0989f9f40e
Project CI / AI game creator shell Rust crates (push) Successful in 1m40s
Project CI / AI game creator shell Rust smoke (push) Successful in 2m9s
Project CI / Backend tests (push) Successful in 5m4s
Project CI / AI game creator shell Rust lane 1/2 (push) Has been cancelled
Project CI / Frontend tests (push) Has been cancelled
Project CI / Repository checks (push) Has been cancelled
Project CI / AI game creator shell web tests (push) Has been cancelled
Project CI / AI game creator shell Rust lane 2/2 (push) Has been cancelled
Project CI / Native shell tests (push) Has been cancelled
- 新增 scripts/check-game-distribution-owner-isolation.mjs:对本地真实栈注册两个账号,逐条验证私有版本读取、上传状态、分片写入、分包确认、送审、撤回与未认证访问的越权口径,并验证请求体伪造 owner 不生效 - api-server 的 submit_version 改用 load_owner_version_or_404:他人送审返回 404 而不是 403,不再用错误码泄露版本是否存在 - package.json 注册 check:game-distribution-owner-isolation - 游戏分发里程碑阶段 A 第 1 条改为已勾选,写入 21 项 PASS 取证与修复前的 403 变异证据
server-rs 工作区说明
更新时间:2026-05-15
server-rs/ 是当前唯一后端工作区,承载 Rust api-server、SpacetimeDB module、领域模块、平台副作用适配和共享契约。旧 server-node、Express、PostgreSQL、Go 服务端和 maincloud 口径均为历史残留,不再作为当前实现目标。
当前职责
crates/api-server:Axum HTTP / SSE / BFF 门面、鉴权、中间件、外部服务编排和 DTO 映射。crates/spacetime-module:SpacetimeDB 表、reducer、procedure、事务 adapter、row mapper 和迁移。crates/spacetime-client:后端访问 SpacetimeDB 的 typed facade。crates/module-*:领域模型、命令、应用规则、领域事件和领域错误。crates/platform-*:OSS、LLM、语音、认证等外部平台能力。crates/shared-contracts:前后端共享 DTO 与公开契约。crates/shared-kernel、crates/shared-logging、crates/tests-support:跨模块基础能力、日志和测试支撑。
开发规则
server-rs/Cargo.toml是 workspace 成员和依赖版本事实源;第三方依赖和 workspace 内 crate path 优先放在[workspace.dependencies]。module-*不直接依赖 Axum、SpacetimeDB table/reducer/procedure、reqwest、OSS、LLM、spacetime-client、tokio或文件系统。api-server不承接领域真相;发现领域规则时优先沉到对应module-*。- SpacetimeDB schema 变化必须同步
spacetime-module/src/migration.rs、生成绑定和当前后端架构文档的表目录。 - 人工命令、本地联调和文档示例不要使用
spacetime --root-dir。
常用命令
cargo check -p api-server --manifest-path server-rs/Cargo.toml
cargo test -p api-server --manifest-path server-rs/Cargo.toml
npm run check:server-rs-ddd
npm run check:spacetime-schema
npm run spacetime:generate
npm run dev:api-server
涉及 API smoke 时用 npm run dev:api-server 启动后端并检查 /healthz,不要使用旧 api-server:maincloud。
当前文档
- ../docs/【后端架构】server-rs与SpacetimeDB数据契约-2026-05-15.md:DDD 边界、API 分组、schema 变更规则和表目录。
- ../docs/【开发运维】本地开发验证与生产运维-2026-05-15.md:本地启动、检查、SpacetimeDB 操作和生产运维。