mirror of
https://github.com/supermemoryai/supermemory.git
synced 2026-08-28 05:25:33 +00:00
Cherry-picks #1582, #1583, #1584 and #1585 from @Sravanjangam (security audit #1578) onto one branch. - MCP: `get_document` scopes to the active space like its sibling read tools, `fetch-graph-data` bounds page/limit, `guided-save` caps prefill at 200k, and `whoAmI` no longer returns the transport session id. - ai-sdk: search limit clamped to 1-50 with a 30s client timeout. - validation: caps on `DocumentsWithMemoriesQuerySchema.limit` and `BulkDeleteMemoriesSchema.containerTags`. - Raycast: `metadata.url` is parsed and only http(s) is offered to the OS opener. Dropped his `add_memory` permission gate: it checked the target against the list of existing spaces, so writes to a new space failed and the no-active-space path surfaced `No write access to space "undefined"`. Write permission stays enforced in the API via `containerTagGate`. Hardening and consistency rather than a security fix, since the API already enforces every permission boundary here. Co-Authored-By: Sravanjangam <163002695+Sravanjangam@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| api.test.ts | ||
| api.ts | ||
| package.json | ||
| schemas.ts | ||
| tsconfig.json | ||