diff --git a/CHANGELOG.md b/CHANGELOG.md index 8e234658..d02ab8b8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,18 @@ All notable changes to the Nextcloud MCP Server will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [PEP 440](https://peps.python.org/pep-0440/). +## v0.120.5 (2026-06-17) + +### Fix + +- **auth**: clarify empty-allowlist startup warning when userinfo is configured +- **auth**: quiet per-validation userinfo TTL log; test introspection-timeout fall-through +- **auth**: document introspection-error fall-through, drop misleading userinfo metric +- **auth**: quiet cache-hit userinfo log, test real-exp userinfo path +- **auth**: harden userinfo fallback (anti-forgery, SSRF guard, unconfigured-introspection) +- **auth**: tighten userinfo-token cache TTL and metric labelling +- **auth**: validate opaque access tokens via userinfo fallback + ## v0.120.4 (2026-06-17) ### Fix diff --git a/pyproject.toml b/pyproject.toml index c53c4148..fbcb6fa4 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "nextcloud-mcp-server" -version = "0.120.4" +version = "0.120.5" description = "Model Context Protocol (MCP) server for Nextcloud integration - enables AI assistants to interact with Nextcloud data" authors = [ {name = "Chris Coutinho", email = "chris@coutinho.io"} diff --git a/uv.lock b/uv.lock index 0877d698..4b5eae60 100644 --- a/uv.lock +++ b/uv.lock @@ -2183,7 +2183,7 @@ wheels = [ [[package]] name = "nextcloud-mcp-server" -version = "0.120.4" +version = "0.120.5" source = { editable = "." } dependencies = [ { name = "aiosqlite" },