Adds postinstall script to rebuild better-sqlite3 native bindings for the current Node.js version. Fixes ERR_DLOPEN_FAILED when installing via npx on a different Node version than was used to publish. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2.7 KiB
2.7 KiB
Changelog
All notable changes to this project are documented here. Format: Keep a Changelog
[Unreleased]
[1.0.1] - 2026-03-29
Fixed
better-sqlite3native module now rebuilt on install viapostinstallscript, fixing Node.js version mismatch errors (e.g. Node v22 vs v25) when installing via npx
[1.0.0] - 2026-03-29
Changed
- Renamed project from
@sanjibdevnath/mcp-excalidraw-localtoexcalidraw-mcp-sentinel - New npm package name:
excalidraw-mcp-sentinel(unscoped) - GitHub repo:
celstnblacc/excalidraw-mcp-sentinel - Docker images:
celstnblacc/excalidraw-mcp-sentinelandcelstnblacc/excalidraw-mcp-sentinel-canvas - CLI binary renamed:
excalidraw-mcp-sentinel - Version reset to 1.0.0 for independent release track
- Added "Why this fork?" section to README with full attribution
Removed
- Superseded planning docs (PLAN.md, PLAN_v2.md, REVIEW.md, HANDOFF.md)
[1.6.3] - 2026-03-29
Security
- Added
security.tsmiddleware module: helmet headers, explicit CORS allowlist, API key auth with timing-safe comparison, prototype pollution guard, Mermaid input size limits - WebSocket authentication: challenge-response (
auth_required→hello + apiKey) with 5 s timeout and close code 4001 on failure; origin verification viaverifyClient - Rate limiting on all
/api/*routes: 100 req/15 min general, 10 req/min destructive, 10 req/min sync write burst sanitizeSearchQuerynow throws typedInvalidSearchQueryErrorinstead of genericError- Docker: added
deploy.resources.limits(canvas 1 CPU/512M, mcp 0.5 CPU/256M) todocker-compose.yml; extended.dockerignorewithtests/and sensitive key file patterns
Fixed
POST /api/elements/sync: array validation now runs before logger access, preventing aTypeErrorcrash (500) on null/non-array input — now returns 400POST /api/elements/sync/v2: element type validated againstEXCALIDRAW_ELEMENT_TYPESbefore write; invalid types return 400 instead of being persisted silently- Upgraded
zodfrom 3.22.4 to 3.25.5 to resolveERR_PACKAGE_PATH_NOT_EXPORTEDcrash at MCP server startup caused byzod-to-json-schemapeer dependency mismatch
Changed
ElementSharedFieldsSchemaextracted fromCreateElementSchema/UpdateElementSchemato eliminate 25-field duplication; both schemas now use.extend()VALID_ELEMENT_TYPESmoved to module-level constant (was allocated per-request)resolveHelloTenantAndProjectparameter typed asHelloMessage(wasany)getAllFilesObject()helper extracted;sendFilesAdded()andGET /api/filesshare itsendLegacyInitialWsMessagesrenamed tosendAuthlessInitialMessages.project-hooks/pre-commitadded to run vitest on every commit