Commit Graph

1029 Commits

Author SHA1 Message Date
Claude 0b3c2ebc8a fix: track main's optional serverInfo and empty-string server version
main now types Client.server_info as Implementation | None (serverInfo is
optional at 2026-07-28) and defaults server version to "" instead of None.

- ServerCard.from_server treats a derived empty version as unset, so a
  server without a version still fails card validation
- reconcile_server_card accepts server_info=None: an anonymous server makes
  no identity claim, so only the protocol version check applies
2026-08-02 18:46:21 +00:00
Claude 63fe92d5eb Merge remote-tracking branch 'origin/main' into feat/experimental-server-card 2026-08-02 18:37:45 +00:00
Claude 5e4acb59ab fix: complete the spec's CORS header set on discovery responses
The extension spec's CORS section requires
'Access-Control-Allow-Headers: Content-Type, If-None-Match' and
'Access-Control-Expose-Headers: ETag' on hosted card and catalog
endpoints; the served responses allowed only Content-Type and exposed
nothing, which would stop a browser-based client from reading the ETag
or sending If-None-Match for a cross-origin 304 revalidation. Both the
explicit discovery_response headers and the CORSMiddleware preflight
config now emit the full set, with tests asserting the headers on the
card response and on a browser preflight requesting If-None-Match.
2026-08-02 18:18:46 +00:00
Claude e3536df3c9 refactor: address review feedback on the Server Card API surface
- Replace build_server_card() with the ServerCard.from_server() classmethod,
  matching the SDK's from_* alternate-constructor idiom; the _ServerIdentity
  protocol moves to mcp.shared.experimental.server_card alongside it.
- Make DiscoveryResult iterable over its listings (__iter__/__len__), so
  'for listing in result:' works without the .listings attribute hop.
- Remove the client-side server_card_url() helper: card URLs must come from
  an AI Catalog entry per the discovery spec, never be constructed by the
  client. fetch_server_card's docstring now says so.
- Explain the RFC 6598 shared address space constant in the SSRF guard and
  rename it _CGNAT_NETWORK -> _SHARED_ADDRESS_SPACE; ipaddress reports these
  addresses as neither private nor global, so the guard names them explicitly.

All symbols are experimental (no deprecation cycle), so the removals are clean.
2026-08-02 18:15:56 +00:00
Max a4f4ccd091 Link the released 2026-07-28 spec and point migrators at /v1/ (#3214) 2026-07-29 15:01:27 +01:00
Max fe47969fb9 Ask which release line a bug report is on (#3213) 2026-07-29 14:55:15 +01:00
Max d82ed88eb5 Describe the maintenance line without hardcoding 1.28 (#3212) 2026-07-29 14:54:45 +01:00
Max b31ddf37ed Retire wording tied to pre-2.0 milestones (#3211) 2026-07-29 14:54:23 +01:00
Max 6f69a3758e Present v2 as the stable release across the README, docs, and policies (#3178)
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
v2.0.0
2026-07-28 14:31:36 +01:00
Max 78e6fbb7e4 Serve v2 docs at the site root, with permanent per-major paths (#3176) 2026-07-28 13:57:21 +01:00
Max af06330a31 Remove unused StreamableHTTPTransport.get_session_id() (#3205) 2026-07-28 13:55:02 +01:00
Max 68ca87e20b Document the two-line release process for stable v2 (#3179) 2026-07-28 13:51:31 +01:00
Max c9c431b71a Expose the middleware chain on MCPServer and stop sending unrequested change notifications (#3201) 2026-07-28 12:24:23 +01:00
Max 528e366558 Fail fast on server-to-client requests in JSON-response mode instead of hanging (#3195) 2026-07-28 11:04:51 +01:00
Max 27f5cc7a46 Remove unused mcpserver.exceptions.ValidationError (#3199) 2026-07-28 10:25:51 +01:00
Max 89c5e700f2 Gate log notifications on the per-request log-level opt-in at 2026-07-28 (#3198) 2026-07-28 02:20:33 +01:00
Max b61ce388dd docs: fix off-by-one hl_lines in apps.md (#3196) 2026-07-28 00:04:57 +01:00
Max b7c9a916d6 Add mcp.types as a permanent alias for mcp_types (#3190) 2026-07-27 23:47:04 +01:00
Max 923341c98a Stop answering cancelled requests (#3188) 2026-07-27 23:26:00 +01:00
Max e8ef138153 docs: fill migration-guide gaps found by automated v1-to-v2 migration runs (#3187) 2026-07-27 23:17:17 +01:00
Max d3ffe87960 Split the registration request model from the registered-client record (#3181) 2026-07-27 23:11:01 +01:00
Max b9422f1c9b Make the per-version wire packages private (mcp_types._v*) (#3191) 2026-07-27 22:16:48 +01:00
Max 45f2a88a9a Point pre-release install pins at 2.0.0rc1 (#3186)
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
v2.0.0rc1
2026-07-27 14:23:57 +01:00
Max 333aca7ac8 Repin conformance harness to the published 0.2.0-alpha.10 (#3184) 2026-07-27 14:03:06 +01:00
Max dcd9c1ee9f Lengthen the demo signing keys in the identity-assertion examples (#3180)
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
CI / checks (push) Failing after 0s
2026-07-26 11:45:26 +01:00
Jeremiah Lowin f599cdfcf9 Cache compiled output-schema validators on ClientSession (#3134)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-07-26 11:29:10 +01:00
Max 11934c90ae Replace FileResource.is_binary with an encoding field (#3171) 2026-07-26 00:58:06 +01:00
Max 814072c94d Narrow message_handler's parameter to notifications and exceptions (#3168) 2026-07-26 00:24:48 +01:00
Max 47bfa85e83 Remove the unused timeout parameter from OAuthClientProvider (#3165) 2026-07-26 00:22:15 +01:00
Max 3212591946 Stop advertising MCP_* env vars for MCPServer settings; drop pydantic-settings (#3170) 2026-07-25 23:22:27 +01:00
Max 7163d8263f Remove the deprecated RFC7523OAuthClientProvider (#3169) 2026-07-25 22:50:57 +01:00
Max 1963af52cc Correct stable v2 target date to 2026-07-28 (#3105)
CI / checks (push) Failing after 0s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-25 20:36:08 +01:00
Max e90a66b554 Rename scopes= to scope= on the client-credentials OAuth providers (#3166) 2026-07-25 20:23:36 +01:00
Max 5dd062d077 Remove Context.client_id (#3167) 2026-07-25 19:11:51 +01:00
Max 0cb920f126 Make CacheConfig() the Client cache default and None the off switch (#3164) 2026-07-25 17:50:53 +01:00
Max 629ca297d2 Isolate the stdio server's stdin and stdout from handler subprocesses (#3117) 2026-07-25 13:05:51 +01:00
Max 00a70148bc Serve the 2026-07-28 protocol over stdio: decide the era from the opening request (#3152)
CI / checks (push) Failing after 1s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-24 13:46:37 +01:00
Max 837ef904f8 Align with spec #3002: optional clientInfo, serverInfo in result _meta (#3143)
Deploy Docs / deploy-docs (push) Has been cancelled
CI / checks (push) Failing after 24m23s
CI / all-green (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
2026-07-23 12:00:36 +01:00
Claude 3d50b08b73 fix: harden Server Card discovery and close review gaps (experimental)
Discovery client:

- Bound each probe with DiscoveryPolicy.max_probe_entries (default 500),
  an aggregate budget over every card and nested-catalog entry one walk
  processes; exhaustion records a single "probe_budget" failure and drops
  the rest. Already-visited nested catalog URLs are never refetched, so
  cyclic or duplicated catalogs terminate. Without this the per-catalog
  entry cap and the depth cap compose multiplicatively (~entries**depth
  fetches from one hostile catalog).
- Catch OSError per entry too: an unresolvable host (socket.gaierror from
  the guard's own DNS resolution) or a tar-pit entry (TimeoutError from
  the per-fetch deadline) becomes a failure instead of killing the whole
  probe, as the DiscoveryResult contract promises. Both exceptions are
  now documented on the public fetchers.
- CardListing.listing_domain/hosting_domain return host[:port] built from
  the parsed hostname, never the raw netloc, and _admit_url rejects
  userinfo-carrying URLs outright, so https://github.com@evil.example/
  can neither be fetched nor rendered as a trusted brand in consent UI.
- _is_blocked_address unwraps IPv4-mapped IPv6 literals and applies the
  IPv4 rules, closing the ::ffff:100.64.0.1 CGNAT bypass (and the
  private-range leak on interpreters without the gh-113171 fix).
- discover_server_cards with http_client=None opens one credential-free
  client for the whole walk instead of one per fetched entry.
- Plain http is refused up front under the hardened policy (the loopback
  carve-out was unreachable: loopback fails the address guard anyway).
- DiscoveryErrorReason is re-exported from the public module, and one
  accept_header() helper replaces the duplicated Accept literals.

Models and server:

- Remote.required_variables now includes required headers that carry no
  value and no default, keyed by header name exactly as resolve_remote
  accepts them, so prompting from the property and then resolving works.
- mount_discovery documents that public_url is the app's public base URL.
- The discovery routes' CORSMiddleware allows only GET, so real browser
  preflights advertise the spec's method list.

Tests cover the budget walk (exact fetch sequence), visited-set dedup,
per-entry DNS-failure and timeout resilience, userinfo rejection and
display, mapped-IPv6 blocking, required-header prompting, Repository and
icons round-trips, and the preflight headers.
2026-07-21 07:26:29 +00:00
Claude e15f284228 docs: add Server Cards page with runnable examples
New Advanced page covering serving a card, publishing on a brand
domain, static publishing, discovery and connect, ETag revalidation,
and the security model (advisory cards, endpoint-keyed dedup, host
scoped consent, SSRF policy defaults). Tutorials are pyright-checked
docs_src modules proved against the real SDK by
tests/docs_src/test_server_cards.py.
2026-07-21 06:22:24 +00:00
Claude 7d731decf8 feat: hardened Server Card discovery client (experimental)
Client-tier helpers: fetch_server_card / fetch_ai_catalog /
discover_server_cards run every fetch through a hardened core
(https-only with loopback-http exception, SSRF address guard with
post-DNS re-check, manual redirect walking with per-hop re-admission,
response size and catalog entry/depth caps, Accept and media type
discipline) governed by DiscoveryPolicy. Probes collect per-entry
failures instead of raising, and CardListing exposes the listing chain
for consent UI. Stateless request/parse pairs support host-owned ETag
revalidation, and reconcile_server_card compares card claims to runtime
values without ever enforcing them.
2026-07-21 06:22:10 +00:00
Claude 1db4632759 feat: serve Server Cards and AI Catalogs over HTTP (experimental)
Server-tier helpers: build_server_card derives the card from a server's
identity fields, route builders and mount helpers serve the card at the
spec-reserved <streamable-http-path>/server-card and the catalog at
/.well-known/ai-catalog.json, and discovery_response is the single
compliance chokepoint (media type, CORS MUSTs, Cache-Control, strong
ETag with If-None-Match 304s, OPTIONS preflight). catalog_identifier
and server_card_entry build urn:air catalog entries, by URL or inline.
2026-07-21 06:22:10 +00:00
Claude f2d46d3fdf feat: add experimental Server Card and AI Catalog models (SEP-2127)
Shared-tier Pydantic models for the experimental-ext-server-card
extension: ServerCard and its Input/KeyValueInput/Repository/Remote
family, resolve_remote for template substitution, and a minimal typed
AICatalog subset. Wire-format constraints (v1 $schema URL, namespaced
name pattern, version-range rejection, url-xor-data catalog entries)
are enforced in validators and pinned by the extension repo's vendored
conformance fixtures.
2026-07-21 06:21:54 +00:00
Max 3a6f2996cd docs: load media examples from disk instead of inline base64 (#3108) 2026-07-16 20:41:05 +01:00
Max ebcc4dc3fb Pin pymdown-extensions back to 11.0 (#3106) 2026-07-16 20:25:33 +01:00
Max 497f7afa61 docs: make API reference rendering independent of page order (#3107) 2026-07-16 18:29:44 +01:00
Andre.Kalberer e464f72c12 docs: document Windows stdio subprocess stdin handling (#3079) 2026-07-16 11:25:47 +01:00
Marcelo Trylesinski 03aaebd3aa Add Streamable HTTP request body limits (#3095) 2026-07-16 08:33:32 +02:00
Marcelo Trylesinski 2713b53b12 Replace httpx and httpx-sse with httpx2 (#2972)
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
v2.0.0b2
2026-07-14 17:05:08 +01:00
Otis Cui 1216c53693 fix: reject trailing newline in tool-name and URI-template varname validation (#3076)
Python's $ with re.match also matches just before a single trailing newline, so tool-name validation accepted "name\n" and UriTemplate.parse accepted varnames like "foo\n". Switch both checks to re.fullmatch.

Closes #3084
2026-07-10 12:56:54 +00:00