Skip to content

fix(mcp): keep integration_save create-field gaps off Sentry - #1203

Merged
kody-bot merged 2 commits into
mainfrom
cursor/sentry-triage-kody-cloudflare-kody-cloudflare-3n-0be3
Aug 4, 2026
Merged

kody-bot merged 2 commits into
mainfrom
cursor/sentry-triage-kody-cloudflare-kody-cloudflare-3n-0be3

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Aug 4, 2026 •

Copy link
Copy Markdown
Owner

Intent

Stop Sentry triage noise from agent mistakes when creating OAuth integrations without required secret field names (KODY-CLOUDFLARE-3N).

Summary

  • integration_save create-time Zod failures (missing accessTokenSecretName, etc.) now throw McpCallerError instead of a plain Error.
  • MCP observability already skips caller failures, so these stay on mcp-event logs and out of Sentry.
  • Same error message text; agents can still fix and retry.

Testing

  • integration-save.node.test.ts (includes Slack-shaped missing accessTokenSecretName case; pins message + type)
  • Pre-push gate: unit + workers unit + e2e (all green)

System changes

System recap — composes existing primitives (low risk)

Mode: recap · Base: main @ a3ea47af · Head: 783c5479

Classification: composes — wires the existing McpCallerError / MCP observability skip path into create-time validation; no new primitives or schema changes.

Primitives touched

Primitive Group Impact
integrations assistant composes — throw McpCallerError for create-field gaps

System map

Agent calls integration_save with incomplete create args; the capability rejects with a caller error that observability keeps off Sentry.

Legend: green = composes (wiring only) · amber = extended by this PR · red = new primitive · gray = context (unchanged, included only when an edge crosses it).

flowchart LR
	integrations["integrations<br/>OAuth integrations"]:::touched
	mcpObs["mcp-observability<br/>MCP failure capture"]:::untouched
	integrations -->|"McpCallerError on create gaps"| mcpObs
	mcpObs -->|"isCallerFailure skips Sentry"| drop["dropped"]:::untouched
	classDef touched fill:#1a7f37,color:#fff
	classDef extended fill:#9a6700,color:#fff
	classDef added fill:#cf222e,color:#fff
	classDef untouched fill:#57606a,color:#fff
Loading
Open in Web Open in Cursor 

Summary by CodeRabbit

  • Bug Fixes
    • Improved validation errors when creating integrations with missing or invalid required fields.
    • Confidential integrations now clearly identify when an access token secret name is missing.
    • Validation failures are reported with more specific caller-facing error details.

Missing required fields when creating an integration (e.g. accessTokenSecretName)
are agent-fixable; throw McpCallerError so they stay off Sentry
(KODY-CLOUDFLARE-3N).
@coderabbitai

coderabbitai Bot commented Aug 4, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Integration creation validation now throws McpCallerError for missing or invalid fields. Tests verify the error type and cover missing accessTokenSecretName for confidential Slack integrations.

Changes

Integration validation

Layer / File(s) Summary
Use typed validation errors
packages/worker/src/mcp/capabilities/integrations/integration-save.ts
Invalid or incomplete integration creation now throws McpCallerError and preserves the existing validation details.
Test validation failures
packages/worker/src/mcp/capabilities/integrations/integration-save.node.test.ts
Tests assert McpCallerError and verify the missing accessTokenSecretName message for a confidential Slack integration.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • kentcdodds/kody#1038: Updates MCP capability validation to use McpCallerError in a different capability module.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes keeping integration_save create-field errors out of Sentry.
Description check ✅ Passed The description includes the required Intent, Summary, and Testing sections and provides relevant implementation and system-change details.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/sentry-triage-kody-cloudflare-kody-cloudflare-3n-0be3

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kody-bot
kody-bot marked this pull request as ready for review August 4, 2026 02:40

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@packages/worker/src/mcp/capabilities/integrations/integration-save.node.test.ts`:
- Around line 168-187: The test for the missing accessTokenSecretName must
continue validating the existing error message, not only the error type. Update
the earlier rejection assertion around integrationSaveCapability.handler to
retain the message-matching check alongside the McpCallerError assertion, while
preserving the current validation scenario.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: e5be8be5-e1ff-4736-9766-355c45518397

📥 Commits

Reviewing files that changed from the base of the PR and between 788669b and c67b635.

📒 Files selected for processing (2)
  • packages/worker/src/mcp/capabilities/integrations/integration-save.node.test.ts
  • packages/worker/src/mcp/capabilities/integrations/integration-save.ts

Comment thread packages/worker/src/mcp/capabilities/integrations/integration-save.node.test.ts Outdated
@github-actions

github-actions Bot commented Aug 4, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-1203.kody-a99.workers.dev

Worker: kody-pr-1203
D1: kody-pr-1203-db
KV: kody-pr-1203-oauth-kv

Mocks:

Address CodeRabbit feedback so create-field gap tests still pin the
caller-facing message alongside McpCallerError.
@kody-bot
kody-bot merged commit a920386 into main Aug 4, 2026
14 of 16 checks passed
@kody-bot
kody-bot deleted the cursor/sentry-triage-kody-cloudflare-kody-cloudflare-3n-0be3 branch August 4, 2026 03:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants