mirror of
https://github.com/penpot/penpot.git
synced 2026-09-02 01:59:17 +00:00
* 🐛 Gate MCP REPL server behind isDevEnv check The ReplServer was starting unconditionally on every MCP server instance, regardless of configuration. This exposed an unauthenticated POST /execute endpoint that forwarded arbitrary JavaScript to connected Penpot plugins. Gate ReplServer creation, startup, and shutdown behind isDevEnv(), consistent with how CljsReplTool and other dev tools are already protected. Log an info message when the REPL server is disabled. Consolidate the dev-env check into a single static isDevEnvEnabled() method that isDevEnv() delegates to, avoiding duplicate logic. Add PluginBridge.close() for proper WebSocket server cleanup on shutdown. Add regression tests that construct PenpotMcpServer and verify hasReplServer() returns the correct value based on the dev-env flag. AI-assisted-by: mimo-v2.5-pro * ✨ Add PENPOT_MCP_REPL_ENABLE env var for explicit REPL control Allow the REPL server to be enabled independently of the devenv setting via a new PENPOT_MCP_REPL_ENABLE environment variable. When set to "true", the REPL server starts regardless of PENPOT_MCP_DEVENV; when set to any other value, it is disabled. When unset, the previous isDevEnv fallback applies. Addresses review feedback on PR #11282. AI-assisted-by: mimo-v2.5-pro
Penpot MCP Server
A Model Context Protocol (MCP) server that provides Penpot integration capabilities for AI clients supporting the model context protocol (MCP).
Setup
-
Install Dependencies
pnpm install -
Build the Project
pnpm run build -
Run the Server
pnpm run start
Penpot Plugin API REPL
The MCP server includes a REPL interface for testing Penpot Plugin API calls. To use it, connect to the URL reported at startup.