Compare commits

...

1 Commits

Author SHA1 Message Date
Zeno Kapitein 4c2e1de768 Surface verified client identity on the site OAuth/MCP consent screen
The sites OAuth server's consent/start response already returns a
`verifiedName` for clients it recognizes from the known-clients registry
(matched by redirect URI), alongside the untrusted client-supplied `name`.
The consent screen carried the field on its type but never rendered it.

Anchor the trust badge to that server-verified identity: when a client is
verified, show "Verified as {verifiedName}" instead of a bare "Verified",
so the signal reflects the name GitBook vouches for rather than only the
self-reported client name. Falls back to the previous label when no
verified name is present.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015dz2F7LM2xbaSCsMfuGax7
2026-07-28 00:12:50 +00:00
2 changed files with 20 additions and 5 deletions
@@ -0,0 +1,5 @@
---
"gitbook": patch
---
Show the verified client identity ("Verified as …") on the site OAuth/MCP consent screen when the client is a recognized application.
@@ -39,7 +39,10 @@ export function ConsentScreen(props: {
<div className="flex min-w-0 flex-col gap-0.5">
<div className="flex flex-wrap items-center gap-x-2 gap-y-1">
<h1 className="font-semibold text-tint-strong">{client.name}</h1>
<ClientTrustBadge verified={client.verified} />
<ClientTrustBadge
verified={client.verified}
verifiedName={client.verifiedName}
/>
</div>
{client.uri ? (
<StyledLink
@@ -184,10 +187,17 @@ function parseRedirectURI(uri: string): { prefix: string; host: string; rest: st
}
/**
* Inline verified/unverified indicator shown next to the client name.
* Inline verified/unverified indicator shown next to the client name. When the OAuth server matched
* the client to a known application, `verifiedName` is the identity GitBook vouches for — anchoring
* the trust signal to that name rather than the client-supplied (untrusted) name.
*/
function ClientTrustBadge(props: { verified: boolean }) {
const { verified } = props;
function ClientTrustBadge(props: { verified: boolean; verifiedName?: string }) {
const { verified, verifiedName } = props;
let label = 'Unverified';
if (verified) {
label = verifiedName ? `Verified as ${verifiedName}` : 'Verified';
}
return (
<span
@@ -197,7 +207,7 @@ function ClientTrustBadge(props: { verified: boolean }) {
)}
>
<Icon icon={verified ? 'circle-check' : 'triangle-exclamation'} className="size-3" />
{verified ? 'Verified' : 'Unverified'}
{label}
</span>
);
}