Skip to content

Release 1.1.4 — automation-mcp 0.1.8 - #2

Merged
jochen-testingbot merged 1 commit into
mainfrom
chore/automation-mcp-0.1.8
Sep 21, 2026
Merged

jochen-testingbot merged 1 commit into
mainfrom
chore/automation-mcp-0.1.8

Conversation

@jochen-testingbot

Copy link
Copy Markdown
Contributor

Picks up @testingbot/automation-mcp@0.1.8, which fixes desktop browser sessions failing to start.

Why this release is needed

0.1.7 sent the legacy JSON-Wire platform capability alongside the W3C platformName. The webdriver client rejects any top-level capability that is neither standard W3C nor colon-namespaced as soon as an extension capability (tb:options) is present, so every desktop browser session failed client-side with Invalid or unsupported WebDriver capabilities found ("platform") before a request ever reached the hub. Mobile sessions were unaffected, which is why the field report read "desktop MCP fails, mobile works".

The subtlety is who was actually broken:

  • Plain npm consumers were not. The dependency range ^0.1.7 means >=0.1.7 <0.2.0, so a fresh npm install @testingbot/mcp-server already resolved to 0.1.8 on its own. This package publishes only dist and vendors nothing.
  • The .mcpb bundle was. scripts/build-mcpb.sh runs npm ci --omit=dev, and npm ci installs exactly what package-lock.json pins — 0.1.7. The desktop bundle would have kept shipping the broken capability indefinitely. The lockfile refresh is the substance of this PR. The same applies to any lockfile-driven CI build.

Changes

The four files your 1.1.3 release touched:

  • package.json — 1.1.3 → 1.1.4, dep range ^0.1.7 → ^0.1.8 (not required by semver, but it documents the real floor)
  • package-lock.json — now pins 0.1.8
  • manifest.json, server.json — via npm run version:sync

Also arriving from 0.1.8

  • waitUntil / timeoutMs on tb_navigate — confirms document.readyState instead of trusting pageLoadStrategy, which on ad-heavy pages could hand the agent a half-built DOM
  • Secret-bearing tool arguments redacted in logs (args.text is tb_type's payload, i.e. whatever gets typed into a login form)
  • Credential-env leak fixed in the appium-mcp child bridge (TESTINGBOT_USERNAME / TESTINGBOT_ACCESS_KEY were not being stripped)
  • SessionManager survives closeAll() — relevant here, since src/server-factory.ts:130 calls addAutomationTools a second time on reconnect
  • tb_listSessions no longer references tb_appiumEndpoint, a tool that never existed

Verification

  • npm run build passes: version sync, lint, format, 253 tests, tsc.
  • Confirmed the fix is in the installed artifact, not just the version string — node_modules/@testingbot/automation-mcp/dist/tools/browse.js has platformName with no legacy platform, and the kebab-case screen-resolution key.
  • Smoke-tested the composed surface against 0.1.8: 40 tools register (12 browser/shared + 27 proxied appium), tb_navigate's schema exposes sessionId, url, waitUntil, timeoutMs, and the corrected tb_listSessions description propagates through.

No release cut yet — tag and publish whenever you're ready.

Picks up the desktop-session fix in @testingbot/automation-mcp 0.1.8.

0.1.7 sent the legacy JSON-Wire `platform` capability alongside the W3C
`platformName`, which the webdriver client rejects outright once an extension
capability (`tb:options`) is present — so every desktop browser session failed
with "Invalid or unsupported WebDriver capabilities found (platform)" before a
request reached the hub. Mobile was unaffected.

The dependency range `^0.1.7` already admitted 0.1.8, so a fresh npm install
resolved to the fix on its own. What did not is the .mcpb bundle:
build-mcpb.sh runs `npm ci --omit=dev`, which installs exactly what the
lockfile pins, so the desktop bundle would have kept shipping 0.1.7. The
lockfile refresh here is the part that matters.

0.1.8 also brings waitUntil/timeoutMs on tb_navigate, redaction of
secret-bearing tool arguments in logs, a credential-env leak fix in the
appium-mcp child bridge, and a SessionManager that survives closeAll() —
relevant to the re-registration path in server-factory.ts, which calls
addAutomationTools a second time on reconnect.
@jochen-testingbot
jochen-testingbot merged commit 17403c0 into main Sep 21, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant