feat(marketplace): template publish + fork + voting/ranking + admin moderation
What this enables:
- A user builds an MCP server. If others would benefit, they click 'Publish as
template' on their server detail page. The spec + pre-rendered TypeScript
snapshot is preserved.
- Visitors browse /templates, filter by category, sort by trending/top/newest.
Each template card shows fork count + active deployment count as natural
manipulation-resistant popularity signal.
- /templates/[slug] shows the full plan: tool list with input schemas,
required-credential explanations (with 'how to get one' deep links), and a
collapsible code preview so users can audit before forking.
- Fork is one click → /servers/new?template=slug. The wizard skips Step 1 and
pre-fills Step 2 with the template's parsed spec. Forker only fills in their
own credentials. mcp_servers.template_id is recorded; template.fork_count is
bumped atomically. Each fork gets its own isolated container with its own
port, its own AES-256 secrets — the template author has zero visibility into
the fork's traffic or data.
- Admin /admin/templates moderation: verify quality templates (shows shield
badge in marketplace), hide low-effort ones, takedown anything malicious.
Takedowns cascade-pause every fork container — owners must re-deploy.
Why template+fork instead of shared-container:
- Shared containers would mean the publisher's quota + their secrets + their
logs are exposed to forkers. Bad ergonomics, bad security, bad ownership.
- Templates/forks decouple the spec (shared, vouched-for) from the runtime
(isolated per user). Network-effect moat without the trust collapse.
Why no 5-star voting in v1:
- Manipulation-anfällig, empty lists without adoption. We use fork count +
active deploys + verified badge. Trending algorithm:
score = (activeDeploys * 3 + forks) / sqrt(ageDays + 1)
Real signal, no brigading attack surface.
Backend:
- New schema: templates table (16 cols incl. tools_schema, generated_code,
required_secrets, allowedDomains, status enum, verified, fork_count).
- mcp_servers.template_id FK + idx for fork lookup.
- @bmm/types: SpecEdit unchanged, CreateServerInput accepts optional templateId.
- preview-cache.ts: new cachePrebuiltCode/loadPrebuiltCode for storing the
template's full rendered server.ts alongside the spec. Generator worker
detects this and skips the render step — uses the audited pre-built code
verbatim. Banned-pattern re-scan at publish time.
- routes/templates.ts: 5 public/auth routes + 2 admin routes. Banned-pattern
re-scan before publish. Slug auto-uniqued. forkCount atomic-increment via
SQL.
UI:
- /templates marketplace with trending/top/newest tabs, category filter, search.
Cards show forks + live count + author + verified badge.
- /templates/[slug] full detail with tools, credentials-with-hints, expandable
code preview, fork CTA, ownership + stats sidebar, 'forking is safe' explainer.
- /servers/new?template=slug — wizard auto-jumps to Step 2 with template spec
pre-filled, fork banner at top with link back to template.
- /servers/[id] new Publish tab with title, category, descriptions, per-secret
hint fields (description + howToGetUrl per UPPER_SNAKE_CASE key).
- /admin/templates moderation with verify/hide/takedown actions.
- Marketing nav now includes /templates.
Verified end-to-end:
- Published Echo Demo Template from marco@test.local's live server
- Marketplace lists it correctly with stats
- Detail page renders with all sections
- Fork CTA navigates to wizard with ?template= param
- Wizard skips Step 1, shows fork banner, pre-fills spec
- Build succeeds in ~10s (cached spec + prebuilt code path skips Claude AND
render), container live on :4109 with proper OAuth 401 → token → 200 flow
- DB: templates.fork_count=1, activeDeployments=1, mcp_servers.template_id
populated on the fork
- /admin/templates shows the new template with verify/hide/takedown controls
This commit is contained in:
@@ -58,6 +58,43 @@ export const adminSettings = pgTable('admin_settings', {
|
||||
updatedAt: timestamp('updated_at').defaultNow().notNull(),
|
||||
});
|
||||
|
||||
export const templateStatusEnum = pgEnum('template_status', [
|
||||
'draft',
|
||||
'public',
|
||||
'hidden',
|
||||
'takedown',
|
||||
]);
|
||||
|
||||
export const templates = pgTable(
|
||||
'templates',
|
||||
{
|
||||
id: uuid('id').defaultRandom().primaryKey(),
|
||||
ownerUserId: uuid('owner_user_id').references(() => users.id, { onDelete: 'set null' }),
|
||||
ownerOrgId: uuid('owner_org_id').references(() => organizations.id, { onDelete: 'set null' }),
|
||||
sourceServerId: uuid('source_server_id'),
|
||||
slug: varchar('slug', { length: 64 }).notNull().unique(),
|
||||
title: varchar('title', { length: 128 }).notNull(),
|
||||
shortDescription: varchar('short_description', { length: 280 }).notNull(),
|
||||
longDescription: text('long_description'),
|
||||
category: varchar('category', { length: 64 }).notNull(),
|
||||
toolsSchema: jsonb('tools_schema').notNull(),
|
||||
generatedCode: text('generated_code').notNull(),
|
||||
requiredSecrets: jsonb('required_secrets').notNull(),
|
||||
scopes: jsonb('scopes').notNull(),
|
||||
allowedDomains: jsonb('allowed_domains'),
|
||||
status: templateStatusEnum('status').default('public').notNull(),
|
||||
verified: boolean('verified').default(false).notNull(),
|
||||
takedownReason: text('takedown_reason'),
|
||||
forkCount: integer('fork_count').default(0).notNull(),
|
||||
createdAt: timestamp('created_at').defaultNow().notNull(),
|
||||
updatedAt: timestamp('updated_at').defaultNow().notNull(),
|
||||
},
|
||||
(t) => ({
|
||||
statusIdx: index('idx_templates_status').on(t.status, t.createdAt),
|
||||
categoryIdx: index('idx_templates_category').on(t.category),
|
||||
}),
|
||||
);
|
||||
|
||||
export const users = pgTable('users', {
|
||||
id: uuid('id').defaultRandom().primaryKey(),
|
||||
email: varchar('email', { length: 255 }).notNull().unique(),
|
||||
@@ -126,11 +163,13 @@ export const mcpServers = pgTable(
|
||||
publicUrl: text('public_url'),
|
||||
toolsSchema: jsonb('tools_schema'),
|
||||
oauthEnabled: boolean('oauth_enabled').default(true).notNull(),
|
||||
templateId: uuid('template_id'),
|
||||
createdAt: timestamp('created_at').defaultNow().notNull(),
|
||||
updatedAt: timestamp('updated_at').defaultNow().notNull(),
|
||||
},
|
||||
(t) => ({
|
||||
orgSlugIdx: index('idx_servers_org_slug').on(t.orgId, t.slug),
|
||||
templateIdx: index('idx_servers_template').on(t.templateId),
|
||||
}),
|
||||
);
|
||||
|
||||
@@ -262,3 +301,4 @@ export type Build = typeof builds.$inferSelect;
|
||||
export type BuildLog = typeof buildLogs.$inferSelect;
|
||||
export type Secret = typeof secrets.$inferSelect;
|
||||
export type OAuthClient = typeof oauthClients.$inferSelect;
|
||||
export type Template = typeof templates.$inferSelect;
|
||||
|
||||
Reference in New Issue
Block a user