Skip to content

fix(search): recheck Zoom approval and bound MCP serialization - #8496

Merged
waleedlatif1 merged 3 commits into
stagingfrom
codex/search-review-hardening
Oct 1, 2026
Merged

waleedlatif1 merged 3 commits into
stagingfrom
codex/search-review-hardening

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Recheck Zoom rollout after acquiring the accounts lock when approving an existing sign-in server, so a disabled rollout cannot persist an approval from stale preparation.
  • Count escaped JSON bytes iteratively for managed Search MCP responses, rejecting overflow without serialization or copying and preserving the existing byte-only admission policy.
  • Document the default-off Zoom fallback and clarify that it applies to eligible organization-owned scopes.

Type of Change

  • Bug fix

Testing

  • 327 provider, parser, approval and availability regression tests, including byte-small wide and deeply nested MCP responses.
  • 34 real Postgres/Redis integration checks; the approval race fails before the fix and leaves persisted state unchanged afterward.
  • 59 synthetic loopback HTTP/MCP checks across Zoom and Lucid (not live provider-account acceptance).
  • Independent guard removals fail their corresponding regressions; restored sources pass. A 1,000-value serialization oracle also passes 5,000 byte-limit checks.
  • App type-check, lint, full repository audits, committed generators, block-registry and docs-manifest checks.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 1, 2026 1:43am UTC

Request Review

@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Adds Zoom Search rollout gate and improves payload size checking.

The PR appears safe to merge; no outstanding finding or new actionable issue was identified.

Summary

The PR rechecks Zoom availability during source approval, replaces full MCP-result serialization with an iterative JSON byte check, and clarifies the default-off Zoom configuration.

  • The resolved prior finding is addressed: byte-small wide and deeply nested responses are no longer rejected by node or depth caps.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Prepare Zoom approval] --> B[Acquire accounts lock]
  B --> C[Recheck rollout]
  C -->|Enabled| D[Approve source]
  C -->|Disabled| E[Reject without persisting]
  F[MCP result] --> G[Count escaped JSON bytes]
  G -->|Within limit| H[Process result]
  G -->|Over limit| I[Reject response]
Loading

Reviews (3) · Last reviewed commit: "fix(search): reject inherited JSON seria..."

Comment thread apps/sim/lib/sim-search/live/managed-mcp-payload.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 6 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 8 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/core/utils/bounded-json.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 8 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit e1e8689 into staging Oct 1, 2026
24 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/search-review-hardening branch October 1, 2026 01:53

This branch was previously deployed

1 inactive deployment
Preview — 03bebe15 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant