Repository navigation
fix(gatekeepers): latch expiry after delivery and cap connect-form reads - #668
Merged
Merged
Conversation
Supabase, Linear, Spotify, ZoomInfo and Home Assistant set expiredNotified before awaiting credentialsExpired(), so one failed callback (a Workshop restart mid-deploy is enough) silenced the reconnect prompt for good, and in four of them the RPC error replaced the auth error the caller saw. They now notify through the kit's notifyCredentialsExpiredOnce, which latches only after delivery, and re-arm with clearCredentialExpiryLatch. Home Assistant and the MCP gatekeeper parsed their connect form with formData() before the account checked the nonce, so anyone holding a connect URL could make the Worker buffer a body as large as the plan allows into a 128 MB isolate. Both now read it through readTextCapped (16 KiB), which accepts a Request as well as a Response. gatekeeper-kit: - connect-handshake adds isConnectAttempted/markConnectAttempted on the connectAttempted key the internal no-nonce connect flows already store, and USAGE states the at-most-once complete() rule they enforce. - connectMutationError's JSDoc notes that a form page served with Referrer-Policy: no-referrer, as htmlResponse pages are, submits with Origin: null (checked in Chromium), so a guarded form needs same-origin. Also clarifies the Cloudflare gatekeeper's omitted-scope comment (no behavior change), and updates the kit plan: status, the complete-once rule, the Origin: null constraint on §4.3 and tokenAuth, package-name fixes, and the candidate leaves reviewed and not built. Records the kit's admission rule in its AGENTS.md and plan §1: a leaf abstracts behavior several gatekeepers share under one contract, and an unusual gatekeeper gets plain TypeScript seams, not a provider-specific variant. Plan entries that leaned on a single consumer now follow it: ironclad's split-key handshake gets no kit variant, OAuth discovery and client registration wait for a second consumer outside the MCP SDK, and scope helpers wait for a second gatekeeper on Google's grant model.
|
LGTM! |
Preview:
|
Maximo-Guk
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Small tweaks to fix some latch issues an minor extensions to gatekeeper-kit