Files
memind/miniapp/README.md
T
john 048f25f580 feat(miniapp): add privacy consent and legal pages
Show privacy popup on launch, gate login on legal consent, and link
user agreement and privacy policy pages in the mini program.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-12 12:18:54 +08:00

3.9 KiB
Raw Blame History

TKMind WeChat Mini Program

This directory contains the native WeChat Mini Program client. It is intentionally isolated from the H5/backend code so development can proceed without changing existing services.

Current MVP

  • Native WeChat login entry via wx.login.
  • H5 account/password login fallback through /auth/login.
  • Chat submission through /api/agent/runs.
  • Agent run polling through /api/agent/runs/:runId.
  • Session detail refresh through /api/sessions/:sessionId.
  • Session list through /api/sessions.
  • MindSpace page list through /api/mindspace/v1/pages.
  • Page preview through Mini Program web-view.

Backend Assumptions

The H5 APIs are reused as-is. Native Mini Program login posts the wx.login code to MINIAPP_LOGIN_PATH in utils/config.js; the current default is /auth/wechat-miniapp/login. If that backend endpoint is not available yet, use the account/password login fallback during local development.

Production / 提审前(当前默认)

  • utils/config.js 默认 LOCAL_DEV = falseAPI 指向 https://m.tkmind.cn
  • project.config.jsonurlCheck: true;DevTools 需配置真实小程序 AppID(非 tourist)。
  • 微信公众平台需配置 request / web-view 合法域名:m.tkmind.cn
  • 已启用 __usePrivacyCheck__,登录页含协议勾选(默认不勾选)、协议全文页与微信隐私弹窗组件。
  • 首次登录须主动勾选协议;登录成功后本地保存 cookie 与同意记录,下次自动登录不再展示协议区。
  • 此配置不会触发 103 发版;仅小程序客户端连线上 Portal。

微信公众平台后台(提审必配)

  1. 设置 → 服务内容声明 → 用户隐私保护指引
    • 声明收集:用户账号、邮箱、微信登录标识、聊天记录、设备信息
    • 用途:账号登录验证、身份识别、提供 AI 对话与会话服务
  2. 设置 → 基本设置 → 服务内容声明
    • 补充用户服务协议与隐私政策说明(协议已内置在小程序 pages/legal/
  3. 提审备注可写:「登录页已增加协议勾选与隐私政策全文,未同意前不提交用户信息;已接入微信隐私保护检测」
  • 微信一键登录还需 Portal 侧配置 H5_WECHAT_MINIAPP_APP_ID / H5_WECHAT_MINIAPP_APP_SECRET 并实现 /auth/wechat-miniapp/login;未部署前可先用账号密码登录。

开发者工具仍显示「游客模式」时

  1. 关闭项目,重新「导入项目」并选择 AppID wx3e79ecd530c88da4(不要选测试号/游客模式)
  2. 或:详情 → 基本信息 → AppID 改为你自己的小程序
  3. 确认 project.config.jsonproject.private.config.jsonappid 均为 wx3e79ecd530c88da4
  4. 重新编译后再点「微信一键登录」

Local Debug (optional)

  1. Start local Portal in the repo root:
pnpm dev
# or ensure http://127.0.0.1:8081/auth/status responds
  1. Switch miniapp back to local Portal without touching production:

    • In utils/config.js, set LOCAL_DEV = true, or
    • Copy utils/config.local.example.jsutils/config.local.js and set API_BASE_URL.

    project.private.config.json only affects DevTools compiler settings; it is not available to runtime require().

  2. WeChat DevTools → 详情 → 本地设置 (local only):

    • enable Do not verify合法域名 / TLS
    • keep tourist AppID only if you use account/password login; real AppID is required for wx.login
  3. Restart Portal after pulling local server changes. Local Portal only bypasses CSRF for WeChat servicewechat.com referrers; production m.tkmind.cn is unchanged.

  4. Use an account that exists in your local .env database auth. Wrong credentials return 401, not 403.

Isolation Rule

Mini Program work should stay inside miniapp/. Do not modify backend, H5, Memory, MindSpace, or production release files for this MVP unless explicitly approved.