Summary
This release hardens deployments and trims what reaches the model. SSO deployments can now switch off local username/password login entirely, database deployments can reconcile declarative settings on every startup, and smart routing returns configurable, much smaller tool definitions — with the new default cutting a typical search response by roughly half. On the reliability side, concurrent JSON settings updates no longer overwrite each other, remote keepalive recovers after a tool-call reconnect, stdio buffer limits are configurable, and pending OAuth authorizations no longer produce false state-expired rejections.
Features
- Disable username/password login while an SSO provider is enabled (
betterAuth.disablePasswordLogin), removing the weaker second sign-in path from SSO-only deployments, withBETTER_AUTH_DISABLE_PASSWORD_LOGINas the recovery override by @SelfRef in #1289 - Configure which MCP tool fields
search_toolsanddescribe_toolreturn (smartRouting.toolDefinitionFields); the newtitle+annotationsdefault cuts a typical search response by roughly half by @SelfRef in #1286 - Reconcile declarative
mcp_settings.jsonservers and groups on every startup in database mode with the opt-inMCPHUB_SETTINGS_SYNC=upsertby @samanhappy in #1285
Fixes
- Prevent concurrent JSON DAO settings updates from overwriting each other by @samanhappy in #1279
- Patch vulnerable transitive dependencies by @samanhappy in #1280
- Restore remote server keepalive after a tool-call reconnect by @samanhappy in #1281
- Allow configuring stdio response buffer limits for servers that return large payloads by @samanhappy in #1284
- Sync
serverInfo.configwith a pending OAuth authorization so valid requests are no longer rejected as state-expired by @Rahulsharma0810 in #1290 - Treat an idle on-demand server as available in the
search_toolsserver list, search scope anddescribe_toolby @SelfRef in #1287
摘要
本版本重点加强部署安全与精简模型上下文。SSO 部署现在可以完全关闭本地用户名/密码登录;数据库部署可在每次启动时同步声明式配置;智能路由返回的工具定义字段可配置,新的默认值使典型搜索结果体积减少约一半。稳定性方面,并发的 JSON 配置更新不再相互覆盖,工具调用重连后远程 keepalive 恢复正常,stdio 响应缓冲区上限可配置,待授权的 OAuth 状态也不再误报 state 过期。
功能
- SSO 部署可关闭用户名/密码登录(
betterAuth.disablePasswordLogin),消除较弱的第二登录入口,并可用BETTER_AUTH_DISABLE_PASSWORD_LOGIN在身份提供商故障时恢复 by @SelfRef in #1289 - 可配置
search_tools与describe_tool返回的 MCP 工具字段(smartRouting.toolDefinitionFields),新的title+annotations默认值使典型搜索结果体积减少约一半 by @SelfRef in #1286 - 数据库模式下可通过
MCPHUB_SETTINGS_SYNC=upsert在每次启动时同步声明式mcp_settings.json中的服务器与分组 by @samanhappy in #1285
修复
- 修复并发的 JSON DAO 配置更新相互覆盖的问题 by @samanhappy in #1279
- 更新存在漏洞的间接依赖 by @samanhappy in #1280
- 修复工具调用重连后远程服务器 keepalive 未恢复的问题 by @samanhappy in #1281
- 可通过配置调整 stdio 响应缓冲区上限,以支持返回大响应的服务器 by @samanhappy in #1284
- 修复 OAuth 待授权状态下
serverInfo.config未同步、导致正常请求被误判为 state 过期的问题 by @Rahulsharma0810 in #1290 - 修复智能路由把空闲的按需服务器误判为不可用的问题(
search_tools服务器列表、搜索范围与describe_tool) by @SelfRef in #1287
References
- fix: sync serverInfo.config with pending OAuth authorization to avoid false state-expired rejections by @Rahulsharma0810 in #1290
- feat(auth): option to disable username/password login while an SSO provider is enabled by @SelfRef in #1289
- fix(smart-routing): treat an idle on-demand server as available in the search_tools server list, search scope and describe_tool by @SelfRef in #1287
- feat(smart-routing): make the tool fields in search_tools and describe_tool results configurable, defaulting to title and annotations by @SelfRef in #1286
- feat: sync declarative database settings on startup by @samanhappy in #1285
- fix: allow configuring stdio response buffer limits by @samanhappy in #1284
- fix: restore remote keepalive after tool-call reconnect by @samanhappy in #1281
- fix(deps): patch vulnerable transitive dependencies by @samanhappy in #1280
- fix: prevent JSON DAO settings updates from overwriting each other by @samanhappy in #1279
- Full changelog: v1.1.0...v1.1.1