Files
heicode/docs
chenchenandClaude Opus 4.8 479cd61a07 docs(integration): complete + correct the desktop client API doc
Review of the client doc against the real code found and fixed:
- §1 auth was not self-contained (deferred the canonical to the deprecated doc).
  Inlined the full signing contract verified against middleware/device_signature.go:
  the exact header set, the fixed-order canonical string (method/path/ts/nonce/
  fingerprint/eph_pubkey/sha256(body)), ed25519(sha256(canonical)), the heicode-aead-v1
  encrypted-body rules, and the X-Heicode-Auth-Error / X-Heicode-Server-Time failure
  headers.
- §2 auth mismatch (accuracy bug): /api/user/self is UserAuth (session/JWT), NOT
  device-signed — a device-only client cannot call it. Marked it optional and
  clarified the two different auth schemes (/api/user/self* vs /api/heicode/*).
- §8: documented that failures return HTTP 200 with success:false (client MUST
  read success), and that error.retryable is always false (decide retry by code).
- §10 inventory: corrected /api/user/self auth + added /self/models.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-04 10:57:43 +08:00
..

Heicode Docs

当前 docs/ 只保留五类主线文档:

文档 用途
heicode.md Heicode 当前产品定位、系统边界和架构共识
plan.md 按当前共识拆出的实施计划
heicode-runtime-auth-newapi-secret-design.md 用户输入、登录用户复用、NewAPI 扣费映射、Azure Key Vault 凭证托管与短期凭证注入边界
heicode-manager-sub-swarm-progress-checklist.md Heicode Manager sub 模式、瀑布/敏捷、蜂群模式的已完成/未完成/依赖/风险/下一步进度清单
heicode-manager-standalone-execution-plan.md Heicode Manager 端可独立完成任务的执行计划、顺序、验收标准和边界
integration/Heicode-登录接口对接文档.md 已上线登录接口对接文档
integration/agent-platform-request-contract.md Manager 请求 Agent 平台时携带的部署、日志、监控、事件与审计接口参数
deployment/azure-production-deploy-guardrails.md Azure VM / PostgreSQL / Redis / Agent / NewAPI 生产部署前的安全守卫、环境变量注入和验证计划

旧 Agent API 草案、旧里程碑、旧架构说明和旧上手材料不再作为实施依据。后续文档和实现以 heicode.md 与 plan.md 为准;生产部署操作以安全守卫文档约束,且不得覆盖产品/架构主线。

代码中的过渡期命名、旧接口注释或旧 UI 文案只作为现状参考;若与 heicode.md / plan.md 冲突,应先更新实现或另行补充当前主线文档,不得恢复旧 Agent/M1-M5 草案作为依据。