Skip to content

fix(gatekeepers): latch expiry after delivery and cap connect-form reads - #668

Merged
ndisidore merged 1 commit into
mainfrom
chore/gk-kit-continuation
Oct 5, 2026
Merged

ndisidore merged 1 commit into
mainfrom
chore/gk-kit-continuation

Conversation

@ndisidore

@ndisidore ndisidore commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Small tweaks to fix some latch issues an minor extensions to gatekeeper-kit

  • Expiry notices in Supabase, Linear, Spotify, ZoomInfo and Home Assistant moved onto the kit's latch, so a failed callback no longer silences a user's reconnect prompt for good
  • Connect forms in Home Assistant and the MCP gatekeeper capped at 16 KiB through readTextCapped, which now also takes a Request
  • New kit helpers for calling complete() at most once per account (isConnectAttempted / markConnectAttempted), plus a warning that pages served with no-referrer submit forms with Origin: null
  • Kit plan and docs updated: status, the rule that the kit covers only behavior several gatekeepers share, the candidate leaves reviewed but not built, and a clearer comment on Cloudflare's omitted scope (no behavior change)

Devin Review

Supabase, Linear, Spotify, ZoomInfo and Home Assistant set expiredNotified
before awaiting credentialsExpired(), so one failed callback (a Workshop
restart mid-deploy is enough) silenced the reconnect prompt for good, and
in four of them the RPC error replaced the auth error the caller saw. They
now notify through the kit's notifyCredentialsExpiredOnce, which latches
only after delivery, and re-arm with clearCredentialExpiryLatch.

Home Assistant and the MCP gatekeeper parsed their connect form with
formData() before the account checked the nonce, so anyone holding a
connect URL could make the Worker buffer a body as large as the plan
allows into a 128 MB isolate. Both now read it through readTextCapped
(16 KiB), which accepts a Request as well as a Response.

gatekeeper-kit:
- connect-handshake adds isConnectAttempted/markConnectAttempted on the
  connectAttempted key the internal no-nonce connect flows already store,
  and USAGE states the at-most-once complete() rule they enforce.
- connectMutationError's JSDoc notes that a form page served with
  Referrer-Policy: no-referrer, as htmlResponse pages are, submits with
  Origin: null (checked in Chromium), so a guarded form needs same-origin.

Also clarifies the Cloudflare gatekeeper's omitted-scope comment (no
behavior change), and updates the kit plan: status, the complete-once
rule, the Origin: null constraint on §4.3 and tokenAuth, package-name
fixes, and the candidate leaves reviewed and not built.

Records the kit's admission rule in its AGENTS.md and plan §1: a leaf
abstracts behavior several gatekeepers share under one contract, and an
unusual gatekeeper gets plain TypeScript seams, not a provider-specific
variant. Plan entries that leaned on a single consumer now follow it:
ironclad's split-key handshake gets no kit variant, OAuth discovery and
client registration wait for a second consumer outside the MCP SDK, and
scope helpers wait for a second gatekeeper on Google's grant model.
@github-actions github-actions Bot added the gatekeeper Changes to a gatekeeper integration label Oct 5, 2026
@ask-bonk

ask-bonk Bot commented Oct 5, 2026

Copy link
Copy Markdown

LGTM!

github run

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread packages/gatekeeper-homeassistant/src/homeassistant.ts
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Preview: pr668-chore-gk-kit-58248020

https://pr668-chore-gk-kit-58248020-router.cloudflare-os-previews.workers.dev

Dashboard · deleted when this PR closes

@ndisidore
ndisidore merged commit b304e8c into main Oct 5, 2026
18 of 21 checks passed
@ndisidore
ndisidore deleted the chore/gk-kit-continuation branch October 5, 2026 21:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gatekeeper Changes to a gatekeeper integration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants