Skip to content

UI: 控制台改用「墨档案」设计,图标导航与认证页重做 - #13

Open
Conner512 wants to merge 17 commits into
mainfrom
ui/ink-archive
Open

Conner512 wants to merge 17 commits into
mainfrom
ui/ink-archive

Conversation

@Conner512

Copy link
Copy Markdown
Owner

Summary

控制台改用「墨档案」设计:纸色底、墨色字,只有一种朱砂强调色;2px 直角加细线,不再使用渐变、光晕和毛玻璃。设计变量和组件规则写在 docs/console-design.md(替代原来的 console-skins.md)。

  • 设计变量:重写 styles.css。三个主题只改强调色:朱砂、黛蓝、松绿。
  • 去掉深色模式开关:暂时只提供浅色,以前存过的明暗偏好会被忽略。
  • 图标导航:侧边栏换成方角线性图标。侧边栏、面包屑、页面标题和概览统计卡都不再显示路由编号。
  • 删除旧皮肤:删掉 skin-liquid.css、skin-aurora.css、skin-hud.css 和 SVG 折射滤镜。
  • 认证页重做:
    • 改为左右两栏布局。
    • 控制台登录页不再显示两段说明文字(ChatGPT 授权登录页仍保留「不要输入 ChatGPT 密码」的提示)。
    • 注册四个步骤都有进度条;验证器页二维码与密钥并排并有复制按钮;恢复码页加警示条。
    • OAuth 授权的确认按钮使用强调色。
  • 按钮语义:撤销、撤回、停用、取消任务等操作统一用危险色;操作弹窗最后的确认按钮使用强调色。

本分支同时带上的 6 个早期提交

这些提交之前只在本地,从未合入 main。这次改版建立在其中的「记忆优先工作台」页面结构之上:

  • 58e01bf ui(console): neural console redesign with memory constellation and owner-scoped overview charts
  • 73beb97 refactor(core): versioned schema migrations, split store helpers, owner/time index(核心层改动,不是界面)
  • dcaae3b ui(console): rebuild the console as a memory-first workbench
  • 567a8c6 ui(console): sci-fi HUD skin with the original twelve-item navigation
  • f0c29f7 ui(console): liquid-glass sci-fi skin
  • b508e9b ui(console): calm liquid glass; distribution ring replaces the radar

如果希望把 73beb97 拆成单独的 PR,需要先调整分支历史再合并。

Verification

本地环境为 macOS 上的 Node.js 26.8.2。

  • npm test:378 个 Node 测试全部通过,25 个 Hermes 测试通过。
  • npm run test:oauth:202 个里 200 个通过。失败的 CFG-01..06 和 SHARED-01 在未改动的 b508e9b 上同样失败,原因是本地 Node 26 不在生产配置校验认可的 LTS 版本内,与本次改动无关。
  • node scripts/check-publication.mjs --worktree 和 --staged:通过,扫描 436 个文件,没有发现问题。
  • 用真实的 render.mjs 和视图模板配合成数据生成页面,在本机无头 Chrome 里截取 1440×900 截图,逐页核对:概览、记忆库(含详情面板)、连接管理、账户安全、外观设置、登录、绑定验证器、OAuth 授权。
  • 未运行:
    • scripts/test-console-browser.py 和 scripts/console_select_checks.py(需要 Playwright 和完整的回环环境;脚本已同步去掉明暗模式的遍历)。
    • gitleaks 密钥扫描(本机没有安装扫描器)。
    • 真实部署和宿主环境验证。

Compatibility

  • 接口与数据:本提交不改 schema、API、scope、钩子或适配器契约。早期提交 73beb97 含 schema 迁移,请单独审阅。
  • 外观偏好:已保存的 theme(a/b/c)继续有效,现在对应三种强调色;已保存的 mode 会被忽略。
  • 资源与安全策略:CSP 和 /assets/styles.css 地址不变,打包内容改为 styles.css 加 controls.css。
  • 字体:使用系统字体。CSP 不允许外部字体源,中文网页字体也过大。
  • 随设计更新的测试:console-shell、console-ui、console-theme-first-paint、console-select-presentation、auth-purpose、registration-console,以及两个浏览器检查脚本。
  • 回滚:回退本提交即可恢复 liquid-glass 皮肤,不涉及数据迁移。

Checklist

  • The change is focused and has relevant regression coverage or documentation checks.
  • Documentation matches the implemented behavior; shared README changes are reflected in both languages. (README unchanged)
  • I reviewed the diff for credentials, personal memory, real conversation content, and runtime artifacts.
  • Publication checks pass for the worktree and staged changes.
  • I have not claimed production readiness or host compatibility based only on a local test.

🤖 Generated with Claude Code

Conner512 and others added 17 commits September 29, 2026 05:57
…ner-scoped overview charts

- New dark-first visual system for all six palettes (contrast >= 4.5:1 kept)
- Overview: memory constellation (categories/types), 30-day activity chart,
  type and lifecycle composition, sparkline, pipeline and timeline
- Core overview adds owner-scoped count aggregates (insights), no content
- Shell: glass sidebar/topbar, keyboard search (/ and Cmd/Ctrl+K)
- Library and detail: translated type/lifecycle chips with colour coding
- Sign-in: synapse field story panel and card form

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WGuzodhrtwbwjzraohufpx
…er/time index

- PRAGMA user_version migration runner with atomic steps and downgrade refusal;
  existing idempotent schema guarantees are re-checked on open (self-healing kept)
- Move schema out of store.mjs (server/lib/store/schema.mjs) and pure helpers
  to server/lib/store/helpers.mjs (store.mjs 5912 -> ~4980 lines)
- Add memories(user_id, created_at DESC, memory_id) for overview recency,
  activity and the unfiltered library; query-plan test
- Tests: presentation checks read CSS intent through a small parser instead of
  exact text; browser suite asserts rendered geometry
- Console: escaping html template helper; overview charts use it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WGuzoDhrtWbwJzRAoHufPX
- New information architecture: a four-item rail (Home, Library, Summaries,
  Organize) with every other page in a grouped Settings area
- Home is search-first with the recent stream; counts, 30-day activity and
  type breakdown are secondary and come only from owner aggregates
- Memory and summary details open in a docked side pane beside the list
  (modal sheet on narrow screens); Escape closes it
- Views are pure functions (visuals.mjs) built with the escaping html tag;
  app.mjs is a controller; new icon set (icons.mjs)
- New visual system: three palettes (Graphite, Tundra, Clay) in light and
  dark, all text pairs >= 4.5:1; controls.css replaces layout-polish.css
- Sign-in explains the three trust guarantees instead of decoration
- Business hooks, CSP, CSRF, account isolation and write dialogs unchanged;
  tests updated to the new layout plus docked-pane geometry checks

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WGuzoDhrtWbwJzRAoHufPX
- Restore the full sidebar: My space (4), Connections & settings (6), Platform (2)
- HUD skin (skin-hud.css, decoration only): cut-corner panels, bracket corners,
  tick rulers, route codes MN-01..12, drifting star field and grid, scan line
- Status bar with local time, session state and measured core-link latency
- Overview radar: sectors are real category shares, rim ticks real daily saves
- Palettes Starport / Aurora / Mars; dark by default, light 'white lab' kept;
  all text pairs >= 4.5:1; motion stops under prefers-reduced-motion
- Reserved skins (neon, holo, crt) documented in docs/console-skins.md

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WGuzoDhrtWbwJzRAoHufPX
- New default skin (skin-liquid.css): translucent refracting glass panels with
  iridescent rims and specular highlights, floating sidebar and top bar,
  capsule controls, iridescent nebula, star field and moving horizon grid
- SVG displacement refraction where backdrop-filter url() is supported;
  plain frosted glass elsewhere; solid surfaces under reduced transparency
- New palettes Nebula / Aurora / Corona (dark default, pearl light), all text
  pairs >= 4.5:1; overview hologram, status bar and full menu retained
- Dialogs avoid backdrop-filter so anchored selects keep viewport coordinates;
  the nebula settles in once to avoid per-frame re-blur under glass
- HUD skin kept unbundled as an alternative; docs/console-skins.md updated

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WGuzoDhrtWbwJzRAoHufPX
- One glass material across panels, chrome, controls and lists: blur and
  saturation, top sheen, hairline specular rim, soft shadow, over a still
  low-saturation colour field; no glow, gradient text, stars or grid
- Overview: distribution ring of real category shares with the total in the
  centre; rounded activity bars; harmonious series colours per mode
- Remove the status readout and its polling; system numerals instead of mono
- Sign-in keeps its aurora look via a separate skin-aurora.css layer
- Palettes renamed Glacier / Mint / Rose; dialogs avoid backdrop blur

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WGuzoDhrtWbwJzRAoHufPX
…ign-in

Replace the liquid-glass skins with one light "ink archive" design: paper,
ink and a single seal-red accent, 2px corners and hairline rules.

- Tokens in styles.css; the three themes now pick the accent only
  (vermilion, indigo, pine). The dark-mode switch is removed for now and a
  saved colour mode is ignored.
- Sidebar navigation uses a square-cap line icon set; route codes are gone
  from the sidebar, breadcrumb, headings and overview metrics.
- Remove skin-liquid/aurora/hud and the SVG refraction filter.
- Sign-in pages: two-column layout, no extra notes on the console sign-in,
  a four-step registration progress bar, QR and secret side by side with a
  copy button, a recovery-code warning, and an accent consent button.
- Revoke, retract, disable and cancel actions read as danger; the final
  submit of an operation dialog uses the accent.
- Document the design in docs/console-design.md (replaces console-skins.md)
  and update the console tests and browser checks to the new contract.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… is gone

The memories page renders two display preferences (accent theme, language)
and three library filters.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The public tunnel routes only styles.css and seven console modules. The
workbench rebuild split html.mjs and icons.mjs out of visuals.mjs, so behind
the tunnel both returned 404, the browser module graph failed and every page
stayed on "Loading".

Fold the escaping template tag and the icon set back into visuals.mjs, import
them from there, stop serving the removed modules, and add a test that walks
the browser import graph and checks it against the documented ingress
allowlist.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace the lettered "M" tile with the chosen mark: a seal inside corner
quotes. The quotes cite the source and the seal is the memory kept on
record. It is inline SVG in the sidebar and on the sign-in, registration
and consent pages; the quotes follow --text and the seal follows --accent,
so all three palettes recolour it.

Serve /assets/favicon.svg as image/svg+xml so the page CSP stays
img-src 'self', and add the path to the ingress example. The geometry and
stroke sizes are documented in console-design.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nce page

The Ink Archive style is settled, so the console keeps only the vermilion
palette. Its colours move into :root. The indigo and pine palettes are
removed, along with the theme select in the top bar and on the sign-in
pages, and the appearance settings page (its route, nav entry, view,
styles and strings).

The interface language stays: a compact select in the top bar and on the
sign-in pages, still saved per account. Themes or colour modes saved by
earlier releases are ignored on first paint.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…les after deploy

Build out the console's full menu as a prototype. One feature map
(web/console/visuals.mjs) lists what each of the fifteen pages offers now
and what is planned: 61 features, 34 live, 24 planned and 3 deliberately
not offered on the web. Four new destinations are composed from it:
Projects & tasks (live project list), Resume & handoff, Privacy &
retention (live egress approvals) and System status (live platform
switches and a feature progress table; operators only). Planned features
render as disabled wireframes with developer notes naming the console
view, write action and Core API they will use. Existing pages list their
planned items in a Roadmap card.

docs/console-feature-standard.md is the development standard: ID and
status rules, the steps for new views, actions and pages, UI and security
rules, and the definition of done. console-feature-map.test.mjs keeps the
map, placeholders, server allowlists, catalog and doc in step.

Fixes for problems seen while deploying the single-palette release:
- Version the stylesheet URL by content hash, so a cached stylesheet from
  the previous release (which still needed the removed data-theme
  attribute) cannot leave pages unstyled.
- Count every category in the overview: Core no longer caps the list at
  twelve, and the ring folds everything past the fifth into "Other".
- Summary detail uses the existing end-of-content label; distribution
  legend labels are translatable.
- "/" and Ctrl/Cmd+K no longer leave a form or an unsaved credential.

The four new routes still have to be added to the Cloudflare tunnel rule
(see docs/console-ingress.example.yml).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Fixtures and a few tests enrol with the previous 30-second TOTP step so
later sign-ins can still use the current one. The server accepts one step
either side of its own clock, so a code generated in the last second of a
step and verified just after the boundary is rejected ("MFA
verification"). That failed WEB-MEM-01 on CI during fixture setup. A
shared helper now waits for a fresh step when fewer than two seconds are
left before generating the code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… memories

ChatGPT could read only public memories and per-revision grants. Only one
of the account's fourteen active memories had a grant, so ChatGPT searches
came back empty although every record was indexed and found by its owner.

Add an account-level read policy (memory_web_policy). While read_all is
on, every internal and sensitive record of that account is readable by
the ChatGPT reader, including records added or corrected later. Secret
and unknown classifications stay invisible, and other accounts are
unaffected. The Core console action memory.web_policy is versioned
(expected_revision; conflicts return SETTINGS_VERSION_CHANGED), idempotent
per operation ID, audited, and allowed for basic memory console
credentials. Core capabilities report the current policy.

The console gets a live "ChatGPT read scope" card (PRV-06) on Privacy &
retention, with an explicit confirmation before switching it on, and the
per-memory ChatGPT dialog says when read-all is in effect. Prototype pages
now list live cards first.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ices and key revocation

The Connections page counted only connections created in its own wizard,
so an account connected through the preconfigured ChatGPT client showed
"0 current connections", and its agents appeared only as raw keys in a
collapsed section.

The page now builds one inventory from every real source and counts it:
- ChatGPT on the web: authorizations with their times and scopes, last
  activity (gateway key use or latest token), read scope with a link to
  Privacy & retention, and revoking a single authorization.
- Agents and devices: each agent key (ChatGPT/Codex plugin, OpenClaw,
  Hermes, ...) with access, last use and details; owners can revoke an
  agent instance's keys (devices.revoke).
- Personal connections: the existing wizard list.
- System keys and history: platform-managed keys (console, ChatGPT web
  gateway, admin tools) and revoked or expired keys.

devices.revoke is a Core console action limited to the owner's own
unmanaged keys (never the console, ChatGPT gateway or admin-scoped keys)
and audited as agent_instance.revoke. The BFF requires the current
password and an unused authenticator code, then forwards only the target
instance. Basic console credentials may call it. The Core connections view
reports each key's state, scopes and whether the console may revoke it;
grants carry their authorization time and scopes.

Feature map: CON-03 is live; key registration and rotation move to CON-05
(planned).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…inding

The ChatGPT card always said read-only. It now reads the authorizations:
read-write when a grant includes memory:write, and a separate write-access
line says whether the account's cloud write binding exists and whether a
new ChatGPT authorization is still needed. Counts follow the same rule.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The fixture probes three free ports one after another, closing each probe
listener first, so the OS can offer the same port again. When the auth and
gateway ports collided, the issuer and resource shared one origin and
validation failed ("public origin mode must match issuer/resource"), which
failed HTTP-MGMT-01 on CI during setup. freePort now remembers the ports it
returned and probes again on a repeat.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant