# TKMind WeChat Mini Program This directory contains the native WeChat Mini Program client. It is intentionally isolated from the H5/backend code so development can proceed without changing existing services. ## Current MVP - Native WeChat login entry via `wx.login`. - H5 account/password login fallback through `/auth/login`. - Chat submission through `/api/agent/runs`. - Agent run polling through `/api/agent/runs/:runId`. - Session detail refresh through `/api/sessions/:sessionId`. - Session list through `/api/sessions`. - MindSpace page list through `/api/mindspace/v1/pages`. - Page preview through Mini Program `web-view`. ## Backend Assumptions The H5 APIs are reused as-is. Native Mini Program login posts the `wx.login` code to `MINIAPP_LOGIN_PATH` in `utils/config.js`; the current default is `/auth/wechat-miniapp/login`. If that backend endpoint is not available yet, use the account/password login fallback during local development. ## Production / 提审前(当前默认) - `utils/config.js` 默认 `LOCAL_DEV = false`,API 指向 **`https://m.tkmind.cn`**。 - `project.config.json` 中 `urlCheck: true`;DevTools 需配置真实小程序 AppID(非 tourist)。 - 微信公众平台需配置 request / web-view 合法域名:`m.tkmind.cn`。 - 已启用 `__usePrivacyCheck__`,登录页含协议勾选(默认不勾选)、协议全文页与微信隐私弹窗组件。 - 首次登录须主动勾选协议;登录成功后本地保存 cookie 与同意记录,下次自动登录不再展示协议区。 - 此配置**不会**触发 103 发版;仅小程序客户端连线上 Portal。 ### 微信公众平台后台(提审必配) 1. **设置 → 服务内容声明 → 用户隐私保护指引** - 声明收集:用户账号、邮箱、微信登录标识、聊天记录、设备信息 - 用途:账号登录验证、身份识别、提供 AI 对话与会话服务 2. **设置 → 基本设置 → 服务内容声明** - 补充用户服务协议与隐私政策说明(协议已内置在小程序 `pages/legal/`) 3. 提审备注可写:「登录页已增加协议勾选与隐私政策全文,未同意前不提交用户信息;已接入微信隐私保护检测」 - **微信一键登录**还需 Portal 侧配置 `H5_WECHAT_MINIAPP_APP_ID` / `H5_WECHAT_MINIAPP_APP_SECRET` 并实现 `/auth/wechat-miniapp/login`;未部署前可先用账号密码登录。 ### 开发者工具仍显示「游客模式」时 1. 关闭项目,重新「导入项目」并选择 AppID `wx3e79ecd530c88da4`(不要选测试号/游客模式) 2. 或:详情 → 基本信息 → AppID 改为你自己的小程序 3. 确认 `project.config.json` 与 `project.private.config.json` 中 `appid` 均为 `wx3e79ecd530c88da4` 4. 重新编译后再点「微信一键登录」 ## Local Debug (optional) 1. Start local Portal in the repo root: ```bash pnpm dev # or ensure http://127.0.0.1:8081/auth/status responds ``` 2. Switch miniapp back to local Portal **without** touching production: - In `utils/config.js`, set `LOCAL_DEV = true`, **or** - Copy `utils/config.local.example.js` → `utils/config.local.js` and set `API_BASE_URL`. `project.private.config.json` only affects DevTools compiler settings; it is **not** available to runtime `require()`. 3. WeChat DevTools → 详情 → 本地设置 (local only): - enable **Do not verify合法域名 / TLS** - keep **tourist AppID** only if you use account/password login; real AppID is required for `wx.login` 4. Restart Portal after pulling local server changes. Local Portal only bypasses CSRF for WeChat `servicewechat.com` referrers; production `m.tkmind.cn` is unchanged. 5. Use an account that exists in your local `.env` database auth. Wrong credentials return `401`, not `403`. ## Isolation Rule Mini Program work should stay inside `miniapp/`. Do not modify backend, H5, Memory, MindSpace, or production release files for this MVP unless explicitly approved.