Repository navigation
Add JWT signing capability - #283
Conversation
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
🚧 Files skipped from review as they are similar to previous changes (3)
📝 WalkthroughWalkthroughAdds a new read-only MCP secrets capability Changes
Sequence Diagram(s)sequenceDiagram
participant Caller as Caller/Client
participant Handler as jwt_sign Handler
participant SecretSvc as Secret Service
participant Crypto as WebCrypto
Caller->>Handler: jwt_sign(request: secretName, claims, header?, algorithm?, jsonField?)
Handler->>Handler: Validate input (Zod) & authenticate caller
Handler->>SecretSvc: resolveSecret(name, scope, storageContext)
SecretSvc-->>Handler: secretValue (string) + metadata (allowedCapabilities, scope)
Handler->>Handler: Check allowedCapabilities for "jwt_sign"
alt Not Approved
Handler-->>Caller: AccessDenied error with approval URL
else Approved
Handler->>Handler: extractPrivateKeyPem(secretValue, jsonField?)
Handler->>Crypto: importKey(PKCS#8 PEM)
Crypto-->>Handler: CryptoKey
Handler->>Handler: encode header & claims (base64url)
Handler->>Crypto: sign(header.payload, CryptoKey)
Crypto-->>Handler: signature
Handler-->>Caller: { jwt: header.payload.signature, algorithm }
end
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Review rate limit: 0/1 reviews remaining, refill in 60 minutes.Comment |
|
🔎 Preview deployed: https://kody-pr-283.kentcdodds.workers.dev Worker: Mocks:
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@docs/use/secrets-and-values.md`:
- Around line 33-43: The docs incorrectly state that codemode.jwt_sign(...)
returns a bare JWT string; update the text around "Signing JWTs with saved
private keys" to document the actual return shape as an object { jwt, algorithm
} and clarify that callers should use result.jwt for the compact JWT and
result.algorithm for the signing algorithm; also update any inline examples to
access result.jwt (not treat the function return as a string) and note that the
private key material is never returned and jwt_sign still requires the saved
secret to approve the jwt_sign capability.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: d6c63557-f7a8-419b-a609-3edd3124cda0
📒 Files selected for processing (5)
docs/use/secrets-and-values.mdpackages/worker/src/mcp/capabilities/secrets/domain.tspackages/worker/src/mcp/capabilities/secrets/jwt-sign.node.test.tspackages/worker/src/mcp/capabilities/secrets/jwt-sign.tspackages/worker/src/mcp/capabilities/secrets/jwt-signing.ts
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit cc8cdd8. Configure here.
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>

Summary
jwt_signcapability under the secrets domain for signing caller-provided JWT header/claims with a private key stored in a saved secret.{ jwt, algorithm }return shape.Testing
npm run test -- --run packages/worker/src/mcp/capabilities/secrets/jwt-sign.node.test.tsnpm run typechecknpx oxfmt --check packages/worker/src/mcp/capabilities/secrets/jwt-sign.ts packages/worker/src/mcp/capabilities/secrets/jwt-signing.ts packages/worker/src/mcp/capabilities/secrets/jwt-sign.node.test.ts packages/worker/src/mcp/capabilities/secrets/domain.ts docs/use/secrets-and-values.mdnpm run testNotes
npm run lintreports only existing warnings outside this change.useras the approval URL fallback scope.Summary by CodeRabbit
New Features
Documentation
Tests