Repository navigation
Preserve binary request bodies in the MCP fetch gateway - #702
Conversation
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
🚧 Files skipped from review as they are similar to previous changes (2)
📝 WalkthroughWalkthroughThe gateway classifies request bodies as UTF-8 text or binary bytes. Placeholder expansion and reference collection apply only to text bodies, while binary payloads are preserved during normal and opt-out forwarding. ChangesBinary body preservation
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant IncomingRequest
participant expandSecretPlaceholders
participant resolveSecret
participant OutgoingRequest
IncomingRequest->>expandSecretPlaceholders: provide request body and headers
expandSecretPlaceholders->>resolveSecret: resolve text-body and header placeholders
resolveSecret-->>expandSecretPlaceholders: resolved secrets
expandSecretPlaceholders->>OutgoingRequest: forward text or unchanged binary body
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🔎 Preview deployed: https://kody-pr-702.kody-a99.workers.dev Worker: Mocks:
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/worker/src/mcp/fetch-gateway.ts`:
- Around line 487-498: Update the TextDecoder construction in readRequestBody to
set ignoreBOM: true alongside fatal: true, preserving a leading UTF-8 BOM when
decoding text request bodies so they round-trip byte-for-byte.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 166650e2-3dea-4be7-a14f-8aff4aa6323f
📒 Files selected for processing (2)
packages/worker/src/mcp/fetch-gateway.node.test.tspackages/worker/src/mcp/fetch-gateway.ts
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Summary
The MCP fetch gateway read every outbound request body with
request.text()before secret-placeholder expansion. Binary bodies (for example multipart uploads with file bytes, such as Discord attachment uploads from package code) were lossily decoded to a string and re-encoded, corrupting the bytes on the wire.This PR makes the gateway binary-safe:
readRequestBodynow reads the body as anArrayBufferand attempts strict UTF-8 decoding (fatal: true). Valid UTF-8 bodies keep the existing text path; anything else is passed through as raw bytes.{ kind: 'text' } | { kind: 'binary' }). Secret placeholder scanning, expansion, and Basic-auth placeholder collection only run on text bodies; binary bodies are forwarded byte-for-byte.x-kody-secret-resolution: offopt-out all behave the same for binary bodies as before.Secret placeholders were never a supported feature inside binary payloads, so skipping expansion there is a behavior clarification, not a regression: placeholder text embedded in binary content is now guaranteed to leave the gateway unresolved.
Testing
npm run validategreen locally.System recap — extends existing primitives (medium risk)
Mode: recap · Base:
main@e5a88469· Head:54e7770aClassification: extends — changes the fetch gateway's request-body handling contract inside the capabilities execute runtime; no new primitives.
Primitives touched
capabilities-executesecretsSystem map
Package and execute
fetchcalls flow through the gateway, which now branches on body kind before secret placeholder expansion.Legend: green = composes (wiring only) · amber = extended by this PR · red = new primitive · gray = context (unchanged, included only when an edge crosses it).
flowchart LR capabilitiesExecute["capabilities-execute<br/>Capabilities execute runtime"]:::extended secrets["secrets<br/>Secret references"]:::touched upstream["Upstream host (e.g. discord.com)"]:::untouched capabilitiesExecute -->|"text body: expand {{secret:...}}"| secrets capabilitiesExecute -->|"binary body: byte-for-byte passthrough"| upstream classDef touched fill:#1a7f37,color:#fff classDef extended fill:#9a6700,color:#fff classDef added fill:#cf222e,color:#fff classDef untouched fill:#57606a,color:#fffBefore / after
request.text(), placeholders resolvedSummary by CodeRabbit