Skip to content

fix(mcp-cloudflare): guard WebAssembly import in TerminalAnimation - #1345

Merged
dcramer merged 1 commit into
mainfrom
seer/fix/mcp-cloudflare-wasm-guard
Sep 28, 2026
Merged

dcramer merged 1 commit into
mainfrom
seer/fix/mcp-cloudflare-wasm-guard

Conversation

@sentry

@sentry sentry Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

This PR addresses a ReferenceError: Can't find variable: WebAssembly that occurs in environments where WebAssembly is not available, such as iOS Safari in private browsing mode.

The root cause was the unconditional dynamic import of asciinema-player in packages/mcp-cloudflare/src/client/components/animation/TerminalAnimation.tsx. The asciinema-player package includes a Rust/WASM bundle that attempts to access the WebAssembly global upon import, leading to a crash if it's undefined.

To fix this, a guard if (typeof WebAssembly === "undefined") return; has been added immediately before the await import("asciinema-player") call. This ensures that the asciinema-player is only loaded if WebAssembly is supported, allowing the component to gracefully degrade (the animation will not play) in unsupported environments without crashing the application.

Fixes MCP-SERVER-FZA

@sentry <feedback>: Autofix iterates on these changes
@sentry stop iterating: Autofix stops iterating on this run

This PR was automatically generated by Sentry. You can adjust this setting at any time.

@github-actions github-actions Bot added the risk: low PR risk score: low label Sep 27, 2026

@sentry-junior sentry-junior Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good at 3e76b52. The latest motivating event reaches asciinema-player 3.17.0's __wbg_load → WebAssembly.instantiate; the installed dependency starts that initialization during module evaluation. Guarding before the dynamic import prevents the actual failure without catching unrelated errors or changing supported-browser behavior. The evidence establishes an absent WebAssembly global, not the description's specific private-browsing explanation.

Verified the built client at http://localhost:5173 in Chromium with WebAssembly absent (--js-flags=--jitless): no player/chunk load and no page errors; the page and installation tabs remain usable. Removing only the compiled guard in a separate control reproduces ReferenceError: WebAssembly is not defined. With WebAssembly enabled, the player loads demo.cast and renders the terminal. This is a capability simulation, not an iOS Safari test. Used the static client build because the repo dev server requires an authenticated Cloudflare remote proxy.

The client build and all 430 Cloudflare tests pass locally. Current-head CI, including the required test gate, is successful. No code corrections needed.

@dcramer
dcramer merged commit e6cde68 into main Sep 28, 2026
20 checks passed
@dcramer
dcramer deleted the seer/fix/mcp-cloudflare-wasm-guard branch September 28, 2026 16:12
BYK pushed a commit that referenced this pull request Sep 30, 2026
…1346)

The env-token-ignored hint claimed the user set a `SENTRY_AUTH_TOKEN`
env var even when the token actually came from a `[auth] token` in
`.sentryclirc` (the shim copies it into `SENTRY_AUTH_TOKEN` at boot).
The shim now records the injecting `.sentryclirc` path and the hint
names it instead, so the source is accurate.

Scoped to the incorrect-source bug from #1345. The larger behavior
proposal in the issue (trust org/host-embedded tokens, only fall back to
the stored DB token when the other fails/can't be trusted) is a separate
design change and isn't included here.

## Testing
`pnpm exec vitest run test/lib/auth-hint.test.ts
test/lib/sentryclirc.test.ts` (39 passed), plus `pnpm run typecheck` and
`pnpm run lint` clean.

Closes #1345

<!--
## Plan
Root cause: applySentryCliRcEnvShim in src/lib/sentryclirc.ts maps a
.sentryclirc [auth] token into env.SENTRY_AUTH_TOKEN. Later,
maybeWarnEnvTokenIgnored in src/lib/auth-hint.ts reports "Detected
SENTRY_AUTH_TOKEN env var" using getActiveEnvVarName(), which cannot
tell an rc-injected token from a real env var. The user sees a wrong
source.

Changes:
- src/lib/sentryclirc.ts: add module-local rcInjectedTokenSource, set
  it to config.sources.token when the shim injects the token, expose
  getRcInjectedTokenSource(), and reset it in clearSentryCliRcCache().
- src/lib/auth-hint.ts: add describeIgnoredTokenSource() naming the
  .sentryclirc file when rc-injected, else the env-var name.
- tests for both the shim provenance and the hint wording.

Out of scope: token trust/precedence changes (issue items 1 and 2).
-->

---------

Co-authored-by: jared-outpost[bot] <jared-outpost[bot]@users.noreply.github.com>
mr-danya pushed a commit to mr-danya/sentry-mcp that referenced this pull request Oct 6, 2026
…etsentry#1346)

The env-token-ignored hint claimed the user set a `SENTRY_AUTH_TOKEN`
env var even when the token actually came from a `[auth] token` in
`.sentryclirc` (the shim copies it into `SENTRY_AUTH_TOKEN` at boot).
The shim now records the injecting `.sentryclirc` path and the hint
names it instead, so the source is accurate.

Scoped to the incorrect-source bug from getsentry#1345. The larger behavior
proposal in the issue (trust org/host-embedded tokens, only fall back to
the stored DB token when the other fails/can't be trusted) is a separate
design change and isn't included here.

## Testing
`pnpm exec vitest run test/lib/auth-hint.test.ts
test/lib/sentryclirc.test.ts` (39 passed), plus `pnpm run typecheck` and
`pnpm run lint` clean.

Closes getsentry#1345

<!--
## Plan
Root cause: applySentryCliRcEnvShim in src/lib/sentryclirc.ts maps a
.sentryclirc [auth] token into env.SENTRY_AUTH_TOKEN. Later,
maybeWarnEnvTokenIgnored in src/lib/auth-hint.ts reports "Detected
SENTRY_AUTH_TOKEN env var" using getActiveEnvVarName(), which cannot
tell an rc-injected token from a real env var. The user sees a wrong
source.

Changes:
- src/lib/sentryclirc.ts: add module-local rcInjectedTokenSource, set
  it to config.sources.token when the shim injects the token, expose
  getRcInjectedTokenSource(), and reset it in clearSentryCliRcCache().
- src/lib/auth-hint.ts: add describeIgnoredTokenSource() naming the
  .sentryclirc file when rc-injected, else the env-var name.
- tests for both the shim provenance and the hint wording.

Out of scope: token trust/precedence changes (issue items 1 and 2).
-->

---------

Co-authored-by: jared-outpost[bot] <jared-outpost[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk: low PR risk score: low

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant