Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
e50d8f4
feat(web): expose PR discussion actions and bisect templates
Qiyuanqiii Oct 9, 2026
54f4683
refactor(web): organize workspace navigation around task workflows
Qiyuanqiii Oct 9, 2026
be9ad4f
feat(web): open exact Run GitHub tools from connections
Qiyuanqiii Oct 9, 2026
3963647
feat: manage MCP bearer credentials through shared product API
Qiyuanqiii Oct 9, 2026
6b4aa79
feat: expose bounded task budgets and immutable project configuration
Qiyuanqiii Oct 9, 2026
25c23c7
fix: preserve legacy task snapshots and isolate configuration reads
Qiyuanqiii Oct 9, 2026
5357e32
feat(web): retain task budget drafts and expose pinned configuration
Qiyuanqiii Oct 9, 2026
44d7042
fix: localize task configuration and retain rejection validity
Qiyuanqiii Oct 9, 2026
1d8d440
fix(web): retain rejected task configuration through draft edits
Qiyuanqiii Oct 9, 2026
d771b95
test(web): await real lazy surfaces before recovery navigation
Qiyuanqiii Oct 9, 2026
2f57243
chore: finalize frontend rebuild integration and evidence scope
Qiyuanqiii Oct 9, 2026
f9471d3
docs: record schema v186 in migration history
Qiyuanqiii Oct 10, 2026
29a3b44
refactor(web): guide users through task preparation and connections
Qiyuanqiii Oct 10, 2026
91fbceb
Rebuild extension onboarding around stages and next actions
Qiyuanqiii Oct 10, 2026
ba31c89
refactor(web): guide task actions with clear state and next steps
Qiyuanqiii Oct 10, 2026
afcdd4f
fix(web): describe the configured reasoning behavior accurately
Qiyuanqiii Oct 10, 2026
ccfeabd
refactor(web): clarify saved request recovery steps
Qiyuanqiii Oct 10, 2026
ece65e7
Guide operator actions with state and next-step copy
Qiyuanqiii Oct 10, 2026
5553688
Guide MCP credential setup by server review state
Qiyuanqiii Oct 10, 2026
5ec28a3
Match evidence and revert guidance to available actions
Qiyuanqiii Oct 10, 2026
6220f3c
fix(web): qualify browser preview and PR submission guidance
Qiyuanqiii Oct 10, 2026
e0d7043
refactor(web): keep runtime diagnostics in permission details
Qiyuanqiii Oct 10, 2026
3673dc9
fix(web): show commit check and signing effects before confirmation
Qiyuanqiii Oct 10, 2026
684a3dd
test(web): align review navigation with guided evidence states
Qiyuanqiii Oct 10, 2026
cf5919b
docs: record guided frontend rebuild and acceptance evidence
Qiyuanqiii Oct 10, 2026
ec8be9d
fix(web): align credential guidance and serialize model refreshes
Qiyuanqiii Oct 10, 2026
aa5cdc1
test(windows): capture fixed-command ownership failures
Qiyuanqiii Oct 10, 2026
75aceac
test(web): await asynchronous configuration validity reports
Qiyuanqiii Oct 10, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
134 changes: 134 additions & 0 deletions docs/FRONTEND_REBUILD_STATUS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,134 @@
# Frontend rebuild status

Baseline: main `71ede3053b1d71f4c6e4f7053b355ebe301c1a1b`, checked on
2026-10-10. The roadmap is not complete. Merged PRs #288 and #293 finish
the first recovery/connection fixes; #286 contributes scoped journey fixes.
Passing those slices does not establish complete product or platform acceptance.

## Product guidance revision — 2026-10-10

The user's latest direction treats language and information architecture as part
of the rebuild. Everyday screens should lead with the current state, the action
available to the user and the next step. Replace defensive explanations and
chains of negations with concise guidance tied to real controls. Keep decision
information, such as the effect of deleting a credential or an unresolved write,
at the relevant action; put implementation details in expandable diagnostics.

Three parallel lanes updated task/recovery flows, connections/extensions and
review/diagnostic tools. The connection hub now groups task preparation, tools
and collaboration, and runtime settings around a return-to-task action. MCP,
Plugin and LSP setup show their actual stage and next step. Empty and error
states point to available actions; model, Docker and Safe Web refreshes read
state without repeating a write. Chinese and existing English translations are
updated together. [Product language guidance](PRODUCT_LANGUAGE.md) records the
conventions for future work.

Implementation details use expandable records. Commit hook/signing effects,
shared credential impact, partial file changes and approval scope remain visible
at the relevant decision. Independent review corrected guidance for staged MCP
credentials, configured reasoning effort, unavailable browser/UI Evidence
capabilities and already-applied or denied revert proposals. Existing identity,
approval, recovery and capability checks remain the behavioral acceptance criteria.
Model selection waits for refreshes and pending switches to finish, preserving
the in-flight write state. GitHub credential guidance follows the connection's
actual credential type, enabled state and system-store availability.

Verification for this revision:

- Full Vitest: **186 files, 1,834 tests passed** on the integrated code. The full
run initially found cross-component assertions referring to old text; their
selectors were updated while retaining request, binding, recovery and authority
assertions. The final full run passed without retries or increased timeouts.
Deferred-response regressions cover both refresh/switch orderings; GitHub
connection tests cover missing PAT/OAuth credentials and unavailable storage.
- TypeScript, production build and generated API/transcript-key checks passed.
Existing large-chunk build warnings remain.
- An intermediate CI run interrupted the baseline Windows fixed-command paging
test before its command timeout. The same seven native subcases passed locally;
the interruption cause remains unconfirmed. Failure-only authority/renewal
timing diagnostics now preserve the next failure's evidence, with the existing
permissions, time budgets, output and replay assertions unchanged.
- Production assets served by the real Go API and isolated test database were
checked at 1280px and 390px. Verified connection navigation, immutable saved
budgets, staged MCP credential guidance and read-only refresh, model status,
Copilot return-focus, task draft retention and permission-menu Escape/focus.
Connection, extension and model pages had no horizontal overflow at 390px;
browser error logs were empty. Original captures are retained under ignored
`build/frontend-rebuild/guidance-*` paths.
- The browser pass used a local fixture with no real model credentials. Credential
forms and approval gates were inspected; remote authentication, MCP discovery,
permission changes and remote writes were not exercised. Native platform and
complete model-to-delivery acceptance remain in the roadmap below.

## Current parallel implementation

All implementation worktrees start from the same baseline. Commits use Qiyuanqiii.
The integration owner reviews and combines the independently tested changes.

| Lane | Implementation scope | State |
| --- | --- | --- |
| Workspace | Direct task navigation, context/recovery and observation entries, file/terminal/preview switching, existing connection/environment entries | Implemented and locally verified |
| Task configuration | Shared Go budget/project-config resolution, immutable creation and successor contracts, safe preview and creation UI | Implemented and locally verified |
| MCP credentials | Go-owned credential presence/write/delete for supported MCP descriptors, first-entry/update/removal UI | Implemented; real OS lifecycle/remote authentication not exercised |
| Review and Git | Existing PR thread/reviewer operations through exact previews and approvals; registered bisect recipe selection and bounds | Implemented; remote writes tested with fixtures only |

The existing Thread/Run identities, draft and attachment recovery, original
operation keys, approval bindings, read-only restrictions, process capability
gates, historical routes and conditional module loading remain acceptance
requirements. No renderer-owned execution or credential authority is introduced.

## Remaining roadmap

- P1/P2: The slices above have contract/recovery tests and production-browser
checks; the full configured-model-to-delivery journey still needs acceptance.
- P3: Task/project configuration, manual HTTPS MCP bearer credentials and PR
discussion/reviewer actions are implemented. Cost caps require a price snapshot
and do not represent exact billing. Project exclusion paths, suggested Skills
and typed command IDs remain recorded metadata without automatic filtering,
installation or execution; see ADR 0170.
- P4: Plugin version history/rollback/trust revocation, Hooks diagnostics, Docker
onboarding, guided UI Evidence, Batch preparation/rework and the scoped macOS
runtime assembly remain separate unfinished work.
- P5: Full project/model-to-delivery, restart/disconnection, long-session,
keyboard/responsive and native cross-platform acceptance is still outstanding.

## First implementation evidence

Local verification used Go 1.26.9 and the repository's pinned frontend packages:

- Full Vitest: **184 files, 1,822 tests passed**. The first combined runs exposed
missing locale providers in new test fixtures and cold real-module compilation
consuming the recovery test's action timeout. Both were corrected without
mocking the recovery callback chain or increasing global timeouts; the final
full run passed.
- TypeScript and production build passed. Settings, configuration and diagnostic
surfaces remain lazy-loaded. Existing large-chunk build warnings remain.
- Combined Go checks passed for bounded budgets, initial/restart creation replay,
changed-budget conflict, project rejection, successor inheritance, v185-to-v186
upgrade, invalid direct SQL inserts, MCP binding and HTTP/OpenAPI contracts.
Full projectconfig, protocolregistry, surfacegovernance, releasegate and
producte2e packages passed. Focused MCP race and injected-store Desktop checks
also passed. This is not a claim of `go test ./...` on every platform.
- Generated OpenAPI/TypeScript and protocol history checks retain old readers and
default fingerprints. Independent review found and repaired legacy zero/large
budget reads, explicit-null parsing and known-rejection retention across draft
edits/remounts.

A real browser used production assets served by an isolated loopback Go process
and a separate test database. Verified task/context navigation, return-draft
retention, file/preview entries, a 390-pixel layout, configuration source display,
reconnection, immutable saved budgets after the project file changed, and the
exact-Run GitHub entry. A staged manual HTTPS MCP descriptor displayed actual
Windows Credential Manager availability and absence of its dedicated test token.
No secret was entered, OS credential changed, MCP discovery approved or remote
GitHub write executed.

The isolated service deliberately had no configured real model. Both UI and HTTP
refused new Thread creation until model setup. A CLI-created fixture supplied the
saved-budget browser check; HTTP creation success is covered by Go/client tests,
not asserted as a real-account browser journey. Original browser JPEGs and local
logs are retained under ignored `build/frontend-rebuild/`; they are not generated
illustrations or repository fixtures.

These checks do not stand in for native desktop, real remote account, Docker or
macOS acceptance. The overall rebuild remains incomplete.
45 changes: 45 additions & 0 deletions docs/PRODUCT_LANGUAGE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# 产品语言与操作引导

Universal Code 面向在项目中完成任务的人。页面说明帮助用户理解当前状态、
选择操作并继续工作。文案与入口、表单、结果反馈一起设计和验收。

## 页面结构

1. 用用户要完成的事情命名入口,例如“连接模型”“查看改动”“恢复任务”。
2. 页面开头用一句话说明当前可以做什么,把主要操作放在说明旁边。
3. 空状态给出第一步,失败状态给出原因和页面中实际可用的下一步。
4. 多阶段功能显示当前阶段和后续操作。例如 MCP 接入依次完成登记、
凭据配置、发现、审查,然后回到任务使用。
5. 将 ID、指纹、协议版本和收据细节放在可展开的“详细记录”或诊断区域。
与选择直接相关的项目、模型、费用和操作范围保持可见。

## 表达方式

优先采用“当前状态 → 下一步”的短句,按钮名称与引导保持一致。
用肯定句描述实际作用与生效范围,把有关实施方法的说明留在工程文档中。

| 场景 | 用户看到的指引 |
| --- | --- |
| 任务创建结果待确认 | 原请求已保存。选择“核对结果”,继续处理这次请求。 |
| 模型列表读取失败 | 模型列表读取失败,请选择“重新读取模型”。 |
| Plugin 导入完成 | 安装包已导入。查看包内容,选择要启用的能力。 |
| MCP 凭据保存成功 | 本机凭据已保存。继续发现服务器,检查连接结果。 |
| 查询输出只有一部分 | 当前显示已保留的输出片段。展开命令记录查看来源。 |
| 查看预算历史 | 本次执行使用创建时保存的预算。后续项目修改用于新任务。 |

文案跟随实际接口和状态。例如保存本机凭据与验证远端连接分别显示各自结果;
写入结果待确认时,下一步应读取原操作结果。重新提交、继续执行和删除等
操作使用各自已有的确认与恢复流程。

保留用户作决定需要的信息:删除的具体对象、共享凭据影响的连接、授权范围、
费用来源和生效时间。使用具体对象和直接语句,让用户在操作处理解影响。

## 一致性与验收

- 常用页面使用“任务”“执行”“项目”;内部标识在详细记录中展示。
- 已有中英文内容同步维护,相同操作沿用相同按钮和结果名称。
- 每条指引对应当前状态下可访问的入口或实际可执行的步骤。
- 原有查询、权限、审批、绑定和恢复行为继续通过相关交互测试。
- 在真实浏览器中检查主流程、空状态、失败状态、键盘操作及窄屏布局。

这一约定随前端重建维护。产品体验以实际操作和用户反馈为准。
22 changes: 22 additions & 0 deletions docs/PROJECT_MEMORY.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,27 @@
# Prayu Project Memory

> 2026-10-10 product guidance revision: the frontend rebuild includes user-facing
> language and information hierarchy. The connection hub groups task preparation,
> tools/collaboration and runtime settings; MCP/Plugin/LSP show actual setup stages.
> Task, approval, recovery and delivery copy explains the current state and next
> available action. Technical records expand on demand, while decision effects
> stay visible. See [product language](PRODUCT_LANGUAGE.md) and the
> [integrated verification](FRONTEND_REBUILD_STATUS.md): 186 frontend files / 1,834
> tests, production build and an isolated real-browser pass. Remaining P4/P5 work
> continues under the same rebuild roadmap.

> 2026-10-10 frontend rebuild checkpoint: V2 exposes task navigation, exact-Run
> recovery/observation, connection management and PR discussion actions. New task
> drafts carry bounded budgets; Go resolves narrowing-only project configuration
> and pins the result through schema v186, creation replay and successor Runs.
> Supported manual HTTPS MCP registrations can manage bearer credentials through
> the shared Go API and OS store. Approval, scope and runtime capability gates
> remain independent. See [implementation status and evidence boundaries](FRONTEND_REBUILD_STATUS.md)
> and [task configuration ADR](adr/0170-task-budget-and-project-configuration.md).
> This checkpoint does not complete P4 environment/extension workflows or native
> cross-platform acceptance. Project exclusion paths and suggested skills/actions
> remain recorded metadata, without automatic filtering, installation or execution.

> 2026-10-09 recovery and connection workflow checkpoint (#292): Continuity
> Fork/Resume and checkpoint Fork open the returned Run in V2 without inheriting
> a source Thread binding. Late completion refreshes record and Thread lists
Expand Down
100 changes: 100 additions & 0 deletions docs/adr/0170-task-budget-and-project-configuration.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
# ADR 0170: Product task budgets and immutable project configuration

Date: 2026-10-09

## Status

Accepted for schema v186, shared Go product creation, read-only previews and the
standalone task configuration presentation. Application routing is integrated at
the existing Thread creation seam; this ADR grants no execution capability.

## Contract

HTTP and in-process Desktop `run_creation.v1` / `thread_creation.v1` requests may
include `budget` with optional `max_turns`, `max_tool_calls`, `max_tokens`,
`max_cost_usd` and `timeout_seconds`. Go canonicalizes omitted fields to the
existing defaults. Turns remain 1..10,000; tools remain 1..1,000,000; tokens are
0..1,000,000,000; cost is 0..100,000 USD; timeout is 0..604,800 seconds. Zero
disables an optional token/cost/timeout dimension. Positive cost must be at least
one micro-USD and is rounded once to micro-USD, matching the monetary ledger.
These are execution limits, never exact billing estimates or permission grants.
An active operator price snapshot remains necessary before a cost-capped model
call; task creation and preview make no model or account calls.

The normalized operator ceiling is pinned as `RunConfig.requested_budget`;
`Run.Budget` contains the effective narrowed limits. The canonical creation
fingerprint binds that operator input, independently of the live repository
file. Default-budget requests retain historical fingerprints. Initial-state
replay checks the durable operation before loading project files and returns the
original snapshot across restart. Changed explicit budgets under the same key
conflict. The existing refusal to replay a creation after its Run has advanced
remains; original-request observation provides that later recovery path.

Web/Desktop creation and Standard Code's initial Run use the same Go loader and
resolver as CLI: `.prayu/config.yaml` is bounded, strictly decoded, inert input;
profiles and read-only selection restrict admission and project budgets must be
strictly below the operator ceiling. Any rejected field blocks the complete
creation. No HTTP/Desktop ignore switch is added. The CLI's explicit
`--ignore-project-config` contract remains. The selected profile is checked
against the project profile set, which may contain several supported profiles.
This adds no global or user configuration file or renderer-selected host path.

Thread successors and explicit continuity branches inherit the stored effective
budget, normalized operator ceiling and project snapshot. They never reload
changed project configuration. Their existing authority reset is unchanged.

Schema v186 replaces only the controlled-creation trigger's fixed budget/root
limits. Its Mission/Session/mode/root/event/network and all-denied execution
checks are preserved. The new branch verifies bounded requested limits and
exact requested/effective/project relationships. New product snapshots reject
budget or project replacement in SQLite. Historical migrations remain frozen;
v185 upgrade preserves old Runs and creation operations without fabricated
operator input. Clean-install schema artifacts are generated from the full plan.

## Read surfaces and provenance

`POST /api/v1/task-configuration/preview` uses the **read bearer**, accepts only
workspace identity, profile and budget, and has no idempotency/mutation effect.
`GET /api/v1/runs/{run_id}/task-configuration` reads the immutable saved snapshot.
Both return `task_configuration.v1`, `capability_grant=false`, normalized
requested/effective budgets, closed field sources, a safe project summary and
fingerprints. A rejected preview has field-specific reasons and no partial
project/effective fingerprint. Decoder details and repository bytes are never
returned; exclusion paths and Skill suggestions are represented as counts.
Malformed JSON, unknown/duplicate fields and unsupported bounds fail closed.

Sources describe normalized effective values: product defaults, operator
overrides or project restrictions. Historical Runs without a retained operator
ceiling use `snapshot` provenance rather than inventing their input history.
Their read projection preserves legal historical CLI ceilings, including zero
or omitted tool limits and values above current product input bounds. The
renderer validates these saved numbers independently of creation inputs and
requires requested/effective snapshot values to match; explicit JSON null is
never a zero/default value. Preview responses cannot claim snapshot provenance.
The configuration fingerprint includes the safe projection and full project
snapshot digest; later file edits do not alter it.

The standalone React `TaskConfiguration` component edits draft request fields
and shows the Go preview, or reads an existing Run snapshot without edits. Reads
are aborted on task changes and late results cannot replace the current view.
Connection identity also gates the first render so a replacement API client
cannot briefly expose the previous connection's saved configuration.
Draft inputs and validity belong to the workspace's parent draft state so closing
the panel cannot silently revert an invalid attempted budget to defaults.
Creation rechecks the file in Go; a preview is never admission authority.

## Explicit limits and follow-up gap

Budget and profile/read-only admission constraints actually take effect.
`exclude_paths` currently has **no runtime access-filter consumer**; it is pinned
metadata, not an enforced file-access restriction. Skill suggestions and typed
test/format action IDs are also recorded metadata and never automatically
installed, enabled or executed. The UI states these limits separately. Adding
an exclusion consumer across every relevant read/write adapter requires a later
scoped contract and regression matrix; this slice does not claim that work.

This changes neither runtime permission selection nor leases, approvals,
execution backends, secrets, command launch, model eligibility or account access.
Tests separate actual Go creation/migration/replay/succession checks from React
presentation fixtures. Native Desktop delivery and live model billing remain
outside the evidence supplied by this slice.
Loading
Loading