Skip to content

Add consent-gated platform feedback capabilities - #783

Merged
kody-bot merged 7 commits into
mainfrom
cursor/platform-feedback-d866
Jul 19, 2026
Merged

kody-bot merged 7 commits into
mainfrom
cursor/platform-feedback-d866

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Jul 19, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • add an authenticated meta_platform_feedback_submit capability that requires explicit user confirmation from a trusted interactive MCP origin
  • persist attributed feedback in D1 with atomic 10-per-day/100-active limits and accurate rolling-window retry hints
  • expose audited admin list/get/triage capabilities with untrusted-content warnings and revision-based concurrency control
  • redact reviewer metadata from submitter exports, prune terminal feedback after 365 days, and document the narrow admin-review privacy boundary in both docs and the live privacy page

Testing

  • npm run validate passes: formatting, lint, typecheck, primitive map, 881 unit tests, 15 Playwright E2E tests, and 2 MCP E2E tests.
  • Focused feedback/origin/auth/job/workflow/export/deletion/retention/concurrency tests pass.
  • Manual /privacy walkthrough passes with all disclosures visible and no browser-console errors.
  • Independent hard-to-reverse/privacy reviews, CodeRabbit, Cursor Bugbot, CI validation, and preview deployment are clean.

Walkthrough

platform_feedback_privacy_walkthrough_demo.mp4

System recap — adds a new primitive (high risk)

Mode: recap · Base: main @ edf1e251 · Head: fb7cb747

Classification: adds — introduces the platform-feedback primitive, a consent-gated cross-user review boundary with new D1 persistence, admin capabilities, abuse controls, and retention behavior.

Primitives touched

Primitive Group Impact
platform-feedback assistant adds — submission, persistence, and admin triage boundary
d1-app-db storage extends — feedback table, revision CAS, limits, and query/cleanup indexes
capability-registry assistant extends — one meta and three admin capabilities
mcp-server surfaces extends — ask-first feedback instructions and trusted interactive origin
rbac auth extends — explicit admin-only feedback review exception
account-export assistant extends — submitter-owned export with reviewer metadata redaction
scheduled-cron surfaces extends — 365-day terminal-feedback retention
app-ui surfaces extends — live privacy disclosure for approved feedback

System map

Approved feedback flows from an authenticated interactive MCP origin through consent and atomic limits into D1; admins cross only through audited role gates, while revision checks, account lifecycle, and retention preserve integrity.

Legend: green = composes (wiring only) · amber = extended by this PR · red = new primitive · gray = context (unchanged, included only when an edge crosses it).

flowchart LR
	appUi["app-ui<br/>Browser app (Remix 3)"]:::extended
	mcpServer["mcp-server<br/>MCP endpoint (/mcp)"]:::extended
	capabilityRegistry["capability-registry<br/>Capability registry"]:::extended
	platformFeedback["platform-feedback<br/>Platform feedback"]:::added
	d1AppDb["d1-app-db<br/>D1 app database"]:::extended
	rbac["rbac<br/>Role-based access control"]:::extended
	accountExport["account-export<br/>Account data export"]:::extended
	scheduledCron["scheduled-cron<br/>Scheduled handler"]:::extended
	appUi -->|"public privacy disclosure"| platformFeedback
	mcpServer -->|"interactive origin + ask-first instructions"| capabilityRegistry
	capabilityRegistry -->|"meta submit + admin review capabilities"| platformFeedback
	platformFeedback -->|"feedback rows + atomic limits + revision CAS"| d1AppDb
	rbac -->|"admin role gate + audit"| platformFeedback
	platformFeedback -->|"submitter rows; reviewer fields redacted"| accountExport
	scheduledCron -->|"prune terminal rows after 365 days"| platformFeedback
	classDef touched fill:#1a7f37,color:#fff
	classDef extended fill:#9a6700,color:#fff
	classDef added fill:#cf222e,color:#fff
	classDef untouched fill:#57606a,color:#fff
Loading

Change flow

sequenceDiagram
	participant Agent
	participant User
	participant MCP as Authenticated MCP boundary
	participant Meta as meta_platform_feedback_submit
	participant DB as D1
	participant Admin as admin_platform_feedback_*
	Agent->>User: Describe proposed attributed feedback and ask permission
	User-->>Agent: Explicit approval
	Agent->>MCP: Interactive authenticated request
	MCP->>Meta: Mark trusted interactive origin; submit user_confirmed=true
	Meta->>DB: Atomic rolling-rate/active-queue check and insert
	Admin->>Admin: Enforce current admin role and untrusted-content warning
	Admin->>DB: Compare-and-swap list/detail triage update by revision
Loading

Invariants

  • The submitter id comes only from the authenticated MCP caller; jobs, workflows, packages, and missing-origin contexts are background and cannot assert interactive consent.
  • user_confirmed: true is accepted only for the submission the user explicitly approved.
  • User-authored summary/details are labeled untrusted; admin list rows omit details and notes and never join unrelated user content.
  • Admin triage updates compare status and revision, so stale same-status note edits cannot silently overwrite another reviewer.
  • Account export includes only submitter-owned fields; account deletion removes remaining rows and clears reviewer attribution on surviving rows.
  • Atomic feedback-row counts limit each account to 10 submissions per rolling day and 100 active rows; resolved/dismissed rows are pruned after 365 days.
Open in Web Open in Cursor 

Summary by CodeRabbit

  • New Features
    • Added consent-gated platform feedback submission with attribution, status tracking, and rolling/active submission limits.
    • Added admin MCP tools to list, retrieve, and update approved feedback (including triage actions and admin notes).
  • Documentation
    • Expanded privacy/authorization/storage guidance and updated the platform-friction workflow and privacy policy copy.
  • Bug Fixes
    • Improved execution-origin handling across interactive vs background MCP flows for jobs and package runs.
  • Tests
    • Added/extended coverage for submission rules, admin redaction, retention/lifecycle deletion behavior, and concurrency.

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@coderabbitai

coderabbitai Bot commented Jul 19, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a consent-gated platform feedback system with D1 storage, submission limits, admin MCP review and triage capabilities, execution-origin enforcement, account export/deletion handling, retention pruning, tests, and updated privacy and authorization documentation.

Changes

Platform feedback workflow

Layer / File(s) Summary
Feedback data and service workflow
packages/worker/migrations/0062-platform-feedback.sql, packages/worker/src/platform-feedback/*, packages/worker/src/platform-feedback/platform-feedback-service.node.test.ts
Adds the feedback schema, repository operations, validation, transitions, limits, domain errors, and service integration tests.
Execution-origin context and submission capability
packages/shared/src/chat.ts, packages/worker/src/mcp/*, packages/worker/src/jobs/*, packages/worker/src/package-runtime/*, packages/worker/src/mcp/capabilities/meta/*
Adds interactive/background MCP execution origins, propagates them through runtime paths, and introduces consent-gated submission.
Admin feedback review capabilities
packages/worker/src/mcp/capabilities/admin/*, packages/worker/src/mcp/capabilities/platform-feedback-capabilities.node.test.ts
Adds audited admin list, get, and update capabilities with pagination, filtering, role checks, formatted responses, and untrusted-content handling.
Account export, deletion, and retention
packages/worker/src/app/*, packages/worker/src/app/retention*
Integrates feedback rows with account deletion, export redaction, terminal-state retention, pruning, and guardrail tests.
Authorization, privacy, and friction guidance
docs/contributing/*, docs/guides/platform-friction.md, docs/use/privacy.md, packages/worker/client/routes/privacy.tsx
Documents approval, admin visibility, privacy boundaries, lifecycle rules, and assistant guidance.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant MCP
  participant FeedbackService
  participant FeedbackDB
  participant Admin
  User->>MCP: Confirm feedback with user_confirmed=true
  MCP->>FeedbackService: Submit interactive feedback
  FeedbackService->>FeedbackDB: Insert attributed submission
  FeedbackDB-->>FeedbackService: Open feedback record
  FeedbackService-->>MCP: Return feedback_id and status
  Admin->>MCP: List, get, or update feedback
  MCP->>FeedbackService: Execute audited admin operation
  FeedbackService->>FeedbackDB: Read or triage record
  FeedbackDB-->>MCP: Formatted feedback response
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately captures the main change: adding consent-gated platform feedback capabilities.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/platform-feedback-d866

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

cursoragent and others added 4 commits July 19, 2026 00:20
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kody-bot
kody-bot marked this pull request as ready for review July 19, 2026 01:19
@github-actions

github-actions Bot commented Jul 19, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-783.kody-a99.workers.dev

Worker: kody-pr-783
D1: kody-pr-783-db
KV: kody-pr-783-oauth-kv

Mocks:

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/worker/src/platform-feedback/repo.ts`:
- Around line 196-227: Use updated_at as the optimistic-concurrency version
instead of status alone. In
packages/worker/src/platform-feedback/repo.ts:196-227, add an expected
updated_at input to updatePlatformFeedbackStatusForAdmin and include it in the
WHERE predicate; in packages/worker/src/platform-feedback/service.ts:255-280,
pass existing.updatedAt before retrying. In
packages/worker/src/platform-feedback/platform-feedback-service.node.test.ts:163-203,
add coverage for competing same-status note updates and verify the stale writer
conflicts or retries safely.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 0cdd1bc1-f95d-4d97-95ed-3e6eb7d9dcb8

📥 Commits

Reviewing files that changed from the base of the PR and between edf1e25 and 6f9232a.

📒 Files selected for processing (45)
  • docs/contributing/adding-capabilities.md
  • docs/contributing/architecture/authorization.md
  • docs/contributing/architecture/data-storage.md
  • docs/contributing/architecture/primitives.yaml
  • docs/contributing/project-intent.md
  • docs/guides/platform-friction.md
  • docs/use/privacy.md
  • packages/shared/src/chat.node.test.ts
  • packages/shared/src/chat.ts
  • packages/worker/client/routes/privacy.tsx
  • packages/worker/migrations/0062-platform-feedback.sql
  • packages/worker/src/app/account-data-targets.ts
  • packages/worker/src/app/account-deletion.node.test.ts
  • packages/worker/src/app/account-export.node.test.ts
  • packages/worker/src/app/account-export.ts
  • packages/worker/src/app/retention.node.test.ts
  • packages/worker/src/app/retention.ts
  • packages/worker/src/jobs/service.node.test.ts
  • packages/worker/src/jobs/service.ts
  • packages/worker/src/jobs/types.ts
  • packages/worker/src/mcp-auth.ts
  • packages/worker/src/mcp-auth.workers.test.ts
  • packages/worker/src/mcp/capabilities/admin/admin-platform-feedback-get.ts
  • packages/worker/src/mcp/capabilities/admin/admin-platform-feedback-list.ts
  • packages/worker/src/mcp/capabilities/admin/admin-platform-feedback-update.ts
  • packages/worker/src/mcp/capabilities/admin/domain.ts
  • packages/worker/src/mcp/capabilities/admin/platform-feedback-shared.ts
  • packages/worker/src/mcp/capabilities/coding/kody-official-guide.ts
  • packages/worker/src/mcp/capabilities/meta/domain.ts
  • packages/worker/src/mcp/capabilities/meta/meta-platform-feedback-submit.ts
  • packages/worker/src/mcp/capabilities/platform-feedback-capabilities.node.test.ts
  • packages/worker/src/mcp/context.ts
  • packages/worker/src/mcp/server-instructions.ts
  • packages/worker/src/package-invocations/service.ts
  • packages/worker/src/package-retrievers/service.ts
  • packages/worker/src/package-runtime/package-app.ts
  • packages/worker/src/package-runtime/package-service.ts
  • packages/worker/src/package-runtime/package-workflows.node.test.ts
  • packages/worker/src/package-runtime/package-workflows.ts
  • packages/worker/src/package-runtime/realtime-session.ts
  • packages/worker/src/platform-feedback/errors.ts
  • packages/worker/src/platform-feedback/platform-feedback-service.node.test.ts
  • packages/worker/src/platform-feedback/repo.ts
  • packages/worker/src/platform-feedback/service.ts
  • packages/worker/src/platform-feedback/types.ts

Comment thread packages/worker/src/platform-feedback/repo.ts
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 7d4069a. Configure here.

Comment thread packages/worker/src/platform-feedback/service.ts
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kody-bot
kody-bot merged commit b962f94 into main Jul 19, 2026
5 checks passed
@kody-bot
kody-bot deleted the cursor/platform-feedback-d866 branch July 19, 2026 01:44
@cursor cursor Bot mentioned this pull request Jul 19, 2026
1 of 2 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants