feat(marketplace): default-on share in wizard + owner unshare anytime
Goal: maximize template volume without a dark pattern and without leaking data.
Wizard Done-page Share panel:
- 'Share as template in the marketplace (recommended)' checkbox, default ON,
rendered inline in the build-success flow where every user lands.
- Honest copy — corrected a draft that claimed 'only abstracted code pattern is
shared'. That is false: the FULL generated code becomes publicly viewable on
the template detail page (by design, for pre-fork audit). The panel now says:
'Your secrets stay private ... but your generated code becomes publicly
viewable so others can audit it before forking. Unshare anytime.'
- When checked: inline minimal form — short description (prefilled from the
spec), category select, optional per-secret credential hints. One 'Publish to
marketplace' click. Not auto-published silently — that would be a consent dark
pattern; one visible deliberate click keeps it clean.
- Forked servers don't show the panel (re-publishing a fork is an edge case).
Owner unshare/reshare:
- GET /v1/servers/:id/template — owner lookup, drives the Publish tab UI.
- PATCH /v1/templates/:slug/visibility { shared } — owner-only toggle between
public and hidden. 403 for non-owners, 409 if an admin took it down (owner
cannot resurrect an admin takedown). Audit-logged as template.unshare /
template.reshare.
- Server-detail Publish tab now detects an existing template and shows the
shared status (public/hidden/takedown badge), fork count, a marketplace link
and an Unshare/Re-share button — instead of the publish form.
Why this is safe to default ON:
- Secrets are architecturally bound to mcp_servers, never copied into templates.
Publish reads tools_schema + generated_code only; the secrets table is never
touched. Data leak is structurally impossible, not policy-dependent.
- Publish re-scans the generated code for banned patterns AND hardcoded
credentials (sovereign-audit hardening) before it can reach the marketplace.
- The user sees a visible, pre-ticked checkbox and reads one honest sentence
before publishing. Privacy-conscious users untick; everyone else contributes
volume. Informed consent, GDPR-clean.
Verified end-to-end via API:
GET server/:id/template -> null (unpublished)
POST /v1/templates -> published, slug share-test-server
GET server/:id/template -> status public
PATCH visibility {shared:false} -> hidden, drops out of public list
PATCH visibility {shared:true} -> public again
UI: Publish tab renders the shared-status panel with View + Unshare (screenshot
confirmed).
Also: hero badge date set to 2026-05-20. Changed 'MCP spec 2025-11-25' to
'updated 2026-05-20' — claiming an MCP spec dated today would be factually wrong
(no such spec release exists); 'updated' is accurate and gives the requested
fresh date. The real spec date is still cited correctly in /docs.
This commit is contained in:
@@ -295,6 +295,15 @@ interface SecretHint {
|
||||
howToGetUrl: string;
|
||||
}
|
||||
|
||||
interface ExistingTemplate {
|
||||
id: string;
|
||||
slug: string;
|
||||
title: string;
|
||||
status: 'draft' | 'public' | 'hidden' | 'takedown';
|
||||
verified: boolean;
|
||||
forkCount: number;
|
||||
}
|
||||
|
||||
function PublishPanel({ serverId, serverStatus }: { serverId: string; serverStatus: string }) {
|
||||
const [title, setTitle] = useState('');
|
||||
const [category, setCategory] = useState('other');
|
||||
@@ -305,6 +314,32 @@ function PublishPanel({ serverId, serverStatus }: { serverId: string; serverStat
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [publishedSlug, setPublishedSlug] = useState<string | null>(null);
|
||||
|
||||
const [existing, setExisting] = useState<ExistingTemplate | null | undefined>(undefined);
|
||||
|
||||
async function reloadExisting() {
|
||||
try {
|
||||
const r = await apiFetch<{ template: ExistingTemplate | null }>(
|
||||
`/v1/servers/${serverId}/template`,
|
||||
);
|
||||
setExisting(r.template);
|
||||
} catch {
|
||||
setExisting(null);
|
||||
}
|
||||
}
|
||||
|
||||
useEffect(() => {
|
||||
reloadExisting();
|
||||
}, [serverId]);
|
||||
|
||||
async function toggleVisibility(shared: boolean) {
|
||||
if (!existing) return;
|
||||
await apiFetch(`/v1/templates/${existing.slug}/visibility`, {
|
||||
method: 'PATCH',
|
||||
body: JSON.stringify({ shared }),
|
||||
});
|
||||
reloadExisting();
|
||||
}
|
||||
|
||||
if (serverStatus !== 'live') {
|
||||
return (
|
||||
<div className="panel p-4">
|
||||
@@ -316,6 +351,64 @@ function PublishPanel({ serverId, serverStatus }: { serverId: string; serverStat
|
||||
);
|
||||
}
|
||||
|
||||
// Already published — show shared status + view + unshare/reshare.
|
||||
if (existing) {
|
||||
const isTakedown = existing.status === 'takedown';
|
||||
const isShared = existing.status === 'public';
|
||||
return (
|
||||
<div className="panel p-4">
|
||||
<div className="flex items-baseline justify-between">
|
||||
<h3 className="text-[14px] font-semibold tracking-tight">Marketplace</h3>
|
||||
<span
|
||||
className={`mono rounded-full border px-2 py-0.5 text-[11px] ${
|
||||
isTakedown
|
||||
? 'border-red-400/40 bg-red-400/10 text-red-300'
|
||||
: isShared
|
||||
? 'border-emerald-400/40 bg-emerald-400/10 text-emerald-300'
|
||||
: 'border-amber-400/40 bg-amber-400/10 text-amber-300'
|
||||
}`}
|
||||
>
|
||||
{existing.status}
|
||||
</span>
|
||||
</div>
|
||||
<p className="mt-1 text-[12.5px] text-[--color-fg-muted]">
|
||||
Published as <span className="mono">{existing.slug}</span> ·{' '}
|
||||
{existing.forkCount} fork{existing.forkCount === 1 ? '' : 's'}
|
||||
{existing.verified && ' · verified'}
|
||||
</p>
|
||||
{isTakedown && (
|
||||
<p className="mt-2 text-[12px] text-[--color-danger]">
|
||||
An admin removed this template from the marketplace. You can't re-share it.
|
||||
</p>
|
||||
)}
|
||||
<div className="mt-3 flex gap-2">
|
||||
<a
|
||||
href={`/templates/${existing.slug}`}
|
||||
target="_blank"
|
||||
rel="noreferrer"
|
||||
className="inline-flex h-8 items-center rounded-md border border-[--color-border] bg-[--color-bg-elevated] px-3 text-[12.5px] text-[--color-fg] transition-colors hover:bg-[--color-bg-subtle]"
|
||||
>
|
||||
View in marketplace
|
||||
</a>
|
||||
{!isTakedown && isShared && (
|
||||
<Button variant="danger" size="md" onClick={() => toggleVisibility(false)}>
|
||||
Unshare
|
||||
</Button>
|
||||
)}
|
||||
{!isTakedown && !isShared && (
|
||||
<Button variant="primary" size="md" onClick={() => toggleVisibility(true)}>
|
||||
Re-share
|
||||
</Button>
|
||||
)}
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
if (existing === undefined) {
|
||||
return <div className="panel p-4 text-[12.5px] text-[--color-fg-muted]">Loading…</div>;
|
||||
}
|
||||
|
||||
function addHint() {
|
||||
setSecretHints((h) => [...h, { key: '', description: '', howToGetUrl: '' }]);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user