Skip to content

fix(content): disclose live metadata updates - #3843

Closed
khoinguyenpham04 wants to merge 1 commit into
noah/content-publish-validationfrom
noah/content-live-metadata
Closed

khoinguyenpham04 wants to merge 1 commit into
noah/content-publish-validationfrom
noah/content-live-metadata

Conversation

@khoinguyenpham04

Copy link
Copy Markdown
Collaborator

What does this PR do?

Final layer of the content-safety stack, based on #3842, after #3832, #3834, and #3840.

SEO, ownership, and byline changes already update live metadata when saved. Adds small localized notices to those existing-entry settings so editors do not mistake them for unpublished content-field changes. Byline credits still use the existing form autosave/Save pipeline; the notice does not promise that an unsaved selection has persisted.

Corrects the content_update MCP tool description, content guide, admin concept page, and REST/MCP/lifecycle references: revision-enabled collections stage content fields, but saved metadata changes affect the live entry. MCP guidance also distinguishes a slug saved with data from a slug-only live update. The automation guide distinguishes the CLI's existing auto-publish default from REST saves. No callbacks, persistence behavior, authorization, or layout structure change. No existing issue is linked; this addresses the independently reproduced content-safety audit.

Rollout remains bottom-up: deploy #3832 across the fleet before applying #3834's migration 092. This final layer has no migration.

Type of change

  • Bug fix
  • Feature (requires maintainer-approved Discussion)
  • Refactor (no behavior change)
  • Translation
  • Documentation
  • Performance improvement
  • Tests
  • Chore (dependencies, CI, tooling)

Checklist

  • I have read CONTRIBUTING.md
  • pnpm typecheck passes
  • pnpm lint passes
  • pnpm test passes (or targeted tests for my change)
  • pnpm format has been run
  • I have added/updated tests for my changes (if applicable)
  • User-visible strings in the admin UI are wrapped for translation (if applicable). Do not include messages.po changes except in translation PRs — a workflow extracts catalogs on merge to main.
  • I have added and reviewed the user-facing changeset (if this PR changes a published package)
  • New features link to an approved Discussion: https://github.com/emdash-cms/emdash/discussions/...
  • I have included screenshots below if this PR changes the UI

A feature Discussion is not applicable to this disclosure fix. No copy-literal automated test is added: it would repeat the implementation. Instead, the real browser smoke verifies the existing/new forms, successful metadata writes, and live-vs-draft behavior; 115 MCP contract cases and 34 adjacent admin cases also pass. Arabic directionality is verified through the actual locale provider. The new notices use source-language fallback until the translation workflow extracts them; no catalogs are changed.

AI-generated code disclosure

  • This PR includes AI-generated code — model/tool: Codex, GPT-6.1 Sol (max). Persistent second-opinion review: GPT-5.6 (xhigh), clean and converged on pass 4.

Screenshots / test output

  • 115 MCP contract tests pass across drafts, publication updates, bylines, taxonomies, and entry locks; 34 adjacent admin tests pass across SEO, byline credits, settings layout, and publish-button localization.
  • Three one-off real-database MCP smoke cases confirm the existing slug-only live path and draft staging with empty or changed data. The diagnostic is removed rather than pinning this legacy behavior as a new product contract test; persistence behavior is unchanged.
  • The real browser smoke returns 200 for ownership, byline, and SEO writes. Anonymous visitors see the saved SEO/byline changes while the content title and live-revision pointer remain unchanged and the content-field draft stays unpublished.
  • Existing entries show the notices; loaded new-entry forms do not. Actual Arabic locale sets lang=ar/dir=rtl, with start-aligned RTL notices and no browser page errors.
  • Current pnpm format, root pnpm build, package/demo typechecks, full/quick lint, zero JSON lint diagnostics, docs build, and diff checks pass.

Remote CI is not verified; the Codex CI connection requires sign-in. These are local validation results, not a claim that GitHub checks are green.

Fixture: disposable published post content-safety-metadata-smoke, with an unpublished content-field title. Viewport 1440×1400, light theme, English and Arabic. All screenshots are inspected rendered results.

Before

Published post editor with a pending title draft and no live-metadata notices in ownership, bylines, or SEO

After

Published post editor showing saved-change notices in ownership, bylines, and SEO while Publish changes remains pending

Arabic

Arabic editor with a mirrored settings panel and start-aligned live-metadata notices using source-language fallback

@changeset-bot

changeset-bot Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: be4aa12

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 12 packages
Name Type
@emdash-cms/admin Patch
emdash Patch
@emdash-cms/cloudflare Patch
@emdash-cms/plugin-test Patch
@emdash-cms/sandbox-workerd Patch
@emdash-cms/auth Patch
@emdash-cms/blocks Patch
create-emdash Patch
@emdash-cms/gutenberg-to-portable-text Patch
@emdash-cms/x402 Patch
@emdash-cms/auth-atproto Patch
@emdash-cms/plugin-embeds Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
docs be4aa12 Oct 04 2026, 08:05 PM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://noah-content-live-metadata.try.emdashcms.com, https://noah-content-live-metadata-emdash-playground.emdash-cms.workers.dev (commit be4aa12)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://907d5939.try.emdashcms.com, https://907d5939-emdash-playground.emdash-cms.workers.dev be4aa12 2026-10-04T20:07:19.991Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://6442427a.try.emdashcms.com, https://6442427a-emdash-playground.emdash-cms.workers.dev 929f135 2026-10-04T01:17:12.521Z Visit the dashboard ↗

@khoinguyenpham04
khoinguyenpham04 added this pull request to stack #3844 October 4, 2026 01:18

@emdashbot emdashbot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the right follow-up for the content-safety stack. It attacks the discoverability problem that SEO/ownership/byline edits go live immediately while content fields stage drafts, by adding inline notices in the admin and correcting the canonical docs and the content_update MCP tool description. The implementation is small, localized, and matches the architecture—no persistence, authorization, or layout changes.

I checked the new admin copy against ContentSettingsPanel and the save/autosave payload flow in router.tsx/ContentEditor.tsx; verified the MCP/REST lifecycle descriptions against emdash-runtime.ts and packages/core/src/api/handlers/content.ts; and confirmed the CLI auto-publish claim in working-with-content.mdx against packages/core/src/cli/commands/content.ts. I did not run the test suite, lint, or docs build. No blocking logic bugs, security issues, or AGENTS.md violations. One copy suggestion: the new notice text is misleading for non-published existing entries, and the same string is repeated three times.

</Text>
{!isNew && (
<Text as="p" size="sm" variant="secondary" DANGEROUS_className="mb-4">
{t`Saved changes update published entries without publishing again.`}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] The new notice is rendered for every existing entry (!isNew), so its claim about "published entries" is false for draft or scheduled entries. It would be more accurate to say the changes are applied to the live entry immediately, and less brittle if the string were not duplicated in three places.

Suggested change
{t`Saved changes update published entries without publishing again.`}
{t`Saved changes are applied to the live entry immediately.`}

</div>
{!isNew && (
<Text as="p" size="sm" variant="secondary" DANGEROUS_className="mb-4">
{t`Saved changes update published entries without publishing again.`}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] Same notice text as line 1080: it overstates the case for non-published existing entries and is repeated verbatim in three places, which makes future drift likely.

Suggested change
{t`Saved changes update published entries without publishing again.`}
{t`Saved changes are applied to the live entry immediately.`}

{t`SEO`}
</Text>
<Text as="p" size="sm" variant="secondary" DANGEROUS_className="mb-4">
{t`Saved changes update published entries without publishing again.`}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] Third copy of the same notice. Consider extracting a shared LiveMetadataNotice component or message descriptor so the live-metadata disclosure stays consistent across ownership, bylines, and SEO.

Suggested change
{t`Saved changes update published entries without publishing again.`}
{t`Saved changes are applied to the live entry immediately.`}

@pkg-pr-new

pkg-pr-new Bot commented Oct 4, 2026

Copy link
Copy Markdown

Open in StackBlitz

@emdash-cms/admin

npm i https://pkg.pr.new/@emdash-cms/admin@3843

@emdash-cms/auth

npm i https://pkg.pr.new/@emdash-cms/auth@3843

@emdash-cms/auth-atproto

npm i https://pkg.pr.new/@emdash-cms/auth-atproto@3843

@emdash-cms/blocks

npm i https://pkg.pr.new/@emdash-cms/blocks@3843

@emdash-cms/cloudflare

npm i https://pkg.pr.new/@emdash-cms/cloudflare@3843

@emdash-cms/contentful-to-portable-text

npm i https://pkg.pr.new/@emdash-cms/contentful-to-portable-text@3843

emdash

npm i https://pkg.pr.new/emdash@3843

create-emdash

npm i https://pkg.pr.new/create-emdash@3843

@emdash-cms/gutenberg-to-portable-text

npm i https://pkg.pr.new/@emdash-cms/gutenberg-to-portable-text@3843

@emdash-cms/plugin-cli

npm i https://pkg.pr.new/@emdash-cms/plugin-cli@3843

@emdash-cms/plugin-test

npm i https://pkg.pr.new/@emdash-cms/plugin-test@3843

@emdash-cms/plugin-types

npm i https://pkg.pr.new/@emdash-cms/plugin-types@3843

@emdash-cms/registry-client

npm i https://pkg.pr.new/@emdash-cms/registry-client@3843

@emdash-cms/registry-lexicons

npm i https://pkg.pr.new/@emdash-cms/registry-lexicons@3843

@emdash-cms/registry-loader

npm i https://pkg.pr.new/@emdash-cms/registry-loader@3843

@emdash-cms/registry-moderation

npm i https://pkg.pr.new/@emdash-cms/registry-moderation@3843

@emdash-cms/registry-verification

npm i https://pkg.pr.new/@emdash-cms/registry-verification@3843

@emdash-cms/sandbox-workerd

npm i https://pkg.pr.new/@emdash-cms/sandbox-workerd@3843

@emdash-cms/x402

npm i https://pkg.pr.new/@emdash-cms/x402@3843

@emdash-cms/plugin-ai-moderation

npm i https://pkg.pr.new/@emdash-cms/plugin-ai-moderation@3843

@emdash-cms/plugin-atproto

npm i https://pkg.pr.new/@emdash-cms/plugin-atproto@3843

@emdash-cms/plugin-audit-log

npm i https://pkg.pr.new/@emdash-cms/plugin-audit-log@3843

@emdash-cms/plugin-color

npm i https://pkg.pr.new/@emdash-cms/plugin-color@3843

@emdash-cms/plugin-embeds

npm i https://pkg.pr.new/@emdash-cms/plugin-embeds@3843

@emdash-cms/plugin-field-kit

npm i https://pkg.pr.new/@emdash-cms/plugin-field-kit@3843

@emdash-cms/plugin-forms

npm i https://pkg.pr.new/@emdash-cms/plugin-forms@3843

@emdash-cms/plugin-webhook-notifier

npm i https://pkg.pr.new/@emdash-cms/plugin-webhook-notifier@3843

commit: 929f135

@github-actions github-actions Bot added review/awaiting-author Reviewed; waiting on the author to respond and removed review/needs-review No maintainer or bot review yet labels Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Visual regression: 2 screens changed

These admin screens render differently on this PR. Confirm every change below is intended before accepting.

Screen Image Compare
content-editor-ltr expected · actual
content-editor-rtl expected · actual

Maintainers: if every change above is intended, comment /accept-baselines
to commit the regenerated Linux baselines to this PR.

Measured head: be4aa120a556aa6a56636fd97e55702d5596d59a. /accept-baselines accepts the snapshots for this commit.

github-actions Bot pushed a commit that referenced this pull request Oct 4, 2026
@khoinguyenpham04
khoinguyenpham04 force-pushed the noah/content-live-metadata branch from 929f135 to be4aa12 Compare October 4, 2026 20:03
@khoinguyenpham04 khoinguyenpham04 mentioned this pull request Oct 4, 2026
8 of 19 tasks
@github-actions github-actions Bot added review/needs-rereview Author pushed changes since the last review and removed review/awaiting-author Reviewed; waiting on the author to respond labels Oct 4, 2026
@khoinguyenpham04
khoinguyenpham04 removed this pull request from stack #3844 October 4, 2026 20:12
@khoinguyenpham04
khoinguyenpham04 added this pull request to stack #3866 October 4, 2026 20:12
github-actions Bot pushed a commit that referenced this pull request Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant