Skip to content

fix: correct CloudFlow headers, Ava errors, and guidance - #332

Merged
dmitrijs-pavlovs-dev merged 6 commits into
mainfrom
fix/cloudflow-ava-guidance
Oct 6, 2026
Merged

dmitrijs-pavlovs-dev merged 6 commits into
mainfrom
fix/cloudflow-ava-guidance

Conversation

@dmitrijs-pavlovs-dev

@dmitrijs-pavlovs-dev dmitrijs-pavlovs-dev commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

CloudFlow connection creates failed because they omitted Idempotency-Key, and updates failed because they omitted If-Match. Creates now require a caller-owned idempotencyKey that survives retries; updates require the connection's observed ETag and reject wildcard preconditions. Header arguments are excluded from request bodies. Collaborator replacements must retain exactly one owner; empty, ownerless, and multiple-owner lists are rejected locally.

Ava HTTP-200 error envelopes now return MCP errors with bounded, sanitized detail. CloudFlow descriptions and guidance cover JavaScript/Python runtime differences, real draft execution, build/refine results, triggering, replacement fields, pagination, idempotency and tenant scope. Customer-search and confirmation descriptions match current behavior. The existing schema parity and pagination wording remain intact.

Guidance now identifies two backend limitations: ETag checking is separate from writing, so simultaneous updates can still race; MCP tracking query parameters affect replay identity, so client/server version changes can conflict despite the same key/body. Callers should serialize updates, verify saved state, and avoid automatic retries when HTTP errors contain only generic text.

Before/after validation compared the isolated pre-change build (15b6b1c) with the feature build (30b213b) against the same real development API:

Operation Pre-change Feature
Connection create, equivalent business body 400 idempotency_key_required; missing header 201; caller Idempotency-Key forwarded
Same connection update, equivalent business changes 428 precondition_required; missing header 200; observed If-Match forwarded and saved state verified
Ephemeral Ava success 200 / MCP success 200 / MCP success
Controlled HTTP-200 Ava error envelope Incorrect MCP success, injected credential/stack exposed MCP error, credential/stack redacted

The connection defects were reproduced and fixed in real dev calls. Ava's error-envelope comparison used a controlled response; the successful Ava calls were live compatibility checks. Cleanup deleted the disposable connection (204), verified absence (404), and left zero test resources. No workflows were executed or production resources modified.

Merged current main (0d2f856) and resolved the generated-tool override conflict, preserving both upstream read-only lookup semantics and this PR's CloudFlow guidance. The combined tree passed the validation below. Live evidence refers to the builds recorded in the before/after table.

Validation:

  • 1,218 unit tests and 284 integration tests pass, including all 106 schema-parity tests.
  • yarn check:dev, yarn check:ci, and yarn build pass.
  • Built-binary MCP fixtures cover owner-preserving collaborator replacement, rejection of empty replacements, create replay/body conflicts, in-progress retries, stale ETags, generated dry-runs, context propagation and Ava errors.
  • Live development calls through the built MCP server verified disabled connection creation (201), identical replay (201), changed-body conflict (422), observed/weak ETag updates (200), stale ETag rejection (412), owner-preserving replacement, local owner validation, and an ephemeral Ava success (200). The disposable connection was deleted (204) and absence verified (404); zero test resources remain.
  • Earlier production read-only calls verified account validation, bounded lists, template lookup and cursor pagination. No production writes or workflow execution occurred. Forced Ava error envelopes remain fixture-covered; hosted OAuth, simultaneous ETag writes, and cross-version replay were not exercised live.

Shared HTTP-error propagation and hosted top-level error preservation are handled by #325. Atomic version enforcement and telemetry exclusion from replay identity require backend changes. Arbitrary generated trigger-payload support remains a separate dependency.

Comment thread src/tools/cloudflow.ts Outdated
Comment thread src/tools/cloudflow.ts
Comment thread src/tools/ava.ts
Comment thread src/tools/cloudflow.ts
Comment thread src/tools/cloudflow.ts Outdated
@dmitrijs-pavlovs-dev dmitrijs-pavlovs-dev self-assigned this Oct 6, 2026
@dmitrijs-pavlovs-dev
dmitrijs-pavlovs-dev merged commit ae57b68 into main Oct 6, 2026
5 checks passed
@dmitrijs-pavlovs-dev
dmitrijs-pavlovs-dev deleted the fix/cloudflow-ava-guidance branch October 6, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants