# Campus Mood Weather — Requirements Specification (English)

> V3.0 / UW3; date: 2026-10-10.  
> Team: [TO FILL:TEAM_NAME]; specification owner: [TO FILL:SRS_OWNER].  
> Companion [English blog](博客_英文.md), [Chinese specification](需求规格说明书_中文.md) and [revised project plan](项目方案_天气宇宙版_修订.md).  
> This is a specification for future implementation and acceptance. This turn produced documents only; existing code has not been verified against UW3.

## 1. Purpose, scope and readers

Give product, design, implementation, testing and course reviewers one first-release baseline: private weather journals, a lightweight personal Weather Universe, campus places, voluntary small tasks and data control. UW3-F01–UW3-F24 are new IDs; old feature numbers must not be reused by matching their suffixes.

V1 excludes anonymous public posts, free-form comments, stranger interaction and real campus contributions. UW3-F24 is a fixed fictional explanation and preview. M0 uses synthetic data only; real private trials require authorization and data-lifecycle validation first.

## 2. Actors and visibility

| Actor | Allowed | Forbidden |
| --- | --- | --- |
| Visitor | Browse places, static tasks, support information and simulation | Read real private entries or save another person's state |
| Active student account | Own journals, Universe, preferences, history, favorites, corrections, export and closure | Choose another owner, read another export or directly change official place data |
| Disabled account | Necessary public content; cleanup progress through a restricted receipt | Private journal, card, decoration, export and history endpoints |
| Data operator | Verify places/tasks/resources and process corrections | Read journal writing, individual weather sequences or WeChat identity mappings |
| Maintenance job | Authorized export/cleanup/expiry work and necessary diagnostics | Expose private payloads to users or logs |
| Console maintainer | Necessary authorized infrastructure maintenance | Share the main account by default or browse private data merely because of administrator status |

Saving a journal is the only journal action. It never triggers publication, statistics or diagnosis. Controlled cloud processing does not mean data is impossible for the service to decrypt. Coursework member IDs do not become an application requirement to collect student IDs or real names.

## 3. Shared rules

### 3.1 Dates and records

- Business timezone: Asia/Shanghai; timestamps: UTC; business dates: YYYY-MM-DD.
- Owner/date is unique. Recording again opens editing. New entries cover today and the previous 29 days; owners may edit existing older entries.
- Updates supply the current version. Competing stale updates never silently overwrite. Retries bind the original request ID and input digest.
- Codes are SUNNY, PARTLY_CLOUDY, CLOUDY, RAINY and STORMY: Sunny, Partly Cloudy, Cloudy, Light Rain and Stormy. Users interpret them; no health score or ranking is produced.
- Up to five tags and 0–1,000 Unicode code points of writing. All text limits use this convention. Both writing and tags may be empty.
- V1 offers eight fixed tags: Study, Rest, Exercise, Social, Alone Time, Anticipation, Tiredness and Calm. Select at most five distinct tags; custom-tag input is excluded. The server validates fixed IDs against a whitelist and rejects unknown or duplicate IDs. This library is a design choice that may change through a versioned update after prototype review.

### 3.2 Universe, statistics and display

- Calendar, monthly archive, cards, distribution and timeline share source entries; cache only necessary derived indexes without duplicated journal writing and invalidate them on deletion.
- Card previews default off; details are owner-only. Missing dates stay blank with neutral empty states.
- Distribution uses recorded days; gaps are neither cloudy weather nor interpolated scores.
- Period windows are 7/30/90 days. Fewer than three entries produce no trend conclusion, although categories remain readable.
- Limit static decoration to six stickers and two backgrounds, original or properly licensed. Disable/reset never affects core functions.
- Closing the application does not guarantee recovery of unsaved writing. Safe reauthentication by the same account may retain current memory input; switching accounts must clear it.

### 3.3 Campus information and tasks

- Places include campus, opening status/hours, environment tags, accessibility and verification date/person. Operators set validity; stale or closed places are not suggested as available.
- Maps mark official places only. Request location for user-initiated actions; denial preserves list access. Disclose actual map-provider data processing.
- Authorized people verify support resources; expired items are disabled. Missing information has an unavailable state, never fictional service contacts.
- Corrections contain 1–200 code points and are visible only to the submitter and authorized operators. Review updates official data without publishing the submitted writing.
- Offer at most three tasks. Completion/skipping is self-reported and idempotent under owner/template/date/state rules; no photos or GPS evidence.

