fix(游戏共创): 把 read_public_game_cover_preview 登记进 native-only 白名单
Project CI / AI game creator shell Rust crates (pull_request) Successful in 4m37s
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Successful in 6m38s
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Successful in 7m52s
Project CI / Frontend tests (pull_request) Successful in 3m2s
Project CI / Backend tests (pull_request) Successful in 7m55s
Project CI / AI game creator shell web tests (pull_request) Successful in 2m58s
Project CI / Repository checks (pull_request) Successful in 6m1s
Project CI / Native shell tests (pull_request) Successful in 7m42s

CI 6/8 里的两条红(`Native shell tests`、`AI game creator shell web tests`)同一根因:`5798551b2`
新增的 Tauri 命令 `read_public_game_cover_preview` 没登记,`check-config.mjs` 的
「App invoke 或显式 native-only 白名单」校验因此失败:

```
Error: AI game creator shell App invoke or explicit native-only allowlist missing commands:
read_public_game_cover_preview
```

为什么静态扫描采不到:这条命令名由渲染层以常量 `COVER_COMMAND` 传给**注入的** invoke
(`src/features/platform-fork/platformForkCover.ts`,注入是为了让封面解析能单测),扫描只认
字面量调用点。按 `apps/ai-game-creator-shell/scripts/check-config.mjs:141` 起加了条目与注释,
注释写明「为什么采不到」以及同批另外两条命令为什么不需要登记。

同批新增命令复核(都不需要登记,都是字面量调用点):
- `create_local_project_from_platform_game` —— `src/features/platform-fork/usePlatformFork.ts`;
- `list_platform_game_catalog` —— `src/features/platform-fork/platformForkCatalog.ts`;
两条命令若漏登记,`check-config` 的同一断言会以同样的方式报出来;现在门禁绿即证明这两条被扫到。
本轮没有新增路由/权限清单(capabilities 只管插件 JS 命令,`invoke` 类命令不走它)。
This commit is contained in:
2026-10-06 13:21:28 +08:00
parent 2a04f293b1
commit 8d362d718e
@@ -138,6 +138,12 @@ const allowedUncalledTauriCommands = [
'suggest_game_distribution_publish_metadata',
'read_game_distribution_publication',
'upload_local_project_game_package',
// 共创列表封面:命令名由渲染层以常量 `COVER_COMMAND` 传给**注入的** invoke
// (`src/features/platform-fork/platformForkCover.ts`,注入是为了让封面解析能单测),
// 静态扫描只认字面量调用点,因此采不到这条命令名 → 显式登记为 native-only 白名单。
// 同一批的 `list_platform_game_catalog` 与 `create_local_project_from_platform_game`
// 都是字面量调用点,不需要登记。
'read_public_game_cover_preview',
// 账户与钱包由 Rust typed command 持有 origin/Bearer/envelope;命令名在 `accountHost.ts`
// 里以字面量出现,静态扫描仍按共享注册表核验。
'read_profile_recharge_center',