Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

test: cover MCP validation short-circuits and registry fail-closed gates

open
Stack 2/2
#345 opened by cursor[bot]cursor/missing-test-coverage-6c42→main
Conversation0
cursor[bot]
Commits
0
Files changed…
opened this pull request
Author
· last week

Risky behavior now covered

  • MCP validation short-circuits — blank or whitespace-only names fail before lookup or spawn; unknown servers report not-found; missing / oauth_pending / error auth never hydrates or starts the server; a disabled layer reports not_active; overlapping validation emits busy; resolver exceptions are classified without spawn. Successful loads map tools (non-string descriptions dropped) and always close the client, including load_failed.
  • MCP registry fail-closed gates — a running agent cannot flip enableMcp; an unchanged flag is a no-op; persist failure keeps the in-session flag and reports internal_error; blank names, system toggles, and plugin toggles without metadata are validation_failed and write nothing; malformed workspace mcp-servers.json is ignored with a warning instead of loading servers.
  • Plugin lookup targeting — mcpServerLookupFromServer drops a blank pluginId so post-auth validation cannot target an empty plugin bucket.

Test files added/updated

  • test/session/mcp-validation-flow.test.ts
  • test/session/mcp-registry-flow.test.ts
  • test/session/mcp-server-lookup.test.ts
  • src/server/session/mcp/McpValidationFlow.ts (optional deps, same pattern as McpAuthFlow; default wiring unchanged)

Why these tests materially reduce regression risk

Validation is the user-initiated path that is allowed to start an otherwise untrusted workspace MCP server. A missed auth or not-found short-circuit can spawn stdio or open an outbound HTTP connection. Registry misclassification can persist a bad config or treat a schema error as an internal failure. Open coverage PRs #331–#344 do not cover these extracted helpers. Existing session tests only exercise concurrency and happy-path upsert.

Validation

  • Targeted 18 new tests + existing MCP auth/session suites + test/platform-boundary.test.ts: green
  • bun run check and bun run typecheck: clean
  • Isolated targeted files are the evidence for this run (full suite historically truncates late on this host)
Open in Web View Automation 
This branch can’t be merged automatically yet
Branch comparison failed — verify branches still exist in storage.
0 approving reviews
None yet
Checks
No checks recorded
Fast-forward
Source must contain the target branch tip
main ← cursor/missing-test-coverage-6c42

Sign in to comment.

Stack

2/2
1

Merge readiness

Checking mergeability after the indexing worker computes the current branch state.

Autopilot

Debug

Reviews

Approved0
ReviewersNone yet

Configure an OpenRouter key in repository settings.

Update README.md

#125 mobile-fixes ← main

Updated 4 months ago

merged
2

test: cover MCP validation short-circuits and registry fail-closed gates

#345 main ← cursor/missing-test-coverage-6c42

Updated last week

open