sh-mcp/packages/shared/package.json
Adam Moussa c85789b75e Add shared transport: dispatch, MCP + OpenAPI adapters, local auth
Add the single authoritative tool-execution path (executeTool) plus the two
universal interfaces over it (design.md §2.5, §7.3):
- dispatch.ts: scope enforcement, ajv input validation, rate limiting, finance
  egress redaction (redactDeep), and structured audit emission on one path.
- audit.ts / rate-limit.ts: injected AuditLogger + RateLimiter abstractions.
- mcp.ts: low-level MCP Server with scope-filtered tools/list (tool-hiding) and
  tools/call routed through executeTool.
- http.ts: Express host mounting /mcp, /openapi.json, POST /tools/:name, /healthz.
- openapi.ts: buildOpenApiDocument wraps the existing path generator into a full
  OpenAPI 3.1 document.
- local-auth.ts: LocalAuthProvider (dev bearer tokens) that refuses to construct
  outside SH_MCP_ENV=local and enforces audience binding (design.md §3, §6).
2026-06-26 12:48:26 -04:00

39 lines
983 B
JSON

{
"name": "@sh-mcp/shared",
"version": "0.1.0",
"type": "module",
"description": "Transport-agnostic core — types, registry, auth interface, redaction, OpenAPI generation",
"exports": {
".": {
"import": "./dist/index.js",
"types": "./dist/index.d.ts"
}
},
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
"engines": {
"node": ">=24.0.0"
},
"scripts": {
"build": "tsc --project tsconfig.json",
"typecheck": "tsc --noEmit --project tsconfig.json",
"test": "vitest run",
"test:watch": "vitest",
"test:coverage": "vitest run --coverage"
},
"devDependencies": {
"@types/express": "5.0.6",
"@types/supertest": "7.2.0",
"@vitest/coverage-v8": "^2.0.0",
"supertest": "7.2.2",
"typescript": "^5.5.0",
"vitest": "^2.0.0"
},
"dependencies": {
"@modelcontextprotocol/sdk": "1.29.0",
"ajv": "8.20.0",
"ajv-formats": "3.0.1",
"express": "5.2.1",
"jose": "^6.2.3"
}
}