Repository navigation
Clarify OAuth reconnect generated UI guidance - #483
Conversation
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (10)
📝 WalkthroughWalkthroughThis PR updates documentation, MCP capability descriptions, error handling, and tool guidance to establish ChangesCredential Connect Flow Updates
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
Poem
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 ESLint
ESLint skipped: no ESLint configuration detected in root package.json. To enable, add Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 639a10b. Configure here.
| - ${conversationIdGuidance} | ||
| - \`memoryContext\`: short and task-focused. Kody may use it to surface a few relevant long-term memories and suppress repeats within the same \`conversationId\`. | ||
| - Do not ask the user to paste secrets in chat; use saved secrets or \`open_generated_ui\`. | ||
| - Credential setup uses the standard connect pages: \`/connect/oauth\` for OAuth integrations and reconnects, \`/connect/secret\` for API keys, PATs, and other user-provided secrets. |
There was a problem hiding this comment.
Security prohibition against pasting secrets in chat removed
High Severity
Every explicit "never ask the user to paste a secret/token/credential into chat" prohibition has been removed from the always-present MCP system instructions (server-instructions.ts), tool descriptions (execute.ts, open-generated-ui.ts), and capability descriptions (secret-list.ts, secret-set.ts, secret-delete.ts). The replacement text tells the AI what to use (/connect/secret, /connect/oauth) but no longer tells it what not to do. The only remaining prohibition lives in docs/guides/connect-secret.md, which is loaded on-demand. Positive instructions alone don't prevent the AI from also offering to accept secrets in chat as a fallback.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit 639a10b. Configure here.


Summary
/connect/oauthfor OAuth integrations/reconnects and/connect/secretfor API key, PAT, token, and credential entry or rotation.open_generated_uiMCP-facing text describes saved package apps and inline MCP App workflows.Behavior
OAuth reconnect links are plain
/connect/oauth?provider=...links derived from integration metadata. Secret collection and rotation use/connect/secret.open_generated_uiremains the package/app UI surface.Testing
Summary by CodeRabbit
Documentation
/connect/oauthfor OAuth,/connect/secretfor API keys and PATs) instead of manual entry methods.Bug Fixes