feat(mcp): Streamable HTTP transport + deploy; secure restoreRevision
- apps/mcp/src/http.ts: serve MCP over Streamable HTTP (MCP 2025-03-26) on :4021, stateless mode (sessionIdGenerator undefined), CORS on /mcp. Remote clients can now call the 6 tools + 4 resources without a stdio subprocess. - deploy/mcpedia-mcp.service: supervised systemd unit (MCP_PORT=4021). - Caddy: mcp.asepharyana.my.id -> 4021; wiki. domain now also routes /trpc/* to the API (was swallowed by web -> tRPC was unreachable on the domain). - apps/api: restoreRevision tRPC mutation now requires x-webhook-secret (the Web UI calls @mcpedia/core directly, so this only gates the open network endpoint). Threads the header into tRPC Context. Secures a state-changing action that was anonymously callable. Verified live: https://mcp.asepharyana.my.id/mcp initialize/tools/list/ resources/list all 200; restoreRevision no-secret -> unauthorized, with-secret -> handler; read-only tRPC reachable via domain.
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
[Unit]
|
||||
Description=MCPedia MCP server (Streamable HTTP)
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
WorkingDirectory=/home/code/mcpedia
|
||||
# Loads DATABASE_URL, EMBED_* from the repo .env (MCP tools read the KB).
|
||||
EnvironmentFile=/home/code/mcpedia/.env
|
||||
# Absolute bun path (systemd has a minimal PATH; /usr/bin/env bun fails).
|
||||
Environment=MCP_PORT=4021
|
||||
ExecStart=/home/code/.bun/bin/bun --cwd apps/mcp src/http.ts
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
User=code
|
||||
Group=code
|
||||
NoNewPrivileges=true
|
||||
PrivateTmp=true
|
||||
MemoryMax=512M
|
||||
TasksMax=256
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user