Repository navigation
docs: credit the #13 and #14 security reports - #25
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Vfeu6oSQ6vQ6ykWEBMoYW2
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f0edbbb502
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| | [Remco Veldkamp (remcoder)](https://github.com/remcoder) | Reports that a large OctoPrint file list (324 files, about 500 KB of JSON) overflows a model's context window in [#4](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/4). The full list is still returned; this is documented as a limitation. | | ||
| | [Jose Martinez (josemartinezbli)](https://github.com/josemartinezbli) | Reports that `SLICER_PROFILE` was ambiguous for PrusaSlicer and OrcaSlicer, with slicer error output, in [#7](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/7). The slicing guide now documents profiles per slicer. | | ||
| | [Gioele Molinari (gioelemo)](https://github.com/gioelemo) | Shares a Prusa Connect configuration in [#9](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/9). The Prusa adapter now normalizes `connect.prusa3d.com` to HTTPS; cloud access has not been confirmed on hardware. | | ||
| | [BruceJin (BruceJqs)](https://github.com/BruceJqs) | Reports that a per-call `bridge_command` in `blender_mcp_edit_model` could launch an arbitrary local executable (CWE-78) in [#14](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/14). Per-call executable selectors now require the server-side `MCP_ALLOW_EXECUTABLE_ARG=1` opt-in ([#20](https://github.com/DMontgomery40/mcp-3D-printer-server/pull/20), [#21](https://github.com/DMontgomery40/mcp-3D-printer-server/pull/21)). | |
There was a problem hiding this comment.
Bump the npm patch version for this documentation update
When this commit is integrated into main, both package manifests remain at 1.2.10, so the required npm publication cannot represent this update and attempting to republish the existing version will fail. Include the npm version patch changes to package.json and package-lock.json in this integration.
AGENTS.md reference: AGENTS.md:L7-L7
Useful? React with 👍 / 👎.
|
|
||
| | Contributor | Contribution | | ||
| | --- | --- | | ||
| | [Raza Sharif (razashariff)](https://github.com/razashariff) | Proposes cryptographic signing, replay protection, and agent identity checks before print commands in [#13](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/13). Signing is not implemented; since 1.2.10, every print start and positive heating command requires human confirmation through MCP elicitation, and printed files are inspected before dispatch. | |
There was a problem hiding this comment.
Qualify the claim that every print requires confirmation
In headless configurations with PRINT_REQUIRE_CONFIRMATION=0 (or BAMBU_REQUIRE_CONFIRMATION=0 for Bambu), requireHumanConfirmation() skips elicitation for ordinary print and heating commands, so saying that every command requires human confirmation overstates the mitigation attributed to 1.2.10. State that confirmation is required by default unless the server explicitly opts out; only physical checks such as finished-bed clearance remain mandatory after opt-out.
AGENTS.md reference: AGENTS.md:L37-L37
Useful? React with 👍 / 👎.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Credits @BruceJqs (#14, per-call bridge_command executable selection, fixed by the #20/#21 opt-in gate) and @razashariff (#13, print-command authentication proposal; 1.2.10 answers the same threat with human confirmation and file inspection rather than signing) in CONTRIBUTORS.md. Docs only; the npm package does not ship CONTRIBUTORS.md.