Skip to content

Add secret-derived Basic Auth helpers - #452

Merged
kentcdodds merged 4 commits into
mainfrom
cursor/secret-auth-helpers-6c6b
May 12, 2026
Merged

kentcdodds merged 4 commits into
mainfrom
cursor/secret-auth-helpers-6c6b

Conversation

@kentcdodds

@kentcdodds kentcdodds commented May 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Add a secret-derived Basic Auth placeholder for secret-aware fetch headers.
  • Add secretHeaders.basic(...) and oauthClientCredentials(...) runtime helpers.
  • Document the PayPal client-credentials pattern and host-approval behavior.
  • Support direct and pre-prefixed Basic Auth placeholder forms without duplicating the scheme, including common Basic scheme casing variants.

Validation

  • npx vitest run --project node-unit packages/worker/src/mcp/fetch-gateway.node.test.ts packages/worker/src/mcp/execute-modules/codemode-utils.node.test.ts packages/worker/src/package-runtime/module-graph.node.test.ts
  • npm run format:check
  • npm run lint (passes with existing warnings)
  • npm run typecheck
  • npm run test
  • npm run validate
  • Reviewer fix passes:
    • npm run format:check && npx vitest run --project node-unit packages/worker/src/mcp/fetch-gateway.node.test.ts && npm run validate
    • npm run format && npm run format:check && npx vitest run --project node-unit packages/worker/src/mcp/fetch-gateway.node.test.ts && npm run validate
Open in Web Open in Cursor 

Summary by CodeRabbit

  • New Features

    • OAuth 2.0 client_credentials flow available as a runtime helper for token exchanges.
    • Helper to derive HTTP Basic Auth Authorization headers from two saved secrets; derived header is resolved server-side and requires host approval.
  • Documentation

    • Execute and secrets guides expanded with client-credentials workflow and Basic Auth secret-header examples.

Review Change Stack

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@coderabbitai

coderabbitai Bot commented May 12, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c6a74e2d-6b5e-46dd-b1b0-3fcebd5689e4

📥 Commits

Reviewing files that changed from the base of the PR and between 945400f and 58ba4eb.

📒 Files selected for processing (2)
  • packages/worker/src/mcp/fetch-gateway.node.test.ts
  • packages/worker/src/mcp/fetch-gateway.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/worker/src/mcp/fetch-gateway.ts

📝 Walkthrough

Walkthrough

Adds OAuth2 client_credentials token exchange and derived HTTP Basic Auth header support: new runtime helpers (oauthClientCredentials, secretHeaders.basic), {{secret-basic:...}} placeholder parsing/building, gateway expansion to resolve derived Basic headers, runtime exports, typecheck updates, tests, and documentation.

Changes

OAuth2 client_credentials and Basic Auth feature

Layer / File(s) Summary
Basic Auth placeholder infrastructure
packages/worker/src/mcp/secrets/placeholders.ts
Introduces {{secret-basic:...}} placeholder regex, ReferencedBasicAuthSecretPlaceholder type, parsing from strings and form-encoded bodies, builders, and containsSecretPlaceholder.
OAuth client credentials & secretHeaders.basic helpers
packages/worker/src/mcp/execute-modules/codemode-utils.ts, packages/worker/src/mcp/execute-modules/codemode-utils.node.test.ts
Adds BasicAuthSecretHeaderInput and OAuthClientCredentialsInput types, implements secretHeaders.basic(...) placeholder builder and oauthClientCredentials(...) (client_credentials POST using the Basic placeholder), mirrors helpers in the generated execute prelude, and adds unit tests for placeholder formatting, OAuth POST, and prelude exposure.
Gateway expansion of Basic Auth placeholders
packages/worker/src/mcp/fetch-gateway.ts, packages/worker/src/mcp/fetch-gateway.node.test.ts
Extends expandSecretPlaceholders to discover basic-auth placeholders in URL/headers/form bodies, resolve username/password secrets (with caching), base64-encode username:password, inject Authorization: Basic ..., dedupe references, and includes tests for parsing, resolution, missing-secret errors, prefixed placeholders, and host-approval enforcement.
Runtime exposure and module generation
packages/worker/src/package-runtime/module-graph.ts, packages/worker/src/package-runtime/module-graph.node.test.ts, packages/worker/src/mcp/run-codemode-registry.ts
Exports secretHeaders and oauthClientCredentials from the virtual kody:runtime module and injects them into the bundled module runtime context; tests updated to assert the new exports.
TypeScript type definitions & placeholder detection
packages/worker/src/repo/checks.ts, packages/worker/src/mcp/generated-ui-api.ts
Adds KodySecretScope, KodySecretHeadersRuntime, and KodyOauthClientCredentialsInput to the execute typecheck prelude and declares secretHeaders/oauthClientCredentials; centralizes placeholder detection with containsSecretPlaceholder and updates generated UI error text.
User-facing documentation and tool guidance
docs/use/execute.md, docs/use/secrets-and-values.md, packages/worker/src/mcp/server-instructions.ts, packages/worker/src/mcp/tools/execute.ts
Documents oauthClientCredentials and secretHeaders.basic import usage, adds a client_credentials example workflow and Basic Auth derivation examples, and updates tool/server guidance about host-approved secret resolution.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • kentcdodds/kody#324: Both PRs modify the fetch-gateway secret-expansion logic (expandSecretPlaceholders) and related secret-placeholder handling, so they are directly related.
  • kentcdodds/kody#85: Both PRs modify fetch-gateway's secret placeholder expansion (expandSecretPlaceholders) and related tests, so they are related.
  • kentcdodds/kody#250: Both PRs touch the package-runtime/module-graph virtual runtime module wiring—this main PR adds new runtime exports while the retrieved PR refactors the module-graph logic, so they are related.

"I'm a rabbit in the code, hopping through the stack,
Secrets tucked in burrows, never out of track.
Basic headers bloom from two small seeds,
OAuth tokens fetched for your client needs.
Approval gates open — now fetch, and don't look back!"

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Add secret-derived Basic Auth helpers' directly and accurately describes the main change: introducing new Basic Auth helper functions and placeholders for secret-aware authorization headers.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/secret-auth-helpers-6c6b

Warning

Review ran into problems

🔥 Problems

Timed out fetching pipeline failures after 30000ms


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@kentcdodds
kentcdodds marked this pull request as ready for review May 12, 2026 17:22
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@github-actions

github-actions Bot commented May 12, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-452.kentcdodds.workers.dev

Worker: kody-pr-452
D1: kody-pr-452-db
KV: kody-pr-452-oauth-kv

Mocks:

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/worker/src/mcp/fetch-gateway.ts`:
- Around line 107-117: The code currently always sets the replacement value to
buildBasicAuthHeader(...) (which includes the "Basic " scheme), so if a template
uses a pre-prefixed header like "Authorization: Basic {{secret-basic:...}}"
expansion becomes "Basic Basic ...". Update the loop that iterates
basicAuthPlaceholders (and uses buildBasicAuthSecretPlaceholderFromReference,
buildBasicAuthHeader, readResolvedSecretValue, resolvedValues, and replacements)
to create the authHeader once, then set two replacement keys: the normal
renderedPlaceholder -> authHeader, and the prefixed key ("Basic " +
renderedPlaceholder) -> authHeader with the "Basic " scheme stripped (e.g.,
authHeader.replace(/^Basic\s+/i, '')). This ensures both "{{secret-basic:...}}"
and "Basic {{secret-basic:...}}" expand correctly without duplicating the
scheme.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 49740107-0b39-43ed-a2d6-e58d908be592

📥 Commits

Reviewing files that changed from the base of the PR and between 7527892 and 7c8dc00.

📒 Files selected for processing (14)
  • docs/use/execute.md
  • docs/use/secrets-and-values.md
  • packages/worker/src/mcp/execute-modules/codemode-utils.node.test.ts
  • packages/worker/src/mcp/execute-modules/codemode-utils.ts
  • packages/worker/src/mcp/fetch-gateway.node.test.ts
  • packages/worker/src/mcp/fetch-gateway.ts
  • packages/worker/src/mcp/generated-ui-api.ts
  • packages/worker/src/mcp/run-codemode-registry.ts
  • packages/worker/src/mcp/secrets/placeholders.ts
  • packages/worker/src/mcp/server-instructions.ts
  • packages/worker/src/mcp/tools/execute.ts
  • packages/worker/src/package-runtime/module-graph.node.test.ts
  • packages/worker/src/package-runtime/module-graph.ts
  • packages/worker/src/repo/checks.ts

Comment thread packages/worker/src/mcp/fetch-gateway.ts Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 7c8dc00. Configure here.

return input.scope
? `{{secret-basic:username=${input.usernameSecret},password=${input.passwordSecret}|scope=${input.scope}}}`
: `{{secret-basic:username=${input.usernameSecret},password=${input.passwordSecret}}}`
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Duplicated placeholder builder risks silent format divergence

Medium Severity

buildBasicAuthSecretPlaceholder is independently implemented with identical logic in both codemode-utils.ts (private, used by secretHeaders.basic) and placeholders.ts (exported, used by the fetch gateway for building and matching). Since the fetch gateway's parseBasicAuthSecretPlaceholders regex must match what secretHeaders.basic produces, any format change in one file without the other would silently break secret resolution at runtime. The codemode-utils.ts copy could import from placeholders.ts instead of duplicating the template string.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 7c8dc00. Configure here.

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/worker/src/mcp/fetch-gateway.ts`:
- Around line 114-120: The current replacement logic sets only the `Basic
${renderedPlaceholder}` key, so incoming headers with a lowercase scheme like
`basic {{...}}` will not match and produce `basic Basic ...`; update the
replacement setup in fetch-gateway.ts to handle scheme case-insensitively by
adding a lowercase variant (e.g., also set `basic ${renderedPlaceholder}`) or by
normalizing the scheme when creating keys (lowercasing the prefix before setting
entries) for the replacements Map; adjust where `prefixedPlaceholder`,
`renderedPlaceholder`, `replacements`, and `authHeader` are used so both `Basic`
and `basic` lookups map to `authHeader`.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 9c658537-fec3-4405-b001-00490b9281eb

📥 Commits

Reviewing files that changed from the base of the PR and between 7c8dc00 and 945400f.

📒 Files selected for processing (2)
  • packages/worker/src/mcp/fetch-gateway.node.test.ts
  • packages/worker/src/mcp/fetch-gateway.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/worker/src/mcp/fetch-gateway.node.test.ts

Comment thread packages/worker/src/mcp/fetch-gateway.ts Outdated
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kentcdodds
kentcdodds merged commit 5675979 into main May 12, 2026
5 checks passed
@kentcdodds
kentcdodds deleted the cursor/secret-auth-helpers-6c6b branch May 12, 2026 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants