Skip to content

Upgrade Cloudflare OAuth provider to 0.8.2 - #843

Merged
kody-bot merged 1 commit into
mainfrom
cursor/legacy-oauth-provider
Jul 22, 2026
Merged

kody-bot merged 1 commit into
mainfrom
cursor/legacy-oauth-provider

Conversation

@kody-bot

Copy link
Copy Markdown
Collaborator

Summary

  • Upgrade @cloudflare/workers-oauth-provider 0.4.0 β†’ 0.8.2
  • Adopt finite refresh-token (30d) and dynamic-client-registration (90d) defaults and purge expired OAuth KV data on scheduled runs
  • Preserve structured OAuth responses without duplicate warning logs
  • Update OAuth helper mocks and malformed-client coverage for the 0.8 auth-code shape

Auth-affecting changes reviewed

  • 0.5: finite refresh/client-registration TTL defaults, cascading client deletion, purgeExpiredData
  • 0.6: structured OAuthError responses
  • 0.7: token-exchange grantId and stricter DCR URI validation
  • 0.8: client-registration callbacks, revocation ownership checks, auth-code validation ordering
  • 0.8.1: minimum 60-second access-token TTL
  • 0.8.2: optional EMA resource claim fallback

Kody uses the defaults and does not opt into EMA. Stable-account grant identity from #840 remains unchanged.

Validation

  • focused OAuth/MCP tests β€” 21 pass
  • typecheck β€” pass
  • pre-push unit + Playwright E2E (17) β€” pass
System recap β€” extends an existing primitive (medium risk)

Mode: recap Β· Base: main @ 50ccd2f6 Β· Head: e1e3d4c9

Classification: extends β€” OAuth token/client lifetimes and cleanup behavior change under the current provider.

Primitives touched

Primitive Group Impact
scheduled-cron surfaces extends β€” purges expired OAuth grants/tokens

System map

MCP OAuth continues through the worker provider; scheduled cleanup removes expired KV state introduced by finite TTLs.

Legend: green = composes (wiring only) Β· amber = extended by this PR Β· red = new primitive Β· gray = context (unchanged, included only when an edge crosses it).

flowchart LR
  oauth["MCP OAuth provider<br/>0.8.2"]:::extended
  cron["scheduled-cron<br/>Scheduled handler"]:::extended
  oauthKv["OAuth KV<br/>grant/token state"]:::untouched
  oauth -->|"issue finite refresh/client records"| oauthKv
  cron -->|"purgeExpiredData"| oauthKv
  classDef touched fill:#1a7f37,color:#fff
  classDef extended fill:#9a6700,color:#fff
  classDef added fill:#cf222e,color:#fff
  classDef untouched fill:#57606a,color:#fff
Loading

Invariants

Grant props still resolve stable per-user identity; no cross-user lookup path changes.

Adopt finite OAuth KV TTLs and scheduled purge, silence default onError
console warnings, and keep malformed-client token exception coverage
working under stricter auth-code validation.
@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@kody-bot, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 14 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
βš™οΈ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: cb2cd047-ef21-4ca1-8dfd-4d51d05a7282

πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between 50ccd2f and e1e3d4c.

β›” Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
πŸ“’ Files selected for processing (4)
  • packages/worker/package.json
  • packages/worker/src/index.ts
  • packages/worker/src/mcp-auth.workers.test.ts
  • packages/worker/src/oauth-handlers.workers.test.ts
✨ Finishing Touches
πŸ§ͺ Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/legacy-oauth-provider

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❀️ Share

Comment @coderabbitai help to get the list of available commands.

@kody-bot
kody-bot marked this pull request as ready for review July 22, 2026 02:20
@github-actions

Copy link
Copy Markdown
Contributor

πŸ”Ž Preview deployed: https://kody-pr-843.kody-a99.workers.dev

Worker: kody-pr-843
D1: kody-pr-843-db
KV: kody-pr-843-oauth-kv

Mocks:

@kody-bot
kody-bot merged commit 7aa0584 into main Jul 22, 2026
7 checks passed
@kody-bot
kody-bot deleted the cursor/legacy-oauth-provider branch July 22, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants