Max Isbey
6c11684ebe
Make the subscription authorization hook accept-or-refuse instead of narrowing
...
Rework the `subscriptions/listen` authorization seam to Go's shape: the hook
(now `authorize=` on ListenHandler / `authorize_subscriptions=` on MCPServer,
typed `AuthorizeSubscription`) either returns to accept the request as asked
or raises MCPError to refuse the whole request before the acknowledgment. It
no longer returns a narrowed filter, and the honored subset is again the plain
support-based echo of the request rather than an intersection with a grant.
Refusing on any unauthorized URI, with a uniform error, is now the documented
pattern; a non-MCPError from the hook still fails closed.
No-Verification-Needed: pushing early for review at maintainer request; verification to follow
2026-07-28 09:31:18 +00:00
Max Isbey
b07b2b331f
Add a subscription narrowing hook and stop sending unrequested change notifications
...
Two server-side gaps on the 2026-07-28 subscriptions/listen path, closed together
because either alone leaves the other's leak open.
Nothing let a server decide per caller what a subscription may watch: any client
could name any resource URI in its filter and the server honored it verbatim.
ListenHandler now takes an optional `narrow` hook (`MCPServer(narrow_subscriptions=...)`)
that runs once before the acknowledgment and returns the filter to grant, or
raises MCPError to refuse the request. The grant is intersected with the request
so a hook can narrow but never widen, and any other exception fails closed rather
than granting.
Separately, the modern-era standalone channel forwarded every notification, so
`ctx.session.send_tool_list_changed()` on a 2026-07-28 stdio connection wrote a
bare, unstamped list_changed frame that no subscription had requested. That
channel now drops the four change-notification methods; they reach clients only
through listen streams, which stamp and filter them.
2026-07-27 23:07:37 +00:00
Max
923341c98a
Stop answering cancelled requests ( #3188 )
2026-07-27 23:26:00 +01:00
Max
11934c90ae
Replace FileResource.is_binary with an encoding field ( #3171 )
2026-07-26 00:58:06 +01:00
Max
814072c94d
Narrow message_handler's parameter to notifications and exceptions ( #3168 )
2026-07-26 00:24:48 +01:00
Max
629ca297d2
Isolate the stdio server's stdin and stdout from handler subprocesses ( #3117 )
2026-07-25 13:05:51 +01:00
Max
00a70148bc
Serve the 2026-07-28 protocol over stdio: decide the era from the opening request ( #3152 )
CI / checks (push) Failing after 1s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-24 13:46:37 +01:00
Max
837ef904f8
Align with spec #3002 : optional clientInfo, serverInfo in result _meta ( #3143 )
Deploy Docs / deploy-docs (push) Has been cancelled
CI / checks (push) Failing after 24m23s
CI / all-green (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
2026-07-23 12:00:36 +01:00
Marcelo Trylesinski
03aaebd3aa
Add Streamable HTTP request body limits ( #3095 )
2026-07-16 08:33:32 +02:00
Marcelo Trylesinski
2713b53b12
Replace httpx and httpx-sse with httpx2 ( #2972 )
...
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-07-14 17:05:08 +01:00
Max
867bba6263
Share one event loop per test module to stop Windows socketpair churn ( #3070 )
2026-07-07 13:19:04 +01:00
Max
d287c9868f
Extend resolver DI to sampling and roots requests ( #3049 )
2026-07-06 18:25:57 +01:00
Max
220d362112
docs: restructure into topical sections and add the four most-asked-for pages ( #3044 )
2026-07-01 21:06:04 +01:00
Max
080f2a869d
Harden the dual-era stream loop's era-lock and rejection semantics ( #3040 )
2026-07-01 17:07:12 +01:00
Max
e50fb5be19
Serve the 2026-07-28 era over stdio and other stream-pair transports ( #3038 )
2026-07-01 00:11:56 +01:00
Max
ca10dade2c
Serve subscriptions/listen with a pluggable event bus (SEP-2575) ( #3035 )
2026-06-30 23:01:04 +01:00
Max
48ef569f7e
Validate Mcp-Param-* headers server-side on the 2026-07-28 HTTP path (SEP-2243) ( #3033 )
2026-06-30 21:39:32 +01:00
Max
4df609119f
Add a client extension API ( #3034 )
2026-06-30 21:31:02 +01:00
Max
7322ca56f4
Require integrity protection for MRTR requestState ( #3032 )
2026-06-30 21:30:32 +01:00
Max
b15b1d5f07
Add a client-side response cache honoring SEP-2549 caching hints ( #3023 )
2026-06-30 11:31:06 +01:00
Max
8d0f928e40
Pass InputRequiredResult through the MCPServer prompt and resource pipelines ( #3020 )
2026-06-29 16:50:58 +01:00
Max
8f2c97b769
Consult request_state only for the question a resolver is asking ( #3019 )
2026-06-29 16:44:05 +01:00
Max
533c6a8226
Add cache_hints constructor map for SEP-2549 caching hints ( #3015 )
2026-06-29 14:11:15 +00:00
Marcelo Trylesinski
c85836a081
Drive resolver elicitation over the 2026-07-28 input_required flow ( #2986 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 14:39:43 +01:00
Marcelo Trylesinski
f664db8952
Add resolver dependency injection for MCPServer tools ( #2969 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 11:51:46 +01:00
Marcelo Trylesinski
4b519782f1
Add a pluggable server extension API with MCP Apps ( #3003 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 10:58:05 +01:00
Max
24717cc8eb
feat: RFC 6570 URI templates with operator-aware security ( #2356 )
2026-06-26 20:29:17 +02:00
Max
067f90578c
Add SSE response mode to the 2026 streamable-HTTP server entry ( #3001 )
2026-06-26 19:09:08 +02:00
Marcelo Trylesinski
c0ecb70e24
Support RFC 8693 token exchange for enterprise IdP flows (SEP-990) ( #2988 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-26 17:57:10 +02:00
Max
08b62308d4
Client auto-resolves InputRequiredResult via existing callbacks (SEP-2322) ( #2998 )
2026-06-26 17:35:23 +02:00
Marcelo Trylesinski
3945bdde11
Remove the dispatch-tier middleware hook ( #2997 )
2026-06-26 17:08:16 +02:00
Marcelo Trylesinski
b31d95a429
Make OpenTelemetry tracing the single default middleware ( #2995 )
2026-06-26 15:47:37 +02:00
Marcelo Trylesinski
f41a5193f3
Preserve empty issuer/resource paths on AuthSettings ( #2987 )
2026-06-26 11:41:41 +02:00
Max
587340279e
Conformance burn-down: server-side InputRequiredResult, Mcp-Method/Name validation, x-mcp-header filter (14 scenarios → green) ( #2974 )
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
2026-06-26 09:51:59 +02:00
Marcelo Trylesinski
0ee7f1b293
Split protocol types into a standalone mcp-types package ( #2973 )
2026-06-25 19:18:38 +02:00
Marcelo Trylesinski
96bf22e57a
Stop flagging snake_case is_error results as tool errors in OTel span ( #2971 )
2026-06-25 15:24:45 +00:00
Marcelo Trylesinski
1b1abf6ab6
Add GenAI semantic-convention attributes to OpenTelemetryMiddleware ( #2970 )
2026-06-25 14:43:54 +00:00
Max
f226d00d0a
Client-side 2026-07-28 support: .discover()/.adopt() + Client(mode=); request-metadata green ( #2950 )
2026-06-25 16:09:23 +02:00
Max
a527142312
Buffer per-request StreamableHTTP streams to avoid serial-router head-of-line block ( #2934 )
2026-06-22 16:20:45 +01:00
Marcelo Trylesinski
ad81ca234a
Slim ServerMiddleware to (ctx, call_next) and add OpenTelemetryMiddleware ( #2941 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-22 14:46:30 +01:00
Max
2397319a68
Server-side 2026-07-28 stateless support: classifier, driver split, server/discover ( #2928 )
2026-06-21 19:34:17 +01:00
Marcelo Trylesinski
4573e4ac33
Deprecate roots, sampling, and logging methods per SEP-2577 ( #2926 )
2026-06-20 18:25:41 +02:00
冯基魁
fda4c54362
fix: correct MCPServer call_tool result type ( #2816 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2026-06-20 16:56:16 +02:00
Marcelo Trylesinski
f253682393
Return -32602 for resource not found (SEP-2164) ( #2920 )
2026-06-20 16:55:23 +02:00
Max
84bf9bde05
First end-to-end 2026-07-28 stateless tools/call (experimental entry + ClientSession pin) ( #2917 )
2026-06-20 14:55:59 +01:00
Max
510832aa45
Re-vendor 2026-07-28 schema and absorb spec #2907 error-code renumber ( #2912 )
2026-06-19 15:46:15 +01:00
Max
734746a3d9
Resolve protocol version per request and expose it as ctx.protocol_version ( #2886 )
2026-06-17 08:46:42 +01:00
Max
65be5a7147
Protocol types for 2026-07-28: superset monolith, committed per-version packages, and wire-method maps ( #2849 )
2026-06-16 17:40:14 +01:00
Max
1012d60004
[v2] ClientSession runs on JSONRPCDispatcher; BaseSession removed ( #2838 )
2026-06-15 14:46:34 +01:00
Max
7267818e44
Fix unknown-method error code and add a protocol version registry ( #2836 )
2026-06-11 16:47:22 +01:00