Skip to content

Assert the caller userId in the publish-note isolation test - #927

Merged
kody-bot merged 1 commit into
mainfrom
cursor/sentry-k1-kody-mcp-caller-errors-6045
Jul 24, 2026
Merged

kody-bot merged 1 commit into
mainfrom
cursor/sentry-k1-kody-mcp-caller-errors-6045

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Jul 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

Last review point from #925, which merged before I could fold it in. CodeRabbit was right and it is worth fixing rather than leaving.

The cross-user test for repo_show_publish_note asserted the scoped lookup like this:

expect(mockModule.getEntitySourceByIdForUser).toHaveBeenCalledWith(
	expect.anything(),
	expect.objectContaining({ id: 'source-1' }),
)

objectContaining only checks the keys it names, so the assertion would still have passed if userId were omitted entirely or passed with the wrong value β€” which is the single thing that test exists to verify. Now it asserts the exact argument:

expect(mockModule.getEntitySourceByIdForUser).toHaveBeenCalledWith(
	expect.anything(),
	{ id: 'source-1', userId: 'user-1' },
)

One line, test-only, no production change.

Validation

npm run validate green in full: format:check, lint (1 pre-existing warning in sentry-tunnel.node.test.ts, 0 errors), typecheck, 1295 unit tests across 400 files, 18 Playwright E2E, 2 MCP E2E, backup:build, primitives:check, migrations:check.

System recap β€” composes existing primitives (low risk)

Mode: recap Β· Base: main @ 36edd717 Β· Head: 5d8adab9

Classification: composes β€” test-only assertion tightening. No production code, no primitive behaviour change.

Primitives touched

Primitive Group Impact
capability-registry assistant composes β€” test coverage only

Invariants

Strengthens the guard on per-user isolation rather than changing it: the repo-source lookup test now fails if the userId predicate is dropped from the query call.

Open in WebΒ Open in CursorΒ 

Summary by CodeRabbit

  • Tests
    • Updated access-control test expectations to verify that source lookups include both the source identifier and requesting user identifier.

The assertion matched only the source id, so it would have passed with the
userId omitted or wrong, which is the one thing the test exists to check.
@coderabbitai

coderabbitai Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. πŸŽ‰

ℹ️ Recent review info
βš™οΈ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 5d7ee862-fb08-45a9-a53d-b851c8068aa7

πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between 36edd71 and 5d8adab.

πŸ“’ Files selected for processing (1)
  • packages/worker/src/mcp/capabilities/repo/repo-show-publish-note.node.test.ts

πŸ“ Walkthrough

Walkthrough

The cross-user access rejection test now asserts that getEntitySourceByIdForUser receives both the source ID and requesting user ID.

Changes

Repository access test

Layer / File(s) Summary
User-scoped lookup assertion
packages/worker/src/mcp/capabilities/repo/repo-show-publish-note.node.test.ts
The cross-user rejection test expects the source and requesting user identifiers in the lookup call.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

  • kentcdodds/kody#925: Updates the same test for user-scoped getEntitySourceByIdForUser arguments.
πŸš₯ Pre-merge checks | βœ… 5
βœ… Passed checks (5 passed)
Check name Status Explanation
Description Check βœ… Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check βœ… Passed The title clearly describes the main test-only change: asserting the caller userId in the publish-note isolation test.
Docstring Coverage βœ… Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check βœ… Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check βœ… Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
πŸ“ Generate docstrings
  • Create stacked PR
  • Commit on current branch
πŸ§ͺ Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/sentry-k1-kody-mcp-caller-errors-6045

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❀️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

πŸ”Ž Preview deployed: https://kody-pr-927.kody-a99.workers.dev

Worker: kody-pr-927
D1: kody-pr-927-db
KV: kody-pr-927-oauth-kv

Mocks:

@kody-bot
kody-bot merged commit 62af8eb into main Jul 24, 2026
5 checks passed
@kody-bot
kody-bot deleted the cursor/sentry-k1-kody-mcp-caller-errors-6045 branch July 24, 2026 22:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants