--- title: project‑cpe 待办事项清单 type: curated permalink: main/projects/4f53c06a-c6c3-40ec-b2fc-5f019ea45fc0/curated/project-cpe-待办事项清单 stable_id: b428ca3d-fd45-4f03-9546-5e656435db89 scope: project project_id: 4f53c06a-c6c3-40ec-b2fc-5f019ea45fc0 workspace_type: development usage_profile_id: null preference_context: development document_type: tasks revision: 2 source_memory_ids: [] source_checkpoint_ids: [] source_file_ids: [] source_git_commit: de28dc8246094e2bc17cab7c764fb4d4a2da71e0 source_git_commits: - de28dc8246094e2bc17cab7c764fb4d4a2da71e0 source_agent_sync_ids: [] model_connection: Sub2API model_name: openai/gpt-oss-120b source_count: 188 source_revisions: memory:2ab0a44e-c56a-4cbc-a82f-c8b8456d5019: '1' memory:e92dbe0b-bb27-4b0e-b5bb-2330a0472fd2: '1' memory:866234ea-0d81-4fd9-912a-6cb68441e1cc: '1' memory:d0a91595-3be4-4366-a615-58833dd0dff8: '1' memory:8c6276e6-d7db-409d-a3cd-5570c2d8fdc5: '1' memory:f0d365e8-4d2c-4d91-bdc0-df4d3d6fa6b3: '1' memory:fa66c797-a786-4966-8cb1-2eff40e3dc4e: '1' memory:fd164c80-b38b-4984-8008-48b57ba46e61: '1' memory:51b5b48b-ac1f-4477-ab2f-dfc46198eb01: '1' source_dispositions: processed: 188 unchanged: 0 unsupported: 0 skipped: 0 cited_source_ids: - memory:2ab0a44e-c56a-4cbc-a82f-c8b8456d5019 - memory:e92dbe0b-bb27-4b0e-b5bb-2330a0472fd2 - memory:866234ea-0d81-4fd9-912a-6cb68441e1cc - memory:d0a91595-3be4-4366-a615-58833dd0dff8 - memory:8c6276e6-d7db-409d-a3cd-5570c2d8fdc5 - memory:f0d365e8-4d2c-4d91-bdc0-df4d3d6fa6b3 - memory:fa66c797-a786-4966-8cb1-2eff40e3dc4e - memory:fd164c80-b38b-4984-8008-48b57ba46e61 - memory:51b5b48b-ac1f-4477-ab2f-dfc46198eb01 job_cited_source_ids: [] conflicts: [] supersedes: [] preferences: [] source_cursor: 87 source_hash: 96f0e4026558c8a03161f53b392fcec7359d4d701c4f33576b44e2f308b0ec5a prompt_version: 2026-08-12.3 schema_version: '3' curation_job_id: a9f69899-ee39-4900-b39a-a54d737f9614 created_at: '2026-08-19T03:55:27.224816+00:00' updated_at: '2026-08-19T18:49:31.225685+00:00' tags: - open‑issues - unresolved - tasks - project‑cpe --- ## Open / Unresolved Work (Consolidated) | Category | Issue | Description | Suggested Next Action | Source IDs | |----------|-------|-------------|-----------------------|------------| | **Security** | AT gateway auth | `/api/at` allows arbitrary AT commands. | Add token‑based authentication or whitelist allowed commands. | ["git:backend/src/handlers.rs"] | | **Credentials** | Redacted sensitive fields | APN password, FRPC token, etc. are stored as `[REDACTED]`. | Store secrets in Vaultwarden or an encrypted config file; provide UI for secure entry. | ["git:backend/src/config.rs", "git:frontend/src/pages/Network.tsx", "git:frontend/src/pages/Frp.tsx"] | | **OTA** | No signing | OTA packages are unsigned. | Sign OTA tarballs (e.g., GPG) and verify signatures in `ota.rs`. | ["memory:e92dbe0b…"] | | **OTA** | No rollback | Once applied, the device cannot revert to the previous version. | Implement A/B partitions or keep a backup copy before applying OTA. | ["git:backend/src/ota.rs", "git:frontend/src/pages/OtaUpdate.tsx"] | | **FRPC** | Log rotation threshold | Logs grow beyond 512 KB. | Make log rotation size configurable or compress old logs. | ["git:backend/src/state.rs"] | | **USB** | File‑lock missing | `set_usb_mode_config` writes directly to mode files. | Use atomic rename or `flock` for exclusive access. | ["git:backend/src/usb_switch.rs"] | | **USB Monitor** | Hard‑coded Feishu webhook | Monitor script only posts to a single Feishu URL. | Add a CLI flag for a configurable webhook; support Slack/Discord. | ["usb_switch_demo.sh"] | | **Testing** | Lack of unit/integration tests | Backend and front‑end have little test coverage. | Add Rust unit tests for utils and Jest/React‑Testing‑Library tests for UI components. | ["git:backend/src/utils.rs", "git:frontend/src/pages/*.tsx"] | | **API** | HTTP 200 for all errors | Errors are wrapped in JSON but HTTP status is always 200. | Return appropriate HTTP status codes (`400`, `401`, `500`, …). | ["git:backend/src/handlers.rs"] | | **CORS** | `*` allowed | Development CORS policy is wide open. | Restrict origins to known production hosts before release. | ["git:backend/src/main.rs"] | | **Refresh** | Aggressive polling on visibility changes | `useAdaptivePolling` may cause rapid extra requests. | Debounce visibility changes (e.g., 500 ms) before adjusting interval. | ["git:frontend/src/hooks/useAdaptivePolling.ts"] | | **InitScript** | Dangerous commands only warned | Scripts with `rm -rf /` etc. are only highlighted. | Add a confirmation modal for dangerous commands and optionally block save. | ["git:frontend/src/pages/InitScript.tsx"] | | **Band‑lock UI** | May allow unsupported bands | UI does not surface backend rejections. | Parse backend error and display to the user. | ["git:frontend/src/pages/Network.tsx"] | | **USB hot‑switch** | Marked experimental | May destabilise the device. | Perform extensive testing; fallback to reboot on failure. | ["git:frontend/src/pages/Configuration.tsx"] | | **Global Error Boundary** | Missing in React tree | Uncaught render errors crash the UI. | Wrap the root `` with an `ErrorBoundary` component. | ["git:frontend/src/main.tsx"] | | **i18n** | No localisation | All UI strings are hard‑coded Chinese. | Introduce `react-i18next` (or similar) and externalise strings. | ["git:frontend/src/**/*.tsx"] | | **Performance** | Large tables lack virtualization | Cell list may degrade performance. | Use `react-window` or MUI DataGrid virtualization. | ["git:frontend/src/pages/Network.tsx"] | | **OTA upload cancellation** | No abort controller | Users cannot stop a large OTA upload. | Add `AbortController` support to the upload API wrapper. | ["git:frontend/src/pages/OtaUpdate.tsx"] | | **USB monitor daemonisation** | Script runs manually | No systemd service provided. | Provide a systemd unit template for `usb_switch_demo.sh`. | ["usb_switch_demo.sh"] | | **Docker image reproducibility** | Base image `ubuntu:18.04` is outdated | Security updates may be missing. | Upgrade to a newer LTS base (e.g., `ubuntu:24.04`). | ["docker/gnu-builder.Dockerfile"] | | **Documentation** | No top‑level end‑to‑end guide | New contributors lack a consolidated overview. | Add a high‑level README covering build → deploy → operate workflow. | [] | **Note**: The table above reflects the consolidated *Open / Unresolved Work* list (Section 7️⃣ of the evidence). Each row is traceable to the cited source IDs.