fix(content): disclose live metadata updates - #3843
khoinguyenpham04 wants to merge 1 commit into
Conversation
🦋 Changeset detectedLatest commit: be4aa12 The changes in this PR will be included in the next version bump. This PR includes changesets to release 12 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
docs | be4aa12 | Oct 04 2026, 08:05 PM |
🚀 Deploying Preview to Cloudflare 🚀Preview URL: https://noah-content-live-metadata.try.emdashcms.com, https://noah-content-live-metadata-emdash-playground.emdash-cms.workers.dev (commit be4aa12)This URL reflects your latest Preview deploymentPreview Deployments by commit
|
There was a problem hiding this comment.
This is the right follow-up for the content-safety stack. It attacks the discoverability problem that SEO/ownership/byline edits go live immediately while content fields stage drafts, by adding inline notices in the admin and correcting the canonical docs and the content_update MCP tool description. The implementation is small, localized, and matches the architecture—no persistence, authorization, or layout changes.
I checked the new admin copy against ContentSettingsPanel and the save/autosave payload flow in router.tsx/ContentEditor.tsx; verified the MCP/REST lifecycle descriptions against emdash-runtime.ts and packages/core/src/api/handlers/content.ts; and confirmed the CLI auto-publish claim in working-with-content.mdx against packages/core/src/cli/commands/content.ts. I did not run the test suite, lint, or docs build. No blocking logic bugs, security issues, or AGENTS.md violations. One copy suggestion: the new notice text is misleading for non-published existing entries, and the same string is repeated three times.
| </Text> | ||
| {!isNew && ( | ||
| <Text as="p" size="sm" variant="secondary" DANGEROUS_className="mb-4"> | ||
| {t`Saved changes update published entries without publishing again.`} |
There was a problem hiding this comment.
[suggestion] The new notice is rendered for every existing entry (!isNew), so its claim about "published entries" is false for draft or scheduled entries. It would be more accurate to say the changes are applied to the live entry immediately, and less brittle if the string were not duplicated in three places.
| {t`Saved changes update published entries without publishing again.`} | |
| {t`Saved changes are applied to the live entry immediately.`} |
| </div> | ||
| {!isNew && ( | ||
| <Text as="p" size="sm" variant="secondary" DANGEROUS_className="mb-4"> | ||
| {t`Saved changes update published entries without publishing again.`} |
There was a problem hiding this comment.
[suggestion] Same notice text as line 1080: it overstates the case for non-published existing entries and is repeated verbatim in three places, which makes future drift likely.
| {t`Saved changes update published entries without publishing again.`} | |
| {t`Saved changes are applied to the live entry immediately.`} |
| {t`SEO`} | ||
| </Text> | ||
| <Text as="p" size="sm" variant="secondary" DANGEROUS_className="mb-4"> | ||
| {t`Saved changes update published entries without publishing again.`} |
There was a problem hiding this comment.
[suggestion] Third copy of the same notice. Consider extracting a shared LiveMetadataNotice component or message descriptor so the live-metadata disclosure stays consistent across ownership, bylines, and SEO.
| {t`Saved changes update published entries without publishing again.`} | |
| {t`Saved changes are applied to the live entry immediately.`} |
@emdash-cms/admin
@emdash-cms/auth
@emdash-cms/auth-atproto
@emdash-cms/blocks
@emdash-cms/cloudflare
@emdash-cms/contentful-to-portable-text
emdash
create-emdash
@emdash-cms/gutenberg-to-portable-text
@emdash-cms/plugin-cli
@emdash-cms/plugin-test
@emdash-cms/plugin-types
@emdash-cms/registry-client
@emdash-cms/registry-lexicons
@emdash-cms/registry-loader
@emdash-cms/registry-moderation
@emdash-cms/registry-verification
@emdash-cms/sandbox-workerd
@emdash-cms/x402
@emdash-cms/plugin-ai-moderation
@emdash-cms/plugin-atproto
@emdash-cms/plugin-audit-log
@emdash-cms/plugin-color
@emdash-cms/plugin-embeds
@emdash-cms/plugin-field-kit
@emdash-cms/plugin-forms
@emdash-cms/plugin-webhook-notifier
commit: |
Visual regression: 2 screens changedThese admin screens render differently on this PR. Confirm every change below is intended before accepting.
Maintainers: if every change above is intended, comment Measured head: |
929f135 to
be4aa12
Compare


What does this PR do?
Final layer of the content-safety stack, based on #3842, after #3832, #3834, and #3840.
SEO, ownership, and byline changes already update live metadata when saved. Adds small localized notices to those existing-entry settings so editors do not mistake them for unpublished content-field changes. Byline credits still use the existing form autosave/Save pipeline; the notice does not promise that an unsaved selection has persisted.
Corrects the
content_updateMCP tool description, content guide, admin concept page, and REST/MCP/lifecycle references: revision-enabled collections stage content fields, but saved metadata changes affect the live entry. MCP guidance also distinguishes a slug saved withdatafrom a slug-only live update. The automation guide distinguishes the CLI's existing auto-publish default from REST saves. No callbacks, persistence behavior, authorization, or layout structure change. No existing issue is linked; this addresses the independently reproduced content-safety audit.Rollout remains bottom-up: deploy #3832 across the fleet before applying #3834's migration 092. This final layer has no migration.
Type of change
Checklist
pnpm typecheckpassespnpm lintpassespnpm testpasses (or targeted tests for my change)pnpm formathas been runmessages.pochanges except in translation PRs — a workflow extracts catalogs on merge tomain.A feature Discussion is not applicable to this disclosure fix. No copy-literal automated test is added: it would repeat the implementation. Instead, the real browser smoke verifies the existing/new forms, successful metadata writes, and live-vs-draft behavior; 115 MCP contract cases and 34 adjacent admin cases also pass. Arabic directionality is verified through the actual locale provider. The new notices use source-language fallback until the translation workflow extracts them; no catalogs are changed.
AI-generated code disclosure
Screenshots / test output
data. The diagnostic is removed rather than pinning this legacy behavior as a new product contract test; persistence behavior is unchanged.lang=ar/dir=rtl, with start-aligned RTL notices and no browser page errors.pnpm format, rootpnpm build, package/demo typechecks, full/quick lint, zero JSON lint diagnostics, docs build, and diff checks pass.Remote CI is not verified; the Codex CI connection requires sign-in. These are local validation results, not a claim that GitHub checks are green.
Fixture: disposable published post
content-safety-metadata-smoke, with an unpublished content-field title. Viewport 1440×1400, light theme, English and Arabic. All screenshots are inspected rendered results.Before
After
Arabic