Claude e29a019376 feat(mcp): validate tool arguments with zod
The MCP endpoint was the only route accepting a body without validation. Its
JSON Schema tool declarations were advertisement only: the low-level SDK Server
validates the JSON-RPC envelope but never the arguments of a tool call, and
every handler cast them with `args as SomeType`.

Tools are now declared with `defineTool(name, config, handler)`, the argument
shape `registerTool` takes, and the JSON Schema advertised in tools/list is
generated from the same zod schema that parses incoming arguments, so the two
cannot drift. Handlers receive inferred arguments and pass them to the existing
services, whose argument types are derived from ontime-types — which means a
schema that drifts from the domain model now fails typecheck.

mcp.registry.ts is the only module aware of the SDK internals. Migrating to the
SDK v2 registerTool API means replacing its two functions with a registration
loop, leaving the tool declarations untouched.

Malformed calls are now protocol errors, matching what the SDK does on the
registerTool path and what v2 will do. Failures raised by the services are
still returned as tool errors so agents can read them and recover.

Fixes three bugs the missing validation allowed:

- Project filenames reached `join(projectsDir, name)` unsanitised, so
  `../canary.json` resolved outside the projects directory. They are now
  confined with the same sanitize-filename + ensureJsonExtension pair the HTTP
  routes use in db.validation.ts.
- ontime_update_project_info forwarded its whole argument object into
  setProjectData, which spreads it into the stored project; an undeclared
  `logo` key also caused the current logo file to be deleted. Only declared
  fields reach it now.
- Batch creation declared nested entries as a bare object. They are modelled
  two levels deep, which encodes that groups cannot be nested and keeps the
  generated schema free of $ref/$defs.

Unknown keys are rejected rather than stripped, so an agent gets an actionable
error instead of a write that silently does less than it reported.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MZioYpY8NR8UM5tAQ7BkfN
2026-08-12 05:28:22 +00:00
2026-05-28 09:50:20 +02:00
2026-08-09 10:41:12 +02:00
2026-08-09 10:44:13 +02:00
2023-05-18 14:02:22 +02:00
2026-03-08 16:22:12 +01:00
2026-07-01 12:48:40 +02:00
2026-06-11 18:58:00 +02:00
2026-03-08 16:22:12 +01:00
2026-03-08 16:22:12 +01:00
2026-03-08 16:22:12 +01:00
2021-06-12 19:26:37 +02:00
2026-08-09 10:44:13 +02:00
2026-03-08 16:22:12 +01:00
2026-03-08 16:22:12 +01:00

License: GPL v3 GitHub Downloads (all assets, all releases) Docker Pulls NPM Downloads Homebrew Cask Version

Download the latest release

Buy Me A Coffee

... or

Need help?

We do our best to have most topics covered by the documentation. However, if your question is not covered, you are welcome to fill in a bug report in an issue, ask a question in GitHub discussions or hop in the discord server for a chat.

Using Ontime?

Let us know! Ontime improves from the collaboration with its users. We would like to understand how you use Ontime and appreciate your feedback.

Ontime

Ontime is a browser-based application that manages event rundowns, scheduling, and cueing.

With Ontime, you can plan, track your schedule, manage automation and cross-department show information all in one place.

Ontime is made by entertainment and broadcast engineers and used by

  • Conference organisers
  • Touring shows and receiving venues
  • Broadcasters and streamers
  • Theatres and opera houses
  • Houses of worship

Main features

  • Multiplatform: Available as a Cloud service and for Windows, macOS, Linux, or self-hosted via Docker.
  • In any device: Ontime is available to any device with a browser, eg: tablets, mobile phones, laptops, signage, media servers...
  • Team Collaboration: Dedicated views for directors, operators, backstage, and signage.
  • Real-Time Updates: Manage and communicate runtime delays effortlessly.
  • Automatable: Ontime can be fully or partially controlled by an operator, or run standalone with the system clock
  • Flexible Integrations: Use one of the APIs provided (OSC, HTTP, Websocket) or the available Companion module to integrate into your workflow (vMix, disguise, Qlab, OBS)

... and a lot more ...

For live environments

Ontime is designed for use in live environments.
This guides the application into being flexible and efficiently integrating into different workflows.

For teams

All information added in Ontime is shared with the production team and other software / hardware in your workflow.
Ontime also improves team collaboration with dedicated views for cuesheets and operators, and for public and production signage.

Simple infrastructure

All the data is distributed over the network, making its distribution and infrastructure flexible and cheap.
With the availability of the docker image, you can also leverage IT infrastructure to make Ontime available online for your team and clients.

Ontime is made by video engineers and entertainment technicians.

App Window

Views

Read the docs to learn more

Using Ontime

Getting started

The easiest way to start with Ontime is by leveraging our Cloud service.
This will give you immediate access to running instances of Ontime which are available to share with anyone with an internet connection.

Alternatively, you can run Ontime locally for free by downloading the latest release for your platform or using the docker image, available at Docker Hub

Once installed and running, any device that shares the same network as Ontime will have access to Ontime.

More information is available in our docs

Continued development

Ontime is under active development. We continue adding and improving features in collaboration with users.

Have an idea? Reach out via email or open an issue

Issues

We use Github's issue tracking for bug reporting and feature requests.
Found a bug? Open an issue.

Contributing

Looking to contribute? All types of help are appreciated, from coding to testing and feature specification.

If you are a developer and would like to contribute with code, please open an issue to discuss before opening a Pull Request.

Information about the project setup can be found in the development documentation

License

This project is licensed under the terms of the GNU GPL v3

Sponsor

You can help the development of this project or say thank you with a one time donation.
See the terms of donations.


Buy Me A Coffee

S
Description
Free, open-source time keeping for live events
Readme 36 MiB
Latest
2026-06-07 11:53:25 +00:00
Languages
TypeScript 92.5%
SCSS 6.1%
JavaScript 1%
HTML 0.4%