Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@
## [Unreleased]

### Added
- **显式云文件上传现在按本次内容决定是否请求隐私同意**(#225,需 Alpha Web 签发端与 Cloud Jobs 上传闸部署后生效)——main 只读取并冻结用户明确选择的项目内文件,为每个文件绑定相对路径、字节数与 SHA-256,并在签发前执行 256 文件、100 MiB 与既有 256 KiB 控制信封限额。纯代码/普通文本不弹框,直接发送并显示一行透明提示;检测到电话(含裸中国手机号/E.164)、邮箱、身份证样式、私钥/凭据或敏感路径时,才按批准稿展示可展开逐文件清单、用途和保留说明,由用户逐次同意。取消、范围不明、分类异常、账号切换、Alpha Web 一次性凭据签发失败或清单指纹不匹配均不发送;renderer/agent、MCP、定时任务与模型附件都拿不到 manifest/token 通道,既有 git diff/code-review 派发保持可用。
- **设置现在由 Alpha 自有页面统一管理**(REQ-090 #443,需下个签名版本生效)——通用、快捷键与扩展存储检查集中到同一设置页;保存后的值会立即作用于运行中的应用,后续修改其它设置不会把刚保存的内容静默回滚。损坏的本机设置会显示安全默认值并允许直接修复,扩展缓存检查或回收进行中重开页面也会继续恢复状态。
- **权限确认改为 Alpha 自有的安全确认框**(REQ-090 #444,需下个签名版本生效)——旧的输入框内 permission dock 及专属换肤已移除;执行前逐项展示请求携带的主体/执行 Agent、action/capability、resources、scope 与 expiry,不再显示契约占位。你可以选择允许一次、按当前项目始终允许或拒绝;永久授权显式携带项目范围与不过期事实。提交未收到原子决定收据或与既有决定冲突时,工具保持暂停,界面保留请求与原决定供精确重试,绝不会假定已经获准;确认框复用 Alpha Dialog 的焦点、键盘与不可关闭合同。
- **实验室扩展可以「本次会话启用」了**(REQ-104 #408,需下个签名版本生效)——目录里标注「实验室」的连接器,已安装后在「已安装」列表行与详情页出现琥珀色会话开关:打开即对当前项目会话立即生效,状态行显示「本次会话已启用 · 会话结束自动关闭」;会话结束(应用重启、重新登录、引擎重启或崩溃)后自动关闭、开关归位,行保留(卸载才消失),下次使用需再次开启。这类扩展永远不会被持久开启:开启只登记在内存里,不写任何配置或账本,崩溃/重启后零残留。开关只在打开了项目会话时可用(无项目上下文时置灰并说明);开启前照常过安全检查——有安全公示、身份对不上或审核数据无法核实时如实拒绝并保持关闭,安全复审已过期时先弹确认框;开启成功但连接未建立时如实提示「已开启,但连接未成功」,绝不谎报。引擎中途重载(比如安装了别的扩展)会自动重新核验并接回本次会话已开启的实验室扩展,核验不过的当场回落关闭。实验室条目的「即将提供」占位说明同步下线,详情页「启用方式」一段改为讲清真实的会话语义。
Expand Down
61 changes: 61 additions & 0 deletions docs/contracts/platform-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ integration. Service wire formats remain owned by their producer repositories.
| Surface | Owner | Desktop seam |
| ---------------------------------------------------------------- | -------------------------------- | -------------------------------------------- |
| Authorization code, refresh/session rotation, endpoint discovery | `alpha-web` | `alpha-auth.ts`, `alpha-endpoints.ts` |
| Manifest-bound `upload_consent` issuance | `alpha-web` | main-process upload issuer client |
| Model gateway and model registry | `alpha-platform` | injected `alpha` provider |
| Cloud Jobs HTTP/SSE, artifacts, schedules, MCP facade | `alpha-platform` | main-process clients and injected MCP server |
| Account summary and billing transactions | `alpha-platform` account service | main-process account client |
Expand Down Expand Up @@ -96,6 +97,66 @@ window exists. Cold-start callbacks defer activation until the next normal
sidecar start. Logout clears token state and re-forks without platform
credentials.

## Explicit cloud file upload and conditional consent

Only the desktop's explicit Cloud Jobs file picker enters the upload-consent
protocol. Model prompts and attachments are not uploads under this contract.
Existing `input.diff` and `code-review` dispatch remain the v1
`grandfathered` egress classes: they are neither disabled nor retrofitted with
an upload manifest. Cloud schedules, bounded-agent envelopes, and the MCP
sidecar have no upload-consent field or token channel.

The main process is the sole upload authority. The renderer can request a
`code-review` file selection and can later confirm or cancel a main-issued
opaque request ID. It cannot provide paths, file bytes, a manifest, a consent
decision, or a token. Main asks the user for one project root and an explicit
set of files, resolves the canonical paths, rejects missing, outside-root,
symlinked, duplicate, non-regular, unreadable, and non-UTF-8 inputs, then reads
and freezes the exact content in memory. An empty or unverifiable selection is
cancelled; it never becomes a whole-project selection.

For that immutable snapshot, main creates the vendored `UploadManifestV1` with
the access-token `sub` as `tenant_id`, normalized relative paths, byte sizes,
per-file SHA-256 summaries, total count and bytes, creation time,
`retention_class`, the required `explicit.file-upload` egress declaration, and
`consent_required`. It validates the schema plus count/total/path-uniqueness
invariants and hashes the exact JSON string later sent to the Cloud Jobs
gateway. Admission fails before issuance above 256 files, 100 MiB total, or
the existing 256 KiB control-envelope limit. The latter is normally the
tightest v1 bound because explicit UTF-8 contents travel inside that envelope.

Client classification is intentionally broader than the platform fallback.
It detects email, bare mainland-China mobile numbers, E.164 numbers (including
sentence-final punctuation), Chinese identity-number shapes, private-key and
credential patterns, and credential-sensitive paths. Pure code and unrelated
numeric content do not become sensitive merely for containing numbers.
Classifier exceptions or malformed results fail closed as sensitive. When no
protected information is found, main dispatches immediately and the renderer
shows one non-blocking transparency line. When protected information is found,
the renderer uses the approved house Dialog/Button surface to show the bounded
file preview, findings, purpose, and retention; cancel mints nothing and sends
nothing.

After confirmation, main reacquires a `cloud.dispatch` access token and
requires the same valid `sub`, then calls the Alpha Web-owned
`POST <web>/auth/upload-consent` issuance seam. The request carries the exact
manifest JSON and its SHA-256. Alpha Web must return the vendored
`upload_consent` JWT branch (`iss=alpha-web`, `aud=alpha-platform-upload`,
`token_use=upload_consent`, `purpose=artifact.upload`). Main checks its subject,
expiry, manifest ID, manifest SHA-256, and egress declaration before sending
the frozen request to Cloud Jobs with `X-Alpha-Upload-Consent`. The desktop
does not call or describe an Alpha Platform issuance API. Deployment of the
real Alpha Web issuer remains an Alpha Web integration prerequisite; desktop
tests use a mocked issuer response.

Pending consent is one-shot process memory, scoped to the requesting renderer,
and consumed before issuance begins. It is never stored in project prefs.
Tokens, manifests, and file bytes never cross preload; handler return values
are checked again at runtime. Upload errors log only a stable code and omit
bearers, issuer responses, and absolute paths. Any attempt to inject upload
control fields through an ordinary renderer or agent envelope fails with
`upload-main-gate-required`.

## Managed cloud artifact persistence

Cloud artifact bytes remain in the main process and stream to a unique `.part`
Expand Down
Loading
Loading