Local reference images were reaching the gateway as localhost URLs, and selected image/video nodes still exposed duplicate inline settings while the composer is the active control surface. This keeps gateway media inputs self-contained, maps GPT Image 2 sizes from the actual aspect ratio controls, and keeps node bodies focused on preview/output state.
Constraint: NewApiWG upstream cannot fetch browser-local /api/images URLs.
Constraint: Selected-node composer owns image and video generation controls.
Rejected: Keep localhost reference URLs | remote gateway requests cannot dereference local browser routes.
Rejected: Keep duplicate inline settings | it creates conflicting controls with the composer.
Confidence: high
Scope-risk: moderate
Directive: Do not send /api/images temporary URLs to NewApiWG upstream; resolve them to data URLs before provider calls.
Tested: npm run test:run -- src/app/api/generate/providers/__tests__/newapiwg.test.ts src/app/api/generate/__tests__/route.test.ts src/components/__tests__/GenerateImageNode.test.tsx src/components/__tests__/GenerateVideoNode.test.tsx src/components/__tests__/PromptNode.test.tsx src/lib/__tests__/llmModels.test.ts src/store/__tests__/workflowStore.integration.test.ts
Tested: npm run build
Tested: git diff --check
Not-tested: npm run lint still fails because next lint resolves to a nonexistent lint directory under Next 16.
Popi/NewAPIWG is now the primary gateway, so the UI and request paths need to avoid legacy provider assumptions while keeping local reference media usable for upstream calls. This change aligns model defaults, point display, inline node controls, and temporary reference image handling around that gateway boundary.
Constraint: Upstream providers cannot fetch localhost reference URLs, but large base64 payloads previously caused request/body reliability issues.
Constraint: Seedance point estimates depend on authenticated NewAPIWG /api/points/estimate responses rather than static catalog prices.
Rejected: Send all reference images directly as large data URLs | would reintroduce oversized JSON/request failures.
Rejected: Restore legacy per-provider key controls by default | current product direction is a single Popi/NewAPI gateway.
Confidence: high
Scope-risk: moderate
Directive: Do not pass /api/images localhost URLs to upstream generation APIs; resolve them server-side or fail before the upstream call.
Tested: npm run test:run -- src/app/api/generate/providers/__tests__/newapiwg.test.ts src/app/api/points/estimate/__tests__/route.test.ts src/lib/images/store.test.ts src/components/__tests__/GenerationComposer.test.tsx src/components/__tests__/ImageInputNode.test.tsx src/components/__tests__/PromptNode.test.tsx src/components/__tests__/ProjectSetupModal.test.tsx src/store/execution/__tests__/generateVideoExecutor.test.ts src/store/execution/__tests__/nanoBananaExecutor.test.ts src/store/utils/__tests__/nodeDefaults.test.ts
Tested: npm run build
Tested: git diff --check
Not-tested: npm run lint fails because next lint is parsed as a missing /lint project directory under Next 16.
Multi-image NewAPIWG generations were sending base64 reference images
inside the /api/generate JSON body. Two ordinary canvas references can
push that payload near the dev/server body boundary, leaving the route
to parse an incomplete JSON string and surface a raw syntax error.
Move large NewAPIWG references through the existing in-memory image
serving path: the browser uploads large data URLs as multipart image
files, sends short /api/images/{id} URLs in the generation request, and
the route resolves those temporary URLs back to server-local image data
before calling providers. The route also turns malformed/truncated JSON
into a readable validation error.
Constraint: Keep provider payload semantics unchanged after /api/generate receives the request
Constraint: Do not rely on request origin matching because Next dev can report 0.0.0.0 while the browser uses localhost
Rejected: Increase body size limits only | still sends multi-MB JSON and does not protect hosted/proxied environments
Rejected: Compress reference images client-side | changes model input fidelity and still leaves large JSON possible
Confidence: high
Scope-risk: moderate
Directive: Do not forward /api/images/{id} temporary URLs to external providers; resolve them server-side first
Tested: npm run test:run -- src/store/execution/__tests__/nanoBananaExecutor.test.ts src/app/api/generate/__tests__/route.test.ts
Tested: npm run build
Not-tested: Live NewAPIWG generation with the user's exact two images
This keeps the testing branch aligned with the current Popi.TV interaction direction: generation is controlled from the selected node context, model/provider selection is simplified around the NewAPI gateway path, Popiai embedding can hydrate workflow state, and media nodes expose names plus dimensions in the canvas header.
Constraint: Testing branch needs the full current source state, not runtime logs or local browser artifacts
Rejected: Commit logs, browserfs state, and handoff bundles | they are local runtime artifacts rather than application source
Confidence: high
Scope-risk: moderate
Reversibility: clean
Directive: Keep model selection consolidated around the NewAPI gateway unless supplier-specific behavior is intentionally reintroduced
Tested: npm run test:run -- src/components/__tests__/FloatingNodeHeader.test.tsx src/components/__tests__/nodeHeaderMedia.test.ts src/components/__tests__/WorkflowCanvas.test.tsx
Tested: npm run test:run -- src/components/__tests__/ImageInputNode.test.tsx src/components/__tests__/GenerateVideoNode.test.tsx src/components/__tests__/GenerateImageNode.test.tsx
Tested: npm run build
Tested: git diff --check -- src
Not-tested: npm run lint | existing script uses next lint and resolves to nonexistent ./lint directory