Manufacturer portal / 制造商门户
Entry: https://manufacturer.kiosk-x.ai/manufacturing Super Admin view: https://operator.kiosk-x.ai/manufacturing
The same code and API serve both workspaces. Use Cognito and the existing second-factor verification. A manufacturer needs the Manufacturers group AND an active, explicit assignment under Operator Access & workflows: factory ID (e.g. zhzn) and exact serial numbers. Serials may be assigned before APK enrollment. No operator account or territory is assigned to this role. Group membership alone does not grant machine access. A Super Admin can review the fleet. Factories cannot view operator finances, take device control or change APK results.
两个工作台使用相同代码和 API。通过 Cognito 与现有双重验证登录。制造商必须属于 Manufacturers 组,并由管理员在运营门户“权限”中明确分配工厂 ID(例如 zhzn)和准确的设备序列号。可以在设备安装 APK 前预先分配序列号。制造商角色不拥有运营账户或地区权限;仅加入用户组不能获得设备访问权限。超级管理员可查看全部制造记录。
Start manufacturing here / 产线先读: Feature-by-feature bench checklist / 功能逐项验收.
Line workflow / 产线流程
- Match the physical serial to the assigned serial. Install the current signed ZHZN cabinet APK from https://api.kiosk-x.ai/downloads and follow the linked verification/install guide. Preserve identity and configuration on update; do not uninstall to bypass a signer mismatch.
- On the actual cabinet, open Factory Test from the APK service menu. Complete camera, microphone, speaker, touch, display and controller tests. Record the board protocol/module and camera ID. Resolve fitted-accessory identity/binding blockers.
- Upload the latest run, enter technician name and employee ID, accept the statement and draw the signature in the APK. The portal reads the existing authenticated
/zhzn/factory-testand/zhzn/factory-signrecords; it does not synthesize either. Offline queued results appear only after a successful upload. - In Inspect → Physical factory acceptance, record actual observations for power/cold-start, VMC, fitted MDB/reader, every-lane dispensing, network and screen/lockdown. Coin/bill/cooling absence is separate from a skipped test. Each observation records the signed-in actor, named technician and server timestamp. When all physical requirements pass, sign the separate physical factory acceptance. This does not replace the APK handwritten signature. The final physical acceptance is immutable; later problems require the service/correction process.
-
Review each serial, then prepare a shipping batch: reference, manufacturer, exact serial list, carrier, waybill, container, departure, ETA, destination and notes. Drafts may be saved while tests are pending. Record dispatch rechecks every serial and refuses duplicate shipment membership. The batch freezes APK and physical acceptance evidence. A dispatch declaration is factory-reported paperwork, not a carrier tracking integration or proof of delivery.
-
核对机身与分配序列号。从下载页面安装当前已签名的 ZHZN 设备 APK,并按安装指南校验文件。更新时保留设备身份,不要通过卸载绕过签名错误。
- 在实际设备 APK 的服务菜单打开工厂测试,完成摄像头、麦克风、扬声器、触摸、显示屏及控制板测试,确认控制协议、模组和摄像头 ID,并解决已安装配件的绑定问题。
- 上传最新测试,填写技术员姓名和工号,确认声明并在 APK 上手写签名。门户读取设备上传记录,不生成虚假通过结果。离线队列上传成功前不会显示为已完成。
- 在“查看详情 → 实物工厂验收”记录上电/冷启动、VMC、实际安装的 MDB/读卡器、全部货道出货、网络和屏幕锁定等观察结果。未安装硬件与跳过测试不同。记录带登录身份、技术员姓名和服务器时间。完成必测项目后,另行签署实物验收,不能代替 APK 手写签名。最终签署不可覆盖,后续问题通过服务或更正流程处理。
- 逐台复核后填写批次、工厂 ID、准确序列号、承运商、运单、集装箱、日期、目的地和备注。测试期间可保存草稿。登记发货时服务器重新检查全部设备,禁止同一序列重复进入已发货批次。批次保存两项验收证据快照。发货登记不等于承运商实时跟踪或签收证明。
Readiness policy / 状态规则
- Red / 红色: a reported APK or physical subsystem failed.
- Yellow / 黄色: no evidence, incomplete required tests, missing APK version, missing wiring identity, absent/superseded signatures, or the APK report is over 72 hours old. A newer APK run requires a new APK signature.
- Green / 绿色: required APK checks, physical FAT and both signatures are present and valid under those gates. This is an evidence assessment, not independent hardware certification.
The portal polls every 30 seconds. The detail panel has its own refresh control; an API/storage failure displays an error rather than a successful empty fleet. A later failure remains visible as a current hold on an already declared shipping batch. Historical report messages retain the original technical language; UI controls and the working guide support English and Simplified Chinese.
门户每 30 秒刷新。详情可单独刷新。API 或存储故障会显示错误,不会伪装为正常的空列表。发货登记后出现新故障,批次仍显示当前待复查状态。历史技术消息保留原始语言,操作界面与流程指南支持英文和简体中文。
Storage and APIs
GET /api/v1/manufacturer: scoped evidence and batch register.GET /api/v1/manufacturer/machines/{serial}: latest report, up to 20 older reports, APK certificate, physical tests and signature.POST /api/v1/manufacturer/machines/{serial}/bench: explicitly observed physical test or physical signature. Version and request ID prevent stale updates and duplicate retries. No APK result editing.POST /api/v1/manufacturer/batches: versioned draft or immutable dispatch declaration. The server validates readiness again.- Fleet persistence:
factory_tests,machine_builds,manufacturer_batches; strict reads/writes fail closed in production. Batch writes share the access-assignment advisory lock across replicas.
Do not put passwords, device secrets, payment credentials or customer financial information in notes. No real cabinet test or shipment is created by deployment verification. Physical qualification still needs a technician on the actual hardware.
The portal and its MFA forms support Simplified Chinese. The shared Cognito classic login page remains English; the manufacturer login page supplies Chinese field guidance. Migrating the shared authentication domain to Managed Login would affect other applications and is a separate release. AWS branding documentation.
Manufacturing bench checklist / 制造产线逐台检查表
For Guangzhou Zhenghe Intelligent Technology Co., Ltd. (ZHZN). Complete this for every serial, not one sample for the whole batch. Use only the approved machine specification/BOM. “Not fitted” is acceptable only for an option that the buyer approved as absent; a missing promised feature is a shipping hold. A test that has not been performed is not verified, never “pass”.
适用于 Guangzhou Zhenghe Intelligent Technology Co., Ltd.(ZHZN)。每个序列号都必须检查,不能用一台样机代表整批。 以客户批准的配置和物料清单为准。只有客户确认不配置的选件才能填写“未安装”;承诺配置却缺少的功能必须暂停发货。未执行的测试填写“未验证”,不能填写“通过”。
A. Before assembly / 装配前
- Confirm model, cabinet serial, destination, supply voltage/frequency, plug, controller/protocol, Android board, APK compatibility, lane map, screens, payment reader, printer, power bank, cameras, locks, lighting and cooling against the approved order. Record exact models and revisions; do not substitute silently.
- Create a per-machine evidence folder with the serial, date and technician. Record actual cabinet/board labels, internal wiring and accessory identifiers. Keep device keys, passwords, payment data and private customer images out of photos and notes.
- Confirm acceptance criteria with the buyer: print size/quality, supported lock behavior, required cameras, lane coverage, temperature if fitted, test duration, payment test limits and destination configuration. Do not invent electrical ratings or a universal burn-in duration.
-
A qualified factory technician must inspect grounding, insulation, cable protection, fuses, strain relief, connector polarity, moving parts and transport restraints to the approved design. This software checklist is not an electrical safety certification.
-
按已批准订单核对型号、机身序列号、目的地、电压/频率、插头、控制板/协议、安卓主板、APK 兼容性、货道表、屏幕、支付读卡器、打印机、充电宝、摄像头、锁、灯光和制冷。记录实际型号和版本,禁止未经确认替换。
- 每台设备建立以序列号、日期和技术员命名的证据文件夹,保存标签、内部接线和配件标识照片。照片和备注中不要出现设备密钥、密码、支付资料或客户私人照片。
- 与客户确认打印规格、锁控行为、摄像头要求、全部货道范围、制冷温度、测试时长、支付测试限额和目的地配置。不要自行编造电气参数或统一老化时长。
- 由合格技术员按批准设计检查接地、绝缘、线缆保护、保险、应力释放、极性、运动部件和运输固定。本软件清单不能代替电气安全认证。
B. Install and identify / 安装与身份核对
Use APK downloads and the installation guide. Verify the release and signer, install/update without erasing enrolled identity, and check the serial shown in the APK against the physical label and portal assignment. Record APK version, Android version, board protocol/module and server-received test timestamp. A screenshot saying “uploaded” is not enough: refresh the portal and confirm that exact serial and run arrived.
