Skip to content

Release v1.2.0: post search, Markdown bodies, client hardening - #16

Merged
dkships merged 2 commits into
mainfrom
improve/v1.2.0
Sep 23, 2026
Merged

dkships merged 2 commits into
mainfrom
improve/v1.2.0

Conversation

@dkships

@dkships dkships commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Summary

  • Adds search_posts. The Publisher API spec has a full-text /posts/search endpoint the server never wrapped.
  • get_post returns the body as Markdown by default. Substack sends a JSON-encoded ProseMirror string (42KB on one sampled post vs 16KB as Markdown). bodyFormat: "prosemirror" keeps the old output; "none" returns metadata only.
  • Fixes found by running the server against mocks and the live API:
    • Network failures now say why (DNS, refused) instead of fetch failed.
    • API keys are redacted from error text, including when a truncated body would cut a key in half.
    • Cancelled tool calls abort the request instead of running to the 30s timeout.
    • Env vars that map to the same publication name no longer register twice.
    • 2026-13-45 dates and .. slugs are rejected before they hit the API.
  • Tool results are compact JSON, about half the tokens.
  • Tool descriptions match live responses: list_posts endDate is exclusive, next is null on the last page, and subscriber counts have no free field.
  • Requires Node 22+ (18 and 20 are EOL). CI runs 22 and 24 on setup-node@v7. SDK 1.30.0 passes the runtime audit, so this supersedes Bump the minor-and-patch group across 1 directory with 4 updates #15 and Bump actions/setup-node from 6 to 7 #13.

Write endpoints in the spec (subscriber import, comp subscriptions) are left out on purpose. The server stays read-only.

Type of change

  • Bug fix
  • New feature
  • Docs
  • Security / dependency update

Checklist

  • npm run build passes locally
  • npm audit shows no high/critical advisories
  • Tested against a real Substack Publisher API key (all 7 tools over stdio)
  • CHANGELOG.md updated
  • No API keys, subscriber data, or .env contents in the diff or description

🤖 Generated with Claude Code

dkships and others added 2 commits September 22, 2026 19:58
Wraps the spec's /posts/search, returns get_post bodies as Markdown
(raw ProseMirror is ~2x larger), surfaces network causes, redacts keys,
honors cancellation, and fixes env key and input validation edge cases.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Node 18 and 20 are EOL. SDK 1.30.0 with a clean runtime audit replaces
Dependabot #15. Docs now match the code and drop private setup notes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@dkships
dkships merged commit bee06c3 into main Sep 23, 2026
2 checks passed
@dkships
dkships deleted the improve/v1.2.0 branch September 23, 2026 03:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant