048f25f580
Show privacy popup on launch, gate login on legal consent, and link user agreement and privacy policy pages in the mini program. Co-authored-by: Cursor <cursoragent@cursor.com>
73 lines
3.9 KiB
Markdown
73 lines
3.9 KiB
Markdown
# TKMind WeChat Mini Program
|
||
|
||
This directory contains the native WeChat Mini Program client. It is intentionally isolated from the H5/backend code so development can proceed without changing existing services.
|
||
|
||
## Current MVP
|
||
|
||
- Native WeChat login entry via `wx.login`.
|
||
- H5 account/password login fallback through `/auth/login`.
|
||
- Chat submission through `/api/agent/runs`.
|
||
- Agent run polling through `/api/agent/runs/:runId`.
|
||
- Session detail refresh through `/api/sessions/:sessionId`.
|
||
- Session list through `/api/sessions`.
|
||
- MindSpace page list through `/api/mindspace/v1/pages`.
|
||
- Page preview through Mini Program `web-view`.
|
||
|
||
## Backend Assumptions
|
||
|
||
The H5 APIs are reused as-is. Native Mini Program login posts the `wx.login` code to `MINIAPP_LOGIN_PATH` in `utils/config.js`; the current default is `/auth/wechat-miniapp/login`. If that backend endpoint is not available yet, use the account/password login fallback during local development.
|
||
|
||
## Production / 提审前(当前默认)
|
||
|
||
- `utils/config.js` 默认 `LOCAL_DEV = false`,API 指向 **`https://m.tkmind.cn`**。
|
||
- `project.config.json` 中 `urlCheck: true`;DevTools 需配置真实小程序 AppID(非 tourist)。
|
||
- 微信公众平台需配置 request / web-view 合法域名:`m.tkmind.cn`。
|
||
- 已启用 `__usePrivacyCheck__`,登录页含协议勾选(默认不勾选)、协议全文页与微信隐私弹窗组件。
|
||
- 首次登录须主动勾选协议;登录成功后本地保存 cookie 与同意记录,下次自动登录不再展示协议区。
|
||
- 此配置**不会**触发 103 发版;仅小程序客户端连线上 Portal。
|
||
|
||
### 微信公众平台后台(提审必配)
|
||
|
||
1. **设置 → 服务内容声明 → 用户隐私保护指引**
|
||
- 声明收集:用户账号、邮箱、微信登录标识、聊天记录、设备信息
|
||
- 用途:账号登录验证、身份识别、提供 AI 对话与会话服务
|
||
2. **设置 → 基本设置 → 服务内容声明**
|
||
- 补充用户服务协议与隐私政策说明(协议已内置在小程序 `pages/legal/`)
|
||
3. 提审备注可写:「登录页已增加协议勾选与隐私政策全文,未同意前不提交用户信息;已接入微信隐私保护检测」
|
||
- **微信一键登录**还需 Portal 侧配置 `H5_WECHAT_MINIAPP_APP_ID` / `H5_WECHAT_MINIAPP_APP_SECRET` 并实现 `/auth/wechat-miniapp/login`;未部署前可先用账号密码登录。
|
||
|
||
### 开发者工具仍显示「游客模式」时
|
||
|
||
1. 关闭项目,重新「导入项目」并选择 AppID `wx3e79ecd530c88da4`(不要选测试号/游客模式)
|
||
2. 或:详情 → 基本信息 → AppID 改为你自己的小程序
|
||
3. 确认 `project.config.json` 与 `project.private.config.json` 中 `appid` 均为 `wx3e79ecd530c88da4`
|
||
4. 重新编译后再点「微信一键登录」
|
||
|
||
## Local Debug (optional)
|
||
|
||
1. Start local Portal in the repo root:
|
||
|
||
```bash
|
||
pnpm dev
|
||
# or ensure http://127.0.0.1:8081/auth/status responds
|
||
```
|
||
|
||
2. Switch miniapp back to local Portal **without** touching production:
|
||
|
||
- In `utils/config.js`, set `LOCAL_DEV = true`, **or**
|
||
- Copy `utils/config.local.example.js` → `utils/config.local.js` and set `API_BASE_URL`.
|
||
|
||
`project.private.config.json` only affects DevTools compiler settings; it is **not** available to runtime `require()`.
|
||
|
||
3. WeChat DevTools → 详情 → 本地设置 (local only):
|
||
- enable **Do not verify合法域名 / TLS**
|
||
- keep **tourist AppID** only if you use account/password login; real AppID is required for `wx.login`
|
||
|
||
4. Restart Portal after pulling local server changes. Local Portal only bypasses CSRF for WeChat `servicewechat.com` referrers; production `m.tkmind.cn` is unchanged.
|
||
|
||
5. Use an account that exists in your local `.env` database auth. Wrong credentials return `401`, not `403`.
|
||
|
||
## Isolation Rule
|
||
|
||
Mini Program work should stay inside `miniapp/`. Do not modify backend, H5, Memory, MindSpace, or production release files for this MVP unless explicitly approved.
|