Commit Graph

1008 Commits

Author SHA1 Message Date
Max Isbey 6c11684ebe Make the subscription authorization hook accept-or-refuse instead of narrowing
Rework the `subscriptions/listen` authorization seam to Go's shape: the hook
(now `authorize=` on ListenHandler / `authorize_subscriptions=` on MCPServer,
typed `AuthorizeSubscription`) either returns to accept the request as asked
or raises MCPError to refuse the whole request before the acknowledgment. It
no longer returns a narrowed filter, and the honored subset is again the plain
support-based echo of the request rather than an intersection with a grant.
Refusing on any unauthorized URI, with a uniform error, is now the documented
pattern; a non-MCPError from the hook still fails closed.

No-Verification-Needed: pushing early for review at maintainer request; verification to follow
2026-07-28 09:31:18 +00:00
Max Isbey b07b2b331f Add a subscription narrowing hook and stop sending unrequested change notifications
Two server-side gaps on the 2026-07-28 subscriptions/listen path, closed together
because either alone leaves the other's leak open.

Nothing let a server decide per caller what a subscription may watch: any client
could name any resource URI in its filter and the server honored it verbatim.
ListenHandler now takes an optional `narrow` hook (`MCPServer(narrow_subscriptions=...)`)
that runs once before the acknowledgment and returns the filter to grant, or
raises MCPError to refuse the request. The grant is intersected with the request
so a hook can narrow but never widen, and any other exception fails closed rather
than granting.

Separately, the modern-era standalone channel forwarded every notification, so
`ctx.session.send_tool_list_changed()` on a 2026-07-28 stdio connection wrote a
bare, unstamped list_changed frame that no subscription had requested. That
channel now drops the four change-notification methods; they reach clients only
through listen streams, which stamp and filter them.
2026-07-27 23:07:37 +00:00
Max 923341c98a Stop answering cancelled requests (#3188) 2026-07-27 23:26:00 +01:00
Max e8ef138153 docs: fill migration-guide gaps found by automated v1-to-v2 migration runs (#3187) 2026-07-27 23:17:17 +01:00
Max d3ffe87960 Split the registration request model from the registered-client record (#3181) 2026-07-27 23:11:01 +01:00
Max b9422f1c9b Make the per-version wire packages private (mcp_types._v*) (#3191) 2026-07-27 22:16:48 +01:00
Max 45f2a88a9a Point pre-release install pins at 2.0.0rc1 (#3186)
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
v2.0.0rc1
2026-07-27 14:23:57 +01:00
Max 333aca7ac8 Repin conformance harness to the published 0.2.0-alpha.10 (#3184) 2026-07-27 14:03:06 +01:00
Max dcd9c1ee9f Lengthen the demo signing keys in the identity-assertion examples (#3180)
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
CI / checks (push) Failing after 0s
2026-07-26 11:45:26 +01:00
Jeremiah Lowin f599cdfcf9 Cache compiled output-schema validators on ClientSession (#3134)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-07-26 11:29:10 +01:00
Max 11934c90ae Replace FileResource.is_binary with an encoding field (#3171) 2026-07-26 00:58:06 +01:00
Max 814072c94d Narrow message_handler's parameter to notifications and exceptions (#3168) 2026-07-26 00:24:48 +01:00
Max 47bfa85e83 Remove the unused timeout parameter from OAuthClientProvider (#3165) 2026-07-26 00:22:15 +01:00
Max 3212591946 Stop advertising MCP_* env vars for MCPServer settings; drop pydantic-settings (#3170) 2026-07-25 23:22:27 +01:00
Max 7163d8263f Remove the deprecated RFC7523OAuthClientProvider (#3169) 2026-07-25 22:50:57 +01:00
Max 1963af52cc Correct stable v2 target date to 2026-07-28 (#3105)
CI / checks (push) Failing after 0s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-25 20:36:08 +01:00
Max e90a66b554 Rename scopes= to scope= on the client-credentials OAuth providers (#3166) 2026-07-25 20:23:36 +01:00
Max 5dd062d077 Remove Context.client_id (#3167) 2026-07-25 19:11:51 +01:00
Max 0cb920f126 Make CacheConfig() the Client cache default and None the off switch (#3164) 2026-07-25 17:50:53 +01:00
Max 629ca297d2 Isolate the stdio server's stdin and stdout from handler subprocesses (#3117) 2026-07-25 13:05:51 +01:00
Max 00a70148bc Serve the 2026-07-28 protocol over stdio: decide the era from the opening request (#3152)
CI / checks (push) Failing after 1s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-24 13:46:37 +01:00
Max 837ef904f8 Align with spec #3002: optional clientInfo, serverInfo in result _meta (#3143)
Deploy Docs / deploy-docs (push) Has been cancelled
CI / checks (push) Failing after 24m23s
CI / all-green (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
2026-07-23 12:00:36 +01:00
Max 3a6f2996cd docs: load media examples from disk instead of inline base64 (#3108) 2026-07-16 20:41:05 +01:00
Max ebcc4dc3fb Pin pymdown-extensions back to 11.0 (#3106) 2026-07-16 20:25:33 +01:00
Max 497f7afa61 docs: make API reference rendering independent of page order (#3107) 2026-07-16 18:29:44 +01:00
Andre.Kalberer e464f72c12 docs: document Windows stdio subprocess stdin handling (#3079) 2026-07-16 11:25:47 +01:00
Marcelo Trylesinski 03aaebd3aa Add Streamable HTTP request body limits (#3095) 2026-07-16 08:33:32 +02:00
Marcelo Trylesinski 2713b53b12 Replace httpx and httpx-sse with httpx2 (#2972)
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
v2.0.0b2
2026-07-14 17:05:08 +01:00
Otis Cui 1216c53693 fix: reject trailing newline in tool-name and URI-template varname validation (#3076)
Python's $ with re.match also matches just before a single trailing newline, so tool-name validation accepted "name\n" and UriTemplate.parse accepted varnames like "foo\n". Switch both checks to re.fullmatch.

Closes #3084
2026-07-10 12:56:54 +00:00
Marcelo Trylesinski 4fc8882c02 docs: replace MkDocs with Zensical (#3073)
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2026-07-10 12:48:46 +01:00
Max 74a242ae7f ci: pick the docs-preview toolchain from the PR checkout (#3081) 2026-07-09 13:57:14 +01:00
Max 148278e07f Gate the test matrix and retry setup-uv's flaky manifest fetch (#3080) 2026-07-09 12:32:53 +01:00
Max 9bdc03d54e Add the client-side subscriptions/listen driver (#3047) 2026-07-07 14:26:09 +01:00
Max 6d2e908f2b docs: pin mkdocs<2 and silence the mkdocs-material advisory banner in CI (#3072) 2026-07-07 13:45:30 +01:00
Max 867bba6263 Share one event loop per test module to stop Windows socketpair churn (#3070) 2026-07-07 13:19:04 +01:00
Max d287c9868f Extend resolver DI to sampling and roots requests (#3049) 2026-07-06 18:25:57 +01:00
Max 53117cb3a9 Make client-side cancellation work over the 2026 transports (#3046) 2026-07-02 19:21:04 +01:00
Max bf4402725d docs: restructure the migration guide around topical groups with a navigation layer (#3058) 2026-07-02 18:54:21 +01:00
Max 2359b40285 docs: modernize the site theme (#3057) 2026-07-02 16:17:33 +01:00
Max e4d95e0d44 docs: add a "What's new in v2" page (#3054) 2026-07-02 15:01:30 +01:00
Max 220d362112 docs: restructure into topical sections and add the four most-asked-for pages (#3044) 2026-07-01 21:06:04 +01:00
Max 080f2a869d Harden the dual-era stream loop's era-lock and rejection semantics (#3040) 2026-07-01 17:07:12 +01:00
Max d39c68df23 De-flake conformance CI: solo re-verification, spawn-storm reduction, result artifacts (#3043) 2026-07-01 16:59:06 +01:00
Max 0da9092037 Point pre-release install pins at 2.0.0b1 (#3039)
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
v2.0.0b1
2026-07-01 00:14:52 +01:00
Max e50fb5be19 Serve the 2026-07-28 era over stdio and other stream-pair transports (#3038) 2026-07-01 00:11:56 +01:00
Max dcf8a6a0b5 Document pydantic.ValidationError in client Raises sections (#3036) 2026-07-01 00:03:17 +01:00
Max 410cc0db31 Add v2 feedback issue template (#3037) 2026-07-01 00:03:11 +01:00
Max ca10dade2c Serve subscriptions/listen with a pluggable event bus (SEP-2575) (#3035) 2026-06-30 23:01:04 +01:00
Max 48ef569f7e Validate Mcp-Param-* headers server-side on the 2026-07-28 HTTP path (SEP-2243) (#3033) 2026-06-30 21:39:32 +01:00
Max 4df609119f Add a client extension API (#3034) 2026-06-30 21:31:02 +01:00