Skip to content

Add featured community listings surfaced as onboarding starter packages - #765

Merged
kody-bot merged 3 commits into
mainfrom
cursor/community-featured-onboarding-d4a5
Jul 16, 2026
Merged

kody-bot merged 3 commits into
mainfrom
cursor/community-featured-onboarding-d4a5

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Jul 16, 2026 •

Copy link
Copy Markdown
Owner

Summary

Third and final PR in the trusted/one-click-install/onboarding series (after #760 and #763). Admins can now mark trusted community listings as featured, and featured listings appear on /onboarding as one-click-installable starter packages for new users.

  • New featured_at column on community_listings (migration 0060). A listing is effectively featured only while featured_at IS NOT NULL and it is effectively trusted (trusted_commit = pinned_commit), so an owner republish silently pulls it from onboarding until an admin re-trusts the new version; the stored mark survives and re-trusting restores it.
  • setCommunityListingFeatured service (rejects untrusted/delisted listings) + listFeaturedCommunityListings (active + featured + trusted, capped at 6 for onboarding).
  • Admin-only community_set_featured MCP capability (requiredRole: 'admin', invisible to non-admins, audited) and admin-only POST /community/:listingId/feature.json handler (audited).
  • Detail page: Featured badge next to Trusted, and an "Admin: onboarding" panel with a feature/unfeature toggle (disabled with an explanation while the listing is untrusted). Revoking trust in the UI also clears the local featured state.
  • Onboarding: new "3. Install a starter package" step listing featured packages (slim OnboardingFeaturedListing payload — no README) linking to their detail pages where the one-click Install button (from Add one-click install for community listings #763) lives. Falls back to the existing "Explore community packages" CTA when nothing is featured. Featured data is omitted for unverified users and fails open to an empty list.
  • community_get exposes the effective featured flag.
  • Docs: usage + contributing community-packages docs, primitives.yaml.

Demo

admin_features_trusted_listing_in_onboarding.mp4

Admin features the trusted @jane/notes-digest listing; the Featured badge appears, and the untrusted listing shows the disabled explanation instead.

new_user_onboarding_starter_package_one_click_install.mp4

A fresh user sees the starter package on /onboarding and one-click installs it.

Onboarding starter package step
Featured badge next to Trusted badge

Testing

  • ✅ npm run validate (format, lint, typecheck, unit, Playwright E2E, MCP E2E — all green)
  • ✅ New node tests: community-feature.node.test.ts (RBAC, validation, error mapping)
  • ✅ Workers integration: featuring requires trust, onboarding list membership, republish drops effective featured, re-trust restores it, delisted rejection, non-admin capability access denied
  • ✅ New Playwright E2E: e2e/community-featured.spec.ts (member 403 + no admin panel, admin toggle, disabled button on untrusted, onboarding starter section appears/disappears)
  • ✅ Manual dev-server demo (videos above)
System recap — extends community listings (medium risk)

Mode: recap · Base: main @ 236554c4 · Head: 7ad88523

Classification: extends — no new primitives; community-listings gains an admin featured mark and the onboarding page gains a starter-package step built on it.

Primitives touched

Primitive Group Impact
community-listings assistant extends — featured_at column, setCommunityListingFeatured / listFeaturedCommunityListings, badge
app-ui surfaces composes — feature toggle on the detail page, "Install a starter package" step on /onboarding
mcp-server surfaces composes — new admin-only community_set_featured capability in the existing community domain
rbac auth composes — requiredRole: 'admin' on the capability; requireUserWithRole on feature.json
d1-app-db storage extends — migration 0060-community-featured-listings.sql adds community_listings.featured_at

System map

Admin featuring flows from the detail-page toggle through RBAC into the community service and D1; onboarding reads the effectively featured listings back out as starter packages.

