Skip to content

fix(local-execute): always load gateway-fetch shim for secret placeholders - #24

Merged
kody-bot merged 1 commit into
mainfrom
cursor/fix-local-execute-secret-placeholder-a937
Oct 9, 2026
Merged

kody-bot merged 1 commit into
mainfrom
cursor/fix-local-execute-secret-placeholder-a937

Conversation

@kody-bot

@kody-bot kody-bot commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Intent

Match kentcdodds/kody#3020: ad-hoc execute --local scripts with no kody:@ imports must still load the origin gateway-fetch shim so {{secret:…}} placeholders expand (or fail closed) instead of leaving workerd raw.

Summary

  • Always call POST /v1/local-execute/package-graph (remove the empty-imports early return).
  • Side-effect import .__kody_virtual__/runtime.js from the local workerd entry when origin returns it.
  • Regression tests for no-import package-graph fetch + Bearer secret placeholder wiring.

Companion platform PR: closes the early return in local-execute-package-graph.ts (kentcdodds/kody#3020).

Testing

  • npm test (146 passed)
  • npm run typecheck

…lders

Always call package-graph (even with no kody:@ imports) and side-effect import the origin-supplied .__kody_virtual__/runtime.js shim before user code so ambient Bearer {{secret:…}} fetch hops through gatewayFetch instead of leaving workerd raw (kentcdodds/kody#3020).
@kody-bot
kody-bot merged commit ea88b58 into main Oct 9, 2026
5 checks passed
@kody-bot
kody-bot deleted the cursor/fix-local-execute-secret-placeholder-a937 branch October 9, 2026 15:23
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.11.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant