Skip to content

fix: demo UX findings across catalog, settings, palette and profiles (Spec demo-ux-fixes) - #1464

Merged
github-actions[bot] merged 11 commits into
mainfrom
fix-demo-ux-findings
Oct 2, 2026
Merged

github-actions[bot] merged 11 commits into
mainfrom
fix-demo-ux-findings

Conversation

@Dumbris

@Dumbris Dumbris commented Oct 2, 2026

Copy link
Copy Markdown
Member

Fixes nine gaps found in a live demo of the Web UI on main (b3191a059, Spec 109-m merged). Spec 109 owns five of them (catalog, palette, Settings), Spec 108 the other four (profile refusal text, token chip, Clients CTA, dialog labels). Decisions are recorded as Spec 109 research D35 and Spec 108 research D39; the plan was demo-ux-fixes. Each fix is test-first and lands on every surface that shows the thing.

What changes for users

Catalog (Web UI, macOS, CLI, MCP, REST)

  • A catalog source whose live search times out or fails is answered from the listing the daemon last saw from it (an in-memory, per-source cache, at most 24 h old, up to 2,000 entries per source, keyed by source id and servers URL, pruned when the registry config reloads). The matches are marked: from_cache in REST and MCP, (cached) in the CLI source column, a "From cached list" badge on the Web UI and macOS. The source stays in unavailable[] with fallback: "cached_listing" and cached_at, and the notice reads "<source>: live search unavailable (<reason>); showing matches from its cached list". A source with nothing cached behaves as before. A missing API key never falls back.
  • The empty-query browse lists the curated reference servers first in Official (then round-robin across sources, still never popularity-ordered), and every surface renders Popular before Official when Popular has entries. The CLI no longer prints an empty section.
  • The cache is per process and not persisted (internal/storage is untouched), so the CLI without a daemon starts cold. Documented.

Settings (Web UI)

  • Toggles for nullable settings show the value the core applies instead of OFF when the key is absent: quarantine_enabled, telemetry.enabled, audit_log.compress, and audit_log.enabled and audit_log.stdout, which depend on the edition and on whether the block exists. Untouched keys are never PATCHed.
  • The header says "Edit a section, then press Save changes to apply it", using the same constant as the button.

Command palette (Web UI)

  • Finds profiles, clients and agent tokens. They load once per open on the first non-empty input, never on open.

Profiles

  • A tool refusal and retrieve_tools name the caller's own profile when it came from the caller's pin, its client binding, the URL or set_profile. An anonymous caller and a dangling base keep the non-disclosing text. This reverses part of Spec 108 D27 and is the one security-semantic change in the PR; see below.
  • The token Profile chip is one line with an ellipsis and the full title on hover.
  • A client row with no mcpproxy entry offers Connect (macOS: Connect…) instead of Upgrade to client credential. Admin-key holders still read Upgrade, revoked and expired credentials Reconnect. The tray's no-credential row uses the same words.
  • Radio and checkbox labels sit next to their control (one unlayered rule after the daisyUI shim).

Audit and decision references

The nine items are the live-demo findings in the plan demo-ux-fixes, numbered 1 to 9: catalog cached fallback (1), nullable Settings toggles (2), Settings header copy (3), refusal names the profile (4), palette indexes profiles, clients and tokens (5), browse order (6), token chip (7), Connect CTA (8), radio labels (9). They are tasks T160 to T165 in specs/109-ux-navigation-consistency/tasks.md and T148 to T152 in specs/108-profiles-v3/tasks.md; task counts are 201 and 186. Spec 110 FR-005 and US1 scenario 3 carry a dated amendment for the browse order.

Deviations from the plan

  • The audit-log toggles are not server-edition only (the plan said so): they sit in an Advanced accordion both editions show, and an absent block resolves to off on the personal edition, so the form defaults are edition-aware (defaultFor(cfg, ctx)), re-resolved if /status arrives after the config.
  • The golden for the cached fallback uses a source that answers 500 once primed, not a hang, so the Go tests stay fast; the timeout path has its own unit tests in internal/registries.
  • The palette tests are in command-palette-directory.spec.ts rather than appended to command-palette.spec.ts. Opening the palette with a profile row selected needs an arrow key because the default row stays "Search tools for ...".

The refusal change (D39) needs a decision

D27 withheld the profile from every caller because naming it to a third party would confirm that a caller is pinned. That threat does not apply to a caller learning its own profile, so the refusal now names it only for pin, binding, URL and set_profile; anonymous (the operator's anonymous_profile), a dangling base and out-of-scope servers are unchanged and byte-identical, pinned as literals. The title goes through %q, so it cannot add a line to an agent's context or an activity log. One predicate, profileDisclosedTo, decides both the refusal text and retrieve_tools.profile. If the reviewer rejects own-credential disclosure, the fallback is slug-only disclosure, or moving finding 4 to a follow-up issue; everything else is independent. The four admin refusals in refusals.json are untouched; the tool refusals have their own golden, internal/profile/testdata/contract/tool_refusals.json. A CHANGELOG entry under Breaking Changes tells consumers that matched the old wording to match block_reason instead.

Tests added or changed

  • Go: internal/registries (catalog_listing_cache_test.go, catalog_browse_order_test.go), internal/config (settings_nullable_defaults_test.go with personal and server variants; every *bool path under Config must be classified in the shared fixture), internal/server (profile_refusals_test.go, spec109_catalog_cached_fallback_test.go; the call-tool, direct, code-execution, REST, precedence, acceptance, retrieve_tools and scope-oracle tests now read the disclosed text from the golden), internal/httpapi (spec109_catalog_cached_fallback_test.go writes the cached-fallback golden, tool_refusal_golden_test.go, the credential_cta label family in profiles_v3_parity_test.go), cmd/mcpproxy (catalog_cached_fallback_test.go, activity_blocked_refusal_test.go, browse rendering).
  • Web: settings-nullable-defaults, settings-header-copy, command-palette-directory, catalog-cached-fallback, catalog-browse-order, agent-tokens-profile-chip, form-control-label-shim, plus updated client-binding-controls and profiles-enums-labels. Playwright: e2e/web-ui-sweep/demo-ux-fixes.spec.ts (chip and radio layout at 1440 and 900) and a palette case in navigation-consistency.spec.ts, both in the smoke run list.
  • macOS: CatalogOrderParityTests, CatalogTests, ProfilesEnumsLabelsTests, ClientBindingModelTests, ClientsTrayMenuTests.
  • Shared fixtures and goldens: internal/registries/testdata/catalog_cached_fallback_order.json, internal/config/testdata/settings_nullable_defaults.json, internal/profile/testdata/contract/tool_refusals.json, and the new credential_cta family in labels.json. Parity matrices for rows 14 and 25 (Spec 109) and 7, 13 and 15 (Spec 108) list the new tests. No frozen tool-surface or response golden changed.

Docs

docs/api/rest-api.md, docs/cli/catalog-commands.md, docs/features/profiles.md, docs/development/macos-tray.md, docs/development/web-ui-verification.md, docs/development/release-gate.md, the Spec 108, 109 and 110 documents, and the CHANGELOG.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying mcpproxy-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 3a4021a
Status: ✅  Deploy successful!
Preview URL: https://3637eabe.mcpproxy-docs.pages.dev
Branch Preview URL: https://fix-demo-ux-findings.mcpproxy-docs.pages.dev

View logs

F3.1 (medium, confirmed): buildPartial now ships the displayed audit_log.enabled
and audit_log.stdout alongside any dirty audit_log key, so a rotation-only or
compress-only save on an absent audit_log block no longer produces a sink-less
block that validateAuditLog refuses, and the saved state matches the form.
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

📦 Build Artifacts

Workflow Run: View Run
Branch: fix-demo-ux-findings

Available Artifacts

  • archive-darwin-amd64 (31 MB)
  • archive-darwin-arm64 (28 MB)
  • archive-linux-amd64 (19 MB)
  • archive-linux-arm64 (17 MB)
  • archive-windows-amd64 (31 MB)
  • archive-windows-arm64 (27 MB)
  • frontend-dist-pr (0 MB)
  • installer-dmg-darwin-amd64 (26 MB)
  • installer-dmg-darwin-arm64 (24 MB)
  • smart-mcp-proxymcpproxy-goLYXGW4.dockerbuild (0 MB)

How to Download

Option 1: GitHub Web UI (easiest)

  1. Go to the workflow run page linked above
  2. Scroll to the bottom "Artifacts" section
  3. Click on the artifact you want to download

Option 2: GitHub CLI

gh run download 36992119420 --repo smart-mcp-proxy/mcpproxy-go

Note: Artifacts expire in 14 days.

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 96.85535% with 5 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
internal/registries/listing_cache.go 94.73% 2 Missing and 1 partial ⚠️
internal/registries/catalog.go 95.65% 1 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved (Model B): Paperclip review verdicts = ACCEPT and qa-gate green at this head SHA. Arming auto-merge; GitHub merges when all required checks pass.

@github-actions
github-actions Bot merged commit fea45c4 into main Oct 2, 2026
68 of 72 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants