ryan
f2ab94501c
refactor(layout): relocate go.mod to backend/ and clean import paths to module root
...
- Relocated go.mod and go.sum into backend/ root directory
- Stripped redundant backend/ segments from all Go imports (github.com/Rain-kl/Wavelet/...)
- Unified Makefile, swagger, and build-test to execute in backend/ module context
- Ensured 100% build-test, code-check, format, and swagger pass
2026-08-28 13:01:51 +08:00
ryan
43dc97e48c
refactor(layout): consolidate backend codebase into backend/ package and clean root directory
...
- Moved cmd/, core/, plugins/, pkg/, downstream/, and main.go into backend/ directory
- Batch updated all Go source files to import github.com/Rain-kl/Wavelet/backend/...
- Updated Makefile, scripts/swagger.sh, architecture guards, and platform skills
- Passed all quality gates (100% tests, 0 lint issues, clean build)
2026-08-28 12:56:02 +08:00
ryan
33b38f8687
docs(migration): update docs and skills for new migration architecture
...
Update all relevant documentation and skills to reflect:
- w_schema_versions shared version table with plugin_id discriminator
- Single 00001_initial.sql per plugin (merged from multi-file approach)
- gooseEngine uses goose.NewProvider with goose.WithStore(sharedStore)
- pkg/migrator deleted, all 26 global SQL files moved to per-plugin
- DDL/DML single-file approach (merged seed + schema)
Files updated:
- .agents/skills/database-migration/SKILL.md (full rewrite)
- docs/WAVELET_WHITE_PAPER.md (table matrix + migration check)
- docs/WAVELET_DEVELOPER_GUIDE.md (scenario 9)
- docs/superpowers/specs/2026-08-27-cordis-plugin-architecture-design.md
- docs/superpowers/specs/2026-08-27-cordis-downstream-developer-guide.md
2026-08-28 12:45:58 +08:00
ryan
9bd012a271
fix(migration): use single w_schema_versions table with plugin_id discriminator
...
Replace per-plugin goose version tables with a single shared table
shared across all plugins, discriminated by plugin_id.
Implementation:
- Implement custom goosedb.Store (sharedStore) that uses a single
w_schema_versions(plugin_id, version_id, applied_at) table
- Each store instance binds to a specific pluginID, filtering all
CRUD operations by that plugin_id
- Goose provider created via goose.WithStore(store) instead of
WithTableName, eliminating per-plugin goose_version_* tables
- Placeholder formatting (PostgreSQL vs SQLite ?) handled by
sharedStore.placeholder() based on dialect
This means:
SELECT * FROM w_schema_versions ORDER BY plugin_id, version_id;
shows the complete migration state of every plugin at a glance.
2026-08-28 12:39:28 +08:00
ryan
65c7c282f5
refactor(migration): merge per-plugin SQL into single initial migration
...
Each plugin now has exactly one migration file (00001_initial.sql)
containing its complete table schema and seed data, replacing the
multi-file approach with split ALTER/INSERT steps.
Changes per plugin:
- auth: w_auth_sources, w_external_accounts, w_access_tokens + login session seed
- user: w_users + system user seed (removed w_access_tokens — belongs to auth)
- admin: w_system_configs, w_templates + all 32 config seeds + 2 template seeds
(removed w_schedules, w_task_executions — belong to driver plugins)
- upload: w_upload_stats + indexes + access_mode + backfill
- message_gateway: all w_message_*, w_push_*, w_push_channels, w_push_histories
- risk_control/logstore: w_user_access_logs (PG + ClickHouse)
- driver_asynq_cron: w_schedules + cleanup seed
- driver_asynq_worker: w_task_executions
All CREATE TABLE use IF NOT EXISTS, all INSERT use ON CONFLICT DO NOTHING.
go:embed patterns remain 'migrations/*.sql' — unchanged.
2026-08-28 12:28:37 +08:00
ryan
530a9dd3ee
refactor(migration): delete pkg/migrator, move SQL to per-plugin embed
...
BREAKING: pkg/migrator/ deleted entirely. Migration SQL files are now
owned by each plugin in its own migrations/ directory.
Architecture:
- Delete pkg/migrator/ (26 global SQL files + ClickHouse migration)
- Move global SQL to per-plugin migrations/ with go:embed + Register()
- Rewrite cmd/app.go gooseEngine: uses Inject[DBService] for DB, iterates
all plugin-registered MigrationEntry, runs goose.Up per entry
- core.MigrationEngine.Migrate signature changed: *Context instead of
context.Context, so engine can resolve services via IoC
Per-plugin migration ownership:
auth/ → w_access_tokens, w_auth_sources, w_external_accounts
user/ → w_users (seed system user)
admin/ → w_system_configs, w_templates (seeds)
upload/ → w_uploads, w_upload_stats
message_gateway/ → w_push_*, w_message_*
risk_control/ → w_user_access_logs (PG + ClickHouse)
driver_asynq_cron/ → w_schedules
driver_asynq_worker/ → w_task_executions
Dependencies:
- cmd/banner.go: removed migration report display (migrations are automatic)
- cmd/reset_passwd.go: removed PreRun migrator.Migrate() call
- go.mod: clickhouse-go kept (used by plugins/infra/database/clickhouse.go)
2026-08-28 12:19:25 +08:00
ryan
c9b702d234
refactor(core): fix cross-domain auth imports, unify migration, add downstream scaffold
...
Architecture:
- Move GetFromContext/SetToContext from plugins/domain/auth to pkg/util
- Move auth context key constants to core/contracts (AuthUserObjKey, AuthTokenAuthKey, etc.)
- Add AuthUserIDKey, AuthUserNameKey, GetCurrentUserID, RevokeToken to contracts.AuthService
- All 4 domain plugin Apply() methods now resolve AuthService via core.Using IoC
- Plugin route middleware uses authSvc.RequireAuthMiddleware() cast to gin.HandlerFunc
- DisallowTokenAuth added to AuthService contract
Migration:
- Replace cmd/app.go SetMigrationRunner bridge with gooseEngine implementing core.MigrationEngine
- Remove cmd/root.go PreRun migration hooks and runMigrations() function
- Migrations now run via core.App.Start() → RunMigrations()
Events:
- Add complete domain event topic catalog and payload DTOs to core/contracts/events.go
- 15 event topics across auth, user, admin, upload, message_gateway, risk_control
Downstream:
- Create downstream/ directory with README and custom_example plugin scaffold
CI:
- Update Makefile code-check architecture guards for Cordis layering
- Enforce: core no gin/gorm/asynq, contracts no plugins/, pkg no plugins/, domain no cross-domain
2026-08-28 11:51:48 +08:00
ryan
416603b616
fix(persistence): migrate all pkg/persistence imports to plugins/infra/database and plugins/infra/cache
...
- Replace db.DB(ctx) with database.DB(ctx) from plugins/infra/database
- Replace db.Redis/db.PrefixedKey/db.GetJSON/db.SetJSON with cachepkg.* from plugins/infra/cache
- Replace pkg/persistence/idgen with pkg/idgen (already exists)
- Replace pkg/persistence/batchwriter with pkg/batchwriter (already exists)
- Replace pkg/persistence/migrator with pkg/migrator (already exists)
- Replace pkg/persistence/logstore with plugins/domain/risk_control/logstore
- Delete defunct pkg/{persistence,cap,message_gateway,push,shared,task}
- Fix vet issues: db alias in domain_test.go, driver_asynq_worker.TaskHandler reference
- Update Makefile architecture guard
- Update docs and skill references
- Update go.mod: gorilla/sessions promotion to direct dependency
2026-08-28 10:59:24 +08:00
ryan
fb6a3edb89
refactor(architecture): eliminate internal package and complete cordis single-owner model and repository migration
...
- Physically purged all legacy internal/ packages, centralized pkg/model/ and pkg/repository/
- Migrated domain models and database repositories into self-contained owner plugins (user, auth, message_gateway, admin, upload, risk_control)
- Decoupled cross-plugin interactions via pure core/contracts and typed EventBus
- Ensured 100% test coverage pass, zero data races (-race clean), and 0 lint issues in make code-check
2026-08-28 08:40:43 +08:00
ryan
1f348fd425
docs(whitepaper): update white paper to reflect 100% pure Cordis single-track architecture
2026-08-28 07:28:55 +08:00
ryan
dc49b72c29
refactor(core): completely decommission legacy internal/apps, internal/platform/bootstrap, and internal/router/v1
2026-08-28 07:28:45 +08:00
ryan
df3c5ae756
docs(whitepaper): update white paper with deep physical migration status and zero-lint test report
2026-08-28 07:16:40 +08:00
ryan
56ef70d81f
feat(cmd): register all 5 domain plugins in newWaveletApp and fix all lint issues
2026-08-28 07:16:30 +08:00
ryan
b259f35bb4
refactor(plugins): complete physical encapsulation of auth, admin, message_gateway, and risk_control domain plugins
2026-08-28 07:15:17 +08:00
ryan
e750fadacd
chore: docs
2026-08-28 00:11:54 +08:00
ryan
5a00879b63
docs(whitepaper): update white paper with comprehensive QA and E2E test report
2026-08-28 00:07:07 +08:00
ryan
b6bfa120fc
feat(core): implement app profile lifecycle dispatcher and wire cli commands
2026-08-28 00:02:30 +08:00
ryan
a4c3f70f0b
feat(plugins): migrate auth, user, message_gateway, risk_control, admin to domain plugins
2026-08-27 23:59:38 +08:00
ryan
75f226cfbf
docs(agents): update AGENTS.md and development skills for cordis architecture
2026-08-27 23:56:16 +08:00
ryan
94c5aa4cd3
docs: publish WAVELET architecture white paper and official developer guide
2026-08-27 23:51:37 +08:00
ryan
a25bf7a4f9
feat(plugins): package database, cache, logger, and storage as infra plugins
2026-08-27 23:51:10 +08:00
ryan
4efc2c92b7
feat(plugins): implement runtime drivers for http, asynq worker, and cron
2026-08-27 23:48:18 +08:00
ryan
ef6296bd22
feat(core): add typed eventbus and domain extension points
2026-08-27 23:47:58 +08:00
ryan
c53a5461ab
feat(core): add typed eventbus and domain extension points
2026-08-27 23:47:57 +08:00
ryan
d853a41eae
docs: initialize WAVELET white paper and developer guide
2026-08-27 23:43:06 +08:00
ryan
a6ab158855
feat(core): implement context service hub and generic ioc container
2026-08-27 23:41:12 +08:00
ryan
3792313797
docs: add cordis plugin architecture implementation plan
2026-08-27 23:38:02 +08:00
ryan
40de54fe5b
docs: add cordis downstream developer guide and cookbook
2026-08-27 23:33:12 +08:00
ryan
360f4f432c
docs: add cordis microkernel and plugin architecture design spec
2026-08-27 23:24:34 +08:00
ryan
ae3b792e16
feat(core): sync framework security hardening and accessibility improvements
...
- add util.Go with panic recovery for background goroutines
- add util.EscapeLike and explicit ESCAPE clause for SQL LIKE queries
- add DummyCheckPassword and subtle.ConstantTimeCompare against timing attacks
- enforce session ID rotation upon login/oauth callback to prevent session fixation
- add sliding window login failure rate limiting and oauth state rate limiting
- fix redis client capture race in pubsub listeners and wait on stop channel
- adjust global --primary to oklch(51.1% 0.262 276.966) for WCAG AA contrast
- fix semantic heading levels and missing aria-labels across UI components
- document security, concurrency, and a11y standards in AGENTS.md
v1.4.2
2026-08-27 23:01:28 +08:00
ryan
b66cf3ae9c
feat(log): PG 分区清理与 logstore import-lint
...
