Files
mcpedia/apps/mcp/package.json
T
asepharyana b621923868 feat(mcp): Streamable HTTP transport + deploy; secure restoreRevision
- apps/mcp/src/http.ts: serve MCP over Streamable HTTP (MCP 2025-03-26) on
  :4021, stateless mode (sessionIdGenerator undefined), CORS on /mcp. Remote
  clients can now call the 6 tools + 4 resources without a stdio subprocess.
- deploy/mcpedia-mcp.service: supervised systemd unit (MCP_PORT=4021).
- Caddy: mcp.asepharyana.my.id -> 4021; wiki. domain now also routes /trpc/*
  to the API (was swallowed by web -> tRPC was unreachable on the domain).
- apps/api: restoreRevision tRPC mutation now requires x-webhook-secret (the
  Web UI calls @mcpedia/core directly, so this only gates the open network
  endpoint). Threads the header into tRPC Context. Secures a state-changing
  action that was anonymously callable.
Verified live: https://mcp.asepharyana.my.id/mcp initialize/tools/list/
resources/list all 200; restoreRevision no-secret -> unauthorized, with-secret
-> handler; read-only tRPC reachable via domain.
2026-08-20 09:53:33 +07:00

28 lines
624 B
JSON

{
"name": "@mcpedia/mcp",
"version": "0.1.0",
"private": true,
"type": "module",
"bin": {
"mcpedia-mcp": "./src/index.ts"
},
"scripts": {
"start": "bun run src/index.ts",
"serve:http": "bun run src/http.ts",
"lint": "tsc --noEmit",
"typecheck": "tsc --noEmit",
"smoke": "bun run src/smoke.test.ts"
},
"dependencies": {
"@mcpedia/config": "workspace:*",
"@mcpedia/core": "workspace:*",
"@mcpedia/search": "workspace:*",
"@modelcontextprotocol/sdk": "^1.29.0",
"zod": "^4.0.0"
},
"devDependencies": {
"@types/node": "^20",
"typescript": "^5.6.0"
}
}