使用 APK 下载页及安装指南。核对发布版本和签名,更新时保留注册身份。APK、机身标签及门户分配序列号必须一致。记录 APK/安卓版本、控制协议/模组和服务器接收时间。不能只凭“上传成功”截图验收;刷新门户,确认准确序列号的这次测试已收到。
C. Feature-by-feature acceptance / 功能逐项验收
For every row record configuration, action performed, expected result, actual result, pass/fail/not verified/not fitted, technician, time and evidence reference. A command being accepted is not proof of physical execution. “Online” is not a hardware test.
每项记录:实际配置、执行步骤、预期结果、观察结果、通过/失败/未验证/未安装、技术员、时间及证据编号。云端接受命令不等于硬件执行成功,“在线”也不等于硬件测试通过。
| Feature / 功能 | Perform on the actual machine / 实机操作 | Evidence and pass condition / 证据与通过条件 |
|---|---|---|
| Photo printing / 照片打印 | If fitted, record printer model, connection, media and configured paper size. Use a synthetic color/gray/text test image through the real customer preview-to-print flow. Check orientation, cropping, color, readable text, feed, cut/eject and recovery after a controlled paper-out or disconnected-printer test. / 已安装时记录型号、连接、耗材和纸张规格。用测试图片执行真实预览到打印流程,检查方向、裁切、颜色、文字、走纸、切纸/出纸,以及缺纸或断连后的恢复。 | Photograph the physical output beside the serial and retain the job reference. One requested print must not become duplicate prints on refresh/reconnect. An error must not be shown as a completed print. Confirm paid-flow reconciliation separately using the approved test process. / 保存实物样张与序列号合照及任务编号;刷新或重连不能重复打印;失败不能显示成功。收费流程另按批准方案核对。 |
| Cloud sales lock / 云端销售锁定 | With a Super Admin/operator present and no active shopper transaction, target this exact serial with the supported cloud disable/lock action. Confirm acknowledgement AND actual blocked new sales; test reconnect/reboot behavior against the approved policy, then authorized unlock and a successful controlled test. / 在无顾客交易时,由有权限管理员对准确序列号执行已支持的停用/锁定,核对确认回执及实机禁止新交易;按批准策略检查重连/重启,授权解锁后再测试。 | Save command/reference, actor, timestamps and before/after screen evidence. Unknown, delayed or failed commands remain unverified/failed. Manufacturer access does not itself authorize remote commands. / 保存命令编号、操作者、时间和前后画面。未知、延迟或失败不能算通过;制造商账号不自动获得远程控制权限。 |
| Android kiosk lockdown / 安卓自助模式锁定 | Check approved startup app, full-screen operation, restricted service entry and return from maintenance. Reboot and confirm the intended shopper screen. / 检查开机自启、全屏、受限维护入口和维护后恢复;重启后回到顾客界面。 | A service PIN screen or installed remote-support app alone does not prove cloud sales lock, physical door lock or unattended remote control. / 有维护 PIN 或远程支持软件,不等于云端销售锁、实体门锁或无人值守控制通过。 |
| Physical door lock / 实体门锁 | If fitted and supported, a qualified technician tests the specified lock/unlock and door sensor with the door area clear, including the approved outage/manual-access behavior. / 已配置且支持时,由技术员在门区安全条件下测试开锁、闭锁、门磁及批准的断电/人工开门方式。 | Confirm actual latch and sensor states, not only a screen icon. If cloud door control is unavailable, mark it unsupported and obtain buyer resolution; do not label a software sales lock as a physical lock. / 核对锁舌和传感器实态;没有云端实体锁能力时标记不支持并由客户处理,不得用软件停售代替实体锁验收。 |
| Power-bank module / 充电宝模块 | Record present/absent first. If present, record actual cabinet/door ID, matching QR, model, bay count and binding. Test each approved bay: correct bank ejects, device charges, return is detected, occupied/empty states update. Test authorized rent→eject→return and failure recovery through the actual flow. / 先记录有无模块;有则核对真实柜/门 ID、二维码、型号、仓位数量和绑定。逐仓检查正确弹出、充电、归还识别及空满状态,按批准流程测试租借、弹出、归还与异常恢复。 | Portal binding must refer to this cabinet with no binding error. Keep rental/return references and approved charge/refund reconciliation. Absent hardware must not show an active rental promise or use another cabinet's QR. / 绑定必须对应本机且无错误;保存租还编号与批准的扣款/退款核对;无模块不能展示可租借承诺,不能贴另一台设备的二维码。 |
