Release 2.2.2.202608291554
This commit is contained in:
14
README.md
14
README.md
@@ -60,18 +60,19 @@ The view shows all ABAP projects in your workspace. Click **Connect All** to con
|
||||
|
||||
### 3. Start the server
|
||||
|
||||
Click **Start Server**. The embedded MCP server starts on `http://127.0.0.1:3000/mcp` (port is configurable). It binds to localhost only and is not accessible from the network.
|
||||
Click **Start Server**. The embedded MCP server starts on `http://127.0.0.1:3000/mcp` (port is configurable). It binds to localhost only and is not accessible from the network. The server prints the client configuration block, with a bearer token, to the view console. The **Copy client config** button copies that block to the clipboard.
|
||||
|
||||
### 4. Configure your MCP client
|
||||
|
||||
Add the following to your client's MCP configuration:
|
||||
Add the following to your client's MCP configuration. Replace `<token>` with the token from the view:
|
||||
|
||||
```json
|
||||
{
|
||||
"mcpServers": {
|
||||
"abap-adt": {
|
||||
"type": "streamable-http",
|
||||
"url": "http://127.0.0.1:3000/mcp"
|
||||
"url": "http://127.0.0.1:3000/mcp",
|
||||
"headers": { "Authorization": "Bearer <token>" }
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -84,12 +85,17 @@ Add the following to your client's MCP configuration:
|
||||
"mcpServers": {
|
||||
"abap-adt": {
|
||||
"type": "streamable-http",
|
||||
"url": "http://127.0.0.1:3000/mcp"
|
||||
"url": "http://127.0.0.1:3000/mcp",
|
||||
"headers": { "Authorization": "Bearer <token>" }
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
#### Why the token and the Origin rejection
|
||||
|
||||
The server binds to `127.0.0.1`, so the network cannot reach it. A local browser can still reach `127.0.0.1`. Any open web page can post JSON-RPC to the `/mcp` endpoint and drive the tools through your ADT session. The server rejects any request that carries an `Origin` header with HTTP 403, because a browser always sends one and an MCP client sends none. The server also requires the bearer token, which a web page cannot read. The server stores the token and reuses it on every later start. The token survives an Eclipse restart. The **Regenerate token** button creates a new token when the token leaks. The old token stops working at once. The token stays in the view and in the clipboard. The token never goes to a log or a tool response.
|
||||
|
||||
### 5. Verify
|
||||
|
||||
Check the health endpoint in your browser or with curl:
|
||||
|
||||
Reference in New Issue
Block a user