Max Isbey
ff1b50b7e6
Resolve dot-segments when deriving and matching OAuth resource URLs
...
resource_url_from_server_url() now applies RFC 3986 remove_dot_segments
(including the %2E spellings WHATWG treats as dots) so the resource
identifier names the location the HTTP client actually requests.
check_resource_allowed() resolves both paths the same way before its
prefix comparison, and parses with urlsplit so ";parameters" stay part
of the last path segment instead of being dropped.
Fixes #3303
2026-08-20 14:53:53 +00:00
Max
0cee6249ba
Hand TypedDict tool results to pydantic natively ( #3331 )
2026-08-20 15:36:21 +01:00
Marcelo Trylesinski
0d92192765
Shorten stdio test comments ( #3329 )
2026-08-18 10:50:47 +02:00
Max
b2025ab815
Acknowledge notification POSTs with 202 on the 2026-07-28 HTTP entry ( #3326 )
2026-08-17 21:15:35 +01:00
Max
9057285683
docs: cover the remaining Tier 1 audit items ( #3325 )
2026-08-17 20:18:30 +01:00
Max
2a1cc94493
Gate external PRs on an assigned, linked issue ( #3291 )
...
Signed-off-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-08-17 17:22:04 +01:00
Max
e473cca6a1
Let Client take StdioServerParameters directly ( #3321 )
2026-08-17 14:31:21 +01:00
Max
fb443cc4b2
MCPServer: content-block returns are unstructured, prompt messages take Image/Audio ( #3320 )
2026-08-17 14:12:31 +01:00
Max
37b3cb1ef7
Stop framing breaking changes as a workflow in AGENTS.md ( #3286 )
2026-08-16 18:10:16 +01:00
Max
31b76cbeed
Drop later-revision cache-hint fields on pre-2026 sessions ( #3223 )
2026-08-16 15:25:22 +01:00
Max
959569ba15
Publish versioning, roadmap, and dependency policies for v2 ( #3215 )
2026-08-16 15:08:17 +01:00
Max
fc41dd56c8
docs: lead the README client example with a URL, not the server object ( #3315 )
2026-08-16 14:27:01 +01:00
Max
5285e936a9
Pin text I/O to UTF-8 and fail CI on locale-dependent reads/writes ( #3296 )
...
Co-authored-by: ShuQingDollarVoyager <57471784+ShuQingDollarVoyager@users.noreply.github.com >
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-08-16 12:41:53 +01:00
Max
52ad0a8876
docs: publish translated docs in twelve languages and the tool that maintains them ( #3280 )
2026-08-14 17:07:34 +01:00
Max
14aa889992
Pin each conformance leg to a spec-revision wire ( #3304 )
2026-08-14 13:39:06 +01:00
ShuQingDollarVoyager
2378e560fb
Read UTF-8 test fixtures with explicit encoding ( #3245 )
...
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-08-14 11:08:55 +01:00
Max
6e304527a5
Bump conformance harness to 0.2.0-alpha.11 ( #3282 )
2026-08-11 15:40:21 +01:00
Max
a4f4ccd091
Link the released 2026-07-28 spec and point migrators at /v1/ ( #3214 )
2026-07-29 15:01:27 +01:00
Max
fe47969fb9
Ask which release line a bug report is on ( #3213 )
2026-07-29 14:55:15 +01:00
Max
d82ed88eb5
Describe the maintenance line without hardcoding 1.28 ( #3212 )
2026-07-29 14:54:45 +01:00
Max
b31ddf37ed
Retire wording tied to pre-2.0 milestones ( #3211 )
2026-07-29 14:54:23 +01:00
Max
6f69a3758e
Present v2 as the stable release across the README, docs, and policies ( #3178 )
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
v2.0.0
2026-07-28 14:31:36 +01:00
Max
78e6fbb7e4
Serve v2 docs at the site root, with permanent per-major paths ( #3176 )
2026-07-28 13:57:21 +01:00
Max
af06330a31
Remove unused StreamableHTTPTransport.get_session_id() ( #3205 )
2026-07-28 13:55:02 +01:00
Max
68ca87e20b
Document the two-line release process for stable v2 ( #3179 )
2026-07-28 13:51:31 +01:00
Max
c9c431b71a
Expose the middleware chain on MCPServer and stop sending unrequested change notifications ( #3201 )
2026-07-28 12:24:23 +01:00
Max
528e366558
Fail fast on server-to-client requests in JSON-response mode instead of hanging ( #3195 )
2026-07-28 11:04:51 +01:00
Max
27f5cc7a46
Remove unused mcpserver.exceptions.ValidationError ( #3199 )
2026-07-28 10:25:51 +01:00
Max
89c5e700f2
Gate log notifications on the per-request log-level opt-in at 2026-07-28 ( #3198 )
2026-07-28 02:20:33 +01:00
Max
b61ce388dd
docs: fix off-by-one hl_lines in apps.md ( #3196 )
2026-07-28 00:04:57 +01:00
Max
b7c9a916d6
Add mcp.types as a permanent alias for mcp_types ( #3190 )
2026-07-27 23:47:04 +01:00
Max
923341c98a
Stop answering cancelled requests ( #3188 )
2026-07-27 23:26:00 +01:00
Max
e8ef138153
docs: fill migration-guide gaps found by automated v1-to-v2 migration runs ( #3187 )
2026-07-27 23:17:17 +01:00
Max
d3ffe87960
Split the registration request model from the registered-client record ( #3181 )
2026-07-27 23:11:01 +01:00
Max
b9422f1c9b
Make the per-version wire packages private (mcp_types._v*) ( #3191 )
2026-07-27 22:16:48 +01:00
Max
45f2a88a9a
Point pre-release install pins at 2.0.0rc1 ( #3186 )
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
v2.0.0rc1
2026-07-27 14:23:57 +01:00
Max
333aca7ac8
Repin conformance harness to the published 0.2.0-alpha.10 ( #3184 )
2026-07-27 14:03:06 +01:00
Max
dcd9c1ee9f
Lengthen the demo signing keys in the identity-assertion examples ( #3180 )
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
CI / checks (push) Failing after 0s
2026-07-26 11:45:26 +01:00
Jeremiah Lowin
f599cdfcf9
Cache compiled output-schema validators on ClientSession ( #3134 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-07-26 11:29:10 +01:00
Max
11934c90ae
Replace FileResource.is_binary with an encoding field ( #3171 )
2026-07-26 00:58:06 +01:00
Max
814072c94d
Narrow message_handler's parameter to notifications and exceptions ( #3168 )
2026-07-26 00:24:48 +01:00
Max
47bfa85e83
Remove the unused timeout parameter from OAuthClientProvider ( #3165 )
2026-07-26 00:22:15 +01:00
Max
3212591946
Stop advertising MCP_* env vars for MCPServer settings; drop pydantic-settings ( #3170 )
2026-07-25 23:22:27 +01:00
Max
7163d8263f
Remove the deprecated RFC7523OAuthClientProvider ( #3169 )
2026-07-25 22:50:57 +01:00
Max
1963af52cc
Correct stable v2 target date to 2026-07-28 ( #3105 )
CI / checks (push) Failing after 0s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-25 20:36:08 +01:00
Max
e90a66b554
Rename scopes= to scope= on the client-credentials OAuth providers ( #3166 )
2026-07-25 20:23:36 +01:00
Max
5dd062d077
Remove Context.client_id ( #3167 )
2026-07-25 19:11:51 +01:00
Max
0cb920f126
Make CacheConfig() the Client cache default and None the off switch ( #3164 )
2026-07-25 17:50:53 +01:00
Max
629ca297d2
Isolate the stdio server's stdin and stdout from handler subprocesses ( #3117 )
2026-07-25 13:05:51 +01:00
Max
00a70148bc
Serve the 2026-07-28 protocol over stdio: decide the era from the opening request ( #3152 )
CI / checks (push) Failing after 1s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-24 13:46:37 +01:00