mirror of
https://github.com/Sea-Haven-Industries/sh-mcp.git
synced 2026-10-07 13:58:58 +00:00
Add the single authoritative tool-execution path (executeTool) plus the two universal interfaces over it (design.md §2.5, §7.3): - dispatch.ts: scope enforcement, ajv input validation, rate limiting, finance egress redaction (redactDeep), and structured audit emission on one path. - audit.ts / rate-limit.ts: injected AuditLogger + RateLimiter abstractions. - mcp.ts: low-level MCP Server with scope-filtered tools/list (tool-hiding) and tools/call routed through executeTool. - http.ts: Express host mounting /mcp, /openapi.json, POST /tools/:name, /healthz. - openapi.ts: buildOpenApiDocument wraps the existing path generator into a full OpenAPI 3.1 document. - local-auth.ts: LocalAuthProvider (dev bearer tokens) that refuses to construct outside SH_MCP_ENV=local and enforces audience binding (design.md §3, §6).
39 lines
983 B
JSON
39 lines
983 B
JSON
{
|
|
"name": "@sh-mcp/shared",
|
|
"version": "0.1.0",
|
|
"type": "module",
|
|
"description": "Transport-agnostic core — types, registry, auth interface, redaction, OpenAPI generation",
|
|
"exports": {
|
|
".": {
|
|
"import": "./dist/index.js",
|
|
"types": "./dist/index.d.ts"
|
|
}
|
|
},
|
|
"main": "./dist/index.js",
|
|
"types": "./dist/index.d.ts",
|
|
"engines": {
|
|
"node": ">=24.0.0"
|
|
},
|
|
"scripts": {
|
|
"build": "tsc --project tsconfig.json",
|
|
"typecheck": "tsc --noEmit --project tsconfig.json",
|
|
"test": "vitest run",
|
|
"test:watch": "vitest",
|
|
"test:coverage": "vitest run --coverage"
|
|
},
|
|
"devDependencies": {
|
|
"@types/express": "5.0.6",
|
|
"@types/supertest": "7.2.0",
|
|
"@vitest/coverage-v8": "^2.0.0",
|
|
"supertest": "7.2.2",
|
|
"typescript": "^5.5.0",
|
|
"vitest": "^2.0.0"
|
|
},
|
|
"dependencies": {
|
|
"@modelcontextprotocol/sdk": "1.29.0",
|
|
"ajv": "8.20.0",
|
|
"ajv-formats": "3.0.1",
|
|
"express": "5.2.1",
|
|
"jose": "^6.2.3"
|
|
}
|
|
}
|