feat(marketplace): template publish + fork + voting/ranking + admin moderation
What this enables:
- A user builds an MCP server. If others would benefit, they click 'Publish as
template' on their server detail page. The spec + pre-rendered TypeScript
snapshot is preserved.
- Visitors browse /templates, filter by category, sort by trending/top/newest.
Each template card shows fork count + active deployment count as natural
manipulation-resistant popularity signal.
- /templates/[slug] shows the full plan: tool list with input schemas,
required-credential explanations (with 'how to get one' deep links), and a
collapsible code preview so users can audit before forking.
- Fork is one click → /servers/new?template=slug. The wizard skips Step 1 and
pre-fills Step 2 with the template's parsed spec. Forker only fills in their
own credentials. mcp_servers.template_id is recorded; template.fork_count is
bumped atomically. Each fork gets its own isolated container with its own
port, its own AES-256 secrets — the template author has zero visibility into
the fork's traffic or data.
- Admin /admin/templates moderation: verify quality templates (shows shield
badge in marketplace), hide low-effort ones, takedown anything malicious.
Takedowns cascade-pause every fork container — owners must re-deploy.
Why template+fork instead of shared-container:
- Shared containers would mean the publisher's quota + their secrets + their
logs are exposed to forkers. Bad ergonomics, bad security, bad ownership.
- Templates/forks decouple the spec (shared, vouched-for) from the runtime
(isolated per user). Network-effect moat without the trust collapse.
Why no 5-star voting in v1:
- Manipulation-anfällig, empty lists without adoption. We use fork count +
active deploys + verified badge. Trending algorithm:
score = (activeDeploys * 3 + forks) / sqrt(ageDays + 1)
Real signal, no brigading attack surface.
Backend:
- New schema: templates table (16 cols incl. tools_schema, generated_code,
required_secrets, allowedDomains, status enum, verified, fork_count).
- mcp_servers.template_id FK + idx for fork lookup.
- @bmm/types: SpecEdit unchanged, CreateServerInput accepts optional templateId.
- preview-cache.ts: new cachePrebuiltCode/loadPrebuiltCode for storing the
template's full rendered server.ts alongside the spec. Generator worker
detects this and skips the render step — uses the audited pre-built code
verbatim. Banned-pattern re-scan at publish time.
- routes/templates.ts: 5 public/auth routes + 2 admin routes. Banned-pattern
re-scan before publish. Slug auto-uniqued. forkCount atomic-increment via
SQL.
UI:
- /templates marketplace with trending/top/newest tabs, category filter, search.
Cards show forks + live count + author + verified badge.
- /templates/[slug] full detail with tools, credentials-with-hints, expandable
code preview, fork CTA, ownership + stats sidebar, 'forking is safe' explainer.
- /servers/new?template=slug — wizard auto-jumps to Step 2 with template spec
pre-filled, fork banner at top with link back to template.
- /servers/[id] new Publish tab with title, category, descriptions, per-secret
hint fields (description + howToGetUrl per UPPER_SNAKE_CASE key).
- /admin/templates moderation with verify/hide/takedown actions.
- Marketing nav now includes /templates.
Verified end-to-end:
- Published Echo Demo Template from marco@test.local's live server
- Marketplace lists it correctly with stats
- Detail page renders with all sections
- Fork CTA navigates to wizard with ?template= param
- Wizard skips Step 1, shows fork banner, pre-fills spec
- Build succeeds in ~10s (cached spec + prebuilt code path skips Claude AND
render), container live on :4109 with proper OAuth 401 → token → 200 flow
- DB: templates.fork_count=1, activeDeployments=1, mcp_servers.template_id
populated on the fork
- /admin/templates shows the new template with verify/hide/takedown controls
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
'use client';
|
||||
|
||||
import { useEffect, useState } from 'react';
|
||||
import { useRouter } from 'next/navigation';
|
||||
import { useRouter, useSearchParams } from 'next/navigation';
|
||||
import { apiFetch } from '@/lib/api';
|
||||
import { Button } from '@/components/ui/button';
|
||||
import { Input, Label, Textarea } from '@/components/input';
|
||||
@@ -98,10 +98,68 @@ export default function NewServerPage() {
|
||||
const [buildId, setBuildId] = useState<string | null>(null);
|
||||
const [serverId, setServerId] = useState<string | null>(null);
|
||||
const [result, setResult] = useState<BuildResult | null>(null);
|
||||
const [forkedTemplateId, setForkedTemplateId] = useState<string | null>(null);
|
||||
const [forkedTemplateTitle, setForkedTemplateTitle] = useState<string | null>(null);
|
||||
|
||||
const searchParams = useSearchParams();
|
||||
const templateSlug = searchParams.get('template');
|
||||
|
||||
const trySlug = (n: string) =>
|
||||
n.toLowerCase().replace(/[^a-z0-9-]+/g, '-').replace(/^-+|-+$/g, '').slice(0, 32);
|
||||
|
||||
// Fork-from-template flow: skip Step 1, jump straight to Step 2 with the template's spec
|
||||
useEffect(() => {
|
||||
if (!templateSlug || preview) return;
|
||||
let cancelled = false;
|
||||
setStep('analyzing');
|
||||
(async () => {
|
||||
try {
|
||||
const res = await apiFetch<{
|
||||
previewId: string;
|
||||
templateId: string;
|
||||
template: {
|
||||
slug: string;
|
||||
title: string;
|
||||
shortDescription: string;
|
||||
tools: PreviewTool[];
|
||||
requiredSecrets: Array<{
|
||||
key: string;
|
||||
description: string;
|
||||
howToGetUrl?: string;
|
||||
}>;
|
||||
};
|
||||
}>(`/v1/templates/${templateSlug}/fork`, { method: 'POST', body: '{}' });
|
||||
if (cancelled) return;
|
||||
setName(res.template.title);
|
||||
setSlug(trySlug(res.template.title));
|
||||
setPrompt(`Fork of "${res.template.title}" template.`);
|
||||
setForkedTemplateId(res.templateId);
|
||||
setForkedTemplateTitle(res.template.title);
|
||||
setPreview({
|
||||
previewId: res.previewId,
|
||||
source: 'mock',
|
||||
spec: {
|
||||
name: res.template.title,
|
||||
description: res.template.shortDescription,
|
||||
tools: res.template.tools,
|
||||
requiredSecrets: res.template.requiredSecrets.map((s) => s.key),
|
||||
scopes: [],
|
||||
},
|
||||
});
|
||||
setEditable(null);
|
||||
setStep('confirm');
|
||||
} catch (e) {
|
||||
if (cancelled) return;
|
||||
const detail = (e as { detail?: { error?: string } }).detail;
|
||||
setError(detail?.error ?? (e as Error).message);
|
||||
setStep('prompt');
|
||||
}
|
||||
})();
|
||||
return () => {
|
||||
cancelled = true;
|
||||
};
|
||||
}, [templateSlug, preview]);
|
||||
|
||||
useEffect(() => {
|
||||
if (preview && !editable) {
|
||||
const e = specToEditable(preview.spec);
|
||||
@@ -256,7 +314,9 @@ export default function NewServerPage() {
|
||||
prompt,
|
||||
secrets: filledSecrets,
|
||||
previewId: preview.previewId,
|
||||
specEdit,
|
||||
// Don't send specEdit when forking — the template's spec + pre-rendered code
|
||||
// are already in the Redis cache. Edits would invalidate the impls.
|
||||
...(forkedTemplateId ? { templateId: forkedTemplateId } : { specEdit }),
|
||||
}),
|
||||
},
|
||||
);
|
||||
@@ -363,6 +423,22 @@ export default function NewServerPage() {
|
||||
|
||||
{step === 'confirm' && preview && editable && (
|
||||
<div className="mt-7 space-y-6">
|
||||
{forkedTemplateTitle && (
|
||||
<div className="panel-subtle p-3 flex items-center justify-between">
|
||||
<div className="text-[12.5px]">
|
||||
Forking <span className="mono font-semibold">{forkedTemplateTitle}</span> — fill in
|
||||
your own credentials below. The template author never sees them.
|
||||
</div>
|
||||
<a
|
||||
href={`/templates/${templateSlug}`}
|
||||
target="_blank"
|
||||
rel="noreferrer"
|
||||
className="text-[11.5px] text-[--color-fg-muted] underline hover:text-[--color-fg]"
|
||||
>
|
||||
Template ↗
|
||||
</a>
|
||||
</div>
|
||||
)}
|
||||
<div className="panel p-4">
|
||||
<div className="flex items-baseline justify-between">
|
||||
<h2 className="text-[14px] font-semibold tracking-tight">Confirm what we'll build</h2>
|
||||
|
||||
Reference in New Issue
Block a user