### 3.4 Identity and data lifecycle

- Derive identity from trusted invocation context; check active internal account and ownership. Client-supplied owners/roles never grant access.
- A disabled account remains barred from old private data even with a valid platform session. Do not create a new session to restore old entries automatically.
- Entry deletion immediately denies business reads and removes views, decoration links, client remnants and outstanding affected exports. Primary payload cleanup within 24 hours is a target to validate.
- Export JSON or Markdown; each download checks ownership and task state. Credentials last at most five minutes and server files at most 24 hours. Downloaded copies belong to the user to manage.
- Account cleanup within seven days is a target. Progress receipts cannot restore accounts or export. Tentative backup retention is at most 30 days, subject to capability verification.
- Replay deletion markers without writing before reopening restored data. Failed work is never reported as completed.

## 4. Functional requirements

Responsibilities follow the current [team division of labor in the English blog](博客_英文.md#3-project-division-of-labor). Xiang Hong coordinates the project and the recording/review back end; Junhan Huang handles campus services; Jiawei Fang handles tasks and personal data management. The five front-end members divide the modules listed below. Jiaqi Zhu provides UI/UX design, Xiang Yu defines data structures and rules, Yuen Lin leads functional and integration checks, and Qizhen Cai leads access, privacy, performance, and usability checks. Qizhen Chen coordinates front-end integration, Xiang Hong coordinates back-end integration and cloud configuration, and Xiang Yu coordinates the data configuration.

### UW3-F01 Weather recording

- **Priority / implementation roles:** P0 / Yifan Ji (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: Login and internal account state (abbreviated IDs refer to UW3).
- **Input and behavior:** Choose one of five weather types; writing is optional and each user has at most one entry per Shanghai calendar date.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** A weather-only entry saves successfully; concurrent creation yields one entry or an explicit conflict; future dates are rejected.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T01. Every item is currently awaiting verification.

### UW3-F02 Tags and writing prompts

- **Priority / implementation roles:** P0 / Yifan Ji (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F01 (abbreviated IDs refer to UW3).
- **Input and behavior:** Allow up to five tags and 0–1,000 Unicode code points of writing; static prompts can be changed or hidden and do not create a psychological profile.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Chinese text and emoji use the same counting rule; limits produce a clear message without losing input; hiding prompts does not affect weather selection.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T02. Every item is currently awaiting verification.

### UW3-F03 Backfilling and editing

- **Priority / implementation roles:** P0 / Yifan Ji (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F01 (abbreviated IDs refer to UW3).
- **Input and behavior:** New entries may cover today and the previous 29 calendar days; existing older entries remain editable; versions prevent overwriting newer changes from another device.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** The 30-day boundary is correct; saving an old version shows a conflict; recording again on the same date opens the existing entry.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T03. Every item is currently awaiting verification.

### UW3-F04 Deletion and synchronized views

- **Priority / implementation roles:** P0 / Yifan Ji (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F01 (abbreviated IDs refer to UW3).
- **Input and behavior:** After owner confirmation, remove the entry and its decoration links from calendars, cards, distributions and timelines; invalidate outstanding affected exports and clear client copies.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Reopening or refreshing does not restore the entry; other accounts cannot delete it; explain that downloaded personal copies remain the user's responsibility.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T04. Every item is currently awaiting verification.

### UW3-F05 Weather calendar

- **Priority / implementation roles:** P0 / Zhifeng Dai (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F01, 03, 04 (abbreviated IDs refer to UW3).
- **Input and behavior:** Show actual entries for the selected month with icons and names; missing dates stay blank; selecting a date opens its entry or permitted backfilling.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Month transitions, leap days and empty months work; missing dates are not filled with cloudy weather; enlarged text remains usable.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T05. Every item is currently awaiting verification.

### UW3-F06 Personal weather distribution

- **Priority / implementation roles:** P0 / Zhifeng Dai (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F01, 04 (abbreviated IDs refer to UW3).
- **Input and behavior:** Calculate five category proportions from recorded days only, show the denominator and a text equivalent, and produce no health score.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Three entries produce a denominator of three; empty data does not divide by zero; results match entries and ignore decorations.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T06. Every item is currently awaiting verification.

### UW3-F07 Period timeline

- **Priority / implementation roles:** P1 / Zhifeng Dai (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F05, 06 (abbreviated IDs refer to UW3).
- **Input and behavior:** Provide 7/30/90-day date-and-weather lists or categorical charts, mark missing dates, and avoid a 1–5 mood score or judgments of improvement.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Windows use business dates; gaps are not interpolated; fewer than three entries show data and a notice without trend conclusions.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T07. Every item is currently awaiting verification.

### UW3-F08 Weather Universe monthly archive

- **Priority / implementation roles:** P1 / Zhifeng Dai (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F03, 05 (abbreviated IDs refer to UW3).
- **Input and behavior:** Organize the owner's entries by year and month and open monthly impression-card lists; the archive and calendar share the original entries rather than duplicate writing.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** A chosen month's entry is reachable within three actions; month switching never exposes another user; empty months have a neutral state.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T08. Every item is currently awaiting verification.

### UW3-F09 Private weather cards and details

- **Priority / implementation roles:** P1 / Zhifeng Dai (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F01, 03, 04, 08 (abbreviated IDs refer to UW3).
- **Input and behavior:** One entry produces one card showing its date, icon and name; writing previews are hidden by default and may be enabled; details show the owner's original entry.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Editing updates the same card; disabling previews removes writing from lists; edits and deletion stay synchronized with details.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T09. Every item is currently awaiting verification.

### UW3-F10 Light decoration and reset

- **Priority / implementation roles:** P1 / Zhifeng Dai (front end), Xiang Hong (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F09 (abbreviated IDs refer to UW3).
- **Input and behavior:** Limit the first version to six original static stickers and two backgrounds; store asset references, support changing, hiding and resetting, and use no unlock tasks or streak rewards.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Failed assets do not prevent reading weather; resetting is repeatable; decoration never changes dates, weather, writing or statistics.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T10. Every item is currently awaiting verification.

### UW3-F11 Campus place list and map

- **Priority / implementation roles:** P1 / Qinghan Zhang (front end), Junhan Huang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** Visitors may browse relevant non-sensitive content; actions that save personal state require authentication. Dependencies: Verified-data administration (abbreviated IDs refer to UW3).
- **Input and behavior:** Browse verified campus places; default to a list without location access; load maps on demand and mark places rather than individual moods.
- **Visibility and outcome:** Only places, static task suggestions, verified support information and synthetic explanations are publicly browsable; favorites, corrections, history and journals remain owner controlled. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** The list works when maps fail or location is denied; unverified examples are marked fictional; closed places are excluded from recommendations.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T11. Every item is currently awaiting verification.

### UW3-F12 Place preference filters

- **Priority / implementation roles:** P1 / Qinghan Zhang (front end), Junhan Huang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** Visitors may browse relevant non-sensitive content; actions that save personal state require authentication. Dependencies: UW3-F11 (abbreviated IDs refer to UW3).
- **Input and behavior:** Filter by current preferences such as quiet, indoor, green, seating and accessibility; never infer preferences from private writing.
- **Visibility and outcome:** Only places, static task suggestions, verified support information and synthetic explanations are publicly browsable; favorites, corrections, history and journals remain owner controlled. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Combined filters and reset work; no-result states allow changing filters; requests contain no private weather or writing.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T12. Every item is currently awaiting verification.

### UW3-F13 Place details and voluntary navigation

- **Priority / implementation roles:** P1 / Qinghan Zhang (front end), Junhan Huang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** Visitors may browse relevant non-sensitive content; actions that save personal state require authentication. Dependencies: UW3-F11 (abbreviated IDs refer to UW3).
- **Input and behavior:** Show opening hours, status, precautions, accessibility and verification date; navigation is user initiated and denied permissions do not block details.
- **Visibility and outcome:** Only places, static task suggestions, verified support information and synthetic explanations are publicly browsable; favorites, corrections, history and journals remain owner controlled. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Closed or stale information is flagged; prohibited places are not recommended; navigation errors return to the list without tracking movement.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T13. Every item is currently awaiting verification.

### UW3-F14 Place favorites

- **Priority / implementation roles:** P1 / Qinghan Zhang (front end), Junhan Huang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: Login and UW3-F11 (abbreviated IDs refer to UW3).
- **Input and behavior:** Owners may add, remove and view favorites; repeated actions are idempotent; removed places are marked unavailable or can be removed.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Repeated clicks create no duplicates; accounts have separate favorites; removed places are never presented as available.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T14. Every item is currently awaiting verification.

### UW3-F15 Place corrections and status

- **Priority / implementation roles:** P1 / Qinghan Zhang (front end), Junhan Huang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: Login, UW3-F11 and correction administration (abbreviated IDs refer to UW3).
- **Input and behavior:** Authenticated users submit 1–200-character corrections and see pending/accepted/not-accepted status; authorized operators review changes before publication.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Users cannot directly change coordinates; other users cannot see submitter identities; empty or duplicate submissions are controlled; decisions are audited.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T15. Every item is currently awaiting verification.

### UW3-F16 Campus support resources

- **Priority / implementation roles:** P1 / Qinghan Zhang (front end), Junhan Huang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** Visitors may browse relevant non-sensitive content; actions that save personal state require authentication. Dependencies: Verified-data administration (abbreviated IDs refer to UW3).
- **Input and behavior:** Show appointment paths, service times and verification dates checked by authorized campus staff; expire stale entries and never invent contact information.
- **Visibility and outcome:** Only places, static task suggestions, verified support information and synthetic explanations are publicly browsable; favorites, corrections, history and journals remain owner controlled. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Missing verification shows an unavailable notice; stale links are not presented as current; stormy weather never triggers automatic disclosure to staff or family.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T16. Every item is currently awaiting verification.

### UW3-F17 Voluntary small-task selection

- **Priority / implementation roles:** P1 / Qizhen Chen (front end), Jiawei Fang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** Visitors may browse relevant non-sensitive content; actions that save personal state require authentication. Dependencies: Task-template administration (abbreviated IDs refer to UW3).
- **Input and behavior:** Offer at most three static tasks based on current duration and indoor/outdoor preferences with alternatives; never send journals to a recommender.
- **Visibility and outcome:** Only places, static task suggestions, verified support information and synthetic explanations are publicly browsable; favorites, corrections, history and journals remain owner controlled. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Preferences yield matching tasks; no matches allow leaving; all weather categories can use the same task library.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T17. Every item is currently awaiting verification.

### UW3-F18 Complete, replace or skip tasks

- **Priority / implementation roles:** P1 / Qizhen Chen (front end), Jiawei Fang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: Login and UW3-F17 (abbreviated IDs refer to UW3).
- **Input and behavior:** Users self-report completion, replace a task or skip it; save an explicit state without photos, location or streak evidence.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Repeated completion is recorded once; skipping has no penalty; retries create no duplicate events; cancellation preserves the prior state.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T18. Every item is currently awaiting verification.

### UW3-F19 Small-task history

- **Priority / implementation roles:** P1 / Qizhen Chen (front end), Jiawei Fang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F18 (abbreviated IDs refer to UW3).
- **Input and behavior:** Owners review completed or skipped tasks by date and may delete history; no points, levels, comparisons or guilt-based completion targets.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Status matches actions; deleted history stays absent after refresh; other accounts cannot read it; empty history has a neutral state.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T19. Every item is currently awaiting verification.

### UW3-F20 What do I want right now?

- **Priority / implementation roles:** P1 / Yifan Ji (front end), Jiawei Fang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** Visitors may browse relevant non-sensitive content; actions that save personal state require authentication. Dependencies: UW3-F01, 08, 11, 17 (abbreviated IDs refer to UW3).
- **Input and behavior:** Link to recording, private writing, places, small tasks, reflection and doing nothing; writing stays private and the first version has no public-posting path.
- **Visibility and outcome:** Only places, static task suggestions, verified support information and synthetic explanations are publicly browsable; favorites, corrections, history and journals remain owner controlled. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Places and tasks require no prior entry; doing nothing returns directly; choices create no psychological profile or nagging notification.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T20. Every item is currently awaiting verification.

### UW3-F21 Privacy and display preferences

- **Priority / implementation roles:** P0 / Linhan Chen (front end), Jiawei Fang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: Login and display state (abbreviated IDs refer to UW3).
- **Input and behavior:** Explain private visibility and controlled server processing; previews default off, decoration and motion can be disabled, and account changes clear sensitive page state.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Disabling effects does not block saving, export or deletion; previous-account content does not remain; no absolute-anonymity or end-to-end-encryption claim is made.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T21. Every item is currently awaiting verification.

### UW3-F22 Owner data export

- **Priority / implementation roles:** P0 / Linhan Chen (front end), Jiawei Fang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F01, 04, 21 and job maintenance (abbreviated IDs refer to UW3).
- **Input and behavior:** Owners generate JSON or Markdown copies; every download checks account and task validity; temporary credentials last at most five minutes and server files at most 24 hours; deletion invalidates unclaimed old exports.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Other accounts, disabled accounts and expired credentials cannot download; decoration settings do not block export; cleanup is retryable and failures are not reported as completed.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T22. Every item is currently awaiting verification.

### UW3-F23 Account closure and cleanup status

- **Priority / implementation roles:** P0 / Linhan Chen (front end), Jiawei Fang (back end); Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** The authenticated owner with an active internal account. Dependencies: UW3-F04, 22 and account/job states (abbreviated IDs refer to UW3).
- **Input and behavior:** After owner reconfirmation, disable the internal account and deny old identity access to private endpoints; seven-day primary cleanup is a target to validate; a restricted receipt reports progress only; backups follow the verified policy.
- **Visibility and outcome:** The result is owner-only; necessary server processing is controlled, and ordinary data operators cannot inspect private content. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** Old credentials cannot read journals or exports after closure; re-entry cannot restore old data; retries do not revive entries; incomplete cleanup stays pending or failed.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T23. Every item is currently awaiting verification.

### UW3-F24 Campus Weather explanation and simulated preview

- **Priority / implementation roles:** P1 / Linhan Chen (front end); Xiang Hong reviews the simulation explanation; no real collection service; Yuen Lin reviews functionality, and Qizhen Cai reviews applicable access, privacy, and performance requirements.
- **User and prerequisites:** Visitors may browse relevant non-sensitive content; actions that save personal state require authentication. Dependencies: Fixed synthetic content (abbreviated IDs refer to UW3).
- **Input and behavior:** Use fixed fictional data to explain a possible opt-in campus summary; label it simulated and not representative; collect no real contributions and expose no real-statistics write endpoint.
- **Visibility and outcome:** Only places, static task suggestions, verified support information and synthetic explanations are publicly browsable; favorites, corrections, history and journals remain owner controlled. Writes return an explicit success, conflict or failure state; unsaved actions do not count as completed.
- **Exceptions:** Invalid inputs, missing/inactive accounts, unavailable resources, denied access and dependency failures receive clear messages. Failed writes preserve current input; timeouts check or retry the original request ID. Failed reads must never reveal another or a previous account's cache.
- **Acceptance:** The demo reads no private entries; no hidden real-contribution endpoint exists; users distinguish personal entries, simulation and future real aggregation.
- **Evidence:** Record normal behavior and key boundaries, version and environment under UW3-T24. Every item is currently awaiting verification.


## 5. Essential supporting work

| ID | Work | Completion condition |
| --- | --- | --- |
| UW3-S01 | Login, internal accounts and campus configuration | Trusted identity and disabled-account checks; campus selection is not enrollment verification |
| UW3-S02 | Authorized information administration | Role checks for places/tasks/resources/corrections; private reads denied even through direct calls |
| UW3-S03 | Unique writes, versions and idempotency | Verify concurrency in the real cloud environment |
| UW3-S04 | Export, deletion and expiry jobs | Observable status, repeat-safe retries and escalation; no arbitrary student-triggered maintenance |
| UW3-S05 | Environments, assets and dependencies | Separate synthetic and real environments; no credentials in repositories; record versions/licenses |
| UW3-S06 | Diagnostics, backup and restore | Non-sensitive logs and incident records; verified plan capabilities; no revival of deleted entries |

Supporting work counts toward contributions and complete delivery; it does not inflate the 24 business requirements.

## 6. Non-functional requirements

| ID | Requirement | Validation |
| --- | --- | --- |
| UW3-N01 | Ownership and role isolation | Two accounts, visitors, disabled users, operators and jobs; reads/writes and direct calls |
| UW3-N02 | Reliable writes and recovery | Same-day races, stale versions, timeout retries and deletion/restore |
| UW3-N03 | Data minimization | Owner endpoints return only needed data; public/operator responses and logs/analytics contain no journal writing, tags, personal weather sequences, exact location, WeChat identities or private download credentials; authentication credentials are used only for necessary authentication and never logged |
| UW3-N04 | Usability targets | 12 participants: first-entry success ≥90% and median ≤30 seconds; visibility understanding ≥90%; place discovery within three actions ≥80%; report counts/failures |
| UW3-N05 | Readability and compatibility | Larger text, icons/names, contrast target 4.5:1, 44px touch target, disabled motion, Android/iOS |
| UW3-N06 | Initial performance target | Interactive first screen ≤2.5 seconds; at least 20 runs with device/network/data and cold-start results |
| UW3-N07 | Deletion/export control | Immediate hiding/deactivation; measured cleanup/expiry evidence; failures remain explicit |
| UW3-N08 | Scope and labeling | Persistent simulation labels; no real-contribution or public-posting entry; no clinical judgment or efficacy claim |

These are targets awaiting verification. With 12 participants, 90% means at least 11 and 80% means at least 10. Interviews and trials have separate evidence.

## 7. Acceptance and evidence

Each UW3-Fxx maps to UW3-Txx using its section 4 acceptance criteria. Also execute cross-module checks:

| Test | Action | Expected |
| --- | --- | --- |
| UW3-X01 | A reads/changes/deletes B's entries, decoration, favorites, history or exports | Denied without leaking private object existence |
| UW3-X02 | An ordinary data operator directly requests private content | Denied; console permissions reviewed separately |
| UW3-X03 | Competing same-day creates/edits and timeout retries | Correct uniqueness, version conflict and idempotency |
| UW3-X04 | Revisit Universe/calendar/distribution/timeline and claim an old export after deletion | No remnant; outstanding affected export invalid |
| UW3-X05 | Use old platform identity/download credentials and progress receipt after closure | Private business denied; receipt returns progress only |
| UW3-X06 | Restore a pre-deletion backup in an isolated environment | Replay markers before access; deleted entries remain absent |
| UW3-X07 | Deny location, fail map/stickers, disable motion/decoration | Lists, records, reflection and export remain usable |
| UW3-X08 | Attempt real contributions or public posts from simulation | V1 provides no such business endpoint; hiding buttons is insufficient |

Record requirement/test ID, software version, environment/device, initial data, steps, expected/actual result, pass/fail/not-tested, evidence location, tester/reviewer, date and defect ID. Without evidence, report not tested.

## 8. Traceability and changes

Owners and milestones are in the [current English blog](博客_英文.md). Requirements changes must also update both specifications, the project plan, guidance, and acceptance scope. Public features require a separate phase prefix; UW3-F24 must not silently become real collection.

Unresolved P0 blockers prevent real private trials. Deferred P1 items must be explicitly removed from delivery promises. Possible future campus-summary rules are in plan section 13; this specification does not authorize implementing that phase.

## 9. References and verification limits

[Assignment](https://bbs.csdn.net/topics/620544586), user-supplied V2.0 plan, [CloudBase quick start](https://cloud.tencent.com/document/product/876/121103) and [security rules](https://cloud.tencent.com/document/product/876/123478). Business parameters are team design choices, not platform-mandated values. WeChat privacy/release pages were inaccessible during this review; actual API declarations, account eligibility and review requirements still need verification.
