# 2026-09-09 — WHOLE-DAY RECORD
## 晴天记录舱 · Project Qingtian / FRO
## FRO File Sharing Development Log

---

**Date:** 9 September 2026  
**Record type:** Whole-day project development record  
**Main project:** Project Qingtian / 晴天  
**Main module:** FRO → File Sharing  
**Project directory:** `~/RemoteOffice`  
**Server application:** `remoteoffice` / FastAPI / Uvicorn  
**Application port:** `8000`

---

# 1. TODAY'S MAIN OBJECTIVE

Today's main work was to complete the planned **FRO File Sharing** six-work-item implementation.

The intended final workflow is:

```text
Qingtian
   ↓
FRO
   ↓
File Sharing
   ↓
Select QNAP File / Folder
   ↓
Set Expiry
   ↓
Generate Share Link
   ↓
Public Recipient
   ↓
Name + Telephone
   ↓
Download
   ↓
HTTP Range / Resume
   ↓
Working Status
```

File Sharing remains a **function inside FRO** and is not a new main Qingtian card.

---

# 2. SIX WORK ITEMS — TODAY'S STATUS

| # | Work Item | Status |
|---|---|---|
| 1 | Remove manual Share Token entry from owner workflow | Completed |
| 2 | Recipient Name + Telephone registration/session | Completed |
| 3 | HTTP Range / resumable download | Implemented and tested |
| 4 | Working Status / download tracking | Completed and verified |
| 5 | FRO File Sharing UI structure | Completed; final visual refinement remains |
| 6 | Public external share link | Operational and externally tested |

## Overall

**6 / 6 planned work items completed.**

The remaining items are final QA, integration and production hardening rather than the six core implementation items.

---

# 3. WORK ITEM 1 — OWNER SHARE TOKEN WORKFLOW

The owner-side workflow was simplified.

The owner does not need to manually paste a long Share Token every time.

The intended workflow is:

```text
FRO
→ File Sharing
→ Select QNAP folder/file
→ Set expiry
→ Generate Link
```

The Share Token is still generated and retained server-side as the access-control mechanism for each individual share.

The Share Token is scoped to the specific shared target and is not an administrator token for the whole IEI server.

Owner-side Recipient Name / Email fields were removed.

---

# 4. WORK ITEM 2 — RECIPIENT REGISTRATION

Recipient registration was implemented.

Required information:

```text
Name
Telephone
```

The previously discussed Email OTP requirement was removed.

The UI must not claim that an OTP is sent.

The information is used for download/access records.

A recipient session is created after registration.

Current recipient session:

```text
Cookie: qingtian_share_session
Lifetime: 24 hours
```

The session is tied to the specific Share Token.

The same browser/device can therefore remember the recipient for subsequent access while the session remains valid.

---

# 5. WORK ITEM 3 — HTTP RANGE / RESUMABLE DOWNLOAD

HTTP Range support was implemented.

Important design decision:

**Original QNAP files remain intact.**

Large files are not physically split into pieces.

The download mechanism supports byte ranges such as:

```text
Range: bytes=0-1048575
Range: bytes=1048576-2097151
```

and returns:

```text
HTTP 206 Partial Content
```

## Test file

```text
RMC_2026/20260904_152208.mp4
```

Size:

```text
13,231,525 bytes
≈ 12.62 MB
```

## Successful Range tests

```text
Range 0–1,048,575
→ HTTP 206
→ 1 MB

Range 1,048,576–2,097,151
→ HTTP 206
→ 1 MB
```

This confirms the server can transmit requested byte ranges.

## Resume concept

The intended behavior is:

```text
Download starts
      ↓
Download reaches halfway
      ↓
Connection stops
      ↓
Client resumes
      ↓
Client requests remaining byte range
      ↓
Server continues from previous byte position
```

The original QNAP file is never modified.

A final real-world interruption/resume test remains part of final QA.

---

# 6. WORK ITEM 4 — WORKING STATUS / DOWNLOAD TRACKING

A persistent download-status record was implemented.

The system records:

```text
Download ID
Share Token
Target path
File name
Recipient name
Recipient telephone
IP address
User agent
Start time
Last activity
Bytes downloaded
Total bytes
Progress percentage
Status
Range start
Range end
Completion time
```

Supported status values include:

```text
Not Started
Downloading
Interrupted
Completed
```

## Meaning of Completed

`Completed` means the server successfully transmitted the file for that connection.

It does not prove that the recipient opened, read or used the downloaded file.

---

# 7. WORKING STATUS REAL TEST

The authenticated Working Status API was successfully tested publicly.

The API returned:

```text
HTTP 200
count: 3
```

Three real records were visible.

### Record 1

```text
Recipient: Foo Kai Hao
Telephone: 0192519844
File: 20260904_152208.mp4
Progress: 100%
Bytes: 13,231,525 / 13,231,525
Status: Completed
```

### Record 2

```text
Recipient: Jenny
Telephone: 0122819845
File: 20260904_152208.mp4
Progress: 100%
Bytes: 13,231,525 / 13,231,525
Status: Completed
```

### Record 3

```text
Recipient: JennyPublic
Telephone: 0122819845
File: 20260904_152208.mp4
Progress: 15.85%
Bytes: 2,097,152 / 13,231,525
Status: Downloading
```

This proves that real download activity is being recorded.

---

# 8. WORKING STATUS UI

The Working Status section was added to the FRO File Sharing interface.

Current columns:

```text
File
Recipient
Progress
Status
Started
Last Activity
```

Progress displays both percentage and transferred bytes.

Example:

```text
100.00%
12.62 MB / 12.62 MB
Completed
```

The Working Status area was then refined toward a bounded scrollable window so that a long history does not make the entire FRO page excessively long.

The desired behavior is:

```text
Working Status
┌──────────────────────────────────────────┐
│ File | Recipient | Progress | Status ... │
│------------------------------------------│
│ record                                  │
│ record                                  │
│ record                                  │
│ record                                  │
│ record                                  │
│                 ↕ scroll                 │
└──────────────────────────────────────────┘
```

A final browser visual check of the scrollbar is still required.

---

# 9. WORK ITEM 5 — FRO FILE SHARING UI STRUCTURE

File Sharing is integrated as a function under FRO.

Current structure:

```text
FRO
└── File Sharing
    ├── Create Share
    │   ├── QNAP File / Folder Browser
    │   ├── Selected Target
    │   ├── Expiry
    │   └── Generate Link
    │
    ├── Share Link
    │   └── Copy
    │
    └── Working Status
        ├── File
        ├── Recipient
        ├── Progress
        ├── Status
        ├── Started
        └── Last Activity
```

The owner-side Name / Email recipient fields were removed.

---

# 10. FRO FILE SHARING APPLICATION ROUTE

A dedicated application route was added:

```text
/fro-file-sharing
```

It renders the existing File Sharing template.

The production template remains:

```text
templates/filedrop.html
```

The route was compiled successfully and tested internally.

Internal test:

```text
http://127.0.0.1:8000/fro-file-sharing
```

Result:

```text
HTTP 200
```

The returned page contained:

```text
创建分享链接
Working Status
```

and did not show the old FRO Dashboard content.

---

# 11. TAILSCALE FUNNEL ROUTING DISCOVERY

An important routing behavior was discovered.

The public Tailscale Funnel mount:

```text
/filedrop
```

forwards to:

```text
http://127.0.0.1:8000
```

Therefore Tailscale strips the `/filedrop` mount prefix before FastAPI receives the request.

For example:

```text
Public:
https://iiei-server.tail37e617.ts.net/filedrop/share/auth

FastAPI receives:
POST /share/auth
```

This caused initial public API failures because FastAPI originally only had:

```text
/filedrop/share/auth
```

---

# 12. PUBLIC FUNNEL ALIASES

Public aliases were added to handle the stripped Funnel prefix.

Aliases include:

```text
/share/auth
/share-targets
/share/create
/share/download-status
```

Each alias calls the existing File Sharing implementation.

This allows the public `/filedrop` Funnel mount to continue working without changing the underlying File Sharing logic.

---

# 13. PUBLIC FILE SHARING UI MOUNT

The existing public `/filedrop` mount was deliberately not replaced.

It currently maps to:

```text
/filedrop
    ↓
http://127.0.0.1:8000
```

A separate public mount was added:

```text
https://iiei-server.tail37e617.ts.net/fro-file-sharing
    ↓
http://127.0.0.1:8000/filedrop
```

This allows the new FRO File Sharing UI to be accessed publicly without disturbing existing public share-link routing.

---

# 14. ADMIN AUTHENTICATION

The FRO admin token was verified.

The configured token length is:

```text
64 characters
```

The actual token value is intentionally not written into this archive.

## Local authentication

```text
POST /filedrop/share/auth
→ HTTP 200
```

## Public authentication

```text
POST https://iiei-server.tail37e617.ts.net/filedrop/share/auth
→ HTTP 200
```

Response:

```json
{
  "authenticated": true,
  "expires_in": 28800
}
```

Admin session lifetime:

```text
8 hours
```

Cookie:

```text
fro_share_admin_session
```

Important current limitation:

The admin session is stored in application memory.

Therefore restarting the `remoteoffice` container clears active admin sessions.

This should be hardened later if persistent login across container restarts is required.

---

# 15. PUBLIC QNAP TARGET BROWSER

After the public authentication alias was corrected, the public target browser was successfully tested.

Request:

```text
/filedrop/share-targets
```

Returned:

```json
{
  "name": "share-file",
  "path": "",
  "folders": [
    {
      "name": "RMC_2026",
      "path": "RMC_2026"
    }
  ],
  "files": []
}
```

This confirms that the public FRO File Sharing UI can read the QNAP Share File target after admin authentication.

---

# 16. PUBLIC SHARE CREATION

A real public share was successfully created.

Target:

```text
RMC_2026
```

Expiry:

```text
24 hours
```

The API returned:

```text
Share Token
Share path
Public URL
Target path
Target type
Target name
Expiry time
```

The public URL format is:

```text
https://iiei-server.tail37e617.ts.net/filedrop/share/<token>
```

The actual token is not recorded in this worklog.

---

# 17. EXTERNAL NETWORK DOWNLOAD TEST

The public sharing system was tested from outside the local network.

A real external download was completed.

Working Status recorded:

```text
100%
13,231,525 / 13,231,525 bytes
Completed
```

Therefore:

**Qingtian / FRO File Sharing can already provide an external Internet download without the recipient needing Tailscale.**

This is a major milestone for Work Item 6.

---

# 18. PUBLIC DOWNLOAD STATUS TEST

The public Working Status endpoint was successfully tested after the required public admin-session alias was added.

Result:

```text
HTTP 200
```

Three records were returned.

This confirms the complete chain:

```text
External download
      ↓
FRO backend
      ↓
Download tracking
      ↓
Working Status API
      ↓
FRO Working Status UI
```

---

# 19. IP ADDRESS OBSERVATION

IP addresses are recorded when available.

Examples observed today included:

```text
110.159.187.43
100.122.72.34
100.117.100.85
```

The recorded IP depends on the actual network/proxy path.

Therefore IP should be treated as connection metadata and should not be considered the sole identity mechanism.

---

# 20. IMPORTANT BACKUPS CREATED TODAY

Backups were created before significant changes.

Known backups include:

```text
app/filedrop.py.bak_20260909_before_working_status
app/filedrop.py.bak_20260909_before_working_status_api
app/filedrop.py.bak_20260909_before_admin_session_check
app/filedrop.py.bak_20260909_before_public_admin_auth_alias
app/filedrop.py.bak_20260909_before_public_share_targets_alias
app/filedrop.py.bak_20260909_before_public_share_create_alias
app/filedrop.py.bak_20260909_before_public_download_status_alias

app/routes.py.bak_20260909_before_fro_file_sharing_route

templates/filedrop.html.bak_20260909_before_working_status_ui
templates/filedrop.html.bak_20260909_before_working_status_ui_v2
```

Historical backups should not be edited.

---

# 21. DOCKER / APPLICATION VERIFICATION

The `remoteoffice` container was restarted multiple times during today's work.

Final runtime remained:

```text
remoteoffice
Uvicorn
0.0.0.0:8000
```

Python syntax checks completed successfully for modified Python files.

Example:

```bash
python3 -m py_compile app/filedrop.py
python3 -m py_compile app/routes.py
```

The application successfully restarted after the changes.

---

# 22. CURRENT PUBLIC ARCHITECTURE

```text
                         INTERNET
                            │
                            ▼
                    Tailscale Funnel
                            │
            iiei-server.tail37e617.ts.net
                            │
              ┌─────────────┴─────────────┐
              │                           │
   /fro-file-sharing                 /filedrop
              │                           │
              ▼                           ▼
  http://127.0.0.1:8000/filedrop   http://127.0.0.1:8000
              │
              ▼
       FRO File Sharing
              │
              ▼
        QNAP Share File
              │
              └── RMC_2026
```

Public share link:

```text
https://iiei-server.tail37e617.ts.net/filedrop/share/<token>
```

---

# 23. CURRENT FILE SHARING SECURITY MODEL

```text
Owner
 ↓
FRO Admin Session
 ↓
Create Share
 ↓
Unique Share Token
 ↓
Public Share Link
 ↓
Recipient Registration
 ↓
Recipient Session
 ↓
Read-only file access
 ↓
Download
 ↓
Working Status
```

The Share Token controls access to the individual shared target.

The admin token controls FRO management functions.

The recipient session controls the registered recipient's access for the specific share.

---

# 24. CURRENT LIMITATIONS / FINAL QA

The following are **not counted as missing core work items**. They are final QA or hardening tasks.

## A. Real interruption/resume test

Need to test:

```text
Start external download
→ stop around 50%
→ resume
→ verify continuation
→ verify final file size
→ verify file integrity
→ verify Working Status
```

## B. Working Status scrollbar

The scrollable Working Status area needs one final browser visual check.

The goal is to make long histories stay inside the Working Status window.

## C. Qingtian → FRO → File Sharing navigation

The normal Qingtian navigation should point to:

```text
FRO
→ File Sharing
```

using:

```text
/fro-file-sharing
```

This integration was not yet finalized today.

## D. Persistent admin session

Admin session is currently memory-based.

A future improvement can store admin sessions persistently.

## E. Download All

A previous large Download All test caused Remote SSH instability.

Do not repeat a large full-folder ZIP test until resource usage and ZIP generation behavior are reviewed.

---

# 25. NEXT SESSION PRIORITY

Recommended order:

```text
1. Connect Qingtian → FRO → File Sharing
2. Finish Working Status scrollbar visual behavior
3. Perform real interrupted-download/resume test
4. Verify final file integrity
5. Review Download All resource usage
6. Consider persistent admin session storage
7. Final production cleanup
```

---

# 26. END-OF-DAY RESULT

## Core FRO File Sharing

```text
Owner share creation        ✅
QNAP folder browser         ✅
Expiry selection            ✅
Share Token generation      ✅
Public URL generation       ✅
Recipient registration      ✅
Recipient session           ✅
External Internet access    ✅
External download           ✅
HTTP Range support          ✅
Download tracking           ✅
Working Status API          ✅
Working Status UI           ✅
Public Funnel routing       ✅
Admin authentication        ✅
Public QNAP target loading  ✅
```

## Planned work item result

**6 / 6 completed.**

## Remaining

```text
Final QA
Integration
UI refinement
Production hardening
```

---

# 27. ARCHIVE LABEL

Recommended archive name:

```text
2026-09-09_FRO_File_Sharing_Whole-Day-Record
```

Recommended folder:

```text
晴天记录舱/
└── 2026/
    └── 2026-09-09/
        ├── 2026-09-09-detail.md
        └── 2026-09-09.md
```

---

# 28. FINAL CONCLUSION

**9 September 2026 was a major FRO File Sharing milestone.**

The six planned core work items were completed.

The system can now:

```text
FRO
→ select QNAP folder
→ set expiry
→ generate share
→ expose public Internet link
→ register recipient
→ download externally
→ support HTTP Range
→ record download activity
→ display Working Status
```

The next stage is no longer basic File Sharing implementation.

The next stage is:

**integration + final QA + production hardening.**

---

# END OF WHOLE-DAY RECORD

**9 September 2026**  
**晴天记录舱 · Project Qingtian / FRO**  
**FRO File Sharing Development Day**
