AddThisFeature

Draft and Publish States

Let users prepare changes privately before anyone else sees them.

moderate Data & Content

What it adds

An explicit draft/published status with server-enforced access, a defined edit model, and cache invalidation on every transition.

What your agent is told to do

5
  1. 1

    Add an explicit status to the content model and enforce it in the query layer. Public reads must be unable to return a draft even when the ID is guessed; a hidden link is not access control.

  2. 2

    Decide and document one edit model: either edits to published content go live immediately, or edits create a separate draft revision that must be published. Pick one and apply it everywhere — a mixed model is where data gets lost.

  3. 3

    Support the full set of transitions, not just publish: unpublish back to draft, republish, discard a draft without touching the live version, and delete.

  4. 4

    Invalidate every cache the moment status changes — page cache, CDN, sitemap, feeds, search index. A published record that a stale cache still serves as missing is the most common bug here.

  5. 5

    Allow a shareable preview to be pinned to a specific unpublished version, so a reviewer sees the version that was sent, not whatever the draft has become since. The token mechanics — expiry, revocation, unguessability, noindex — are owned by Signed Share Links; use that rather than minting your own tokens.

Edge cases it handles

6
  • A published record that is unpublished must disappear from listings, search, sitemaps, and feeds — not just from its own page.
  • A URL that was public and is now a draft needs a deliberate answer: 404, 410, or a signed-in-only view. Decide it, do not let the framework decide.
  • Two editors working a draft at once must not silently overwrite each other; detect the conflict at save time.
  • Publishing must validate that required fields are present. Draft state is exactly where incomplete records live.
  • A draft revision of a deleted parent record must be cleaned up, not left readable.
  • Scheduled transitions to a future time are owned by Scheduled Publishing; this feature owns only the status model those jobs act on.

Definition of done

8
  • Draft content is unreachable by unauthorised users even with a direct ID or URL.
  • The edit model is one documented rule applied consistently across all content types.
  • Unpublish, republish, and discard-draft all work and are reflected everywhere the content appeared.
  • Every status change invalidates page, CDN, feed, sitemap, and search-index caches.
  • Publishing enforces required-field validation.
  • A preview can be pinned to a specific unpublished version, using the existing signed-link mechanism.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.