Repository navigation
v1.8.3
Release v1.8.3
Release type: stable
Release line: 1.8.x
Branch: release/1.8.x
Installation
npm install @frontmcp/sdk@1.8.3What's New
CHANGELOG
Features
- Introduced
browserFetchfunction to simulate browser-like cookie handling in e2e tests, enhancing test accuracy for authentication flows. - Added support for
passthroughCallerTokenin OpenAPI adapter options, allowing the forwarding of the MCP client's token to APIs when no other credentials are available.
Improvements
- Updated OpenAPI security handling to include a more robust
securityResolverandauthProviderMapper, improving flexibility in authentication configuration. - Enhanced SaaS source schema with detailed verification logic for JWT tokens, ensuring secure and reliable token validation.
- Improved npm source handling by enforcing provenance checks, preventing unverified package loads unless explicitly overridden.
What's Changed
- fix(security): close OAuth and token gaps in local and remote auth by @frontegg-david in #613
- fix(security): enforce authorities on agents, templates and skills HTTP; reject rules that check nothing; keep CONTEXT providers per caller by @frontegg-david in #614
- fix(security): plugins and adapters: stop token passthrough, route CodeCall namespaces through the sandbox limits, enforce approval, feature-flag, skilled-openapi and dashboard settings by @frontegg-david in #615
- fix(security): follow-ups to #613, #614 and #615 (1/2): bind sign-ins to the browser, refuse unenforced plugin settings, serve the primary scope by @frontegg-david in #620
- fix(security): follow-ups to #613, #614 and #615 (2/2): bind Remember and elicitation to the verified caller, gate agents and surfaces by @frontegg-david in #616
Full Changelog: v1.8.2...v1.8.3