Release 1.1.4 — automation-mcp 0.1.8 - #2
Merged
Merged
Conversation
Picks up the desktop-session fix in @testingbot/automation-mcp 0.1.8. 0.1.7 sent the legacy JSON-Wire `platform` capability alongside the W3C `platformName`, which the webdriver client rejects outright once an extension capability (`tb:options`) is present — so every desktop browser session failed with "Invalid or unsupported WebDriver capabilities found (platform)" before a request reached the hub. Mobile was unaffected. The dependency range `^0.1.7` already admitted 0.1.8, so a fresh npm install resolved to the fix on its own. What did not is the .mcpb bundle: build-mcpb.sh runs `npm ci --omit=dev`, which installs exactly what the lockfile pins, so the desktop bundle would have kept shipping 0.1.7. The lockfile refresh here is the part that matters. 0.1.8 also brings waitUntil/timeoutMs on tb_navigate, redaction of secret-bearing tool arguments in logs, a credential-env leak fix in the appium-mcp child bridge, and a SessionManager that survives closeAll() — relevant to the re-registration path in server-factory.ts, which calls addAutomationTools a second time on reconnect.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Picks up
@testingbot/automation-mcp@0.1.8, which fixes desktop browser sessions failing to start.Why this release is needed
0.1.7 sent the legacy JSON-Wire
platformcapability alongside the W3CplatformName. Thewebdriverclient rejects any top-level capability that is neither standard W3C nor colon-namespaced as soon as an extension capability (tb:options) is present, so every desktop browser session failed client-side withInvalid or unsupported WebDriver capabilities found ("platform")before a request ever reached the hub. Mobile sessions were unaffected, which is why the field report read "desktop MCP fails, mobile works".The subtlety is who was actually broken:
^0.1.7means>=0.1.7 <0.2.0, so a freshnpm install @testingbot/mcp-serveralready resolved to 0.1.8 on its own. This package publishes onlydistand vendors nothing..mcpbbundle was.scripts/build-mcpb.shrunsnpm ci --omit=dev, andnpm ciinstalls exactly whatpackage-lock.jsonpins — 0.1.7. The desktop bundle would have kept shipping the broken capability indefinitely. The lockfile refresh is the substance of this PR. The same applies to any lockfile-driven CI build.Changes
The four files your 1.1.3 release touched:
package.json—1.1.3→1.1.4, dep range^0.1.7→^0.1.8(not required by semver, but it documents the real floor)package-lock.json— now pins0.1.8manifest.json,server.json— vianpm run version:syncAlso arriving from 0.1.8
waitUntil/timeoutMsontb_navigate— confirmsdocument.readyStateinstead of trustingpageLoadStrategy, which on ad-heavy pages could hand the agent a half-built DOMargs.textistb_type's payload, i.e. whatever gets typed into a login form)TESTINGBOT_USERNAME/TESTINGBOT_ACCESS_KEYwere not being stripped)SessionManagersurvivescloseAll()— relevant here, sincesrc/server-factory.ts:130callsaddAutomationToolsa second time on reconnecttb_listSessionsno longer referencestb_appiumEndpoint, a tool that never existedVerification
npm run buildpasses: version sync, lint, format, 253 tests, tsc.node_modules/@testingbot/automation-mcp/dist/tools/browse.jshasplatformNamewith no legacyplatform, and the kebab-casescreen-resolutionkey.tb_navigate's schema exposessessionId, url, waitUntil, timeoutMs, and the correctedtb_listSessionsdescription propagates through.No release cut yet — tag and publish whenever you're ready.