registry.json holds each server's bearer token (the connection secret). It was written with the process default umask, leaving it group/world-readable on POSIX multi-user hosts. Write with mode 0o600 and chmod the existing file (writeFile only applies mode on creation). No-op on Windows (NTFS uses ACLs, and the file already sits under the user profile and is gitignored), effective on Linux/macOS where the gateway may run. Gateway-only change — not part of the app installer or auto-updater, so no version bump. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| test | ||
| .gitignore | ||
| agent-client.js | ||
| code.js | ||
| index.js | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| registry.example.json | ||
| registry.js | ||
mhu-diagnostics-gateway
A standalone local stdio MCP gateway for remote, read-only diagnostics of the Multi-Hoster-Uploader app.
It is two things at once:
- an MCP server to Claude Code (stdio transport), exposing read-only diagnostic tools, and
- a plain WebSocket client to a diagnostic agent running inside the Electron app on a remote Windows server.
The operator enables "Diagnose-Zugriff" on a server, copies the connection code, and tells
Claude server <name> at <host>, code <CODE>. Claude calls connect_server(code, host) and then
the read-only diagnostic tools. After the first successful connect the server is remembered under
its label, so later you can just say connect_server(label:"prod-3") with no code.
This package is fully self-contained. It does not import anything from the parent Electron app and is not part of the app build.
Install
cd gateway
npm install
Requires Node >= 18.
Register with Claude Code (one time)
claude mcp add --transport stdio mhu-diag -- node "C:\Users\ploet\Desktop\Claude Projekte\multi-hoster-uploader\gateway\index.js"
Adjust the absolute path if you cloned the repo elsewhere.
Usage
In Claude Code, tell Claude:
server prod-3 at 127.0.0.1, code mhu1_<...>
Claude will call connect_server and then diagnostic tools such as server_health
(the one-shot "what's wrong" hub), read_log, list_errors, get_queue_state,
get_rotation_state, and so on.
Security
- Read-only. No screen access, no input injection, no writes. Only reads logs, errors, queue/history/config (redacted), rotation and system info.
- The code is a secret — it carries the auth token. Do not paste it anywhere public.
- The safe default is to reach the agent over
127.0.0.1via an SSH local port-forward or WireGuard. Seedocs/remote-diagnostics-setup.md. registry.jsonstores tokens and is git-ignored — never commit it.