Skip to content

liongard-v0.1.2

Choose a tag to compare

@github-actions github-actions released this 27 Aug 00:41
· 6 commits to main since this release

Fixed

  • An agent could point this connector's local database at any file on the machine.
    The MCP server forwarded a db argument straight through to sync, and the store runs a
    migration that drops and rebuilds its tables. A tool call naming another application's SQLite
    file would therefore rewrite that file. The MCP surface now refuses arguments that name a
    filesystem location - by name, and by what the flag's own help text says it does, so a newly
    generated path flag is refused before anyone has to notice it. Nothing an agent could
    legitimately call changed.

  • LIONGARD_ACCESS_KEY_ID and LIONGARD_ACCESS_KEY_SECRET were ignored, so every call went out
    unauthenticated.
    Liongard hands you an Access Key ID and an Access Key Secret and never shows
    the encoded form the API actually wants, and the README, the SKILL and the guide all tell you to
    export those two variables. The config loader read neither: it only ever looked for a
    pre-encoded LIONGARD_API_KEY, so an operator who followed the shipped instructions got an empty
    X-ROAR-API-KEY header and a 401 on every command, with nothing in doctor naming the cause.
    The loader composes the pair into base64 of accessKeyId:accessKeySecret again, as it did when
    the connector first shipped; a pre-encoded LIONGARD_API_KEY still wins when both are set.
    Both variables are now declared on all three install channels, so Claude Desktop asks for them
    and the copy-paste MCP config blocks carry them. LIONGARD_API_KEY is no longer marked required
    in manifest.json or server.json either: while it was, the MCPB bundle and the registry
    install both forced a value into it, and because the pre-encoded key wins the ID/secret pair
    stayed dead through every official install no matter what the docs said. All three fields now
    state the one-of contract - set the key or set the pair, never both - and the install pages show
    the two setups separately instead of one line that sets all three at once.

Changed

  • Every source file now carries one project copyright line (Copyright 2026 Servosity Inc. and msp-skills contributors) instead of the ten different strings the fleet had accumulated; individual contributor credit moved to the repository NOTICE. Source headers only, no behaviour changed.