fix: bind MCP server HTTP to 127.0.0.1 only (#787)

The embedded HTTP sidecar was using server.listen(port) without a host
argument, which defaults to 0.0.0.0 (all interfaces). This exposed the
server to the local network. Now explicitly binds to 127.0.0.1.

Also excludes release/ from tsconfig to fix pre-existing TS errors.

Bumps @next-ai-drawio/mcp-server to 0.1.18.
This commit is contained in:
Dayuan Jiang
2026-04-06 09:04:38 +09:00
committed by GitHub
parent f593901fee
commit 41c410c2ba
3 changed files with 4 additions and 3 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@next-ai-drawio/mcp-server",
"version": "0.1.17",
"version": "0.1.18",
"description": "MCP server for Next AI Draw.io - AI-powered diagram generation with real-time browser preview",
"type": "module",
"main": "dist/index.js",
+1 -1
View File
@@ -155,7 +155,7 @@ export function startHttpServer(port = 6002): Promise<number> {
}
})
server.listen(port, () => {
server.listen(port, "127.0.0.1", () => {
serverPort = port
log.info(`HTTP server running on http://localhost:${port}`)
resolve(port)
+2 -1
View File
@@ -35,6 +35,7 @@
"packages",
"electron",
"electron-standalone",
"dist-electron"
"dist-electron",
"release"
]
}