Summary
This release strengthens server configuration isolation, adds conservative cache hints for modern MCP clients, and improves dashboard editing and readability. Ordinary-user server configuration no longer expands service-process environment values, and authorization metadata remains literal.
Features
- Add private cache scope and conservative TTL hints for modern MCP responses.
- Document MCP protocol compatibility and migration, and clarify PostgreSQL connection-pool sizing.
Fixes
- Isolate server configuration environment expansion according to the owner's live privileges, including HTTP/SSE headers and reconnect paths (GHSA-547h-r8jj-9wmc).
- Preserve individual stdio arguments, including spaces, quotes, backslashes, and empty values, in the server editor.
- Improve dark-mode contrast for notices, upload states, and Toast controls.
摘要
本版本加强服务配置隔离,为现代 MCP 客户端增加保守的缓存提示,并改善管理界面的参数编辑和可读性。普通用户的服务配置不再展开服务进程环境变量,授权元数据保持原始字面值。
功能
- 为现代 MCP 响应增加私有缓存范围和保守的 TTL 提示。
- 完善 MCP 协议兼容性与迁移文档,并说明 PostgreSQL 连接池容量的计算方式。
修复
- 根据所有者的实时权限隔离服务配置中的环境变量展开,覆盖 HTTP/SSE 请求头和重连路径(GHSA-547h-r8jj-9wmc)。
- 服务编辑器保留每个 stdio 参数的边界,包括空格、引号、反斜杠和空参数。
- 改善深色模式下提示信息、上传状态和 Toast 控件的对比度。
References
- fix: improve dark-mode contrast for notices and upload states by @samanhappy in #1265
- docs(config): clarify that DB_POOL_SIZE is a per-pool limit by @FBISiri in #1266
- feat(mcp): add conservative modern cache hints by @samanhappy in #1267
- docs(mcp): document protocol compatibility and migration by @samanhappy in #1268
- fix: preserve stdio argument boundaries in server editor by @samanhappy in #1269
- fix(security): isolate server configuration environment by @samanhappy in #1270
- Full changelog: v1.0.45...v1.0.46