Skip to content

test(client): cover delegated MCP thread ids in signed relay URLs - #17790

Open
Mnigos wants to merge 1 commit into
pingdotgg:mainfrom
Mnigos:relay-signed-url-tests-followup
Open

Mnigos wants to merge 1 commit into
pingdotgg:mainfrom
Mnigos:relay-signed-url-tests-followup

Conversation

@Mnigos

@Mnigos Mnigos commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Context

#15813 (#15813) was closed in favor of #17599 (#17599), with the note: "If there's test coverage here that #17599 doesn't have, a small follow-up PR adding it is welcome." Since then #17602 (#17602) builds the signed URL from the HttpApi contract. That covers most of what #15813 tested. One thread id shape is still untested.

Threads that OAuth MCP clients delegate get ids like thread:mcp:client%3A<session>:<request>:0, because the server URI-encodes the client:<session> namespace into the id. The id itself contains a %. The current test only uses mcp:<uuid> and checks that the path contains /mcp%3A. Nothing checks that a % in the id goes out as %25, so the server decodes it back to the same id, or that the proof signs that URL.

Change

  • The MCP thread id test in environmentHttpAuth.test.ts now runs each thread loader (snapshot, bounded snapshot, history) for both id shapes: mcp:<uuid> and a delegated thread:mcp:client%3A… id.
  • It checks the exact request path (…/threads/thread%3Amcp%3Aclient%253Asession-1%3Arequest-1%3A0/bounded and so on) instead of a substring, and still checks that the proof signs the URL that was sent.

Verification

Check Result
vp test run src/state/environmentHttpAuth.test.ts (client-runtime) 41 passed (3 to 6 MCP thread cases)
vp run typecheck (client-runtime) passes
vp fmt --check / vp lint on the test file clean

Test-only change, no UI, so no screenshots.

Implemented with Claude Opus 5.5, coordinated by Claude Fable 5.1 in Claude Code.

Threads that OAuth MCP clients delegate get ids like
thread:mcp:client%3A<session>:<request>:0, so the id itself carries a "%".
The thread snapshot, bounded snapshot and history requests must send that
"%" as %25 and sign the same URL. Run the MCP thread id test over both id
shapes and assert the exact request path instead of a substring.
@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Oct 10, 2026
macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 10, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 4489991

Macroscope's review found this PR approvable — This is a narrowly scoped, test-only coverage expansion confined to an ignored path, with no production behavior, product-default, or static-analysis configuration changes. Its impact is limited to validating delegated MCP thread ID encoding and signed URL requests in the test harness.

Notes:

  • Diff unchanged. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ff272edd-dc20-4658-9c1b-ab6a33b30758

📥 Commits

Reviewing files that changed from the base of the PR and between c77a7b7 and 4489991.


📒 Files selected for processing (1)
  • packages/client-runtime/src/state/environmentHttpAuth.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.



📝 Walkthrough

Walkthrough

The HTTP auth test now checks URL encoding for two thread ID shapes across snapshot, bounded snapshot, and history requests. It also verifies that each DPoP proof signs the URL sent by its request.

Changes

Thread URL encoding tests

Layer / File(s) Summary
Thread request URL assertions
packages/client-runtime/src/state/environmentHttpAuth.test.ts
The test runs snapshot, bounded snapshot, and history loaders with an MCP thread ID and a delegated thread ID. It checks each expected pathname and confirms that the DPoP proof URL matches the sent URL.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: juliusmarminge


Merge Risk: ⚪ Minimal · up to 44899

The added coverage does not change runtime behavior, and no issue requiring a fix before merge was identified.

Pre-merge checks | Passed 3 | Failed 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check Warning The description explains the problem, change, and verification results. It does not provide the required Scope and approval section or clearly document explicit maintainer approval or the applicable s… Add a Scope and approval section. Link the relevant issue or discussion, include the explicit maintainer approval comment, or explain why this focused test-only change qualifies as an obvious bug fix without prior approval.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check Passed The title clearly identifies the test change and the delegated MCP thread ID behavior it covers.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.

Full details: Description check

Explanation

The description explains the problem, change, and verification results. It does not provide the required Scope and approval section or clearly document explicit maintainer approval or the applicable small-fix exemption.


  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 11, 2026 — with ChatGPT Codex Connector
@macroscopeapp
macroscopeapp Bot dismissed their stale review October 11, 2026 07:05

Dismissing prior approval to re-evaluate 4489991

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants