Commit Graph

326 Commits

Author SHA1 Message Date
ryan 48211fa587 chore: code-check 2026-08-28 13:42:49 +08:00
ryan 9213ee79b3 refactor(core): finalize context test and standalone repository fallback 2026-08-28 13:38:22 +08:00
ryan a296818922 refactor(user): decouple repository from direct database infra import 2026-08-28 13:37:13 +08:00
ryan 3570ccd5c3 feat(core): implement plugin fiber state machine and reactive dependency reconciler 2026-08-28 13:35:43 +08:00
ryan 33294b3fae feat(core): implement scoped revertible effects for context extpoints 2026-08-28 13:34:07 +08:00
ryan 0b4e928d1a docs(core): add cordis architecture alignment implementation plan 2026-08-28 13:32:55 +08:00
ryan 0bc19e34cb docs(core): add cordis architecture alignment design spec 2026-08-28 13:32:05 +08:00
ryan b92ba54707 docs(core): update developer guide and white paper with cordis composability standards 2026-08-28 13:30:47 +08:00
ryan e19bf36580 refactor(core): align architecture with cordis spatiotemporal composability 2026-08-28 13:28:58 +08:00
ryan 9f8890d159 refactor(module): simplify module name to Wavelet and standardize import paths
- Declared module Wavelet in backend/go.mod
- Replaced github.com/Rain-kl/Wavelet/ with clean Wavelet/ import paths across backend codebase
- Updated architecture guards, Makefile, swagger, and build tests
- 100% passed all tests, lint checks, and binary compilation
2026-08-28 13:10:30 +08:00
ryan f2ab94501c refactor(layout): relocate go.mod to backend/ and clean import paths to module root
- Relocated go.mod and go.sum into backend/ root directory
- Stripped redundant backend/ segments from all Go imports (github.com/Rain-kl/Wavelet/...)
- Unified Makefile, swagger, and build-test to execute in backend/ module context
- Ensured 100% build-test, code-check, format, and swagger pass
2026-08-28 13:01:51 +08:00
ryan 43dc97e48c refactor(layout): consolidate backend codebase into backend/ package and clean root directory
- Moved cmd/, core/, plugins/, pkg/, downstream/, and main.go into backend/ directory
- Batch updated all Go source files to import github.com/Rain-kl/Wavelet/backend/...
- Updated Makefile, scripts/swagger.sh, architecture guards, and platform skills
- Passed all quality gates (100% tests, 0 lint issues, clean build)
2026-08-28 12:56:02 +08:00
ryan 33b38f8687 docs(migration): update docs and skills for new migration architecture
Update all relevant documentation and skills to reflect:
- w_schema_versions shared version table with plugin_id discriminator
- Single 00001_initial.sql per plugin (merged from multi-file approach)
- gooseEngine uses goose.NewProvider with goose.WithStore(sharedStore)
- pkg/migrator deleted, all 26 global SQL files moved to per-plugin
- DDL/DML single-file approach (merged seed + schema)

Files updated:
- .agents/skills/database-migration/SKILL.md (full rewrite)
- docs/WAVELET_WHITE_PAPER.md (table matrix + migration check)
- docs/WAVELET_DEVELOPER_GUIDE.md (scenario 9)
- docs/superpowers/specs/2026-08-27-cordis-plugin-architecture-design.md
- docs/superpowers/specs/2026-08-27-cordis-downstream-developer-guide.md
2026-08-28 12:45:58 +08:00
ryan 9bd012a271 fix(migration): use single w_schema_versions table with plugin_id discriminator
Replace per-plugin goose version tables with a single shared table
shared across all plugins, discriminated by plugin_id.

Implementation:
- Implement custom goosedb.Store (sharedStore) that uses a single
  w_schema_versions(plugin_id, version_id, applied_at) table
- Each store instance binds to a specific pluginID, filtering all
  CRUD operations by that plugin_id
- Goose provider created via goose.WithStore(store) instead of
  WithTableName, eliminating per-plugin goose_version_* tables
- Placeholder formatting (PostgreSQL  vs SQLite ?) handled by
  sharedStore.placeholder() based on dialect

This means:
  SELECT * FROM w_schema_versions ORDER BY plugin_id, version_id;
shows the complete migration state of every plugin at a glance.
2026-08-28 12:39:28 +08:00
ryan 65c7c282f5 refactor(migration): merge per-plugin SQL into single initial migration
Each plugin now has exactly one migration file (00001_initial.sql)
containing its complete table schema and seed data, replacing the
multi-file approach with split ALTER/INSERT steps.

