Repository navigation
Add consent-gated platform feedback capabilities - #783
Conversation
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
📝 WalkthroughWalkthroughAdds a consent-gated platform feedback system with D1 storage, submission limits, admin MCP review and triage capabilities, execution-origin enforcement, account export/deletion handling, retention pruning, tests, and updated privacy and authorization documentation. ChangesPlatform feedback workflow
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant User
participant MCP
participant FeedbackService
participant FeedbackDB
participant Admin
User->>MCP: Confirm feedback with user_confirmed=true
MCP->>FeedbackService: Submit interactive feedback
FeedbackService->>FeedbackDB: Insert attributed submission
FeedbackDB-->>FeedbackService: Open feedback record
FeedbackService-->>MCP: Return feedback_id and status
Admin->>MCP: List, get, or update feedback
MCP->>FeedbackService: Execute audited admin operation
FeedbackService->>FeedbackDB: Read or triage record
FeedbackDB-->>MCP: Formatted feedback response
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
🔎 Preview deployed: https://kody-pr-783.kody-a99.workers.dev Worker: Mocks:
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/worker/src/platform-feedback/repo.ts`:
- Around line 196-227: Use updated_at as the optimistic-concurrency version
instead of status alone. In
packages/worker/src/platform-feedback/repo.ts:196-227, add an expected
updated_at input to updatePlatformFeedbackStatusForAdmin and include it in the
WHERE predicate; in packages/worker/src/platform-feedback/service.ts:255-280,
pass existing.updatedAt before retrying. In
packages/worker/src/platform-feedback/platform-feedback-service.node.test.ts:163-203,
add coverage for competing same-status note updates and verify the stale writer
conflicts or retries safely.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 0cdd1bc1-f95d-4d97-95ed-3e6eb7d9dcb8
📒 Files selected for processing (45)
docs/contributing/adding-capabilities.mddocs/contributing/architecture/authorization.mddocs/contributing/architecture/data-storage.mddocs/contributing/architecture/primitives.yamldocs/contributing/project-intent.mddocs/guides/platform-friction.mddocs/use/privacy.mdpackages/shared/src/chat.node.test.tspackages/shared/src/chat.tspackages/worker/client/routes/privacy.tsxpackages/worker/migrations/0062-platform-feedback.sqlpackages/worker/src/app/account-data-targets.tspackages/worker/src/app/account-deletion.node.test.tspackages/worker/src/app/account-export.node.test.tspackages/worker/src/app/account-export.tspackages/worker/src/app/retention.node.test.tspackages/worker/src/app/retention.tspackages/worker/src/jobs/service.node.test.tspackages/worker/src/jobs/service.tspackages/worker/src/jobs/types.tspackages/worker/src/mcp-auth.tspackages/worker/src/mcp-auth.workers.test.tspackages/worker/src/mcp/capabilities/admin/admin-platform-feedback-get.tspackages/worker/src/mcp/capabilities/admin/admin-platform-feedback-list.tspackages/worker/src/mcp/capabilities/admin/admin-platform-feedback-update.tspackages/worker/src/mcp/capabilities/admin/domain.tspackages/worker/src/mcp/capabilities/admin/platform-feedback-shared.tspackages/worker/src/mcp/capabilities/coding/kody-official-guide.tspackages/worker/src/mcp/capabilities/meta/domain.tspackages/worker/src/mcp/capabilities/meta/meta-platform-feedback-submit.tspackages/worker/src/mcp/capabilities/platform-feedback-capabilities.node.test.tspackages/worker/src/mcp/context.tspackages/worker/src/mcp/server-instructions.tspackages/worker/src/package-invocations/service.tspackages/worker/src/package-retrievers/service.tspackages/worker/src/package-runtime/package-app.tspackages/worker/src/package-runtime/package-service.tspackages/worker/src/package-runtime/package-workflows.node.test.tspackages/worker/src/package-runtime/package-workflows.tspackages/worker/src/package-runtime/realtime-session.tspackages/worker/src/platform-feedback/errors.tspackages/worker/src/platform-feedback/platform-feedback-service.node.test.tspackages/worker/src/platform-feedback/repo.tspackages/worker/src/platform-feedback/service.tspackages/worker/src/platform-feedback/types.ts
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 7d4069a. Configure here.
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>

Summary
meta_platform_feedback_submitcapability that requires explicit user confirmation from a trusted interactive MCP originTesting
npm run validatepasses: formatting, lint, typecheck, primitive map, 881 unit tests, 15 Playwright E2E tests, and 2 MCP E2E tests./privacywalkthrough passes with all disclosures visible and no browser-console errors.Walkthrough
System recap — adds a new primitive (high risk)
Mode: recap · Base:
main@edf1e251· Head:fb7cb747Classification: adds — introduces the
platform-feedbackprimitive, a consent-gated cross-user review boundary with new D1 persistence, admin capabilities, abuse controls, and retention behavior.Primitives touched
platform-feedbackd1-app-dbcapability-registrymcp-serverrbacaccount-exportscheduled-cronapp-uiSystem map
Approved feedback flows from an authenticated interactive MCP origin through consent and atomic limits into D1; admins cross only through audited role gates, while revision checks, account lifecycle, and retention preserve integrity.
Legend: green = composes (wiring only) · amber = extended by this PR · red = new primitive · gray = context (unchanged, included only when an edge crosses it).
Change flow
Invariants
user_confirmed: trueis accepted only for the submission the user explicitly approved.Summary by CodeRabbit