feat(web): config-gated Privacy and Terms links plus sign-in consent line - #1051
Merged
Merged
Conversation
…line The hosted deployment's terms of service and privacy policy pages are currently linked nowhere on the site or dashboard, and the sign-in flow shows no consent line. Add NEXT_PUBLIC_PRIVACY_URL / NEXT_PUBLIC_TERMS_URL to lib/site.ts, following the PRICING_PATH pattern: empty by default so self-host and staging builds are unaffected, populated by the hosted deployment at image build time. - Landing page footer, plus the blog/docs/mcp footers via a shared LegalFooterLinks helper, show "Privacy"/"Terms" only when configured. - A shared SignInConsent component renders "By signing in you agree to the Terms and Privacy policy." beneath the landing page's Sign in link and the dashboard's signed-out sign-in prompt, only when both URLs are set. - Links accept a same-origin path or an absolute URL; isExternalURL() decides target=_blank based on origin vs SITE_URL. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
jiashuoz
added a commit
that referenced
this pull request
Sep 27, 2026
#1051 read NEXT_PUBLIC_PRIVACY_URL and NEXT_PUBLIC_TERMS_URL in site.ts but never declared them in web/Dockerfile, so `docker build` dropped the hosted deployment's values and 1.12.0 shipped without the footer links or the consent line. Adds the ARG/ENV pair and a comment explaining why the Dockerfile is the allowlist. Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
6 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds config-gated links to the hosted deployment's Terms of Service and Privacy Policy, which are currently linked nowhere on the e2a website or dashboard, plus a consent line on the sign-in flow.
web/src/lib/site.ts:PRIVACY_URL/TERMS_URL, resolved fromNEXT_PUBLIC_PRIVACY_URL/NEXT_PUBLIC_TERMS_URL, following the same pattern asPRICING_PATH— empty by default, so self-host and staging builds are completely unaffected. Also addsisExternalURL()(decidestarget="_blank"based on origin vsSITE_URL) andlegalFooterLinks()(the shared "Privacy"/"Terms" entry list, present only when configured).FOOTER_LINKS) appends Privacy/Terms when set. The blog, docs, and MCP page footers reuse the samelegalFooterLinks()data via a small sharedLegalFooterLinkscomponent so all public footers stay consistent.SignInConsentcomponent rendersBy signing in you agree to the Terms and Privacy policy.beneath the landing page nav's "Sign in" link and the dashboard's signed-out sign-in prompt ((app)/AppLayoutClient.tsx) — only when both URLs are configured; omitted entirely otherwise.web/.env.exampleanddocs/deployment.mddocument both new env vars.Why
The hosted deployment (e2a.dev) has legal pages with no discoverable links anywhere on the site, and no consent language in the sign-in flow. This wires up config-gated surfacing without making self-host or staging deployments carry any legal-page assumptions.
Env vars
NEXT_PUBLIC_PRIVACY_URL— path or absolute URL to the Privacy Policy.NEXT_PUBLIC_TERMS_URL— path or absolute URL to the Terms of Service.Both accept a same-origin path (e.g.
/privacy) or an absolute URL. Leaving either unset hides the corresponding footer link; the sign-in consent line only appears when both are set.Follow-up
The hosted deployment's actual build args (setting these two env vars to the ops repo's
/privacyand/termsroutes) land intokencanopy/e2a-opsseparately, after this ships in a release.Test plan
npm run lint— cleannpx tsc --noEmit— cleannpm test— 123 suites / 1053 tests passingnpm run build— static export succeeds🤖 Generated with Claude Code