sh-mcp/packages/shared/package.json
Adam Moussa 00762de0a6 Address CodeQL findings: bound ajv error work + edge rate limiting
GHAS code-scanning alerts on this PR:
- dispatch.ts (js/resource-exhaustion): ajv ran with allErrors:true on
  untrusted input, letting a crafted payload force unbounded error
  enumeration. Switch to allErrors:false (default) so validation
  short-circuits on the first failure; the 400 still names that path.
- http.ts (js/missing-rate-limiting): the authenticated routes (/mcp,
  /tools/:name) had no edge throttle — auth/JWT verification ran on every
  request before the per-sub dispatch limiter could apply. Add an IP-keyed
  express-rate-limit in front of authenticate (120/60s default, configurable),
  returning the standard 429 shape. Defense-in-depth over the per-sub +
  per-tool limiter in executeTool; API GW/WAF remains the production edge.

Tests: +2 cases proving the edge limiter throttles before auth (429, not
401) on /tools and /mcp. 407 pass; tsc/eslint/prettier clean.
2026-06-26 13:01:12 -04:00

40 lines
1,019 B
JSON

{
"name": "@sh-mcp/shared",
"version": "0.1.0",
"type": "module",
"description": "Transport-agnostic core — types, registry, auth interface, redaction, OpenAPI generation",
"exports": {
".": {
"import": "./dist/index.js",
"types": "./dist/index.d.ts"
}
},
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
"engines": {
"node": ">=24.0.0"
},
"scripts": {
"build": "tsc --project tsconfig.json",
"typecheck": "tsc --noEmit --project tsconfig.json",
"test": "vitest run",
"test:watch": "vitest",
"test:coverage": "vitest run --coverage"
},
"devDependencies": {
"@types/express": "5.0.6",
"@types/supertest": "7.2.0",
"@vitest/coverage-v8": "^2.0.0",
"supertest": "7.2.2",
"typescript": "^5.5.0",
"vitest": "^2.0.0"
},
"dependencies": {
"@modelcontextprotocol/sdk": "1.29.0",
"ajv": "8.20.0",
"ajv-formats": "3.0.1",
"express": "5.2.1",
"express-rate-limit": "^8.2.1",
"jose": "^6.2.3"
}
}