# Reported issues for Ryan Lindsey

Pod holds 8 of 8 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [Ryan Lindsey](/mcp/ryan-lindsey).

## Most discussed

### fix(fit): the deferred run is cancelled at 30 seconds and the report never completes

Epic #270 moved the `analyze_fit` call into `ctx.waitUntil` so `/fit/run` could redirect immediately. `ctx.waitUntil` is capped at 30 seconds and the run takes 78.

Found by the whole-epic review after all seven children merged. Nothing in the spec, the epic, or any comment in the change names this budget, and no test can see it.

## The measurement against the limit

`analyze_fit` was measured at **78,222 ms** on 2026-09-18, trace `77c557ab4623b2fa059f29c7f75053b2`. That number is quoted in…

[Read the thread](https://github.com/ryanlindsey/ryanlindsey.me/issues/349) · 2026-09-22 · closed · 2 comments

### fix(mcp): the one catch-all error log drops the error message, in the form measured not to work

`workers/mcp/src/define.ts:308` logs the error as a second argument, which is the one form this codebase established does not work.

```ts
console.error(`mcp/${spec.surface}: ${spec.auditName} failed`, error);
```

Measured 2026-09-17 and recorded in `workers/mcp/src/fit-start.ts`: Cloudflare Worker observability renders `console.error(msg, err)` as the message followed by the stack and **drops `err.message` entirely**. That measurement is why `completeRun` interpolates instead:

```ts…

[Read the thread](https://github.com/ryanlindsey/ryanlindsey.me/issues/354) · 2026-09-22 · closed · 1 comment

### fix(evals): payloadOf takes the first data line without matching on id, on the one SSE reader with live callers

`payloadOf` is the SSE reader with live production callers, and it carries only half the lesson that cost `/fit` eighteen days.

```ts
// workers/mcp/src/evals-client.ts
const data = text.split('\n').find((line) => line.startsWith('data:'));
```

It takes the **first** `data:` line in the stream and never matches on the JSON-RPC `id`. `src/lib/fit/client.ts` used to do exactly this, and the comment on its replacement records what it cost: `fit_reports` held zero rows from #37 until the fix,…

[Read the thread](https://github.com/ryanlindsey/ryanlindsey.me/issues/351) · 2026-09-22 · closed · 1 comment

### Spec: a /connect page for setting up the MCP server

## Why

Every link on this site labelled MCP sends a person somewhere they cannot use. `AGENT_LINKS` in `src/lib/nav.ts` points the footer's FOR AGENTS column and the mobile overlay's strip at `MCP_ENDPOINT`, and `/chat` points its PREFER A PROTOCOL? rail and its `<noscript>` note at the same address. Measured 2026-09-24: a browser `GET https://mcp.ryanlindsey.me/mcp` with `Accept: text/html` answers `405` with `application/json`. The address is right for a client and a dead end for a reader.…

[Read the thread](https://github.com/ryanlindsey/ryanlindsey.me/issues/395) · 2026-09-24 · closed · 0 comments

### The fit workflow test reads the instance before /fit/start has created it

**Measured 2026-09-23.** `tests/fit-workflow.test.ts` › "the deferred run is a workflow instance named by the permalink id" failed once in CI and passed on the same code everywhere else.

## The failure

Release PR #381, `checks` run [35883324048](https://github.com/ryanlindsey/ryanlindsey.me/actions/runs/35883324048/job/107257029164?pr=381), at `777c78d`:

```
FAIL tests/fit-workflow.test.ts > the deferred run is a workflow instance named by the permalink id
Error: instance.not_found
 ❯…

[Read the thread](https://github.com/ryanlindsey/ryanlindsey.me/issues/384) · 2026-09-23 · closed · 0 comments

### Stop `scripts/token.mjs` defaulting `--scopes` to the whole set

`scripts/token.mjs:286` defaults `--scopes` to every scope there is:

```js
const scopes = String(arg('scopes', SCOPES.join(',')))
```

So a mint that forgets the flag hands its audience `fit,profile,documents,narrative,evals,authoring`. Both withheld scopes are in that list, and both of them now open something.

Found during review of `ryanlindsey/ryanlindsey.me#266`, which is what made the second one true. Not fixed there: `scripts/token.mjs` is outside that issue's file list, and a mint…

[Read the thread](https://github.com/ryanlindsey/ryanlindsey.me/issues/284) · 2026-09-18 · closed · 0 comments

### bug(mcp): rate limiting does not enforce in production — 140 calls/second pass a 60/minute bucket

The `RATE_LIMITER` binding does not limit anything in production. Both MCP origins served **140 requests in 1 second** against a documented 60/60s bucket, with zero refusals, and `mcp_tool_calls` has never recorded a single `rate_limited` outcome.

03 §3 requires every public tool call to be rate-limited. The audit half of that requirement is working (see below); the limiting half is not.

## Evidence

```
140 parallel POSTs, get_contact, burst completed in 1s:
  mcp.ryanlindsey.me -> 0/140…

[Read the thread](https://github.com/ryanlindsey/ryanlindsey.me/issues/29) · 2026-09-08 · closed · 0 comments

### bug(mcp): ryanlindsey.me/mcp loops on its own origin — 7 of 8 tools fail with 522

Since #27 deployed, **`https://ryanlindsey.me/mcp` — the endpoint 03 §1 names as primary — fails for seven of the eight tools and for `resources/list`.** The vanity host `https://mcp.ryanlindsey.me/mcp` is unaffected and fully working.

## Symptom

| Call | `mcp.ryanlindsey.me` | `ryanlindsey.me` |
|---|---|---|
| `initialize` | ok | ok |
| `get_contact` | ok | ok |
| `request_private_access` | ok | ok |
| `get_resume` | ok | **`The résumé could not be read from the site right now.`** |
|…

[Read the thread](https://github.com/ryanlindsey/ryanlindsey.me/issues/28) · 2026-09-08 · closed · 0 comments

## Most recent

The remaining reports are on [the project's issue tracker](https://github.com/ryanlindsey/ryanlindsey.me/issues).
