Skip to content

Fix authentication format and calendar date handling - #21

Merged
TheEagleByte merged 1 commit into
mainfrom
fix/auth-and-calendar-dates
Dec 30, 2025
Merged

TheEagleByte merged 1 commit into
mainfrom
fix/auth-and-calendar-dates

Conversation

@TheEagleByte

@TheEagleByte TheEagleByte commented Dec 30, 2025 •

Copy link
Copy Markdown
Owner

Summary

  • Fix email/password authentication: Changed from Bearer token to Basic base64(userId:token) format, which is what the Skylight API actually expects
  • Fix calendar events query: The API treats date_max as exclusive, so querying a single day (e.g., 2025-12-30 to 2025-12-30) returned no events. Now we add 1 day to date_max to include events on the end date
  • Add debug logging: Added logging for auth flow to help troubleshoot login issues
  • Add automatic retry: For email/password auth, automatically retry once on 401 errors by re-logging in

Test plan

  • Verify email/password login works correctly
  • Verify get_calendar_events returns events for a single day
  • Verify calendar events for date ranges work correctly

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Fixed calendar event retrieval to correctly include the end date in results
    • Added automatic retry on temporary authentication failures to reduce manual re-login requirements
  • Changes

    • Updated authentication protocol to use improved security methods
    • Enhanced error messaging for better troubleshooting of authentication issues

✏️ Tip: You can customize this high-level summary in your review settings.

- Fix email/password auth to use Basic base64(userId:token) format
- Fix calendar events query to treat date_max as exclusive (add 1 day)
- Add debug logging for auth flow
- Add automatic retry on 401 for email/password auth
- Bump version to 1.1.7

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Dec 30, 2025 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Version 1.1.7 updates the authentication mechanism from Bearer token to Basic auth using base64-encoded userId:token pairs, adds debug logging throughout the auth flow, implements automatic retry on 401 errors for email/password authentication, and adjusts calendar event date handling to treat date_max as inclusive.

Changes

Cohort / File(s) Summary
Release & Versioning
CHANGELOG.md, package.json
Version bumped to 1.1.7 with changelog entry documenting authentication mechanism change, debug logging, and automatic 401 retry for email/password auth.
Authentication Core
src/api/auth.ts, src/api/client.ts
Auth switched from Bearer to Basic auth (base64 userId:token). Added credential tracking (userId + token), debug logging, 401 error handling with detailed messages. Request flow now includes isRetry flag; email/password auth retries once on 401 before failing.
Calendar Endpoint
src/api/endpoints/calendar.ts
Added internal date adjustment helper; getCalendarEvents now treats date_max as inclusive by adding 1 day before API call.

Sequence Diagram(s)

sequenceDiagram
    actor User
    participant Client as SkylightClient
    participant Auth as Auth Service
    participant API as API Server

    User->>Client: request(endpoint)
    Client->>Client: request(endpoint, {}, false)
    
    alt Email/Password Mode
        Client->>Client: getCredentials()
        Client->>Auth: login(email, password)
        Auth->>API: POST /login
        API-->>Auth: {token, userId}
        Auth-->>Client: {token, userId}
        Client->>Client: getAuthHeader() → Basic auth
    else Token/Basic Mode
        Client->>Client: getCredentials()
        Client->>Client: getAuthHeader() → existing auth
    end

    Client->>API: GET endpoint<br/>(with auth header)
    
    alt 401 Response
        API-->>Client: 401 Unauthorized
        alt Email/Password + !isRetry
            rect rgb(255, 240, 245)
                Note over Client: Retry Flow
                Client->>Client: clearCredentials()
                Client->>Auth: login(email, password)
                Auth->>API: POST /login
                API-->>Auth: {token, userId}
                Auth-->>Client: {token, userId}
                Client->>Client: getAuthHeader() → Basic auth
                Client->>Client: request(endpoint, {}, true)
                Client->>API: GET endpoint<br/>(retry with new token)
            end
        else Other Auth Mode OR isRetry=true
            Client->>Client: handleResponseError(401)
            Client->>User: throw AuthenticationError
        end
    else Success
        rect rgb(245, 255, 240)
            Note over Client: Request Succeeds
            API-->>Client: Response
            Client-->>User: Return data
        end
    end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Poem

🐰 A hop, skip, and jump through the auth-scape we go,
With Basic credentials in base64's glow!
When 401 strikes, we retry with grace,
No token left behind in this secure place,
Calendar dates now inclusive and bright—
Version 1.1.7 sets everything right! 🔐✨

Pre-merge checks and finishing touches

✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title directly captures the two main fixes in the changeset: authentication format change and calendar date handling correction.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
✨ Finishing touches
  • 📝 Generate docstrings

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
src/api/endpoints/calendar.ts (1)

22-26: Potential timezone edge case in date parsing.

Using new Date(dateStr + "T00:00:00") parses the date in the local system timezone, which could cause unexpected results near DST transitions or on servers in different timezones. Consider parsing as UTC for consistent behavior:

🔎 Proposed fix for timezone-safe parsing
 function addDays(dateStr: string, days: number): string {
-  const date = new Date(dateStr + "T00:00:00");
-  date.setDate(date.getDate() + days);
-  return date.toISOString().split("T")[0];
+  const date = new Date(dateStr + "T00:00:00Z");
+  date.setUTCDate(date.getUTCDate() + days);
+  return date.toISOString().split("T")[0];
 }
📜 Review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 0acfc20 and ed541f7.

📒 Files selected for processing (5)
  • CHANGELOG.md
  • package.json
  • src/api/auth.ts
  • src/api/client.ts
  • src/api/endpoints/calendar.ts
🧰 Additional context used
📓 Path-based instructions (1)
**/*.ts

📄 CodeRabbit inference engine (CLAUDE.md)

**/*.ts: Use npm run build to compile TypeScript
Configure TypeScript with ES2022 target, NodeNext module resolution, and strict mode

Files:

  • src/api/auth.ts
  • src/api/endpoints/calendar.ts
  • src/api/client.ts
🧠 Learnings (5)
📚 Learning: 2025-12-29T21:36:49.327Z
Learnt from: CR
Repo: TheEagleByte/skylight-mcp PR: 0
File: CLAUDE.md:0-0
Timestamp: 2025-12-29T21:36:49.327Z
Learning: Support two authentication methods: Email/Password (SKYLIGHT_EMAIL and SKYLIGHT_PASSWORD) or Manual Token (SKYLIGHT_TOKEN with optional SKYLIGHT_AUTH_TYPE)

Applied to files:

  • CHANGELOG.md
  • src/api/auth.ts
  • src/api/client.ts
📚 Learning: 2025-12-29T21:36:49.327Z
Learnt from: CR
Repo: TheEagleByte/skylight-mcp PR: 0
File: CLAUDE.md:0-0
Timestamp: 2025-12-29T21:36:49.327Z
Learning: Applies to api/client.ts : Implement HTTP client in api/client.ts with Bearer/Basic auth, auto-login, and subscription status tracking

Applied to files:

  • src/api/auth.ts
  • src/api/client.ts
📚 Learning: 2025-12-29T21:36:49.327Z
Learnt from: CR
Repo: TheEagleByte/skylight-mcp PR: 0
File: CLAUDE.md:0-0
Timestamp: 2025-12-29T21:36:49.327Z
Learning: Applies to api/auth.ts : Implement login endpoint for email/password authentication in api/auth.ts

Applied to files:

  • src/api/auth.ts
  • src/api/client.ts
📚 Learning: 2025-12-29T21:36:49.327Z
Learnt from: CR
Repo: TheEagleByte/skylight-mcp PR: 0
File: CLAUDE.md:0-0
Timestamp: 2025-12-29T21:36:49.327Z
Learning: Applies to config.ts : Use Zod-validated env config in config.ts supporting email/password and token authentication methods

Applied to files:

  • src/api/auth.ts
  • src/api/client.ts
📚 Learning: 2025-12-29T21:36:49.327Z
Learnt from: CR
Repo: TheEagleByte/skylight-mcp PR: 0
File: CLAUDE.md:0-0
Timestamp: 2025-12-29T21:36:49.327Z
Learning: Applies to utils/dates.ts : Use utils/dates.ts to parse flexible date formats including 'today', 'tomorrow', day names, and YYYY-MM-DD

Applied to files:

  • src/api/endpoints/calendar.ts
🧬 Code graph analysis (2)
src/api/endpoints/calendar.ts (2)
src/api/types.ts (2)
  • CalendarEventResource (140-144)
  • CalendarEventsResponse (187-187)
src/api/client.ts (1)
  • getClient (270-275)
src/api/client.ts (2)
src/config.ts (3)
  • Config (34-34)
  • getConfig (89-94)
  • usesEmailAuth (99-101)
src/utils/errors.ts (1)
  • AuthenticationError (19-24)
🔇 Additional comments (13)
CHANGELOG.md (1)

1-22: LGTM!

The changelog is well-structured, follows Keep a Changelog format, and clearly documents both the fixes and behavioral changes introduced in this version. The explanations are concise and helpful for users troubleshooting auth or calendar issues.

package.json (1)

3-3: LGTM!

Version bump to 1.1.7 aligns with the changelog entry and the scope of changes in this PR.

src/api/auth.ts (3)

35-36: LGTM!

Debug logging for login attempts using console.error is appropriate for MCP servers where stdout is reserved for protocol communication.


48-61: LGTM!

Enhanced error handling with captured error body provides better debugging context. The empty catch block is appropriate here since we want to continue even if reading the error body fails.


65-66: LGTM!

Logging only the first 10 characters of the token is a reasonable balance between debuggability and security.

src/api/endpoints/calendar.ts (1)

36-49: LGTM!

The date handling logic correctly addresses the exclusive date_max API behavior. The inline comments clearly explain the reasoning, which is helpful for future maintainers.

src/api/client.ts (7)

30-31: LGTM!

Adding resolvedUserId and updating the loginPromise type appropriately supports the new credential-based flow.


42-69: LGTM!

The getCredentials method correctly handles both authentication flows and prevents duplicate logins with the loginPromise pattern.


92-106: LGTM!

The auth header logic correctly constructs Basic base64(userId:token) for email/password authentication while preserving backward compatibility for manual token configurations.


128-144: LGTM!

The enhanced 401 error handling provides actionable guidance for email/password users, suggesting verification of the frame ID which is a common misconfiguration issue.


198-207: LGTM!

The 401 retry logic correctly limits retry attempts to one via the isRetry flag, preventing infinite loops while providing resilience against transient auth failures.


179-179: LGTM!

Debug logging for requests and responses aids troubleshooting without exposing sensitive data.

Also applies to: 196-196


262-264: LGTM!

The initialize method correctly uses getCredentials to align with the new credential-based flow.

@TheEagleByte
TheEagleByte merged commit b1fc826 into main Dec 30, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant