## ADDED Requirements ### Requirement: AI share lifecycle separate from course publish Desktop StudyDeck SHALL provide an independently controlled “AI 配置分享” mode. Course publish authentication requirements MUST remain unchanged (unauthenticated course APIs). AI config endpoints MUST require a paired session token. #### Scenario: AI share default off - **WHEN** the parent has not enabled AI share - **THEN** AI config endpoints are unavailable or reject unauthenticated access #### Scenario: Course APIs unchanged - **WHEN** AI share is enabled - **THEN** existing course catalog/pack endpoints MUST NOT require the AI session token ### Requirement: Device pairing The system SHALL support pairing an iPad to the desktop AI share channel via QR (or short code) that conveys connection and ephemeral public-key material but MUST NOT include the apiKey. Successful pairing yields a revocable `sessionToken`. #### Scenario: Pair issues session token - **WHEN** an iPad completes a valid pairing handshake with PC AI share - **THEN** the iPad receives a sessionToken usable for subsequent encrypted config fetch #### Scenario: QR excludes apiKey - **WHEN** the PC displays an AI pairing QR - **THEN** decoding the QR MUST NOT reveal the apiKey ### Requirement: Encrypted config transfer Authenticated `GET` of AI config SHALL return an AES-GCM (or equivalent authenticated encryption) ciphertext of `AiRuntimeConfig` derived from the pairing shared secret or a key sealed at pair time. Plaintext apiKey MUST NOT be returned over cleartext JSON without encryption. #### Scenario: Encrypted payload - **WHEN** a paired iPad fetches AI config with a valid token - **THEN** the response body is encrypted such that a LAN eavesdropper without the session keys cannot recover the apiKey ### Requirement: Version compare and offline cache Before using AI features, the iPad SHALL attempt to reach PC when possible. If PC is reachable, the iPad MUST compare `updatedAt` and prefer the newer config, persisting updates to secure local storage. If PC is unreachable and a cache exists, the iPad MUST use the cache. If PC is unreachable and no cache exists, the iPad MUST block AI with a clear reason (unpaired / share off / no history). #### Scenario: PC newer wins - **WHEN** PC is reachable and PC `updatedAt` is newer than the iPad cache - **THEN** the iPad stores and uses the PC config #### Scenario: Offline with cache - **WHEN** PC is unreachable and the iPad has a previously synced config - **THEN** AI features may proceed using the cached config #### Scenario: Offline without cache - **WHEN** PC is unreachable and the iPad has no usable cached config - **THEN** AI features are unavailable with an explanatory message ### Requirement: Revoke paired devices Desktop StudyDeck SHALL allow revoking a paired device or rotating credentials such that the old sessionToken is rejected on subsequent config requests. After revoke or key rotation, the iPad cache MUST be treatable as stale on next failed sync (401/revoke). #### Scenario: Revoke rejects token - **WHEN** the parent revokes a paired device - **THEN** subsequent `/ai/config` calls with that token fail authorization ### Requirement: Server source reserved The config model and sync merge helpers SHALL accept `source: "server"` and a three-way `updatedAt` comparison hook for future subscription configs. Full cloud billing MAY be stubbed; clients MUST tolerate a disabled server source without error loops. #### Scenario: Server source stub - **WHEN** server subscription sync is not configured - **THEN** clients continue PC/local sync only and do not crash or block on missing server