# Changelog / 更新日志 All notable changes to this repository should be documented in this file. 本仓库的重要变更建议统一记录在此文件中。 The format loosely follows Keep a Changelog and can be adapted to the team's habits. 本文档参考了 Keep a Changelog 的思路,也可以根据团队习惯调整。 ## [0.2.7] - 2026-09-30 ### Done / 完成 - P6 hosted submission delivered as plan A (owner call: author-hosted https URL, embedded play; no file hosting): crearte-server `3e11446` (0.13.0 — D-B runtime immutable on metadata_change, D-C hosted works cannot carry a bundle, unit + fresh-empty-DB integration incl. real-HTTP draft→submit→approve→hosted_url/play_origin/fallback readback and public payload runtime/hostedUrl; zero migrations, zero new deps, Approve mapping untouched — the feared hosted_url write gap was a false alarm, PayloadToWork at import.go:39 already covers it) and crearte `fee5f3b` (0.19.0 — content-layer WorkRuntime three modes with hostedUrl/fallback aligned to server json names, submit-form third radio 自托管内嵌 w/ https + fallback=external⇒url mirror validation, prefill refusal removed and hosted fields backfilled, new_version stays virtual-only; playback side zero changes per spec; vitest 492 / typecheck / admin-flow 6 / main suite 69 green; e2e hosted draft-payload flow added). Dual independent review PASS with notes; six-leg host acceptance green (incl. branch-backend full-loop 1 passed; first admin-flow 1-passed reading was stack-contention false alarm, rerun 6 passed RC=0). T5 CSP probe: deploy templates carry no main-site frame-src (the two `frame-src 'none'` hits belong to runtime-subdomain pages only) — zero deploy changes on record. Known gaps: D-D (admin hostedUrl display row) delivered same day as crearte 0.19.1 `9bd9372` — maintainer-direct follow-up patch (Task 2 brief had omitted the row; reviews passed against the brief rather than full spec §3 — lesson: review against the spec). Plain-text row, deliberately no anchor, plus fallback label row; four legs rerun green (vitest 492 / typecheck / admin-flow 7 / main suite 70). Remaining: new_version hosted rejection is server-side only (FE no hard check, spec-accepted). See spec D-A…D-F. - P6 hosted 作品投稿以方案 A 交付(owner 拍板:作者自部署、投稿只存 https URL、站内沙箱 iframe 播;不做文件托管):crearte-server `3e11446`(0.13.0——D-B metadata_change 禁改 runtime、D-C hosted 禁带 bundle;单测 + 空库集成含真 HTTP 草稿→提交→过审→hosted_url/play_origin/fallback 读回与公开载荷 runtime/hostedUrl;零迁移零新依赖,Approve 落库未动——此前担心的 hosted_url 落库缺口系误报,PayloadToWork 本就覆盖)与 crearte `fee5f3b`(0.19.0——内容层三档 + hostedUrl/fallback 字段与 server json 名逐字对齐;表单第三 radio「自托管内嵌」+ https 校验 + fallback 默认 external 镜像校验;预填拒绝分支删除并回填;new_version 仍 virtual-only;播放端零改动;vitest 492 / typecheck / admin-flow 6 / 主套件 69 绿;e2e 新增 hosted 草稿载荷流)。双路独立审查 PASS with notes;六腿本机验收全绿(含分支后端真栈 full-loop 1 passed;admin-flow 首轮 1 passed 为栈腿争用假警报,复跑 6 passed RC=0 坐实)。T5:deploy 模板无主站 frame-src 下发(两处 'none' 属运行时子域页),零改动记录。遗留:D-D(审核面 hostedUrl 展示行)当日补交 crearte 0.19.1 `9bd9372`——控制者直改小补丁(Task 2 任务书漏列该条;审查按任务书对照未扯出——教训:审查依据应为 spec §3 全量)。纯文本无锚点行+降级中文标签行,四腿复跑全绿(vitest 492 / typecheck / admin-flow 7 / 主套件 70)。仅剩:new_version 拒 hosted 仅 server 拦(前端无硬校验,spec 已接受)。选型见 spec D-A…D-F。 ## [0.2.6] - 2026-09-30 ### Done / 完成 - P7 admin console delivered: crearte-server `ca24805` (0.12.0 — audit_log table via migration 0010, audit middleware on a consolidated admin route group (owner call: no more per-route RequireAdmin), gin FullPath templates recorded for every admin request incl. GETs and failed attempts while unauthorized 401/403 stays unrecorded; user list / PATCH role / audit query endpoints; last-admin demotion guard 409 enforced in the shared service so CLI and API both obey; token invalidation on role change verified end-to-end) and crearte `900f13a` (0.18.0 — /admin/users with search/pagination/demote-confirm dual-point copy incl. 409 echo, /admin/audit with localized time, zh action labels w/ fallback, status coloring, route filter; apiRepo admin trio with AdminApiError; e2e admin-flow extended w/ self-recording semantics; vitest 488 / main suite 68 green). Host acceptance: six legs all green incl. fresh-empty-DB -count=1 integration (10 ok, zero FAIL/skip) and real-stack full-loop 1 passed ×2 against the branch backend. See spec §2 decisions D-A…D-D. - P7 管理后台增强交付:crearte-server `ca24805`(0.12.0——迁移 0010 audit_log;审计中间件挂收敛后的 admin 路由组(owner 定稿:不再逐条手挂),admin 面全请求入史含 GET 与失败尝试(FullPath 模板),未遂 401/403 不入史;用户列表/PATCH 角色/审计查询三端点;唯一 admin 降级 409 护栏落在共享 service,CLI/API 双覆盖;角色变更废 token 端到端验证)与 crearte `900f13a`(0.18.0——/admin/users(搜索/分页/降级确认双要点文案含 409 原文回显)+ /admin/audit(本地化时间/中文动作标签+未知回退/状态着色/route 过滤);apiRepo 管理面三方法+AdminApiError;e2e admin-flow 扩两流含自记录语义;vitest 488 / 主套件 68 绿)。本机验收六腿全绿:容器四连、空库 -count=1 集成 10 ok 零 FAIL 零 skip、护栏矩阵(非唯一降级 OK / 唯一降级 CLI 拒 + API 409)、废 token 401、审计流水含失败尝试、分支后端真栈 full-loop 1 passed ×2。选型见 spec §2 D-A…D-D。 ## [0.2.5] - 2026-09-30 ### Docs / 文档 - Creator center `/creator` delivered (maintainer-direct need, plan 2026-09-30-creator-center.md executed): pure-frontend crearte 0.17.0 — new route + homepage-style view (hero, auth-state-aware work-data placeholder card, tutorial placeholder card linking to the submission guide) and a third header nav tab; merged & pushed as crearte `e2fab8a` after TDD e2e (4 new default cases + 1 appended noauth case) and a 6-lens review; server/deploy untouched by design. - 创作者中心 `/creator` 交付(维护者直接需求,计划 2026-09-30-creator-center.md 已执行):纯前端 crearte 0.17.0——新路由 + 首页样式视图(hero、按登录态分流的作品数据占位卡、链向现有投稿指南的教程占位卡)与页头第三个导航 tab;TDD e2e(默认配置新增 4 用例 + noauth 追加 1 断言)与 6 透镜审查后以 crearte `e2fab8a` 合并推送;后端/部署仓按设计零改动。 ## [0.2.4] - 2026-09-30 ### Docs / 文档 - Roadmap P2 delivered: GitHub Actions baseline in all three repos — crearte-server `validate.yml` (check + empty-DB Postgres integration with a silent-skip guard + real-stack e2e-stack hosting the cross-repo checkout pair), crearte `validate.yml` (push:master trigger) plus `e2e-stack.sh` GO/REQUIRED env knobs, crearte-deploy `validate.yml` (compose config across four profiles with a negative empty-password guard test). First real-stack run uncovered a serve-runtime defect: the runtime triple (/__bootstrap, /sw.js, /agent.js) was gated behind the fixtures subdomain table, so live-registered games could never install the SW — fixed with a position-only move (crearte `5e0fb2e`). Merged & pushed 2026-09-30: server `7b97108` / crearte `711b6de` / deploy `522545d`; Actions enablement and branch protection are owner-manual tails (spec §2.4). - 路线图 P2 交付:三仓 GitHub Actions 基线——crearte-server `validate.yml`(check + 空库 Postgres 集成层带静默 skip 守卫 + e2e-stack 真栈 job 宿主双仓 checkout)、crearte `validate.yml`(push:master 触发)及 `e2e-stack.sh` 的 GO/REQUIRED 环境变量开关、crearte-deploy `validate.yml`(四 profile compose config 正路 + 空密码反路守卫断言)。真栈首跑拓出 serve-runtime 缺陷:运行时三件套(/__bootstrap、/sw.js、/agent.js)被卡在夹具子域表门槛之后,活体注册的作品永远装不上 SW——已以纯位置搬移修复(crearte `5e0fb2e`)。2026-09-30 合并推送:server `7b97108` / crearte `711b6de` / deploy `522545d`;Actions 启用确认与分支保护为 owner 手动尾巴(spec §2.4)。 ## [0.2.3] - 2026-09-30 ### Docs / 文档 - Roadmap P5 delivered: favorites & 5-star ratings went full-stack — server `favorites`/`ratings` tables + `ReactionRepository` with reaction-watermark ETag invalidation and user-space endpoints (crearte-server `e3da246`), and frontend hot sort (Bayesian prior mean + favorite log weight), game-page reaction widget, card badges, account my-reactions section (crearte `eb5fbed`), merged & pushed 2026-09-30 after a 9-step live prod-stack smoke; crearte-deploy untouched by design (scope revision recorded in spec). - 路线图 P5 交付:收藏与五星评分全栈落地——服务端 `favorites`/`ratings` 新表 + `ReactionRepository`(反应水位驱动 ETag 失效)与用户态端点(crearte-server `e3da246`);前端热门排序(贝叶斯先验均分 + 收藏对数权重)、详情页反应组件、卡片徽标、账号页我的反应(crearte `eb5fbed`),2026-09-30 经 prod 演练栈 9 步冒烟后合并推送;crearte-deploy 按设计零改动(范围修订已记入 spec)。 ## [0.2.2] - 2026-09-29 ### Docs / 文档 - Roadmap P1 delivered: prod write side went live in the compose drill — minio-prod + api-prod storage/games env + templated nginx wildcard block (crearte `63bb96d` / crearte-deploy `4d53d58`), POSTGRES_PASSWORD default retired, TLS deferred by design with a real-server checklist in README. - 路线图 P1 交付:prod 写侧在本机演练栈完整启用——minio-prod、api-prod 存储/游玩域名环境、nginx 通配块模板化(crearte `63bb96d` / crearte-deploy `4d53d58`);POSTGRES_PASSWORD 默认值退役;TLS 按设计缓做,真机清单已入 README。 ## [0.2.1] - 2026-09-29 ### Fixed / 修复 - `clone_all.sh` pins `master` for `crearte` and `crearte-server` instead of the stale `feat/submission-preview` work branch — fresh clones and updates land on the integration branch that carries the merged roadmap work. (Note: `update_repo` switches clean checkouts to the pinned branch; dirty ones are skipped.) - `clone_all.sh` 中 `crearte` 与 `crearte-server` 的引导分支由过时的 `feat/submission-preview` 工作分支改为 `master` —— 全新克隆与更新落在承载路线图已合并工作的集成分支上。(注意:`update_repo` 会把干净的 checkout 切到钉子分支,脏工作树自动跳过切换。) ## [0.2.0] - 2026-09-29 ### Changed / 变更 - Roadmap delivered: P0 (known-defect cleanup — CORS `If-None-Match` fix in crearte-server `a8ea755`, compose key-store drift cleanup in crearte-deploy `27044be`) and P4 (author page `/users/:user`, crearte `f12cbf1`) are merged to their repos' master and pushed; roadmap statuses updated. - 路线图交付:P0(已知缺陷清理——crearte-server `a8ea755` 的 CORS `If-None-Match` 修复、crearte-deploy `27044be` 的 compose 密钥库遗留清理)与 P4(作者主页 `/users/:user`,crearte `f12cbf1`)均已合并至各仓 master 并推送;路线图状态已更新。 ## [0.1.0] - 2026-09-29 ### Added / 新增 - Added `docs/ROADMAP.md`: the cross-repo roadmap decomposed into sub-projects P0–P8 (ops foundation → product value → governance), with ordering rationale and a doc index for future specs and plans. - 新增 `docs/ROADMAP.md`:跨仓库路线图,分解为 P0–P8 子项目(上线底座 → 产品价值 → 治理长尾),含排序理由与后续 spec/计划的文档索引。 ### Changed / 变更 - Doc convention: all specs, implementation plans and cross-repo coordination docs now live in the monorepo `docs/` instead of per-repo `docs/superpowers/`; this supersedes the crearte-deploy 0.3.0 "canonical home" convention. Commits in the monorepo wrapper may go directly to `master` (user-approved); the three inner repos keep their own branch rules. - 文档约定:所有 spec、实现计划与跨仓库协作文档统一收归 monorepo `docs/`,不再散落各内层仓库的 `docs/superpowers/`;此约定取代 crearte-deploy 0.3.0 的「canonical home」约定。monorepo wrapper 可直接提交 `master`(维护者确认),内层三仓仍遵循各自分支规范。