Legend: green = composes (wiring only) · amber = extended by this PR · red = new primitive · gray = context (unchanged, included only when an edge crosses it).

flowchart LR
	appUi["app-ui<br/>Browser app"]:::touched
	rbac["rbac<br/>Role-based access control"]:::touched
	mcpServer["mcp-server<br/>MCP endpoint"]:::touched
	communityListings["community-listings<br/>Community package listings"]:::extended
	d1AppDb["d1-app-db<br/>D1 app database"]:::extended
	appUi -->|"POST /community/:id/feature.json (admin toggle)"| rbac
	mcpServer -->|"community_set_featured (requiredRole: admin)"| rbac
	rbac -->|"setCommunityListingFeatured (requires trusted)"| communityListings
	communityListings -->|"featured_at column (migration 0060)"| d1AppDb
	appUi -->|"/onboarding starter step ← listFeaturedCommunityListings (featured ∧ trusted ∧ active, cap 6)"| communityListings
	classDef touched fill:#1a7f37,color:#fff
	classDef extended fill:#9a6700,color:#fff
	classDef added fill:#cf222e,color:#fff
	classDef untouched fill:#57606a,color:#fff
Loading

Before / after

before: community_listings(trusted_commit, trusted_by_user_id, trusted_at)
after:  community_listings(... , featured_at)
        effective featured = featured_at IS NOT NULL AND trusted_commit = pinned_commit
before: OnboardingLoaderData { mcpServerUrl, setupPrompt, hasMcpClient, emailVerified, needsOnboarding }
after:  OnboardingLoaderData { ..., featuredListings: OnboardingFeaturedListing[] }  // slim: no README

Invariants

  • community-listing-isolation: unchanged — featuring only affects which public listings onboarding highlights; installs still go through the Add one-click install for community listings #763 fork + publish-check path and the featured flag never bypasses the untrusted acknowledgement (featuring requires effective trust).
  • Featured marks never outlive trust: the effective flag is computed as featured_at IS NOT NULL AND trusted, so an owner republish drops the listing from onboarding without an explicit revoke.
  • primitives.yaml updated in this PR (community-listings summary + migration path).
Open in Web Open in Cursor 

Summary by CodeRabbit

  • New Features
    • Admins can mark effectively trusted community listings as featured, making them appear as onboarding starter packages.
    • Adds an admin-only “Feature in onboarding” control and Featured badge; featuring is cleared when trust is revoked and handled correctly across republish flows.
    • Onboarding falls back to exploring community packages when no featured listings exist.
  • Documentation
    • Updated contributing and usage docs for featured listings and onboarding behavior, including the new admin MCP capability.
  • Tests
    • Added end-to-end coverage for permissions, validation, UI/API behavior, and onboarding visibility/state transitions.

@coderabbitai

coderabbitai Bot commented Jul 16, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds admin-controlled featured community listings backed by featured_at, effective only for trusted current commits. Featured listings are exposed through HTTP and MCP controls, displayed on community details, and shown as onboarding starter packages for verified users.

Changes

Featured community listings

Layer / File(s) Summary
Effective featured state
packages/worker/migrations/*, packages/worker/src/community/*
Adds featured_at, derives effective featured status from trust and pinned commits, and provides repository/service operations with validation and cache invalidation.
Admin feature control
packages/worker/src/app/handlers/*, packages/worker/client/routes/community-detail.tsx, packages/worker/src/app/routes.ts, packages/worker/src/app/router.ts
Adds the admin-only feature endpoint, detail-page controls, featured badge, state refresh, and handler coverage.
MCP featuring capability
packages/worker/src/mcp/capabilities/community/*, docs/contributing/community-packages.md, docs/use/community-packages.md
Adds the admin-only community_set_featured capability and exposes featured through community_get.
Onboarding starter packages
packages/worker/src/app/*, packages/worker/client/routes/onboarding.tsx, e2e/community-featured.spec.ts, e2e/d1-utils.ts
Loads capped featured listings for verified users and renders starter package links or the existing community browse card.
Architecture documentation
docs/contributing/architecture/primitives.yaml
Updates the community-listings primitive references for trust marks, featured onboarding marks, and the featured listings migration.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Admin
  participant CommunityDetail
  participant CommunityFeatureAPI
  participant CommunityService
  participant Database
  Admin->>CommunityDetail: select feature or unfeature
  CommunityDetail->>CommunityFeatureAPI: POST featured state
  CommunityFeatureAPI->>CommunityService: update listing
  CommunityService->>Database: write featured_at
  Database-->>CommunityService: return updated listing
  CommunityService-->>CommunityFeatureAPI: return effective state
  CommunityFeatureAPI-->>CommunityDetail: refresh featured badge
Loading

Possibly related PRs

  • kentcdodds/kody#599: Provides the community listing and MCP capability foundation extended by featured listings.
  • kentcdodds/kody#721: Modifies the same community listing E2E seeding flow used for featured state.
  • kentcdodds/kody#760: Provides the trust state used to determine when featured status is effective.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 13.51% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: featured community listings shown as onboarding starter packages.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/community-featured-onboarding-d4a5

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kody-bot
kody-bot marked this pull request as ready for review July 16, 2026 19:02
@github-actions

github-actions Bot commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-765.kody-a99.workers.dev

Worker: kody-pr-765
D1: kody-pr-765-db
KV: kody-pr-765-oauth-kv

Mocks:

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/worker/src/app/handlers/community-feature.ts`:
- Around line 42-51: Update the admin action handler’s logAuditEvent call for
the community listing feature operation to await the audit write instead of
discarding its promise, ensuring the success response is returned only after the
audit attempt completes.

In `@packages/worker/src/community/service.ts`:
- Around line 592-595: Update the repository method
setCommunityListingFeaturedAt used by the service call so featured: true retains
an existing featured_at value, using a null-coalescing database update rather
than refreshing it on retries; ensure featured: false still clears the
timestamp.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 0dbc5716-4ddb-467d-8b07-eddc3ee57b5e

📥 Commits

Reviewing files that changed from the base of the PR and between 236554c and 7ad8852.

📒 Files selected for processing (33)
  • docs/contributing/architecture/primitives.yaml
  • docs/contributing/community-packages.md
  • docs/use/community-packages.md
  • e2e/community-featured.spec.ts
  • e2e/d1-utils.ts
  • packages/worker/client/routes/community-detail.tsx
  • packages/worker/client/routes/onboarding.tsx
  • packages/worker/migrations/0060-community-featured-listings.sql
  • packages/worker/src/app/community-data.ts
  • packages/worker/src/app/community-detail-content.tsx
  • packages/worker/src/app/community-public-types.ts
  • packages/worker/src/app/community-public.ts
  • packages/worker/src/app/data-cache.ts
  • packages/worker/src/app/handlers/community-detail.tsx
  • packages/worker/src/app/handlers/community-feature.node.test.ts
  • packages/worker/src/app/handlers/community-feature.ts
  • packages/worker/src/app/handlers/onboarding.ts
  • packages/worker/src/app/loader-data.ts
  • packages/worker/src/app/onboarding-data.node.test.ts
  • packages/worker/src/app/onboarding-data.ts
  • packages/worker/src/app/router.ts
  • packages/worker/src/app/routes.ts
  • packages/worker/src/app/ssr-render.node.test.ts
  • packages/worker/src/community/community-flow-test-schema.ts
  • packages/worker/src/community/community-flow.workers.test.ts
  • packages/worker/src/community/repo.ts
  • packages/worker/src/community/service.ts
  • packages/worker/src/community/types.ts
  • packages/worker/src/mcp/capabilities/community/domain.ts
  • packages/worker/src/mcp/capabilities/community/get.ts
  • packages/worker/src/mcp/capabilities/community/set-featured.ts
  • packages/worker/src/mcp/capabilities/community/shared.ts
  • packages/worker/tsconfig-client.json

Comment on lines +42 to +51
void logAuditEvent({
db: env.APP_DB,
category: 'admin',
action: 'community_listing_feature',
result: 'success',
email: actor.email,
ip: getRequestIp(request) ?? undefined,
path: new URL(request.url).pathname,
reason: `listing_id=${listing.id};featured=${parsed.data.featured}`,
})

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Await the admin audit write before returning success.

Discarding this promise lets the response complete without guaranteeing that the state-changing admin action is persisted in the audit log. logAuditEvent already swallows persistence failures, so awaiting it will not turn audit failures into request failures.

Proposed fix
-				void logAuditEvent({
+				await logAuditEvent({
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
void logAuditEvent({
db: env.APP_DB,
category: 'admin',
action: 'community_listing_feature',
result: 'success',
email: actor.email,
ip: getRequestIp(request) ?? undefined,
path: new URL(request.url).pathname,
reason: `listing_id=${listing.id};featured=${parsed.data.featured}`,
})
await logAuditEvent({
db: env.APP_DB,
category: 'admin',
action: 'community_listing_feature',
result: 'success',
email: actor.email,
ip: getRequestIp(request) ?? undefined,
path: new URL(request.url).pathname,
reason: `listing_id=${listing.id};featured=${parsed.data.featured}`,
})
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/app/handlers/community-feature.ts` around lines 42 - 51,
Update the admin action handler’s logAuditEvent call for the community listing
feature operation to await the audit write instead of discarding its promise,
ensuring the success response is returned only after the audit attempt
completes.

Comment on lines +592 to +595
await setCommunityListingFeaturedAt(input.env.APP_DB, {
listingId: input.listingId,
featured: input.featured,
})

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Preserve featured_at when the listing is already featured.

The repository setter refreshes this timestamp on every featured: true request. Because onboarding orders by featured_at and applies a limit, retrying the MCP operation—declared idempotent—can change which packages appear and may exclude the retried listing.

Make the database update preserve an existing timestamp, for example with COALESCE(featured_at, ?), while featured: false still clears it.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/community/service.ts` around lines 592 - 595, Update the
repository method setCommunityListingFeaturedAt used by the service call so
featured: true retains an existing featured_at value, using a null-coalescing
database update rather than refreshing it on retries; ensure featured: false
still clears the timestamp.

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 02537b3. Configure here.

Comment thread packages/worker/client/routes/community-detail.tsx Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/worker/src/app/handlers/community-trust.node.test.ts (1)

68-78: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Cover the revoke path for featured.

This test only verifies trusted: true/featured: true. Add a revocation case asserting trusted: false and featured: false (and ideally a re-trust case) so the effective featured-state synchronization cannot regress.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/app/handlers/community-trust.node.test.ts` around lines
68 - 78, Extend the test around handler.handler and buildTrustRequest with a
revoke case that submits trusted: false and asserts a successful response
containing trusted: false and featured: false. Preferably follow it with a
re-trust case asserting both values return to true, preserving the existing
success and synchronization expectations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@packages/worker/src/app/handlers/community-trust.node.test.ts`:
- Around line 68-78: Extend the test around handler.handler and
buildTrustRequest with a revoke case that submits trusted: false and asserts a
successful response containing trusted: false and featured: false. Preferably
follow it with a re-trust case asserting both values return to true, preserving
the existing success and synchronization expectations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 947fde7a-ccbc-4c35-a41c-a49f2cf74636

📥 Commits

Reviewing files that changed from the base of the PR and between 02537b3 and d829bc6.

📒 Files selected for processing (3)
  • packages/worker/client/routes/community-detail.tsx
  • packages/worker/src/app/handlers/community-trust.node.test.ts
  • packages/worker/src/app/handlers/community-trust.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/worker/client/routes/community-detail.tsx

@kody-bot
kody-bot merged commit 25328c8 into main Jul 16, 2026
5 checks passed
@kody-bot
kody-bot deleted the cursor/community-featured-onboarding-d4a5 branch July 16, 2026 19:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants