Skip to content

v0.3.14 — opt-in link previews for private sites and shares

Choose a tag to compare

@kdr kdr released this 19 Jul 04:11
· 15 commits to main since this release
0816c6f

✨ New

Paste a Cloudglue link into Slack, iMessage, Notion, or Discord and it can now unfurl as a real card — title, description, thumbnail — instead of a bare URL or a generic "Sign in" box.

Public sites and shares already previewed. For a public site, the card comes from the Open Graph tags in the HTML you generate, so this release teaches every authoring surface to emit them on each publish: og:title, og:description, og:image (an absolute URL — a share's preview_url works), og:url, twitter:card. Regenerating a page without them silently reverts the card to a bare link, which is the failure this guidance exists to prevent. Unfurl bots don't run JavaScript, so the tags must be in the static HTML.

Private sites and shares never reached the bot at all — the edge gate redirects it to sign-in before any HTML is served. They now opt in explicitly:

# Private site: card = --preview-title + the site description + --preview-image
tinycloud publish ./site --visibility private --link-preview full \
  --preview-title "Q3 launch clips" \
  --preview-image "https://…/preview.png" --json

# Private share: card = the share's own title, description, and thumbnail
tinycloud publish video ./launch.mp4 --visibility private \
  --name "Q3 launch review" --link-preview full --json
  • --link-preview none is the default and stays today's behavior.
  • Flipping the setting on an existing site is a settings PATCH — no re-upload, no new version — reported as the new settings-only action. On an existing share it reuses the share.
  • --preview-image must be publicly fetchable: site assets sit behind the same gate the bot can't pass. It's validated as an absolute http(s) URL before anything uploads.
  • --preview-title / --preview-image are site-only and require --link-preview full; both rules are enforced rather than silently ignored.

⚠️ Before you turn it on

--link-preview full makes the card title, description, and image readable by anyone who fetches the link — the user-agent check only routes requests; the setting is the security boundary. Nothing else is exposed: no site content, no video, no tokens or cookies, and playback stays sign-in gated in every mode. Platforms cache the unfurl per exact URL and rehost the image, so switching back to none stops future previews but does not retract cards already posted.

Because of that, the skill and system prompt both tell the agent to ask you first before opting a private artifact in.

Notes

Still 16 verbs; features 33 → 34 with the new publish.link.preview.v1 id. The bundled Cloudglue SDK moves to 0.7.20 for the share link_preview parameter. The skill floor rises to 0.3.14, since the skill now teaches the new flags.

Install

curl -fsSL https://app.cloudglue.dev/tinycloud.sh | bash
# or
npx @cloudglue/tinycloud@latest