Files
9router/src/app/api/mcp/[plugin]/message/route.js
T
decoluaandCursor f8b73faf5d feat(cowork): re-enable Claude Cowork with preset-only stdio MCP
Restore Cowork feature while closing the RCE vector: drop user-defined
stdio commands so only hard-coded preset plugins (browsermcp) may spawn.
Custom MCP now accepts remote URL only. Routes stay gated to localhost.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-08 15:35:37 +07:00

20 lines
609 B
JavaScript

import { NextResponse } from "next/server";
import { sendToChild, findPlugin } from "@/lib/mcp/stdioSseBridge";
export const runtime = "nodejs";
export const dynamic = "force-dynamic";
export async function POST(request, { params }) {
const { plugin } = await params;
if (!findPlugin(plugin)) {
return NextResponse.json({ error: `Unknown plugin: ${plugin}` }, { status: 404 });
}
try {
const body = await request.json();
sendToChild(plugin, body);
return new Response(null, { status: 202 });
} catch (e) {
return NextResponse.json({ error: e.message }, { status: 500 });
}
}