TapeNow WebMCP 能力覆盖与接入建议 / Capability coverage and adoption
核验日期 / Reviewed: 2026-09-28。范围 / Scope: 当前工作区的 server、cloud、React UI 和本次 P0 接口;仅文档与建议,尚未实现或注册 WebMCP 工具。TapeNow 0.6 已部署;本文 WebMCP 方案仍未实现,未开展浏览器兼容性验收。
Gateway 三链接入 / Three-chain Gateway
新增 BSC、X Layer、Base 的 Gateway 后端和 JavaScript SDK,可覆盖核验、发布、恢复、停用及客户域名流程;钱包签名仍由调用方明确取得。原生 WebMCP 尚未注册。使用指南与 SDK 示例。
Gateway APIs and the JavaScript SDK cover verification, publication, restoration, retirement and custom domains across three chains. Callers must explicitly obtain wallet signatures. Native WebMCP tools are not registered.
结论 / Decision
WebMCP 适合让浏览器里的代理理解并操作 TapeNow 的项目、版本、预览、发布和恢复流程。可以覆盖整条用户旅程,但不能保证每一步无人介入。建议先提供状态查询与发布准备,再接入有明确审批范围的写操作。不能把现有所有 REST 接口直接批量变成工具,也不能因为模型说“已确认”就让服务器执行付费或不可逆操作。
WebMCP can cover the complete TapeNow journey through structured browser tools and explicit human handoffs. Begin with reads and preparation; add bounded mutations only after server-enforced approval and retry behavior are designed. Complete workflow coverage does not mean fully autonomous execution. This document proposes product contracts, not implemented endpoints.
官方状态与兼容性 / Verified platform status
1. 2026-09-26 的社区草案将入口定义在 Document,不是已完成的 W3C 标准。正式接入应探测 document.modelContext,并保持普通页面可用。WebMCP 草案 / Draft
2. Chrome 现行文档使用 document.modelContext.registerTool()、getTools()、executeTool(),注册可用 AbortSignal 管理生命周期。当前英文文档注明 Chrome 155 起弃用 JSON 字符串输入,不能照搬早期 executeTool(tool, JSON.stringify(args)) 示例。Imperative API
3. 关于旧入口:搜索索引保留的官方意大利语文档 2026-07-01 版本明确说 navigator.modelContext 在 Chrome 150 弃用,应改用 document.modelContext;本次直接抓取的最新英文与意大利语页面均已不保留这条历史说明;因此 Chrome 150 是官方历史文档的弃用记录,不是对当前旧别名是否仍能运行的实测。官方议题解释了 Document 生命周期与旧 Window/Navigator 绑定的差别。不要据此承诺旧别名在所有版本仍存在。官方历史译文、规范议题 #173
4. Chrome 从 149 开放 origin trial;开发调试文档仍要求启用 WebMCP 功能或参加试验。版本号本身不代表目标用户默认可用。此次未核实 Edge、Safari、Firefox 的正式上线承诺,产品不能标注“所有浏览器支持”。用实际运行环境探测,记录浏览器版本、试验状态、API 形状,并在不支持时回退正常 UI。Chrome trial、调试要求
5. Native WebMCP 是网页内的工具接口,复用当前页、登录态和用户可见上下文;远程 MCP 通常需要独立服务、认证与连接。给页面注册工具不会自动产生远程 MCP URL,也不会自动让任意桌面代理取得登录权限。若以后做桥接,应作为单独的授权边界审查。WebMCP 与 MCP、Chrome agents 入口
The current entry point is document.modelContext. The search-indexed historical official localized documentation records the Navigator alias deprecation in Chrome 150; direct current English and Italian pages no longer retain that note. Current English documentation uses Document and separately deprecates stringified execution arguments from Chrome 155. Treat WebMCP as experimental and feature-detect the actual browser. No cross-browser shipping claim is made. Native page tools do not create a remotely accessible MCP server, nor grant an external agent a user's session.
当前产品事实 / Repository facts
主要实现:server/routes.mjs、server/sources.mjs、server/oauth.mjs、server/runtime.mjs、server/batch2-routes.mjs、server/p0-data-routes.mjs、server/ecosystem-routes.mjs、server/cf-domains.mjs、cloud/worker.mjs。权限在 server/project-access.mjs;预算在 server/publication-budget.mjs,批准指纹在 server/release-policy.mjs。
云端当前要求会话、写请求 Origin/CSRF;共享工作区通过 X-TapeNow-Workspace 选择所有者,再由服务器重新校验成员。成员操作进入所有者的 DO 队列,凭据和 R2 路径仍归所有者,审计 actor 单独记录。工具必须复用这些接口,不传递可伪造的 actor 或自报角色。UI 工具隐藏不是授权措施;撤销后工具即使仍显示,也必须得到服务器拒绝。
The browser adapter must preserve authenticated API behavior and selected owner workspace. The server derives the actor and validates roles again; tool visibility is only presentation. Existing sharing is deliberately restricted: a Viewer is read-only and a Publisher cannot configure owner credentials, domains, members or secrets. Proposed tools must not silently broaden these permissions.
全功能映射 / Full feature mapping
记号 / Legend: R 查询/read;P 准备/prepare,可能保存草案,不能误标只读;M 状态变更/mutation;C 公开、付费、撤销或删除/consequential;H 用户交接/handoff。O=Owner,P=Publisher,V=Viewer,Op=Operator。表内路径省略 /api;工具名均是建议,未实现。权限列描述当前云端限制,不是要求放宽。
| 能力 / Capability | 现有接口或界面 / Existing surface | 建议工具 / Proposed contract | 等级与边界 / Class, role, boundary |
|---|---|---|---|
| 登录、会话、退出 / Authentication | GET /session; POST /auth/password, /auth/otp, /auth/verify, /auth/logout | session_status; open_sign_in; request_sign_out | R/H/M; 登录表单接管密码和 OTP,输出绝不含 CSRF/session token |
| 邀请 / Platform invitations | GET/POST /invitations; POST /invitations/revoke | list_invitations; prepare_invite; execute_invite_change | Op only; M/C; 发邮件、重新邀请与撤销逐项确认 |
| 工作区、成员角色 / Workspaces and roles | GET /workspaces; GET /state; X-TapeNow-Workspace | list_workspaces; select_workspace; get_project_summary | R/M-local; 只列已授权项目,切换清理旧页工具与缓存 |
| 项目创建、设置 / Project configuration | POST /projects; PATCH /projects/:pid | prepare_project; save_project | O; M; 网络、容器、数据库版本变更使相关批准过期 |
| 成员增删与降权 / Membership | GET/POST/DELETE /projects/:pid/members | list_members; prepare_member_change; execute_member_change | O; R/C; existing invited accounts only; no implicit invitations |
| 暂停与恢复 / Suspension | GET/POST /projects/:pid/suspension | get_suspension; prepare_suspension; execute_suspension | O/Op; C; 原因必填;不能删除链上内容或第三方副本 |
| 本地构建导入 / File import | POST /projects/:pid/import; file picker/ZIP | choose_artifact; validate_import; import_artifact | O/P; H/M; 只用用户选定文件句柄,不读取任意磁盘路径 |
| 示例生成 / Sample generation | POST /projects/:pid/sample | create_sample | O; M; 可能使用绑定配置,成员不可调用 |
| GitHub 流程 / Git workflow | GET/POST /projects/:pid/github-workflow | inspect_workflow; prepare_workflow_install; install_workflow | O; R/C; 改仓库必须显示分支、提交内容与权限 |
| Git/Vercel 来源 / Source import | POST /projects/:pid/github-build, /github-artifact, /vercel-inspect, /vercel-import | inspect_source; start_build; import_source_artifact | O/P for allowed build/import; M; Vercel inspect O today; member cannot override build command/directories |
| 构建任务 / Build jobs | GET /projects/:pid/source-jobs; GET /source-jobs/:jid; POST /source-jobs/:jid/import | list_builds; get_build_status; import_build | R/M; legacy GET job polls/persists for O/P, V cached only; do not call polling tool readOnly |
| 文件清单、日志、签名回执 / Files, logs, receipts | GET /state; GET /releases/:rid/files, /receipt; POST /releases/:rid/verify; GET /keys | get_release_summary; get_logs; verify_archive; get_receipt_keys | O/P/V metadata and public keys; signed receipt O only (contains owner configuration, cannot redact signed payload); verify O/P M (writes audit/log); cap outputs |
| 导出与离线验签 / Export and offline verification | GET /releases/:rid/export; receipt-verification guide | prepare_export; download_archive; open_verify_guide | O; H; 用户接收下载,代理只回报文件名/哈希,不返回 ZIP/base64 |
| 发布就绪与批准 / Readiness and approval | GET /releases/:rid/readiness; POST /approve; PATCH /compatibility | inspect_readiness; prepare_release_approval; open_approval | R/P/H; approve O/P, compatibility O; human approval cannot be fabricated by tool input |
| 依赖清单 / Dependencies | GET/PUT /releases/:rid/dependencies | list_dependencies; prepare_dependencies; save_dependencies | O/P/V read, O/P write; 原始 URL/声明是非可信输入,不发任意网络请求 |
| 当前版本与恢复候选 / Current release and restore | POST /projects/:pid/promote, /restore; GET /releases/:rid/restore-check | inspect_restore; prepare_restore; create_restore_candidate; select_current_release | O/P writes; restore is not database rollback or automatic republish |
| 私有预览 / Private preview | POST /releases/:rid/private-preview, /private-preview/revoke; GET /preview/:pid/:rid | prepare_private_preview; open_preview_controls; revoke_preview | O/P; H/C; 密码仅在用户界面显示,不进入工具输入输出或日志 |
| 公开预览 / Public preview | POST /releases/:rid/preview | prepare_public_preview; execute_public_preview | O/P; C; 明确公开范围及无法撤回公开副本,不能自动填 acknowledgePublic |
| 托管站点 / TapeNow site publishing | POST /releases/:rid/site-check, /site-access, /publish-site | inspect_site; prepare_site_publish; execute_site_publish | O/P; P/C; 区分上传、可访问、内容核验与生产入口 |
| Cloudflare Pages / Pages publishing | POST /releases/:rid/cloudflare, /cloudflare/verify, /cloudflare/access | prepare_pages_publish; execute_pages_publish; verify_pages | O/P; C; production approval and owner-bound provider credentials |
| 供应商 OAuth / OAuth grants | GET /oauth; POST /oauth/:provider/start; callback; resources; bind; refresh; DELETE grant | list_connection_status; open_provider_consent; select_resource; prepare_disconnect | O; R/H/C; 外部 OAuth 页人工授权,工具不读 grant token、授权码或 cookie |
| 手工连接与环境变量 / Connections and environment | POST /connections; DELETE /connections/:key; POST/DELETE project environment | inspect_config_status; open_secret_editor; prepare_disconnect | O; H/C; 不提供 get_secret/set_secret 工具;用户在安全表单中填写 |
| PostgreSQL 与业务 API / Customer data services | GET project data-connections; POST/DELETE project postgres or business-api/:environment; POST .../check | get_data_connection_status; open_data_connection; check_data_connection | O config/check; P/V safe summaries; tools never expose DSN/password; check can persist state and make bounded network calls |
| Supabase 健康及邮件 / DB health and email | GET project data-health; POST email-test/:environment, email-verify/:environment | inspect_data_health; prepare_email_test; open_email_verification | O; R/M/H; 邮件发送有外部副作用,验证码人工填写;不迁移客户业务数据库 |
| Runtime / Runtime deploy and verification | GET /runtime/template; GET/POST project runtime; POST runtime/:rid/verify | inspect_runtime; prepare_runtime_deploy; deploy_runtime; verify_runtime | O; R/C; 执行代码、绑定和域名需清单审批;不交给成员 |
| 链选择、容器发现 / Chains and containers | project chain config; POST project container/resolve; GET project ecosystem | inspect_chain_target; resolve_container; open_ecosystem | O/P resolve, O config; query cannot invent ownership |
| 链上历史导入 / Onchain archive import | POST project chain-import | prepare_chain_import; import_chain_archive | O/P; M; 绑定 chain/block/hash/container;导入内容不授予容器所有权 |
| 链上发布计划 / Chain planning | POST release chain/prepare; GET chain/plan; POST chain/preflight | prepare_chain_publish; inspect_chain_plan; quote_chain_step | O/P; P; 估价会保存状态,网络/目标/产物/步骤匹配,不是只读 |
| 钱包签名 / Wallet signing | POST chain/intent; browser wallet; POST chain/pending, /confirm, /rejected | open_wallet_step; record_transaction; reconcile_transaction | O/P; H/C; 每步现有预算约束;工具绝不收私钥/助记词或代签 |
| 费用、激活与回读 / Costs, activation, readback | POST chain/costs, /activation, /readback; POST project chain-observe | reconcile_costs; prepare_activation; verify_chain_content | O/P chain operations; project observe O today; P/M/C by operation; activation may spend, readback persists |
| 域名登记与连接 / Domains | POST project domains; POST /domains/:did/connect; DELETE /domains/:did | prepare_domain_change; execute_domain_change | O; C; provider resource retained on local removal; no hidden overwrite |
| CF 区域、DNS 与缓存 / Zones, DNS, cache | GET project cloudflare/zones; POST domain dns-plan, dns-apply, purge | list_zones; prepare_dns; execute_dns; prepare_cache_purge; execute_cache_purge | O; R/P/C; digest and expiry; purge scoped paths, never implicit purge-all |
| 链上域名 / Onchain domain binding | POST /domains/:did/chain-prepare, /chain-verify, /chain-access | prepare_chain_domain; open_domain_wallet_step; verify_chain_domain; run_browser_domain_check | O; P/H/C; dual-RPC/DNS + private Node HTTPS/all-file hashes; recheck before activation; browser challenge fallback only without checker; never fabricate proof |
| 归档保留与回收 / Archive lifecycle | GET/PATCH project retention; POST project trash; PATCH release archive-pin; POST archive-restore | inspect_retention; prepare_archive_change; execute_archive_change; restore_archive | O lifecycle edits; O/P archive restore; C; 描述何时永久删除与恢复窗口 |
| 指标与诊断 / Metrics and diagnostics | GET project diagnostics; status/log panels | get_diagnostics; get_project_metrics | O/P/V scoped R; 不泄露全账户用量或其他项目 |
| 引导、导航、语言 / Guidance, navigation, language | /docs; UI guide; PATCH /onboarding; src/i18n.tsx | open_guide; navigate_project; set_language; dismiss_onboarding | R/M-local; language enum zh-CN/en; tool names stable, UI labels localized |
| 平台备份与恢复 / Platform backup and recovery | scripts/backup-*.mjs, cold restore/NAS/offline procedures | explain_backup; show_recovery_checklist | operator H; 当前没有浏览器备份执行 API;不虚构 run_backup 工具 |
HashPort 的 chain-verify 先核验双 RPC 链上文件/绑定与 DNS;配置私有检查器时,再由 Node 固定公开 IPv4、验证 TLS 并比对自定义域名全部文件大小与哈希,重新核验绑定、DNS、目标及批准后激活。结果明确标记 private-node-checker:不依赖浏览器 CORS,但不能证明所有地区或用户浏览器缓存都可访问。检查器故障必须失败,不能静默降级为成功。
只有未配置检查器时,才创建 5 分钟有效的 browserCheck,等待实际浏览器 HTTPS/全部文件哈希检查,再由 chain-access 复核并激活。拟议 WebMCP 工具必须调用真实检查或交接用户,不能凭模型判断伪造服务器结果、httpsVerified、空 failedPaths 或过期 checkId。
With the private checker configured, HashPort verifies dual-RPC chain content and DNS, then pinned-IP TLS and all file hashes from GC4G, and rechecks binding, DNS, target and approval before activation. The private-node-checker scope is independent of browser CORS, not proof of every browser or region. Only installations without that checker use the five-minute current-browser challenge and chain-access fallback. Proposed WebMCP tools must never synthesize either server or client proof.
操作分级与强制审批 / Action and approval model
官方的 readOnlyHint、untrustedContentHint、consequentialHint 是给浏览器/代理的提示;不能替代 TapeNow 的后端权限、校验或审批记录。外部内容可能携带提示注入,跨源工具暴露应明确限制;只读输出也可能泄露隐私。官方工具安全
A hint is not a capability grant. Our design recommendation is to enforce all rights on the existing server paths and add a bounded operation record for agent-triggered consequential actions. No permission should depend on an agent saying that the user agreed.
- R:输出精简结构化状态。只读意味着不保存状态、不发送邮件、不触发 vendor 写入;HTTP GET 并不自动等于 R。敏感读仍要验项目和角色。
- P:生成计划,列清项目、所有者、环境、链、目标、公开范围、文件哈希、费用上限、副作用和到期时间。P 可能保存计划,
readOnlyHint:false。 - M:可逆改动也要 schema、成员权限、配额和幂等约束;批量执行必须限制项目集合和数量。
- C:公开发布、域名写入、成员撤销、销毁、钱包支出需要服务器可验证的明确审批。UI 显示计划后由用户批准;执行工具仅消费该次批准。批准按钮不能由同一普通工具输入
approved:true代替。 - H:外部 OAuth、钱包签名、密码/验证码、实体手机测试和离线备份让用户完成;代理可以说明、定位界面、等待并核验结果,不能冒称已完成。
Prepare → approve → execute 的推荐记录
这不是当前已有统一 API。建议在现有业务门禁之上增加 operation 记录,字段至少包括 operationId、服务器推导的 actorId/ownerId、projectId、action、resource IDs、workspace version、manifest/config/target digests、预算/币种/chainId、scope、expiry、一次性消费状态和结果引用。用户批准必须来自可信应用交互并绑定这份摘要;执行时再次校验角色、暂停、资源版本、预算与批准是否撤销。不要把可任意填写的 approvalToken 当成同意。
既有链上报价只有效 60 秒,并校验 plan、step、approval digest、目标链和剩余预算;WebMCP 必须复用,不能扩大预算。DNS 计划现有有效期为 5 分钟,apply 重新比对 digest;工具应展示该计划而不是另造一套跳过重算的捷径。审批失效返回 needs_reapproval,不要静默更新目标继续执行。
Use a server-issued operation record bound to actor, owner, project, action, current resource hashes, target network, budget and expiry. Trusted application confirmation approves that exact record. Execution rechecks role, suspension, freshness and remaining budget and atomically consumes it. Existing chain quotes expire after 60 seconds; DNS plans expire after five minutes. This proposal adds no broader authority than those existing checks.
幂等与恢复 / Idempotency and recovery
建议键为 actor+owner+project+action+idempotencyKey,存 request digest;同键不同参数 409,同键同参数返回已有结果。供应商超时并不说明未执行:先查 operation/provider receipt,不能盲目重发部署、邮件、DNS 或交易。链上只恢复已知 txHash 的确认,不重复请求钱包签名。取消浏览器调用不等于撤销已发出的交易;页面重载也不能丢失服务器 operation 状态。
Record the request digest and result for each scoped idempotency key. After a timeout, reconcile provider or transaction state before retrying. Browser cancellation and navigation do not undo completed remote actions. These are proposed safeguards; the current app has operation-specific recovery and does not yet provide a universal agent idempotency layer.
Schema 例子 / Proposed schemas
以下仅为契约示例,不是工具注册实现。服务器拒绝未知字段;工具不提供 genericFetch、arbitrarySQL、shell、rawProviderRequest。workspace 选择来自已验证页面上下文,以下 ID 再次由后端归属校验。
{
"name": "get_release_summary",
"inputSchema": {
"type": "object",
"additionalProperties": false,
"required": ["projectId", "releaseId"],
"properties": {
"projectId": {"type": "string", "pattern": "^p-[a-f0-9]{12}$"},
"releaseId": {"type": "string", "pattern": "^d-[a-f0-9]{12}$"}
}
},
"annotations": {"readOnlyHint": true, "untrustedContentHint": true}
}{
"name": "prepare_publication",
"inputSchema": {
"type": "object", "additionalProperties": false,
"required": ["projectId", "releaseId", "target", "expectedManifestHash"],
"properties": {
"projectId": {"type": "string", "pattern": "^p-[a-f0-9]{12}$"},
"releaseId": {"type": "string", "pattern": "^d-[a-f0-9]{12}$"},
"target": {"enum": ["private-preview", "pages-preview", "pages-production", "tapenow-site", "chain"]},
"expectedManifestHash": {"type": "string", "pattern": "^[a-f0-9]{64}$"},
"chainId": {"enum": [56, 196]},
"maximumNative": {"type": "string", "pattern": "^[0-9]{1,9}(\\.[0-9]{1,18})?$", "maxLength": 28}
}
},
"annotations": {"readOnlyHint": false, "consequentialHint": false}
}chainId 与预算只在 chain 目标接受,并由服务器用整数 wei 转换/检查。返回 {operationId,status:'needs_confirmation',summary,expiresAt},无密码、token、原始交易私密数据;用户确认后 execution 仅收 operationId 与受限 idempotencyKey,不再允许改 target 或金额。WebMCP 的 execute 返回普通可 JSON 序列化值;不要机械复制远程 MCP 的传输封装。
For chain publication, validate chain and budget as a target-specific variant and convert amounts using exact integer units. Return an operation reference and human-readable summary. A later execute call cannot substitute another target or amount. All examples are proposed schemas, not shipped tool registration code.
Secrets、代理来源与非可信内容 / Secrets and untrusted data
保留 Cookie/CSRF 在应用的请求层,工具结果只返回去敏后的身份状态。不要把 session 接口的 token 原样喂给代理。数据库 DSN、供应商 bearer token、OAuth code、私有预览密码、钱包私钥/助记词和邮件验证码都不应进入工具 schema、工具结果、日志、错误详情或遥测。授权读配置返回“已配置/检查时间/公开标识”,不是配置值。
README、构建日志、仓库文件、网页依赖、DNS TXT、链上文件、第三方错误文本都当作 data,不能当指令。结果使用稳定枚举、数字与结构化字段,把用户文字放在受限 untrusted 区域,设置 untrustedContentHint;禁止输出中的“请执行下一步”自动获得权限。限制字符串长度、列表数、分页和输出大小;可疑 URL 使用现有 SSRF/出口约束,不能通过工具绕过。
Never expose passwords, tokens, OTPs, wallet secrets or private-preview passwords to the tool channel. Treat repository text, logs, external errors, DNS records and onchain content as untrusted data. Tool descriptions are application-owned; imported content cannot rewrite them. Audit actor, operation, resource IDs, approval digest, outcome and provider receipt, never secret values. Same-origin confinement and least-privilege tool registration complement backend controls; they do not replace them.
分阶段最小工具集 / Phased minimum toolset
第一阶段建议 8 个:session_status、list_workspaces、get_project_summary、get_release_summary、inspect_readiness、get_build_status(只读快照)、open_guide、set_language(本地状态)。先完成 403/撤销、输出去敏、页面切换注销工具和不支持浏览器回退测试,不开付费工具。
第二阶段增加 prepare_publication、inspect_restore、prepare_dns、open_provider_consent、open_secret_editor、open_wallet_step。准备/导航与执行分开;先验证用户确实看得懂目标、变化、费用和公开范围。
第三阶段逐个加入获批的 import、publish、restore、member-change、DNS/cache 和 archive 变更工具。不要把“一键完成所有发布”作为无范围限制的入口。平台邀请、暂停和运维备份单独在角色适用的界面开放或仅提供交接指引。
Phase 1 ships a small read/navigation surface. Phase 2 adds preparation and human handoffs. Phase 3 adds individually bounded mutations after approval, retry and recovery tests. Avoid a universal “do everything” tool or exposing every REST route verbatim.
实现前验收场景 / Required acceptance scenarios
- 无 WebMCP 的浏览器:UI 正常、无运行错误;有功能浏览器:枚举工具与当前项目/角色一致,登出/切换注销旧工具。
- Viewer 直接调用写工具或 HTTP:403;Publisher 伪造连接、成员、其他项目 releaseId:403;撤销后的下一次请求失败。
- 工具只读快照不改变 state/version;GET job 轮询的写入不能错误标 read-only。
- 准备后改变文件、网络、配置、角色、暂停状态、金额或超时:执行拒绝并重新批准;代理传
approved:true不能自批。 - 同操作超时/重试:仅一次可计费外部执行;同键不同参数 409;半完成 DNS/部署/链交易有可核验恢复路径。
- 注入 README/日志/链文件要求读取 secrets 或跨项目发布:当作文本,权限不变;工具输出无任何 secret fixture。
- 钱包拒绝、切链失败、OAuth 取消、手机离线、备份设备缺席:清楚返回 handoff/blocked,不能标为完成。
- 真正发布需核验 HTTP/内容 hash/链回执;“请求已接受”“交易已提交”“缓存已清理请求”都不等于最终可访问。
Test real tools and backend behavior, not only schema validity. The above scenarios are a future acceptance plan. This documentation task did not register tools or run browser WebMCP evaluations.
恢复对齐现状与边界 / Recovery status and limits
TapeNow 0.6 已部署。迁移 004 的成员、暂停和审计表已纳入平台备份;生产 Cloudflare OAuth 配置包含 10 项作用域(含 dns.read、dns.write、zone.read、cache.purge)。私有 Node 连接检查器及专用隧道已运行;19 份加密恢复材料包含检查器配置、隧道配置和两个服务定义,并使用原恢复密钥。GC4G、B2、NAS 的本次副本校验一致。
2026-09-28T07:09:32.770Z 快照的隔离 PostgreSQL 原生恢复已通过:7 个工作区、35 个版本、成员 0 条、暂停 1 条、审计 8 条;新表 RLS 与受限 RPC 授权已核验。成员为 0 是撤销后的快照,不能称为已验证非空成员关系恢复。恢复前必须先加载暂停状态,再开放服务;workspace-only 导出仍不是完整平台灾备。没有演练托管 Supabase/DNS 整站故障切换,也没有因此证明恢复凭据在所有外部供应商上可用。
TapeNow 0.6 is deployed. Migration 004, ten Cloudflare OAuth scopes and 19 sealed recovery files are aligned; the private Node checker and dedicated tunnel are live. The same original recovery key successfully decrypted the actual B2 snapshot, with GC4G/B2/NAS hashes matching. Isolated native PostgreSQL restore verified 0 membership, 1 suspension and 8 audit rows, RLS and restricted RPC grants. This proves the recorded snapshot and configuration recovery, not populated membership restoration or a complete hosted-cloud disaster recovery exercise. Restore suspension before serving traffic and never expand privileges automatically.
Evidence: artifacts/p0-dual-chain-2026-09-28/checker-recovery/native-recovery.json, checker-recovery.json and replica-status.json. Operational verification is separate from the future WebMCP acceptance plan.
来源与证据 / Sources and evidence
所有平台事实均使用上文链接的官方规范、Chrome 文档或标准维护仓库;未把社区兼容表当作浏览器上线依据。本产品方案和权限/审批设计是基于 TapeNow 源码的建议,不声称由 WebMCP 规范自动提供。
本地盘点输出:.omo/evidence/webmcp/route-inventory.txt。文档完整性/双语 HTML/链接与 schema 检查输出:.omo/evidence/webmcp/receipt.txt。本次证据不代表 SQL、生产、浏览器兼容性或付费流程实测。