Commit Graph

1023 Commits

Author SHA1 Message Date
Claude 137de1f9fe fix(client/auth): non-fatal SEP-2468 check on eager path; flag discovery only on completion
Address second-round review findings: an issuer-mismatched ASM from a
blind eager probe is skipped as failed discovery (falling through to
the {origin}/token fallback) instead of raising out of the auth flow
before the original request is sent; and eager_discovery_attempted is
now set only when the probe sequence completes, so a probe interrupted
by a transport failure is retried on the next refresh rather than
permanently recorded as done.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CjbXueCDdFNJK6imejCXgM
2026-08-07 06:02:14 +00:00
Claude 7e70eaec56 fix(client/auth): make hint-less eager discovery best-effort, never destructive
Address review findings: without a WWW-Authenticate resource_metadata
hint the eager probes are unanchored, so a co-hosted origin can serve
another resource's documents. Treat a resource-mismatched PRM as failed
discovery instead of raising out of the auth flow; on a SEP-2352
binding mismatch skip the refresh and discard the unanchored discovery
results (including rejected ASM metadata) but keep the credentials for
the anchored 401 path to judge. Run the probes only once per context so
servers publishing no metadata are not re-probed on every in-process
refresh, and finalize the inner refresh generator with aclosing().

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CjbXueCDdFNJK6imejCXgM
2026-08-07 05:54:35 +00:00
Claude a80aae2bb1 fix(client/auth): discover AS metadata before cold-start token refresh
On a cold start (stored refresh token reused before any 401) the eager
pre-401 refresh built its URL from the urljoin(origin, "/token")
fallback because authorization-server metadata had not been discovered
yet. Servers whose token endpoint lives under a path returned 404, the
client cleared its stored tokens, and headless clients were forced into
an interactive re-auth they cannot perform (#3240, #3250).

Run protected-resource + authorization-server metadata discovery before
the eager refresh so it targets the discovered token endpoint, applying
the same SEP-2352 issuer-binding checks as the 401 discovery path: when
the stored credentials are bound to a different issuer they are dropped
and the refresh is skipped, so credentials are never presented to an
authorization server they are not bound to, and the subsequent 401 flow
re-registers cleanly. Servers publishing no metadata keep the previous
{origin}/token fallback behavior.

Fixes #3240

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CjbXueCDdFNJK6imejCXgM
2026-08-07 05:27:18 +00:00
Max a4f4ccd091 Link the released 2026-07-28 spec and point migrators at /v1/ (#3214) 2026-07-29 15:01:27 +01:00
Max fe47969fb9 Ask which release line a bug report is on (#3213) 2026-07-29 14:55:15 +01:00
Max d82ed88eb5 Describe the maintenance line without hardcoding 1.28 (#3212) 2026-07-29 14:54:45 +01:00
Max b31ddf37ed Retire wording tied to pre-2.0 milestones (#3211) 2026-07-29 14:54:23 +01:00
Max 6f69a3758e Present v2 as the stable release across the README, docs, and policies (#3178)
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
v2.0.0
2026-07-28 14:31:36 +01:00
Max 78e6fbb7e4 Serve v2 docs at the site root, with permanent per-major paths (#3176) 2026-07-28 13:57:21 +01:00
Max af06330a31 Remove unused StreamableHTTPTransport.get_session_id() (#3205) 2026-07-28 13:55:02 +01:00
Max 68ca87e20b Document the two-line release process for stable v2 (#3179) 2026-07-28 13:51:31 +01:00
Max c9c431b71a Expose the middleware chain on MCPServer and stop sending unrequested change notifications (#3201) 2026-07-28 12:24:23 +01:00
Max 528e366558 Fail fast on server-to-client requests in JSON-response mode instead of hanging (#3195) 2026-07-28 11:04:51 +01:00
Max 27f5cc7a46 Remove unused mcpserver.exceptions.ValidationError (#3199) 2026-07-28 10:25:51 +01:00
Max 89c5e700f2 Gate log notifications on the per-request log-level opt-in at 2026-07-28 (#3198) 2026-07-28 02:20:33 +01:00
Max b61ce388dd docs: fix off-by-one hl_lines in apps.md (#3196) 2026-07-28 00:04:57 +01:00
Max b7c9a916d6 Add mcp.types as a permanent alias for mcp_types (#3190) 2026-07-27 23:47:04 +01:00
Max 923341c98a Stop answering cancelled requests (#3188) 2026-07-27 23:26:00 +01:00
Max e8ef138153 docs: fill migration-guide gaps found by automated v1-to-v2 migration runs (#3187) 2026-07-27 23:17:17 +01:00
Max d3ffe87960 Split the registration request model from the registered-client record (#3181) 2026-07-27 23:11:01 +01:00
Max b9422f1c9b Make the per-version wire packages private (mcp_types._v*) (#3191) 2026-07-27 22:16:48 +01:00
Max 45f2a88a9a Point pre-release install pins at 2.0.0rc1 (#3186)
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
v2.0.0rc1
2026-07-27 14:23:57 +01:00
Max 333aca7ac8 Repin conformance harness to the published 0.2.0-alpha.10 (#3184) 2026-07-27 14:03:06 +01:00
Max dcd9c1ee9f Lengthen the demo signing keys in the identity-assertion examples (#3180)
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
CI / checks (push) Failing after 0s
2026-07-26 11:45:26 +01:00
Jeremiah Lowin f599cdfcf9 Cache compiled output-schema validators on ClientSession (#3134)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-07-26 11:29:10 +01:00
Max 11934c90ae Replace FileResource.is_binary with an encoding field (#3171) 2026-07-26 00:58:06 +01:00
Max 814072c94d Narrow message_handler's parameter to notifications and exceptions (#3168) 2026-07-26 00:24:48 +01:00
Max 47bfa85e83 Remove the unused timeout parameter from OAuthClientProvider (#3165) 2026-07-26 00:22:15 +01:00
Max 3212591946 Stop advertising MCP_* env vars for MCPServer settings; drop pydantic-settings (#3170) 2026-07-25 23:22:27 +01:00
Max 7163d8263f Remove the deprecated RFC7523OAuthClientProvider (#3169) 2026-07-25 22:50:57 +01:00
Max 1963af52cc Correct stable v2 target date to 2026-07-28 (#3105)
CI / checks (push) Failing after 0s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-25 20:36:08 +01:00
Max e90a66b554 Rename scopes= to scope= on the client-credentials OAuth providers (#3166) 2026-07-25 20:23:36 +01:00
Max 5dd062d077 Remove Context.client_id (#3167) 2026-07-25 19:11:51 +01:00
Max 0cb920f126 Make CacheConfig() the Client cache default and None the off switch (#3164) 2026-07-25 17:50:53 +01:00
Max 629ca297d2 Isolate the stdio server's stdin and stdout from handler subprocesses (#3117) 2026-07-25 13:05:51 +01:00
Max 00a70148bc Serve the 2026-07-28 protocol over stdio: decide the era from the opening request (#3152)
CI / checks (push) Failing after 1s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-24 13:46:37 +01:00
Max 837ef904f8 Align with spec #3002: optional clientInfo, serverInfo in result _meta (#3143)
Deploy Docs / deploy-docs (push) Has been cancelled
CI / checks (push) Failing after 24m23s
CI / all-green (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
2026-07-23 12:00:36 +01:00
Max 3a6f2996cd docs: load media examples from disk instead of inline base64 (#3108) 2026-07-16 20:41:05 +01:00
Max ebcc4dc3fb Pin pymdown-extensions back to 11.0 (#3106) 2026-07-16 20:25:33 +01:00
Max 497f7afa61 docs: make API reference rendering independent of page order (#3107) 2026-07-16 18:29:44 +01:00
Andre.Kalberer e464f72c12 docs: document Windows stdio subprocess stdin handling (#3079) 2026-07-16 11:25:47 +01:00
Marcelo Trylesinski 03aaebd3aa Add Streamable HTTP request body limits (#3095) 2026-07-16 08:33:32 +02:00
Marcelo Trylesinski 2713b53b12 Replace httpx and httpx-sse with httpx2 (#2972)
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
v2.0.0b2
2026-07-14 17:05:08 +01:00
Otis Cui 1216c53693 fix: reject trailing newline in tool-name and URI-template varname validation (#3076)
Python's $ with re.match also matches just before a single trailing newline, so tool-name validation accepted "name\n" and UriTemplate.parse accepted varnames like "foo\n". Switch both checks to re.fullmatch.

Closes #3084
2026-07-10 12:56:54 +00:00
Marcelo Trylesinski 4fc8882c02 docs: replace MkDocs with Zensical (#3073)
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-07-10 12:48:46 +01:00
Max 74a242ae7f ci: pick the docs-preview toolchain from the PR checkout (#3081) 2026-07-09 13:57:14 +01:00
Max 148278e07f Gate the test matrix and retry setup-uv's flaky manifest fetch (#3080) 2026-07-09 12:32:53 +01:00
Max 9bdc03d54e Add the client-side subscriptions/listen driver (#3047) 2026-07-07 14:26:09 +01:00
Max 6d2e908f2b docs: pin mkdocs<2 and silence the mkdocs-material advisory banner in CI (#3072) 2026-07-07 13:45:30 +01:00
Max 867bba6263 Share one event loop per test module to stop Windows socketpair churn (#3070) 2026-07-07 13:19:04 +01:00