Skip to content

fix(desktop): polish onboarding (Welcome / PasteKey / ChooseModel)#48

Closed
hqhq1025 wants to merge 2 commits intomainfrom
wt/polish-onboarding
Closed

fix(desktop): polish onboarding (Welcome / PasteKey / ChooseModel)#48
hqhq1025 wants to merge 2 commits intomainfrom
wt/polish-onboarding

Conversation

@hqhq1025
Copy link
Copy Markdown
Collaborator

Summary

Token-discipline polish on the three onboarding screens (sweep 2 of the page-by-page polish — full audit at docs/research/27-pages-polish-audit.md).

After Settings #45 and chain-rewrite #46 converged on the same --text-* / --space-* / --tracking-* recipes, the onboarding flow was the only main surface still mixing raw text-[24px] / text-[14px] / text-[11px] / h-[40px] / h-[28px] values. This PR aligns it.

Component-level changes

File What changed
onboarding/index.tsx (Stepper) Drop raw text-[11px] tracking-[0.05em] for --text-2xs + --tracking-label; add <span class="sr-only">Step N of M</span> so screen readers get progress; gate the dot-grow animation behind motion-safe:.
onboarding/Welcome.tsx Title goes text-[24px]--text-xl with --tracking-heading/--leading-heading; subtitle and "where to get key" caption move to the same recipe as PasteKey/Settings; provider links use --text-xs/--duration-fast. PathButton: motion-safe:hover:-translate-y + active:translate-y-0 press-down.
onboarding/ChooseModel.tsx Heading + description on shared recipe; ModelPicker chips bumped from h-[28px] to h-[var(--size-control-sm)] (32 px) to match the 40 px input rhythm and Settings; chips gain aria-pressed; cost/baseUrl notes align on --text-xs / --leading-ui.

Non-goals

  • No new copy, no new i18n keys (zero zh-CN audit needed).
  • No new tokens — every replacement uses tokens already in packages/ui/src/tokens.css.
  • No layout overhaul; 480 px container card untouched. PasteKey was already token-clean and is not modified.

Coverage report (rest of the polish sweep)

The companion audit docs/research/27-pages-polish-audit.md (gitignored) maps each surface to its in-flight PR. Backlog filed for: preview states (loading/empty/error), Toast, CommandPalette, inline-comment anchoring, cross-platform chrome, sidebar resize. Those overlap with wt/ux-loading-stages, wt/preview-ux-v2, wt/feat-mobile-frame and need to land before another polish pass.

Test plan

  • pnpm typecheck — clean.
  • pnpm lint — 0 errors (1 pre-existing complexity warning in packages/core).
  • pnpm --filter @open-codesign/desktop test — 138/138 pass.
  • Manual: launch onboarding in pnpm dev, walk Welcome → PasteKey → ChooseModel in EN and zh-CN, light + dark.

PRINCIPLES

  • ✅ Compatibility — render-only changes, no schema/IPC/contract touch.
  • ✅ Upgradeability — token-driven; future theme work flips one variable.
  • ✅ No bloat — net -8 LOC, no new deps.
  • ✅ Elegance — removes the last raw-px outliers the audit flagged for this surface.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

  • [Minor] Screen-reader step label is hardcoded in English, bypassing i18n — this introduces inconsistent accessibility language when users switch locale, evidence apps/desktop/src/renderer/src/onboarding/index.tsx:111
    Suggested fix:
    const t = useT();
    
    <span className="sr-only">
      {t('onboarding.stepper.progress', { current, total })}
    </span>

Summary

  • Review mode: initial
  • 1 issue found in added/modified lines.

Testing

  • Not run (automation)

open-codesign Bot

return (
<div className="flex items-center gap-2">
<div className="flex items-center gap-[var(--space-2)]">
<span className="sr-only">{`Step ${current} of ${total}`}</span>
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hardcoded English text in an accessibility label bypasses the language toggle. Please localize this string through useT() so screen readers follow the selected locale.

const t = useT();

<span className="sr-only">
  {t('onboarding.stepper.progress', { current, total })}
</span>

hqhq1025 added a commit that referenced this pull request Apr 18, 2026
Codex flagged a recurring i18n violation pattern across PRs #48 and #49: hardcoded
English ARIA strings bypass the i18n layer and ship inconsistent screen-reader
output to localized users. The toast close button was the last remaining
hardcoded aria-label outside the onboarding flow.

- Add common.dismissNotification key (en + zh-CN)
- Wire useT() into ToastItem and consume the new key
hqhq1025 added a commit that referenced this pull request Apr 18, 2026
Codex flagged a recurring i18n violation pattern across PRs #48 and #49: hardcoded
English ARIA strings bypass the i18n layer and ship inconsistent screen-reader
output to localized users. The toast close button was the last remaining
hardcoded aria-label outside the onboarding flow.

- Add common.dismissNotification key (en + zh-CN)
- Wire useT() into ToastItem and consume the new key
Token discipline pass on the three onboarding screens — all raw px sizes
swapped for the equivalent token utility, label/heading recipes aligned
across the flow, motion-safe variants applied to hover translates, and
chip control sized to --size-control-sm for visual rhythm with the input.

- index.tsx Stepper: drop raw text-[11px], use --text-2xs +
  --tracking-label; add screen-reader step count, motion-safe transition.
- Welcome: title bumped to --text-xl with --tracking-heading;
  subtitle/captions on token recipe; PathButton hover translate gated by
  motion-safe + active state for press feedback.
- ChooseModel: heading/description on shared recipe; ModelPicker chips
  bumped to h-[var(--size-control-sm)] (32 px) so the chip row matches
  the 40 px input rhythm; chips carry aria-pressed; cost/baseUrl notes
  on --text-xs / --leading-ui.

No new strings, no new tokens, no layout/visual restructuring — the
purpose is to align this surface with the same recipes Settings #45 and
the chain-rewrite #46 already converged on, so dark-mode + zh-CN behave
predictably.

PRINCIPLES:
- Compatibility: render-only changes, no schema/IPC touch.
- Upgradeability: tokens centralize for future theme work.
- No bloat: -8 LOC net.
- Elegance: removes raw-px inconsistencies the audit doc flagged.

Signed-off-by: hqhq1025 <1506751656@qq.com>
@hqhq1025 hqhq1025 force-pushed the wt/polish-onboarding branch from f0dc7c3 to f38953b Compare April 18, 2026 20:56
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

  • [Minor] Screen-reader progress text is hardcoded in English, bypassing i18n and causing accessibility language mismatch when users switch locale, evidence apps/desktop/src/renderer/src/onboarding/index.tsx:111
    Suggested fix:
    import { useT } from '@open-codesign/i18n';
    
    function Stepper({ current, total }: { current: number; total: number }) {
      const t = useT();
    
      return (
        <div className="flex items-center gap-[var(--space-2)]">
          <span className="sr-only">
            {t('onboarding.stepper.progress', { current, total })}
          </span>
          {/* ... */}
        </div>
      );
    }

Summary

  • Review mode: follow-up after new commits
  • 1 issue found in added/modified lines.

Testing

  • Not run (automation)

open-codesign Bot

return (
<div className="flex items-center gap-2">
<div className="flex items-center gap-[var(--space-2)]">
<span className="sr-only">{`Step ${current} of ${total}`}</span>
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hardcoded English text in an accessibility label bypasses the language toggle. Please localize this via so screen readers follow the selected locale.

@hqhq1025
Copy link
Copy Markdown
Collaborator Author

Superseded by #49 — overlapping onboarding scope. #49 is a strict superset (token cleanup + stepper role=progressbar a11y + Welcome motion-safe wrap + ChooseModel chip --size-control-sm). Closing to avoid conflicts.

@hqhq1025 hqhq1025 closed this Apr 19, 2026
hqhq1025 added a commit that referenced this pull request Apr 19, 2026
Codex flagged a recurring i18n violation pattern across PRs #48 and #49: hardcoded
English ARIA strings bypass the i18n layer and ship inconsistent screen-reader
output to localized users. The toast close button was the last remaining
hardcoded aria-label outside the onboarding flow.

- Add common.dismissNotification key (en + zh-CN)
- Wire useT() into ToastItem and consume the new key
hqhq1025 added a commit that referenced this pull request Apr 19, 2026
* feat(core): system prompt — adopt Claude Design patterns

Adds a new prompt section that embeds high-leverage craft directives
paraphrased from patterns observed in the publicly leaked Claude Design
system prompt. Direct response to feedback that generated designs are
sparse, generic, and monotone.

The new section sits between tweaks-protocol and anti-slop in the
composer, applies to all create/revise/tweak modes, and codifies:

- silent artifact-type classification (landing / dashboard / case study /
  pricing / deck / etc.) controlling section ladder and density target
- density floor — default to "rich", drop only on explicit "minimal"
- real, specific content — concrete bans on common placeholder strings
- before/after side-by-side rendering when comparison is implied
- big-number visual blocks (display weight + label + delta + sparkline)
- three-family typography ladder (display + sans + mono)
- dark-theme warmth requirements (accent + gradient + transparent borders)
- SVG monogram/wordmark for logos (no emoji, no flat circles)
- distinguished customer-quote treatment
- single-page structure ladder (hero → trust → 3-5 sections → focal →
  closing CTA), with dashboard and slide deck substitutions

Directives are independently authored — no original Claude Design text is
reproduced verbatim. Attribution and the underlying structural analysis
live in docs/research/15-claude-design-prompts.md (gitignored, internal).

Vitest coverage:
- new test asserts all ten directive headers appear in the create-mode
  composed prompt
- existing drift test ensures the new .txt and the inlined TS constant
  stay byte-identical

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(core): rename 'Claude-Design-style' → 'Craft directives' to remove provenance comment per codex review

Signed-off-by: hqhq1025 <1506751656@qq.com>

* test(core): cover revise mode for craft directives (PR #43 codex Minor)

* fix(desktop): replace hardcoded text-[Npx] with --text-* tokens in preview/inline-comment (#57)

Codex has flagged this exact pattern as a Blocker on PRs #50 and #51 ("hardcoded
pixel font size violates token-only UI constraint"). Sweeps the chat-adjacent
surface that is not covered by any in-flight worktree.

Mappings:
- text-[11px] -> text-[var(--text-xs)] (12px, closest token)
- text-[12px] -> text-[var(--text-xs)]
- text-[13px] -> text-[var(--text-sm)]

Files touched: InlineCommentComposer.tsx, PreviewToolbar.tsx, PreviewPane.tsx.
The bg-[rgba(255,255,255,0.88)] frosted pill in PreviewPane is left for a
follow-up because it requires a new translucent surface token.

* fix(desktop): localize Toast dismiss button aria-label (#56)

Codex flagged a recurring i18n violation pattern across PRs #48 and #49: hardcoded
English ARIA strings bypass the i18n layer and ship inconsistent screen-reader
output to localized users. The toast close button was the last remaining
hardcoded aria-label outside the onboarding flow.

- Add common.dismissNotification key (en + zh-CN)
- Wire useT() into ToastItem and consume the new key

* fix(desktop): tokenize ConnectionStatusDot tooltip values (#58)

* chore(desktop): biome auto-format InlineCommentComposer (unblock pre-push)

* fix(desktop): tokenize ConnectionStatusDot tooltip hardcoded values

* fix(desktop): tokenize LanguageToggle hardcoded sizes/spacing (#60)

* fix(desktop): tokenize LanguageToggle hardcoded sizes/spacing

* chore(desktop): biome format InlineCommentComposer (drive-by, unblocks pre-push)

* [Claude Design adoption] PR-B: examples gallery (#50)

* feat(hub): examples gallery as first-class section

PR-B from doc 28 (Claude Design adoption). Ships eight curated examples
(cosmic animation, organic loaders, landing page, case study, dashboard,
pitch slide, welcome email, mobile habit tracker) with stylised inline
SVG thumbnails, an `ExamplesTab` view component, and full en + zh-CN
translations for every title, description, category label, and surrounding
chrome.

The tab is self-contained: a single `onUsePrompt` prop hands the chosen
example back to the host so PR-A can wire it into the hub without further
plumbing. No App.tsx changes here — independent of PR-A landing first.

Compatibility ✅  Upgradeability ✅  No bloat ✅  Elegance ✅

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(hub): use --font-size-body-xs token for example card category badge

Replaces hardcoded text-[10px] with the existing --font-size-body-xs
typography token (11px). Resolves Codex token-only UI constraint blocker
on PR #50.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(templates): throw on missing locale content for examples (no silent fallback)

Codex blocker on PR #50: getExamples returned `{ title: id, description: '' }`
when both the requested locale and the en fallback lacked an entry, shipping
degraded UI without surfacing the bug.

- Throw a descriptive Error when no registry has the example id
- Add vitest case asserting the throw path
- Drive-by: biome format apps/desktop/src/renderer/src/components/InlineCommentComposer.tsx
  (pre-existing format drift on main blocking pre-push)

Signed-off-by: hqhq1025 <1506751656@qq.com>

---------

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): tokenize PreviewToolbar values missed by #57 (#62)

* fix(desktop): tokenize remaining PreviewToolbar hardcoded values missed by #57

Replaces three remaining hardcoded px values in PreviewToolbar with design
tokens to keep the export menu aligned with the token system:
- h-[30px] → h-[var(--size-control-sm)]
- w-[14px] h-[14px] → w-[var(--size-icon-sm)] h-[var(--size-icon-sm)]
- min-w-[200px] → min-w-[var(--size-stage-min)]

Adds a new --size-stage-min (200px) token to packages/ui for menu/popover
minimum widths. The other three font-size values noted in the original
audit were already tokenized by #57.

* chore: format Download icon and silence pre-existing core complexity lint

- Wrap PreviewToolbar Download icon across multiple lines per Biome formatter
- Add biome-ignore for pre-existing noExcessiveCognitiveComplexity in
  packages/core/src/index.ts runModel (blocks pre-push hook; refactor
  tracked separately, mirrors the precedent set in 9051fae)

* fix(desktop): drop unused fileURLToPath import in main entry (#63)

* fix(desktop): PreviewPane hint pill + iframe respect dark mode (#69)

Co-authored-by: Claude <noreply@anthropic.com>

* fix(desktop): i18n ThemeToggle aria/tooltip strings (#70)

Replace hardcoded English with t() calls; add theme.{toggleAria,switchToLight,switchToDark} to en.json and zh-CN.json.

Co-authored-by: Claude <noreply@anthropic.com>

* fix(desktop): tokenize raw utilities in preview Loading/Error states (#64)

* fix(desktop): tokenize raw utilities in preview Loading/Error states

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): tokenize space-y-3 in LoadingState skeleton header

Signed-off-by: hqhq1025 <1506751656@qq.com>

---------

Signed-off-by: hqhq1025 <1506751656@qq.com>

* feat(desktop): Snapshots SQLite schema + IPC handlers (PR-A) (#29)

* feat(desktop): snapshots SQLite + IPC foundation (PR-A of version history)

- packages/shared: DesignSnapshotV1 + DesignV1 Zod schemas, SnapshotCreateInput interface
- apps/desktop: better-sqlite3 persistence (designs + design_snapshots tables, WAL, FK cascade)
  initSnapshotsDb(path) for production, initInMemoryDb() for tests
- snapshots:v1:* IPC handlers: list-designs, create-design, list, get, create, delete
  All reject malformed payloads with CodesignError('IPC_BAD_INPUT')
- preload: window.codesign.snapshots namespace bridged to renderer
- Vitest: 26 new tests across snapshots-db + snapshots-ipc (111 pass total)

New dep: better-sqlite3@^11 (MIT, native, already in CLAUDE.md stack)
No ulid added — using crypto.randomUUID() instead.

PR-B will wire auto-snapshot-on-sendPrompt + history sidebar UI.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* style(desktop): fix biome formatting in snapshots-db.test.ts

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): address codex snapshots cascade/parent/sort findings

- Enable PRAGMA foreign_keys = ON in applySchema so ON DELETE CASCADE
  / SET NULL fire in production (previously only the test enabled it
  manually, hiding the regression).
- Constrain design_snapshots.parent_id with a self-referential FK
  (ON DELETE SET NULL) and validate in the IPC layer that parentId
  resolves to a snapshot in the same design — prevents silent history
  corruption from stale or cross-design ids.
- Sort listDesigns by updated_at DESC, created_at DESC so designs
  bubble after new snapshots are added (createSnapshot already bumps
  updated_at).
- Drop the now-redundant manual pragma in the cascade test and add
  coverage for parent SET NULL, cross-design parent rejection, and
  the activity-based design sort.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): reject invalid create-design input instead of silent default

The snapshots:v1:create-design IPC handler coerced empty/non-string payloads to 'Untitled design', hiding caller bugs and violating the no-silent-fallback rule. Reject with IPC_BAD_INPUT instead, drop the matching preload coercion, and update tests to cover the new contract.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): translate SQLite errors to typed IPC contract in snapshots-ipc

Wraps every snapshot DB call in a translateSqliteError helper that maps
better-sqlite3 SqliteError codes to typed CodesignError instances:

- SQLITE_CONSTRAINT_FOREIGNKEY -> IPC_BAD_INPUT
- SQLITE_BUSY / SQLITE_LOCKED  -> IPC_DB_BUSY
- SQLITE_FULL                  -> IPC_DB_FULL
- other                        -> IPC_DB_ERROR (full details logged server-side)

Renderer no longer sees raw provider error strings. Adds vitest cases that
stub better-sqlite3 prepare() to throw each code and assert the right
CodesignError is surfaced.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(snapshots-ipc): map SQLite constraint subcodes individually

Bare SQLITE_CONSTRAINT also covers UNIQUE / NOT NULL / CHECK violations,
so translating it as "Parent snapshot does not exist" misled the UI on
unrelated failures. Match each subcode explicitly:

- SQLITE_CONSTRAINT_FOREIGNKEY  -> IPC_BAD_INPUT, parent-snapshot message
- SQLITE_CONSTRAINT_UNIQUE/PK   -> IPC_CONFLICT, "Snapshot already exists"
- SQLITE_CONSTRAINT_NOTNULL/CHECK -> IPC_BAD_INPUT, neutral constraint message
- bare SQLITE_CONSTRAINT (no suffix) -> generic IPC_DB_ERROR

Adds vitest coverage for each new branch.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(snapshots-ipc): clarify FK error covers design and parent

SQLITE_CONSTRAINT_FOREIGNKEY fires for both a missing design_id and a
missing parent_id, but the previous translation always reported "Parent
snapshot does not exist" — leading contributors to look for the wrong
cause. Key the FK message by call-site context and use a message that
names both columns ("Referenced design or parent snapshot does not
exist"); fall back to a generic "Referenced item does not exist" for
unmapped contexts.

Also extracts the static SQLite-code lookup into a small helper to keep
translateSqliteError below the cognitive-complexity threshold.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): schema-version snapshots:v1 IPC payloads

Every snapshots:v1:* object payload now carries `schemaVersion: 1`, both
on the wire (preload bridge) and in the main-process parser. Mismatched
or missing versions throw IPC_BAD_INPUT so future handler revisions can
break cleanly instead of silently mis-parsing legacy callers.

- snapshots-ipc.ts: requireSchemaV1() helper applied to list-designs,
  list, get, create, delete, create-design (now object-shaped).
- preload/index.ts: every snapshots invoke wraps the payload with
  { schemaVersion: 1, ... }.
- snapshots-ipc.test.ts: updated existing fixtures via a v1() helper and
  added a parameterised gating suite that asserts every channel rejects
  missing and mismatched schemaVersion values.

Addresses Codex Major review on PR #29.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): degrade gracefully when snapshots DB init fails

Previously initSnapshotsDb() ran inside app.whenReady() without a guard,
so any open/migration/native-binding failure rejected the boot promise
and prevented createWindow() from ever firing — the user got a silent
no-window app.

Add safeInitSnapshotsDb() wrapper that captures the error, then in main
boot: log it with full stack via electron-log, surface it through
dialog.showErrorBox, skip registerSnapshotsIpc, and continue to open
the window. Snapshot-dependent renderer features will fail loudly via
their IPC channels, but the rest of the app stays usable.

Also reset the singleton if applySchema throws so a retry can recover
instead of returning a half-open DB handle.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): typed SNAPSHOTS_UNAVAILABLE stub when snapshots DB init fails

When safeInitSnapshotsDb fails at boot, main/index.ts previously skipped
registerSnapshotsIpc entirely. Renderer calls to window.codesign.snapshots.*
then surfaced as Electron's opaque "No handler registered" rejection,
violating the no-silent-fallback / error-context requirement (PR #29 codex
Major).

Install registerSnapshotsUnavailableIpc stubs for the same channel set so
every renderer call rejects with a typed CodesignError carrying code
SNAPSHOTS_UNAVAILABLE and a message pointing the user at Settings → Storage.
The channel list is exported (SNAPSHOTS_CHANNELS_V1) so the test can pin
it to the live registration set and prevent drift.

Adds vitest coverage that asserts SNAPSHOTS_UNAVAILABLE is thrown for every
channel and that the stub set matches registerSnapshotsIpc exactly.

Signed-off-by: hqhq1025 <1506751656@qq.com>

---------

Signed-off-by: hqhq1025 <1506751656@qq.com>

* feat(exporters): Markdown export of generated artifact (#66)

* feat(exporters): add Markdown export with simple HTML→MD conversion

Adds a tier-1 Markdown exporter (.md with YAML frontmatter carrying
schemaVersion: 1). Conversion is a small set of regex passes covering
h1..h6, p, a, img, ul/ol, strong/em, code/pre — anything else is
stripped. Zero new runtime deps.

Wired through the existing exporter IPC + Preview toolbar Export menu,
with en + zh-CN i18n strings.

Compatibility ✅  Upgradeability ✅  No bloat ✅  Elegance ✅

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(exporters): allowlist URL schemes in markdown export

Sanitize <a href> and <img src> during htmlToMarkdown so unsafe schemes
(javascript:, vbscript:, file:, non-image data:, etc.) cannot ride into
the exported .md and execute via downstream renderers. Allow http(s),
mailto, relative URLs, fragments; permit data:image/* only on <img>.
Unsafe links collapse to plain text, unsafe images are dropped.

Also fix the IPC default extension for the markdown format (`design.md`
instead of `design.markdown`) when no defaultFilename is provided.

Addresses codex review on PR #66.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(exporters): close encoded-scheme bypass in markdown sanitizeUrl

Decode HTML entities (named, hex, decimal), URL %escapes, and strip
control characters (TAB/CR/LF/etc.) before scheme allowlisting so
payloads like &#x6A;avascript:, %6Aavascript:, JavaScript:, and tab-
prefixed schemes can no longer slip through the link/image sanitizer.

Adds regression tests covering each bypass vector.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(exporters): only decode scheme prefix in sanitizeUrl

The previous follow-up ran decodeURIComponent on the entire URL which
both threw on legitimate inputs containing literal `%` (dropping the
link entirely) and rewrote percent-escaped path/query characters such
as %2F or %C3%A9. Restrict entity + percent decoding to the scheme
portion (before the first colon) used solely for the safety check, and
emit the original (control-stripped, trimmed) URL when the scheme is
allowlisted.

Adds regression tests for %2F in query, UTF-8 percent-escapes in path,
literal trailing %, and confirms the existing entity / %-encoded
javascript bypass guards still strip dangerous schemes.

Signed-off-by: hqhq1025 <1506751656@qq.com>

---------

Signed-off-by: hqhq1025 <1506751656@qq.com>

* [Claude Design adoption] PR-A: designs hub + multi-type create wizard (#51)

* feat(desktop): designs hub + multi-type create wizard (Claude Design adoption PR-A)

Replaces the straight-to-composer launch flow with a designs hub modeled on
Claude Design's Recent / Your designs / Examples / Design systems navigation
plus a typed create wizard (Prototype / Slide deck / From template / Other).

- Hub view with four sibling tabs and a primary "New design" CTA
- Modal create flow; CTA stays disabled until a project name is provided
- Per-type forms; PR-F will fill in the wireframe vs high-fidelity cards
- Examples and Design systems tabs ship as placeholders for PR-B / PR-C
- Project schema lives in shared with schemaVersion=1; persisted to
  localStorage for now (SQLite migration arrives with PR-C)
- Full en + zh-CN coverage; tokens from packages/ui (no hardcoded values)
- Vitest covering the create-draft logic; existing 144-test suite untouched

Compatibility: green - no IPC/main changes, no schema breaks.
Upgradeability: green - schemaVersion field on every Project payload.
No bloat: green - no new dependencies; reuses lucide-react + zustand.
Elegance: green - single store action per intent; per-type forms < 40 LOC.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): surface project storage errors via toast + warn (no silent fallback)

- readStoredProjects/persistProjects now console.warn and return an error
  string instead of swallowing exceptions; createProject pushes an error
  toast on persist failure while keeping in-memory state consistent.
- Validate stored projects with the Project zod schema (safeParse) and
  count rejected records so corrupted entries surface a toast instead of
  silently disappearing.
- openProject resets project-scoped workspace state (messages, preview,
  inputs, generation flags) to prevent cross-project state leakage.
- Add errors.projectStorageFailed i18n key (en + zh-CN).
- Vitest: mock localStorage.setItem to throw, assert toast pushed and the
  new project is still added to in-memory state.

Addresses Codex blocker on PR #51.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): replace hardcoded checkbox sizing with --size-icon-md token

SlideDeckForm checkbox used `w-4 h-4` literals which violate the
token-only UI constraint. Swap to `var(--size-icon-md)` (16px) so the
control scales with centralized theming.

Addresses Codex blocker on PR #51.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* chore: clear pre-existing biome errors blocking pre-push hook

- tailwindExtractor: replace non-null assertion with safe cast
- InlineCommentComposer: apply formatter

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): wire ExamplesTab onUsePrompt after rebase onto PR-B

PR-B merged ExamplesTab as a real component requiring an onUsePrompt
callback. After rebase, surface that prop through HubView and have App
prefill the workspace prompt + switch view.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): reset project-scoped workspace state in createProject

createProject was only clearing messages/previewHtml/generationStage,
leaving inputFiles, referenceUrl, selectedElement, lastPromptInput,
and generation/error flags inherited from the previously open project.
Mirror openProject's full reset so a freshly created project starts
with a clean workspace and prompt context.

Adds vitest coverage for the reset.

Refs codex review on PR #51.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(ui): replace hardcoded sizing in hub/create with new tokens

PR-A introduced raw arbitrary-value Tailwind classes (360px sidebar,
560px modal, 60ch prose, 240px card minimum, 1px hover lift) that
violate the token-only constraint in CLAUDE.md. Add five tokens to
packages/ui/src/tokens.css and route every call site through them so
themes and density tweaks stay centralized.

---------

Signed-off-by: hqhq1025 <1506751656@qq.com>

* feat(core): Skills system foundation — loader + 4 starter skills (#33)

* feat(core): skills loader + 4 starter skills + provider injector (PR-A)

- packages/shared/src/skills.ts: SkillFrontmatterV1 zod schema + LoadedSkill
  interface (canonical location; avoids core→providers circular dep)
- packages/core/src/skills/: inline YAML frontmatter parser, loadSkillsFromDir,
  loadAllSkills with 3-tier priority (project > user > builtin), loader tests
- packages/core/src/skills/builtin/: 4 starter skills (frontend-design-anti-slop,
  pitch-deck, data-viz-recharts, mobile-mock) — self-written, Apache-2.0, no
  Anthropic SKILL.md text copied
- packages/providers/src/skill-injector.ts: injectSkillsIntoMessages, pure,
  supports system and prefix scope, provider-wildcard matching, injector tests

No new runtime deps added. Inline YAML parser (~100 lines) handles folded
scalars, nested mappings, inline + block sequences.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(core): skills loader collects errors and throws instead of silent drop

Replace the three silent continue/console.warn paths in loadSkillsFromDir
with error collection; after processing all files, throw CodesignError
'SKILL_LOAD_FAILED' if any errors were accumulated. Update tests to
expect the throw, and add a new loadAllSkills test for a broken skill
(missing description field).

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(core): propagate non-ENOENT errors in skills loader

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(providers): sort skills into canonical order before injection

Mixed-scope skill injection was order-dependent: whichever skill
appeared first in the caller's array decided whether the block went
into the system prompt or the first user message. That made
prompt-shaping behaviour a function of loader iteration order rather
than the active skill set.

Sort skills by source precedence (project > user > builtin) and then
alphabetical name before building the block. The chosen scope, the
concatenated body, and the resulting prompt blob are now byte-identical
across runs regardless of input order, which also stabilises prompt
caching and snapshot tests.

Adds a vitest case that feeds three random permutations of a five-skill
fixture and asserts the resulting system content is byte-identical to
the canonical sort, plus a mixed system/prefix scope test that confirms
the higher-precedence skill picks the channel.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(providers): inject mixed-scope skills into separate channels

Previously a mixed system/prefix skill set was concatenated into a single
block and injected via the highest-precedence skill's channel, silently
routing the rest into the wrong channel and violating each skill's
trigger.scope contract. Now we partition active skills by scope and
inject system-scope skills into the system message and prefix-scope
skills into the first user message, preserving canonical order within
each channel.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(core): preserve newlines in YAML literal block scalar (PR #33 codex Minor)

---------

Signed-off-by: hqhq1025 <1506751656@qq.com>

* feat(desktop): viewport switcher (desktop / tablet / mobile with phone bezel) (#32)

* feat(desktop): mobile/tablet/desktop viewport preview with phone bezel

- Add PreviewViewport type and previewViewport/setPreviewViewport to store
- Add PhoneFrame component (CSS-only iPhone bezel, fully tokenised)
- Add viewport switcher (Desktop/Tablet/Mobile) to PreviewToolbar
- PreviewPane renders iframe inside PhoneFrame at 375x812 for mobile,
  centred 768px container for tablet, and full-width for desktop
- Add preview.viewport i18n keys (en + zh-CN)
- Add 4 unit tests for setPreviewViewport in store.test.ts

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(ui): tokenize phone frame dimensions + give tablet wrapper a height

Replace hard-coded px values in PhoneFrame with CSS custom properties from
packages/ui tokens.css. Add --size-preview-mobile-*, --size-preview-tablet-width,
--radius-phone, and --border-width-strong tokens. Fix tablet branch in
PreviewPane to propagate h-full so the iframe is no longer zero-height.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(ui): tokenize preview viewport sizes (mobile/tablet/desktop)

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(ui): tokenize preview hint badge color/size

Address Codex blocker re-flagged on PR #32:
- Replace hardcoded values in PreviewPane hint badge (left-5/top-5,
  bg-[rgba(255,255,255,0.88)], px-3/py-1, text-[11px]) with
  --space-5/--space-3/--space-1, --color-surface-elevated, --text-xs.
- Replace hardcoded sizes/motion in PreviewToolbar viewport controls
  and Download button (w-[14px], w-[30px], h-[30px], duration-150,
  literal cubic-bezier) with --size-icon-sm, --size-control-xs,
  --duration-fast, --ease-out.
- Add tokens: --color-surface-elevated (light + dark),
  --size-control-xs (30px), --size-icon-sm (14px).

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(ui): tokenize PhoneFrame border + remaining hardcoded values

Replace hard-coded `outline: '1px solid ...'` with the existing `--shadow-inset-soft` token composed into boxShadow. Removes the last non-tokenized value in PhoneFrame so the component is fully driven by packages/ui tokens.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(ui): make PhoneFrame notch overlay click-through (pointer-events: none)

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): add aria-label to viewport switcher buttons

title alone is not a reliable accessible name for screen readers;
add aria-label using the same i18n string so assistive tech announces
Mobile/Tablet/Desktop instead of a generic button.

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(desktop): tokenize iframe background in mobile preview (PR #32 codex Major)

* fix(desktop): tokenize desktop preview iframe bg + dedup icon size tokens (PR #32 codex follow-up)

---------

Signed-off-by: hqhq1025 <1506751656@qq.com>

* fix(core): exclude craft-directives from tweak mode (PR #43 codex Major)

---------

Signed-off-by: hqhq1025 <1506751656@qq.com>
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant