Skip to content

feat(core): Share CLI and MCP authentication protocol - #1421

Open
BYK wants to merge 3 commits into
mainfrom
feat/toolkit-core-api-auth
Open

BYK wants to merge 3 commits into
mainfrom
feat/toolkit-core-api-auth

Conversation

@BYK

@BYK BYK commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

  • Add a private toolkit-core workspace package for bearer-token validation and OAuth device-grant form bodies.
  • Use the same token normalization in CLI and MCP API requests; reject malformed MCP credentials before any request without including the credential in errors.
  • Keep host trust, credential storage, transport, response validation, and product-specific errors with each product.

Validation

  • Root typecheck and lint; CLI Biome lint and dependency policy; generated definitions and docs checks.
  • CLI: 490 files, 10,408 passed, 13 skipped. MCP core: 128 files passed, 1 skipped; 1,753 passed, 6 skipped. MCP server: 83 passed. MCP test client: 80 passed. Cloudflare: 431 passed. Shared package: 3 passed. The combined test command hit its 10-minute limit after CLI completed; remaining packages passed separately.
  • CLI npm bundle and MCP server builds pass with the shared source bundled in both.

Dependency

Includes the two pending commits from #1415 so generated CLI skill versions match the current development version. The authentication change is the final commit. The diff against main will narrow to that commit after #1415 merges.

BYK and others added 3 commits October 5, 2026 23:13
Co-Authored-By: GPT-6 Sol <agent@openai.com>
Update tracked skill frontmatter in Craft's post-release version bump without depending on the ignored API schema or a network fetch. Exercise the real script with isolated npm and git stubs to prove the files change before the commit.

Co-Authored-By: GPT-6 Sol <agent@openai.com>
Co-Authored-By: GPT-6 Sol <agent@openai.com>
@github-actions github-actions Bot added the risk: medium PR risk score: medium label Oct 5, 2026
mr-danya pushed a commit to mr-danya/sentry-mcp that referenced this pull request Oct 6, 2026
)

I opened a PR that is using the new CLI instead of the old
`@sentry/cli@2`:
getsentry/sentry-javascript#23398

Some E2E tests failed with `TypeError: Bun.serve is not a function`,
because we actually check internally if `Bun` would be an option. With
that polyfill in this CLI this behavior is now forced, without Bun
actually being there. Idk why this actually exists, but exporting `Bun`
instead fixes it.

---

AI description:

The Node polyfills were installed with `globalThis.Bun = BunPolyfill`,
which broke consumers of the npm package in both directions.

Under Bun the global is readonly, so merely importing the package threw
"Attempted to assign to readonly property" and took the whole process
down. Under Node it left an object named `Bun` on the global, so
unrelated libraries that feature-detect `typeof Bun !== "undefined"`
took their Bun code path and called methods the polyfill does not
implement, failing with errors like "Bun.serve is not a function". Both
are reachable by anyone who merely depends on this package, since
importing it is enough.

The polyfills are already delivered through esbuild's `inject`, which
substitutes unbound identifiers with exported bindings, so exporting
`Bun` gives the bundle the same value lexically without touching the
global. The real Bun is preferred when present, so running under Bun
keeps the genuine implementation rather than shadowing it.

Verified by importing the built bundle in Node: `globalThis.Bun` stays
undefined, where it previously became an object whose `serve` and
`version` were missing.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
mr-danya pushed a commit to mr-danya/sentry-mcp that referenced this pull request Oct 6, 2026
)

I opened a PR that is using the new CLI instead of the old
`@sentry/cli@2`:
getsentry/sentry-javascript#23398

Some E2E tests failed with `TypeError: Bun.serve is not a function`,
because we actually check internally if `Bun` would be an option. With
that polyfill in this CLI this behavior is now forced, without Bun
actually being there. Idk why this actually exists, but exporting `Bun`
instead fixes it.

---

AI description:

The Node polyfills were installed with `globalThis.Bun = BunPolyfill`,
which broke consumers of the npm package in both directions.

Under Bun the global is readonly, so merely importing the package threw
"Attempted to assign to readonly property" and took the whole process
down. Under Node it left an object named `Bun` on the global, so
unrelated libraries that feature-detect `typeof Bun !== "undefined"`
took their Bun code path and called methods the polyfill does not
implement, failing with errors like "Bun.serve is not a function". Both
are reachable by anyone who merely depends on this package, since
importing it is enough.

The polyfills are already delivered through esbuild's `inject`, which
substitutes unbound identifiers with exported bindings, so exporting
`Bun` gives the bundle the same value lexically without touching the
global. The real Bun is preferred when present, so running under Bun
keeps the genuine implementation rather than shadowing it.

Verified by importing the built bundle in Node: `globalThis.Bun` stays
undefined, where it previously became an object whose `serve` and
`version` were missing.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
mr-danya pushed a commit to mr-danya/sentry-mcp that referenced this pull request Oct 6, 2026
)

I opened a PR that is using the new CLI instead of the old
`@sentry/cli@2`:
getsentry/sentry-javascript#23398

Some E2E tests failed with `TypeError: Bun.serve is not a function`,
because we actually check internally if `Bun` would be an option. With
that polyfill in this CLI this behavior is now forced, without Bun
actually being there. Idk why this actually exists, but exporting `Bun`
instead fixes it.

---

AI description:

The Node polyfills were installed with `globalThis.Bun = BunPolyfill`,
which broke consumers of the npm package in both directions.

Under Bun the global is readonly, so merely importing the package threw
"Attempted to assign to readonly property" and took the whole process
down. Under Node it left an object named `Bun` on the global, so
unrelated libraries that feature-detect `typeof Bun !== "undefined"`
took their Bun code path and called methods the polyfill does not
implement, failing with errors like "Bun.serve is not a function". Both
are reachable by anyone who merely depends on this package, since
importing it is enough.

The polyfills are already delivered through esbuild's `inject`, which
substitutes unbound identifiers with exported bindings, so exporting
`Bun` gives the bundle the same value lexically without touching the
global. The real Bun is preferred when present, so running under Bun
keeps the genuine implementation rather than shadowing it.

Verified by importing the built bundle in Node: `globalThis.Bun` stays
undefined, where it previously became an object whose `serve` and
`version` were missing.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk: medium PR risk score: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant