Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
245 commits
Select commit Hold shift + click to select a range
f522526
docs: specify Cloudflare desktop updates
hyf9011 Aug 24, 2026
722096a
docs: plan Sherlock Cloudflare updates
hyf9011 Aug 24, 2026
1774254
feat: make Sherlock update downloads explicit
hyf9011 Aug 24, 2026
bf097bb
release: promote Sherlock development source to 0.6.0
hyf9011 Aug 24, 2026
a26eb0f
fix: sign formal Sherlock disk image
hyf9011 Aug 24, 2026
a9de7ff
fix: refresh signed DMG update metadata
hyf9011 Aug 24, 2026
4c3d684
chore: publish updates from evanarts Cloudflare
hyf9011 Aug 24, 2026
b99a89a
fix: mount updater beside current Harness settings
hyf9011 Aug 24, 2026
328f575
release: bump Sherlock formal update to 0.6.1
hyf9011 Aug 24, 2026
7f6f1a8
fix: keep update control inside sidebar
hyf9011 Aug 24, 2026
6a3a787
release: bump Sherlock formal update to 0.6.2
hyf9011 Aug 24, 2026
8c0e923
fix: align sidebar updater with settings row
hyf9011 Aug 24, 2026
8753b94
fix: keep download icon for ready updates
hyf9011 Aug 24, 2026
06fa7f5
release: bump Sherlock formal update to 0.6.3
hyf9011 Aug 24, 2026
e2898e5
fix: use compact rounded updater button
hyf9011 Aug 24, 2026
c2e9480
fix: set updater button to 28 square
hyf9011 Aug 24, 2026
e77b170
docs: record Sherlock formal release workflow
hyf9011 Aug 25, 2026
1cbb47f
release: publish Sherlock 0.6.6
hyf9011 Aug 25, 2026
1d9c84c
docs: design research canvas file drops
hyf9011 Aug 25, 2026
7a3be3e
docs: plan research canvas file drops
hyf9011 Aug 25, 2026
a8b9794
feat: add research canvas navigation
hyf9011 Aug 25, 2026
1a88a70
chore: ignore local worktrees
hyf9011 Aug 25, 2026
3c2f169
feat: expose safe research file paths
hyf9011 Aug 25, 2026
7d0a6ec
feat: add research canvas file drop model
hyf9011 Aug 25, 2026
9c68077
fix: bound research canvas file payloads
hyf9011 Aug 25, 2026
eb72565
feat: render persistent research file cards
hyf9011 Aug 25, 2026
fbc03f6
feat: drag files from Sherlock details
hyf9011 Aug 25, 2026
0e8371e
test: verify research canvas file drops
hyf9011 Aug 25, 2026
500d801
fix: open details when inspecting tool calls
hyf9011 Aug 25, 2026
b0bd6f5
fix: route research file drops before composer
hyf9011 Aug 25, 2026
918bd0e
fix: release research drops from file plugin capture
hyf9011 Aug 25, 2026
4857655
fix: bound research canvas file model
hyf9011 Aug 25, 2026
9f27d5e
fix: harden file drop compatibility mutation
hyf9011 Aug 25, 2026
d784ae4
fix: bound research FileList traversal
hyf9011 Aug 25, 2026
1da39d5
release: publish Sherlock 0.6.8
hyf9011 Aug 25, 2026
c26a05a
release: publish Sherlock 0.7.0
hyf9011 Aug 25, 2026
693c529
docs: design zero-cost cross-model web search
hyf9011 Aug 26, 2026
117803f
feat: group conversation execution details
hyf9011 Aug 26, 2026
9dc452b
feat: add zero-cost cross-model web search
hyf9011 Aug 26, 2026
2158c7e
fix: resolve bundled packages for fresh profiles
hyf9011 Aug 26, 2026
0b74d96
docs: design Sherlock Harness preview
hyf9011 Aug 26, 2026
34a1cad
docs: plan Sherlock Harness preview
hyf9011 Aug 26, 2026
043bad3
修复:同步内置 Skill 版本并建立正式构建 Git 门禁
hyf9011 Aug 26, 2026
388a4f2
修复:支持大型工作树状态的正式构建检查
hyf9011 Aug 26, 2026
bc2e376
合并:统一 Sherlock 0.7.0 正式版与主分支修复
hyf9011 Aug 26, 2026
29d2808
发布:准备 Sherlock 0.7.1 正式版
hyf9011 Aug 26, 2026
086569f
修复:阻止启动缺少内置 Node 的构建
hyf9011 Aug 26, 2026
75a01c7
流程:固化 Sherlock 本地免公证测试构建
hyf9011 Aug 26, 2026
93d8163
修复:优化文件读取与空目录搜索提示
hyf9011 Aug 26, 2026
c061e5f
优化:完善更新交互与多模态模型配置
hyf9011 Aug 26, 2026
3e2045d
文档:完善研究画布与右侧对话设计
hyf9011 Aug 26, 2026
85332eb
文档:制定研究工作区开发计划
hyf9011 Aug 26, 2026
e7c1e08
功能:建立研究画布会话状态模型
hyf9011 Aug 26, 2026
dcb1c8d
修复:校准研究画布模型边界
hyf9011 Aug 26, 2026
0ded63f
功能:支持研究画布框选与成组拖动
hyf9011 Aug 26, 2026
9f2fcc3
修复:校验画布拖拽并延迟持久化
hyf9011 Aug 26, 2026
f0aa03f
功能:将研究对话固定到右侧栏
hyf9011 Aug 26, 2026
bcdb13d
功能:发送研究画布所选文件附件
hyf9011 Aug 26, 2026
40a9e12
修复:防止研究发送失败误恢复草稿
hyf9011 Aug 26, 2026
3480e79
功能:将助手结果按需加入研究画布
hyf9011 Aug 26, 2026
f326be3
修复:收紧研究画布助手产物边界
hyf9011 Aug 26, 2026
6d94b4a
验证:完成研究工作区本地构建检查
hyf9011 Aug 26, 2026
e2d6a21
修复:清理研究会话临时状态并支持键盘选择
hyf9011 Aug 26, 2026
347153c
修复:隔离非研究状态并限制画布操作入口
hyf9011 Aug 26, 2026
2bfbec6
功能:统一研究右栏并完善画布文件操作
hyf9011 Aug 26, 2026
616850b
修复:统一研究输入框与附件标签样式
hyf9011 Aug 27, 2026
39d38f5
优化:研究文件内联标签与提示定位
hyf9011 Aug 27, 2026
4e5e6f0
修复:研究输入菜单汉化与弹层裁切
hyf9011 Aug 27, 2026
986fbf3
修复研究浮层定位与文件标签样式
hyf9011 Aug 27, 2026
c7b87de
修复浅色模式标签与对话气泡配色
hyf9011 Aug 27, 2026
af710f8
升级至0.7.3并移除Memory Evolve
hyf9011 Aug 27, 2026
5a64b6b
移除记忆插件并完善研究对话显示
hyf9011 Aug 27, 2026
4fb766b
修复输入框布局与加载状态回退
hyf9011 Aug 27, 2026
d2aa84d
支持文件拖入研究画布和标签键盘删除
hyf9011 Aug 27, 2026
91cd0d5
记录研究画布可视组件设计
hyf9011 Aug 27, 2026
ed6c865
制定研究画布可视组件开发计划
hyf9011 Aug 27, 2026
a3f49dc
同步现有研究功能依赖补丁
hyf9011 Aug 27, 2026
fafbb27
修复输入框标签底部遮挡
hyf9011 Aug 27, 2026
f4750cf
补充输入框真实依赖渲染回归
hyf9011 Aug 27, 2026
95441af
加固画布预览的框架权限边界
hyf9011 Aug 27, 2026
636b025
修复输入框回归测试类型收窄
hyf9011 Aug 27, 2026
02f21dc
阻止预览子框架逃逸并验证特权通信
hyf9011 Aug 27, 2026
2197695
收紧预览导航并实测生产通信边界
hyf9011 Aug 27, 2026
6806e63
支持研究文件安全预览协议
hyf9011 Aug 27, 2026
a31b732
修复研究预览撤销与跨源访问
hyf9011 Aug 27, 2026
8c58a84
拒绝无可信窗口的研究预览
hyf9011 Aug 27, 2026
1a3e2d0
支持研究画布组件拖角缩放
hyf9011 Aug 27, 2026
5be76db
修复研究画布比例约束与尺寸保留
hyf9011 Aug 27, 2026
251fbbc
完善研究画布消息与图片组件
hyf9011 Aug 27, 2026
167efea
修复研究预览授权与拖入生命周期
hyf9011 Aug 27, 2026
2747c05
修复研究预览撤销竞态与重试
hyf9011 Aug 27, 2026
3997fbf
修复研究预览持久存储与资源上限
hyf9011 Aug 27, 2026
94c32f8
修复研究预览跨挂载授权日志
hyf9011 Aug 27, 2026
9750929
修复研究预览持久提交判定
hyf9011 Aug 27, 2026
b3bdca2
确认研究画布消息与图片组件完成
hyf9011 Aug 27, 2026
2c64c9a
支持画布PDF与HTML内容预览
hyf9011 Aug 27, 2026
ebf6de9
修复PDF预览资源与布局边界
hyf9011 Aug 27, 2026
1842114
修复PDF预览二维内容适配
hyf9011 Aug 27, 2026
250d9f2
修复PDF预览重入测量状态
hyf9011 Aug 27, 2026
dccb069
确认PDF与HTML画布预览完成
hyf9011 Aug 27, 2026
fbf31ab
更新主窗口可信事件回归断言
hyf9011 Aug 27, 2026
1b4ab69
完成研究画布可视组件实机验收
hyf9011 Aug 27, 2026
24c8421
记录研究画布预览扩展方案
hyf9011 Aug 28, 2026
ec10150
持久保存每个对话的模型选择
hyf9011 Aug 28, 2026
1543513
修复模型默认回退与持久化路由
hyf9011 Aug 28, 2026
ed52f23
补充右侧输入菜单层级修复方案
hyf9011 Aug 28, 2026
c5d7fc2
完善画布网页组件交互与资源加载
hyf9011 Aug 28, 2026
332d203
修复网页预览大 JSON 校验
hyf9011 Aug 28, 2026
9f3a2d8
改为连续滚动画布PDF预览
hyf9011 Aug 28, 2026
457cb1e
修复混合尺寸PDF页流布局
hyf9011 Aug 28, 2026
50894a2
补齐画布原生文件预览
hyf9011 Aug 28, 2026
89bb094
收紧原生预览校验与读取生命周期
hyf9011 Aug 28, 2026
10cfeac
复用Office插件支持画布预览
hyf9011 Aug 28, 2026
235abac
修复Office预览异步隔离与校验边界
hyf9011 Aug 28, 2026
437cfb9
支持画布组件改名并同步附件标签
hyf9011 Aug 28, 2026
ef6bf23
补强Office补丁完整性与PPT滚动兼容
hyf9011 Aug 28, 2026
c8e9f1b
修复附件改名的撤销历史同步
hyf9011 Aug 28, 2026
4b440d1
补齐附件引用更新的类型声明
hyf9011 Aug 28, 2026
0ff8181
修复画布组件上的缩放与边框层级
hyf9011 Aug 28, 2026
1afc0a5
补强画布缩放桥接与离开状态
hyf9011 Aug 28, 2026
f4ca429
改用私有端口加固画布缩放桥接
hyf9011 Aug 28, 2026
cf754b8
改用原生滚轮事件缩放研究画布
hyf9011 Aug 28, 2026
9b34415
修复输入菜单层级并移除外围遮罩
hyf9011 Aug 28, 2026
9a4e8a9
阻止网页预览脚本唤起外部浏览器
hyf9011 Aug 28, 2026
93d5b31
修复长PDF渐进预览阻塞
hyf9011 Aug 28, 2026
ec26ff2
校验Office预览压缩包真实展开内容
hyf9011 Aug 28, 2026
3b9081b
补充画布手势与输入菜单验收计划
hyf9011 Aug 28, 2026
40b29f4
修复旧会话模型与底部布局回归
hyf9011 Aug 28, 2026
30e5e81
补全浮动输入框交互与滚动留白
hyf9011 Aug 28, 2026
7a49576
修复面板变高时对话末尾跟随
hyf9011 Aug 28, 2026
1c99168
修复轨迹页输入框后的黑色留白
hyf9011 Aug 28, 2026
7661bb1
更新 Sherlock 0.7.3 正式版说明
hyf9011 Aug 28, 2026
f55d9d9
发布:记录 Sherlock 0.7.3 正式版资源
hyf9011 Aug 28, 2026
93a5960
文档:制定多会话功能集成与版本治理方案
hyf9011 Aug 31, 2026
d7e6883
计划:拆分 Sherlock 多会话治理实施步骤
hyf9011 Aug 31, 2026
77fdc81
重构:统一 Sherlock Git 仓库状态检查
hyf9011 Aug 31, 2026
c6b6557
修复:收紧 Sherlock Git 状态边界
hyf9011 Aug 31, 2026
4109cb4
修复 Sherlock Agent 品牌与消息顺序
hyf9011 Aug 31, 2026
9babe0f
工具:增加功能会话提交交接卡
hyf9011 Aug 31, 2026
7fc1368
发布:更新 Sherlock 客户端至 0.7.4
hyf9011 Aug 31, 2026
f68a4f6
修复:收紧功能交接卡信任边界
hyf9011 Aug 31, 2026
f215d36
修复:拒绝无评分重命名状态
hyf9011 Aug 31, 2026
a597312
修复:避免退出时访问已销毁窗口
hyf9011 Aug 31, 2026
c1e2e95
工具:增加集成批次清单与只读预检
hyf9011 Aug 31, 2026
bda3727
修复:补齐集成预检阶段门禁
hyf9011 Aug 31, 2026
35207e5
修复:验证批次已合并证据
hyf9011 Aug 31, 2026
7e28afb
工具:增加单一集成批次租约
hyf9011 Aug 31, 2026
b1aa2b0
修复:防止租约归档竞态覆盖
hyf9011 Aug 31, 2026
cfc43da
修复:以独占目录安全归档租约
hyf9011 Aug 31, 2026
ca293ac
工具:增加集成批次创建与接管
hyf9011 Aug 31, 2026
0004e9b
修复:保留批次创建竞态现场
hyf9011 Aug 31, 2026
903f902
优化研究引用与权限菜单交互
hyf9011 Aug 31, 2026
d3f5d8a
集成:按完整功能历史合并并支持恢复
hyf9011 Aug 31, 2026
d41082e
修复研究标签显示与组件选中抖动
hyf9011 Aug 31, 2026
98d5f66
修复:补齐合并中断恢复状态
hyf9011 Aug 31, 2026
14fcb8d
集成:增加验收绑定与主分支安全推进
hyf9011 Aug 31, 2026
dfa183a
修复:补齐主分支晋升确认与恢复
hyf9011 Aug 31, 2026
bce148d
完善研究输入框自适应与回复内容编辑
hyf9011 Aug 31, 2026
432a405
构建:增加共享客户端来源门禁
hyf9011 Aug 31, 2026
b0d7848
文档:落地 Sherlock 多会话集成规范
hyf9011 Aug 31, 2026
61585d4
修复:校准集成运行手册与退出码契约
hyf9011 Aug 31, 2026
37f0683
修复研究输入标签遮挡光标
hyf9011 Aug 31, 2026
aeaed55
修复研究输入标签间光标定位
hyf9011 Aug 31, 2026
159f6cc
集成:创建批次 20260831-02
hyf9011 Aug 31, 2026
06f1934
集成:合并功能 codex/feat/session-integration-controls-20260831
hyf9011 Aug 31, 2026
0407462
集成:记录功能 codex/feat/session-integration-controls-20260831 合并验证
hyf9011 Aug 31, 2026
ea7c459
发布:补充 Sherlock 0.7.4 更新日志
hyf9011 Aug 31, 2026
99e6a7e
优化:统一对话与研究文件标签
hyf9011 Aug 31, 2026
19816ce
修复:优化拖入文件标签交互
hyf9011 Aug 31, 2026
bc8ce12
修复:保持文件标签选中状态
hyf9011 Aug 31, 2026
eef8b74
优化:扩展研究画布缩放与内容回位
hyf9011 Aug 31, 2026
6c76294
优化:增加克制的 Sherlock 启动动画
hyf9011 Aug 31, 2026
8d7cf38
优化:研究组件标签分阶段确认
hyf9011 Aug 31, 2026
6e0fdb0
发布:准备 Sherlock 0.7.5 正式版
hyf9011 Aug 31, 2026
e3f3a65
功能:新增对话与研究快捷入口
hyf9011 Aug 31, 2026
c3b49af
修复:完善新研究首屏与PDF预览
hyf9011 Aug 31, 2026
c9ade3a
优化:完善空研究引导与回复卡片布局
hyf9011 Aug 31, 2026
8fb4f2f
修复:统一空白会话输入区控制布局
hyf9011 Aug 31, 2026
5ad60d8
修复:新研究可切回新对话
hyf9011 Aug 31, 2026
442bbf7
修复:兼容含大尺寸视频的PPT预览
hyf9011 Aug 31, 2026
92ffca4
修复:侧边栏展开后自动聚焦搜索框
hyf9011 Aug 31, 2026
420595a
功能:新增研究画布选中内容生成工具栏
hyf9011 Aug 31, 2026
b283627
验证:记录研究组件生成工具栏实机设计验收
hyf9011 Aug 31, 2026
73f17a0
功能:完善研究画布思维导图生成模式
hyf9011 Sep 1, 2026
b2eef02
修正:限制简要思维导图节点密度
hyf9011 Sep 1, 2026
96c8c05
修正:优化思维导图组件框与横向布局
hyf9011 Sep 1, 2026
015755a
修正:重建研究画布依赖补丁
hyf9011 Sep 1, 2026
415f916
修正:统一思维导图组件顶栏样式
hyf9011 Sep 1, 2026
56a0109
文档:记录思维导图顶栏视觉复核
hyf9011 Sep 1, 2026
8326e6c
修复:连接复杂思维导图根节点
hyf9011 Sep 1, 2026
87348b3
文档:记录复杂导图连线与搜索焦点复核
hyf9011 Sep 1, 2026
c17fc5d
修复:允许未激活窗口首次点击搜索
hyf9011 Sep 1, 2026
eadd945
修复:显示侧栏搜索框并优化导图文字排版
hyf9011 Sep 1, 2026
1b04dcf
设计:画布生成任务独立并发执行
hyf9011 Sep 1, 2026
f412e89
文档:明确排队任务子会话标识可选
hyf9011 Sep 1, 2026
4841258
计划:拆解画布独立生成任务实施步骤
hyf9011 Sep 1, 2026
de5ba62
功能:定义画布生成任务服务契约
hyf9011 Sep 1, 2026
42acef4
功能:支持画布任务四路并发调度
hyf9011 Sep 1, 2026
33b8f7d
功能:接入画布子任务运行与恢复服务
hyf9011 Sep 1, 2026
51d4a34
构建:打包画布生成任务运行服务
hyf9011 Sep 1, 2026
5f9a327
修复:确保画布任务终态可被客户端接收
hyf9011 Sep 1, 2026
19fd103
功能:在画布组件内并发执行生成任务
hyf9011 Sep 1, 2026
a7bc2d2
修复:启动画布任务并持续同步状态
hyf9011 Sep 1, 2026
e954325
修复:通过宿主会话解析器启动画布任务
hyf9011 Sep 1, 2026
84bf22c
修复:隔离画布任务的外部工具能力
hyf9011 Sep 1, 2026
85829a0
优化:紧凑显示已发送的引用标签
hyf9011 Sep 1, 2026
5590be1
修复:回收文件生成结果并紧凑排列引用标签
hyf9011 Sep 1, 2026
bed9fa3
完善:研究标签显示类型图标并支持画布定位
hyf9011 Sep 1, 2026
3d3a26c
修复:支持从PPT组件生成思维导图
hyf9011 Sep 1, 2026
925d7f7
功能:支持编辑思维导图节点并统一短语对齐
hyf9011 Sep 1, 2026
173797b
功能:支持整理画布并全选全部组件
hyf9011 Sep 1, 2026
2e480a2
功能:支持编辑总结提炼内容
hyf9011 Sep 1, 2026
aa1a554
文档:规划研究画布全局功能栏
hyf9011 Sep 1, 2026
a9dea0f
功能:建立研究网页组件安全边界
hyf9011 Sep 1, 2026
4e73b38
功能:支持智能容器独立生成任务
hyf9011 Sep 1, 2026
2d2c73f
功能:新增研究画布链接与智能容器
hyf9011 Sep 1, 2026
853dd68
构建:设置本地测试版版本为 0.7.6
hyf9011 Sep 1, 2026
dc4de5c
修复:规范化链接组件中的网址空格
hyf9011 Sep 1, 2026
2c62f89
设计:明确研究组件标题自适应与下载方案
hyf9011 Sep 1, 2026
a902791
设计:补充微信文章安全阅读视图
hyf9011 Sep 1, 2026
4b5ae8a
计划:拆分研究网页体验与组件下载实施
hyf9011 Sep 1, 2026
f42136e
功能:新增微信文章安全阅读服务
hyf9011 Sep 1, 2026
e9fe95e
功能:扩展研究网页检查与阅读桥
hyf9011 Sep 1, 2026
413267f
功能:持久化网页标题并计算自适应布局
hyf9011 Sep 1, 2026
93cb88e
修复:自适应展示网页并错开画布底栏
hyf9011 Sep 1, 2026
6258cdc
功能:新增研究组件安全下载服务
hyf9011 Sep 1, 2026
ea7cf02
功能:按组件类型生成下载描述
hyf9011 Sep 1, 2026
4b4903d
功能:思维导图支持矢量与图片下载
hyf9011 Sep 1, 2026
9d1a704
功能:所有研究组件增加下载入口
hyf9011 Sep 1, 2026
803f046
修复:原生生成监控容器并读取微信正文
hyf9011 Sep 1, 2026
a21da56
优化:缩小画布底栏并放宽缩放下限
hyf9011 Sep 1, 2026
56c60e1
优化:整理画布改为内容自适应混合平铺
hyf9011 Sep 1, 2026
5cf401c
修复:恢复链接读取与智能容器生成
hyf9011 Sep 1, 2026
2293083
修复:补齐微信文章组件读取授权
hyf9011 Sep 1, 2026
9de649c
修复:消除微信链接组件读取竞态
hyf9011 Sep 1, 2026
15b26ae
集成:创建批次 20260902-01
hyf9011 Sep 1, 2026
0eda551
集成:合并功能 codex/feat/research-selection-actions-20260831
hyf9011 Sep 1, 2026
8a81252
集成:记录功能 codex/feat/research-selection-actions-20260831 合并验证
hyf9011 Sep 1, 2026
5b1373b
修复:确保依赖补丁可重复安装
hyf9011 Sep 1, 2026
241f5c6
集成:创建批次 20260902-02
hyf9011 Sep 1, 2026
8b327b9
集成:合并功能 codex/feat/research-selection-actions-qa-20260831
hyf9011 Sep 1, 2026
b3c11dc
集成:记录功能 codex/feat/research-selection-actions-qa-20260831 合并验证
hyf9011 Sep 1, 2026
190a3b3
修复:忽略已取消的历史集成批次
hyf9011 Sep 1, 2026
f93b8b9
发布:更新 Sherlock 0.7.6 更新日志
hyf9011 Sep 1, 2026
011f0ea
发布:记录 Sherlock 0.7.6 正式发布结果
hyf9011 Sep 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
11 changes: 11 additions & 0 deletions .codex/environments/environment.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# THIS IS AUTOGENERATED. DO NOT EDIT MANUALLY
version = 1
name = "Sherlock Desktop"

[setup]
script = ""

[[actions]]
name = "Run"
icon = "run"
command = "./script/build_and_run.sh"
23 changes: 23 additions & 0 deletions .githooks/commit-msg
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
#!/bin/sh

set -eu

message_file="$1"
node - "$message_file" <<'NODE'
const fs = require('node:fs')

const messagePath = process.argv[2]
const message = fs
.readFileSync(messagePath, 'utf8')
.split(/\r?\n/)
.filter((line) => !line.trimStart().startsWith('#'))
.join('\n')
.trim()

if (!/[\u3400-\u9fff\uf900-\ufaff]/u.test(message)) {
process.stderr.write(
'提交信息必须包含中文说明,例如:修复:确保正式版使用最新内置 Skill。\n'
)
process.exit(1)
}
NODE
198 changes: 89 additions & 109 deletions .github/workflows/release.yml

Large diffs are not rendered by default.

10 changes: 9 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,15 +2,23 @@ node_modules/
out/
dist/
dist-dev/
dist-legacy/
dist-notarized/
dist-release/
release-assets/
release-cloudflare/
.playwright-cli/
artifacts/
.DS_Store
*.log
coverage/
build/icon.iconset/
build/app-icon.iconset/
build/icon-1024.png
build/sherlock-plugin-profile/
.env
.env.*
!.env.example
.coaligne/
.coaligneignore

.worktrees/

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,130 @@
# Task 3 实施报告:研究文件安全预览协议

## Status

- 已完成 Task 3 的主进程持久授权表、短期 capability、只读预览协议、Finder/sidebar 窄 admission bridge 和显式撤销接口。
- 当前版本保持 `0.7.3`;未发布、未改公开更新源,也未运行全量测试。
- 本任务的本地提交信息为:`支持研究文件安全预览协议`。

## 现有契约与接口选择

- Better Sidebar 的 renderer 拖拽 `{ path, name }` 可伪造,既有 `/sidebar/file` 仅做 lexical containment,因此没有复用它作为预览授权凭据。
- sidebar admission 固定为 `{ sessionId, nodeId, relativePath }`。主进程从 `${userData}/harness/storages/workspace.json` 反查 session 对应的权威 workspace root,再对 root 和目标执行 `realpath` 与分隔符安全的 containment 检查;renderer 不能提交 root 或绝对路径。
- Finder admission 在 preload 内对真实 `File` 调用 `webUtils.getPathForFile`。空路径或合成 File 不触发 IPC;renderer 得到的仅是 `{ authorizationId, url, contentType, name }` descriptor。
- renderer 可持久化的画布 JSON 只需要保留 opaque `authorizationId`。重启恢复必须同时匹配主进程持久记录中的 `(sessionId, nodeId)`,不会采用 renderer 写入的 path。
- 既有 `dshDesktop.getPathForFile(File)` 暂时只为当前附件发送/Finder drop 兼容保留;新的 preview capability 不读取其返回值,也没有 `read(path)` 或 `admitFinderPath`。Task 5 在 rich-node consumer 完成迁移并建立回归后再删除或收窄该 legacy 方法。

## Implementation

- 新增 `src/main/state/research-file-preview.ts`:
- `${userData}/research-file-preview/authorizations.v1.json` 下的有界 JSON 授权存储,原子 temp/rename 写入,文件权限 `0600`;持久数据不含 capability token。
- Finder 与 sidebar admission、重启 reissue、authorization/node/session revoke,以及短期 token 过期处理。
- `sherlock-preview://<opaque-token>/...` 的 GET/HEAD handler;支持 200、单 Range 206、无效/多 Range 416,并返回准确 `Content-Length`、`Content-Range`、MIME。
- 图片、SVG、PDF、HTML 及 HTML 相对 CSS/图片/脚本的扩展名与 magic 检查;每次请求重新 `realpath`,阻止 `..`、encoded slash/backslash/NUL 和 symlink escape。
- `Cache-Control: no-store`、`X-Content-Type-Options: nosniff`、`Referrer-Policy: no-referrer` 与阻断网络、子 frame、对象、表单、base URL 的 CSP。Task 2 安全门虽然已经通过,但脚本执行仍由后续 Task 6 在 sandbox iframe 接线时显式开放;当前静态 HTML 为 fail-closed。
- `src/main/index.ts` 在 app ready 前注册 privileged scheme,在 ready 后、`createWindow()` 前安装 `protocol.handle`,且未把 `sherlock-preview:` 加入 `isTrustedAppUrl`。
- 新增 preload helper,所有新 preview API 只在已有 `process.isMainFrame` 分支内暴露;主进程 IPC 复用 Task 2 的 trusted main-frame 校验。

## TDD Evidence

### RED

先创建 `test/research-file-preview.test.ts` 并扩展 `test/research-file-drop.test.ts`,随后运行:

```text
npm test -- --run test/research-file-preview.test.ts test/research-file-drop.test.ts
```

预期失败原因:生产模块 `../src/main/state/research-file-preview` 尚不存在,同时 preload 尚无 `researchPreview` descriptor bridge;既有 Research drop 测试仍为绿色。这确认失败来自缺失的新行为,而非既有回归。

自审阶段又先增加 HTML 顶层预览可被 sandbox iframe 装载的 CSP 行为断言;它因 CSP 含 `frame-ancestors 'none'` 得到 RED,随后删除该会阻断预览组件自身嵌入的 directive,并保留 `frame-src 'none'` 来阻止预览内容继续嵌套页面。

### GREEN

```text
npm test -- --run test/research-file-preview.test.ts test/research-file-drop.test.ts
Test Files 2 passed (2)
Tests 63 passed (63)
```

覆盖 Finder/sidebar admission、主进程 workspace identity、持久恢复、token 过期/撤销、GET/HEAD、开区间/后缀 Range、416、多 Range 拒绝、MIME/magic、HTML 子资源、encoded traversal、symlink escape、真实生产 IPC handler 的 trusted-main-frame 行为,以及 synthetic File 零 IPC。

直接受影响的 Task 2 安全边界回归:

```text
npm test -- --run test/preload-main-frame.test.ts test/security.test.ts test/ipc-trust.test.ts
Test Files 3 passed (3)
Tests 11 passed (11)
```

## Typecheck and hygiene

```text
npm run typecheck
> tsc --noEmit -p tsconfig.node.json
exit 0

git diff --check
exit 0
```

## Risks / follow-up boundary

- Task 3 只生产安全 preview descriptor 与协议。Task 5/6 才会让 rich canvas node 消费 descriptor、在节点删除/session 切换时调用 revoke,并完成图片/PDF/HTML 的真实组件接线。
- 当前 HTML 脚本由 CSP 禁用;Task 6 必须同时用 sandbox iframe(无 `allow-same-origin`、表单、popup、下载、top navigation)及既有 Task 2 frame/IPC 测试来证明可安全开放本 capability 下的脚本。
- 最终 packaged app 与真实画布交互验证属于 Task 7;本任务按计划只执行聚焦测试、类型检查与 diff 检查。

## Review fix round 1/5

### 撤销事务性

评审指出 `revokeAuthorization`、`revokeNode`、`revokeSession` 原先会先删除内存授权和 capability,再忽略 `storage.save(false)` 并返回成功。这会让旧磁盘授权在重启后复活,同时误导调用方撤销已经持久化。

先增加三组表驱动行为测试,在可控存储拒绝写入时得到 RED:三种入口都返回了 `true`,而测试要求 `false`。实现改为先构造保留授权候选集合,只有 `storage.save` 成功后才提交内存删除与 token 撤销。失败时内存、旧 token 和磁盘记录全部保持一致;写入恢复后再次撤销成功,重启也无法 restore。

### 动态主窗口 Origin 与 Chromium CORS

评审确认 `corsEnabled/supportFetchAPI` 本身不足以让 Task 6 的 PDF.js 从动态 Harness origin 跨源 fetch。先增加真实 registry + production protocol wrapper 行为测试,得到 RED:`handleResearchFilePreviewProtocolRequest` 尚不存在。

实现后的 protocol wrapper 每次请求都从当前 `mainWindow.webContents.getURL()` 解析 origin,并复用可信应用 URL 策略,仅接受实际 `http://127.0.0.1:<port>` 或 `http://localhost:<port>` origin。renderer 无法传入 allowed origin。带 Origin 的合法请求精确回显:

- `Access-Control-Allow-Origin: <当前精确 origin>`;
- `Vary: Origin`;
- `Access-Control-Expose-Headers: Accept-Ranges, Content-Length, Content-Range, Content-Type`。

错误端口、外部 origin 或当前窗口不是可信 Harness HTTP URL 时,在任何 `realpath/stat/read/stream` 前返回 403,且不返回 ACAO。无 Origin 的 image/iframe navigation 保持原 capability 语义。另窄支持 OPTIONS,只接受 GET/HEAD 与 `Range` 请求头,并返回相同精确 origin、`Access-Control-Allow-Headers: Range` 和允许方法。

本轮 GREEN:

```text
npm test -- --run test/research-file-preview.test.ts test/research-file-drop.test.ts
Test Files 2 passed (2)
Tests 68 passed (68)

npm test -- --run test/preload-main-frame.test.ts test/security.test.ts test/ipc-trust.test.ts
Test Files 3 passed (3)
Tests 11 passed (11)

npm run typecheck
> tsc --noEmit -p tsconfig.node.json
exit 0
```

当前仓库没有小型 Electron/Chromium CORS 集成 harness,因此本轮用真实 service、真实文件访问和生产 origin wrapper 验证边界;Task 7 仍需在本地构建的真实 Sherlock 中用 PDF.js 验证动态端口的 Range fetch。

## Review fix round 2/5

评审继续验证发现:round 1 的 `researchPreviewOriginForWindow()` 会对缺失、已销毁或非可信 URL 的窗口返回 `null`,但 production wrapper 仍把 `null` 交给 registry;无 Origin 导航因此绕过 CORS 分支并读取文件。

先新增六组零读取回归,覆盖:

- main window 缺失;
- main window 已销毁;
- 外部 HTTP URL;
- `file:` URL;
- `dsh-recovery:` URL;
- loopback HTTPS 等其他非 Harness HTTP URL。

GET 与 HEAD 均有覆盖。RED 时六组都实际返回 200;修复后 production wrapper 在无法取得可信 Harness HTTP origin 时直接返回 403,完全不会进入 registry,因此 capability/path 与注入 filesystem 的 `realpath/stat/readSlice/stream` 调用数均为 0。可信窗口下无 Origin 的 image/iframe navigation 仍由已有测试保持为 200。

本轮提交信息:`拒绝无可信窗口的研究预览`。
Original file line number Diff line number Diff line change
@@ -0,0 +1,145 @@
# Task 4 report — persistent canvas geometry and corner resize

## Status

Implemented one normalized geometry model for Research canvas nodes, persisted
the normalized shape, replaced fixed hit rectangles with real node dimensions,
and added four-corner resize behavior to the installed conversation renderer.
No composer, sidebar, version, update-feed, or release code was changed.

## RED

The first focused run was made after adding pure and mounted-renderer tests and
before changing the installed dependency:

```text
Test Files 2 failed (2)
Tests 10 failed | 120 passed (130)
```

The failures were the intended missing behavior: no exported geometry
normalizer or resize helper, viewport rectangles still fixed at 220 x 64,
legacy JSON lacked normalized sizes, and the mounted real `ResearchCanvas`
rendered no handles, preview shield, or live resize operation.

A second narrow RED cycle covered preview wheel ownership. The mounted real
rich preview body bubbled into the canvas wheel listener and produced
`defaultPrevented: true`; after the ownership guard it remained unprevented and
the viewport stayed unchanged.

## Geometry policy

All values are world units. `x` and `y` remain node centers.

| Kind | Default | Minimum | Aspect behavior |
|---|---:|---:|---|
| Generic unsupported file | 220 x 64 | fixed | not resizable; no handles |
| Assistant artifact | 360 x 240 | 240 x 120 | free; 240 is the Task 4 safe auto-height placeholder |
| Image / SVG | 320 x 272 | 160 x 152 | 4:3 content plus 32 title pixels |
| PDF | 320 x 446.117647 | 240 x 342.588235 | 17:22 page content plus 32 title pixels |
| HTML | 480 x 360 | 320 x 240 | free |

The shared title bar is 32 px. The shared maximum is 2400 x 2400. Image and
PDF `aspectRatio` applies only to content height, never to the title bar.
Persisted natural ratios are admitted only when finite and between 0.25 and 8,
then narrowed to the type's feasible range under both its minimum dimensions
and the 2400 x 2400 ceiling. Invalid, non-finite, and negative sizes fall back
to the kind default; finite sizes are clamped. Legacy nodes normalize on load
and are repaired on the next workspace persistence write.

Rich-kind detection is centralized: supported `image/*` and known image/SVG
extensions map to image, PDF MIME/extension maps to PDF, HTML/XHTML
MIME/extension maps to HTML, supported assistant artifact kinds map to
assistant, and everything else maps to generic.

## Interaction semantics

- Space-pan is checked first, including pointer-down over a resize handle or an
interactive preview body.
- A selected rich node renders NW, NE, SW, and SE handles. A generic node never
renders handles.
- Resize precedes normal card movement and changes only the operated node, even
when a group is selected.
- Pointer screen deltas are divided by canvas scale. The actual clamped size
delta shifts the center by half, keeping the opposite corner fixed.
- Assistant and HTML resize freely. Image and PDF resize proportionally using
their content ratio.
- Live move/resize publishes in-memory geometry without storage writes.
Pointer-up, pointer-cancel, window blur, and unmount each persist once.
- The title/noninteractive frame remains the move surface; marked rich preview
bodies own pointer and wheel interaction.
- Rich nodes always contain a real preview shield layer. Space-pan, node move,
and resize activate it through root interaction state so Task 6 iframes
cannot steal an active pointer. No generic card or fake iframe was used in
the rendered tests.
- Existing selection, group move, marquee, Delete, and context deletion paths
remain exercised by the focused mounted-renderer suite.

## Patch evidence

The installed dependency was regenerated with:

```text
npx patch-package @deepseek-ai/dsh-client-ui-conversation
✔ Created file patches/@deepseek-ai+dsh-client-ui-conversation+0.1.0-rc.7.patch
```

The regenerated full patch still contains the approved shared InputBar
`padding-bottom: 8px` replacement and the previous Research implementation,
plus the new normalizer, resize helper, shared rich frame, handles, shield, and
pointer operation branches. `git apply --check --reverse` succeeds against the
installed tree.

No `.d.ts` file was changed: the package's public declaration index does not
declare the existing Research runtime/testing exports, and Task 4 did not
change a consumed TypeScript contract.

## Review fix round 1

Review identified two important boundary defects and both received a separate
RED/GREEN cycle:

1. An admitted wide image ratio of 8 previously normalized 160 x 52, violating
the image policy's 160 x 152 minimum. A new pure regression failed with that
exact result. Normalization and resize now share constraints whose minimum
width is `max(type minWidth, (type minHeight - titleHeight) * ratio)` and
whose maximum width accounts for both global width and content-height
ceilings. The regression now yields 960 x 152; a 0.25 ratio also remains at
least 160 x 672. Ratios are narrowed further only when the type minima and
global maxima otherwise have no feasible intersection.
2. Repositioning a deduplicated assistant artifact rebuilt it without geometry,
resetting 720 x 480 manual state to 360 x 240 auto. A new pure regression
failed with that reset. The found-node branch now retains its canonical
persisted width, height, size mode, and applicable aspect ratio while still
updating title, content, and center position.

The review-fix RED was `2 failed | 58 passed` in
`test/research-file-drop.test.ts`; its immediate GREEN was `60 passed`.

## GREEN and verification

Final evidence is recorded from fresh runs immediately before commit:

- `npm test -- --run test/research-file-drop.test.ts test/sherlock-composer-workspace-ui.test.ts`
— 2 files, 132 tests passed.
- `npm run typecheck` — exit 0.
- `git diff --check` — exit 0.
- `git apply --check --reverse patches/@deepseek-ai+dsh-client-ui-conversation+0.1.0-rc.7.patch`
— exit 0.

## Self-review and risks

- Geometry is defined once and both persistence and viewport hit-testing call
that same normalizer; Task 5/6 should extend preview bodies, not introduce a
second sizing model.
- Assistant auto height intentionally remains a safe 240-unit placeholder until
Task 5 installs the specified `ResizeObserver` measurement.
- Image natural ratio and PDF first-page ratio will replace their initial
ratios in Tasks 5/6. The current admission bounds prevent corrupt persisted
ratios from producing unusable geometry.
- HTML and PDF bodies are placeholders at this task boundary. The shared frame,
wheel/pointer ownership marker, and shield are production renderer behavior
ready for their real preview consumers.
- No full test suite or local packaged-app run was performed because this task's
brief requires only the two focused files, typecheck, patch validation, and
diff checks; final real-app QA belongs to Task 7.
Loading