fix: demo UX findings across catalog, settings, palette and profiles (Spec demo-ux-fixes) - #1464
Merged
Merged
Conversation
…matches save behaviour (Spec 109 T161, T162)
…Upgrade (Spec 108 T150)
…s Popular above Official (Spec 109 T164)
…ails (Spec 109 T160)
…n profile (Spec 108 T148)
… changelog (Spec 108 D39)
Deploying mcpproxy-docs with
|
| Latest commit: |
3a4021a
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://3637eabe.mcpproxy-docs.pages.dev |
| Branch Preview URL: | https://fix-demo-ux-findings.mcpproxy-docs.pages.dev |
F3.1 (medium, confirmed): buildPartial now ships the displayed audit_log.enabled and audit_log.stdout alongside any dirty audit_log key, so a rotation-only or compress-only save on an absent audit_log block no longer produces a sink-less block that validateAuditLog refuses, and the saved state matches the form.
Contributor
📦 Build ArtifactsWorkflow Run: View Run Available Artifacts
How to DownloadOption 1: GitHub Web UI (easiest)
Option 2: GitHub CLI gh run download 36992119420 --repo smart-mcp-proxy/mcpproxy-go
|
|
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes nine gaps found in a live demo of the Web UI on main (
b3191a059, Spec 109-m merged). Spec 109 owns five of them (catalog, palette, Settings), Spec 108 the other four (profile refusal text, token chip, Clients CTA, dialog labels). Decisions are recorded as Spec 109 research D35 and Spec 108 research D39; the plan wasdemo-ux-fixes. Each fix is test-first and lands on every surface that shows the thing.What changes for users
Catalog (Web UI, macOS, CLI, MCP, REST)
from_cachein REST and MCP,(cached)in the CLI source column, a "From cached list" badge on the Web UI and macOS. The source stays inunavailable[]withfallback: "cached_listing"andcached_at, and the notice reads "<source>: live search unavailable (<reason>); showing matches from its cached list". A source with nothing cached behaves as before. A missing API key never falls back.internal/storageis untouched), so the CLI without a daemon starts cold. Documented.Settings (Web UI)
quarantine_enabled,telemetry.enabled,audit_log.compress, andaudit_log.enabledandaudit_log.stdout, which depend on the edition and on whether the block exists. Untouched keys are never PATCHed.Command palette (Web UI)
Profiles
retrieve_toolsname the caller's own profile when it came from the caller's pin, its client binding, the URL orset_profile. An anonymous caller and a dangling base keep the non-disclosing text. This reverses part of Spec 108 D27 and is the one security-semantic change in the PR; see below.Audit and decision references
The nine items are the live-demo findings in the plan
demo-ux-fixes, numbered 1 to 9: catalog cached fallback (1), nullable Settings toggles (2), Settings header copy (3), refusal names the profile (4), palette indexes profiles, clients and tokens (5), browse order (6), token chip (7), Connect CTA (8), radio labels (9). They are tasks T160 to T165 inspecs/109-ux-navigation-consistency/tasks.mdand T148 to T152 inspecs/108-profiles-v3/tasks.md; task counts are 201 and 186. Spec 110 FR-005 and US1 scenario 3 carry a dated amendment for the browse order.Deviations from the plan
defaultFor(cfg, ctx)), re-resolved if/statusarrives after the config.internal/registries.command-palette-directory.spec.tsrather than appended tocommand-palette.spec.ts. Opening the palette with a profile row selected needs an arrow key because the default row stays "Search tools for ...".The refusal change (D39) needs a decision
D27 withheld the profile from every caller because naming it to a third party would confirm that a caller is pinned. That threat does not apply to a caller learning its own profile, so the refusal now names it only for pin, binding, URL and
set_profile;anonymous(the operator'sanonymous_profile), a dangling base and out-of-scope servers are unchanged and byte-identical, pinned as literals. The title goes through%q, so it cannot add a line to an agent's context or an activity log. One predicate,profileDisclosedTo, decides both the refusal text andretrieve_tools.profile. If the reviewer rejects own-credential disclosure, the fallback is slug-only disclosure, or moving finding 4 to a follow-up issue; everything else is independent. The four admin refusals inrefusals.jsonare untouched; the tool refusals have their own golden,internal/profile/testdata/contract/tool_refusals.json. A CHANGELOG entry under Breaking Changes tells consumers that matched the old wording to matchblock_reasoninstead.Tests added or changed
internal/registries(catalog_listing_cache_test.go,catalog_browse_order_test.go),internal/config(settings_nullable_defaults_test.gowith personal and server variants; every*boolpath underConfigmust be classified in the shared fixture),internal/server(profile_refusals_test.go,spec109_catalog_cached_fallback_test.go; the call-tool, direct, code-execution, REST, precedence, acceptance, retrieve_tools and scope-oracle tests now read the disclosed text from the golden),internal/httpapi(spec109_catalog_cached_fallback_test.gowrites the cached-fallback golden,tool_refusal_golden_test.go, thecredential_ctalabel family inprofiles_v3_parity_test.go),cmd/mcpproxy(catalog_cached_fallback_test.go,activity_blocked_refusal_test.go, browse rendering).settings-nullable-defaults,settings-header-copy,command-palette-directory,catalog-cached-fallback,catalog-browse-order,agent-tokens-profile-chip,form-control-label-shim, plus updatedclient-binding-controlsandprofiles-enums-labels. Playwright:e2e/web-ui-sweep/demo-ux-fixes.spec.ts(chip and radio layout at 1440 and 900) and a palette case innavigation-consistency.spec.ts, both in the smoke run list.CatalogOrderParityTests,CatalogTests,ProfilesEnumsLabelsTests,ClientBindingModelTests,ClientsTrayMenuTests.internal/registries/testdata/catalog_cached_fallback_order.json,internal/config/testdata/settings_nullable_defaults.json,internal/profile/testdata/contract/tool_refusals.json, and the newcredential_ctafamily inlabels.json. Parity matrices for rows 14 and 25 (Spec 109) and 7, 13 and 15 (Spec 108) list the new tests. No frozen tool-surface or response golden changed.Docs
docs/api/rest-api.md,docs/cli/catalog-commands.md,docs/features/profiles.md,docs/development/macos-tray.md,docs/development/web-ui-verification.md,docs/development/release-gate.md, the Spec 108, 109 and 110 documents, and the CHANGELOG.