Files
pad/web
xarmian 3c0aed55db feat(server): add webmcp_enabled platform setting + session flag (#763)
* chore(docs): correct cloud MCP from "future /mcp endpoint" to live mcp.getpad.dev vhost

The HTTPHandlerDispatcher description called the remote MCP server a
"future /mcp endpoint." It's live: a cloud-mode-gated Streamable HTTP
server mounted on the dedicated mcp.getpad.dev vhost via
SetMCPTransport / registerMCPRoutes. Point at handlers_mcp.go.

Claude-Session: https://claude.ai/code/session_01KmxkPxLksjf1pmrZDpsnTJ

* feat(server): add webmcp_enabled platform setting + session flag

Introduce the opt-in gate for the browser-side WebMCP surface
(PLAN-1888 Phase 1, DR-6). New webmcp_enabled platform setting,
default off, admin-writable, surfaced to the web client via the
/api/v1/auth/session payload so client tool registration can gate
on it.

- internal/server/handlers_admin.go: add settingWebMCPEnabled to the
  admin-PATCH whitelist (else silently dropped) + serialize a "false"
  default in the GET settings response.
- internal/server/handlers_auth.go: emit webmcp_enabled in the session
  payload via a fail-closed webMCPEnabled() helper (false on unset or
  read error).
- web/src/lib/api/client.ts: add webmcp_enabled?: boolean to AuthSession.
- web/.../console/admin/settings/+page.svelte: Integrations section with
  a WebMCP toggle + security warning copy (Phase 4 admin-warning intent).
- Go tests: admin PATCH persists + non-admin 403; session payload reflects
  stored value with default false.

No migration (platform_settings is an existing kv table).

Refs TASK-1889 / PLAN-1888

Claude-Session: https://claude.ai/code/session_01KmxkPxLksjf1pmrZDpsnTJ
2026-06-24 22:28:34 -04:00
..
2026-03-26 01:52:36 +00:00
2026-03-26 01:52:36 +00:00
2026-03-26 01:52:36 +00:00
2026-03-26 01:52:36 +00:00
2026-03-26 01:52:36 +00:00
2026-03-26 01:52:36 +00:00

Pad Web UI

SvelteKit 2 + Svelte 5 frontend for Pad, compiled to static files and embedded into the Go binary.

Development

npm install
npm run dev          # Dev server at localhost:5173 (proxies API to localhost:7777)
npm run build        # Production build to build/
npm run check        # Type checking with svelte-check

When developing, run the Go backend separately with make dev from the project root.

Building for Production

Do not build in isolation. Always use make build from the project root — this builds the web frontend, then compiles the Go binary with the build output embedded via //go:embed.

Stack

  • Svelte 5 with runes ($state, $derived, $effect)
  • SvelteKit 2 with adapter-static (SPA mode)
  • Tiptap block editor with markdown round-trip
  • svelte-dnd-action for drag-and-drop in board/list views
  • SSE for real-time updates
  • TypeScript throughout

Structure

src/
  routes/                    SvelteKit pages
    +layout.svelte           App shell (sidebar + main)
    +page.svelte             Landing/redirect
    [workspace]/
      +page.svelte           Dashboard (collections, phases, activity)
      +layout.svelte         SSE connection per workspace
      [collection]/
        +page.svelte         Collection view (board/list)
      [collection]/[item]/
        +page.svelte         Item detail + editor
      conventions/            Purpose-built conventions page
      playbooks/              Purpose-built playbooks page
      settings/               Workspace settings
  lib/
    api/client.ts            HTTP API client
    components/
      layout/                Sidebar, navigation
      editor/                Tiptap editor, raw markdown editor
      fields/                FieldEditor, relation picker
      items/                 ItemCard, ItemDetail
      collections/           BoardView, ListView
      common/                StatusBadge, badges, modals
      search/                CommandPalette
      activity/              ActivityFeed
    stores/                  Svelte 5 reactive stores
      workspace.svelte.ts    Workspace state
      collections.svelte.ts  Collection + item state
      ui.svelte.ts           Sidebar, mobile state
    types/index.ts           TypeScript types and constants
  app.css                    Global styles and design tokens