feat: implement simple mcp exposure application - #9

Open
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market
Open

feat: implement simple mcp exposure application#9
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market

Conversation

@tenequm

Copy link
Copy Markdown
Member

No description provided.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Dec 11, 2025

Copy link
Copy Markdown

Deploying splits with Cloudflare Pages Cloudflare Pages

Latest commit:a8007ad
Status: ✅ Deploy successful!
Preview URL:https://55038ce1.splits-2l5.pages.dev
Branch Preview URL:https://feat-cascade-market.splits-2l5.pages.dev

View logs

- Implement OAuth 2.0 authorization server with PKCE (RFC 6749, 8414)
- Add SIWS (Sign In With Solana) using native signIn or CAIP-122 fallback
- Add well-known endpoints for MCP SDK discovery (RFC 9728)
- Add rate limiting (60 req/min per IP) on MCP gateway
- Enhance payment verification with on-chain confirmation via Tabs
- Add auth_codes and refresh_tokens tables for OAuth state
- Configure for market.cascade.fyi deployment
Facilitator (apps/facilitator/):
- Implement x402 v2 facilitator at facilitator.cascade.fyi
- Support RFC #646 instruction layouts (3-6 instructions)
- Add CPI verification via simulation for smart wallets
- Add deadline validator and durable nonce support
- Include 46 tests (37 unit, 9 integration)
Gateway:
- Upgrade from Tabs v1 to x402 v2 protocol
- Add dynamic fee payer discovery from facilitator
- Construct proper PaymentRequirements with feePayer
Go CLI (packages/golang/cli/):
- Add tunnel client for connecting local MCPs to gateway
- Use urfave/cli/v3 with goreleaser for releases
- Support cross-platform single binary distribution
Also:
- Add explore, pay, splits, tabs routes to market app
- Fix Dashboard type guards for query functions
- Update ADR-0004 to reflect Go CLI implementation
- Rename ADR-0005 to cascade-market-base-support.md
- Import PaymentPayload, PaymentRequirements, Network from @x402/core/types
- Remove duplicate local type definitions
- Use Network branded type for proper type safety
Also adds Go CLI packaging files:
- Apache 2.0 LICENSE
- README with installation/usage docs
- .gitignore for build artifacts
…rification
Replace manual SIWS implementation with official library functions:
- Server stores full SolanaSignInInput in KV (not just nonce flag)
- Use verifySignIn() for complete field + signature validation
- Use createSignInMessageText() for fallback message construction
- Structured API contract with proper Uint8Array serialization
Tabs:
- Implement full smart account UI (was external redirect)
- Add SmartAccountPanel, TransactionHistory, DemoPanel components
- Add use-smart-account hook with SDK integration
- Add Helius API for transaction history
Splits:
- Use useWalletConnection() instead of SIWS auth
- Fix "wallet not connected" when wallet is connected
Refactor:
- Delete lib/squads.ts, use @cascade-fyi/tabs-sdk directly
- Add lib/constants.ts for USDC_MINT, EXECUTOR_PUBKEY
- Use usdc.toDecimalString() from utils for formatting
…MCP refactor
- Add Astro Starlight documentation app with ADRs, specifications, and benchmarks
- Add /api/echo/resource (x402 demo) and /api/settle (Tabs executor proxy) endpoints
- Refactor GitHub MCP example with proper client/types module separation
- Update Dashboard and Services page with improved flow
ADRs and benchmarks are now maintained in the Starlight docs site
under apps/docs/src/content/docs/. Remove duplicates from legacy
locations to avoid confusion.
Replace Go CLI with TypeScript implementation using @effect/cli.
Enables better integration with the monorepo toolchain and shared
types from splits-sdk.
P0 (blocking):
- Fix timing attack in token verification (crypto.subtle.timingSafeEqual)
- Remove hardcoded secret fallbacks in tunnel.ts and new.tsx
- Add MCP x402 transport (JSON-RPC body extraction for payments)
- Implement /sign endpoint for transaction signing
P1 (before launch):
- Add transaction validation in /sign using tabs-sdk
- Validate JSON-RPC response before settlement
- Implement refresh token rotation in OAuth
- Fix auth code race condition with atomic UPDATE...RETURNING
- Add secret validation middleware at startup
Also exports SPLIT_CONFIG_DISCRIMINATOR from splits-sdk for
getProgramAccounts filtering in service discovery.
Replace database-backed service registry with on-chain discovery
per ADR-0004 §4.7. Services are now identified by SplitConfig PDAs
with labels starting with @ (e.g., @cascade/twitter).
- Add splits.ts with discoverServices() and serviceExists()
- Update explore.tsx to use on-chain discovery
- Remove services.ts (database-backed registry)
- Simplify schema.sql (remove services table)
Adds --sourcemap for debugging and --no-compile-autoload-dotenv
to prevent automatic .env loading in compiled binaries.
Improve naming clarity for the Durable Object that bridges
Gateway HTTP requests to CLI WebSocket connections.
- Rename tunnel.ts → service-bridge.ts
- Rename class TunnelRelay → ServiceBridge
- Rename binding TUNNEL_RELAY → SERVICE_BRIDGE
- Update ADR-0004 references
- Fix WebSocket handler signatures (wasClean param, ArrayBuffer)
- Add pending request rejection on disconnect
Revert the class rename from c1a0039 while keeping the bug fixes
(WebSocket handler signatures, pending request rejection).
"Tunnel" is more familiar terminology to developers (like ngrok),
while "Bridge" is an internal implementation detail. The class name
TunnelRelay accurately describes what it does: relays MCP requests
through a WebSocket tunnel to supplier CLIs.
Changes:
- Rename service-bridge.ts → tunnel.ts
- Rename class ServiceBridge → TunnelRelay
- Rename binding SERVICE_BRIDGE → TUNNEL_RELAY
- Update gateway references and ADR-0004
- Clarify "CLI clients" → "supplier CLIs" in comments
Security fixes from review:
1. Transaction injection prevention (CRITICAL)
- Verify exactly 1 instruction in /sign endpoint
- Prevents malicious instruction injection attacks
2. Rate limiting for /sign endpoint (HIGH)
- 30 requests/minute per wallet using KV sliding window
- Prevents DoS attacks on signing endpoint
3. Optimize getProgramAccounts (MEDIUM)
- Add memcmp filter on "CSPL:@" prefix at offset 105
- Server-side filtering for marketplace services only
- Improves scalability as splits grow
4. SIWS session validation in OAuth (MEDIUM)
- Derive userAddress from verified session cookie
- Remove client-provided userAddress from input
- Prevents wallet address spoofing
5. OAuth client_id format validation (LOW)
- Validate format: lowercase alphanumeric + hyphens, 3-64 chars
- Prevents invalid client identifiers
Add OAuth login, status, serve (supplier tunnel), and MCP management:
- login: OAuth 2.0 + PKCE flow with local callback server
- status: Display wallet, Tabs account, and configured MCPs
- serve: WebSocket tunnel to Gateway for local MCP exposure
- mcp add/remove/proxy: Claude Code integration with x402 payments
Supporting libraries:
- auth: XDG credential storage with auto-refresh
- config: Claude Code settings.json manipulation
- tokens: Service token decoding for suppliers
- tunnel: WebSocket client with Cloudflare DO reconnection
- x402: Payment building via tabs-sdk
Also includes:
- Gateway audit logging for executor signing (W8)
- ADR-0004 update for Tabs PDA discovery pattern
Add /.well-known/oauth-authorization-server endpoint to enable
MCP clients to automatically discover OAuth endpoints. This improves
interoperability with OAuth 2.1 compliant clients.
Replace custom D1+JWT OAuth implementation with Cloudflare's
workers-oauth-provider library, eliminating D1 dependency entirely.
- Add HTML consent page with wallet-standard SIWS
- Use KV-backed opaque tokens with AES-GCM encryption
- Simplify gateway auth via OAuthProvider's ctx.props
- Update ADR-0004 to reflect new architecture
…n tx validation
x402 SVM clients v2.4+ append a Memo instruction for replay protection.
Wallet extensions (Phantom, Solflare) inject Lighthouse instructions.
Amend detectInstructionLayout to allow these trailing instructions after
the transfer, and skip them in fee payer safety checks.
Also bump @x402/core to ^2.5.0 and @coinbase/x402 to ^2.1.0.
Direct SPL TransferChecked is fully verified statically (layout,
amount, mint, destination ATA, fee payer safety). Simulation is only
needed for CPI transfers (smart wallets). This eliminates the Solana
RPC round-trip that was causing 17-79s verify latency.
- Replace custom signer with toFacilitatorSvmSigner from @x402/svm
- Keep custom simulateForCpi for RFC #646 CPI verification
- Rename worker to cascade-facilitator-old, domain to facilitator-old.cascade.fyi
- Add payload destructuring guards (fixes potential 500 on malformed requests)
- Remove unused @coinbase/x402 dependency
- Update market references to facilitator-old.cascade.fyi
Proxy-based RPC from @solana/kit fails the "getBalance" in rpc
property detection. Pass as explicit {[network]: rpc} map instead.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tenequm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: implement simple mcp exposure application - #9

Open
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market
Open

feat: implement simple mcp exposure application#9
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market

Conversation

@tenequm

Copy link
Copy Markdown
Member

No description provided.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Dec 11, 2025

Copy link
Copy Markdown

Deploying splits with Cloudflare Pages Cloudflare Pages

Latest commit:a8007ad
Status: ✅ Deploy successful!
Preview URL:https://55038ce1.splits-2l5.pages.dev
Branch Preview URL:https://feat-cascade-market.splits-2l5.pages.dev

View logs

- Implement OAuth 2.0 authorization server with PKCE (RFC 6749, 8414)
- Add SIWS (Sign In With Solana) using native signIn or CAIP-122 fallback
- Add well-known endpoints for MCP SDK discovery (RFC 9728)
- Add rate limiting (60 req/min per IP) on MCP gateway
- Enhance payment verification with on-chain confirmation via Tabs
- Add auth_codes and refresh_tokens tables for OAuth state
- Configure for market.cascade.fyi deployment
Facilitator (apps/facilitator/):
- Implement x402 v2 facilitator at facilitator.cascade.fyi
- Support RFC #646 instruction layouts (3-6 instructions)
- Add CPI verification via simulation for smart wallets
- Add deadline validator and durable nonce support
- Include 46 tests (37 unit, 9 integration)
Gateway:
- Upgrade from Tabs v1 to x402 v2 protocol
- Add dynamic fee payer discovery from facilitator
- Construct proper PaymentRequirements with feePayer
Go CLI (packages/golang/cli/):
- Add tunnel client for connecting local MCPs to gateway
- Use urfave/cli/v3 with goreleaser for releases
- Support cross-platform single binary distribution
Also:
- Add explore, pay, splits, tabs routes to market app
- Fix Dashboard type guards for query functions
- Update ADR-0004 to reflect Go CLI implementation
- Rename ADR-0005 to cascade-market-base-support.md
- Import PaymentPayload, PaymentRequirements, Network from @x402/core/types
- Remove duplicate local type definitions
- Use Network branded type for proper type safety
Also adds Go CLI packaging files:
- Apache 2.0 LICENSE
- README with installation/usage docs
- .gitignore for build artifacts
…rification
Replace manual SIWS implementation with official library functions:
- Server stores full SolanaSignInInput in KV (not just nonce flag)
- Use verifySignIn() for complete field + signature validation
- Use createSignInMessageText() for fallback message construction
- Structured API contract with proper Uint8Array serialization
Tabs:
- Implement full smart account UI (was external redirect)
- Add SmartAccountPanel, TransactionHistory, DemoPanel components
- Add use-smart-account hook with SDK integration
- Add Helius API for transaction history
Splits:
- Use useWalletConnection() instead of SIWS auth
- Fix "wallet not connected" when wallet is connected
Refactor:
- Delete lib/squads.ts, use @cascade-fyi/tabs-sdk directly
- Add lib/constants.ts for USDC_MINT, EXECUTOR_PUBKEY
- Use usdc.toDecimalString() from utils for formatting
…MCP refactor
- Add Astro Starlight documentation app with ADRs, specifications, and benchmarks
- Add /api/echo/resource (x402 demo) and /api/settle (Tabs executor proxy) endpoints
- Refactor GitHub MCP example with proper client/types module separation
- Update Dashboard and Services page with improved flow
ADRs and benchmarks are now maintained in the Starlight docs site
under apps/docs/src/content/docs/. Remove duplicates from legacy
locations to avoid confusion.
Replace Go CLI with TypeScript implementation using @effect/cli.
Enables better integration with the monorepo toolchain and shared
types from splits-sdk.
P0 (blocking):
- Fix timing attack in token verification (crypto.subtle.timingSafeEqual)
- Remove hardcoded secret fallbacks in tunnel.ts and new.tsx
- Add MCP x402 transport (JSON-RPC body extraction for payments)
- Implement /sign endpoint for transaction signing
P1 (before launch):
- Add transaction validation in /sign using tabs-sdk
- Validate JSON-RPC response before settlement
- Implement refresh token rotation in OAuth
- Fix auth code race condition with atomic UPDATE...RETURNING
- Add secret validation middleware at startup
Also exports SPLIT_CONFIG_DISCRIMINATOR from splits-sdk for
getProgramAccounts filtering in service discovery.
Replace database-backed service registry with on-chain discovery
per ADR-0004 §4.7. Services are now identified by SplitConfig PDAs
with labels starting with @ (e.g., @cascade/twitter).
- Add splits.ts with discoverServices() and serviceExists()
- Update explore.tsx to use on-chain discovery
- Remove services.ts (database-backed registry)
- Simplify schema.sql (remove services table)
Adds --sourcemap for debugging and --no-compile-autoload-dotenv
to prevent automatic .env loading in compiled binaries.
Improve naming clarity for the Durable Object that bridges
Gateway HTTP requests to CLI WebSocket connections.
- Rename tunnel.ts → service-bridge.ts
- Rename class TunnelRelay → ServiceBridge
- Rename binding TUNNEL_RELAY → SERVICE_BRIDGE
- Update ADR-0004 references
- Fix WebSocket handler signatures (wasClean param, ArrayBuffer)
- Add pending request rejection on disconnect
Revert the class rename from c1a0039 while keeping the bug fixes
(WebSocket handler signatures, pending request rejection).
"Tunnel" is more familiar terminology to developers (like ngrok),
while "Bridge" is an internal implementation detail. The class name
TunnelRelay accurately describes what it does: relays MCP requests
through a WebSocket tunnel to supplier CLIs.
Changes:
- Rename service-bridge.ts → tunnel.ts
- Rename class ServiceBridge → TunnelRelay
- Rename binding SERVICE_BRIDGE → TUNNEL_RELAY
- Update gateway references and ADR-0004
- Clarify "CLI clients" → "supplier CLIs" in comments
Security fixes from review:
1. Transaction injection prevention (CRITICAL)
- Verify exactly 1 instruction in /sign endpoint
- Prevents malicious instruction injection attacks
2. Rate limiting for /sign endpoint (HIGH)
- 30 requests/minute per wallet using KV sliding window
- Prevents DoS attacks on signing endpoint
3. Optimize getProgramAccounts (MEDIUM)
- Add memcmp filter on "CSPL:@" prefix at offset 105
- Server-side filtering for marketplace services only
- Improves scalability as splits grow
4. SIWS session validation in OAuth (MEDIUM)
- Derive userAddress from verified session cookie
- Remove client-provided userAddress from input
- Prevents wallet address spoofing
5. OAuth client_id format validation (LOW)
- Validate format: lowercase alphanumeric + hyphens, 3-64 chars
- Prevents invalid client identifiers
Add OAuth login, status, serve (supplier tunnel), and MCP management:
- login: OAuth 2.0 + PKCE flow with local callback server
- status: Display wallet, Tabs account, and configured MCPs
- serve: WebSocket tunnel to Gateway for local MCP exposure
- mcp add/remove/proxy: Claude Code integration with x402 payments
Supporting libraries:
- auth: XDG credential storage with auto-refresh
- config: Claude Code settings.json manipulation
- tokens: Service token decoding for suppliers
- tunnel: WebSocket client with Cloudflare DO reconnection
- x402: Payment building via tabs-sdk
Also includes:
- Gateway audit logging for executor signing (W8)
- ADR-0004 update for Tabs PDA discovery pattern
Add /.well-known/oauth-authorization-server endpoint to enable
MCP clients to automatically discover OAuth endpoints. This improves
interoperability with OAuth 2.1 compliant clients.
Replace custom D1+JWT OAuth implementation with Cloudflare's
workers-oauth-provider library, eliminating D1 dependency entirely.
- Add HTML consent page with wallet-standard SIWS
- Use KV-backed opaque tokens with AES-GCM encryption
- Simplify gateway auth via OAuthProvider's ctx.props
- Update ADR-0004 to reflect new architecture
…n tx validation
x402 SVM clients v2.4+ append a Memo instruction for replay protection.
Wallet extensions (Phantom, Solflare) inject Lighthouse instructions.
Amend detectInstructionLayout to allow these trailing instructions after
the transfer, and skip them in fee payer safety checks.
Also bump @x402/core to ^2.5.0 and @coinbase/x402 to ^2.1.0.
Direct SPL TransferChecked is fully verified statically (layout,
amount, mint, destination ATA, fee payer safety). Simulation is only
needed for CPI transfers (smart wallets). This eliminates the Solana
RPC round-trip that was causing 17-79s verify latency.
- Replace custom signer with toFacilitatorSvmSigner from @x402/svm
- Keep custom simulateForCpi for RFC #646 CPI verification
- Rename worker to cascade-facilitator-old, domain to facilitator-old.cascade.fyi
- Add payload destructuring guards (fixes potential 500 on malformed requests)
- Remove unused @coinbase/x402 dependency
- Update market references to facilitator-old.cascade.fyi
Proxy-based RPC from @solana/kit fails the "getBalance" in rpc
property detection. Pass as explicit {[network]: rpc} map instead.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tenequm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: implement simple mcp exposure application - #9

Open
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market
Open

feat: implement simple mcp exposure application#9
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market

Conversation

@tenequm

Copy link
Copy Markdown
Member

No description provided.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Dec 11, 2025

Copy link
Copy Markdown

Deploying splits with Cloudflare Pages Cloudflare Pages

Latest commit:a8007ad
Status: ✅ Deploy successful!
Preview URL:https://55038ce1.splits-2l5.pages.dev
Branch Preview URL:https://feat-cascade-market.splits-2l5.pages.dev

View logs

- Implement OAuth 2.0 authorization server with PKCE (RFC 6749, 8414)
- Add SIWS (Sign In With Solana) using native signIn or CAIP-122 fallback
- Add well-known endpoints for MCP SDK discovery (RFC 9728)
- Add rate limiting (60 req/min per IP) on MCP gateway
- Enhance payment verification with on-chain confirmation via Tabs
- Add auth_codes and refresh_tokens tables for OAuth state
- Configure for market.cascade.fyi deployment
Facilitator (apps/facilitator/):
- Implement x402 v2 facilitator at facilitator.cascade.fyi
- Support RFC #646 instruction layouts (3-6 instructions)
- Add CPI verification via simulation for smart wallets
- Add deadline validator and durable nonce support
- Include 46 tests (37 unit, 9 integration)
Gateway:
- Upgrade from Tabs v1 to x402 v2 protocol
- Add dynamic fee payer discovery from facilitator
- Construct proper PaymentRequirements with feePayer
Go CLI (packages/golang/cli/):
- Add tunnel client for connecting local MCPs to gateway
- Use urfave/cli/v3 with goreleaser for releases
- Support cross-platform single binary distribution
Also:
- Add explore, pay, splits, tabs routes to market app
- Fix Dashboard type guards for query functions
- Update ADR-0004 to reflect Go CLI implementation
- Rename ADR-0005 to cascade-market-base-support.md
- Import PaymentPayload, PaymentRequirements, Network from @x402/core/types
- Remove duplicate local type definitions
- Use Network branded type for proper type safety
Also adds Go CLI packaging files:
- Apache 2.0 LICENSE
- README with installation/usage docs
- .gitignore for build artifacts
…rification
Replace manual SIWS implementation with official library functions:
- Server stores full SolanaSignInInput in KV (not just nonce flag)
- Use verifySignIn() for complete field + signature validation
- Use createSignInMessageText() for fallback message construction
- Structured API contract with proper Uint8Array serialization
Tabs:
- Implement full smart account UI (was external redirect)
- Add SmartAccountPanel, TransactionHistory, DemoPanel components
- Add use-smart-account hook with SDK integration
- Add Helius API for transaction history
Splits:
- Use useWalletConnection() instead of SIWS auth
- Fix "wallet not connected" when wallet is connected
Refactor:
- Delete lib/squads.ts, use @cascade-fyi/tabs-sdk directly
- Add lib/constants.ts for USDC_MINT, EXECUTOR_PUBKEY
- Use usdc.toDecimalString() from utils for formatting
…MCP refactor
- Add Astro Starlight documentation app with ADRs, specifications, and benchmarks
- Add /api/echo/resource (x402 demo) and /api/settle (Tabs executor proxy) endpoints
- Refactor GitHub MCP example with proper client/types module separation
- Update Dashboard and Services page with improved flow
ADRs and benchmarks are now maintained in the Starlight docs site
under apps/docs/src/content/docs/. Remove duplicates from legacy
locations to avoid confusion.
Replace Go CLI with TypeScript implementation using @effect/cli.
Enables better integration with the monorepo toolchain and shared
types from splits-sdk.
P0 (blocking):
- Fix timing attack in token verification (crypto.subtle.timingSafeEqual)
- Remove hardcoded secret fallbacks in tunnel.ts and new.tsx
- Add MCP x402 transport (JSON-RPC body extraction for payments)
- Implement /sign endpoint for transaction signing
P1 (before launch):
- Add transaction validation in /sign using tabs-sdk
- Validate JSON-RPC response before settlement
- Implement refresh token rotation in OAuth
- Fix auth code race condition with atomic UPDATE...RETURNING
- Add secret validation middleware at startup
Also exports SPLIT_CONFIG_DISCRIMINATOR from splits-sdk for
getProgramAccounts filtering in service discovery.
Replace database-backed service registry with on-chain discovery
per ADR-0004 §4.7. Services are now identified by SplitConfig PDAs
with labels starting with @ (e.g., @cascade/twitter).
- Add splits.ts with discoverServices() and serviceExists()
- Update explore.tsx to use on-chain discovery
- Remove services.ts (database-backed registry)
- Simplify schema.sql (remove services table)
Adds --sourcemap for debugging and --no-compile-autoload-dotenv
to prevent automatic .env loading in compiled binaries.
Improve naming clarity for the Durable Object that bridges
Gateway HTTP requests to CLI WebSocket connections.
- Rename tunnel.ts → service-bridge.ts
- Rename class TunnelRelay → ServiceBridge
- Rename binding TUNNEL_RELAY → SERVICE_BRIDGE
- Update ADR-0004 references
- Fix WebSocket handler signatures (wasClean param, ArrayBuffer)
- Add pending request rejection on disconnect
Revert the class rename from c1a0039 while keeping the bug fixes
(WebSocket handler signatures, pending request rejection).
"Tunnel" is more familiar terminology to developers (like ngrok),
while "Bridge" is an internal implementation detail. The class name
TunnelRelay accurately describes what it does: relays MCP requests
through a WebSocket tunnel to supplier CLIs.
Changes:
- Rename service-bridge.ts → tunnel.ts
- Rename class ServiceBridge → TunnelRelay
- Rename binding SERVICE_BRIDGE → TUNNEL_RELAY
- Update gateway references and ADR-0004
- Clarify "CLI clients" → "supplier CLIs" in comments
Security fixes from review:
1. Transaction injection prevention (CRITICAL)
- Verify exactly 1 instruction in /sign endpoint
- Prevents malicious instruction injection attacks
2. Rate limiting for /sign endpoint (HIGH)
- 30 requests/minute per wallet using KV sliding window
- Prevents DoS attacks on signing endpoint
3. Optimize getProgramAccounts (MEDIUM)
- Add memcmp filter on "CSPL:@" prefix at offset 105
- Server-side filtering for marketplace services only
- Improves scalability as splits grow
4. SIWS session validation in OAuth (MEDIUM)
- Derive userAddress from verified session cookie
- Remove client-provided userAddress from input
- Prevents wallet address spoofing
5. OAuth client_id format validation (LOW)
- Validate format: lowercase alphanumeric + hyphens, 3-64 chars
- Prevents invalid client identifiers
Add OAuth login, status, serve (supplier tunnel), and MCP management:
- login: OAuth 2.0 + PKCE flow with local callback server
- status: Display wallet, Tabs account, and configured MCPs
- serve: WebSocket tunnel to Gateway for local MCP exposure
- mcp add/remove/proxy: Claude Code integration with x402 payments
Supporting libraries:
- auth: XDG credential storage with auto-refresh
- config: Claude Code settings.json manipulation
- tokens: Service token decoding for suppliers
- tunnel: WebSocket client with Cloudflare DO reconnection
- x402: Payment building via tabs-sdk
Also includes:
- Gateway audit logging for executor signing (W8)
- ADR-0004 update for Tabs PDA discovery pattern
Add /.well-known/oauth-authorization-server endpoint to enable
MCP clients to automatically discover OAuth endpoints. This improves
interoperability with OAuth 2.1 compliant clients.
Replace custom D1+JWT OAuth implementation with Cloudflare's
workers-oauth-provider library, eliminating D1 dependency entirely.
- Add HTML consent page with wallet-standard SIWS
- Use KV-backed opaque tokens with AES-GCM encryption
- Simplify gateway auth via OAuthProvider's ctx.props
- Update ADR-0004 to reflect new architecture
…n tx validation
x402 SVM clients v2.4+ append a Memo instruction for replay protection.
Wallet extensions (Phantom, Solflare) inject Lighthouse instructions.
Amend detectInstructionLayout to allow these trailing instructions after
the transfer, and skip them in fee payer safety checks.
Also bump @x402/core to ^2.5.0 and @coinbase/x402 to ^2.1.0.
Direct SPL TransferChecked is fully verified statically (layout,
amount, mint, destination ATA, fee payer safety). Simulation is only
needed for CPI transfers (smart wallets). This eliminates the Solana
RPC round-trip that was causing 17-79s verify latency.
- Replace custom signer with toFacilitatorSvmSigner from @x402/svm
- Keep custom simulateForCpi for RFC #646 CPI verification
- Rename worker to cascade-facilitator-old, domain to facilitator-old.cascade.fyi
- Add payload destructuring guards (fixes potential 500 on malformed requests)
- Remove unused @coinbase/x402 dependency
- Update market references to facilitator-old.cascade.fyi
Proxy-based RPC from @solana/kit fails the "getBalance" in rpc
property detection. Pass as explicit {[network]: rpc} map instead.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tenequm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: implement simple mcp exposure application - #9

Open
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market
Open

feat: implement simple mcp exposure application#9
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market

Conversation

@tenequm

Copy link
Copy Markdown
Member

No description provided.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Dec 11, 2025

Copy link
Copy Markdown

Deploying splits with Cloudflare Pages Cloudflare Pages

Latest commit:a8007ad
Status: ✅ Deploy successful!
Preview URL:https://55038ce1.splits-2l5.pages.dev
Branch Preview URL:https://feat-cascade-market.splits-2l5.pages.dev

View logs

- Implement OAuth 2.0 authorization server with PKCE (RFC 6749, 8414)
- Add SIWS (Sign In With Solana) using native signIn or CAIP-122 fallback
- Add well-known endpoints for MCP SDK discovery (RFC 9728)
- Add rate limiting (60 req/min per IP) on MCP gateway
- Enhance payment verification with on-chain confirmation via Tabs
- Add auth_codes and refresh_tokens tables for OAuth state
- Configure for market.cascade.fyi deployment
Facilitator (apps/facilitator/):
- Implement x402 v2 facilitator at facilitator.cascade.fyi
- Support RFC #646 instruction layouts (3-6 instructions)
- Add CPI verification via simulation for smart wallets
- Add deadline validator and durable nonce support
- Include 46 tests (37 unit, 9 integration)
Gateway:
- Upgrade from Tabs v1 to x402 v2 protocol
- Add dynamic fee payer discovery from facilitator
- Construct proper PaymentRequirements with feePayer
Go CLI (packages/golang/cli/):
- Add tunnel client for connecting local MCPs to gateway
- Use urfave/cli/v3 with goreleaser for releases
- Support cross-platform single binary distribution
Also:
- Add explore, pay, splits, tabs routes to market app
- Fix Dashboard type guards for query functions
- Update ADR-0004 to reflect Go CLI implementation
- Rename ADR-0005 to cascade-market-base-support.md
- Import PaymentPayload, PaymentRequirements, Network from @x402/core/types
- Remove duplicate local type definitions
- Use Network branded type for proper type safety
Also adds Go CLI packaging files:
- Apache 2.0 LICENSE
- README with installation/usage docs
- .gitignore for build artifacts
…rification
Replace manual SIWS implementation with official library functions:
- Server stores full SolanaSignInInput in KV (not just nonce flag)
- Use verifySignIn() for complete field + signature validation
- Use createSignInMessageText() for fallback message construction
- Structured API contract with proper Uint8Array serialization
Tabs:
- Implement full smart account UI (was external redirect)
- Add SmartAccountPanel, TransactionHistory, DemoPanel components
- Add use-smart-account hook with SDK integration
- Add Helius API for transaction history
Splits:
- Use useWalletConnection() instead of SIWS auth
- Fix "wallet not connected" when wallet is connected
Refactor:
- Delete lib/squads.ts, use @cascade-fyi/tabs-sdk directly
- Add lib/constants.ts for USDC_MINT, EXECUTOR_PUBKEY
- Use usdc.toDecimalString() from utils for formatting
…MCP refactor
- Add Astro Starlight documentation app with ADRs, specifications, and benchmarks
- Add /api/echo/resource (x402 demo) and /api/settle (Tabs executor proxy) endpoints
- Refactor GitHub MCP example with proper client/types module separation
- Update Dashboard and Services page with improved flow
ADRs and benchmarks are now maintained in the Starlight docs site
under apps/docs/src/content/docs/. Remove duplicates from legacy
locations to avoid confusion.
Replace Go CLI with TypeScript implementation using @effect/cli.
Enables better integration with the monorepo toolchain and shared
types from splits-sdk.
P0 (blocking):
- Fix timing attack in token verification (crypto.subtle.timingSafeEqual)
- Remove hardcoded secret fallbacks in tunnel.ts and new.tsx
- Add MCP x402 transport (JSON-RPC body extraction for payments)
- Implement /sign endpoint for transaction signing
P1 (before launch):
- Add transaction validation in /sign using tabs-sdk
- Validate JSON-RPC response before settlement
- Implement refresh token rotation in OAuth
- Fix auth code race condition with atomic UPDATE...RETURNING
- Add secret validation middleware at startup
Also exports SPLIT_CONFIG_DISCRIMINATOR from splits-sdk for
getProgramAccounts filtering in service discovery.
Replace database-backed service registry with on-chain discovery
per ADR-0004 §4.7. Services are now identified by SplitConfig PDAs
with labels starting with @ (e.g., @cascade/twitter).
- Add splits.ts with discoverServices() and serviceExists()
- Update explore.tsx to use on-chain discovery
- Remove services.ts (database-backed registry)
- Simplify schema.sql (remove services table)
Adds --sourcemap for debugging and --no-compile-autoload-dotenv
to prevent automatic .env loading in compiled binaries.
Improve naming clarity for the Durable Object that bridges
Gateway HTTP requests to CLI WebSocket connections.
- Rename tunnel.ts → service-bridge.ts
- Rename class TunnelRelay → ServiceBridge
- Rename binding TUNNEL_RELAY → SERVICE_BRIDGE
- Update ADR-0004 references
- Fix WebSocket handler signatures (wasClean param, ArrayBuffer)
- Add pending request rejection on disconnect
Revert the class rename from c1a0039 while keeping the bug fixes
(WebSocket handler signatures, pending request rejection).
"Tunnel" is more familiar terminology to developers (like ngrok),
while "Bridge" is an internal implementation detail. The class name
TunnelRelay accurately describes what it does: relays MCP requests
through a WebSocket tunnel to supplier CLIs.
Changes:
- Rename service-bridge.ts → tunnel.ts
- Rename class ServiceBridge → TunnelRelay
- Rename binding SERVICE_BRIDGE → TUNNEL_RELAY
- Update gateway references and ADR-0004
- Clarify "CLI clients" → "supplier CLIs" in comments
Security fixes from review:
1. Transaction injection prevention (CRITICAL)
- Verify exactly 1 instruction in /sign endpoint
- Prevents malicious instruction injection attacks
2. Rate limiting for /sign endpoint (HIGH)
- 30 requests/minute per wallet using KV sliding window
- Prevents DoS attacks on signing endpoint
3. Optimize getProgramAccounts (MEDIUM)
- Add memcmp filter on "CSPL:@" prefix at offset 105
- Server-side filtering for marketplace services only
- Improves scalability as splits grow
4. SIWS session validation in OAuth (MEDIUM)
- Derive userAddress from verified session cookie
- Remove client-provided userAddress from input
- Prevents wallet address spoofing
5. OAuth client_id format validation (LOW)
- Validate format: lowercase alphanumeric + hyphens, 3-64 chars
- Prevents invalid client identifiers
Add OAuth login, status, serve (supplier tunnel), and MCP management:
- login: OAuth 2.0 + PKCE flow with local callback server
- status: Display wallet, Tabs account, and configured MCPs
- serve: WebSocket tunnel to Gateway for local MCP exposure
- mcp add/remove/proxy: Claude Code integration with x402 payments
Supporting libraries:
- auth: XDG credential storage with auto-refresh
- config: Claude Code settings.json manipulation
- tokens: Service token decoding for suppliers
- tunnel: WebSocket client with Cloudflare DO reconnection
- x402: Payment building via tabs-sdk
Also includes:
- Gateway audit logging for executor signing (W8)
- ADR-0004 update for Tabs PDA discovery pattern
Add /.well-known/oauth-authorization-server endpoint to enable
MCP clients to automatically discover OAuth endpoints. This improves
interoperability with OAuth 2.1 compliant clients.
Replace custom D1+JWT OAuth implementation with Cloudflare's
workers-oauth-provider library, eliminating D1 dependency entirely.
- Add HTML consent page with wallet-standard SIWS
- Use KV-backed opaque tokens with AES-GCM encryption
- Simplify gateway auth via OAuthProvider's ctx.props
- Update ADR-0004 to reflect new architecture
…n tx validation
x402 SVM clients v2.4+ append a Memo instruction for replay protection.
Wallet extensions (Phantom, Solflare) inject Lighthouse instructions.
Amend detectInstructionLayout to allow these trailing instructions after
the transfer, and skip them in fee payer safety checks.
Also bump @x402/core to ^2.5.0 and @coinbase/x402 to ^2.1.0.
Direct SPL TransferChecked is fully verified statically (layout,
amount, mint, destination ATA, fee payer safety). Simulation is only
needed for CPI transfers (smart wallets). This eliminates the Solana
RPC round-trip that was causing 17-79s verify latency.
- Replace custom signer with toFacilitatorSvmSigner from @x402/svm
- Keep custom simulateForCpi for RFC #646 CPI verification
- Rename worker to cascade-facilitator-old, domain to facilitator-old.cascade.fyi
- Add payload destructuring guards (fixes potential 500 on malformed requests)
- Remove unused @coinbase/x402 dependency
- Update market references to facilitator-old.cascade.fyi
Proxy-based RPC from @solana/kit fails the "getBalance" in rpc
property detection. Pass as explicit {[network]: rpc} map instead.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tenequm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: implement simple mcp exposure application - #9

Open
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market
Open

feat: implement simple mcp exposure application#9
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market

Conversation

@tenequm

Copy link
Copy Markdown
Member

No description provided.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Dec 11, 2025

Copy link
Copy Markdown

Deploying splits with Cloudflare Pages Cloudflare Pages

Latest commit:a8007ad
Status: ✅ Deploy successful!
Preview URL:https://55038ce1.splits-2l5.pages.dev
Branch Preview URL:https://feat-cascade-market.splits-2l5.pages.dev

View logs

- Implement OAuth 2.0 authorization server with PKCE (RFC 6749, 8414)
- Add SIWS (Sign In With Solana) using native signIn or CAIP-122 fallback
- Add well-known endpoints for MCP SDK discovery (RFC 9728)
- Add rate limiting (60 req/min per IP) on MCP gateway
- Enhance payment verification with on-chain confirmation via Tabs
- Add auth_codes and refresh_tokens tables for OAuth state
- Configure for market.cascade.fyi deployment
Facilitator (apps/facilitator/):
- Implement x402 v2 facilitator at facilitator.cascade.fyi
- Support RFC #646 instruction layouts (3-6 instructions)
- Add CPI verification via simulation for smart wallets
- Add deadline validator and durable nonce support
- Include 46 tests (37 unit, 9 integration)
Gateway:
- Upgrade from Tabs v1 to x402 v2 protocol
- Add dynamic fee payer discovery from facilitator
- Construct proper PaymentRequirements with feePayer
Go CLI (packages/golang/cli/):
- Add tunnel client for connecting local MCPs to gateway
- Use urfave/cli/v3 with goreleaser for releases
- Support cross-platform single binary distribution
Also:
- Add explore, pay, splits, tabs routes to market app
- Fix Dashboard type guards for query functions
- Update ADR-0004 to reflect Go CLI implementation
- Rename ADR-0005 to cascade-market-base-support.md
- Import PaymentPayload, PaymentRequirements, Network from @x402/core/types
- Remove duplicate local type definitions
- Use Network branded type for proper type safety
Also adds Go CLI packaging files:
- Apache 2.0 LICENSE
- README with installation/usage docs
- .gitignore for build artifacts
…rification
Replace manual SIWS implementation with official library functions:
- Server stores full SolanaSignInInput in KV (not just nonce flag)
- Use verifySignIn() for complete field + signature validation
- Use createSignInMessageText() for fallback message construction
- Structured API contract with proper Uint8Array serialization
Tabs:
- Implement full smart account UI (was external redirect)
- Add SmartAccountPanel, TransactionHistory, DemoPanel components
- Add use-smart-account hook with SDK integration
- Add Helius API for transaction history
Splits:
- Use useWalletConnection() instead of SIWS auth
- Fix "wallet not connected" when wallet is connected
Refactor:
- Delete lib/squads.ts, use @cascade-fyi/tabs-sdk directly
- Add lib/constants.ts for USDC_MINT, EXECUTOR_PUBKEY
- Use usdc.toDecimalString() from utils for formatting
…MCP refactor
- Add Astro Starlight documentation app with ADRs, specifications, and benchmarks
- Add /api/echo/resource (x402 demo) and /api/settle (Tabs executor proxy) endpoints
- Refactor GitHub MCP example with proper client/types module separation
- Update Dashboard and Services page with improved flow
ADRs and benchmarks are now maintained in the Starlight docs site
under apps/docs/src/content/docs/. Remove duplicates from legacy
locations to avoid confusion.
Replace Go CLI with TypeScript implementation using @effect/cli.
Enables better integration with the monorepo toolchain and shared
types from splits-sdk.
P0 (blocking):
- Fix timing attack in token verification (crypto.subtle.timingSafeEqual)
- Remove hardcoded secret fallbacks in tunnel.ts and new.tsx
- Add MCP x402 transport (JSON-RPC body extraction for payments)
- Implement /sign endpoint for transaction signing
P1 (before launch):
- Add transaction validation in /sign using tabs-sdk
- Validate JSON-RPC response before settlement
- Implement refresh token rotation in OAuth
- Fix auth code race condition with atomic UPDATE...RETURNING
- Add secret validation middleware at startup
Also exports SPLIT_CONFIG_DISCRIMINATOR from splits-sdk for
getProgramAccounts filtering in service discovery.
Replace database-backed service registry with on-chain discovery
per ADR-0004 §4.7. Services are now identified by SplitConfig PDAs
with labels starting with @ (e.g., @cascade/twitter).
- Add splits.ts with discoverServices() and serviceExists()
- Update explore.tsx to use on-chain discovery
- Remove services.ts (database-backed registry)
- Simplify schema.sql (remove services table)
Adds --sourcemap for debugging and --no-compile-autoload-dotenv
to prevent automatic .env loading in compiled binaries.
Improve naming clarity for the Durable Object that bridges
Gateway HTTP requests to CLI WebSocket connections.
- Rename tunnel.ts → service-bridge.ts
- Rename class TunnelRelay → ServiceBridge
- Rename binding TUNNEL_RELAY → SERVICE_BRIDGE
- Update ADR-0004 references
- Fix WebSocket handler signatures (wasClean param, ArrayBuffer)
- Add pending request rejection on disconnect
Revert the class rename from c1a0039 while keeping the bug fixes
(WebSocket handler signatures, pending request rejection).
"Tunnel" is more familiar terminology to developers (like ngrok),
while "Bridge" is an internal implementation detail. The class name
TunnelRelay accurately describes what it does: relays MCP requests
through a WebSocket tunnel to supplier CLIs.
Changes:
- Rename service-bridge.ts → tunnel.ts
- Rename class ServiceBridge → TunnelRelay
- Rename binding SERVICE_BRIDGE → TUNNEL_RELAY
- Update gateway references and ADR-0004
- Clarify "CLI clients" → "supplier CLIs" in comments
Security fixes from review:
1. Transaction injection prevention (CRITICAL)
- Verify exactly 1 instruction in /sign endpoint
- Prevents malicious instruction injection attacks
2. Rate limiting for /sign endpoint (HIGH)
- 30 requests/minute per wallet using KV sliding window
- Prevents DoS attacks on signing endpoint
3. Optimize getProgramAccounts (MEDIUM)
- Add memcmp filter on "CSPL:@" prefix at offset 105
- Server-side filtering for marketplace services only
- Improves scalability as splits grow
4. SIWS session validation in OAuth (MEDIUM)
- Derive userAddress from verified session cookie
- Remove client-provided userAddress from input
- Prevents wallet address spoofing
5. OAuth client_id format validation (LOW)
- Validate format: lowercase alphanumeric + hyphens, 3-64 chars
- Prevents invalid client identifiers
Add OAuth login, status, serve (supplier tunnel), and MCP management:
- login: OAuth 2.0 + PKCE flow with local callback server
- status: Display wallet, Tabs account, and configured MCPs
- serve: WebSocket tunnel to Gateway for local MCP exposure
- mcp add/remove/proxy: Claude Code integration with x402 payments
Supporting libraries:
- auth: XDG credential storage with auto-refresh
- config: Claude Code settings.json manipulation
- tokens: Service token decoding for suppliers
- tunnel: WebSocket client with Cloudflare DO reconnection
- x402: Payment building via tabs-sdk
Also includes:
- Gateway audit logging for executor signing (W8)
- ADR-0004 update for Tabs PDA discovery pattern
Add /.well-known/oauth-authorization-server endpoint to enable
MCP clients to automatically discover OAuth endpoints. This improves
interoperability with OAuth 2.1 compliant clients.
Replace custom D1+JWT OAuth implementation with Cloudflare's
workers-oauth-provider library, eliminating D1 dependency entirely.
- Add HTML consent page with wallet-standard SIWS
- Use KV-backed opaque tokens with AES-GCM encryption
- Simplify gateway auth via OAuthProvider's ctx.props
- Update ADR-0004 to reflect new architecture
…n tx validation
x402 SVM clients v2.4+ append a Memo instruction for replay protection.
Wallet extensions (Phantom, Solflare) inject Lighthouse instructions.
Amend detectInstructionLayout to allow these trailing instructions after
the transfer, and skip them in fee payer safety checks.
Also bump @x402/core to ^2.5.0 and @coinbase/x402 to ^2.1.0.
Direct SPL TransferChecked is fully verified statically (layout,
amount, mint, destination ATA, fee payer safety). Simulation is only
needed for CPI transfers (smart wallets). This eliminates the Solana
RPC round-trip that was causing 17-79s verify latency.
- Replace custom signer with toFacilitatorSvmSigner from @x402/svm
- Keep custom simulateForCpi for RFC #646 CPI verification
- Rename worker to cascade-facilitator-old, domain to facilitator-old.cascade.fyi
- Add payload destructuring guards (fixes potential 500 on malformed requests)
- Remove unused @coinbase/x402 dependency
- Update market references to facilitator-old.cascade.fyi
Proxy-based RPC from @solana/kit fails the "getBalance" in rpc
property detection. Pass as explicit {[network]: rpc} map instead.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tenequm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: implement simple mcp exposure application - #9

Open
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market
Open

feat: implement simple mcp exposure application#9
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market

Conversation

@tenequm

Copy link
Copy Markdown
Member

No description provided.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Dec 11, 2025

Copy link
Copy Markdown

Deploying splits with Cloudflare Pages Cloudflare Pages

Latest commit:a8007ad
Status: ✅ Deploy successful!
Preview URL:https://55038ce1.splits-2l5.pages.dev
Branch Preview URL:https://feat-cascade-market.splits-2l5.pages.dev

View logs

- Implement OAuth 2.0 authorization server with PKCE (RFC 6749, 8414)
- Add SIWS (Sign In With Solana) using native signIn or CAIP-122 fallback
- Add well-known endpoints for MCP SDK discovery (RFC 9728)
- Add rate limiting (60 req/min per IP) on MCP gateway
- Enhance payment verification with on-chain confirmation via Tabs
- Add auth_codes and refresh_tokens tables for OAuth state
- Configure for market.cascade.fyi deployment
Facilitator (apps/facilitator/):
- Implement x402 v2 facilitator at facilitator.cascade.fyi
- Support RFC #646 instruction layouts (3-6 instructions)
- Add CPI verification via simulation for smart wallets
- Add deadline validator and durable nonce support
- Include 46 tests (37 unit, 9 integration)
Gateway:
- Upgrade from Tabs v1 to x402 v2 protocol
- Add dynamic fee payer discovery from facilitator
- Construct proper PaymentRequirements with feePayer
Go CLI (packages/golang/cli/):
- Add tunnel client for connecting local MCPs to gateway
- Use urfave/cli/v3 with goreleaser for releases
- Support cross-platform single binary distribution
Also:
- Add explore, pay, splits, tabs routes to market app
- Fix Dashboard type guards for query functions
- Update ADR-0004 to reflect Go CLI implementation
- Rename ADR-0005 to cascade-market-base-support.md
- Import PaymentPayload, PaymentRequirements, Network from @x402/core/types
- Remove duplicate local type definitions
- Use Network branded type for proper type safety
Also adds Go CLI packaging files:
- Apache 2.0 LICENSE
- README with installation/usage docs
- .gitignore for build artifacts
…rification
Replace manual SIWS implementation with official library functions:
- Server stores full SolanaSignInInput in KV (not just nonce flag)
- Use verifySignIn() for complete field + signature validation
- Use createSignInMessageText() for fallback message construction
- Structured API contract with proper Uint8Array serialization
Tabs:
- Implement full smart account UI (was external redirect)
- Add SmartAccountPanel, TransactionHistory, DemoPanel components
- Add use-smart-account hook with SDK integration
- Add Helius API for transaction history
Splits:
- Use useWalletConnection() instead of SIWS auth
- Fix "wallet not connected" when wallet is connected
Refactor:
- Delete lib/squads.ts, use @cascade-fyi/tabs-sdk directly
- Add lib/constants.ts for USDC_MINT, EXECUTOR_PUBKEY
- Use usdc.toDecimalString() from utils for formatting
…MCP refactor
- Add Astro Starlight documentation app with ADRs, specifications, and benchmarks
- Add /api/echo/resource (x402 demo) and /api/settle (Tabs executor proxy) endpoints
- Refactor GitHub MCP example with proper client/types module separation
- Update Dashboard and Services page with improved flow
ADRs and benchmarks are now maintained in the Starlight docs site
under apps/docs/src/content/docs/. Remove duplicates from legacy
locations to avoid confusion.
Replace Go CLI with TypeScript implementation using @effect/cli.
Enables better integration with the monorepo toolchain and shared
types from splits-sdk.
P0 (blocking):
- Fix timing attack in token verification (crypto.subtle.timingSafeEqual)
- Remove hardcoded secret fallbacks in tunnel.ts and new.tsx
- Add MCP x402 transport (JSON-RPC body extraction for payments)
- Implement /sign endpoint for transaction signing
P1 (before launch):
- Add transaction validation in /sign using tabs-sdk
- Validate JSON-RPC response before settlement
- Implement refresh token rotation in OAuth
- Fix auth code race condition with atomic UPDATE...RETURNING
- Add secret validation middleware at startup
Also exports SPLIT_CONFIG_DISCRIMINATOR from splits-sdk for
getProgramAccounts filtering in service discovery.
Replace database-backed service registry with on-chain discovery
per ADR-0004 §4.7. Services are now identified by SplitConfig PDAs
with labels starting with @ (e.g., @cascade/twitter).
- Add splits.ts with discoverServices() and serviceExists()
- Update explore.tsx to use on-chain discovery
- Remove services.ts (database-backed registry)
- Simplify schema.sql (remove services table)
Adds --sourcemap for debugging and --no-compile-autoload-dotenv
to prevent automatic .env loading in compiled binaries.
Improve naming clarity for the Durable Object that bridges
Gateway HTTP requests to CLI WebSocket connections.
- Rename tunnel.ts → service-bridge.ts
- Rename class TunnelRelay → ServiceBridge
- Rename binding TUNNEL_RELAY → SERVICE_BRIDGE
- Update ADR-0004 references
- Fix WebSocket handler signatures (wasClean param, ArrayBuffer)
- Add pending request rejection on disconnect
Revert the class rename from c1a0039 while keeping the bug fixes
(WebSocket handler signatures, pending request rejection).
"Tunnel" is more familiar terminology to developers (like ngrok),
while "Bridge" is an internal implementation detail. The class name
TunnelRelay accurately describes what it does: relays MCP requests
through a WebSocket tunnel to supplier CLIs.
Changes:
- Rename service-bridge.ts → tunnel.ts
- Rename class ServiceBridge → TunnelRelay
- Rename binding SERVICE_BRIDGE → TUNNEL_RELAY
- Update gateway references and ADR-0004
- Clarify "CLI clients" → "supplier CLIs" in comments
Security fixes from review:
1. Transaction injection prevention (CRITICAL)
- Verify exactly 1 instruction in /sign endpoint
- Prevents malicious instruction injection attacks
2. Rate limiting for /sign endpoint (HIGH)
- 30 requests/minute per wallet using KV sliding window
- Prevents DoS attacks on signing endpoint
3. Optimize getProgramAccounts (MEDIUM)
- Add memcmp filter on "CSPL:@" prefix at offset 105
- Server-side filtering for marketplace services only
- Improves scalability as splits grow
4. SIWS session validation in OAuth (MEDIUM)
- Derive userAddress from verified session cookie
- Remove client-provided userAddress from input
- Prevents wallet address spoofing
5. OAuth client_id format validation (LOW)
- Validate format: lowercase alphanumeric + hyphens, 3-64 chars
- Prevents invalid client identifiers
Add OAuth login, status, serve (supplier tunnel), and MCP management:
- login: OAuth 2.0 + PKCE flow with local callback server
- status: Display wallet, Tabs account, and configured MCPs
- serve: WebSocket tunnel to Gateway for local MCP exposure
- mcp add/remove/proxy: Claude Code integration with x402 payments
Supporting libraries:
- auth: XDG credential storage with auto-refresh
- config: Claude Code settings.json manipulation
- tokens: Service token decoding for suppliers
- tunnel: WebSocket client with Cloudflare DO reconnection
- x402: Payment building via tabs-sdk
Also includes:
- Gateway audit logging for executor signing (W8)
- ADR-0004 update for Tabs PDA discovery pattern
Add /.well-known/oauth-authorization-server endpoint to enable
MCP clients to automatically discover OAuth endpoints. This improves
interoperability with OAuth 2.1 compliant clients.
Replace custom D1+JWT OAuth implementation with Cloudflare's
workers-oauth-provider library, eliminating D1 dependency entirely.
- Add HTML consent page with wallet-standard SIWS
- Use KV-backed opaque tokens with AES-GCM encryption
- Simplify gateway auth via OAuthProvider's ctx.props
- Update ADR-0004 to reflect new architecture
…n tx validation
x402 SVM clients v2.4+ append a Memo instruction for replay protection.
Wallet extensions (Phantom, Solflare) inject Lighthouse instructions.
Amend detectInstructionLayout to allow these trailing instructions after
the transfer, and skip them in fee payer safety checks.
Also bump @x402/core to ^2.5.0 and @coinbase/x402 to ^2.1.0.
Direct SPL TransferChecked is fully verified statically (layout,
amount, mint, destination ATA, fee payer safety). Simulation is only
needed for CPI transfers (smart wallets). This eliminates the Solana
RPC round-trip that was causing 17-79s verify latency.
- Replace custom signer with toFacilitatorSvmSigner from @x402/svm
- Keep custom simulateForCpi for RFC #646 CPI verification
- Rename worker to cascade-facilitator-old, domain to facilitator-old.cascade.fyi
- Add payload destructuring guards (fixes potential 500 on malformed requests)
- Remove unused @coinbase/x402 dependency
- Update market references to facilitator-old.cascade.fyi
Proxy-based RPC from @solana/kit fails the "getBalance" in rpc
property detection. Pass as explicit {[network]: rpc} map instead.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tenequm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: implement simple mcp exposure application - #9

Open
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market
Open

feat: implement simple mcp exposure application#9
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market

Conversation

@tenequm

Copy link
Copy Markdown
Member

No description provided.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Dec 11, 2025

Copy link
Copy Markdown

Deploying splits with Cloudflare Pages Cloudflare Pages

Latest commit:a8007ad
Status: ✅ Deploy successful!
Preview URL:https://55038ce1.splits-2l5.pages.dev
Branch Preview URL:https://feat-cascade-market.splits-2l5.pages.dev

View logs

- Implement OAuth 2.0 authorization server with PKCE (RFC 6749, 8414)
- Add SIWS (Sign In With Solana) using native signIn or CAIP-122 fallback
- Add well-known endpoints for MCP SDK discovery (RFC 9728)
- Add rate limiting (60 req/min per IP) on MCP gateway
- Enhance payment verification with on-chain confirmation via Tabs
- Add auth_codes and refresh_tokens tables for OAuth state
- Configure for market.cascade.fyi deployment
Facilitator (apps/facilitator/):
- Implement x402 v2 facilitator at facilitator.cascade.fyi
- Support RFC #646 instruction layouts (3-6 instructions)
- Add CPI verification via simulation for smart wallets
- Add deadline validator and durable nonce support
- Include 46 tests (37 unit, 9 integration)
Gateway:
- Upgrade from Tabs v1 to x402 v2 protocol
- Add dynamic fee payer discovery from facilitator
- Construct proper PaymentRequirements with feePayer
Go CLI (packages/golang/cli/):
- Add tunnel client for connecting local MCPs to gateway
- Use urfave/cli/v3 with goreleaser for releases
- Support cross-platform single binary distribution
Also:
- Add explore, pay, splits, tabs routes to market app
- Fix Dashboard type guards for query functions
- Update ADR-0004 to reflect Go CLI implementation
- Rename ADR-0005 to cascade-market-base-support.md
- Import PaymentPayload, PaymentRequirements, Network from @x402/core/types
- Remove duplicate local type definitions
- Use Network branded type for proper type safety
Also adds Go CLI packaging files:
- Apache 2.0 LICENSE
- README with installation/usage docs
- .gitignore for build artifacts
…rification
Replace manual SIWS implementation with official library functions:
- Server stores full SolanaSignInInput in KV (not just nonce flag)
- Use verifySignIn() for complete field + signature validation
- Use createSignInMessageText() for fallback message construction
- Structured API contract with proper Uint8Array serialization
Tabs:
- Implement full smart account UI (was external redirect)
- Add SmartAccountPanel, TransactionHistory, DemoPanel components
- Add use-smart-account hook with SDK integration
- Add Helius API for transaction history
Splits:
- Use useWalletConnection() instead of SIWS auth
- Fix "wallet not connected" when wallet is connected
Refactor:
- Delete lib/squads.ts, use @cascade-fyi/tabs-sdk directly
- Add lib/constants.ts for USDC_MINT, EXECUTOR_PUBKEY
- Use usdc.toDecimalString() from utils for formatting
…MCP refactor
- Add Astro Starlight documentation app with ADRs, specifications, and benchmarks
- Add /api/echo/resource (x402 demo) and /api/settle (Tabs executor proxy) endpoints
- Refactor GitHub MCP example with proper client/types module separation
- Update Dashboard and Services page with improved flow
ADRs and benchmarks are now maintained in the Starlight docs site
under apps/docs/src/content/docs/. Remove duplicates from legacy
locations to avoid confusion.
Replace Go CLI with TypeScript implementation using @effect/cli.
Enables better integration with the monorepo toolchain and shared
types from splits-sdk.
P0 (blocking):
- Fix timing attack in token verification (crypto.subtle.timingSafeEqual)
- Remove hardcoded secret fallbacks in tunnel.ts and new.tsx
- Add MCP x402 transport (JSON-RPC body extraction for payments)
- Implement /sign endpoint for transaction signing
P1 (before launch):
- Add transaction validation in /sign using tabs-sdk
- Validate JSON-RPC response before settlement
- Implement refresh token rotation in OAuth
- Fix auth code race condition with atomic UPDATE...RETURNING
- Add secret validation middleware at startup
Also exports SPLIT_CONFIG_DISCRIMINATOR from splits-sdk for
getProgramAccounts filtering in service discovery.
Replace database-backed service registry with on-chain discovery
per ADR-0004 §4.7. Services are now identified by SplitConfig PDAs
with labels starting with @ (e.g., @cascade/twitter).
- Add splits.ts with discoverServices() and serviceExists()
- Update explore.tsx to use on-chain discovery
- Remove services.ts (database-backed registry)
- Simplify schema.sql (remove services table)
Adds --sourcemap for debugging and --no-compile-autoload-dotenv
to prevent automatic .env loading in compiled binaries.
Improve naming clarity for the Durable Object that bridges
Gateway HTTP requests to CLI WebSocket connections.
- Rename tunnel.ts → service-bridge.ts
- Rename class TunnelRelay → ServiceBridge
- Rename binding TUNNEL_RELAY → SERVICE_BRIDGE
- Update ADR-0004 references
- Fix WebSocket handler signatures (wasClean param, ArrayBuffer)
- Add pending request rejection on disconnect
Revert the class rename from c1a0039 while keeping the bug fixes
(WebSocket handler signatures, pending request rejection).
"Tunnel" is more familiar terminology to developers (like ngrok),
while "Bridge" is an internal implementation detail. The class name
TunnelRelay accurately describes what it does: relays MCP requests
through a WebSocket tunnel to supplier CLIs.
Changes:
- Rename service-bridge.ts → tunnel.ts
- Rename class ServiceBridge → TunnelRelay
- Rename binding SERVICE_BRIDGE → TUNNEL_RELAY
- Update gateway references and ADR-0004
- Clarify "CLI clients" → "supplier CLIs" in comments
Security fixes from review:
1. Transaction injection prevention (CRITICAL)
- Verify exactly 1 instruction in /sign endpoint
- Prevents malicious instruction injection attacks
2. Rate limiting for /sign endpoint (HIGH)
- 30 requests/minute per wallet using KV sliding window
- Prevents DoS attacks on signing endpoint
3. Optimize getProgramAccounts (MEDIUM)
- Add memcmp filter on "CSPL:@" prefix at offset 105
- Server-side filtering for marketplace services only
- Improves scalability as splits grow
4. SIWS session validation in OAuth (MEDIUM)
- Derive userAddress from verified session cookie
- Remove client-provided userAddress from input
- Prevents wallet address spoofing
5. OAuth client_id format validation (LOW)
- Validate format: lowercase alphanumeric + hyphens, 3-64 chars
- Prevents invalid client identifiers
Add OAuth login, status, serve (supplier tunnel), and MCP management:
- login: OAuth 2.0 + PKCE flow with local callback server
- status: Display wallet, Tabs account, and configured MCPs
- serve: WebSocket tunnel to Gateway for local MCP exposure
- mcp add/remove/proxy: Claude Code integration with x402 payments
Supporting libraries:
- auth: XDG credential storage with auto-refresh
- config: Claude Code settings.json manipulation
- tokens: Service token decoding for suppliers
- tunnel: WebSocket client with Cloudflare DO reconnection
- x402: Payment building via tabs-sdk
Also includes:
- Gateway audit logging for executor signing (W8)
- ADR-0004 update for Tabs PDA discovery pattern
Add /.well-known/oauth-authorization-server endpoint to enable
MCP clients to automatically discover OAuth endpoints. This improves
interoperability with OAuth 2.1 compliant clients.
Replace custom D1+JWT OAuth implementation with Cloudflare's
workers-oauth-provider library, eliminating D1 dependency entirely.
- Add HTML consent page with wallet-standard SIWS
- Use KV-backed opaque tokens with AES-GCM encryption
- Simplify gateway auth via OAuthProvider's ctx.props
- Update ADR-0004 to reflect new architecture
…n tx validation
x402 SVM clients v2.4+ append a Memo instruction for replay protection.
Wallet extensions (Phantom, Solflare) inject Lighthouse instructions.
Amend detectInstructionLayout to allow these trailing instructions after
the transfer, and skip them in fee payer safety checks.
Also bump @x402/core to ^2.5.0 and @coinbase/x402 to ^2.1.0.
Direct SPL TransferChecked is fully verified statically (layout,
amount, mint, destination ATA, fee payer safety). Simulation is only
needed for CPI transfers (smart wallets). This eliminates the Solana
RPC round-trip that was causing 17-79s verify latency.
- Replace custom signer with toFacilitatorSvmSigner from @x402/svm
- Keep custom simulateForCpi for RFC #646 CPI verification
- Rename worker to cascade-facilitator-old, domain to facilitator-old.cascade.fyi
- Add payload destructuring guards (fixes potential 500 on malformed requests)
- Remove unused @coinbase/x402 dependency
- Update market references to facilitator-old.cascade.fyi
Proxy-based RPC from @solana/kit fails the "getBalance" in rpc
property detection. Pass as explicit {[network]: rpc} map instead.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tenequm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: implement simple mcp exposure application - #9

Open
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market
Open

feat: implement simple mcp exposure application#9
tenequm wants to merge 34 commits into
mainfrom
feat/cascade-market

Conversation

@tenequm

Copy link
Copy Markdown
Member

No description provided.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Dec 11, 2025

Copy link
Copy Markdown

Deploying splits with Cloudflare Pages Cloudflare Pages

Latest commit:a8007ad
Status: ✅ Deploy successful!
Preview URL:https://55038ce1.splits-2l5.pages.dev
Branch Preview URL:https://feat-cascade-market.splits-2l5.pages.dev

View logs

- Implement OAuth 2.0 authorization server with PKCE (RFC 6749, 8414)
- Add SIWS (Sign In With Solana) using native signIn or CAIP-122 fallback
- Add well-known endpoints for MCP SDK discovery (RFC 9728)
- Add rate limiting (60 req/min per IP) on MCP gateway
- Enhance payment verification with on-chain confirmation via Tabs
- Add auth_codes and refresh_tokens tables for OAuth state
- Configure for market.cascade.fyi deployment
Facilitator (apps/facilitator/):
- Implement x402 v2 facilitator at facilitator.cascade.fyi
- Support RFC #646 instruction layouts (3-6 instructions)
- Add CPI verification via simulation for smart wallets
- Add deadline validator and durable nonce support
- Include 46 tests (37 unit, 9 integration)
Gateway:
- Upgrade from Tabs v1 to x402 v2 protocol
- Add dynamic fee payer discovery from facilitator
- Construct proper PaymentRequirements with feePayer
Go CLI (packages/golang/cli/):
- Add tunnel client for connecting local MCPs to gateway
- Use urfave/cli/v3 with goreleaser for releases
- Support cross-platform single binary distribution
Also:
- Add explore, pay, splits, tabs routes to market app
- Fix Dashboard type guards for query functions
- Update ADR-0004 to reflect Go CLI implementation
- Rename ADR-0005 to cascade-market-base-support.md
- Import PaymentPayload, PaymentRequirements, Network from @x402/core/types
- Remove duplicate local type definitions
- Use Network branded type for proper type safety
Also adds Go CLI packaging files:
- Apache 2.0 LICENSE
- README with installation/usage docs
- .gitignore for build artifacts
…rification
Replace manual SIWS implementation with official library functions:
- Server stores full SolanaSignInInput in KV (not just nonce flag)
- Use verifySignIn() for complete field + signature validation
- Use createSignInMessageText() for fallback message construction
- Structured API contract with proper Uint8Array serialization
Tabs:
- Implement full smart account UI (was external redirect)
- Add SmartAccountPanel, TransactionHistory, DemoPanel components
- Add use-smart-account hook with SDK integration
- Add Helius API for transaction history
Splits:
- Use useWalletConnection() instead of SIWS auth
- Fix "wallet not connected" when wallet is connected
Refactor:
- Delete lib/squads.ts, use @cascade-fyi/tabs-sdk directly
- Add lib/constants.ts for USDC_MINT, EXECUTOR_PUBKEY
- Use usdc.toDecimalString() from utils for formatting
…MCP refactor
- Add Astro Starlight documentation app with ADRs, specifications, and benchmarks
- Add /api/echo/resource (x402 demo) and /api/settle (Tabs executor proxy) endpoints
- Refactor GitHub MCP example with proper client/types module separation
- Update Dashboard and Services page with improved flow
ADRs and benchmarks are now maintained in the Starlight docs site
under apps/docs/src/content/docs/. Remove duplicates from legacy
locations to avoid confusion.
Replace Go CLI with TypeScript implementation using @effect/cli.
Enables better integration with the monorepo toolchain and shared
types from splits-sdk.
P0 (blocking):
- Fix timing attack in token verification (crypto.subtle.timingSafeEqual)
- Remove hardcoded secret fallbacks in tunnel.ts and new.tsx
- Add MCP x402 transport (JSON-RPC body extraction for payments)
- Implement /sign endpoint for transaction signing
P1 (before launch):
- Add transaction validation in /sign using tabs-sdk
- Validate JSON-RPC response before settlement
- Implement refresh token rotation in OAuth
- Fix auth code race condition with atomic UPDATE...RETURNING
- Add secret validation middleware at startup
Also exports SPLIT_CONFIG_DISCRIMINATOR from splits-sdk for
getProgramAccounts filtering in service discovery.
Replace database-backed service registry with on-chain discovery
per ADR-0004 §4.7. Services are now identified by SplitConfig PDAs
with labels starting with @ (e.g., @cascade/twitter).
- Add splits.ts with discoverServices() and serviceExists()
- Update explore.tsx to use on-chain discovery
- Remove services.ts (database-backed registry)
- Simplify schema.sql (remove services table)
Adds --sourcemap for debugging and --no-compile-autoload-dotenv
to prevent automatic .env loading in compiled binaries.
Improve naming clarity for the Durable Object that bridges
Gateway HTTP requests to CLI WebSocket connections.
- Rename tunnel.ts → service-bridge.ts
- Rename class TunnelRelay → ServiceBridge
- Rename binding TUNNEL_RELAY → SERVICE_BRIDGE
- Update ADR-0004 references
- Fix WebSocket handler signatures (wasClean param, ArrayBuffer)
- Add pending request rejection on disconnect
Revert the class rename from c1a0039 while keeping the bug fixes
(WebSocket handler signatures, pending request rejection).
"Tunnel" is more familiar terminology to developers (like ngrok),
while "Bridge" is an internal implementation detail. The class name
TunnelRelay accurately describes what it does: relays MCP requests
through a WebSocket tunnel to supplier CLIs.
Changes:
- Rename service-bridge.ts → tunnel.ts
- Rename class ServiceBridge → TunnelRelay
- Rename binding SERVICE_BRIDGE → TUNNEL_RELAY
- Update gateway references and ADR-0004
- Clarify "CLI clients" → "supplier CLIs" in comments
Security fixes from review:
1. Transaction injection prevention (CRITICAL)
- Verify exactly 1 instruction in /sign endpoint
- Prevents malicious instruction injection attacks
2. Rate limiting for /sign endpoint (HIGH)
- 30 requests/minute per wallet using KV sliding window
- Prevents DoS attacks on signing endpoint
3. Optimize getProgramAccounts (MEDIUM)
- Add memcmp filter on "CSPL:@" prefix at offset 105
- Server-side filtering for marketplace services only
- Improves scalability as splits grow
4. SIWS session validation in OAuth (MEDIUM)
- Derive userAddress from verified session cookie
- Remove client-provided userAddress from input
- Prevents wallet address spoofing
5. OAuth client_id format validation (LOW)
- Validate format: lowercase alphanumeric + hyphens, 3-64 chars
- Prevents invalid client identifiers
Add OAuth login, status, serve (supplier tunnel), and MCP management:
- login: OAuth 2.0 + PKCE flow with local callback server
- status: Display wallet, Tabs account, and configured MCPs
- serve: WebSocket tunnel to Gateway for local MCP exposure
- mcp add/remove/proxy: Claude Code integration with x402 payments
Supporting libraries:
- auth: XDG credential storage with auto-refresh
- config: Claude Code settings.json manipulation
- tokens: Service token decoding for suppliers
- tunnel: WebSocket client with Cloudflare DO reconnection
- x402: Payment building via tabs-sdk
Also includes:
- Gateway audit logging for executor signing (W8)
- ADR-0004 update for Tabs PDA discovery pattern
Add /.well-known/oauth-authorization-server endpoint to enable
MCP clients to automatically discover OAuth endpoints. This improves
interoperability with OAuth 2.1 compliant clients.
Replace custom D1+JWT OAuth implementation with Cloudflare's
workers-oauth-provider library, eliminating D1 dependency entirely.
- Add HTML consent page with wallet-standard SIWS
- Use KV-backed opaque tokens with AES-GCM encryption
- Simplify gateway auth via OAuthProvider's ctx.props
- Update ADR-0004 to reflect new architecture
…n tx validation
x402 SVM clients v2.4+ append a Memo instruction for replay protection.
Wallet extensions (Phantom, Solflare) inject Lighthouse instructions.
Amend detectInstructionLayout to allow these trailing instructions after
the transfer, and skip them in fee payer safety checks.
Also bump @x402/core to ^2.5.0 and @coinbase/x402 to ^2.1.0.
Direct SPL TransferChecked is fully verified statically (layout,
amount, mint, destination ATA, fee payer safety). Simulation is only
needed for CPI transfers (smart wallets). This eliminates the Solana
RPC round-trip that was causing 17-79s verify latency.
- Replace custom signer with toFacilitatorSvmSigner from @x402/svm
- Keep custom simulateForCpi for RFC #646 CPI verification
- Rename worker to cascade-facilitator-old, domain to facilitator-old.cascade.fyi
- Add payload destructuring guards (fixes potential 500 on malformed requests)
- Remove unused @coinbase/x402 dependency
- Update market references to facilitator-old.cascade.fyi
Proxy-based RPC from @solana/kit fails the "getBalance" in rpc
property detection. Pass as explicit {[network]: rpc} map instead.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@tenequm