Commit Graph

28 Commits

Author SHA1 Message Date
Claude a8c7b98922
스팸/도배 감지 최소 버전(2.7-C) 구현: 대화방 단위 자동 응대 일시중단 + 재개
PRD.md §4 엣지케이스가 "안전 관련이라 v1 최소 버전 필요"로 명시한 항목(P0)인데
관련 로직이 0건이었던 마지막 콘텐츠 갭(roadmap.md §2.7-C, deploy-checklist.md
N4-C3a/b)을 채운다. Track C(콘텐츠 갭) A/B/C 전체 완료.

- core-backend/flood_detect.go(신규): floodMessageThreshold=5건 /
  floodWindow=2분 상수 + floodDetected()/floodReason(). 안전을 위해 반드시
  있어야 하는 기술적 최소값이라 명시적으로 placeholder로 남기고 구현했다 —
  roadmap.md §3의 "PoC 결과가 있어야 정할 수 있는 것"(자율성 기본값 등 UX
  기본값)과는 성격이 다름. 카운트는 대화방 내 sender_id != 소유자인 메시지만
  집계(트윈 자동발송·소유자 본인 발송은 소유자 ID로 남으므로 자동 제외).
- core-backend/main.go: POST /conversations/:id/messages 하드게이트에
  peer-veto → 그룹 대화 차단 다음, 에스컬레이션 체크 이전 지점으로 추가 —
  트윈 자동발송 시도가 전부 지나가는 동일한 우회 불가 지점. 이미
  TwinDisabledByFlood가 켜져 있으면 재계산 없이 즉시 차단(중복 로그/쿼리
  방지). 새로 임계치를 넘기면 대화방을 영구 차단하고 EscalationLog 기록 +
  notifyUser 푸시.
- core-backend/models.go: Conversation.TwinDisabledByFlood 필드 추가.
  TwinDisabledByPeer(거부권, 사람의 일방적 선택 — v1엔 되돌리기 API 없음)와
  달리 이건 시스템이 자동으로 취하는 조치라서 AGENTS.md "every automatic
  action needs post-hoc notification + one-tap undo"가 그대로 적용됨 —
  POST /conversations/:id/flood-reset로 되돌릴 수 있게 별도 필드로 분리.
- core-backend/a1_a2_routes.go: GET /conversations 응답에
  twin_disabled_by_flood 추가(twin_disabled_by_peer와 동일한 자리).
- core-backend/flood_detect_test.go(신규): 임계치 경계값(정확히 N건은
  통과, N+1건은 차단), 사람 발송은 게이트 안 걸림, 윈도우 밖 과거 메시지는
  집계 제외, flood-reset으로 재개, 존재하지 않는 대화방 404 — 5개 테스트.
- mobile/lib/models/models.dart, services/api_client.dart: 모델·API
  클라이언트에 twinDisabledByFlood/resetFlood() 추가.
- mobile/lib/screens/conversation_list_screen.dart: 대화 목록에 도배 차단
  배지(거부권과 같은 자리, 다른 아이콘/문구).
- mobile/lib/screens/chat_screen.dart: 채팅방을 열면(목록에서 넘어온 초기
  상태) 또는 발송 시도가 다시 차단되면 배너에 "자동응대 재개" 버튼을 보여줌
  — one-tap undo. 새 알림 메커니즘을 만들지 않고 기존 EscalationLog/
  InboxScreen을 그대로 재사용.
- mobile/test/models_test.dart: twin_disabled_by_flood 파싱 테스트 추가.
- docs/roadmap.md §2.7-C, docs/deploy-checklist.md N4-C3a/b·Track C 요약·
  "바로 다음 5개"를 완료로 갱신.

테스트: go test ./... 51/51, python3 -m pytest tests/ -q 47/47,
flutter analyze 클린 + flutter test 5/5 모두 통과.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014YSB5PqF38raTxP5ABgr9m
2026-08-03 05:12:29 +00:00
Claude 73dfa2c33c
Merge remote-tracking branch 'origin/main'
# Conflicts:
#	docs/deploy-checklist.md
2026-08-03 05:00:58 +00:00
Claude 5733ec4399
관계별 페르소나(2.7-B) 구현: 관계 티어 필드 + 온보딩/연락처 UI + 톤 프롬프트 분기
PRD.md §2.1-②·§3.1 P0 갭 우선순위 #2. close/formal 2종 관계 티어를 추가하고,
초안 생성 시 상대별 톤을 다르게 낸다.

- core-backend: TwinSettings.RelationshipTier(전역 기본값, 안전 우선 formal
  기본), Contact.RelationshipTier(1:1 연락처별 오버라이드, nullable).
  persona.go의 resolveRelationshipTier()가 연락처 오버라이드 → 전역 기본값 →
  formal 순으로 해석하고, 그룹 대화는 상대가 여럿이라 항상 전역 기본값만 사용.
  POST /conversations/:id/draft는 기존에 인증을 요구하지 않던 동작을 깨지
  않도록 currentUser(..., false)로 선택적 인증 처리 후 티어를 주입.
- 안전 관련 부수 수정: 그룹 대화에서는 전역 자율성 레벨(L1/L2)과 무관하게
  와카뷰 자동 발송을 무조건 차단(단톡 따라잡기는 L0 고정이 맞음).
- ai-service: RELATIONSHIP_TIER_INSTRUCTIONS + system_prompt_for_tier()로
  Gemini system_instruction에 관계 톤 지침을 주입. 에스컬레이션/정체성 게이팅
  로직은 티어와 무관하게 그대로 유지.
- mobile: 온보딩(말투 샘플 다음 단계)과 자율성 설정 화면에 전역 기본값
  SegmentedButton, 연락처 추가/수정 다이얼로그에 _RelationshipTierPicker로
  상대별 오버라이드 추가.
- 테스트: core-backend persona_test.go 6개(해석 순서·그룹 예외·비인증
  기본값 포함), ai-service 6개(system_prompt_for_tier + draft_reply 경로)
  전부 추가, 기존 스위트 모두 통과(go test, pytest 47/47, flutter analyze/test).
  실제 Flutter 빌드 + Playwright로 온보딩→연락처 오버라이드→목록 표시까지
  전체 라운드트립 시각 검증 완료.
- docs: roadmap.md §2.7-B, deploy-checklist.md N4-C2a~d 완료 처리. 다음
  우선순위는 Track C3(스팸/도배 감지 최소 버전).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014YSB5PqF38raTxP5ABgr9m
2026-08-03 04:59:34 +00:00
Cursor Agent 9d2e7ec621
docs: mark iMessage theme and C1 production deploy done
Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-08-03 04:32:18 +00:00
Cursor Agent 1897dde10e
feat(ui): iMessage-inspired light default + soft charcoal dark
Default ThemeMode.light with white messenger stage, blue mine bubbles,
and gray peer bubbles. Dark theme uses elevated charcoal instead of
pure black; composer and CTAs follow common messenger patterns.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-08-03 04:29:15 +00:00
Claude 0d848bcb9a
Merge remote-tracking branch 'origin/main'
# Conflicts:
#	docs/deploy-checklist.md
2026-08-03 03:18:13 +00:00
Claude 64323b824e
feat: implement 단톡 따라잡기 (group catch-up summary) — roadmap.md §2.7-A
Closes the biggest content gap found against PRD.md §3.1 P0: group chat
catch-up was one of only two v1 MVP scenarios and had zero implementation.

Backend (core-backend):
- ConversationParticipant.LastReadMessageID read marker.
- POST /conversations/:id/read advances the caller's marker (never backward).
- GET /conversations/:id/summary builds context from messages since that
  marker and calls ai-service's new POST /summarize; returns unread_count
  and needs_reply.
- GET /conversations now reports unread_count per room.
- Safety: group conversations now unconditionally block twin-authored
  sends (POST /conversations/:id/messages), regardless of the sender's
  global autonomy level. PRD.md §2.3-③ requires this scenario stay L0-fixed
  with no auto-send; autonomy level is a per-user global setting today, so
  this closes the only path a global L2 whitelist match could otherwise
  auto-send into a group.

