Skills Manager v1.27.0
发布日期:2026-07-03
递交范围:v1.26.0...v1.27.0
发布概览
- 备份重设计 Phase 2:使用 GitHub 登录即可连接备份——不用建仓库、不用粘贴令牌、不需要任何 git 知识。
用户可见更新
- 使用 GitHub 登录 —— 备份页新的首选连接方式:点一下按钮,在浏览器输入 8 位码,剩下的交给应用——自动创建私有仓库
skills-manager-backup(名称可改)、登录凭证存入系统钥匙串,然后自动恢复现有备份或完成首次备份。凭证不会出现在任何文件里,应用也永远接触不到你的 GitHub 密码。 - 个人访问令牌作为高级选项 —— 更喜欢用令牌,或需要网络备选方案?同一面板的「高级」折叠项接受 PAT,同样自动完成仓库设置,并附预填权限的令牌创建链接。登录遇到网络错误时会明确指引到这里。
- 公开仓库警示 —— 应用自动创建的仓库始终是私有的;如果连接了一个已存在的公开仓库,现在会警示这意味着什么暴露,并给出在 GitHub 上修改可见性的路径。
- 内置 Git 引擎(实验性) —— 设置页新增开关:备份的 HTTPS 网络操作(拉取、推送、克隆、远端检查)改走应用内置的 Git 引擎——不依赖系统 git,凭证从钥匙串内存注入。默认关闭;SSH 与自定义远端始终走系统 git;可随时切回。
开发者与治理更新
- 新增
core/github_api.rs:极简 GitHub REST 客户端(令牌校验、查找或创建私有仓、device flow 申请/轮询),错误带稳定标记映射为人话文案;遵循应用代理设置。两个 device flow 端点已用真实 OAuth client id 实测。 - OAuth App 的 client id 按设计内置于二进制(公开标识符,已启用 device flow);有意不使用 client secret。授权成功后 OAuth 令牌在后端完成全部连接流程——永远不会进入 webview。
- 新增
core/git2_engine.rs:只接管网络操作,凭证经 git2 回调从钥匙串注入(2 次尝试上限),错误统一规范化为系统 git 的词汇,既有 UI 错误映射与恢复引导对引擎切换无感;推送行为一致性(tracking ref + upstream 配置)有本地裸仓库 roundtrip 与非快进拒绝测试覆盖。 - 引擎偏好在每个网络命令入口从设置同步;内置引擎克隆失败会清理残留目标,重试不会卡死。
- Windows 测试修复:git2 引擎测试改用平台正确的
file:///C:/...URL。
当前校验状态
- ✅ 跨平台构建通过(macOS Intel / macOS ARM / Windows x64 / Linux x64)
- ✅ TypeScript typecheck 通过
English release notes
Release date: 2026-07-03
Commit range: v1.26.0...v1.27.0
Release Overview
- Backup redesign Phase 2: connect your backup by signing in with GitHub — no repository setup, no tokens to paste, no git knowledge required.
User-facing
- Sign in with GitHub — The Backup page's new primary connect path: click once, enter an 8-character code in the browser, and the app does the rest — creates a private
skills-manager-backuprepository (name adjustable), stores the sign-in credential in the system keychain, and then either restores your existing backup or pushes the first one. The credential never appears in any file, and the app never sees your GitHub password. - Personal access token as the advanced option — Prefer a token, or need it as a network fallback? An "advanced" toggle in the same panel accepts a PAT with the same automatic repository setup, plus a pre-filled token-creation link. Network errors during sign-in point here explicitly.
- Public-repository warning — Repositories the app creates are always private; if you connect a pre-existing PUBLIC repository, a warning now explains what that exposes and how to change the visibility on GitHub.
- Built-in Git engine (experimental) — A new Settings toggle routes the backup's HTTPS network operations (fetch, push, clone, remote checks) through the app's built-in Git engine: no system git required, credentials injected in memory from the keychain. Default off; SSH and custom remotes always use system git; switch back anytime.
Developer & Governance
- New
core/github_api.rs: minimal GitHub REST client (token validation, find-or-create private repo, device flow start/poll) with stable error markers mapped to plain-language copy; honors the app proxy setting. Both device-flow endpoints verified against the live OAuth client id. - The OAuth App client id ships in the binary by design (public identifier, device flow enabled); there is deliberately no client secret. On authorization the OAuth token completes the entire connect in the backend — it never reaches the webview.
- New
core/git2_engine.rs: network-operations-only scope, keychain credentials via the git2 callback (2-attempt cap), errors normalized to system git's vocabulary so the existing UI error mapping and recovery routing work unchanged; push parity (tracking ref + upstream config) covered by local bare-repo roundtrip and non-fast-forward rejection tests. - Engine preference syncs from settings at every network command entry; a failed built-in-engine clone cleans its partial target so retries don't wedge.
- Windows test fix: platform-correct
file:///C:/...URLs in the git2 engine tests.
Current Verification
- ✅ Cross-platform build passed (macOS Intel / macOS ARM / Windows x64 / Linux x64)
- ✅ TypeScript typecheck passed
完整变更:v1.26.0...v1.27.0