4da2acbee4
- Removed unsafe OAuth endpoint extraction from error message text - Fixed PKCE verifier storage with typed #codeVerifier field - Fixed refresh token fallback using access token as refresh token - Enforced restrictive file permissions (0o700/0o600) for MCP configs - Fixed wizard buildConfig() to respect user-chosen env var and header names - Fixed reauth endpoint discovery for non-OAuth servers - Stored original config on connection, resolved config only for transport - Added runtime type validation for enabled/timeout in config loaders - Converted all TS private keywords to ES # private fields - Wrapped uncaught throws in /mcp add with try/catch error handling - Replaced new Promise with Promise.withResolvers() pattern - Sanitized TUI output with replaceTabs/truncateToWidth - Enforced http/https URL validation in add wizard - Fixed greedy /mcp prefix match in input controller - Corrected config filename references in MCP guide - Added server name validation to updateMCPServer - Fixed timeout timer leak in stdio transport