AI service (ai-service): new summarize.py module (same Gemini-call shape as
generation.py's draft_reply, no escalation/identity gating since nothing
generated here is ever sent) + POST /summarize.

Mobile: "새 대화" dialog now supports adding/removing multiple peer fields
(2+ peers -> is_group:true automatically); unread badge on conversation
rows; ChatScreen takes isGroup and renders its L1 panel as L0-locked for
groups; new "안 본 동안 요약" AppBar action opens a dialog with the summary
and, when a reply looks needed, a button that feeds straight into the
existing draft-request flow.

Verified with a real Flutter build against a live core-backend + ai-service
instance (Playwright driving 3 demo accounts through group creation, unread
badges, and the summary dialog) — this caught a real ordering bug: marking
the read marker on chat *open* meant the summary was always empty by the
time you could tap it, since opening the room already advanced the marker
past everything you'd come to catch up on. Fixed by marking read on screen
*exit* (dispose) instead, so the marker reflects what was unread that whole
visit and updates once you leave.

go test / pytest / flutter analyze+test all pass.
2026-08-03 03:16:54 +00:00
Cursor Agent 0aae8fb578
docs: mark Soft Neutral production web deploy done
msn.iykyka.com rebuilt from e05a0f0 after dual-push to Gitea.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-08-03 02:45:07 +00:00
Claude be9d5be7fe
Merge remote-tracking branch 'origin/main'
# Conflicts:
#	docs/deploy-checklist.md
2026-08-03 02:22:45 +00:00
Claude 497c0ab537
docs: add PRD content-gap checklist (단톡 따라잡기, 페르소나, 스팸 감지)
PRD.md §3.1 lists 10 P0 features for v1; cross-checking the actual code
against that table found three that are fully unimplemented despite being
required scope, not deferred PoC defaults:

- 단톡 따라잡기 (group catch-up summary) — one of only two v1 MVP
  scenarios, currently 0%: no summary endpoint, no AI-service logic, no
  client UI, and the "new conversation" dialog can't even create a group
  (server already supports is_group + multiple user_ids).
- 관계별 페르소나 (relationship-tier tone, min. 2 tiers) — TwinSettings
  only has AutonomyLevel, no tier concept anywhere.
- 스팸/도배 감지 — PRD explicitly calls this out as needing a v1-minimum
  version for safety, not deferred; nothing implemented.

Added as roadmap.md §2.7 (workstream breakdown, priority A→B→C) and
deploy-checklist.md N4 Track C (mirrors Track A/B's format), cross-linked.
Explicitly scoped out image/file sending, read receipts, and typing
indicators as a separate "not proposed, PRD scope change needed" note,
since AGENTS.md requires calling out in-scope vs future-phase ideas.
2026-08-03 02:20:27 +00:00
Cursor Agent e05a0f07ce
docs: note Soft Neutral main merge; prod web rebuild pending SSH
GitHub main is at 553cb62; gitea dual-push and msn.iykyka.com web rebuild
still need host credentials in this environment.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-08-03 02:11:35 +00:00
Cursor Agent ca4aeb059d
feat(ui): Quiet Ink redesign — teal accent, light/dark
Replace aurora-glass purple with a calm messenger system: off-white/
charcoal canvas, Plus Jakarta Sans, solid teal CTAs, and quieter
panels across signup, chats, contacts, inbox, and settings.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 09:01:57 +00:00
Claude f470dd473c
docs: log the aurora-glass UI redesign in deploy-checklist.md
Keeps deploy-checklist.md's DONE list in sync with the actual UI redesign
work per AGENTS.md's "Phase 1 앱 빌드 작업 규칙". Also flags that this
pushed to GitHub main but has not been redeployed to the live
msn.iykyka.com production host, since this session has no access to that
host (deploy runs via scripts/server-up.sh on the iykyka box itself).
2026-07-31 09:01:12 +00:00
Cursor Agent ef73b93d83
feat(fcm): send pushes via HTTP v1 service account
Prefer FCM_SERVICE_ACCOUNT_FILE/JSON over legacy FCM_SERVER_KEY,
mount secrets/ into core-backend, and document Master JSON placement.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 07:33:23 +00:00
Cursor Agent 82a5809d4e
feat(n4): wire FCM token path and document Master secrets
Add PushTokenService with Firebase Messaging fallback to install
placeholders, conditional google-services Gradle plugin, fcm-setup.md,
and mark Android UI checklist api-done via prod e2e 16/16.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 04:51:57 +00:00
Cursor Agent fea1b555b4
docs: mark Track B production deploy done
N4-B4 verified: /demo returns pairing_steps on msn.iykyka.com.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 04:46:07 +00:00
Cursor Agent c7029ab2cd
feat: finish Track A polish and Track B demo pairing content
Add PATCH contact for missing peer IDs, contacts banner and edit UI,
enrich /demo with pairing steps, and update tester/signup guidance.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 04:43:25 +00:00
Cursor Agent fdd02d8252
docs: mark Track A production web rebuild done
N4-A5 verified on msn.iykyka.com after deploying 3d00b00.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 04:38:39 +00:00
Cursor Agent 3d00b00de7
feat(mobile): Track A messenger UX — ID chip, contacts chat, L0 draft
Show/copy numeric user ID, require peer ID for contacts, start chat in one tap,
clarify empty states, and route L0 twin drafts into the human composer.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 04:36:41 +00:00
Cursor Agent d614d9e5c4
docs: record Gemini key live on msn.iykyka.com (draft status=ok)
Server ai-service recreated with GEMINI_API_KEY; live draft smoke passed.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 04:19:44 +00:00
Cursor Agent 9065479e87
docs(ops): complete N3 stabilize — backup, tester guide, smoke results
Record invite/metrics/dashboard/draft(no_key) checks, pg_dump restore
rehearsal, and tester-facing guide for msn.iykyka.com.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 04:06:09 +00:00
Cursor Agent d60da60981
feat(deploy): cut over msn.iykyka.com to Ykavu compose stack
Attach web to nginx-proxy_default; record live cutover (NPM host #7,
old MSN stopped) and mark N2-B8–B12 done.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 03:08:34 +00:00
Cursor Agent 0a33ff3bcc
docs: mark N2-B8–B12 blocked pending SSH/Portainer access
Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 02:31:49 +00:00
Cursor Agent 4a39bc7b7d
feat(deploy): Docker Compose stack for msn.iykyka.com (N2-B)
Add Postgres + internal AI + core-backend + Flutter web (nginx API/WS
proxy). Document Portainer usage and env template; mark N2-B1–B7 done.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 02:26:40 +00:00
Cursor Agent c7e70ac18b
docs: mark N1 smoke done (E2E 16/16, DEMO-YKAVU)
Record local smoke results after restarting core-backend on current main.
Document msn.iykyka.com CORS/API change list for N1-6; next is N2-B Docker.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 02:13:51 +00:00
Cursor Agent e7a1233f84
docs: confirm N2-A1/A3–A6 deploy decisions
Master: replace old MSN, AI internal-only, Web-first client, secrets in
Portainer/env only, ALLOW_DEMO_INVITE on for testers. N2-A complete.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 02:08:03 +00:00
Cursor Agent 3a8b5b1a76
docs: confirm N2-A2 production DB as PostgreSQL
Master decision: msn.iykyka.com deploy uses Postgres (tech-design §8).
SQLite remains local/test only; update compose/volume/backup checklist items.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 02:04:53 +00:00
Cursor Agent 2eed4e492c
docs: add deploy/residual checklist (N1–N5) after Phase 1 A–C
Consolidate Claude + Cursor DONE state and the next execution track
(smoke → Docker msn.iykyka.com → stabilize → FCM/Android QA → human PoC).
Sync stale PLANNING Q1–Q7/stack status and point AGENTS/README/CLAUDE/roadmap
at docs/deploy-checklist.md.

Co-authored-by: okuma <o0kuma@users.noreply.github.com>
2026-07-31 01:54:55 +00:00