjs memory-v2-health.test.mjs memory-v2-runtime.test.mjs memory-v2-plugin-backends.test.mjs memory-v2-pgvector.test.mjs memory-v2-pgvector-schema.test.mjs memory-v2-pgvector-backfill.test.mjs memory-v2-pgvector-smoke.test.mjs memory-v2-qdrant.test.mjs memory-v2-weaviate.test.mjs memory-v2-mem0.test.mjs memory-v2-letta.test.mjs memory-v2-external-adapters.test.mjs scripts/embed-memory-v2-local-hash.test.mjs scripts/check-memory-v2-app-canary.test.mjs scripts/check-memory-v2-config-gaps.test.mjs scripts/check-memory-v2-contracts.test.mjs scripts/check-memory-v2-health.test.mjs scripts/check-memory-v2-session-flow.test.mjs scripts/check-memory-v2-stack.test.mjs scripts/setup-memory-v2-pgvector-schema.test.mjs scripts/backfill-memory-v2-pgvector.test.mjs scripts/scaffold-memory-v2-backend.test.mjs scripts/smoke-memory-v2-pgvector.test.mjs scripts/smoke-memory-v2-qdrant.test.mjs scripts/smoke-memory-v2-external.test.mjs scripts/mock-memory-v2-services.test.mjs",
|
||||
"test": "node --test auth.test.mjs asr-proxy.test.mjs billing.test.mjs billing-token-state.test.mjs billing-recharge.test.mjs wechat-pay.test.mjs wechat-oauth.test.mjs wechat-mp.test.mjs schedule-intent.test.mjs schedule-reminder-worker.test.mjs capabilities.test.mjs policies.test.mjs chat-skills.test.mjs chat-intent-router.test.mjs chat-finish-sync.test.mjs chat-agent-run-gate.test.mjs conversation-display.test.mjs user-publish.test.mjs user-memory-profile.test.mjs skills-registry.test.mjs agent-run-gateway.test.mjs agent-run-routes.test.mjs session-broker.test.mjs sse-event-taxonomy.test.mjs goosed-proxy-boundary.test.mjs agent-run-stream.test.mjs mindspace-h5-html-finish-guard.test.mjs admin-routes.test.mjs direct-chat-service.test.mjs tool-gateway.test.mjs mindspace.test.mjs mindspace-scan.test.mjs mindspace-assets.test.mjs mindspace-local-runtime-services.test.mjs mindspace-local-server-adapter.test.mjs mindspace-public-asset-token.test.mjs mindspace-remote-server-adapter.test.mjs mindspace-server-adapter.test.mjs mindspace-pages.test.mjs mindspace-page-sync-service.test.mjs public-site-bases.test.mjs mindspace-html-download-links.test.mjs mindspace-page-purge.test.mjs mindspace-public-delivery.test.mjs mindspace-public-page-context.test.mjs mindspace-published-page-csp.test.mjs mindspace-published-script-localize.test.mjs agent-run-deliverable-check.test.mjs mindspace-public-route.test.mjs mindspace-publications.test.mjs mindspace-public-links.test.mjs mindspace-chat-save.test.mjs mindspace-chat-docx-package.test.mjs mindspace-public-finish-sync.test.mjs mindspace-chat-context.test.mjs mindspace-canonical-url.test.mjs mindspace-conversation-package.test.mjs mindspace-conversation-package-backfill.test.mjs mindspace-conversation-package-public-html.test.mjs mindspace-conversation-package-verify.test.mjs mindspace-conversation-package-registry.test.mjs mindspace-conversation-package-routes.test.mjs mindspace-conversation-package-store.test.mjs mindspace-conversation-schema.test.mjs mindspace-runtime-config.test.mjs mindspace-config.test.mjs mindspace-analytics.test.mjs mindspace-service.test.mjs mindspace-storage-adapter.test.mjs mindspace-content-scan.test.mjs mindspace-html-localize.test.mjs mindspace-visual-editor.test.mjs mindspace-cleanup.test.mjs mindspace-thumbnails.test.mjs mindspace-workspace-thumbnails.test.mjs mindspace-workspace-sync.test.mjs mindspace-asset-preview.test.mjs mindspace-agent-jobs.test.mjs mindspace-agent-runner.test.mjs mindspace-sandbox-mcp.test.mjs mindspace-userdata-postgres.test.mjs postgres-user-data-space-service.test.mjs user-data-space-service.test.mjs page-data-routes.test.mjs page-access-policy.test.mjs page-access-visitor.test.mjs page-data-public-service.test.mjs page-data-integration.test.mjs page-data-log-store.test.mjs page-data-ops.test.mjs page-data-session-store.test.mjs page-data-browser-client.test.mjs page-data-policy-index.test.mjs message-stream.test.mjs mindspace-service/mindspace-rpc-server.test.mjs plaza-posts.test.mjs plaza-interactions.test.mjs plaza-algorithm.test.mjs plaza-seo.test.mjs plaza-ops.test.mjs user-auth.test.mjs llm-providers.test.mjs admin-guard.test.mjs user-feedback.test.mjs memory-v2.test.mjs memory-v2-admin-config.test.mjs memory-v2-lifecycle.test.mjs memory-v2-adapter-scaffold.test.mjs memory-v2-backend-contract.test.mjs memory-v2-health.test.mjs memory-v2-runtime.test.mjs memory-v2-plugin-backends.test.mjs memory-v2-pgvector.test.mjs memory-v2-pgvector-schema.test.mjs memory-v2-pgvector-backfill.test.mjs memory-v2-pgvector-smoke.test.mjs memory-v2-qdrant.test.mjs memory-v2-weaviate.test.mjs memory-v2-mem0.test.mjs memory-v2-letta.test.mjs memory-v2-external-adapters.test.mjs scripts/embed-memory-v2-local-hash.test.mjs scripts/check-memory-v2-app-canary.test.mjs scripts/check-memory-v2-config-gaps.test.mjs scripts/check-memory-v2-contracts.test.mjs scripts/check-memory-v2-health.test.mjs scripts/check-memory-v2-session-flow.test.mjs scripts/check-memory-v2-stack.test.mjs scripts/setup-memory-v2-pgvector-schema.test.mjs scripts/backfill-memory-v2-pgvector.test.mjs scripts/scaffold-memory-v2-backend.test.mjs scripts/smoke-memory-v2-pgvector.test.mjs scripts/smoke-memory-v2-qdrant.test.mjs scripts/smoke-memory-v2-external.test.mjs scripts/mock-memory-v2-services.test.mjs",
|
||||
"test:mindspace-service": "node --test mindspace-service/mindspace-rpc-server.test.mjs",
|
||||
"verify:chat-finish-sync": "node scripts/verify-chat-finish-sync.mjs",
|
||||
"verify:public-finish-sync-runtime": "node scripts/verify-public-finish-sync-runtime.mjs",
|
||||
@@ -66,7 +66,7 @@
|
||||
"verify:mindspace-publish-guards:full": "node scripts/verify-mindspace-publish-guards.mjs --with-runtime",
|
||||
"verify:mindspace-page-sync-guards": "node scripts/verify-mindspace-page-sync-guards.mjs",
|
||||
"verify:public-page-interaction": "node scripts/verify-public-page-interaction.mjs",
|
||||
"verify:page-data": "node --test page-data-acceptance.test.mjs page-data-integration.test.mjs page-data-public-service.test.mjs page-data-ops.test.mjs page-data-delivery-assess.test.mjs mindspace-page-data-finish-guard.test.mjs mindspace-page-data-finish-guard.integration.test.mjs",
|
||||
"verify:page-data": "node --test mindspace-userdata-postgres.test.mjs postgres-user-data-space-service.test.mjs page-data-acceptance.test.mjs page-data-integration.test.mjs page-data-public-service.test.mjs page-data-ops.test.mjs page-data-delivery-assess.test.mjs mindspace-page-data-finish-guard.test.mjs mindspace-page-data-finish-guard.integration.test.mjs",
|
||||
"verify:page-data-delivery": "node scripts/repair-page-data-workspace-bindings.mjs --dry-run",
|
||||
"repair:page-data-bindings": "node scripts/repair-page-data-workspace-bindings.mjs",
|
||||
"repair:page-data:103": "node scripts/ensure-page-data-datasets.mjs && node scripts/repair-page-data-workspace-bindings.mjs",
|
||||
@@ -93,7 +93,7 @@
|
||||
"debug": "^4.4.3",
|
||||
"express": "^4.21.2",
|
||||
"framer-motion": "^12.42.0",
|
||||
"http-proxy-middleware": "^3.0.3",
|
||||
"http-proxy-middleware": "^3.0.7",
|
||||
"jsonrepair": "^3.14.0",
|
||||
"lucide-react": "^1.21.0",
|
||||
"mysql2": "^3.22.5",
|
||||
@@ -105,7 +105,7 @@
|
||||
"react-router-dom": "^7.13.1",
|
||||
"redis": "^4.7.1",
|
||||
"sharp": "^0.35.2",
|
||||
"undici": "^6.26.0"
|
||||
"undici": "^6.27.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/react": "^19.0.10",
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
import test from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import fs from 'node:fs';
|
||||
|
||||
const skillText = fs.readFileSync(new URL('./skills/page-data-collect/SKILL.md', import.meta.url), 'utf8');
|
||||
|
||||
test('page-data-collect skill uses PostgreSQL DDL and fails closed on private data errors', () => {
|
||||
assert.match(skillText, /GENERATED BY DEFAULT AS IDENTITY PRIMARY KEY/);
|
||||
assert.match(skillText, /TIMESTAMPTZ NOT NULL DEFAULT CURRENT_TIMESTAMP/);
|
||||
assert.doesNotMatch(skillText, /INTEGER PRIMARY KEY AUTOINCREMENT/);
|
||||
assert.match(skillText, /数据层失败必须立即停止/);
|
||||
assert.match(skillText, /禁止继续写 HTML、bind 或发布/);
|
||||
assert.match(skillText, /平台没有延迟补执行队列/);
|
||||
});
|
||||
|
||||
test('page-data-collect skill pins deletion to the public client API', () => {
|
||||
assert.match(skillText, /client\.deleteRow\('dataset_name', rowId\)/);
|
||||
assert.match(skillText, /禁止发明 `softDeleteRows`/);
|
||||
assert.match(skillText, /表必须包含 `deleted_at TIMESTAMPTZ`/);
|
||||
});
|
||||
Generated
+10
-10
@@ -24,8 +24,8 @@ importers:
|
||||
specifier: ^12.42.0
|
||||
version: 12.42.0(react-dom@19.2.7(react@19.2.7))(react@19.2.7)
|
||||
http-proxy-middleware:
|
||||
specifier: ^3.0.3
|
||||
version: 3.0.6
|
||||
specifier: ^3.0.7
|
||||
version: 3.0.7
|
||||
jsonrepair:
|
||||
specifier: ^3.14.0
|
||||
version: 3.14.0
|
||||
@@ -60,8 +60,8 @@ importers:
|
||||
specifier: ^0.35.2
|
||||
version: 0.35.2
|
||||
undici:
|
||||
specifier: ^6.26.0
|
||||
version: 6.26.0
|
||||
specifier: ^6.27.0
|
||||
version: 6.27.0
|
||||
devDependencies:
|
||||
'@types/react':
|
||||
specifier: ^19.0.10
|
||||
@@ -1201,8 +1201,8 @@ packages:
|
||||
resolution: {integrity: sha512-4FbRdAX+bSdmo4AUFuS0WNiPz8NgFt+r8ThgNWmlrjQjt1Q7ZR9+zTlce2859x4KSXrwIsaeTqDoKQmtP8pLmQ==}
|
||||
engines: {node: '>= 0.8'}
|
||||
|
||||
http-proxy-middleware@3.0.6:
|
||||
resolution: {integrity: sha512-jhO3QfahaHWfQjEnyGW0vpYIYaXcnA6FEfehrBthOokGppvmI6zcV+1yb6TWn3vyeh8yQUoEqH51DNHOCjivxg==}
|
||||
http-proxy-middleware@3.0.7:
|
||||
resolution: {integrity: sha512-iwbQltVlx8bCrqePUM8C+hllHvdawVhQJaLrj1X7qllkvFQdXFsr16pW/mo9+JDVjN+QO2XUx9jd8SmoFkE5qw==}
|
||||
engines: {node: ^14.18.0 || ^16.10.0 || >=18.0.0}
|
||||
|
||||
http-proxy@1.18.1:
|
||||
@@ -1635,8 +1635,8 @@ packages:
|
||||
undici-types@7.24.6:
|
||||
resolution: {integrity: sha512-WRNW+sJgj5OBN4/0JpHFqtqzhpbnV0GuB+OozA9gCL7a993SmU+1JBZCzLNxYsbMfIeDL+lTsphD5jN5N+n0zg==}
|
||||
|
||||
undici@6.26.0:
|
||||
resolution: {integrity: sha512-4yqz8a3n5HmGTlsbADNtr/dJlhkh/55Rq798G6ibiULcXbDtaLpTl1pvdqcbFfeoj3iSi52lePFM7h9H21cw/A==}
|
||||
undici@6.27.0:
|
||||
resolution: {integrity: sha512-YmfV3YnEDzXRC5lZ2jWtWWHKGUm1zIt8AhesR1tens+HTNv+YZlN/dp6G727LOvMJ8xjP9Be7Y2Sdr96LDm+pg==}
|
||||
engines: {node: '>=18.17'}
|
||||
|
||||
unpipe@1.0.0:
|
||||
@@ -2678,7 +2678,7 @@ snapshots:
|
||||
statuses: 2.0.2
|
||||
toidentifier: 1.0.1
|
||||
|
||||
http-proxy-middleware@3.0.6:
|
||||
http-proxy-middleware@3.0.7:
|
||||
dependencies:
|
||||
'@types/http-proxy': 1.17.17
|
||||
debug: 4.4.3
|
||||
@@ -3125,7 +3125,7 @@ snapshots:
|
||||
|
||||
undici-types@7.24.6: {}
|
||||
|
||||
undici@6.26.0: {}
|
||||
undici@6.27.0: {}
|
||||
|
||||
unpipe@1.0.0: {}
|
||||
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
import pg from 'pg';
|
||||
import {
|
||||
buildControlSchemaSql,
|
||||
buildEnsureCurrentUserCanSetRoleSql,
|
||||
deriveUserSpaceNames,
|
||||
provisionUserSpace,
|
||||
quotePgIdentifier,
|
||||
@@ -107,6 +108,10 @@ export function createPostgresUserDataSpaceService(options = {}) {
|
||||
await client.query('ROLLBACK');
|
||||
throw error;
|
||||
}
|
||||
} else {
|
||||
// PostgreSQL 17 grants CREATEROLE owners ADMIN but not SET by default.