CleanupExpired 先按月 DROP 过期分区,再删边界行并清理空分区;apps 禁止直连 analytics。
2026-08-16 16:48:15 +08:00
ryan
a8fcf6087a
chore(message-gateway): swagger and format
2026-08-16 12:27:03 +08:00
ryan
30acdb91e8
feat(message-gateway): add profile bot pairing card
2026-08-16 12:23:44 +08:00
ryan
124ce9bebb
feat(message-gateway): add admin channel cards and per-type forms
2026-08-16 12:22:28 +08:00
ryan
635c1760ad
feat(message-gateway): add user bind and unbind APIs
2026-08-16 12:19:32 +08:00
ryan
69d39d906f
feat(message-gateway): add admin channel CRUD APIs
2026-08-16 12:17:05 +08:00
ryan
09ec9d0af3
feat(message-gateway): run adapters on worker and handle pairing inbound
2026-08-16 12:14:17 +08:00
ryan
7ca6dbe272
feat(message-gateway): add QQ official C2C botgo adapter
...
Pin github.com/tencent-connect/botgo v0.2.1. Connect uses C2C intent
only via the official WebSocket session manager.
2026-08-16 12:10:15 +08:00
ryan
ef97ca5c7e
feat(message-gateway): add Telegram private-chat telebot adapter
2026-08-16 12:06:03 +08:00
ryan
cc86370e50
feat(message-gateway): emit message_gateway.inbound domain events
2026-08-16 12:04:55 +08:00
ryan
60afdf7c7b
feat(message-gateway): add channel, binding, and pairing repositories
2026-08-16 12:04:14 +08:00
ryan
9b1ef1cf7f
feat(message-gateway): add w_message_* models and goose migrations
2026-08-16 12:03:23 +08:00
ryan
8ea4c7e13e
feat(message-gateway): add channel types, registry, and pairing codes
2026-08-16 12:01:52 +08:00
ryan
a4db79e9bd
chore: ignore local git worktrees directory
2026-08-16 12:00:42 +08:00
ryan
8b1eb9ca0d
docs(message-gateway): add Wavelet message gateway implementation plan
2026-08-16 11:59:59 +08:00
ryan
e36db8a56c
docs(message-gateway): add Wavelet inbound channel gateway design spec
2026-08-16 11:55:57 +08:00
ryan
37d5a87c9b
chore: docs
2026-08-16 11:32:46 +08:00
ryan
e52592b16d
feat(log): 解耦用户访问日志存储,支持切换日志主库
...
用户访问日志可在 ClickHouse、PostgreSQL、SQLite 之间切换。
关闭 ClickHouse 时由主库承接写入与查询;切换任务会冻结写入、复制数据后翻转主库。
启动时校验日志主库与运行配置一致,定期清理按各库保留天数删除过期记录。
2026-08-16 11:17:55 +08:00
ryan
6a53619dd2
feat(framework): 回灌 OpenFlare 分层、安全与运行时改进
...
将平台域持久化收敛为 repository 唯一入口,model 去掉 IO。
邮件头写入前清除 CR/LF,防止 header 注入。
httppool 支持可配置 Transport;batchwriter 增加 MinBatchSize/Stats,flush 失败交回批次;任务 PermanentError 作为 SkipRetry 终态。
设置与推送页的确认改为 AlertDialog;axios 去尾斜杠并按 Gin 数组序列化查询参数。
升级共享 Go 依赖(Gin、Asynq、OTel、GORM、Redis 等)。
2026-08-16 11:07:20 +08:00
ryan
b9b42e3174
ci: make canary
2026-08-16 10:13:39 +08:00