Skip to content

Releases: cego/bookstack-mcp-server

v2.1.0-r3

Choose a tag to compare

@gusocegodk gusocegodk released this 07 Oct 08:50
3ead323

Comment, import and tag tools, and ZIP export.

New tools (71 in total)

  • Comments, BookStack v25.11+: bookstack_comments_list, _create, _read, _update, _delete. Covers replies and archiving.
  • Imports, v25.07+: bookstack_imports_list, _create, _read, _run, _delete. Upload a portable ZIP and run it into a book or chapter.
  • Tags, v26.05+: bookstack_tags_list_names and bookstack_tags_list_values.
  • ZIP export: a zip format on the book, chapter and page export tools, returned base64.

Changes

  • Uploads are capped at 50000 KB in this server, for both base64 content and file_path. A refused upload is reported as a validation error.
  • The README describes the fork, with per-user OAuth as its primary usage.

Image

ghcr.io/cego/bookstack-mcp-server:2.1.0-r3@sha256:362df728674961ca07723ed3acbc0dbb189d2a5d752e0af1a117ccc368ab2762

linux/amd64, with provenance and an SBOM.

v2.1.0-r2

Choose a tag to compare

@gusocegodk gusocegodk released this 06 Oct 11:40
716c1de

Security and correctness fixes from a full-codebase review.

Security

  • x-bookstack-url must be on BOOKSTACK_ALLOWED_BASE_URLS and come with x-bookstack-token. The configured token is never sent to a host the caller picks, and redirects are no longer followed.
  • file_path uploads need BOOKSTACK_UPLOAD_ROOT under every transport.
  • Page parsing runs in linear time (ReDoS fix).
  • Errors returned to callers carry no stack traces or server paths.
  • axios is now 1.20.0.

Correctness

  • Page sections skip fenced code, include their subsections, and report the heading they matched.
  • grep context can be used as old_string.
  • Tool failures are isError results the model can read. Resource templates are listed via resources/templates/list. GET/DELETE /message answers 405.
  • Network failures on read requests are retried and reported clearly.

Breaking changes

  • x-bookstack-url requires BOOKSTACK_ALLOWED_BASE_URLS and x-bookstack-token.
  • stdio file_path requires BOOKSTACK_UPLOAD_ROOT.
  • Tool errors are isError results instead of JSON-RPC errors.
  • Templated resources moved to resources/templates/list.

Image

ghcr.io/cego/bookstack-mcp-server:2.1.0-r2@sha256:7719340115df7e58ccc9b01b7af4b0c418b0a07558498b8e8710a08100e9952d

linux/amd64, with provenance and an SBOM.

v2.1.0-r1

Choose a tag to compare

@gusocegodk gusocegodk released this 06 Oct 09:35
12733e3

Upstream 2.1.0 plus per-user OAuth for the HTTP transport.

Changes

  • MCP_AUTH_MODE=oauth makes the HTTP transport an OAuth resource server (MCP authorization spec 2025-11-25). Each user signs in with an OIDC provider, and BookStack acts as that user.
  • Access tokens are checked against the issuer's published keys and bound to this server's audience. Each one is exchanged (RFC 8693) for a BookStack token; the token the MCP client sent is never forwarded.
  • Images are tagged <version>-r<revision>, and are built, smoke-tested and pushed on release tags.

Image

ghcr.io/cego/bookstack-mcp-server:2.1.0-r1@sha256:a5314db3bdbc111020b3c4cd69eb976691614d212a489fc59770cffb8f5415aa

linux/amd64, with provenance and an SBOM. Configuration: see "Per-user OAuth" in the README.