Skip to content

v1.8.3

Choose a tag to compare

@github-actions github-actions released this 28 Sep 08:53
· 106 commits to main since this release

Release v1.8.3

Release type: stable
Release line: 1.8.x
Branch: release/1.8.x

Installation

npm install @frontmcp/sdk@1.8.3

What's New

CHANGELOG

Features

  • Introduced browserFetch function to simulate browser-like cookie handling in e2e tests, enhancing test accuracy for authentication flows.
  • Added support for passthroughCallerToken in OpenAPI adapter options, allowing the forwarding of the MCP client's token to APIs when no other credentials are available.

Improvements

  • Updated OpenAPI security handling to include a more robust securityResolver and authProviderMapper, improving flexibility in authentication configuration.
  • Enhanced SaaS source schema with detailed verification logic for JWT tokens, ensuring secure and reliable token validation.
  • Improved npm source handling by enforcing provenance checks, preventing unverified package loads unless explicitly overridden.

What's Changed

  • fix(security): close OAuth and token gaps in local and remote auth by @frontegg-david in #613
  • fix(security): enforce authorities on agents, templates and skills HTTP; reject rules that check nothing; keep CONTEXT providers per caller by @frontegg-david in #614
  • fix(security): plugins and adapters: stop token passthrough, route CodeCall namespaces through the sandbox limits, enforce approval, feature-flag, skilled-openapi and dashboard settings by @frontegg-david in #615
  • fix(security): follow-ups to #613, #614 and #615 (1/2): bind sign-ins to the browser, refuse unenforced plugin settings, serve the primary scope by @frontegg-david in #620
  • fix(security): follow-ups to #613, #614 and #615 (2/2): bind Remember and elicitation to the verified caller, gate agents and surfaces by @frontegg-david in #616

Full Changelog: v1.8.2...v1.8.3