|
||||
// Reconcile existing spaces before the runtime executes SET LOCAL ROLE.
|
||||
await client.query(buildEnsureCurrentUserCanSetRoleSql(names.agentRole));
|
||||
}
|
||||
provisionedUsers.add(names.userId);
|
||||
} finally {
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import test from 'node:test';
|
||||
import { createPostgresUserDataSpaceService } from './postgres-user-data-space-service.mjs';
|
||||
|
||||
const USER_ID = '18a143d1-3ac5-42b3-a4af-d07f8445bce6';
|
||||
|
||||
test('existing PostgreSQL user spaces reconcile agent SET permission before tenant access', async () => {
|
||||
const queries = [];
|
||||
const client = {
|
||||
async query(sql) {
|
||||
queries.push(String(sql));
|
||||
if (String(sql).includes('SELECT migration_state FROM mindspace_control.user_spaces')) {
|
||||
return { rows: [{ migration_state: 'cutover' }] };
|
||||
}
|
||||
if (String(sql).includes('FROM information_schema.columns')) return { rows: [] };
|
||||
return { rows: [] };
|
||||
},
|
||||
release() {},
|
||||
};
|
||||
const service = createPostgresUserDataSpaceService({
|
||||
userId: USER_ID,
|
||||
pgPool: { connect: async () => client },
|
||||
});
|
||||
|
||||
await service.getSchema();
|
||||
|
||||
const reconcileIndex = queries.findIndex((sql) => (
|
||||
sql.includes("r.rolname = 'ms_u_18a143d13ac5_agent'")
|
||||
&& sql.includes('WITH INHERIT FALSE, SET TRUE')
|
||||
));
|
||||
const setRoleIndex = queries.findIndex((sql) => sql.includes('SET LOCAL ROLE "ms_u_18a143d13ac5_agent"'));
|
||||
assert.ok(reconcileIndex >= 0, 'existing space must reconcile the agent role membership');
|
||||
assert.ok(setRoleIndex > reconcileIndex, 'role reconciliation must happen before SET LOCAL ROLE');
|
||||
});
|
||||
@@ -0,0 +1,25 @@
|
||||
import test from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import fs from 'node:fs';
|
||||
|
||||
const releaseScript = fs.readFileSync(
|
||||
new URL('./scripts/release-portal-runtime-prod.sh', import.meta.url),
|
||||
'utf8',
|
||||
);
|
||||
|
||||
test('103 release remounts goosed after swapping the live directory', () => {
|
||||
assert.match(releaseScript, /remount_goosed_after_live_swap\(\)/);
|
||||
assert.match(releaseScript, /docker-compose\.prod\.yml/);
|
||||
assert.match(releaseScript, /up -d --force-recreate/);
|
||||
assert.match(releaseScript, /MindSpace\/\.goosed-remount-/);
|
||||
assert.match(releaseScript, /containers\[@\].*!= 9/);
|
||||
assert.match(releaseScript, /seq 18006 18014/);
|
||||
assert.match(releaseScript, /\/opt\/portal\/mindspace-sandbox-mcp\.mjs/);
|
||||
|
||||
const swapIndex = releaseScript.indexOf('mv "${RUNTIME_DIR}" "${APP_DIR}"');
|
||||
const remountIndex = releaseScript.indexOf('remount_goosed_after_live_swap', swapIndex);
|
||||
const portalStartIndex = releaseScript.indexOf('say "启动新的 Portal runtime"');
|
||||
assert.ok(swapIndex >= 0, 'live directory swap must exist');
|
||||
assert.ok(remountIndex > swapIndex, 'goosed remount must happen after the live swap');
|
||||
assert.ok(portalStartIndex > remountIndex, 'Portal must start only after goosed remount succeeds');
|
||||
});
|
||||
@@ -0,0 +1,16 @@
|
||||
import test from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import fs from 'node:fs';
|
||||
|
||||
const releaseScript = fs.readFileSync(
|
||||
new URL('./scripts/release-portal-runtime-prod.sh', import.meta.url),
|
||||
'utf8',
|
||||
);
|
||||
|
||||
test('103 release preflight checks host and container access to the user-space PostgreSQL', () => {
|
||||
assert.match(releaseScript, /MINDSPACE_USERDATA_PG_URL/);
|
||||
assert.match(releaseScript, /user-space PostgreSQL URL cannot execute SELECT 1/);
|
||||
assert.match(releaseScript, /host\.docker\.internal/);
|
||||
assert.match(releaseScript, /port: 5433/);
|
||||
assert.match(releaseScript, /cannot reach user-space PostgreSQL/);
|
||||
});
|
||||
@@ -143,6 +143,26 @@ async function bundleSandboxMcp() {
|
||||
await run(esbuildBin, args);
|
||||
}
|
||||
|
||||
async function bundleMindSearchMcp() {
|
||||
if (!(await exists(esbuildBin))) {
|
||||
throw new Error(`未找到 esbuild: ${esbuildBin}`);
|
||||
}
|
||||
console.log('==> 打包 MindSearch MCP 为单文件 runtime');
|
||||
const args = [
|
||||
'tkmind-search-mcp.mjs',
|
||||
'--bundle',
|
||||
'--platform=node',
|
||||
'--format=esm',
|
||||
`--target=${runtimeNodeTarget}`,
|
||||
'--outfile=.runtime/portal/tkmind-search-mcp.mjs',
|
||||
'--banner:js=import { createRequire as __createRequire } from "node:module"; const require = __createRequire(import.meta.url);',
|
||||
];
|
||||
for (const pkg of externalPackages) {
|
||||
args.push(`--external:${pkg}`);
|
||||
}
|
||||
await run(esbuildBin, args);
|
||||
}
|
||||
|
||||
async function bundleAgentRunWorker() {
|
||||
if (!(await exists(esbuildBin))) {
|
||||
throw new Error(`未找到 esbuild: ${esbuildBin}`);
|
||||
@@ -414,6 +434,7 @@ async function writeMetadata() {
|
||||
'',
|
||||
'Bundled alongside server.mjs (required for sandbox-fs MCP):',
|
||||
' mindspace-sandbox-mcp.mjs (esbuild bundle; includes schedule-service deps)',
|
||||
' tkmind-search-mcp.mjs (esbuild bundle; required when MindSearch is enabled)',
|
||||
' wechat-mp.bundle.mjs (esbuild bundle; hot-swappable WeChat MP module)',
|
||||
'',
|
||||
'Post-deploy validation (scripts/check-mindspace-public-links.mjs):',
|
||||
@@ -486,6 +507,7 @@ async function main() {
|
||||
await bundleServer();
|
||||
await bundleWechatMp();
|
||||
await bundleSandboxMcp();
|
||||
await bundleMindSearchMcp();
|
||||
await bundleAgentRunWorker();
|
||||
if (runtimeInstallMode === 'bundle-node-modules' && !skipNodeModules) {
|
||||
await copyNodeModules();
|
||||
|
||||
@@ -152,7 +152,7 @@ fi
|
||||
|
||||
verify_runtime_artifact() {
|
||||
local missing=0
|
||||
for required in server.mjs wechat-mp.bundle.mjs mindspace-sandbox-mcp.mjs mindspace-public-links.mjs dist package.json scripts/run-memind-portal-prod.sh scripts/check-mindspace-public-links.mjs scripts/load-env.mjs scripts/wechat-mp-menu.mjs scripts/memind-portal-tunnel.sh; do
|
||||
for required in server.mjs wechat-mp.bundle.mjs mindspace-sandbox-mcp.mjs tkmind-search-mcp.mjs mindspace-public-links.mjs dist package.json scripts/run-memind-portal-prod.sh scripts/check-mindspace-public-links.mjs scripts/load-env.mjs scripts/wechat-mp-menu.mjs scripts/memind-portal-tunnel.sh; do
|
||||
if [[ ! -e "${RUNTIME_ROOT}/${required}" ]]; then
|
||||
echo "runtime 产物缺失: ${RUNTIME_ROOT}/${required}" >&2
|
||||
missing=1
|
||||
@@ -203,6 +203,7 @@ set -euo pipefail
|
||||
missing=0
|
||||
|
||||
pg_isready_bin="/opt/homebrew/opt/postgresql@17/bin/pg_isready"
|
||||
psql_bin="/opt/homebrew/opt/postgresql@17/bin/psql"
|
||||
if [[ -x "${pg_isready_bin}" ]]; then
|
||||
if ! "${pg_isready_bin}" -h 127.0.0.1 -p 5432 -q 2>/dev/null; then
|
||||
echo "goosed dependency check failed: host PostgreSQL (127.0.0.1:5432) is not accepting connections" >&2
|
||||
@@ -213,22 +214,39 @@ else
|
||||
echo "goosed dependency check warning: pg_isready not found; skipping PostgreSQL readiness check" >&2
|
||||
fi
|
||||
|
||||
portal_env="/Users/john/Project/Memind/.env"
|
||||
userdata_pg_url=""
|
||||
if [[ -f "${portal_env}" ]]; then
|
||||
userdata_pg_url="$(grep -E '^MINDSPACE_USERDATA_PG_URL=' "${portal_env}" | tail -1 | cut -d= -f2- || true)"
|
||||
fi
|
||||
if [[ -z "${userdata_pg_url}" ]]; then
|
||||
echo "goosed dependency check failed: Portal .env must set MINDSPACE_USERDATA_PG_URL" >&2
|
||||
missing=1
|
||||
elif [[ -x "${psql_bin}" ]] && ! "${psql_bin}" "${userdata_pg_url}" -Atc 'SELECT 1' >/dev/null 2>&1; then
|
||||
echo "goosed dependency check failed: user-space PostgreSQL URL cannot execute SELECT 1" >&2
|
||||
missing=1
|
||||
fi
|
||||
|
||||
docker_bin="/opt/homebrew/bin/docker"
|
||||
if [[ -x "${docker_bin}" ]] && "${docker_bin}" ps --format '{{.Names}}' 2>/dev/null | grep -q '^goosed-prod-1$'; then
|
||||
goosed_indexes=()
|
||||
while IFS= read -r name; do
|
||||
if [[ "${name}" =~ ^goosed-prod-([0-9]+)$ ]]; then
|
||||
goosed_containers=()
|
||||
goosed_indexes=()
|
||||
if [[ -x "${docker_bin}" ]]; then
|
||||
while IFS='|' read -r name service; do
|
||||
if [[ "${service}" =~ ^goosed-([0-9]+)$ ]]; then
|
||||
goosed_containers+=("${name}")
|
||||
goosed_indexes+=("${BASH_REMATCH[1]}")
|
||||
fi
|
||||
done < <("${docker_bin}" ps --format '{{.Names}}' | sort -V)
|
||||
if ((${#goosed_indexes[@]} == 0)); then
|
||||
echo "goosed dependency check failed: no goosed-prod-* containers running" >&2
|
||||
missing=1
|
||||
fi
|
||||
for index in "${goosed_indexes[@]}"; do
|
||||
container="goosed-prod-${index}"
|
||||
done < <("${docker_bin}" ps \
|
||||
--filter 'label=com.docker.compose.project=goosed-prod' \
|
||||
--format '{{.Names}}|{{.Label "com.docker.compose.service"}}')
|
||||
fi
|
||||
if ((${#goosed_containers[@]} > 0)); then
|
||||
for position in "${!goosed_containers[@]}"; do
|
||||
container="${goosed_containers[$position]}"
|
||||
index="${goosed_indexes[$position]}"
|
||||
host_port=$((18005 + index))
|
||||
if ! "${docker_bin}" ps --format '{{.Names}} {{.Ports}} {{.Status}}' | grep -q "^${container} .*0.0.0.0:${host_port}->18006/tcp.*healthy"; then
|
||||
health="$("${docker_bin}" inspect "${container}" --format '{{if .State.Health}}{{.State.Health.Status}}{{else}}{{.State.Status}}{{end}}' 2>/dev/null || true)"
|
||||
if [[ "${health}" != "healthy" ]] || ! "${docker_bin}" port "${container}" 18006/tcp 2>/dev/null | grep -q "0.0.0.0:${host_port}$"; then
|
||||
echo "goosed dependency check failed: ${container} is not healthy on host port ${host_port}" >&2
|
||||
missing=1
|
||||
fi
|
||||
@@ -236,6 +254,17 @@ if [[ -x "${docker_bin}" ]] && "${docker_bin}" ps --format '{{.Names}}' 2>/dev/n
|
||||
echo "goosed dependency check failed: ${container} missing /usr/local/bin/node or /opt/portal/mindspace-sandbox-mcp.mjs" >&2
|
||||
missing=1
|
||||
fi
|
||||
if ! "${docker_bin}" exec "${container}" /usr/local/bin/node -e '
|
||||
const net = require("net");
|
||||
const socket = net.connect({ host: "host.docker.internal", port: 5433 });
|
||||
const fail = () => process.exit(1);
|
||||
socket.setTimeout(3000, fail);
|
||||
socket.once("error", fail);
|
||||
socket.once("connect", () => { socket.end(); process.exit(0); });
|
||||
' >/dev/null 2>&1; then
|
||||
echo "goosed dependency check failed: ${container} cannot reach user-space PostgreSQL at host.docker.internal:5433" >&2
|
||||
missing=1
|
||||
fi
|
||||
done
|
||||
if [[ -f /Users/john/Project/Memind/.env ]]; then
|
||||
portal_mcp_node="$(grep -E '^GOOSED_MCP_NODE_PATH=' /Users/john/Project/Memind/.env | tail -1 | cut -d= -f2- || true)"
|
||||
@@ -244,8 +273,7 @@ if [[ -x "${docker_bin}" ]] && "${docker_bin}" ps --format '{{.Names}}' 2>/dev/n
|
||||
echo "goosed dependency check failed: Portal .env must set GOOSED_MCP_NODE_PATH and GOOSED_MCP_SERVER_PATH for Docker goosed" >&2
|
||||
missing=1
|
||||
else
|
||||
for index in "${goosed_indexes[@]}"; do
|
||||
container="goosed-prod-${index}"
|
||||
for container in "${goosed_containers[@]}"; do
|
||||
if ! "${docker_bin}" exec "${container}" sh -lc "test -x '${portal_mcp_node}' && test -f '${portal_mcp_server}'" >/dev/null 2>&1; then
|
||||
echo "goosed dependency check failed: ${container} cannot resolve Portal .env MCP paths '${portal_mcp_node}' and '${portal_mcp_server}'" >&2
|
||||
missing=1
|
||||
@@ -350,6 +378,84 @@ OLD_LIVE_DIR="${ARCHIVE_DIR}/Memind-source-before-${RELEASE_ID}"
|
||||
BUNDLE="${INCOMING_DIR}/memind-portal-runtime-${RELEASE_ID}.tar.gz"
|
||||
MANIFEST="${INCOMING_DIR}/memind-portal-runtime-${RELEASE_ID}.manifest.txt"
|
||||
SHA_FILE="${INCOMING_DIR}/memind-portal-runtime-${RELEASE_ID}.sha256"
|
||||
|
||||
remount_goosed_after_live_swap() {
|
||||
local docker_bin="/opt/homebrew/bin/docker"
|
||||
local compose_dir="/Users/john/Project/goosed-prod"
|
||||
local compose_file="${compose_dir}/docker-compose.prod.yml"
|
||||
local marker_rel="MindSpace/.goosed-remount-${RELEASE_ID}"
|
||||
local marker_host="${APP_DIR}/${marker_rel}"
|
||||
local marker_value="${RELEASE_ID}-$(date +%s)"
|
||||
local ready=0
|
||||
|
||||
if [[ ! -x "${docker_bin}" || ! -f "${compose_file}" ]]; then
|
||||
echo "goosed remount failed: docker or ${compose_file} is unavailable" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
mkdir -p "${APP_DIR}/MindSpace"
|
||||
printf '%s\n' "${marker_value}" > "${marker_host}"
|
||||
|
||||
say "重建 goosed 容器以刷新 Portal/MindSpace bind mount"
|
||||
if ! (
|
||||
cd "${compose_dir}"
|
||||
"${docker_bin}" compose -f "${compose_file}" up -d --force-recreate
|
||||
); then
|
||||
rm -f "${marker_host}"
|
||||
return 1
|
||||
fi
|
||||
|
||||
for _ in $(seq 1 60); do
|
||||
local healthy=1
|
||||
local containers=()
|
||||
while IFS= read -r container; do
|
||||
[[ -n "${container}" ]] && containers+=("${container}")
|
||||
done < <("${docker_bin}" ps \
|
||||
--filter 'label=com.docker.compose.project=goosed-prod' \
|
||||
--format '{{.Names}}')
|
||||
|
||||
if ((${#containers[@]} != 9)); then
|
||||
healthy=0
|
||||
fi
|
||||
|
||||
local container
|
||||
for container in "${containers[@]}"; do
|
||||
local state
|
||||
state="$("${docker_bin}" inspect "${container}" --format '{{if .State.Health}}{{.State.Health.Status}}{{else}}{{.State.Status}}{{end}}' 2>/dev/null || true)"
|
||||
if [[ "${state}" != "healthy" ]]; then
|
||||
healthy=0
|
||||
continue
|
||||
fi
|
||||
local observed
|
||||
observed="$("${docker_bin}" exec "${container}" sh -lc "cat '${APP_DIR}/${marker_rel}'" 2>/dev/null || true)"
|
||||
if [[ "${observed}" != "${marker_value}" ]]; then
|
||||
healthy=0
|
||||
fi
|
||||
if ! "${docker_bin}" exec "${container}" sh -lc 'test -f /opt/portal/mindspace-sandbox-mcp.mjs' >/dev/null 2>&1; then
|
||||
healthy=0
|
||||
fi
|
||||
done
|
||||
|
||||
local port
|
||||
for port in $(seq 18006 18014); do
|
||||
if [[ "$(curl -skS -m 5 "https://127.0.0.1:${port}/status" 2>/dev/null || true)" != "ok" ]]; then
|
||||
healthy=0
|
||||
fi
|
||||
done
|
||||
|
||||
if [[ "${healthy}" -eq 1 ]]; then
|
||||
ready=1
|
||||
break
|
||||
fi
|
||||
sleep 2
|
||||
done
|
||||
|
||||
rm -f "${marker_host}"
|
||||
if [[ "${ready}" -ne 1 ]]; then
|
||||
echo "goosed remount failed: containers did not become healthy on the new live directory" >&2
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
FULL_BACKUP_TAR="${BACKUP_DIR}/memind-full-${RELEASE_ID}-before.tar.gz"
|
||||
PERSIST_BACKUP_TAR="${BACKUP_DIR}/memind-persisted-${RELEASE_ID}-before.tar.gz"
|
||||
PERSISTED_ITEMS=(
|
||||
@@ -542,6 +648,8 @@ rm -rf "${OLD_LIVE_DIR}"
|
||||
mv "${APP_DIR}" "${OLD_LIVE_DIR}"
|
||||
mv "${RUNTIME_DIR}" "${APP_DIR}"
|
||||
|
||||
remount_goosed_after_live_swap
|
||||
|
||||
say "更新 LaunchAgent 指向 runtime 启动脚本"
|
||||
cat > "${HOME}/Library/LaunchAgents/${PORTAL_LABEL}.plist" <<EOF
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
@@ -627,6 +735,7 @@ say "检查 live 目录中不再保留源码树"
|
||||
allowed_live_mjs=(
|
||||
"${APP_DIR}/server.mjs"
|
||||
"${APP_DIR}/mindspace-sandbox-mcp.mjs"
|
||||
"${APP_DIR}/tkmind-search-mcp.mjs"
|
||||
"${APP_DIR}/mindspace-public-links.mjs"
|
||||
)
|
||||
extra_files=""
|
||||
|
||||
@@ -36,6 +36,11 @@ const messageTs = read('src/utils/message.ts');
|
||||
assertIncludes(messageTs, 'deriveUserFacingText', 'message.ts');
|
||||
assertIncludes(messageTs, 'deriveAssistantFacingText', 'message.ts');
|
||||
assertIncludes(messageTs, 'chat-finish-sync.mjs', 'message.ts');
|
||||
assertIncludes(
|
||||
messageTs,
|
||||
'deriveUserFacingText(message.metadata.displayText)',
|
||||
'message.ts metadata displayText guard',
|
||||
);
|
||||
|
||||
const conversationDisplay = read('conversation-display.mjs');
|
||||
assertIncludes(conversationDisplay, 'TASK_ROUTING_HINT_RE', 'conversation-display.mjs');
|
||||
@@ -44,6 +49,18 @@ assertIncludes(conversationDisplay, 'deriveAssistantFacingText', 'conversation-d
|
||||
|
||||
const chatSkills = read('chat-skills.mjs');
|
||||
assertIncludes(chatSkills, 'stripKnownChatSkillPrompt', 'chat-skills.mjs');
|
||||
assertIncludes(chatSkills, "legacyEndMarker = '并说明后台入口与口令。'", 'chat-skills.mjs');
|
||||
|
||||
const chatPanel = read('src/components/ChatPanel.tsx');
|
||||
assertIncludes(chatPanel, "import { VoiceInputButton } from './VoiceInputButton'", 'ChatPanel.tsx');
|
||||
assertIncludes(chatPanel, '<VoiceInputButton', 'ChatPanel.tsx');
|
||||
assertIncludes(chatPanel, 'onLiveTranscript={handleVoiceLiveTranscript}', 'ChatPanel.tsx');
|
||||
assertIncludes(chatPanel, 'onTranscript={handleVoiceTranscript}', 'ChatPanel.tsx');
|
||||
assertIncludes(chatPanel, 'setInput(mergeVoiceText(text))', 'ChatPanel.tsx voice transcript wiring');
|
||||
|
||||
const voiceInputButton = read('src/components/VoiceInputButton.tsx');
|
||||
assertIncludes(voiceInputButton, 'useVoiceSession({', 'VoiceInputButton.tsx');
|
||||
assertIncludes(voiceInputButton, 'onTranscript?.(transcript)', 'VoiceInputButton.tsx');
|
||||
|
||||
const server = read('server.mjs');
|
||||
assertIncludes(server, 'canUseSnapshotCache', 'server.mjs');
|
||||
|
||||
@@ -134,11 +134,11 @@ load_skill → page-data-collect
|
||||
|
||||
```sql
|
||||
CREATE TABLE IF NOT EXISTS survey_responses (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
id BIGINT GENERATED BY DEFAULT AS IDENTITY PRIMARY KEY,
|
||||
q1_feature TEXT NOT NULL,
|
||||
q2_usage TEXT NOT NULL,
|
||||
q3_suggestion TEXT NOT NULL,
|
||||
created_at TEXT NOT NULL DEFAULT (datetime('now', '+8 hours'))
|
||||
created_at TIMESTAMPTZ NOT NULL DEFAULT CURRENT_TIMESTAMP
|
||||
);
|
||||
```
|
||||
|
||||
@@ -157,6 +157,13 @@ CREATE TABLE IF NOT EXISTS survey_responses (
|
||||
}
|
||||
```
|
||||
|
||||
**数据层失败必须立即停止(fail closed)**:
|
||||
|
||||
- `private_data_execute`、`private_data_register_dataset`、`private_data_schema/query` 任一返回连接错误、权限错误或 `isError: true` 时,禁止继续写 HTML、bind 或发布。
|
||||
- 禁止声称“先准备 HTML,PG 恢复后会自动生效”;平台没有延迟补执行队列。数据库恢复后必须重新执行建表、注册、bind 和交付前自检。
|
||||
- PostgreSQL 连接错误应原样报告,不得把 `/tmp/.s.PGSQL.*`、`ECONNREFUSED` 或 `permission denied` 解释成“稍后会自动恢复”。
|
||||
- dataset 配置了 `soft_delete` 时,表必须包含 `deleted_at TIMESTAMPTZ`;配置了 `own_rows` 时,表必须包含 policy 指定的所有者字段。
|
||||
|
||||
### 3. 页面层:写 HTML
|
||||
|
||||
- 用 `write_file` / `edit_file` 写入或更新 `public/*.html`
|
||||
@@ -167,6 +174,14 @@ CREATE TABLE IF NOT EXISTS survey_responses (
|
||||
<script src="/assets/page-data-client.js"></script>
|
||||
```
|
||||
|
||||
客户端只允许调用 `page-data-client.js` 已公开的方法:`listRows`、`getSchema`、`getStats`、`insertRow`、`updateRow`、`deleteRow`、`authenticate`。删除单行使用:
|
||||
|
||||
```js
|
||||
await client.deleteRow('dataset_name', rowId);
|
||||
```
|
||||
|
||||
禁止发明 `softDeleteRows`、`deleteRows` 等不存在的方法;服务端会根据 dataset 的 `soft_delete` 授权把 `deleteRow` 转换为软删除。
|
||||
|
||||
- **第三方 JS 库**(Chart.js、ECharts 等)禁止写 CDN `https://...`;发布页 CSP 只允许同源脚本。优先用平台预置路径,或下载到 `public/assets/` 后用相对路径引用:
|
||||
|
||||
```html
|
||||
@@ -287,6 +302,7 @@ CREATE TABLE IF NOT EXISTS survey_responses (
|
||||
3. HTML 含 `page-data-client.js`;已 bind 或发布后平台会注入 pageId
|
||||
4. HTML **不含** `127.0.0.1:`、`/api/survey/`、`PLACEHOLDER_PAGE_ID`
|
||||
5. 向用户说明:访客如何提交、管理员如何用口令查看记录
|
||||
6. HTML 未调用 `softDeleteRows` / `deleteRows` 等客户端不存在的方法;删除使用 `deleteRow(dataset, rowId)`
|
||||
|
||||
## 回复格式
|
||||
|
||||
|
||||
+77
-1242
File diff suppressed because it is too large
Load Diff
+257
@@ -0,0 +1,257 @@
|
||||
import type { InsufficientBalanceDetails, SessionEvent } from '../types';
|
||||
|
||||
export const API = '/api';
|
||||
const DEFAULT_API_TIMEOUT_MS = 20_000;
|
||||
|
||||
export class ApiError extends Error {
|
||||
readonly status: number;
|
||||
readonly code?: string;
|
||||
readonly details?: InsufficientBalanceDetails | Record<string, unknown>;
|
||||
|
||||
constructor(
|
||||
status: number,
|
||||
message: string,
|
||||
code?: string,
|
||||
details?: InsufficientBalanceDetails | Record<string, unknown>,
|
||||
) {
|
||||
super(sanitizeUserFacingErrorMessage(message));
|
||||
this.name = 'ApiError';
|
||||
this.status = status;
|
||||
this.code = code;
|
||||
this.details = details;
|
||||
}
|
||||
}
|
||||
|
||||
export function sanitizeUserFacingErrorMessage(message: string) {
|
||||
const normalized = String(message ?? '').trim();
|
||||
const serviceName = [103, 111, 111, 115, 101]
|
||||
.map((code) => String.fromCharCode(code))
|
||||
.join('');
|
||||
const servicePattern = new RegExp(`${serviceName}d?`, 'i');
|
||||
if (!normalized) return normalized;
|
||||
if (!servicePattern.test(normalized)) return normalized;
|
||||
if (/超时|timeout/i.test(normalized)) {
|
||||
return '后端连接超时,请确认后端服务正常后重试';
|
||||
}
|
||||
if (/不可用|连接失败|failed to fetch|networkerror|fetch failed|upstream|econn|enotfound/i.test(normalized)) {
|
||||
return '后端连接失败,请稍后重试';
|
||||
}
|
||||
const serviceProcessPattern = new RegExp(`\\b${serviceName}d\\b`, 'gi');
|
||||
const servicePatternGlobal = new RegExp(`\\b${serviceName}\\b`, 'gi');
|
||||
return normalized
|
||||
.replace(serviceProcessPattern, '后端服务')
|
||||
.replace(servicePatternGlobal, '后端');
|
||||
}
|
||||
|
||||
export async function parseErrorResponse(res: Response): Promise<{
|
||||
message: string;
|
||||
code?: string;
|
||||
details?: InsufficientBalanceDetails | Record<string, unknown>;
|
||||
}> {
|
||||
const text = await res.text().catch(() => '');
|
||||
try {
|
||||
const body = JSON.parse(text) as Record<string, unknown>;
|
||||
const nested =
|
||||
body.error && typeof body.error === 'object'
|
||||
? (body.error as Record<string, unknown>)
|
||||
: body;
|
||||
const message =
|
||||
typeof nested.message === 'string'
|
||||
? nested.message
|
||||
: typeof body.message === 'string'
|
||||
? body.message
|
||||
: text;
|
||||
const code =
|
||||
typeof nested.code === 'string'
|
||||
? nested.code
|
||||
: typeof body.code === 'string'
|
||||
? body.code
|
||||
: undefined;
|
||||
const details = nested.details ?? body.details;
|
||||
if (code === 'INSUFFICIENT_BALANCE') {
|
||||
return {
|
||||
message: sanitizeUserFacingErrorMessage(message),
|
||||
code,
|
||||
details: {
|
||||
code: 'INSUFFICIENT_BALANCE' as const,
|
||||
balanceCents: Number((details as Record<string, unknown>)?.balanceCents ?? body.balanceCents ?? 0),
|
||||
minRechargeCents: Number(
|
||||
(details as Record<string, unknown>)?.minRechargeCents ?? body.minRechargeCents ?? 500,
|
||||
),
|
||||
suggestedTiers: Array.isArray((details as Record<string, unknown>)?.suggestedTiers)
|
||||
? ((details as Record<string, unknown>).suggestedTiers as unknown[]).map((value) => Number(value))
|
||||
: Array.isArray(body.suggestedTiers)
|
||||
? body.suggestedTiers.map((value) => Number(value))
|
||||
: [],
|
||||
},
|
||||
};
|
||||
}
|
||||
return {
|
||||
message: sanitizeUserFacingErrorMessage(message),
|
||||
code,
|
||||
details: details && typeof details === 'object'
|
||||
? (details as InsufficientBalanceDetails | Record<string, unknown>)
|
||||
: undefined,
|
||||
};
|
||||
} catch {
|
||||
return { message: sanitizeUserFacingErrorMessage(text || res.statusText) };
|
||||
}
|
||||
}
|
||||
|
||||
let unauthorizedHandler: (() => void) | null = null;
|
||||
let unauthorizedHandling = false;
|
||||
|
||||
export function setUnauthorizedHandler(handler: (() => void) | null) {
|
||||
unauthorizedHandler = handler;
|
||||
if (handler) unauthorizedHandling = false;
|
||||
}
|
||||
|
||||
export function resetUnauthorizedGuard() {
|
||||
unauthorizedHandling = false;
|
||||
}
|
||||
|
||||
export function notifyUnauthorized() {
|
||||
if (!unauthorizedHandler || unauthorizedHandling) return;
|
||||
unauthorizedHandling = true;
|
||||
unauthorizedHandler();
|
||||
}
|
||||
|
||||
export async function fetchWithTimeout(
|
||||
input: RequestInfo | URL,
|
||||
init?: RequestInit,
|
||||
timeoutMs = DEFAULT_API_TIMEOUT_MS,
|
||||
): Promise<Response> {
|
||||
const controller = new AbortController();
|
||||
const upstreamSignal = init?.signal;
|
||||
const timeout = window.setTimeout(() => controller.abort(), timeoutMs);
|
||||
|
||||
const abortFromUpstream = () => controller.abort();
|
||||
if (upstreamSignal) {
|
||||
if (upstreamSignal.aborted) controller.abort();
|
||||
else upstreamSignal.addEventListener('abort', abortFromUpstream, { once: true });
|
||||
}
|
||||
|
||||
try {
|
||||
return await fetch(input, {
|
||||
...init,
|
||||
signal: controller.signal,
|
||||
});
|
||||
} finally {
|
||||
window.clearTimeout(timeout);
|
||||
upstreamSignal?.removeEventListener('abort', abortFromUpstream);
|
||||
}
|
||||
}
|
||||
|
||||
export async function portalFetch<T>(path: string, init?: RequestInit): Promise<T> {
|
||||
let res: Response;
|
||||
try {
|
||||
res = await fetchWithTimeout(path, {
|
||||
...init,
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
...init?.headers,
|
||||
},
|
||||
});
|
||||
} catch (err) {
|
||||
throw new ApiError(0, formatNetworkError(err));
|
||||
}
|
||||
|
||||
if (res.status === 401) {
|
||||
notifyUnauthorized();
|
||||
const text = await res.text().catch(() => '');
|
||||
throw new ApiError(401, text || '未授权,请重新登录');
|
||||
}
|
||||
|
||||
if (!res.ok) {
|
||||
const parsed = await parseErrorResponse(res);
|
||||
throw new ApiError(
|
||||
res.status,
|
||||
parsed.message || `${res.status} ${res.statusText}`,
|
||||
parsed.code,
|
||||
parsed.details,
|
||||
);
|
||||
}
|
||||
|
||||
if (res.status === 204) return undefined as T;
|
||||
const text = await res.text().catch(() => '');
|
||||
if (text.trimStart().startsWith('<')) {
|
||||
throw new ApiError(
|
||||
res.status,
|
||||
`接口 ${path} 返回了页面而非 JSON,请重启后端(pnpm dev 或 node server.mjs)`,
|
||||
);
|
||||
}
|
||||
try {
|
||||
return JSON.parse(text) as T;
|
||||
} catch {
|
||||
throw new ApiError(res.status, '服务器响应格式错误');
|
||||
}
|
||||
}
|
||||
|
||||
export function formatNetworkError(err: unknown) {
|
||||
const message = err instanceof Error ? err.message : '网络请求失败';
|
||||
if (err instanceof DOMException && err.name === 'AbortError') {
|
||||
return '后端连接超时,请确认后端服务正常后重试';
|
||||
}
|
||||
if (message.includes('Failed to fetch') || message.includes('NetworkError')) {
|
||||
return '无法连接后端服务,请先运行: pnpm dev 或 node server.mjs';
|
||||
}
|
||||
return sanitizeUserFacingErrorMessage(message);
|
||||
}
|
||||
|
||||
export function sanitizeSessionEvent(event: SessionEvent): SessionEvent {
|
||||
if (event.type !== 'Error') return event;
|
||||
return { ...event, error: sanitizeUserFacingErrorMessage(event.error) };
|
||||
}
|
||||
|
||||
export async function apiFetch<T>(
|
||||
path: string,
|
||||
init?: RequestInit,
|
||||
options?: { timeoutMs?: number },
|
||||
): Promise<T> {
|
||||
let res: Response;
|
||||
try {
|
||||
res = await fetchWithTimeout(
|
||||
`${API}${path}`,
|
||||
{
|
||||
...init,
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
...init?.headers,
|
||||
},
|
||||
},
|
||||
options?.timeoutMs,
|
||||
);
|
||||
} catch (err) {
|
||||
throw new ApiError(0, formatNetworkError(err));
|
||||
}
|
||||
|
||||
if (res.status === 401) {
|
||||
notifyUnauthorized();
|
||||
const text = await res.text().catch(() => '');
|
||||
throw new ApiError(401, text || '未授权,请重新登录');
|
||||
}
|
||||
|
||||
if (!res.ok) {
|
||||
const parsed = await parseErrorResponse(res);
|
||||
throw new ApiError(
|
||||
res.status,
|
||||
parsed.message || `${res.status} ${res.statusText}`,
|
||||
parsed.code,
|
||||
parsed.details,
|
||||
);
|
||||
}
|
||||
|
||||
if (res.status === 204) return undefined as T;
|
||||
const rawText = await res.text().catch(() => '');
|
||||
if (rawText.trimStart().startsWith('<')) {
|
||||
throw new ApiError(
|
||||
res.status,
|
||||
`接口 ${API}${path} 返回了页面而非 JSON,请重启后端(pnpm dev 或 node server.mjs)`,
|
||||
);
|
||||
}
|
||||
try {
|
||||
return JSON.parse(rawText) as T;
|
||||
} catch {
|
||||
throw new ApiError(res.status, '服务器响应格式错误');
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,80 @@
|
||||
import type { MindSpaceAgentJob } from '../types';
|
||||
import { apiFetch } from './core';
|
||||
import type { MindSpaceListPage } from './mindspace-pages';
|
||||
|
||||
export async function createMindSpaceAgentJob(input: {
|
||||
jobType: string;
|
||||
instruction: string;
|
||||
allowedAssetIds: string[];
|
||||
outputType?: 'page_draft' | 'html_page' | 'markdown';
|
||||
outputCategoryId?: string;
|
||||
idempotencyKey?: string;
|
||||
locale?: string;
|
||||
timezone?: string;
|
||||
capabilities?: {
|
||||
network?: boolean;
|
||||
shell?: boolean;
|
||||
createPage?: boolean;
|
||||
};
|
||||
}): Promise<MindSpaceAgentJob> {
|
||||
const result = await apiFetch<{ data: MindSpaceAgentJob }>('/mindspace/v1/agent/jobs', {
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
job_type: input.jobType,
|
||||
instruction: input.instruction,
|
||||
allowed_asset_ids: input.allowedAssetIds,
|
||||
output_type: input.outputType ?? 'page_draft',
|
||||
output_category_id: input.outputCategoryId,
|
||||
idempotency_key: input.idempotencyKey,
|
||||
locale: input.locale,
|
||||
timezone: input.timezone,
|
||||
capabilities: input.capabilities,
|
||||
}),
|
||||
});
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function getMindSpaceAgentJob(jobId: string): Promise<MindSpaceAgentJob> {
|
||||
const result = await apiFetch<{ data: MindSpaceAgentJob }>(
|
||||
`/mindspace/v1/agent/jobs/${encodeURIComponent(jobId)}`,
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function listMindSpaceAgentJobs(options?: {
|
||||
limit?: number;
|
||||
offset?: number;
|
||||
}): Promise<{ items: MindSpaceAgentJob[]; page: MindSpaceListPage }> {
|
||||
const limit = options?.limit ?? 10;
|
||||
const offset = options?.offset ?? 0;
|
||||
const result = await apiFetch<{ data: MindSpaceAgentJob[]; page?: MindSpaceListPage }>(
|
||||
`/mindspace/v1/agent/jobs?limit=${encodeURIComponent(String(limit))}&offset=${encodeURIComponent(String(offset))}`,
|
||||
);
|
||||
return { items: result.data, page: result.page ?? {} };
|
||||
}
|
||||
|
||||
export async function runMindSpaceAgentJob(
|
||||
jobId: string,
|
||||
): Promise<{ started: boolean; jobId: string }> {
|
||||
const result = await apiFetch<{ data: { started: boolean; jobId: string } }>(
|
||||
`/mindspace/v1/agent/jobs/${encodeURIComponent(jobId)}/run`,
|
||||
{ method: 'POST', body: JSON.stringify({}) },
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function cancelMindSpaceAgentJob(jobId: string): Promise<MindSpaceAgentJob> {
|
||||
const result = await apiFetch<{ data: MindSpaceAgentJob }>(
|
||||
`/mindspace/v1/agent/jobs/${encodeURIComponent(jobId)}/cancel`,
|
||||
{ method: 'POST', body: JSON.stringify({}) },
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function retryMindSpaceAgentJob(jobId: string): Promise<MindSpaceAgentJob> {
|
||||
const result = await apiFetch<{ data: MindSpaceAgentJob }>(
|
||||
`/mindspace/v1/agent/jobs/${encodeURIComponent(jobId)}/retry`,
|
||||
{ method: 'POST', body: JSON.stringify({}) },
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
@@ -0,0 +1,246 @@
|
||||
import type {
|
||||
MindSpace,
|
||||
MindSpaceAsset,
|
||||
MindSpaceCleanupItem,
|
||||
MindSpaceConversationPackage,
|
||||
MindSpaceQuota,
|
||||
MindSpaceScheduleReminder,
|
||||
MindSpaceUpload,
|
||||
} from '../types';
|
||||
import { CHAT_IMAGE_UPLOAD_MAX_INPUT_BYTES } from '../utils/imageUpload';
|
||||
import { API, ApiError, apiFetch } from './core';
|
||||
|
||||
function formatBytes(bytes: number) {
|
||||
if (!Number.isFinite(bytes) || bytes < 0) return '0B';
|
||||
if (bytes >= 1024 * 1024) {
|
||||
const mb = bytes / 1024 / 1024;
|
||||
return `${Number.isInteger(mb) ? mb : mb.toFixed(1)}MB`;
|
||||
}
|
||||
if (bytes >= 1024) {
|
||||
const kb = bytes / 1024;
|
||||
return `${Number.isInteger(kb) ? kb : kb.toFixed(1)}KB`;
|
||||
}
|
||||
return `${bytes}B`;
|
||||
}
|
||||
|
||||
function readNumberDetail(details: ApiError['details'], key: string) {
|
||||
if (!details || typeof details !== 'object') return null;
|
||||
const value = (details as Record<string, unknown>)[key];
|
||||
return typeof value === 'number' && Number.isFinite(value) ? value : null;
|
||||
}
|
||||
|
||||
function isImageUploadFile(file: File) {
|
||||
if (file.type.startsWith('image/')) return true;
|
||||
return /\.(png|jpe?g|webp|gif)$/i.test(file.name);
|
||||
}
|
||||
|
||||
function normalizeMindSpaceUploadError(error: unknown, file: File): Error {
|
||||
if (!(error instanceof ApiError)) {
|
||||
return error instanceof Error ? error : new Error('上传失败,请重试');
|
||||
}
|
||||
|
||||
const imageMax = formatBytes(CHAT_IMAGE_UPLOAD_MAX_INPUT_BYTES);
|
||||
if (error.code === 'quota_exceeded' || error.status === 429) {
|
||||
const requiredBytes = readNumberDetail(error.details, 'requiredBytes');
|
||||
const availableBytes = readNumberDetail(error.details, 'availableBytes');
|
||||
const detail =
|
||||
requiredBytes !== null && availableBytes !== null
|
||||
? `当前剩余 ${formatBytes(availableBytes)},本次需要 ${formatBytes(requiredBytes)}。`
|
||||
: '';
|
||||
return new ApiError(
|
||||
error.status,
|
||||
`剩余空间不足,${detail}请减少图片数量或压缩后重试。`,
|
||||
error.code,
|
||||
error.details,
|
||||
);
|
||||
}
|
||||
|
||||
if (error.code === 'file_too_large' || error.status === 413) {
|
||||
const message = isImageUploadFile(file)
|
||||
? `图片文件过大,单张图片不能超过 ${imageMax},请压缩后重试。`
|
||||
: `文件过大,请压缩到单文件上限以内后重试。`;
|
||||
return new ApiError(error.status, message, error.code, error.details);
|
||||
}
|
||||
|
||||
if (/MindSpace\s*服务异常/.test(error.message) || error.code === 'internal_error') {
|
||||
return new ApiError(
|
||||
error.status,
|
||||
`上传失败,请减少图片数量或压缩图片后重试;单张图片上限 ${imageMax}。`,
|
||||
error.code,
|
||||
error.details,
|
||||
);
|
||||
}
|
||||
|
||||
return error;
|
||||
}
|
||||
|
||||
export async function getMindSpace(): Promise<MindSpace> {
|
||||
const result = await apiFetch<{ data: MindSpace }>('/mindspace/v1/space');
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function getMindSpaceConversationPackage(
|
||||
sessionId: string,
|
||||
): Promise<MindSpaceConversationPackage> {
|
||||
const result = await apiFetch<{ data: MindSpaceConversationPackage }>(
|
||||
`/mindspace/v1/conversation-packages/${encodeURIComponent(sessionId)}`,
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export function buildMindSpaceConversationPackageManifestDownloadUrl(sessionId: string): string {
|
||||
return `${API}/mindspace/v1/conversation-packages/${encodeURIComponent(sessionId)}/manifest.json`;
|
||||
}
|
||||
|
||||
export async function ignoreMindSpaceScheduleReminder(reminderId: string) {
|
||||
const result = await apiFetch<{ data: MindSpaceScheduleReminder }>(
|
||||
`/mindspace/v1/schedule/reminders/${encodeURIComponent(reminderId)}/ignore`,
|
||||
{ method: 'POST' },
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function deleteMindSpaceScheduleReminders(ids: string[]) {
|
||||
const result = await apiFetch<{ data: { deleted: number } }>(
|
||||
'/mindspace/v1/schedule/reminders/bulk-delete',
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({ ids }),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function listMindSpaceCleanupItems(): Promise<{
|
||||
items: MindSpaceCleanupItem[];
|
||||
totalBytes: number;
|
||||
}> {
|
||||
const result = await apiFetch<{
|
||||
data: { items: MindSpaceCleanupItem[]; totalBytes: number };
|
||||
}>('/mindspace/v1/space/cleanup');
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function runMindSpaceCleanup(itemIds: string[]): Promise<{
|
||||
removedCount: number;
|
||||
freedBytes: number;
|
||||
quota?: MindSpaceQuota;
|
||||
}> {
|
||||
const result = await apiFetch<{
|
||||
data: { removedCount: number; freedBytes: number; quota?: MindSpaceQuota };
|
||||
}>('/mindspace/v1/space/cleanup', {
|
||||
method: 'POST',
|
||||
body: JSON.stringify({ item_ids: itemIds }),
|
||||
});
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function listMindSpaceAssets(
|
||||
categoryCode?: string,
|
||||
): Promise<MindSpaceAsset[]> {
|
||||
const query = categoryCode ? `?category_code=${encodeURIComponent(categoryCode)}` : '';
|
||||
const result = await apiFetch<{ data: MindSpaceAsset[] }>(`/mindspace/v1/assets${query}`);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function uploadMindSpaceAsset(
|
||||
categoryId: string,
|
||||
file: File,
|
||||
options: {
|
||||
maxImageBytes?: number;
|
||||
onProgress?: (progress: number) => void;
|
||||
sessionId?: string | null;
|
||||
messageId?: string | null;
|
||||
} = {},
|
||||
): Promise<MindSpaceAsset> {
|
||||
const maxImageBytes = options.maxImageBytes ?? CHAT_IMAGE_UPLOAD_MAX_INPUT_BYTES;
|
||||
if (file.type.startsWith('image/') && file.size > maxImageBytes) {
|
||||
throw new ApiError(
|
||||
413,
|
||||
`图片文件过大,当前 ${(file.size / 1024 / 1024).toFixed(2)}MB,超过 ${maxImageBytes / 1024 / 1024}MB 上传上限。`,
|
||||
);
|
||||
}
|
||||
|
||||
let created: { data: MindSpaceUpload };
|
||||
try {
|
||||
created = await apiFetch<{ data: MindSpaceUpload }>('/mindspace/v1/uploads', {
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
category_id: categoryId,
|
||||
filename: file.name,
|
||||
size_bytes: file.size,
|
||||
declared_mime_type: file.type || null,
|
||||
...(options.sessionId ? { session_id: options.sessionId } : {}),
|
||||
...(options.messageId ? { message_id: options.messageId } : {}),
|
||||
}),
|
||||
});
|
||||
} catch (error) {
|
||||
throw normalizeMindSpaceUploadError(error, file);
|
||||
}
|
||||
|
||||
try {
|
||||
await uploadFileContent(created.data.uploadUrl, file, options.onProgress);
|
||||
const completed = await apiFetch<{ data: MindSpaceAsset }>(
|
||||
`/mindspace/v1/uploads/${created.data.id}/complete`,
|
||||
{ method: 'POST', body: JSON.stringify({}) },
|
||||
);
|
||||
return completed.data;
|
||||
} catch (error) {
|
||||
await apiFetch(`/mindspace/v1/uploads/${created.data.id}`, {
|
||||
method: 'DELETE',
|
||||
}).catch(() => {});
|
||||
throw normalizeMindSpaceUploadError(error, file);
|
||||
}
|
||||
}
|
||||
|
||||
export async function claimMindSpaceConversationUploads(
|
||||
sessionId: string,
|
||||
messageId: string,
|
||||
): Promise<{ claimedCount: number }> {
|
||||
const result = await apiFetch<{ data: { claimedCount: number } }>(
|
||||
`/mindspace/v1/conversation-packages/${encodeURIComponent(sessionId)}/claim-uploads`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({ message_id: messageId }),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
function uploadFileContent(
|
||||
url: string,
|
||||
file: File,
|
||||
onProgress?: (progress: number) => void,
|
||||
): Promise<void> {
|
||||
return new Promise((resolve, reject) => {
|
||||
const xhr = new XMLHttpRequest();
|
||||
xhr.open('PUT', url);
|
||||
xhr.setRequestHeader('Content-Type', 'application/octet-stream');
|
||||
xhr.upload.onprogress = (event) => {
|
||||
if (!event.lengthComputable || !onProgress) return;
|
||||
onProgress(Math.min(0.99, Math.max(0, event.loaded / event.total)));
|
||||
};
|
||||
xhr.onload = () => {
|
||||
if (xhr.status >= 200 && xhr.status < 300) {
|
||||
onProgress?.(1);
|
||||
resolve();
|
||||
return;
|
||||
}
|
||||
let message = '文件内容上传失败';
|
||||
try {
|
||||
const body = JSON.parse(xhr.responseText || '{}') as { error?: { message?: string } };
|
||||
message = body?.error?.message ?? message;
|
||||
} catch {
|
||||
// Keep the generic upload error when the response is not JSON.
|
||||
}
|
||||
reject(new ApiError(xhr.status, message));
|
||||
};
|
||||
xhr.onerror = () => reject(new ApiError(0, '文件内容上传失败'));
|
||||
xhr.onabort = () => reject(new ApiError(0, '文件上传已取消'));
|
||||
xhr.send(file);
|
||||
});
|
||||
}
|
||||
|
||||
export async function deleteMindSpaceAsset(assetId: string): Promise<void> {
|
||||
await apiFetch(`/mindspace/v1/assets/${assetId}`, { method: 'DELETE' });
|
||||
}
|
||||
@@ -0,0 +1,351 @@
|
||||
import type {
|
||||
ChatSaveResult,
|
||||
MindSpacePage,
|
||||
MindSpacePageDeletePreview,
|
||||
MindSpacePageDeleteResult,
|
||||
MindSpaceSaveCategory,
|
||||
} from '../types';
|
||||
import {
|
||||
ApiError,
|
||||
apiFetch,
|
||||
formatNetworkError,
|
||||
notifyUnauthorized,
|
||||
parseErrorResponse,
|
||||
} from './core';
|
||||
|
||||
export type MindSpaceListPage = {
|
||||
total?: number;
|
||||
offset?: number;
|
||||
limit?: number;
|
||||
has_more?: boolean;
|
||||
};
|
||||
|
||||
export async function getMindSpacePageDeletePreview(
|
||||
pageId: string,
|
||||
): Promise<MindSpacePageDeletePreview> {
|
||||
const result = await apiFetch<{ data: MindSpacePageDeletePreview }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/delete-preview`,
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function deleteMindSpacePage(
|
||||
pageId: string,
|
||||
options?: { removeFromPlaza?: boolean },
|
||||
): Promise<MindSpacePageDeleteResult> {
|
||||
const params = new URLSearchParams();
|
||||
if (options?.removeFromPlaza) params.set('remove_from_plaza', 'true');
|
||||
const query = params.toString() ? `?${params.toString()}` : '';
|
||||
const result = await apiFetch<{ data: MindSpacePageDeleteResult }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}${query}`,
|
||||
{ method: 'DELETE' },
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function listMindSpacePages(options?: {
|
||||
status?: string;
|
||||
limit?: number;
|
||||
offset?: number;
|
||||
categoryCode?: string;
|
||||
}): Promise<{ items: MindSpacePage[]; page: MindSpaceListPage }> {
|
||||
const params = new URLSearchParams();
|
||||
if (options?.status) params.set('status', options.status);
|
||||
if (options?.limit != null) params.set('limit', String(options.limit));
|
||||
if (options?.offset != null) params.set('offset', String(options.offset));
|
||||
if (options?.categoryCode) params.set('category_code', options.categoryCode);
|
||||
const query = params.toString() ? `?${params.toString()}` : '';
|
||||
const result = await apiFetch<{ data: MindSpacePage[]; page?: MindSpaceListPage }>(
|
||||
`/mindspace/v1/pages${query}`,
|
||||
);
|
||||
return { items: result.data, page: result.page ?? {} };
|
||||
}
|
||||
|
||||
export async function getMindSpacePage(pageId: string): Promise<MindSpacePage> {
|
||||
const result = await apiFetch<{ data: MindSpacePage }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}`,
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function saveChatMessageAsPage(input: {
|
||||
sessionId: string;
|
||||
messageId: string;
|
||||
title: string;
|
||||
summary?: string;
|
||||
templateId?: string;
|
||||
categoryCode?: MindSpaceSaveCategory;
|
||||
selectedLinkIndex?: number;
|
||||
acknowledgedFindingIds?: string[];
|
||||
replacePageId?: string;
|
||||
saveAsNew?: boolean;
|
||||
}): Promise<ChatSaveResult> {
|
||||
const result = await apiFetch<{ data: ChatSaveResult }>(
|
||||
'/mindspace/v1/pages/save-from-chat',
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
session_id: input.sessionId,
|
||||
message_id: input.messageId,
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
template_id: input.templateId ?? 'editorial',
|
||||
category_code: input.categoryCode ?? 'draft',
|
||||
selected_link_index: input.selectedLinkIndex ?? 0,
|
||||
acknowledged_finding_ids: input.acknowledgedFindingIds,
|
||||
page_type: input.templateId === 'report' ? 'report' : 'article',
|
||||
replace_page_id: input.replacePageId,
|
||||
save_as_new: input.saveAsNew ?? false,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function createMindSpacePageFromAsset(input: {
|
||||
assetId: string;
|
||||
title?: string;
|
||||
summary?: string;
|
||||
}): Promise<MindSpacePage> {
|
||||
const result = await apiFetch<{ data: { page: MindSpacePage } }>(
|
||||
'/mindspace/v1/pages/from-asset',
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
asset_id: input.assetId,
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data.page;
|
||||
}
|
||||
|
||||
export async function createMindSpacePage(input: {
|
||||
title: string;
|
||||
summary?: string;
|
||||
content: string;
|
||||
templateId: string;
|
||||
}): Promise<MindSpacePage> {
|
||||
const result = await apiFetch<{ data: MindSpacePage }>('/mindspace/v1/pages', {
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
content: input.content,
|
||||
template_id: input.templateId,
|
||||
page_type: input.templateId === 'report' ? 'report' : 'article',
|
||||
}),
|
||||
});
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function updateMindSpacePage(
|
||||
pageId: string,
|
||||
input: {
|
||||
expectedVersion: number;
|
||||
title: string;
|
||||
summary: string;
|
||||
content: string;
|
||||
templateId: string;
|
||||
changeNote?: string;
|
||||
},
|
||||
): Promise<MindSpacePage> {
|
||||
const result = await apiFetch<{ data: MindSpacePage }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}`,
|
||||
{
|
||||
method: 'PUT',
|
||||
body: JSON.stringify({
|
||||
expected_version: input.expectedVersion,
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
content: input.content,
|
||||
template_id: input.templateId,
|
||||
page_type: input.templateId === 'report' ? 'report' : 'article',
|
||||
change_note: input.changeNote,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function rewriteMindSpacePageDownloadLinks(
|
||||
pageId: string,
|
||||
content: string,
|
||||
): Promise<string> {
|
||||
const result = await apiFetch<{ data: { html: string } }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/rewrite-download-links`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({ content }),
|
||||
},
|
||||
);
|
||||
return result.data.html;
|
||||
}
|
||||
|
||||
export async function fetchMindSpacePageDraftPreview(
|
||||
pageId: string,
|
||||
input: {
|
||||
title: string;
|
||||
summary: string;
|
||||
content: string;
|
||||
templateId: string;
|
||||
},
|
||||
): Promise<string> {
|
||||
let res: Response;
|
||||
try {
|
||||
res = await fetch(`/api/mindspace/v1/pages/${encodeURIComponent(pageId)}/preview-draft`, {
|
||||
method: 'POST',
|
||||
credentials: 'same-origin',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
content: input.content,
|
||||
template_id: input.templateId,
|
||||
}),
|
||||
});
|
||||
} catch (err) {
|
||||
throw new ApiError(0, formatNetworkError(err));
|
||||
}
|
||||
if (res.status === 401) {
|
||||
notifyUnauthorized();
|
||||
throw new ApiError(401, '未授权,请重新登录');
|
||||
}
|
||||
if (!res.ok) {
|
||||
const parsed = await parseErrorResponse(res);
|
||||
throw new ApiError(res.status, parsed.message || `${res.status} ${res.statusText}`, parsed.code);
|
||||
}
|
||||
return res.text();
|
||||
}
|
||||
|
||||
export function openMindSpaceDraftPreviewWindow(html: string) {
|
||||
const blob = new Blob([html], { type: 'text/html;charset=utf-8' });
|
||||
const url = URL.createObjectURL(blob);
|
||||
const opened = window.open(url, '_blank', 'noopener,noreferrer');
|
||||
if (!opened) {
|
||||
URL.revokeObjectURL(url);
|
||||
throw new ApiError(0, '无法打开新窗口,请检查浏览器是否拦截弹窗');
|
||||
}
|
||||
window.setTimeout(() => URL.revokeObjectURL(url), 120_000);
|
||||
}
|
||||
|
||||
export async function uploadMindSpacePageThumbnail(
|
||||
pageId: string,
|
||||
input: {
|
||||
imageBase64: string;
|
||||
mimeType?: string;
|
||||
title?: string;
|
||||
summary?: string;
|
||||
content?: string;
|
||||
},
|
||||
): Promise<{ updatedAt: number }> {
|
||||
const result = await apiFetch<{ data: { updatedAt: number } }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/thumbnail/upload`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
image_base64: input.imageBase64,
|
||||
mime_type: input.mimeType,
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
html: input.content,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function regenerateMindSpacePageThumbnail(
|
||||
pageId: string,
|
||||
input: {
|
||||
title?: string;
|
||||
summary?: string;
|
||||
content?: string;
|
||||
useAi?: boolean;
|
||||
instruction?: string;
|
||||
} = {},
|
||||
): Promise<{ updatedAt: number; content?: string | null }> {
|
||||
const result = await apiFetch<{ data: { updatedAt: number; content?: string | null } }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/thumbnail/regenerate`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
html: input.content,
|
||||
use_ai: input.useAi ?? false,
|
||||
instruction: input.instruction,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function bindMindSpacePageLiveEdit(
|
||||
pageId: string,
|
||||
sessionId: string,
|
||||