| Every camera / 所有摄像头 | Record physical camera count, purpose, ID and orientation. Test each through its actual assigned flow with a test chart: framing, focus, exposure, lighting, preview/capture, permission denial, reconnect and reboot. / 记录数量、用途、ID 和方向;用测试卡在实际流程逐个检查取景、对焦、曝光、照明、预览/拍摄、权限拒绝、重连和重启。 | Save a non-personal test image and ID mapping. One working preview does not verify every camera, identity service or a vision model's accuracy. / 保存非个人测试图片和 ID 对照;一个预览正常不代表全部摄像头、身份服务或视觉模型准确率通过。 |
| Touch, screens, sound / 触摸、屏幕、声音 | Test all touch areas, rotation, brightness, dead pixels/flicker, each fitted display, microphone recording/playback and speakers at the approved volume. / 测试全区域触摸、旋转、亮度、坏点/闪烁、所有屏幕、录音回放及批准音量的扬声器。 | APK results plus actual observations; no hidden dialogs, unusable UI or exposed service tools after reboot. / 保存 APK 结果和实测记录;重启后不能有遮挡弹窗、不可用界面或暴露维护工具。 |
| Controller and every lane / 控制板与所有货道 | Verify board identity/protocol, lane numbering and product map. Perform controlled vending on every configured lane including later shelves; verify correct item, quantity, product-fall detection, jam/empty reporting and recovery. / 核对控制板、协议、货道编号和商品映射;包含后续层板在内逐货道测试正确商品、数量、掉货检测、卡货/空货报告和恢复。 | Record a lane-by-lane results sheet. A board handshake or one successful lane cannot stand in for full lane coverage. / 保存逐货道表;控制板握手或单货道成功不能代替全覆盖。 |
| Payments / 支付 | For fitted/approved readers and channels, verify reader identity/binding, configured currency and merchant/destination setup. Use the business-approved test mode or expressly approved small live test; confirm approve→vend, decline→no vend, failure reconciliation and duplicate prevention. / 对已配置并批准的支付渠道核对读卡器绑定、币种、商户及目的地设置;使用批准的测试模式或明确批准的小额实测,验证支付成功出货、拒付不出货、失败核对及防重复。 | Keep redacted transaction/refund references. A browser success page, reader power light or factory APK certificate is not settlement proof or worldwide payment approval. / 保存脱敏交易/退款编号;浏览器成功页、读卡器灯或 APK 证书不是结算凭证或全球支付批准。 |
| Network and cloud / 网络与云端 | Test the configured Wi-Fi/LTE/Ethernet paths, signal, time sync, heartbeats, interruption, reconnect, queued test upload and command acknowledgement. / 测试配置的网络、信号、时间同步、心跳、中断、重连、队列上传和命令回执。 | Correct serial visible in the portal; stale data stays distinguishable from live data. No duplicate sale/print after retry. / 门户显示正确序列号,旧数据与实时数据可区分;重试不重复销售或打印。 |
| Power recovery / 断电恢复 | With no active transaction and qualified bench supervision, perform the approved cold-start/outage/recovery test; then retest any explicitly approved interrupted workflow. / 在无活动交易、由合格技术员监督条件下执行批准的冷启动/断电恢复;中断交易测试仅按另行批准方案执行。 | Identity/configuration retained, correct startup screen, no unwanted vend/print, cloud reconnects and errors reconcile. / 身份配置保留,启动界面正确,无意外出货/打印,网络恢复且异常可核对。 |
| Cooling, sensors and lighting / 制冷、传感器与灯光 | Test every fitted option against the approved specification: measured temperature and stability, fans/airflow, door/drop sensors, LEDs and fault reporting. / 按规格测试所有已装选件:实测温度/稳定性、风扇气流、门磁/掉货传感器、灯光和故障报告。 | Record measurements and evidence; missing promised options, overheating or unresolved faults stop shipment. / 保存测量与证据;缺少承诺配置、过热或未解决故障必须停发。 |
| QR and shopper flows / 二维码与顾客流程 | Scan each physical QR using a test phone. Verify machine, power-bank, payment and support destinations separately. Check intended language, catalog, stock and any enabled photo/game/reward flow. / 用测试手机逐一扫描机身二维码,分别核对设备、充电宝、支付和支持入口,检查语言、商品、库存及已启用的拍照/游戏/奖励流程。 | No wrong-machine routing; disabled/unavailable features must not be advertised as usable. / 不得跳转到另一台设备;未启用或不可用功能不能宣传为可使用。 |
D. Where to record it / 记录位置
- APK Factory Test: retain the actual camera/audio/touch/display/controller run and APK handwritten sign-off. Use the current accessory attachment procedure for
photoPrint,powerbankandnayax. Current Android views do not expose the accessory write controls; authorized cabinet-authenticated bench tooling is required. Do not invent a button, identifier or credential. - Manufacturer portal → Inspect → Physical factory acceptance: use the existing power, vmc, mdb, reader, dispense, coin, bill, cooling, network and screen test codes. Add feature-specific evidence references in the relevant observation (printing/cameras under screen; cloud checks under network) and in batch notes. Preserve a complete serial-specific checklist in the approved evidence store.
- Important limit: the portal does not yet have separate structured test fields or automatic gates for every printer, power-bank bay or remote-lock scenario in this expanded checklist. Its green status covers the implemented APK/FAT gates only. Staff must manually review the expanded checklist and resolve all promised-feature holds before dispatch; do not treat free-text notes as automatic validation.
- APK 工厂测试: 保存真实测试和 APK 手写签名。
photoPrint、powerbank、nayax按配件绑定指南由授权设备身份的产线工具操作。现有安卓视图没有配件写入按钮,不要编造按钮、标识或凭据。 - 制造商门户 → 查看详情 → 实物工厂验收: 使用现有测试代码,在相关观察项和批次备注中填写打印、摄像头、云控等证据编号;完整逐台清单存放在批准的证据库。
- 当前限制: 新清单中的打印、逐仓充电宝和各类远程锁场景尚无全部独立结构化字段或自动门禁。绿色仅表示现有 APK/FAT 规则通过。员工必须人工复核扩展清单,解决承诺功能的所有问题后才可发货;文字备注不等于自动校验。
E. Release to shipping / 发货前放行
Retest after repairs or configuration changes. Upload a current APK run, obtain the matching APK signature, complete and sign physical FAT, and inspect the expanded checklist. Within the portal's 72-hour APK evidence window, prepare the exact serial list, carrier, tracking/waybill, container if applicable, dates, destination and packing photos. Confirm approved spare parts, manuals, keys and transport protection. A Super Admin reviews exceptions; a failed promised feature is not resolved by deleting its evidence or calling it absent. Never change an immutable signed physical record to hide a later fault; use the documented correction/service process and hold shipping.
维修或改配置后必须复测。上传最新 APK 结果并匹配签名,完成实物 FAT 签署,复核扩展清单。在 72 小时 APK 证据有效期内登记准确序列号、承运商、运单、适用的集装箱信息、日期、目的地及包装照片,核对备件、说明书、钥匙和运输保护。由超级管理员处理例外。删除失败证据或把承诺功能改写为“未安装”不能解除发货问题。不得覆盖已签实物记录来隐藏新故障,应走更正/服务流程并暂停发货。
Handoff: share the manufacturer registration link, choose Sign up, verify the work email, and ask a Super Admin to assign factory zhzn and exact serials. Never share administrator credentials. Use 简体中文 in the portal; the shared Cognito registration screen remains English. Email = 邮箱; Password = 密码; Sign up = 注册; Sign in = 登录; Forgot your password = 忘记密码.