feat(marketplace): dashboard nav link + My-templates filter
The logged-in user can now reach the marketplace and filter to their own templates. Dashboard nav: - Added 'Marketplace' item (Overview · Servers · Marketplace · Audit · Settings). /templates page — login-aware: - Detects session via /v1/auth/me. Logged-in users get a 'Dashboard' + '+ New server' header instead of 'Home' + 'Start building'. - New [All templates | My templates] scope toggle, shown only when logged in. - 'My templates' loads GET /v1/templates/mine and shows EVERY status the user owns (public / hidden / draft / takedown) with a colored status badge on each card — so a template you unshared doesn't appear to have vanished. - Sort tabs (trending/top/newest) hide in 'mine' scope — meaningless for a handful of own templates. Category filter + search still apply (client-side). - Takedown cards link to the source server's Publish tab instead of the detail route (which 410s); everything else opens the detail page. Backend: - GET /v1/templates/mine (requireAuth) — all own templates, any status, registered before /:slug so the static route always wins the match. - GET /v1/templates/:slug — now does an optional session check: the OWNER can view their own hidden/draft template (so a 'My templates' card click never dead-ends in a 404). takedown stays 410 for everyone, owner included — that's an admin decision, not the owner's to reverse. Detail page: - Fork CTA is gated on status === 'public'. For a non-public template the owner sees an amber 'not forkable — re-share from the Publish tab' notice plus a 'Manage in server' link, instead of a Fork button that would fail silently. Verified: - GET /v1/templates/mine → marco's 1 template; 401 without auth - Owner GET of a hidden template → 200 status:hidden; anon → 404 - Dashboard nav shows Marketplace (screenshot) - /templates 'My templates' toggle → only own template, public badge, sort tabs hidden (screenshot)
This commit is contained in:
@@ -16,6 +16,7 @@ import {
|
||||
users,
|
||||
} from '@bmm/db';
|
||||
import { GeneratorSpec } from '@bmm/types';
|
||||
import { getSession } from '@bmm/auth';
|
||||
import { requireAuth, requireAdmin } from '../plugins/session.js';
|
||||
import { audit } from '../lib/audit.js';
|
||||
import { cacheSpec, cachePrebuiltCode } from '../lib/preview-cache.js';
|
||||
@@ -345,6 +346,33 @@ export async function templateRoutes(app: FastifyInstance): Promise<void> {
|
||||
return reply.send({ templates: ranked, categories: CATEGORIES });
|
||||
});
|
||||
|
||||
// ---- My templates (authed — all statuses, for the marketplace "Mine" filter) ----
|
||||
// Registered before /:slug so the static segment always wins the router match.
|
||||
app.get('/v1/templates/mine', { preHandler: requireAuth }, async (req, reply) => {
|
||||
const user = req.user!;
|
||||
const rows = await db
|
||||
.select()
|
||||
.from(templates)
|
||||
.where(eq(templates.ownerUserId, user.userId))
|
||||
.orderBy(desc(templates.createdAt));
|
||||
|
||||
const enriched = await Promise.all(
|
||||
rows.map(async (t) => {
|
||||
const [active] = await db
|
||||
.select({ c: count() })
|
||||
.from(mcpServers)
|
||||
.where(and(eq(mcpServers.templateId, t.id), eq(mcpServers.status, 'live')));
|
||||
return {
|
||||
...t,
|
||||
ownerName: user.email.split('@')[0],
|
||||
ownerOrgName: null,
|
||||
activeDeployments: Number(active?.c ?? 0),
|
||||
};
|
||||
}),
|
||||
);
|
||||
return reply.send({ templates: enriched, categories: CATEGORIES });
|
||||
});
|
||||
|
||||
// ---- Detail ----
|
||||
app.get('/v1/templates/:slug', async (req, reply) => {
|
||||
const Params = z.object({ slug: z.string().regex(SLUG_REGEX) });
|
||||
@@ -365,16 +393,19 @@ export async function templateRoutes(app: FastifyInstance): Promise<void> {
|
||||
.limit(1);
|
||||
if (!row) return reply.code(404).send({ error: 'not_found' });
|
||||
if (row.template.status === 'takedown') {
|
||||
// Takedown is an admin decision — sealed for everyone, including the owner.
|
||||
return reply.code(410).send({
|
||||
error: 'taken_down',
|
||||
reason: row.template.takedownReason,
|
||||
});
|
||||
}
|
||||
if (row.template.status !== 'public') {
|
||||
// hidden / draft — only owner can view
|
||||
// Note: viewing endpoint is public, so we 404 to non-owners.
|
||||
// (Owner UI would use a separate auth'd endpoint; out of scope for v1.)
|
||||
return reply.code(404).send({ error: 'not_found' });
|
||||
// hidden / draft — visible only to the owner (optional auth check).
|
||||
const session = await getSession(req.cookies['bmm_session']);
|
||||
const isOwner = session != null && session.userId === row.template.ownerUserId;
|
||||
if (!isOwner) {
|
||||
return reply.code(404).send({ error: 'not_found' });
|
||||
}
|
||||
}
|
||||
|
||||
const [active] = await db
|
||||
|
||||
Reference in New Issue
Block a user