options?: { parentSessionId?: string },
|
||||
): Promise<{ sessionId: string; pageId: string; parentSessionId?: string }> {
|
||||
const result = await apiFetch<{ data: { sessionId: string; pageId: string; parentSessionId?: string } }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/live-edit/bind`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
session_id: sessionId,
|
||||
...(options?.parentSessionId ? { parent_session_id: options.parentSessionId } : {}),
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function forkMindSpacePageEditSession(
|
||||
pageId: string,
|
||||
parentSessionId: string,
|
||||
h5ApiBase?: string | null,
|
||||
): Promise<{ sessionId: string; pageId: string; parentSessionId: string }> {
|
||||
const result = await apiFetch<{
|
||||
data: { sessionId: string; pageId: string; parentSessionId: string };
|
||||
}>(`/mindspace/v1/pages/${encodeURIComponent(pageId)}/live-edit/fork-session`, {
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
parent_session_id: parentSessionId,
|
||||
...(h5ApiBase ? { h5_api_base: h5ApiBase } : {}),
|
||||
}),
|
||||
});
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function closeMindSpacePageEditSession(
|
||||
pageId: string,
|
||||
input: {
|
||||
sessionId: string;
|
||||
parentSessionId?: string | null;
|
||||
summary?: string;
|
||||
},
|
||||
): Promise<{ sessionId: string; pageId: string; merged: boolean }> {
|
||||
const result = await apiFetch<{
|
||||
data: { sessionId: string; pageId: string; merged: boolean };
|
||||
}>(`/mindspace/v1/pages/${encodeURIComponent(pageId)}/live-edit/close-session`, {
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
session_id: input.sessionId,
|
||||
parent_session_id: input.parentSessionId ?? undefined,
|
||||
summary: input.summary ?? '',
|
||||
}),
|
||||
});
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function getMindSpacePageLiveRevision(pageId: string): Promise<{
|
||||
pageId: string;
|
||||
versionNo: number;
|
||||
updatedAt: number;
|
||||
liveRevision: number;
|
||||
}> {
|
||||
const result = await apiFetch<{
|
||||
data: { pageId: string; versionNo: number; updatedAt: number; liveRevision: number };
|
||||
}>(`/mindspace/v1/pages/${encodeURIComponent(pageId)}/live-edit/revision`);
|
||||
return result.data;
|
||||
}
|
||||
@@ -0,0 +1,165 @@
|
||||
import type {
|
||||
MindSpacePublication,
|
||||
MindSpacePublicationStats,
|
||||
MindSpacePublishCheck,
|
||||
MindSpaceRedactedCopyResult,
|
||||
} from '../types';
|
||||
import { apiFetch } from './core';
|
||||
import { getMindSpacePage } from './mindspace-pages';
|
||||
|
||||
export async function checkMindSpacePagePublication(
|
||||
pageId: string,
|
||||
input: {
|
||||
pageVersionId: string;
|
||||
accessMode: MindSpacePublishCheck['accessMode'];
|
||||
urlSlug: string;
|
||||
password?: string;
|
||||
expiresAt?: number | null;
|
||||
},
|
||||
): Promise<MindSpacePublishCheck> {
|
||||
const result = await apiFetch<{ data: MindSpacePublishCheck }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/publish-check`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
page_version_id: input.pageVersionId,
|
||||
access_mode: input.accessMode,
|
||||
url_slug: input.urlSlug,
|
||||
password: input.password,
|
||||
expires_at: input.expiresAt,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function publishMindSpacePage(
|
||||
pageId: string,
|
||||
input: {
|
||||
pageVersionId: string;
|
||||
accessMode: MindSpacePublishCheck['accessMode'];
|
||||
urlSlug: string;
|
||||
acknowledgedFindingIds: string[];
|
||||
password?: string;
|
||||
expiresAt?: number | null;
|
||||
},
|
||||
): Promise<MindSpacePublication> {
|
||||
const result = await apiFetch<{ data: MindSpacePublication }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/publish`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
page_version_id: input.pageVersionId,
|
||||
access_mode: input.accessMode,
|
||||
url_slug: input.urlSlug,
|
||||
password: input.password,
|
||||
expires_at: input.expiresAt,
|
||||
acknowledged_finding_ids: input.acknowledgedFindingIds,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function updatePublicationStatus(
|
||||
publicationId: string,
|
||||
input: {
|
||||
accessMode: MindSpacePublishCheck['accessMode'];
|
||||
expiresAt?: number | null;
|
||||
},
|
||||
): Promise<MindSpacePublication> {
|
||||
const result = await apiFetch<{ data: MindSpacePublication }>(
|
||||
`/mindspace/v1/publications/${encodeURIComponent(publicationId)}/update-status`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
access_mode: input.accessMode,
|
||||
expires_at: input.expiresAt,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function redactMindSpacePage(
|
||||
pageId: string,
|
||||
input: {
|
||||
pageVersionId: string;
|
||||
expectedVersion: number;
|
||||
title: string;
|
||||
summary: string;
|
||||
content: string;
|
||||
},
|
||||
): Promise<MindSpaceRedactedCopyResult> {
|
||||
const result = await apiFetch<{ data: MindSpaceRedactedCopyResult }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/redact`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
page_version_id: input.pageVersionId,
|
||||
expected_version: input.expectedVersion,
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
content: input.content,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function fixMindSpacePagePublication(
|
||||
pageId: string,
|
||||
input: {
|
||||
pageVersionId: string;
|
||||
expectedVersion: number;
|
||||
title: string;
|
||||
summary: string;
|
||||
content: string;
|
||||
},
|
||||
): Promise<MindSpaceRedactedCopyResult> {
|
||||
const result = await apiFetch<{ data: MindSpaceRedactedCopyResult }>(
|
||||
`/mindspace/v1/pages/${encodeURIComponent(pageId)}/publish-fix`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
page_version_id: input.pageVersionId,
|
||||
expected_version: input.expectedVersion,
|
||||
title: input.title,
|
||||
summary: input.summary,
|
||||
content: input.content,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
/** @deprecated use redactMindSpacePage */
|
||||
export async function createMindSpaceRedactedCopy(
|
||||
pageId: string,
|
||||
pageVersionId: string,
|
||||
): Promise<MindSpaceRedactedCopyResult> {
|
||||
const page = await getMindSpacePage(pageId);
|
||||
return redactMindSpacePage(pageId, {
|
||||
pageVersionId,
|
||||
expectedVersion: page.versionNo,
|
||||
title: page.title,
|
||||
summary: page.summary,
|
||||
content: page.content ?? '',
|
||||
});
|
||||
}
|
||||
|
||||
export async function offlineMindSpacePublication(publicationId: string): Promise<void> {
|
||||
await apiFetch(
|
||||
`/mindspace/v1/publications/${encodeURIComponent(publicationId)}/offline`,
|
||||
{ method: 'POST', body: JSON.stringify({}) },
|
||||
);
|
||||
}
|
||||
|
||||
export async function getMindSpacePublicationStats(
|
||||
publicationId: string,
|
||||
): Promise<MindSpacePublicationStats> {
|
||||
const result = await apiFetch<{ data: MindSpacePublicationStats }>(
|
||||
`/mindspace/v1/publications/${encodeURIComponent(publicationId)}/stats`,
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
@@ -0,0 +1,166 @@
|
||||
import type {
|
||||
PageDataAccessPolicy,
|
||||
PageDataDatasetSummary,
|
||||
PageDataLogEntry,
|
||||
PageDataOpsOverview,
|
||||
} from '../types';
|
||||
import { ApiError, apiFetch } from './core';
|
||||
|
||||
export async function listOwnerPageDataPolicies(): Promise<
|
||||
Array<{
|
||||
pageId: string;
|
||||
ownerUserId: string;
|
||||
accessMode: string;
|
||||
datasetCount: number;
|
||||
scopeHash: string;
|
||||
updatedAt: number;
|
||||
}>
|
||||
> {
|
||||
const result = await apiFetch<{
|
||||
data: {
|
||||
policies: Array<{
|
||||
pageId: string;
|
||||
ownerUserId: string;
|
||||
accessMode: string;
|
||||
datasetCount: number;
|
||||
scopeHash: string;
|
||||
updatedAt: number;
|
||||
}>;
|
||||
};
|
||||
}>('/page-data/policies');
|
||||
return result.data.policies;
|
||||
}
|
||||
|
||||
export async function listPageDataDatasets(): Promise<PageDataDatasetSummary[]> {
|
||||
const result = await apiFetch<{ data: { datasets: PageDataDatasetSummary[] } }>('/page-data');
|
||||
return result.data.datasets;
|
||||
}
|
||||
|
||||
export async function getPageDataPolicy(pageId: string): Promise<PageDataAccessPolicy | null> {
|
||||
try {
|
||||
const result = await apiFetch<{ data: { policy: PageDataAccessPolicy } }>(
|
||||
`/page-data/policies/${encodeURIComponent(pageId)}`,
|
||||
);
|
||||
return result.data.policy;
|
||||
} catch (error) {
|
||||
if (error instanceof ApiError && error.status === 404) return null;
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
export async function applyPageDataPublishPolicy(
|
||||
pageId: string,
|
||||
input: {
|
||||
datasetName: string;
|
||||
capabilities?: {
|
||||
read?: boolean;
|
||||
insert?: boolean;
|
||||
update?: boolean;
|
||||
softDelete?: boolean;
|
||||
};
|
||||
},
|
||||
): Promise<PageDataAccessPolicy> {
|
||||
const result = await apiFetch<{ data: { policy: PageDataAccessPolicy } }>(
|
||||
`/page-data/policies/${encodeURIComponent(pageId)}/apply-publish`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
datasetName: input.datasetName,
|
||||
capabilities: input.capabilities ?? {},
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data.policy;
|
||||
}
|
||||
|
||||
export async function savePageDataPolicy(
|
||||
pageId: string,
|
||||
policy: Partial<PageDataAccessPolicy>,
|
||||
): Promise<PageDataAccessPolicy> {
|
||||
const result = await apiFetch<{ data: { policy: PageDataAccessPolicy } }>(
|
||||
`/page-data/policies/${encodeURIComponent(pageId)}`,
|
||||
{
|
||||
method: 'PUT',
|
||||
body: JSON.stringify(policy),
|
||||
},
|
||||
);
|
||||
return result.data.policy;
|
||||
}
|
||||
|
||||
export function buildPageDataExportUrl(dataset: string, format: 'json' | 'csv' = 'json') {
|
||||
const params = new URLSearchParams({ format });
|
||||
return `/api/page-data/${encodeURIComponent(dataset)}/export?${params.toString()}`;
|
||||
}
|
||||
|
||||
export async function getPageDataOpsOverview(pageId: string): Promise<PageDataOpsOverview> {
|
||||
const result = await apiFetch<{ data: PageDataOpsOverview }>(
|
||||
`/page-data/policies/${encodeURIComponent(pageId)}/ops`,
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function listPageDataLogs(
|
||||
pageId: string,
|
||||
input: { limit?: number; offset?: number } = {},
|
||||
): Promise<{ pageId: string; logs: PageDataLogEntry[]; count: number }> {
|
||||
const params = new URLSearchParams();
|
||||
if (input.limit != null) params.set('limit', String(input.limit));
|
||||
if (input.offset != null) params.set('offset', String(input.offset));
|
||||
const query = params.toString();
|
||||
const result = await apiFetch<{ data: { pageId: string; logs: PageDataLogEntry[]; count: number } }>(
|
||||
`/page-data/policies/${encodeURIComponent(pageId)}/logs${query ? `?${query}` : ''}`,
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function revokePageDataTokens(
|
||||
pageId: string,
|
||||
input: { revokeAll?: boolean; token?: string },
|
||||
): Promise<{ pageId: string; revokedCount: number; revokeAll: boolean }> {
|
||||
const result = await apiFetch<{ data: { pageId: string; revokedCount: number; revokeAll: boolean } }>(
|
||||
`/page-data/policies/${encodeURIComponent(pageId)}/tokens/revoke`,
|
||||
{
|
||||
method: 'POST',
|
||||
body: JSON.stringify({
|
||||
revokeAll: Boolean(input.revokeAll),
|
||||
token: input.token,
|
||||
}),
|
||||
},
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function resetPageDataPassword(
|
||||
pageId: string,
|
||||
password: string,
|
||||
): Promise<{ pageId: string; passwordReset: boolean; revokedSessions: number }> {
|
||||
const result = await apiFetch<{
|
||||
data: { pageId: string; passwordReset: boolean; revokedSessions: number };
|
||||
}>(`/page-data/policies/${encodeURIComponent(pageId)}/password/reset`, {
|
||||
method: 'POST',
|
||||
body: JSON.stringify({ password }),
|
||||
});
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function closePageDataDataset(
|
||||
pageId: string,
|
||||
dataset: string,
|
||||
): Promise<{ pageId: string; dataset: string; closed: boolean }> {
|
||||
const result = await apiFetch<{ data: { pageId: string; dataset: string; closed: boolean } }>(
|
||||
`/page-data/policies/${encodeURIComponent(pageId)}/datasets/${encodeURIComponent(dataset)}/close`,
|
||||
{ method: 'POST' },
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
|
||||
export async function restorePageDataRow(
|
||||
dataset: string,
|
||||
rowId: number | string,
|
||||
): Promise<{ restored: boolean; row: Record<string, unknown> }> {
|
||||
const result = await apiFetch<{ data: { restored: boolean; row: Record<string, unknown> } }>(
|
||||
`/page-data/${encodeURIComponent(dataset)}/rows/${encodeURIComponent(String(rowId))}/restore`,
|
||||
{ method: 'POST' },
|
||||
);
|
||||
return result.data;
|
||||
}
|
||||
@@ -1586,7 +1586,7 @@ export function MindSpacePageDetail({
|
||||
<button
|
||||
type="button"
|
||||
className={previewRefreshPending ? 'is-refresh-pending' : undefined}
|
||||
onClick={handleManualPreviewRefresh}
|
||||
onClick={() => handleManualPreviewRefresh()}
|
||||
title={previewRefreshPending ? '草稿已有新内容,点击刷新预览' : '将当前草稿同步到预览'}
|
||||
>
|
||||
刷新预览{previewRefreshPending ? ' · 有新修改' : ''}
|
||||
@@ -1684,15 +1684,21 @@ export function MindSpacePageDetail({
|
||||
) : null}
|
||||
|
||||
{confirmPublicationStatusOpen && page?.publication ? (
|
||||
<MindSpaceModal className="mindspace-confirm-publication-status-modal">
|
||||
<MindSpaceModal
|
||||
open={confirmPublicationStatusOpen}
|
||||
onClose={() => setConfirmPublicationStatusOpen(false)}
|
||||
title="页面预览期确认"
|
||||
eyebrow="PUBLICATION STATUS"
|
||||
className="mindspace-confirm-publication-status-modal"
|
||||
disableClose={statusConfirming}
|
||||
>
|
||||
<div className="mindspace-modal-content">
|
||||
<h3>页面预览期确认</h3>
|
||||
<p>你的页面当前处于 30 分钟预览期。请选择后续状态:</p>
|
||||
<div className="mindspace-modal-actions">
|
||||
<button
|
||||
className="mindspace-secondary"
|
||||
disabled={statusConfirming}
|
||||
onClick={() => confirmPublicationStatus('private')}
|
||||
onClick={() => confirmPublicationStatus('owner_only')}
|
||||
>
|
||||
{statusConfirming ? '处理中...' : '改为私有'}
|
||||
</button>
|
||||
|
||||
@@ -477,6 +477,10 @@ function formatBytes(bytes: number) {
|
||||
|
||||
type AssetFilter = 'all' | 'images' | 'files' | 'pages';
|
||||
|
||||
function previewBlocked() {
|
||||
return new Error('预览模式仅供查看,不能修改内容');
|
||||
}
|
||||
|
||||
function canGenerateWithAgent(asset: MindSpaceAsset) {
|
||||
const textLikeMimeTypes = new Set([
|
||||
'text/plain',
|
||||
|
||||
@@ -17,7 +17,16 @@ export function VoiceInputDialog({
|
||||
onSend: (text: string) => void;
|
||||
onError?: (message: string) => void;
|
||||
}) {
|
||||
const { phase, text, analyser, liveRecognition, stopListening, finishFallbackRecording, resetSession } =
|
||||
const {
|
||||
phase,
|
||||
text,
|
||||
analyser,
|
||||
liveRecognition,
|
||||
updateText,
|
||||
stopListening,
|
||||
finishFallbackRecording,
|
||||
resetSession,
|
||||
} =
|
||||
useVoiceSession({
|
||||
active: open && !disabled,
|
||||
onError,
|
||||
|
||||
@@ -204,7 +204,7 @@ export function getDisplayText(message: Message): string {
|
||||
// REGRESSION GUARD: never show agent-only routing/skill prefixes in the chat UI.
|
||||
if (message.role === 'user') {
|
||||
if ('displayText' in message.metadata && message.metadata.displayText != null) {
|
||||
return stripImageUrlLines(message.metadata.displayText);
|
||||
return stripImageUrlLines(deriveUserFacingText(message.metadata.displayText));
|
||||
}
|
||||
const raw = message.content
|
||||
.filter((c): c is Extract<MessageContent, { type: 'text' }> => c.type === 'text')
|
||||
|
||||
+14
-1
@@ -1870,7 +1870,7 @@ export function createUserAuth(pool, options = {}) {
|
||||
);
|
||||
// Wire up the sandbox MCP for user workspace tools and the private data space.
|
||||
// File operations are OS-bound to the user's workspace; private_data_* tools
|
||||
// only touch the user's single SQLite data space inside that workspace.
|
||||
// only touch the user's isolated PostgreSQL schema.
|
||||
let sandboxMcp = null;
|
||||
if (effectiveCapabilities.static_publish || effectiveCapabilities.private_data_space) {
|
||||
try {
|
||||
@@ -1879,6 +1879,13 @@ export function createUserAuth(pool, options = {}) {
|
||||
env,
|
||||
user,
|
||||
});
|
||||
const containerFlag = String(env.GOOSED_MCP_CONTAINERIZED ?? '').trim();
|
||||
const containerized = containerFlag
|
||||
? containerFlag === '1'
|
||||
: Boolean(
|
||||
env.GOOSED_MCP_NODE_PATH &&
|
||||
path.resolve(env.GOOSED_MCP_NODE_PATH) !== path.resolve(process.execPath),
|
||||
);
|
||||
sandboxMcp = {
|
||||
// When goosed runs in a container its filesystem is split from the portal's,
|
||||
// so the host paths the portal would otherwise send (node binary, MCP script)
|
||||
@@ -1891,6 +1898,12 @@ export function createUserAuth(pool, options = {}) {
|
||||
workspaceRef: workspaceCapability.workspaceRef,
|
||||
userId: user.id,
|
||||
nodeExecPath: env.GOOSED_MCP_NODE_PATH,
|
||||
containerized,
|
||||
userDataBackend: env.MINDSPACE_USERDATA_BACKEND,
|
||||
userDataPgUrl: env.MINDSPACE_USERDATA_PG_URL,
|
||||
userDataMcpPgUrl: env.MINDSPACE_USERDATA_MCP_PG_URL,
|
||||
userDataPgHostGateway: env.MINDSPACE_USERDATA_MCP_PG_HOST,
|
||||
userDataAutoProvision: env.MINDSPACE_USERDATA_AUTO_PROVISION,
|
||||
};
|
||||
} catch (err) {
|
||||
console.warn('[getAgentSessionPolicy] sandbox MCP setup failed, falling back:', err?.message);
|
||||
|
||||
+12
-1
@@ -398,7 +398,15 @@ test('agent session policy preserves sandbox root and exposes workspace ref meta
|
||||
const auth = createUserAuth(createAgentPolicyPool(userRow), {
|
||||
h5Root: root,
|
||||
persistSessions: false,
|
||||
env: { GOOSED_SANDBOX_PUBLISH_ROOT: '/srv/goosed-mindspace' },
|
||||
env: {
|
||||
GOOSED_SANDBOX_PUBLISH_ROOT: '/srv/goosed-mindspace',
|
||||
GOOSED_MCP_NODE_PATH: '/usr/local/bin/node',
|
||||
GOOSED_MCP_SERVER_PATH: '/opt/portal/mindspace-sandbox-mcp.mjs',
|
||||
GOOSED_MCP_CONTAINERIZED: '1',
|
||||
MINDSPACE_USERDATA_BACKEND: 'postgres',
|
||||
MINDSPACE_USERDATA_PG_URL: 'postgresql://mindspace:secret@127.0.0.1:5433/mindspace_userdata_prod',
|
||||
MINDSPACE_USERDATA_AUTO_PROVISION: '1',
|
||||
},
|
||||
});
|
||||
|
||||
const policy = await auth.getAgentSessionPolicy(userRow.id);
|
||||
@@ -407,6 +415,9 @@ test('agent session policy preserves sandbox root and exposes workspace ref meta
|
||||
assert.equal(sandboxFs.envs.SANDBOX_ROOT, path.resolve('/srv/goosed-mindspace/user-1'));
|
||||
assert.equal(sandboxFs.envs.MINDSPACE_WORKSPACE_ROOT, path.resolve(root, 'MindSpace', 'user-1'));
|
||||
assert.equal(sandboxFs.envs.MINDSPACE_WORKSPACE_REF, 'mindspace://users/user-1/workspace');
|
||||
assert.equal(new URL(sandboxFs.envs.MINDSPACE_USERDATA_PG_URL).hostname, 'host.docker.internal');
|
||||
assert.equal(sandboxFs.envs.MINDSPACE_USERDATA_BACKEND, 'postgres');
|
||||
assert.equal(sandboxFs.envs.MINDSPACE_USERDATA_AUTO_PROVISION, '1');
|
||||
});
|
||||
|
||||
test('admin capabilities include granted platform skills', async () => {
|
||||
|
||||
Reference in New Issue
Block a user