UNPKG

open-meteo-mcp-server

Version:

Model Context Protocol server for Open-Meteo weather APIs

52 lines 2.53 kB
import type { NextFunction, Request, Response } from 'express'; /** * Generates a cryptographically secure session ID using the Web Crypto API * (built-in since Node.js 14.17). Never use Math.random() for session IDs. */ export declare function generateSessionId(): string; /** * Express middleware that enforces API key authentication when the API_KEY * environment variable is set. When API_KEY is not configured, all requests * are allowed through (development/local mode). * * Accepts the key via: * - Authorization: Bearer <key> * - X-API-Key: <key> */ export declare function createAuthMiddleware(): (req: Request, res: Response, next: NextFunction) => void; /** * Express middleware guarding against DNS rebinding attacks: without it, a page * served from any website can drive a locally bound MCP server through the * victim's browser. * * Requests carrying no `Origin` header — CLI clients, SDK transports, container * probes — pass through untouched. A request that does carry one is browser-issued * and must match the ALLOWED_ORIGINS allow-list (comma-separated), which is empty * by default: no browser is expected to talk to this server unless configured. */ export declare function createOriginValidator(): (req: Request, res: Response, next: NextFunction) => void; /** * The MCP spec requires clients to accept both application/json and * text/event-stream; clients sending `*\/*` or a single type are otherwise * rejected with a 406. This widens the header on their behalf. * * Crucially it rewrites `rawHeaders` and not just `req.headers`: the SDK hands * the request to Hono's `getRequestListener`, which rebuilds the web-standard * Request from Node's raw header array, so mutating the parsed object alone is * invisible to the transport. */ export declare function createAcceptNormalizer(): (req: Request, _res: Response, next: NextFunction) => void; /** * Returns a safe, generic error message for HTTP responses. * Never expose internal error details (stack traces, connection strings, * internal hostnames) to clients. */ export declare function sanitizeErrorMessage(_err: unknown): string; export declare function getClientIp(req: Request): string; /** * Creates an express-rate-limit middleware. * Reads RATE_LIMIT_RPM from env (default: 60 requests per minute). * Uses trusted-proxy-aware IP extraction for the key. */ export declare function createRateLimiter(): import("express-rate-limit").RateLimitRequestHandler; //# sourceMappingURL=security.d.ts.map