feat(marketplace): default-on share in wizard + owner unshare anytime
Goal: maximize template volume without a dark pattern and without leaking data.
Wizard Done-page Share panel:
- 'Share as template in the marketplace (recommended)' checkbox, default ON,
rendered inline in the build-success flow where every user lands.
- Honest copy — corrected a draft that claimed 'only abstracted code pattern is
shared'. That is false: the FULL generated code becomes publicly viewable on
the template detail page (by design, for pre-fork audit). The panel now says:
'Your secrets stay private ... but your generated code becomes publicly
viewable so others can audit it before forking. Unshare anytime.'
- When checked: inline minimal form — short description (prefilled from the
spec), category select, optional per-secret credential hints. One 'Publish to
marketplace' click. Not auto-published silently — that would be a consent dark
pattern; one visible deliberate click keeps it clean.
- Forked servers don't show the panel (re-publishing a fork is an edge case).
Owner unshare/reshare:
- GET /v1/servers/:id/template — owner lookup, drives the Publish tab UI.
- PATCH /v1/templates/:slug/visibility { shared } — owner-only toggle between
public and hidden. 403 for non-owners, 409 if an admin took it down (owner
cannot resurrect an admin takedown). Audit-logged as template.unshare /
template.reshare.
- Server-detail Publish tab now detects an existing template and shows the
shared status (public/hidden/takedown badge), fork count, a marketplace link
and an Unshare/Re-share button — instead of the publish form.
Why this is safe to default ON:
- Secrets are architecturally bound to mcp_servers, never copied into templates.
Publish reads tools_schema + generated_code only; the secrets table is never
touched. Data leak is structurally impossible, not policy-dependent.
- Publish re-scans the generated code for banned patterns AND hardcoded
credentials (sovereign-audit hardening) before it can reach the marketplace.
- The user sees a visible, pre-ticked checkbox and reads one honest sentence
before publishing. Privacy-conscious users untick; everyone else contributes
volume. Informed consent, GDPR-clean.
Verified end-to-end via API:
GET server/:id/template -> null (unpublished)
POST /v1/templates -> published, slug share-test-server
GET server/:id/template -> status public
PATCH visibility {shared:false} -> hidden, drops out of public list
PATCH visibility {shared:true} -> public again
UI: Publish tab renders the shared-status panel with View + Unshare (screenshot
confirmed).
Also: hero badge date set to 2026-05-20. Changed 'MCP spec 2025-11-25' to
'updated 2026-05-20' — claiming an MCP spec dated today would be factually wrong
(no such spec release exists); 'updated' is accurate and gives the requested
fresh date. The real spec date is still cited correctly in /docs.
This commit is contained in:
@@ -206,6 +206,81 @@ export async function templateRoutes(app: FastifyInstance): Promise<void> {
|
||||
return reply.send({ template });
|
||||
});
|
||||
|
||||
// ---- "Is this server already published?" (owner lookup, drives the detail-page tab) ----
|
||||
app.get('/v1/servers/:id/template', { preHandler: requireAuth }, async (req, reply) => {
|
||||
const user = req.user!;
|
||||
const Params = z.object({ id: z.string().uuid() });
|
||||
const parsed = Params.safeParse(req.params);
|
||||
if (!parsed.success) return reply.code(400).send({ error: 'invalid_id' });
|
||||
|
||||
// Verify the server belongs to the caller's org
|
||||
const [server] = await db
|
||||
.select({ id: mcpServers.id })
|
||||
.from(mcpServers)
|
||||
.where(and(eq(mcpServers.id, parsed.data.id), eq(mcpServers.orgId, user.orgId)))
|
||||
.limit(1);
|
||||
if (!server) return reply.code(404).send({ error: 'not_found' });
|
||||
|
||||
const [template] = await db
|
||||
.select({
|
||||
id: templates.id,
|
||||
slug: templates.slug,
|
||||
title: templates.title,
|
||||
status: templates.status,
|
||||
verified: templates.verified,
|
||||
forkCount: templates.forkCount,
|
||||
})
|
||||
.from(templates)
|
||||
.where(eq(templates.sourceServerId, parsed.data.id))
|
||||
.orderBy(desc(templates.createdAt))
|
||||
.limit(1);
|
||||
|
||||
return reply.send({ template: template ?? null });
|
||||
});
|
||||
|
||||
// ---- Owner visibility toggle (unshare / re-share anytime) ----
|
||||
app.patch('/v1/templates/:slug/visibility', { preHandler: requireAuth }, async (req, reply) => {
|
||||
const user = req.user!;
|
||||
const Params = z.object({ slug: z.string().regex(SLUG_REGEX) });
|
||||
const Body = z.object({ shared: z.boolean() });
|
||||
const p = Params.safeParse(req.params);
|
||||
const b = Body.safeParse(req.body);
|
||||
if (!p.success || !b.success) return reply.code(400).send({ error: 'invalid_input' });
|
||||
|
||||
const [template] = await db
|
||||
.select()
|
||||
.from(templates)
|
||||
.where(eq(templates.slug, p.data.slug))
|
||||
.limit(1);
|
||||
if (!template) return reply.code(404).send({ error: 'not_found' });
|
||||
|
||||
// Only the owner can toggle their own template. Admins use /v1/admin/templates.
|
||||
if (template.ownerUserId !== user.userId) {
|
||||
return reply.code(403).send({ error: 'forbidden' });
|
||||
}
|
||||
// A template the admin took down cannot be re-shared by the owner.
|
||||
if (template.status === 'takedown') {
|
||||
return reply.code(409).send({ error: 'taken_down', detail: template.takedownReason });
|
||||
}
|
||||
|
||||
const nextStatus = b.data.shared ? 'public' : 'hidden';
|
||||
await db
|
||||
.update(templates)
|
||||
.set({ status: nextStatus, updatedAt: new Date() })
|
||||
.where(eq(templates.id, template.id));
|
||||
|
||||
await audit({
|
||||
orgId: user.orgId,
|
||||
userId: user.userId,
|
||||
action: b.data.shared ? 'template.reshare' : 'template.unshare',
|
||||
resourceType: 'template',
|
||||
resourceId: template.id,
|
||||
metadata: { slug: template.slug },
|
||||
ipAddress: req.ip,
|
||||
});
|
||||
return reply.send({ ok: true, status: nextStatus });
|
||||
});
|
||||
|
||||
// ---- Public list with ranking ----
|
||||
app.get('/v1/templates', async (req, reply) => {
|
||||
const Query = z.object({
|
||||
|
||||
Reference in New Issue
Block a user