Reset core/viewer/editor/mcp packages and apps/editor from private-editor
Wholesale swap of packages/{core,viewer,editor,mcp} and apps/editor with the
versions from the private editor repo, which is the production source of truth.
Setup changes:
- packages/{core,viewer,editor} versions held at 0.7.0 baseline (matching
the most recent published release) so a bump=minor publishes 0.8.0
- packages/mcp held at 0.1.1 (never published; first publish will go through
the new release.yml flow)
- peerDependencies and devDependencies for inter-package @pascal-app/*
references pinned to ^0.7.0 instead of '*' / 'workspace:*' so they are
valid for npm consumers
- Root package.json: TypeScript bumped to 6.0.2, added overrides for
@types/react, @types/react-dom, @types/three to prevent JSX namespace
fragmentation across the workspace
- release.yml extended to also publish editor and mcp; 'both' option renamed
to 'all'; added a sync step that updates inter-package peerDeps/devDeps to
match the new versions on every bump (so viewer/editor/mcp tarballs always
reference the version of core they were built against)
- Root scripts gained release:editor and release:mcp shortcuts
Verification:
- bun install --frozen-lockfile is consistent
- packages/{core,viewer,mcp} build cleanly, dist/index.d.ts emitted
- packages/editor check-types reports 21 pre-existing errors, identical to
what private-editor currently reports
Open PRs against editor-v2 will need rebasing/conflict resolution.
This commit is contained in:
@@ -52,7 +52,7 @@ export async function connectHttp(
|
||||
): Promise<HttpTransportHandle> {
|
||||
const host = options.host ?? DEFAULT_HOST
|
||||
const authToken = options.authToken ?? process.env.PASCAL_MCP_HTTP_TOKEN
|
||||
if (!isLoopbackHost(host) && !authToken) {
|
||||
if (!(isLoopbackHost(host) || authToken)) {
|
||||
throw new Error(
|
||||
'HTTP transport on a non-loopback host requires PASCAL_MCP_HTTP_TOKEN or authToken',
|
||||
)
|
||||
@@ -149,7 +149,7 @@ function createHttpGuard(options: {
|
||||
|
||||
if (options.authToken) {
|
||||
const supplied = bearerToken(req) ?? headerValue(req.headers['x-pascal-mcp-token'])
|
||||
if (!supplied || !safeEqual(supplied, options.authToken)) {
|
||||
if (!(supplied && safeEqual(supplied, options.authToken))) {
|
||||
sendJson(res, 401, { error: 'unauthorized' })
|
||||
return false
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user