feat(cbinsights): add CB Insights API v2 integration - #6879
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
PR SummaryCursor Bugbot is generating a summary for commit a86468f. Configure here. |
Greptile SummaryThe PR adds a CB Insights API v2 integration with credential exchange, bounded bearer-token caching, strict organization-ID validation, model-input projection for generative endpoints, block/tool registration, generated metadata, tests, and documentation.
Confidence Score: 5/5The PR appears safe to merge. No blocking failure remains.
|
| Filename | Overview |
|---|---|
| apps/sim/tools/cbinsights/utils.ts | Implements shared authorization, bounded token caching, retries, request limits, strict ID parsing, filter normalization, and response helpers; the previously reported validation and cache issues are resolved. |
| apps/sim/tools/cbinsights/cbinsights.test.ts | Covers authorization, cache bounds, malformed and unsafe IDs, filter handling, request construction, response projection, and model-input selection. |
| apps/sim/blocks/blocks/cbinsights.ts | Defines the CB Insights workflow block, operation-specific fields, tool selection, parameter mapping, outputs, and credential visibility. |
| apps/sim/tools/cbinsights/search_firmographics.ts | Builds validated firmographics searches while preventing filterless credit-consuming requests. |
| apps/sim/tools/registry.ts | Registers the new CB Insights tools for runtime dispatch. |
| apps/docs/content/docs/en/integrations/cbinsights.mdx | Documents authentication, licensing, credit-aware usage, all exposed operations, and their input/output contracts. |
Sequence Diagram
sequenceDiagram
participant Workflow
participant Tool as CB Insights Tool
participant Cache as Token Cache
participant Auth as CB Insights Authorization
participant API as CB Insights API v2
Workflow->>Tool: Execute operation
Tool->>Cache: Look up credential digest
alt Token absent or expired
Tool->>Auth: Exchange client credentials
Auth-->>Tool: Bearer token
Tool->>Cache: Store token and prune cache
end
Tool->>API: Authorized API request
alt API returns 401
Tool->>Cache: Delete cached token
Tool->>Auth: Reauthorize once
Auth-->>Tool: Fresh bearer token
Tool->>API: Retry request once
end
API-->>Tool: JSON response
Tool-->>Workflow: Projected tool output
Reviews (6): Last reviewed commit: "fix(cbinsights): bound a numeric organiz..." | Re-trigger Greptile
|
@cursor review |
Covers every non-streaming v2 endpoint across 25 tools: free organization lookup, firmographics search, funding rounds and cap tables, investments, portfolio exits, business relationships, management and board, the Mosaic / Commercial Maturity / Exit Probability outlooks and their histories, funding windows, revenue, strategy maps, Scouting Reports, ChatCBI, and RAG context. CB Insights authorizes by client-credential exchange rather than a static key, so the tools run through directExecution: the shared executor trades the credentials for a bearer token, caches it briefly, and re-authorizes once on a 401 — the token lifetime is undocumented, so expiry is discovered rather than predicted. ChatCBI and RAG declare request.modelInput so an activated Sim secret in the message is projected to its canonical label before reaching a third party's model. directExecution still runs projectToolModelInputParams, so the two are compatible. The two streaming endpoints are deliberately excluded; they deliver incremental JSON chunks and their non-streaming counterparts return the same content in one piece.
- Reject an organization ID list containing an invalid entry instead of dropping it. Silently filtering meant a typo ran the request against a narrower set — spending credits on the wrong organizations, or quietly widening a filtered search — and still reported success. - Apply the same rule to the optional firmographics ID filters, where a dropped filter broadens the search rather than narrowing it. - Bound the process-wide token cache so a long-lived worker serving many CB Insights accounts does not grow with the cumulative number of accounts seen. Expired entries are swept on write, then the oldest evicted.
f98dbfa to
803a3ec
Compare
|
@cursor review |
- Measure the firmographics empty-search guard against the filters alone. limit, nextPageToken, and sort were in the same object, so a request carrying only paging slipped past it and issued an unfiltered search over the whole database — which still spends credits. - Reject a mistyped numeric bound instead of dropping it. A bad headcount, funding, or valuation filter silently widened the search, the same failure mode already fixed for ID lists. - Treat an empty comma segment identically on the required and optional paths. A trailing or doubled comma is a separator artifact that cannot change which records are requested, so both paths now discard it; every other malformed entry is still rejected.
|
@cursor review |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 5222387. Configure here.
Number reads "0x10" as 16 and "1e2" as 100, so either notation resolved to a real but unintended organization and the request spent credits on it. Both the path-scoped and the bulk validators now require a plain run of digits, and use Number.isSafeInteger so an ID past the precision limit cannot round to a neighbouring one.
|
@cursor review |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 474b86f. Configure here.
…range The string path already required a safe integer; the numeric path still used Number.isInteger, which accepts a value past the precision limit. JSON parsing has already rounded such a value, so the request would target a different organization than the caller supplied.
|
@cursor review |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit e5b8380. Configure here.
Summary
Auth. CB Insights uses a client-credential exchange rather than a static key, so the tools run through
directExecution. The shared executor trades the credentials for a bearer token, caches it briefly keyed by a digest (never the credentials), and re-authorizes once on a 401 — the token's lifetime is undocumented, so expiry is discovered rather than predicted.Model input. ChatCBI and RAG declare
request.modelInputwithmode: 'project'so an activated Sim secret inside the message is projected to its canonical label before it reaches a third party's model.directExecutionstill runsprojectToolModelInputParams(tools/index.ts:1985), so the two compose. The ID-only endpoints are deliberately left unprojected — a resource ID is not model-visible content, even on an AI-backed endpoint.Every path, request field, and response shape was taken from the published Swagger document rather than inferred.
Type of Change
Testing
Tested manually. 33 unit tests across the block and the tools, covering the credential exchange, token reuse, the 401 re-authorize retry and its give-up path, org-ID path validation, the 100-ID and 1-100 limit bounds, filter compaction, and every response projection. Each test was mutation-verified by reverting its fix and watching it go red.
bun run lint,bun run check:audits(30 audits), andbun run type-checkall pass.Note: the live API cannot be exercised without client credentials, so the wire contract is verified against the Swagger spec and unit tests, not a real round trip.
Notes
The two streaming endpoints (
chatcbichunked,scoutingreportstream) are intentionally excluded — they deliver incremental JSON chunks that are not valid single JSON when accumulated, and their non-streaming counterparts return the same content in one piece.Checklist