Commit Graph

141 Commits

Author SHA1 Message Date
Claude 63fe92d5eb Merge remote-tracking branch 'origin/main' into feat/experimental-server-card 2026-08-02 18:37:45 +00:00
Claude e3536df3c9 refactor: address review feedback on the Server Card API surface
- Replace build_server_card() with the ServerCard.from_server() classmethod,
  matching the SDK's from_* alternate-constructor idiom; the _ServerIdentity
  protocol moves to mcp.shared.experimental.server_card alongside it.
- Make DiscoveryResult iterable over its listings (__iter__/__len__), so
  'for listing in result:' works without the .listings attribute hop.
- Remove the client-side server_card_url() helper: card URLs must come from
  an AI Catalog entry per the discovery spec, never be constructed by the
  client. fetch_server_card's docstring now says so.
- Explain the RFC 6598 shared address space constant in the SSRF guard and
  rename it _CGNAT_NETWORK -> _SHARED_ADDRESS_SPACE; ipaddress reports these
  addresses as neither private nor global, so the guard names them explicitly.

All symbols are experimental (no deprecation cycle), so the removals are clean.
2026-08-02 18:15:56 +00:00
Max 528e366558 Fail fast on server-to-client requests in JSON-response mode instead of hanging (#3195) 2026-07-28 11:04:51 +01:00
Max 923341c98a Stop answering cancelled requests (#3188) 2026-07-27 23:26:00 +01:00
Max d3ffe87960 Split the registration request model from the registered-client record (#3181) 2026-07-27 23:11:01 +01:00
Max 814072c94d Narrow message_handler's parameter to notifications and exceptions (#3168) 2026-07-26 00:24:48 +01:00
Max 837ef904f8 Align with spec #3002: optional clientInfo, serverInfo in result _meta (#3143)
Deploy Docs / deploy-docs (push) Has been cancelled
CI / checks (push) Failing after 24m23s
CI / all-green (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
2026-07-23 12:00:36 +01:00
Claude 3d50b08b73 fix: harden Server Card discovery and close review gaps (experimental)
Discovery client:

- Bound each probe with DiscoveryPolicy.max_probe_entries (default 500),
  an aggregate budget over every card and nested-catalog entry one walk
  processes; exhaustion records a single "probe_budget" failure and drops
  the rest. Already-visited nested catalog URLs are never refetched, so
  cyclic or duplicated catalogs terminate. Without this the per-catalog
  entry cap and the depth cap compose multiplicatively (~entries**depth
  fetches from one hostile catalog).
- Catch OSError per entry too: an unresolvable host (socket.gaierror from
  the guard's own DNS resolution) or a tar-pit entry (TimeoutError from
  the per-fetch deadline) becomes a failure instead of killing the whole
  probe, as the DiscoveryResult contract promises. Both exceptions are
  now documented on the public fetchers.
- CardListing.listing_domain/hosting_domain return host[:port] built from
  the parsed hostname, never the raw netloc, and _admit_url rejects
  userinfo-carrying URLs outright, so https://github.com@evil.example/
  can neither be fetched nor rendered as a trusted brand in consent UI.
- _is_blocked_address unwraps IPv4-mapped IPv6 literals and applies the
  IPv4 rules, closing the ::ffff:100.64.0.1 CGNAT bypass (and the
  private-range leak on interpreters without the gh-113171 fix).
- discover_server_cards with http_client=None opens one credential-free
  client for the whole walk instead of one per fetched entry.
- Plain http is refused up front under the hardened policy (the loopback
  carve-out was unreachable: loopback fails the address guard anyway).
- DiscoveryErrorReason is re-exported from the public module, and one
  accept_header() helper replaces the duplicated Accept literals.

Models and server:

- Remote.required_variables now includes required headers that carry no
  value and no default, keyed by header name exactly as resolve_remote
  accepts them, so prompting from the property and then resolving works.
- mount_discovery documents that public_url is the app's public base URL.
- The discovery routes' CORSMiddleware allows only GET, so real browser
  preflights advertise the spec's method list.

Tests cover the budget walk (exact fetch sequence), visited-set dedup,
per-entry DNS-failure and timeout resilience, userinfo rejection and
display, mapped-IPv6 blocking, required-header prompting, Repository and
icons round-trips, and the preflight headers.
2026-07-21 07:26:29 +00:00
Claude f2d46d3fdf feat: add experimental Server Card and AI Catalog models (SEP-2127)
Shared-tier Pydantic models for the experimental-ext-server-card
extension: ServerCard and its Input/KeyValueInput/Repository/Remote
family, resolve_remote for template substitution, and a minimal typed
AICatalog subset. Wire-format constraints (v1 $schema URL, namespaced
name pattern, version-range rejection, url-xor-data catalog entries)
are enforced in validators and pinned by the extension repo's vendored
conformance fixtures.
2026-07-21 06:21:54 +00:00
Marcelo Trylesinski 2713b53b12 Replace httpx and httpx-sse with httpx2 (#2972)
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-07-14 17:05:08 +01:00
Otis Cui 1216c53693 fix: reject trailing newline in tool-name and URI-template varname validation (#3076)
Python's $ with re.match also matches just before a single trailing newline, so tool-name validation accepted "name\n" and UriTemplate.parse accepted varnames like "foo\n". Switch both checks to re.fullmatch.

Closes #3084
2026-07-10 12:56:54 +00:00
Max 9bdc03d54e Add the client-side subscriptions/listen driver (#3047) 2026-07-07 14:26:09 +01:00
Max 867bba6263 Share one event loop per test module to stop Windows socketpair churn (#3070) 2026-07-07 13:19:04 +01:00
Max d287c9868f Extend resolver DI to sampling and roots requests (#3049) 2026-07-06 18:25:57 +01:00
Max 53117cb3a9 Make client-side cancellation work over the 2026 transports (#3046) 2026-07-02 19:21:04 +01:00
Max 080f2a869d Harden the dual-era stream loop's era-lock and rejection semantics (#3040) 2026-07-01 17:07:12 +01:00
Max 48ef569f7e Validate Mcp-Param-* headers server-side on the 2026-07-28 HTTP path (SEP-2243) (#3033) 2026-06-30 21:39:32 +01:00
Max 4df609119f Add a client extension API (#3034) 2026-06-30 21:31:02 +01:00
Max 24717cc8eb feat: RFC 6570 URI templates with operator-aware security (#2356) 2026-06-26 20:29:17 +02:00
Marcelo Trylesinski b31d95a429 Make OpenTelemetry tracing the single default middleware (#2995) 2026-06-26 15:47:37 +02:00
Marcelo Trylesinski 5b2713d40c Mirror x-mcp-header tool arguments into Mcp-Param-* request headers (SEP-2243) (#2990) 2026-06-26 14:36:56 +02:00
Max 3a8da8c0c3 Fix docs/release follow-ups from the mcp-types package split (#2977) 2026-06-26 13:16:09 +02:00
Max 9dc8c5f02d find_invalid_x_mcp_header: never repr a non-string annotation value (#2989)
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com>
2026-06-26 09:54:28 +00:00
Max 587340279e Conformance burn-down: server-side InputRequiredResult, Mcp-Method/Name validation, x-mcp-header filter (14 scenarios → green) (#2974)
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
2026-06-26 09:51:59 +02:00
Marcelo Trylesinski 0ee7f1b293 Split protocol types into a standalone mcp-types package (#2973) 2026-06-25 19:18:38 +02:00
Max f226d00d0a Client-side 2026-07-28 support: .discover()/.adopt() + Client(mode=); request-metadata green (#2950) 2026-06-25 16:09:23 +02:00
Max a527142312 Buffer per-request StreamableHTTP streams to avoid serial-router head-of-line block (#2934) 2026-06-22 16:20:45 +01:00
Marcelo Trylesinski ad81ca234a Slim ServerMiddleware to (ctx, call_next) and add OpenTelemetryMiddleware (#2941)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-06-22 14:46:30 +01:00
Max 2397319a68 Server-side 2026-07-28 stateless support: classifier, driver split, server/discover (#2928) 2026-06-21 19:34:17 +01:00
Marcelo Trylesinski 4573e4ac33 Deprecate roots, sampling, and logging methods per SEP-2577 (#2926) 2026-06-20 18:25:41 +02:00
Max 734746a3d9 Resolve protocol version per request and expose it as ctx.protocol_version (#2886) 2026-06-17 08:46:42 +01:00
Max 1012d60004 [v2] ClientSession runs on JSONRPCDispatcher; BaseSession removed (#2838) 2026-06-15 14:46:34 +01:00
Max 7267818e44 Fix unknown-method error code and add a protocol version registry (#2836) 2026-06-11 16:47:22 +01:00
Max 5d826490b6 [v2] Dispatcher/ServerRunner receive-path swap — replaces BaseSession (#2710) 2026-06-09 12:58:47 +01:00
Max b478bff56d Remove the unsupported WebSocket transport (#2785) 2026-06-08 12:05:27 +01:00
Max bdc48e98b1 Fix stdio client shutdown bugs and rebuild the stdio test suite (#2773) 2026-06-05 16:15:43 +01:00
Max 19fe9faec8 Run StreamableHTTP transport tests in process instead of over sockets (#2767) 2026-06-03 12:45:00 +01:00
Max ed39e73c0b Run SSE and Unicode transport tests in process instead of over sockets (#2765) 2026-06-02 21:46:53 +01:00
Felix Weinberger 2dfb51a4d1 fix(auth): coerce empty-string optional URL fields to None in OAuthClientMetadata (#2404) 2026-04-13 15:42:35 +01:00
Marcelo Trylesinski 37891f42a4 Add basic OpenTelemetry tracing for client and server requests (#2381) 2026-03-31 20:33:33 +00:00
Marcelo Trylesinski e6235d1667 Propagate contextvars.Context through anyio streams without modifying SessionMessage (#2298) 2026-03-31 12:49:38 -04:00
Max Isbey 67201a9bbd test: fix WS test port race; narrow to single smoke test covering both transport ends (#2267) 2026-03-18 15:48:30 +00:00
Max Isbey e1fd62e0f3 fix: close all memory stream ends in client transport cleanup (#2266) 2026-03-13 14:43:54 +00:00
Shivam Aggarwal 51c53f2c18 fix: accept wildcard media types in Accept header per RFC 7231 (#2152)
Co-authored-by: Shivam <shivam@Shivams-MacBook-Air-2.local>
2026-03-09 16:30:02 +00:00
Max Isbey 528abfab86 tests: remove lax-no-cover pragmas by moving assertions before cancellation (#2206) 2026-03-04 16:11:34 +00:00
Varun6578 b3149d2f33 fix: clean up SSE session on client disconnect (#2200)
Co-authored-by: Varun Sharma <sharmava@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-03-04 14:45:11 +00:00
Max Isbey e82203bfc4 refactor: remove unused mcp.shared.progress module (#2080) 2026-02-18 13:10:02 +00:00
Felix Weinberger be5bb7c4f2 fix: normalize trailing slashes before length check in check_resource_allowed (#2074) 2026-02-17 14:34:59 +00:00
Max Isbey 705497a593 fix: allow null id in JSONRPCError per JSON-RPC 2.0 spec (#2056) 2026-02-17 10:30:34 +00:00
BabyChrist666 3b53fb9a00 fix: add HTTP readiness check to wait_for_server and remove dead code in SSE tests (#2073) 2026-02-17 08:34:47 +01:00