github es617/obsidian-sync-mcp v0.7.2

latest release: v0.7.3
2 hours ago

Security

  • Credentials embedded in COUCHDB_URL are now redacted from all logs, at every level — including the raw Error objects the sync library logs — so user:pass@host no longer leaks into container logs (#37). Contributed by @bruno-b-martins.

Fixes

  • The static token and the OAuth password/CSRF comparisons hash both sides before the constant-time check, so a non-ASCII Authorization header or a missing password field now returns a clean 401 instead of throwing (previously a malformed 401 without WWW-Authenticate, or a 500) (#36). Contributed by @bruno-b-martins.
  • READ_ONLY is now enforced in the vault backend as well as by hiding the write tools, so a write can't slip through a code path that bypasses the tools (#38). Contributed by @bruno-b-martins.

CI

  • Workflows run with least-privilege permissions (read-only by default; publish jobs request only what they need), every action is pinned to a commit SHA, oxlint is pinned to a fixed version, and the published image gets a build-provenance attestation; a Dependabot config keeps the pins current (#42). Contributed by @bruno-b-martins.

Docs

  • SECURITY.md corrected to match the code: accurate token-persistence timing and CORS origins, and the metadata-index description now reflects reality (the stale FlexSearch and 50-match-cap text is gone) (#43). Contributed by @bruno-b-martins.

Don't miss a new obsidian-sync-mcp release

NewReleases is sending notifications on new releases.