* ci: publish accounted-mcp and gnubok-mcp to npm when their version changes accounted-mcp has never been published (npm view is E404) although every "connect Claude" doc says `npx -y accounted-mcp`, and gnubok-mcp is at 1.0.1 on the registry while the repo has carried 1.1.0 since #706. No workflow published to npm; this adds one. .github/workflows/npm-publish.yml runs on a push to main that touches a packages/*/package.json, and on workflow_dispatch (package: all or one, plus a dry_run that packs and validates without touching the registry). One matrix job per package: it fails first with a message naming the NPM_TOKEN secret if it is absent, then compares the package.json version with `npm view <name> versions` (E404 counts as "never published", any other failure is an error), skips when the version is already on the registry, and otherwise runs `npm publish --provenance --access public`. Permissions are contents: read plus id-token: write for the provenance attestation. Actions are pinned to the same SHAs as the sibling workflows. npm rejects a provenance attestation whose package.json repository.url does not match the source repository, and gnubok-mcp still pointed at erp-mafia/gnubok, so both repository fields now name erp-mafia/accounted in npm's canonical form with the monorepo directory. `npm pkg fix` normalised the bin paths, and accounted-mcp's index.mjs gets the executable bit gnubok-mcp's already had. Versions are not bumped. Both READMEs get a Releasing section: bump version, merge to main, the workflow publishes; the NPM_TOKEN repository secret must exist. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Signed-off-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> * fix(packages): keep the ./index.mjs bin form the package tests pin Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci(npm-publish): scope NPM_TOKEN to the publish step and keep the matrix static The token was job-level env, visible to checkout, setup-node and the version gate; it now reaches only npm publish. The matrix no longer interpolates the workflow_dispatch input into an expression: both packages always get a job and a Select step skips the one not requested. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Signed-off-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
169 lines
4.7 KiB
JavaScript
Executable File
169 lines
4.7 KiB
JavaScript
Executable File
#!/usr/bin/env node
|
|
/**
|
|
* accounted-mcp: Connect an MCP client to your Accounted bookkeeping account.
|
|
*
|
|
* Usage in claude_desktop_config.json:
|
|
* {
|
|
* "mcpServers": {
|
|
* "accounted": {
|
|
* "command": "npx",
|
|
* "args": ["-y", "accounted-mcp"],
|
|
* "env": {
|
|
* "ACCOUNTED_API_KEY": "gnubok_sk_..."
|
|
* }
|
|
* }
|
|
* }
|
|
* }
|
|
*/
|
|
|
|
const API_KEY = process.env.ACCOUNTED_API_KEY
|
|
const DEFAULT_MCP_URL =
|
|
'https://app.accounted.se/api/extensions/ext/mcp-server/mcp'
|
|
|
|
function resolveMcpUrl(rawUrl) {
|
|
try {
|
|
const url = new URL(rawUrl)
|
|
if (url.protocol !== 'http:' && url.protocol !== 'https:') {
|
|
throw new Error('unsupported protocol')
|
|
}
|
|
if (!url.searchParams.has('tool_namespace')) {
|
|
url.searchParams.set('tool_namespace', 'accounted')
|
|
}
|
|
return url.toString()
|
|
} catch {
|
|
process.stderr.write('accounted-mcp: ACCOUNTED_URL must be a valid HTTP(S) URL\n')
|
|
process.exit(1)
|
|
}
|
|
}
|
|
|
|
const MCP_URL = resolveMcpUrl(process.env.ACCOUNTED_URL || DEFAULT_MCP_URL)
|
|
|
|
// Optional distribution-channel marker (for example, "claude-desktop").
|
|
// Forwarded for telemetry only and never used for authentication or behavior.
|
|
const rawClient = process.env.ACCOUNTED_CLIENT
|
|
const CLIENT =
|
|
rawClient && /^[A-Za-z0-9._-]{1,64}$/.test(rawClient) ? rawClient : undefined
|
|
if (rawClient && !CLIENT) {
|
|
process.stderr.write(
|
|
'accounted-mcp: ignoring ACCOUNTED_CLIENT: must match [A-Za-z0-9._-]{1,64}\n'
|
|
)
|
|
}
|
|
|
|
if (!API_KEY) {
|
|
process.stderr.write(
|
|
'Error: ACCOUNTED_API_KEY is required.\n' +
|
|
'Get your API key at: https://app.accounted.se/settings/api\n' +
|
|
'\n' +
|
|
'No API key (or no account yet)? Connect over OAuth instead; the sign-in\n' +
|
|
'screen lets you create the account, and setup continues in the chat:\n' +
|
|
' claude mcp add --transport http accounted \\\n' +
|
|
' "https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted"\n' +
|
|
' codex mcp add accounted --url \\\n' +
|
|
' "https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted"\n' +
|
|
' Claude.ai / Desktop: Settings > Connectors > Add custom connector with that URL.\n' +
|
|
'\n' +
|
|
'Add it to your Claude Desktop config:\n' +
|
|
'{\n' +
|
|
' "mcpServers": {\n' +
|
|
' "accounted": {\n' +
|
|
' "command": "npx",\n' +
|
|
' "args": ["-y", "accounted-mcp"],\n' +
|
|
' "env": {\n' +
|
|
' "ACCOUNTED_API_KEY": "gnubok_sk_..."\n' +
|
|
' }\n' +
|
|
' }\n' +
|
|
' }\n' +
|
|
'}\n'
|
|
)
|
|
process.exit(1)
|
|
}
|
|
|
|
let buffer = ''
|
|
|
|
process.stdin.setEncoding('utf8')
|
|
process.stdin.on('data', (chunk) => {
|
|
buffer += chunk
|
|
|
|
let newlineIdx
|
|
while ((newlineIdx = buffer.indexOf('\n')) !== -1) {
|
|
const line = buffer.slice(0, newlineIdx).trim()
|
|
buffer = buffer.slice(newlineIdx + 1)
|
|
|
|
if (!line) continue
|
|
|
|
handleMessage(line).catch((err) => {
|
|
process.stderr.write(`accounted-mcp error: ${err.message}\n`)
|
|
})
|
|
}
|
|
})
|
|
|
|
process.stdin.on('end', () => {
|
|
process.exit(0)
|
|
})
|
|
|
|
async function handleMessage(line) {
|
|
let parsed
|
|
try {
|
|
parsed = JSON.parse(line)
|
|
} catch {
|
|
process.stderr.write('accounted-mcp: invalid JSON\n')
|
|
return
|
|
}
|
|
|
|
const isNotification = parsed.id === undefined || parsed.id === null
|
|
|
|
try {
|
|
const res = await fetch(MCP_URL, {
|
|
method: 'POST',
|
|
headers: {
|
|
'Content-Type': 'application/json',
|
|
Authorization: `Bearer ${API_KEY}`,
|
|
...(CLIENT ? { 'X-Accounted-Client': CLIENT } : {}),
|
|
},
|
|
body: line,
|
|
})
|
|
|
|
if (res.status === 202 || res.status === 204) {
|
|
return
|
|
}
|
|
|
|
const responseText = await res.text()
|
|
|
|
// Guard against non-JSON error responses such as CDN or proxy pages.
|
|
if (!res.ok && !isNotification) {
|
|
let message = `HTTP ${res.status}`
|
|
try {
|
|
const json = JSON.parse(responseText)
|
|
if (json.error) {
|
|
message =
|
|
typeof json.error === 'string'
|
|
? json.error
|
|
: JSON.stringify(json.error)
|
|
}
|
|
} catch {
|
|
// The body was not JSON: use the generic HTTP status message.
|
|
}
|
|
const errorResponse = JSON.stringify({
|
|
jsonrpc: '2.0',
|
|
id: parsed.id,
|
|
error: { code: -32000, message },
|
|
})
|
|
process.stdout.write(`${errorResponse}\n`)
|
|
return
|
|
}
|
|
|
|
if (responseText) {
|
|
process.stdout.write(`${responseText}\n`)
|
|
}
|
|
} catch (err) {
|
|
if (!isNotification) {
|
|
const errorResponse = JSON.stringify({
|
|
jsonrpc: '2.0',
|
|
id: parsed.id,
|
|
error: { code: -32000, message: `Connection error: ${err.message}` },
|
|
})
|
|
process.stdout.write(`${errorResponse}\n`)
|
|
}
|
|
}
|
|
}
|