Skip to content

feat(desktop): add scoped memory workflow preview - #1663

Open
knqiufan wants to merge 50 commits into
oceanbase:masterfrom
knqiufan:codex/desktop-preview
Open

knqiufan wants to merge 50 commits into
oceanbase:masterfrom
knqiufan:codex/desktop-preview

Conversation

@knqiufan

@knqiufan knqiufan commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Problem and result

PowerContext needs a Windows desktop client for connecting to an existing Server and saving, finding and reading scoped memories. This PR adds an unsigned internal preview with Chinese/English UI, connection management, Scope selection, memory workflows and local diagnostics.

Refs #1654, RFC #1455 and #1428. This preview does not close those issues.

Changes

  • Independent Tauri 2 + React/TypeScript workspace with light/dark/system themes and a persistent connection, Scope and identity bar.
  • Explicit connection activation; native TLS/endpoint validation, Windows vault or session-only credentials, generated OpenAPI/IPC contracts, and cancellation/invalidation of stale contexts.
  • Single-instance activation registered before profile storage initialization. Repeated launches show, restore and focus the existing window. A lifetime exclusive lock protects profile reads, writes and credential cleanup against concurrent owners, including startup races.
  • Scope title search with pagination. Successful selection changes the current Scope and closes the dialog; failures remain visible.
  • Plaintext notes limited to 8192 UTF-8 bytes, no Enter submission, unknown-write handling without automatic replay, full-text search capped at 10 results, and exact-version reading/copying using the complete citation.
  • Save callbacks are invalidated when their editor unmounts or its context changes. A completed old save cannot clear a new draft's navigation warning, including leaving and returning to the same Scope. The connection editor has the same protection. Dispatched writes retain their original native target and still refresh authoritative write metadata.
  • Responsive memory cards, contained result actions and independently scrolling bounded detail panels.
  • Fixed-command local diagnostics verify the registered executable/version/digest and contain owned helper processes. CLI versions 1.0.1 and 1.1.1 are supported by the adapter.
  • Desktop generation matches the upstream OpenAPI contract at 6e237568; the ten-operation allowlist is unchanged. The sqlite-6e237568-v1 compatibility profile records matching Server source, contract and qualification-wheel evidence.

User-facing changes

The installed UI launches without a local Server; business operations require a separately available Server and authorized Scope. Older compatibility selections require explicitly choosing the current qualified profile and rechecking the connection. Desktop does not introduce a public backend API, database migration, Server lifecycle management or Agent configuration changes.

Validation

  • pnpm --dir desktop lint, test (25 tests), typecheck, build and ipc:check.
  • Rust 1.95.0 MSVC: native suite (43 tests), formatting and Clippy with warnings denied.
  • Regression tests reproduce both reported failures on the original implementation: late-save draft protection and concurrent profile ownership.
  • Four real SQLite Server modes: anonymous loopback, Bearer, HTTPS with explicit CA/base path, and injected-provider/enforced access. The qualification wheel matches Server source 6e237568, with its SHA-256 recorded in the manifest.
  • Local Windows 11 NSIS installation and actual installed WebView2 acceptance: repeated launches preserve the editor, a delayed response from a committed Scope A save preserves Scope B's draft warning, save/search/exact reads, clipboard, connection isolation, byte/search limits, unknown outcomes without replay, and independent Server survival after forced Desktop termination. Reopening after forced exit preserves saved profiles. The existing minimized window also restores on a repeated launch.
  • Python acceptance-harness Ruff and Windows/Linux type checks; uv lock --check. Whole-repository hooks pass except pre-existing Windows platform diagnostics in unchanged code-understanding modules. Whole-repository Linux-targeted ty check passes.

Installed acceptance runs in the Desktop workflow's windows job. The installed-package job is manual-only and intentionally skipped for normal PR runs. See the current PR checks and desktop/VALIDATION.md for qualification scope and reproducible commands. Local test data, drivers and temporary reports are cleaned up; existing user data is preserved.

Remaining qualification

The package is unsigned. Clean standard-user Windows 11 with/without WebView2, actual IME/screen-reader/high-contrast and complete keyboard qualification, notification cold activation, named Agent capture/recall, release ownership and performance budgets remain open. Local and hosted-runner execution do not establish these remaining release gates.

AI usage statement

Implemented with OpenAI Codex under the contributor's direction, including UI changes, lifecycle and single-instance fixes, tests, review, local validation and packaging. Human maintainer review remains required.

@knqiufan knqiufan changed the title feat(desktop): add S1 native foundation and Windows CI feat(desktop): add native connections and diagnostics preview Sep 19, 2026
@knqiufan knqiufan changed the title feat(desktop): add native connections and diagnostics preview feat(desktop): add scoped memory workflow preview Sep 19, 2026
- Add a top context bar with the saved-connection menu, connection
  status pill, current scope entry, exact-scope dialog, and identity
  details; move scope selection into a modal hosting the existing
  Scopes component.
- Turn the home page into an overview: current connection facts,
  available features, honest unverified local-environment entries with
  a diagnostics entry point, and a getting-started guide.
- Restyle connections as a saved-profile list plus a detail panel with
  a credential block, replace-credential entry, and a grouped latest
  verification section; save, check, activate and remove stay separate
  explicit actions.
- Restyle memories into a save area, a search row with fixed
  full-text/limit indicators, and a results-plus-reader split view with
  a citation summary block; keep exact-citation reads, full-reference
  copy, and the unknown-write safeguards unchanged.
- Sync bilingual copy and update frontend tests and installed-suite
  locators to the new layout without dropping assertions.
fix(desktop): wrap memory hit actions so CJK titles never collapse
@CLAassistant

CLAassistant commented Sep 23, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@knqiufan
knqiufan force-pushed the codex/desktop-preview branch from 3501e4a to 72fd2c3 Compare September 23, 2026 06:03
@knqiufan
knqiufan marked this pull request as ready for review September 23, 2026 06:45
@knqiufan

knqiufan commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

补充 Desktop UI 实机截图,来自提交 051cfe74 的 Windows CI 安装包。以下为启动后尚未启用连接、尚未选择 Scope 的真实界面;保存与搜索按钮因此处于禁用状态。

总览

总览

连接

连接

记忆

记忆

@Teingi Teingi removed the 1.2.0 label Sep 27, 2026
Comment thread desktop/ui/src/app/MemoryWorkspace.tsx Outdated
Comment on lines +77 to +81
if (generation.current === original) {
setOutcome(result);
if (result.record.status === "succeeded") {
setText("");
onDirty(false);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If a save in Scope A finishes after switching to B and typing a new draft, its callback still calls onDirty(false). Leaving the page then silently discards B's draft. Please prevent callbacks from an unmounted form from changing the current draft's dirty state.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@PsiACE Understood. The issue has been fixed.Save callbacks are now invalidated when their editor unmounts or its context changes, so an old save cannot clear a new draft’s dirty state. Regression tests cover switching Scopes and leaving/reopening the same Scope.

Comment on lines +308 to +309
let mut next = self.document.clone();
next.profiles.retain(|p| p.id != id);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Each profile repository saves its entire in-memory snapshot. Two independently opened repositories can save Personal and Work successfully, but reopening leaves only Work. Please enforce the RFC's one-instance-per-user/channel rule before opening profile storage. The Tauri single-instance plugin may fit here.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@PsiACE Thanks for the suggestion, This issue has also been fixed. The Tauri single-instance plugin is now registered before profile storage is opened. Repeated launches restore and focus the existing window. The profile repository also holds an exclusive file lock for its lifetime to prevent concurrent owners during startup races. Regression tests and installed-client checks confirm that profiles and unsaved drafts are preserved.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants