Commit Graph

231 Commits

Author SHA1 Message Date
Max Isbey cdc78fc9d5 Keep the public server signatures resolvable by typing.get_type_hints
Moving the HTTP transport and auth imports under TYPE_CHECKING made
typing.get_type_hints() raise NameError on public methods it used to
resolve on: MCPServer.streamable_http_app / sse_app / run_sse_async /
run_streamable_http_async / session_manager and Server.streamable_http_app
/ session_manager (EventStore, TransportSecuritySettings,
StreamableHTTPSessionManager, AuthSettings, OAuthAuthorizationServerProvider,
TokenVerifier were typing-only names in real annotations).

Two of those types get web-framework-free homes so the server modules can
import them for real without loading starlette: the resumability contract
(EventStore, EventMessage, EventCallback, EventId, StreamId) moves to
mcp.server.event_store, and mcp.server.transport_security keeps only the
pydantic TransportSecuritySettings while its starlette middleware moves
beside the transports. Both old import paths keep working with the same
objects. The session manager and the OAuth annotations are spelled through
the lazy mcp.server namespace instead (the trick already used for
Client.server), so they evaluate on demand and MCPServer stops importing
the OAuth provider stack at module load. The starlette-owned annotations
of the app builders (Starlette, Route, Request/Response) stay typing-only;
get_type_hints on those methods needs starlette's names supplied by the
caller.
2026-07-29 22:02:59 +00:00
Max Isbey 1f3fbc7ca3 Use one lazy-attribute helper for the packages, invisible to type checkers
Three implementations of lazy module attributes had grown: the
hand-rolled __getattr__/__dir__ in mcp/__init__.py, the submodule
fallback factory used by the four package inits, and a one-name
__getattr__ in mcp.server.elicitation. They shared two problems.

An unconditional module-level __getattr__ is visible to type checkers,
so pyright typed every misspelled `mcp.<name>` (and `mcp.client.<name>`,
...) as `object` instead of reporting it. And the submodule fallback ran
a filesystem find_spec on every attribute miss and speculatively imported
whatever matched, so a name sweep (cloudpickle's whichmodule, hasattr
probes) could import real submodules as a side effect, while
dir(mcp.client) no longer listed submodules it would happily resolve.

mcp.shared._lazy.lazy_module_attrs now serves all of them: lazy exports
(a `(module, attr)` pair or a zero-argument loader, resolved once and
cached in the namespace) plus known submodules (an explicit set, or the
package's real submodules listed once on first need). A miss is a plain
AttributeError with no search and no import, and __dir__ reports the
exports and submodules. Every caller binds the pair under
`if not TYPE_CHECKING:`, so attribute typos are pyright errors again
while the TYPE_CHECKING mirrors keep the real names typed. The
mcp.server.auth package gets the same fallback so qualified annotations
such as `mcp.server.auth.provider.TokenVerifier` resolve on demand.

The elicitation gate's wire-schema type is resolved through the same
mechanism from a cached accessor, so validating rendered schemas no
longer re-executes the wire-package import on every call.
2026-07-29 21:59:46 +00:00
Max Isbey 2a7fb0c739 Keep PrimitiveSchemaDefinition reachable on mcp.server.elicitation
Its module-level import moved into the validation function that uses it, so
the attribute would otherwise disappear from the module namespace. Resolve it
on first access via a module-level __getattr__ (and keep it in dir()) so
existing references to mcp.server.elicitation.PrimitiveSchemaDefinition keep
working without reintroducing the import at module load.
2026-07-29 19:46:20 +00:00
Max Isbey 3ac881f1b4 Test HttpResource.read() instead of excluding it from coverage
The method body had been marked `# pragma: no cover` (widened further once
httpx2 moved into the method). Exercise it against an httpx2 MockTransport
instead, covering both the response body and the raise_for_status path, and
drop the pragma.
2026-07-29 19:46:20 +00:00
Max c9c431b71a Expose the middleware chain on MCPServer and stop sending unrequested change notifications (#3201) 2026-07-28 12:24:23 +01:00
Max 528e366558 Fail fast on server-to-client requests in JSON-response mode instead of hanging (#3195) 2026-07-28 11:04:51 +01:00
Max 89c5e700f2 Gate log notifications on the per-request log-level opt-in at 2026-07-28 (#3198) 2026-07-28 02:20:33 +01:00
Max 923341c98a Stop answering cancelled requests (#3188) 2026-07-27 23:26:00 +01:00
Max 11934c90ae Replace FileResource.is_binary with an encoding field (#3171) 2026-07-26 00:58:06 +01:00
Max 814072c94d Narrow message_handler's parameter to notifications and exceptions (#3168) 2026-07-26 00:24:48 +01:00
Max 629ca297d2 Isolate the stdio server's stdin and stdout from handler subprocesses (#3117) 2026-07-25 13:05:51 +01:00
Max 00a70148bc Serve the 2026-07-28 protocol over stdio: decide the era from the opening request (#3152)
CI / checks (push) Failing after 1s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-24 13:46:37 +01:00
Max 837ef904f8 Align with spec #3002: optional clientInfo, serverInfo in result _meta (#3143)
Deploy Docs / deploy-docs (push) Has been cancelled
CI / checks (push) Failing after 24m23s
CI / all-green (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
2026-07-23 12:00:36 +01:00
Marcelo Trylesinski 03aaebd3aa Add Streamable HTTP request body limits (#3095) 2026-07-16 08:33:32 +02:00
Marcelo Trylesinski 2713b53b12 Replace httpx and httpx-sse with httpx2 (#2972)
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-07-14 17:05:08 +01:00
Max 867bba6263 Share one event loop per test module to stop Windows socketpair churn (#3070) 2026-07-07 13:19:04 +01:00
Max d287c9868f Extend resolver DI to sampling and roots requests (#3049) 2026-07-06 18:25:57 +01:00
Max 220d362112 docs: restructure into topical sections and add the four most-asked-for pages (#3044) 2026-07-01 21:06:04 +01:00
Max 080f2a869d Harden the dual-era stream loop's era-lock and rejection semantics (#3040) 2026-07-01 17:07:12 +01:00
Max e50fb5be19 Serve the 2026-07-28 era over stdio and other stream-pair transports (#3038) 2026-07-01 00:11:56 +01:00
Max ca10dade2c Serve subscriptions/listen with a pluggable event bus (SEP-2575) (#3035) 2026-06-30 23:01:04 +01:00
Max 48ef569f7e Validate Mcp-Param-* headers server-side on the 2026-07-28 HTTP path (SEP-2243) (#3033) 2026-06-30 21:39:32 +01:00
Max 4df609119f Add a client extension API (#3034) 2026-06-30 21:31:02 +01:00
Max 7322ca56f4 Require integrity protection for MRTR requestState (#3032) 2026-06-30 21:30:32 +01:00
Max b15b1d5f07 Add a client-side response cache honoring SEP-2549 caching hints (#3023) 2026-06-30 11:31:06 +01:00
Max 8d0f928e40 Pass InputRequiredResult through the MCPServer prompt and resource pipelines (#3020) 2026-06-29 16:50:58 +01:00
Max 8f2c97b769 Consult request_state only for the question a resolver is asking (#3019) 2026-06-29 16:44:05 +01:00
Max 533c6a8226 Add cache_hints constructor map for SEP-2549 caching hints (#3015) 2026-06-29 14:11:15 +00:00
Marcelo Trylesinski c85836a081 Drive resolver elicitation over the 2026-07-28 input_required flow (#2986)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-06-29 14:39:43 +01:00
Marcelo Trylesinski f664db8952 Add resolver dependency injection for MCPServer tools (#2969)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-06-29 11:51:46 +01:00
Marcelo Trylesinski 4b519782f1 Add a pluggable server extension API with MCP Apps (#3003)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-06-29 10:58:05 +01:00
Max 24717cc8eb feat: RFC 6570 URI templates with operator-aware security (#2356) 2026-06-26 20:29:17 +02:00
Max 067f90578c Add SSE response mode to the 2026 streamable-HTTP server entry (#3001) 2026-06-26 19:09:08 +02:00
Marcelo Trylesinski c0ecb70e24 Support RFC 8693 token exchange for enterprise IdP flows (SEP-990) (#2988)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-06-26 17:57:10 +02:00
Max 08b62308d4 Client auto-resolves InputRequiredResult via existing callbacks (SEP-2322) (#2998) 2026-06-26 17:35:23 +02:00
Marcelo Trylesinski 3945bdde11 Remove the dispatch-tier middleware hook (#2997) 2026-06-26 17:08:16 +02:00
Marcelo Trylesinski b31d95a429 Make OpenTelemetry tracing the single default middleware (#2995) 2026-06-26 15:47:37 +02:00
Marcelo Trylesinski f41a5193f3 Preserve empty issuer/resource paths on AuthSettings (#2987) 2026-06-26 11:41:41 +02:00
Max 587340279e Conformance burn-down: server-side InputRequiredResult, Mcp-Method/Name validation, x-mcp-header filter (14 scenarios → green) (#2974)
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
2026-06-26 09:51:59 +02:00
Marcelo Trylesinski 0ee7f1b293 Split protocol types into a standalone mcp-types package (#2973) 2026-06-25 19:18:38 +02:00
Marcelo Trylesinski 96bf22e57a Stop flagging snake_case is_error results as tool errors in OTel span (#2971) 2026-06-25 15:24:45 +00:00
Marcelo Trylesinski 1b1abf6ab6 Add GenAI semantic-convention attributes to OpenTelemetryMiddleware (#2970) 2026-06-25 14:43:54 +00:00
Max f226d00d0a Client-side 2026-07-28 support: .discover()/.adopt() + Client(mode=); request-metadata green (#2950) 2026-06-25 16:09:23 +02:00
Max a527142312 Buffer per-request StreamableHTTP streams to avoid serial-router head-of-line block (#2934) 2026-06-22 16:20:45 +01:00
Marcelo Trylesinski ad81ca234a Slim ServerMiddleware to (ctx, call_next) and add OpenTelemetryMiddleware (#2941)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-06-22 14:46:30 +01:00
Max 2397319a68 Server-side 2026-07-28 stateless support: classifier, driver split, server/discover (#2928) 2026-06-21 19:34:17 +01:00
Marcelo Trylesinski 4573e4ac33 Deprecate roots, sampling, and logging methods per SEP-2577 (#2926) 2026-06-20 18:25:41 +02:00
冯基魁 fda4c54362 fix: correct MCPServer call_tool result type (#2816)
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com>
2026-06-20 16:56:16 +02:00
Marcelo Trylesinski f253682393 Return -32602 for resource not found (SEP-2164) (#2920) 2026-06-20 16:55:23 +02:00
Max 84bf9bde05 First end-to-end 2026-07-28 stateless tools/call (experimental entry + ClientSession pin) (#2917) 2026-06-20 14:55:59 +01:00