chore: release v1.0.2
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
d073b6348d
commit
d1689a2e5c
+22
-16
@@ -5,28 +5,34 @@ Format: [Keep a Changelog](https://keepachangelog.com/en/1.0.0/)
|
|||||||
|
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
|
## [1.0.2] - 2026-03-30
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
- `frontend/src/utils/scenePreparation.ts` with scene-preparation utilities (`expandLabelsToNative`, `prepareElementsForScene`, `convertElementsPreservingImageProps`)
|
- `frontend/src/utils/scenePreparation.ts` — centralized scene-preparation utilities (`expandLabelsToNative`, `prepareElementsForScene`, `convertElementsPreservingImageProps`)
|
||||||
- Backend tests: `tests/backend/db-unit.test.ts`, `tests/backend/mcp-contract.test.ts`, `tests/backend/mcp-sanitization.test.ts`, `tests/backend/security-unit.test.ts`, `tests/backend/smoke-ws.test.ts`, `tests/backend/tenant-authz-behavior.test.ts`
|
- E2E regression suite: `tests/e2e/phase2-regressions.spec.ts` (4 tests: position stability, auto-title, two-tab sync, curved arrow deformability)
|
||||||
- Frontend test: `tests/frontend/scene-preparation.test.ts`
|
- Backend tests: `db-unit`, `mcp-contract`, `mcp-sanitization`, `security-unit`, `smoke-ws`, `tenant-authz-behavior`
|
||||||
- E2E regression suite: `tests/e2e/phase2-regressions.spec.ts`
|
- Frontend tests: `scene-preparation`, `helpers`, `sync-logic`
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
- `computeElementHash` is now order-stable for equivalent element sets
|
- `computeElementHash` is now order-stable for equivalent element sets
|
||||||
- `frontend/src/App.tsx` now uses centralized scene-preparation utilities for label expansion and native-vs-converted routing
|
- `frontend/src/App.tsx` uses centralized scene-preparation utilities for label expansion and native-vs-converted routing
|
||||||
- Documentation test counts updated to `443`
|
- Rate limits raised: general 100→500 req/15min, write burst 10→30 req/min
|
||||||
|
- MCP unknown tool calls now return JSON-RPC `MethodNotFound` (-32601) instead of generic error
|
||||||
|
- Test count: 446/446
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
- MCP unknown tool calls now return JSON-RPC `MethodNotFound` (`-32601`)
|
- **Double WebSocket connection race** — second WS created during `CONNECTING` state seeded `knownContainerIdsRef` prematurely, blocking title auto-injection; guard now also blocks `CONNECTING` state
|
||||||
- `import_scene` now enforces dangerous-key checks on parsed scene payloads before processing
|
- **Title/subtitle not injected for WS-delivered containers** — `CaptureUpdateAction.NEVER` suppresses `onChange`; `handleCanvasChange()` now called explicitly after `element_created`
|
||||||
- Double WebSocket connection race: guard now also blocks `CONNECTING` state, preventing a second WS from seeding `knownContainerIdsRef` prematurely
|
- **Text alignment lost after sync** — `ElementSharedFieldsSchema` did not declare `textAlign`, `verticalAlign`, `containerId`; Zod silently stripped these on every REST round-trip
|
||||||
- Title/subtitle auto-injection for WS-delivered container elements: `handleCanvasChange()` now called explicitly after `element_created` updates scene (Excalidraw's `CaptureUpdateAction.NEVER` suppresses the `onChange` callback)
|
- **Curved arrow deforms after sync** — element replace strategy discarded Excalidraw-internal control point state; now merges incoming over existing
|
||||||
- Curved arrow control points remain deformable after sync round-trip (merge strategy preserves Excalidraw internals)
|
- **MCP `import_scene` prototype pollution** — `assertNoDangerousKeys()` now called on all parsed JSON payloads (MCP stdio bypasses Express middleware)
|
||||||
- E2E: `curved arrow stays deformable after sync round-trip` regression test passing
|
- **FTS5 colon column-filter injection** — `:` added to blocked character set in `sanitizeSearchQuery`
|
||||||
- `textAlign`, `verticalAlign`, `containerId` added to `ElementSharedFieldsSchema` in `server.ts` — Zod was silently stripping these fields on every REST round-trip, causing bound text to lose centering after sync
|
- **Global state race in `createProject`/`listProjects`** — explicit `tenantId?` param added; MCP callers pass captured ID at call time
|
||||||
- `ServerElement` type updated with `textAlign?`, `verticalAlign?`, `containerId?` to match schema
|
- Subtitle elements in MCP `create_element` now set `textAlign: "center"` and `verticalAlign: "top"`
|
||||||
- Subtitle element in MCP `create_element` now sets `textAlign: "center"` and `verticalAlign: "top"`
|
- `ServerElement` type updated with `textAlign?`, `verticalAlign?`, `containerId?`
|
||||||
- E2E: `new container arrival auto-injects title and subtitle text` now reliably passes with the double-WS fix
|
- `pendingTitleTimerRef` now cleaned up on component unmount (prevented stale closure after unmount)
|
||||||
|
- `localStorage` JSON.parse for widget position wrapped in try/catch (malformed value no longer crashes component)
|
||||||
|
- Docker `LABEL org.opencontainers.image.source` corrected to fork URL
|
||||||
|
|
||||||
## [1.0.1] - 2026-03-29
|
## [1.0.1] - 2026-03-29
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "excalidraw-mcp-sentinel",
|
"name": "excalidraw-mcp-sentinel",
|
||||||
"version": "1.0.1",
|
"version": "1.0.2",
|
||||||
"description": "Hardened, self-hosted Excalidraw MCP server with SQLite persistence, multi-tenancy, auto-sync, security middleware, and 369 tests",
|
"description": "Hardened, self-hosted Excalidraw MCP server with SQLite persistence, multi-tenancy, auto-sync, security middleware, and 369 tests",
|
||||||
"main": "dist/index.js",
|
"main": "dist/index.js",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
|
|||||||
Reference in New Issue
Block a user