npx skills add ...
npx skills add qfeius/make-platform-skills --skill make-app-service
Use when generating, refactoring, reviewing, or debugging Make App apps/service APIs and UI-Service contracts. Covers route design, apps/docs/api.md, layered structure, Make adapters, direct Make response passthrough, schema normalization including independent fields/createFields collections, record CRUD, record-write-permission and records/bulk, list filter/sort/groupFilter parsing, record groups, Entity Preset, candidate/lookup/file proxies, runtime config, login-context forwarding, AbortSignal propagation, validation, logging, and tests. Always coordinate /api/make/app/principal/permission through make-app-permission. Use make-app-actions for action semantics, make-app-sort for sorting, make-app-filter for filtering, and make-app-group for grouping. Does not own UI layout, auth, permission policy, build/runtime, DSL, Make CLI deployment, or CanvasTable internals.
npx skills add qfeius/make-platform-skills --skill make-app-service
Use this skill for Make App Service API work in apps/service.
make-app-service owns the Service API contract between apps/ui and apps/service, thin Make Data API orchestration, Service route shape, Make adapter runtime config semantics, direct Make response passthrough, Service-side validation, boundary logging, and Service API tests.
It does not own record-action behavior (make-app-actions), sorting behavior (make-app-sort), filtering behavior (make-app-filter), grouping behavior (make-app-group), Make AI 助手 transport semantics (make-ai-assistant), UI layout (makeui), authentication implementation (make-app-auth), single-app permission logic (make-app-permission), runtime build/start contracts (make-app-runtime), DSL modeling (makedsl), Make CLI execution (makecli), or CanvasTable rendering/editing (canvas-table-integration).
apps/docs/api.md, apps/service/src, apps/service/src/config.ts or host-equivalent config entry, existing tests, and the host project's declared data flow.apps/docs/api.md before or with any Service route or response-shape change./api/**. Prefix-free /app/**, /auth/**, or /health routes may be local compatibility only; do not document them as the published UI contract unless the deploy route actually exposes them.apps/docs/api.md names it as non-proxy; ordinary completed Make errors remain unchanged.app.ts, server.ts, config.ts, logger.ts, make-client/, services/, utils/, with tests beside the route/adapter/helper they cover.appKey from normalized runtime config, not from route-local domains or UI input.make-app-permission, including /api/make/app/principal/permission; do not omit it from a generated or refactored Make App.fields and createFields separately; missing createFields means an empty create collection with no fallback to fields. Preserve unknown response properties, including editableFields, but leave their permission semantics to make-app-permission.record-write-permission route before edit UI and the records/bulk route for batch edit; use make-app-actions for target, permission, one-request semantics, and the established complete UI-Service response contract. Do not apply generic passthrough/normalization rules to alter either action route's successful or failed response shape.AbortSignal from the Service boundary into every downstream adapter; read references/service-api-contracts.md before implementation.@qfei-design/make-ai-assistant, use make-ai-assistant for the Make App AI Chat protocol first. Service then implements only its documented route handlers, proxy adapter, config validation, logging, cancellation, and tests.| Task / topic | Read |
|---|---|
| Service route shapes and UI-Service response contracts | references/service-api-contracts.md |
Request cancellation, client disconnect handling, downstream AbortSignal propagation | references/service-api-contracts.md |
| Service folder structure, layering, logging, errors | references/service-layering.md |
Make Data API adapter rules, schema fields / createFields, records, files, lookup, candidates | references/make-data-adapter.md |
| Test requirements, contract checks, safety review | references/testing-and-safety.md |
| Single-app permission proxy, Make IAM principal permission, app-scope permission payloads | Use make-app-permission |
| Auth proxy, cookies, unified login, 401/403 behavior | Use make-app-auth |
Service build output, port 3000, dist/server.js, package scripts, publish readiness | Use make-app-runtime |
| UI layout, forms, detail display, visual states | Use makeui |
| Make field/table rendering in CanvasTable | Use canvas-table-integration |
| Record sorting, sortable capabilities, Preset sort, records sort | Use make-app-sort |
| Advanced filter package behavior and Preset filter | Use make-app-filter |
| Record grouping, groupable capabilities, Preset group, record-groups, groupFilter | Use make-app-group |
| Record action precheck, strict selection target, one-request batch update | Use make-app-actions |
| Make App AI 助手, AI助手, AI 对话框, SSE, Agent Gateway, assistant capabilities, interface domain config | Use make-ai-assistant for the confirmed /api/make/app/ai/v1/** 18-operation protocol. Service owns routes, validation, logs, cancellation, and runtime config consumption |
make-app-service defines Service-owned app APIs such as schema, records, candidates, lookup options, file proxy, and thin custom orchestration.make-app-observability for the default request Trace ID: validate or create it at the boundary, return X-Log-Id, carry safe context into logs, and forward only validated trace headers to Make Gateway. This Skill owns the route and adapter implementation, while make-app-observability owns the cross-boundary invariant and audit.MAKE_APP_KEY and MAKE_API_BASE_URL, while leaving deployment injection to runtime/operations.make-app-auth. It may still mount and document the App Service auth proxy path required by the host contract, normally /api/make/auth/** and /api/make/oauth/** for Make Deploy Service-fronted Apps that use gatewayBaseUrl: "/api/make".make-app-permission. It should still provide the Service layering, logging, tests, and docs needed by that permission proxy.make-app-runtime.makedsl.makeui and canvas-table-integration.make-ai-assistant. The current Make App AI adapter does not carry Artifact payloads.Generated or refactored Make App Service code should provide these capabilities when the UI needs them and the host project does not already have equivalent routes:
/api/health, /api/config for published UI access; /health may exist as local or k8s-probe compatibility/api/schema, /api/entities/:entityKey/fields/api/make/app/principal/permission through make-app-permissionmake-ai-assistant: expose the exact /api/make/app/ai/v1/** 18-operation allowlist for capabilities, paginated Agents, multi-session chats, feedback, messages/history, response events/snapshot/cancel, uploads/parts/complete, and content bytes; never a generic proxymake-app-actionsKeep route handlers small. Put Make/backend calls in adapter modules, cross-route business orchestration in services/, and pure schema/value helpers in utils/.
apps/docs/api.md is the UI-Service contract source. Do not change Service route behavior without updating it.gatewayBaseUrl: "/api/make", apps/docs/api.md must document published browser paths under /api/make/**, for example /api/make/auth/**, /api/make/oauth/**, and /api/make/app/**. Do not document prefix-free /app/** as the published path unless the deploy HTTPRoute exposes it. Older /api projects may keep /api/auth/** and /api/app/** only as an explicit legacy contract.apps/service code must use a layered, componentized source structure instead of flat route/adapter/helper files. For new Make POC Services, default to the platform tree: app.ts, server.ts, config.ts, logger.ts, make-client/ for Make/backend adapters, services/ for multi-step orchestration, utils/ for pure helpers, and colocated tests.apps/service/src tree is a readiness defect for generated POC work when it mixes route registration, Make request construction, schema normalization, lookup/file orchestration, config parsing, logging, and helpers side by side. Split it before reporting the Service as complete.app.ts or routes/ only validate input, call a service/adapter, map Service-owned preflight errors, log safe boundary context, and send the documented response. Ordinary direct Make proxies preserve completed HTTP status, Content-Type, and body for 2xx, 4xx, and 5xx; the selected Make AI assistant adapter instead follows its explicit safe-error contract. Do not put raw Make payload construction, schema variant parsing, record lookup orchestration, file proxy mapping, or custom workflow steps directly into route handlers.apps/docs/api.md explicitly marks it as non-proxy. Start from the default route-response-mode table in references/service-api-contracts.md, then document any host-specific exception and its migration. Ordinary completed Make errors remain unchanged; the selected Make AI assistant error contract is a separately documented exception.appKey, X-Make-Target, Make response code checks, pagination translation, file body mapping, and consuming a prepared login/session forwarding context. Auth/session mechanics and shared forwarding helpers belong to make-app-auth; publish/runtime proxy header contracts belong to make-app-runtime./make/data/v1/record; local preview with MAKE_APP_LOCAL_PREVIEW=true uses makecli configure resolve --target local-preview --output=json field make_api_origin plus /api/make/data/v1/record. This applies to record list, record detail, lookup target-record reads, and any custom Service route that reads Make records.Cookie session header when the host uses cookie/unified-login auth, preserve an existing Authorization header only when the host contract already uses bearer auth, and apply the host gateway context headers such as X-Forwarded-Host and X-Forwarded-Proto through the shared auth/runtime helper. Do not invent auth policy here; use make-app-auth for auth mechanics, but do not drop the login context before calling gateway.makecli as a data source. Do not shell out to makecli, npx makecli, local makecli config, or makecli JSON stdout to serve schema, records, candidates, lookup options, files, or custom API data. Online Service containers do not have makecli, so runtime data must come from Make gateway/API adapters.appKey from deployment-injected MAKE_APP_KEY; generated production code must not invent, hard-code, or let UI input override that scope. A documented protocol route may carry appKey in its query or body only when the Service validates exact equality with MAKE_APP_KEY before calling an adapter.MAKE_APP_KEY is missing for a Service that calls Make Meta/Data APIs, config loading must fail with a clear non-secret error before the Service is reported ready. Local test fixtures may inject MAKE_APP_KEY explicitly.apps/service/src/config.ts or the host equivalent. MAKE_API_BASE_URL is the preferred published gateway-origin env var; MAKE_SERVER_URL is a compatibility alias only. Local preview derives its public gateway origin from makecli configure resolve --target local-preview --output=json instead of deployment env.MAKE_API_BASE_URL nor MAKE_SERVER_URL is configured for a Make-backed Service, config loading must fail with a clear non-secret error before the Service is reported ready.MAKE_API_BASE_URL / MAKE_SERVER_URL values are strict k8s gateway origins such as http://make-gateway.make-dev. New generated Service code must not put /make, /api/make, /meta, /data, /auth, or another service path scope in this env var. Local-preview resolve output must be consumed as make_api_origin; if older makecli fallback returns or reads a path-scoped public /api/make API base, normalize that only inside the local-preview adapter./api/make/**; published uses k8s gateway origin + /make/**, such as http://make-gateway.make-dev/make/meta/** and http://make-gateway.make-dev/make/data/**.make-ai-assistant: the browser calls the fixed /api/make/app/ai/v1/** 18-operation family through same origin; local preview Service upstreams use make_api_origin plus /api/make/app/ai/v1/**; published Service upstreams use the strict origin from MAKE_API_BASE_URL or its compatibility alias MAKE_SERVER_URL plus /make/app/ai/v1/**. Service must read deployed scope from MAKE_APP_KEY and reject every query/body appKey that differs from it; every non-GET/HEAD request requires one HTTP(S) same-origin Origin checked against the selected Host. Do not add an assistant-only/AI Gateway/Agent Gateway origin, token, environment variable, or hard-coded domain. Preserve bare JSON objects, empty 204 responses, Make-AI-Api-Version, SSE, and bytes as separate success modes, and do not narrow valid protocol DTOs in a host validator. For AI errors, preserve bounded schema-valid flat {code,message,requestId?,details?} with its HTTP status, including extensible unknown codes; malformed/non-public upstream errors become a safe Service error without leaking raw diagnostics. Never remap a valid public typed error to 502./make out of MAKE_API_BASE_URL, and do not overload a path-scoped base URL to reach unrelated services./api/make prefix. /api/make/** belongs to same-origin browser access, Service ingress, and local-preview public gateway calls; published Service internal upstream URLs use gateway-origin plus /make.apps/dsl/**, /dsl/**, or copied *.yaml files to start or serve schema/data in published Apps.entity.properties.fields, entity.fields, or the host-documented equivalent at the Service/API boundary, and preserve field capabilities.sortable / capabilities.groupable for sorting and grouping.fields and createFields as separate collections. Normalize each collection independently; a missing or invalid createFields becomes [] and never falls back to fields. Preserve editableFields as response metadata when the host contract requires lossless forwarding, but do not use it to derive current edit behavior./preset/v1/entity adapter with MakeService.GetResource / MakeService.UpdateResource, preserve the established login context, and update only submitted dimensions. Use make-app-sort, make-app-filter, and make-app-group for dimension semantics.capabilities.sortable === true. Reject invalid, duplicate, non-sortable, or more-than-five rules before Make calls.GET /api/users and GET /api/departments or the host equivalent; do not use local demo arrays in generated Service.{ options, total }. Do not expose full target records to selector UIs by default.<img src> cannot attach Authorization. When Make file downloads require a bearer token, keep the URL browser-facing through a Service download proxy, verify the current App session first, and let only the Service adapter attach the deployment-injected token. Do not put Make tokens or raw /data/v1/download/** URLs in UI state, public config, JSX, or logs.AbortSignal. Do not stop at ignoring a stale response, and do not treat an expected AbortError as a user-visible 5xx failure.make-app-permission and its required tests.record-write-permission and records/bulk, follow make-app-actions:
precheck the complete target with one Make /data/v1/permission call, parse the
explicit-selection HTTP 200 / business-code 20000032 denial and its
noPermissionRecordIds losslessly from the raw response before JavaScript
Number coercion and generic Make error mapping, keep select-all 403 denial
ID-less, reuse the target for one Make /data/v1/field call, and never split
diagnostics or loop single-record updates.Prefer these UI-Service contracts for new Make App Service projects unless the host project already documents equivalent routes:
Lookup relation update routes are optional and should be generated only when the UI needs editable lookup relationships and the Service can preserve a full qfei_relation snapshot safely.
makeui: this skill provides Service contracts and normalized API shapes; makeui decides how UI renders them.make-app-permission: this skill provides Service layering and tests; make-app-permission owns the principal permission route, IAM upstream path, App scope payload, and frontend permission contract.canvas-table-integration: this skill provides schema/records/candidate APIs and owns Service-side disconnect-to-downstream cancellation; table rendering, editing UI, and browser-side virtual-page scheduling stay in the canvas skill.make-app-sort: this skill implements and tests Preset/records routes and Make adapters; make-app-sort owns sortable rules, draft/save timing, and header linkage.make-app-filter: this skill implements and tests Preset/records routes and Make adapters; make-app-filter owns package filter behavior, hydration, and save timing.make-app-group: this skill implements and tests Preset group, record-groups, records groupFilter, and Make adapters; make-app-group owns groupable rules, groupFilter composition, grouped data timing, and CanvasTable grouped-flow coordination.make-app-actions: this skill implements and tests record-write-permission, records/bulk, strict target parsing, Make adapters, and error mapping; make-app-actions owns selection intent, action timing, permission-key choice, frozen snapshots, and UI feedback.make-ai-assistant: this skill implements Make App AI route handlers, proxy adapters, runtime config validation, safe logs, AbortSignal propagation, and Service tests; make-ai-assistant owns package integration, the v1 18-operation DTO/response/stream semantics, multi-session behavior, and interface-domain rules.make-app-auth: this skill may preserve Service-fronted app route shape, but auth proxy and session behavior stay in auth.make-app-runtime: this skill writes Service source and tests; runtime build/start/port checks stay in runtime.