mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-11 20:19:51 +08:00
feat(mcp-server): serve the bundled draw.io same-origin behind an api token
GET /drawio/<path> serves dist/drawio with a MIME table, a day of caching and nosniff; paths are normalized and never reach WEB-INF or META-INF. The preview embeds /drawio/index.html when the copy exists and DRAWIO_BASE_URL is unset, else the external draw.io as before (and start_session says so). Every /api request must carry the per-process X-Drawio-Token the page gets in its HTML; pages send frame-ancestors 'self' and nosniff.
This commit is contained in:
@@ -12,6 +12,7 @@ const html = readFileSync(join(dir, "index.html"), "utf8")
|
||||
.replace("{{DRAWIO_URL}}", "about:blank")
|
||||
.replace("{{SESSION_JSON}}", '""')
|
||||
.replace("{{ORIGIN_JSON}}", '"https://embed.diagrams.net"')
|
||||
.replace("{{TOKEN_JSON}}", '"test-token"')
|
||||
const scripts = [...html.matchAll(/<script>([\s\S]*?)<\/script>/g)].map((m) =>
|
||||
m[1].replace("{{SCRIPT}}", ""),
|
||||
)
|
||||
|
||||
@@ -14,6 +14,7 @@ const html = readFileSync(join(dir, "index.html"), "utf8")
|
||||
.replace("{{DRAWIO_URL}}", "about:blank")
|
||||
.replace("{{SESSION_JSON}}", '"mcp-test"')
|
||||
.replace("{{ORIGIN_JSON}}", JSON.stringify(DRAWIO))
|
||||
.replace("{{TOKEN_JSON}}", JSON.stringify("test-token"))
|
||||
const scripts = [...html.matchAll(/<script>([\s\S]*?)<\/script>/g)].map((m) =>
|
||||
m[1].replace("{{SCRIPT}}", ""),
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user