# Task 10 — Workspace Registry Manager Publish UX ## Delivered - Added a typed `WorkspacePublishDialog` with an explicit two-stage flow: validate the canonical draft, then confirm publication. The dialog displays the action and pinned base revision before a request can be sent. - Connected the workspace editor's Publish action and staged deletion action to that dialog; local browser drafts remain local until the explicit confirmation. - Added registry pull, workspace bundle import, and Blob-URL export controls. Imports are saved as browser-only drafts and never publish automatically; export URLs are revoked after download. - Added field-level 409 conflict presentation with base, local, and registry values. The only recovery actions are Pull latest registry and Reload workspace; no automatic merge, overwrite, or re-publication occurs. - Kept diagnostics user-initiated and restricted UI/API draft data to canonical workspace fields. Conflict payloads now pass through the canonical draft sanitizer and reject unknown/secret fields before rendering. ## TDD evidence - Wrote the publish-dialog and manager import/export tests before the implementation and observed the expected RED failures (missing dialog/import control). - Added a regression test for conflict payloads containing a secret field and observed it fail before wiring the conflict parser through the canonical sanitizer. - Added a regression test for a failed pull during conflict recovery and observed the original unhandled rejection before adding the redacted in-dialog error state. ## Verification Run in `frontend/` after the final changes: ```text npx vitest run src/shell/WorkspacePublishDialog.test.tsx src/api/workspaces.test.ts src/shell/WorkspaceManager.test.tsx # 3 files passed, 15 tests passed npx tsc -b # exit 0 ``` ```text npx vitest run # 51 files passed, 370 tests passed ```