Tiancheng Lu
← Back home

Private product · sanitized case study

Outsider Studio · AI short-video production

An AI short-video creation tool taken from a desktop production pipeline to a full commercialization loop: licensing, quotas, distribution and operations.

Role
Solo developer
Period
2026.05 – 2026.07
Scale
Private monorepo · 105 commits · v0.3.18
Shape
Desktop + cloud · four apps

The problem

POV short-video creators using AI face a fragmented flow: topic, script, storyboard, image generation, voiceover and editing scattered across tools, with context constantly re-shipped. Selling it as a product also requires licensing checks, quota billing, key distribution, invite-based growth, and risk-control auditing — a whole layer of commercial infrastructure.

The project answers two questions at once: production — a desktop pipeline from topic → script → storyboard → image gen → TTS → export, with retry and checkpoint resume for long-running tasks; business — a self-built licensing service + admin console + distribution system + soft-OTA release pipeline, so the desktop product can actually be sold and operated.

System boundary

A four-app monorepo with no shared npm packages; the apps couple through JSON contracts (field names, camelCase), and contract changes require synchronized releases on both ends.

AppFormResponsibility
Studio Desktop (Tauri v2, React 19 + Rust) Production pipeline: script → storyboard → image gen → voiceover → cover → editing-software draft export
License Licensing service (CF Pages Functions + D1) Per-machine activation keys, expiry authority, quota counting, heartbeat, risk control
License Admin Admin console (Vite + React, 28 pages) Keys / redemption codes / invite rewards / distribution / audit / system settings
Site Product site (Next.js) Landing page, downloads, docs
  • The desktop app talks to model providers directly; users bring their own API keys, stored in the Rust side, never relayed through our servers;
  • Our cloud only handles licensing and the commercial loop — generation traffic never touches it;
  • The WebView never calls the licensing domain; everything goes through Rust IPC (invoke).

Key decisions

  1. 1

    Tauri v2 over Electron

    For a personal desktop tool, bundle size, memory footprint and system-level capabilities (secure IPC, auto-update) are decisive; see the public write-up below.

  2. 2

    Sensitive material lives in Rust process memory, never on disk

    Licensing session tokens and built-in prompt decryption keys are memory-only, cleared on validation failure or expiry; disk keeps only the activation key itself. Built-in prompts ship encrypted and unlock after activation.

  3. 3

    Three-state licensing gate with graceful degradation

    active = full features / expired = browse past work + renew panel / blocked = clear error and retry path. Every generation, write and export command goes through a unified license guard; reading history is never restricted — expiring never deletes user assets.

  4. 4

    Merchant-of-Record payment orchestration, outsource tax & compliance

    A solo seller should not hand-roll global tax compliance; an MoR payment orchestrator handles invoicing, sales tax and chargebacks end to end (ADR-0001).

  5. 5

    Commercial model first

    Offers / Promotions were modeled before any UI; redemption codes, trial pools, invite rewards and rush channels are all instances of the same model, preventing later marketing needs from breaking the data model (ADR-0002).

  6. 6

    Long-running task engineering

    Storyboard splitting runs up to 4 segments in parallel, a global image queue caps concurrency, with failure retry / batch cancel / checkpoint resume; quotas are pre-checked at the pipeline entrance — fail fast, never half-done billing.

  7. 7

    Soft OTA updates

    In-app update channel with a documented release pipeline and version management, so users never manually reinstall.

View sanitized architecture (Mermaid source) ›

The diagram uses generic role labels only — no real domains, paths or provider names.

%% Outsider Studio 脱敏架构图(公开版)
%% 所有节点使用通用角色标注:不含真实域名、接口路径、供应商名称、管理路径
flowchart TB
  User([创作者])

  subgraph Client["桌面端 · Tauri v2(React 19 + Rust)"]
    UI["制作流水线 UI<br/>选题 · 脚本 · 分镜 · 生图 · 配音 · 导出"]
    Core["Rust 核心<br/>授权会话 / API Key / 解密材料<br/>只存进程内存 · 不落盘"]
    Queue["全局任务队列<br/>并发控制 · 重试 · 批量取消 · 断点续跑"]
    Gate["License 门禁<br/>active / expired / blocked 三态"]
    UI -->|"invoke (IPC)"| Core
    UI --> Queue
    Gate -.守卫所有生成/写入/导出命令.-> Queue
  end

  subgraph Cloud["自有云端 · 授权与商业闭环(Serverless + 边缘数据库)"]
    Lic["授权服务<br/>一机一码 · 到期权威 · 配额计数 · 风控"]
    Admin["管理后台(28 页面)<br/>密钥 · 兑换码 · 邀请奖励 · 分销 · 审计"]
    Portal["分销商门户"]
    Site["产品站(Next.js)"]
    Admin --> Lic
    Portal --> Lic
  end

  Ext["外部模型服务(多家)<br/>文本 / 图像 · 路由与降级"]
  TTS["自托管开源 TTS 引擎"]
  Pay["支付编排商(MoR 模式)<br/>税务 / 合规外包"]
  Export["剪映草稿导出"]

  User --> Client
  Client -->|"HTTPS 授权 API<br/>激活 / 校验 / 心跳 / 配额"| Lic
  Core -->|"用户自带 API Key · 直连不经中转"| Ext
  Client --> TTS
  Client --> Export
  Lic --> Pay
  Ops([运营者]) --> Admin
  Dist([分销商]) --> Portal

Verification

  • A full-stack test report (352 lines, maintained per release) covering 10 Studio API endpoints, 28 admin pages, 6 distributor-portal pages and 5 product-site pages;
  • 7 end-to-end business flows (invite rewards, code activation, rush approval → key issuance, card review, notification stack, audit trail, access log) re-tested with curl, all passing;
  • Per-app unit tests + type checks + build verification;
  • Known issues are publicly recorded in the report — nothing hidden.

Public artifacts

Redaction boundary

The following are intentionally excluded from this case study:

  • Real domains, API paths and admin-console paths;
  • Licensing signing / encryption implementation details (mechanism design only, no cryptography specifics);
  • Model-provider credentials and commercial terms;
  • Customer, distribution and invitation data;
  • Real voice material or copyrighted assets (screenshots / demos always use synthetic data).