| Add embedded admin UI foundation Closes #92 ## Summary - embed a Svelte 5 / SvelteKit static operator console in the Go binary - add admin open and admin status against the existing coordinator, with lazy loopback listener startup - protect the browser boundary with one-time launch tokens, HttpOnly SameSite sessions, Host/Origin/Fetch Metadata/CSRF validation, no CORS, and a hash-based CSP - expose authenticated readiness/version state and deterministic hashed assets with SPA fallback - implement the selected operator-console visual direction with a visible Light / Dark / System selector; System is the default - add frontend build/type/unit/Playwright CI and documented source-install/runtime workflows ## Verification - ./scripts/check-admin-ui-assets.sh - npm run check - npm run test - npm run test:e2e - live Playwright E2E against the embedded loopback daemon: 2/2 passed - go test ./... - git diff --check The live browser QA also caught and fixed an initial CSP/bootstrap incompatibility without adding unsafe-inline. The one local go install ./... run was explicit dogfood for this foundation, not a routine PR gate. | 1 个月前 |