- apps/mcp/src/http.ts: serve MCP over Streamable HTTP (MCP 2025-03-26) on :4021, stateless mode (sessionIdGenerator undefined), CORS on /mcp. Remote clients can now call the 6 tools + 4 resources without a stdio subprocess. - deploy/mcpedia-mcp.service: supervised systemd unit (MCP_PORT=4021). - Caddy: mcp.asepharyana.my.id -> 4021; wiki. domain now also routes /trpc/* to the API (was swallowed by web -> tRPC was unreachable on the domain). - apps/api: restoreRevision tRPC mutation now requires x-webhook-secret (the Web UI calls @mcpedia/core directly, so this only gates the open network endpoint). Threads the header into tRPC Context. Secures a state-changing action that was anonymously callable. Verified live: https://mcp.asepharyana.my.id/mcp initialize/tools/list/ resources/list all 200; restoreRevision no-secret -> unauthorized, with-secret -> handler; read-only tRPC reachable via domain.
28 lines
624 B
JSON
28 lines
624 B
JSON
{
|
|
"name": "@mcpedia/mcp",
|
|
"version": "0.1.0",
|
|
"private": true,
|
|
"type": "module",
|
|
"bin": {
|
|
"mcpedia-mcp": "./src/index.ts"
|
|
},
|
|
"scripts": {
|
|
"start": "bun run src/index.ts",
|
|
"serve:http": "bun run src/http.ts",
|
|
"lint": "tsc --noEmit",
|
|
"typecheck": "tsc --noEmit",
|
|
"smoke": "bun run src/smoke.test.ts"
|
|
},
|
|
"dependencies": {
|
|
"@mcpedia/config": "workspace:*",
|
|
"@mcpedia/core": "workspace:*",
|
|
"@mcpedia/search": "workspace:*",
|
|
"@modelcontextprotocol/sdk": "^1.29.0",
|
|
"zod": "^4.0.0"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "^20",
|
|
"typescript": "^5.6.0"
|
|
}
|
|
}
|