Changes per plugin:
- auth: w_auth_sources, w_external_accounts, w_access_tokens + login session seed
- user: w_users + system user seed (removed w_access_tokens — belongs to auth)
- admin: w_system_configs, w_templates + all 32 config seeds + 2 template seeds
  (removed w_schedules, w_task_executions — belong to driver plugins)
- upload: w_upload_stats + indexes + access_mode + backfill
- message_gateway: all w_message_*, w_push_*, w_push_channels, w_push_histories
- risk_control/logstore: w_user_access_logs (PG + ClickHouse)
- driver_asynq_cron: w_schedules + cleanup seed
- driver_asynq_worker: w_task_executions

All CREATE TABLE use IF NOT EXISTS, all INSERT use ON CONFLICT DO NOTHING.
go:embed patterns remain 'migrations/*.sql' — unchanged.
2026-08-28 12:28:37 +08:00
ryan 530a9dd3ee refactor(migration): delete pkg/migrator, move SQL to per-plugin embed
BREAKING: pkg/migrator/ deleted entirely. Migration SQL files are now
owned by each plugin in its own migrations/ directory.

Architecture:
- Delete pkg/migrator/ (26 global SQL files + ClickHouse migration)
- Move global SQL to per-plugin migrations/ with go:embed + Register()
- Rewrite cmd/app.go gooseEngine: uses Inject[DBService] for DB, iterates
  all plugin-registered MigrationEntry, runs goose.Up per entry
- core.MigrationEngine.Migrate signature changed: *Context instead of
  context.Context, so engine can resolve services via IoC

Per-plugin migration ownership:
  auth/             → w_access_tokens, w_auth_sources, w_external_accounts
  user/             → w_users (seed system user)
  admin/            → w_system_configs, w_templates (seeds)
  upload/           → w_uploads, w_upload_stats
  message_gateway/  → w_push_*, w_message_*
  risk_control/     → w_user_access_logs (PG + ClickHouse)
  driver_asynq_cron/  → w_schedules
  driver_asynq_worker/ → w_task_executions

Dependencies:
- cmd/banner.go: removed migration report display (migrations are automatic)
- cmd/reset_passwd.go: removed PreRun migrator.Migrate() call
- go.mod: clickhouse-go kept (used by plugins/infra/database/clickhouse.go)
2026-08-28 12:19:25 +08:00
ryan c9b702d234 refactor(core): fix cross-domain auth imports, unify migration, add downstream scaffold
Architecture:
- Move GetFromContext/SetToContext from plugins/domain/auth to pkg/util
- Move auth context key constants to core/contracts (AuthUserObjKey, AuthTokenAuthKey, etc.)
- Add AuthUserIDKey, AuthUserNameKey, GetCurrentUserID, RevokeToken to contracts.AuthService
- All 4 domain plugin Apply() methods now resolve AuthService via core.Using IoC
- Plugin route middleware uses authSvc.RequireAuthMiddleware() cast to gin.HandlerFunc
- DisallowTokenAuth added to AuthService contract

Migration:
- Replace cmd/app.go SetMigrationRunner bridge with gooseEngine implementing core.MigrationEngine
- Remove cmd/root.go PreRun migration hooks and runMigrations() function
- Migrations now run via core.App.Start() → RunMigrations()

Events:
- Add complete domain event topic catalog and payload DTOs to core/contracts/events.go
- 15 event topics across auth, user, admin, upload, message_gateway, risk_control

Downstream:
- Create downstream/ directory with README and custom_example plugin scaffold

CI:
- Update Makefile code-check architecture guards for Cordis layering
- Enforce: core no gin/gorm/asynq, contracts no plugins/, pkg no plugins/, domain no cross-domain
2026-08-28 11:51:48 +08:00
ryan 416603b616 fix(persistence): migrate all pkg/persistence imports to plugins/infra/database and plugins/infra/cache
- Replace db.DB(ctx) with database.DB(ctx) from plugins/infra/database
- Replace db.Redis/db.PrefixedKey/db.GetJSON/db.SetJSON with cachepkg.* from plugins/infra/cache
- Replace pkg/persistence/idgen with pkg/idgen (already exists)
- Replace pkg/persistence/batchwriter with pkg/batchwriter (already exists)
- Replace pkg/persistence/migrator with pkg/migrator (already exists)
- Replace pkg/persistence/logstore with plugins/domain/risk_control/logstore
- Delete defunct pkg/{persistence,cap,message_gateway,push,shared,task}
- Fix vet issues: db alias in domain_test.go, driver_asynq_worker.TaskHandler reference
- Update Makefile architecture guard
- Update docs and skill references
- Update go.mod: gorilla/sessions promotion to direct dependency
2026-08-28 10:59:24 +08:00
ryan fb6a3edb89 refactor(architecture): eliminate internal package and complete cordis single-owner model and repository migration
- Physically purged all legacy internal/ packages, centralized pkg/model/ and pkg/repository/
- Migrated domain models and database repositories into self-contained owner plugins (user, auth, message_gateway, admin, upload, risk_control)
- Decoupled cross-plugin interactions via pure core/contracts and typed EventBus
- Ensured 100% test coverage pass, zero data races (-race clean), and 0 lint issues in make code-check
2026-08-28 08:40:43 +08:00
ryan 1f348fd425 docs(whitepaper): update white paper to reflect 100% pure Cordis single-track architecture 2026-08-28 07:28:55 +08:00
ryan dc49b72c29 refactor(core): completely decommission legacy internal/apps, internal/platform/bootstrap, and internal/router/v1 2026-08-28 07:28:45 +08:00
ryan df3c5ae756 docs(whitepaper): update white paper with deep physical migration status and zero-lint test report 2026-08-28 07:16:40 +08:00
ryan 56ef70d81f feat(cmd): register all 5 domain plugins in newWaveletApp and fix all lint issues 2026-08-28 07:16:30 +08:00
ryan b259f35bb4 refactor(plugins): complete physical encapsulation of auth, admin, message_gateway, and risk_control domain plugins 2026-08-28 07:15:17 +08:00
ryan e750fadacd chore: docs 2026-08-28 00:11:54 +08:00
ryan 5a00879b63 docs(whitepaper): update white paper with comprehensive QA and E2E test report 2026-08-28 00:07:07 +08:00
ryan b6bfa120fc feat(core): implement app profile lifecycle dispatcher and wire cli commands 2026-08-28 00:02:30 +08:00
ryan a4c3f70f0b feat(plugins): migrate auth, user, message_gateway, risk_control, admin to domain plugins 2026-08-27 23:59:38 +08:00
ryan 75f226cfbf docs(agents): update AGENTS.md and development skills for cordis architecture 2026-08-27 23:56:16 +08:00
ryan 94c5aa4cd3 docs: publish WAVELET architecture white paper and official developer guide 2026-08-27 23:51:37 +08:00
ryan a25bf7a4f9 feat(plugins): package database, cache, logger, and storage as infra plugins 2026-08-27 23:51:10 +08:00
ryan 4efc2c92b7 feat(plugins): implement runtime drivers for http, asynq worker, and cron 2026-08-27 23:48:18 +08:00
ryan ef6296bd22 feat(core): add typed eventbus and domain extension points 2026-08-27 23:47:58 +08:00
ryan c53a5461ab feat(core): add typed eventbus and domain extension points 2026-08-27 23:47:57 +08:00
ryan d853a41eae docs: initialize WAVELET white paper and developer guide 2026-08-27 23:43:06 +08:00
ryan a6ab158855 feat(core): implement context service hub and generic ioc container 2026-08-27 23:41:12 +08:00
ryan 3792313797 docs: add cordis plugin architecture implementation plan 2026-08-27 23:38:02 +08:00
ryan 40de54fe5b docs: add cordis downstream developer guide and cookbook 2026-08-27 23:33:12 +08:00
ryan 360f4f432c docs: add cordis microkernel and plugin architecture design spec 2026-08-27 23:24:34 +08:00
ryan ae3b792e16 feat(core): sync framework security hardening and accessibility improvements
- add util.Go with panic recovery for background goroutines
- add util.EscapeLike and explicit ESCAPE clause for SQL LIKE queries
- add DummyCheckPassword and subtle.ConstantTimeCompare against timing attacks
- enforce session ID rotation upon login/oauth callback to prevent session fixation
- add sliding window login failure rate limiting and oauth state rate limiting
- fix redis client capture race in pubsub listeners and wait on stop channel
- adjust global --primary to oklch(51.1% 0.262 276.966) for WCAG AA contrast
- fix semantic heading levels and missing aria-labels across UI components
- document security, concurrency, and a11y standards in AGENTS.md
v1.4.2
2026-08-27 23:01:28 +08:00
ryan b66cf3ae9c feat(log): PG 分区清理与 logstore import-lint
CleanupExpired 先按月 DROP 过期分区,再删边界行并清理空分区;apps 禁止直连 analytics。
2026-08-16 16:48:15 +08:00
ryan a8fcf6087a chore(message-gateway): swagger and format 2026-08-16 12:27:03 +08:00
ryan 30acdb91e8 feat(message-gateway): add profile bot pairing card 2026-08-16 12:23:44 +08:00
ryan 124ce9bebb feat(message-gateway): add admin channel cards and per-type forms 2026-08-16 12:22:28 +08:00
ryan 635c1760ad feat(message-gateway): add user bind and unbind APIs 2026-08-16 12:19:32 +08:00
ryan 69d39d906f feat(message-gateway): add admin channel CRUD APIs 2026-08-16 12:17:05 +08:00
ryan 09ec9d0af3 feat(message-gateway): run adapters on worker and handle pairing inbound 2026-08-16 12:14:17 +08:00
ryan 7ca6dbe272 feat(message-gateway): add QQ official C2C botgo adapter
Pin github.com/tencent-connect/botgo v0.2.1. Connect uses C2C intent
only via the official WebSocket session manager.
2026-08-16 12:10:15 +08:00
ryan ef97ca5c7e feat(message-gateway): add Telegram private-chat telebot adapter 2026-08-16 12:06:03 +08:00
ryan cc86370e50 feat(message-gateway): emit message_gateway.inbound domain events 2026-08-16 12:04:55 +08:00