Skip to content

v2.12.0

Choose a tag to compare

@github-actions github-actions released this 30 May 06:24
3c8ec0d

What's Changed

Security

  • list_resources masks webhook secrets and basic-auth credentials by default (#204) — when system({ action: 'list_resources', include_full: true }) is called, the per-resource fields manual_webhook_secret_github / manual_webhook_secret_gitlab / manual_webhook_secret_gitea / manual_webhook_secret_bitbucket and http_basic_auth_password are now replaced with '***' so an MCP client / LLM granted "list resources" cannot silently exfiltrate webhook HMAC signing keys or front-of-app passwords. Pass reveal: true alongside include_full: true to round-trip plaintext. Mirrors the v2.9.0 env_vars masking posture from #159 / #182. Applied at the API boundary in listResources() so any other code path also inherits masking by default.

Fixed

  • system list_resources returns essential projection by default (#203) — previously typed as Promise<ResourceListItem[]> but actually returned the full Coolify /api/v1/resources payload (~95 fields per row, ~16 KB per item, 500+ KB on instances with 30+ resources) which blew MCP token budgets and made the tool unusable for LLM-driven workflows. Now defaults to a true { uuid, name, type, status? } projection applied at the API boundary. Set include_full: true to opt back into the raw Coolify payload. Mirrors the include_logs opt-in pattern from #158.
  • is_build_time typo bleed-in from #172 (#205) — test mock at src/__tests__/coolify-client.test.ts:4335 and the [2.11.0] CHANGELOG entry both referenced the wrong underscored field name (is_build_time). The correct name is is_buildtime (one word) per #174 / v2.9.0; runtime code was already correct, this is doc + test-mock cleanup only.
  • toResourceListItemEssential guards status with typeof — replaces an unchecked item.status as string cast. If a future Coolify version emits status as an object/null, the field is now dropped from the essential projection instead of silently violating the ResourceListItem interface.

Changed (breaking, typed-only)

  • listResources signature (#203, #204): Promise<ResourceListItem[]>Promise<ResourceListItem[] | ResourceListItemFull[]> with new optional options?: { include_full?: boolean; reveal?: boolean } parameter. Programmatic consumers of @masonator/coolify-mcp will need to widen their result type (or narrow at the call site with include_full). Note: the previous type was wrong-at-runtime against real Coolify (claimed 4 fields, returned ~95), so any caller that worked end-to-end was already accommodating the bloated shape.

Added (types)

  • ResourceListItemFull typeResourceListItem & Record<string, unknown>. Surfaces only when include_full: true is passed; documents that the full Coolify row carries arbitrary additional fields beyond the typed essentials.

📦 View on npm