FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Reject non application/json POST requests by Kehrlann · Pull Request #1164 · modelcontextprotocol/java-sdk · GitHub

Repository navigation

Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension .java  (8) All 1 file type selected
Viewed files
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Unified
Split
Hide whitespace
Diff view
Unified
Split
Hide whitespace
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,32 @@
*/
final class HttpServletRequestUtils {

private static final String APPLICATION_JSON = "application/json";

private HttpServletRequestUtils() {
}

/**
* Checks whether a {@code Content-Type} header value denotes
* {@code application/json}. Only the media type is compared, case-insensitively;
* parameters such as {@code charset} are ignored. This is not a substring search, so
* a value like {@code text/plain; a=application/json} is rejected.
* <p>
* Requiring {@code application/json} prevents browsers from sending cross-origin
* JSON-RPC messages as CORS "simple requests" (e.g. with {@code text/plain}), which
* would otherwise reach the server without a preflight.
* @param contentType The {@code Content-Type} header value, may be {@code null}
* @return {@code true} if the media type is {@code application/json}
*/
static boolean isJsonContentType(String contentType) {
if (contentType == null) {
return false;
}
int parametersStart = contentType.indexOf(';');
String mediaType = parametersStart == -1 ? contentType : contentType.substring(0, parametersStart);
return APPLICATION_JSON.equalsIgnoreCase(mediaType.trim());
}

/**
* Reads the request body, decoded using the request's character encoding (or UTF-8 if
* not specified), while bounding the number of bytes read.
Expand Down
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Original file line number Diff line number Diff line change
Expand Up @@ -377,6 +377,14 @@ protected void doPost(HttpServletRequest request, HttpServletResponse response)
return;
}

if (!HttpServletRequestUtils.isJsonContentType(request.getContentType())) {
this.responseError(response, HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE,
McpError.builder(McpSchema.ErrorCodes.INVALID_REQUEST)
.message("Unsupported Media Type: Content-Type must be application/json")
.build());
return;
}

// Get the session ID from the request parameter
String sessionId = request.getParameter("sessionId");
if (sessionId == null) {
Expand Down Expand Up @@ -481,6 +489,16 @@ private void sendEvent(PrintWriter writer, String eventType, String data) throws
}
}

private void responseError(HttpServletResponse response, int httpCode, McpError mcpError) throws IOException {
response.setContentType(APPLICATION_JSON);
response.setCharacterEncoding(UTF_8);
response.setStatus(httpCode);
String jsonError = jsonMapper.writeValueAsString(mcpError);
PrintWriter writer = response.getWriter();
writer.write(jsonError);
writer.flush();
}

/**
* Cleans up resources when the servlet is being destroyed.
* <p>
Expand Down
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Original file line number Diff line number Diff line change
Expand Up @@ -168,7 +168,13 @@ protected void doPost(HttpServletRequest request, HttpServletResponse response)
return;
}

McpTransportContext transportContext = this.contextExtractor.extract(request);
if (!HttpServletRequestUtils.isJsonContentType(request.getContentType())) {
this.responseError(response, HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE,
McpError.builder(McpSchema.ErrorCodes.INVALID_REQUEST)
.message("Unsupported Media Type: Content-Type must be application/json")
.build());
return;
}

String accept = request.getHeader(ACCEPT);
if (accept == null || !(accept.contains(APPLICATION_JSON) && accept.contains(TEXT_EVENT_STREAM))) {
Expand All @@ -179,6 +185,8 @@ protected void doPost(HttpServletRequest request, HttpServletResponse response)
return;
}

McpTransportContext transportContext = this.contextExtractor.extract(request);

try {
String body = HttpServletRequestUtils.readBody(request, this.requestMaxSize);

Expand Down
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Original file line number Diff line number Diff line change
Expand Up @@ -503,6 +503,14 @@ protected void doPost(HttpServletRequest request, HttpServletResponse response)
badRequestErrors.add("application/json required in Accept header");
}

if (!HttpServletRequestUtils.isJsonContentType(request.getContentType())) {
this.responseError(response, HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE,
McpError.builder(McpSchema.ErrorCodes.INVALID_REQUEST)
.message("Unsupported Media Type: Content-Type must be application/json")
.build());
return;
}

McpTransportContext transportContext = this.contextExtractor.extract(request);

try {
Expand Down
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,9 @@
import jakarta.servlet.ServletInputStream;
import jakarta.servlet.http.HttpServletRequest;
import org.junit.jupiter.api.Test;
import org.junit.jupiter.params.ParameterizedTest;
import org.junit.jupiter.params.provider.NullAndEmptySource;
import org.junit.jupiter.params.provider.ValueSource;

import static org.assertj.core.api.Assertions.assertThat;
import static org.assertj.core.api.Assertions.assertThatThrownBy;
Expand Down Expand Up @@ -100,6 +103,22 @@ void honorsRequestCharacterEncoding() throws Exception {
assertThat(body).isEqualTo("café");
}

@ParameterizedTest
@ValueSource(strings = { "application/json", "application/json; charset=utf-8", "application/json;charset=UTF-8",
"Application/JSON", " application/json ; charset=utf-8" })
void acceptsJsonContentType(String contentType) {
assertThat(HttpServletRequestUtils.isJsonContentType(contentType)).isTrue();
}

@ParameterizedTest
@NullAndEmptySource
@ValueSource(strings = { "text/plain", "text/plain;charset=UTF-8", "text/plain; a=application/json",
"application/x-www-form-urlencoded", "multipart/form-data", "application/json-seq", "application/jsonp",
"application/json, text/plain", "text/event-stream" })
void rejectsNonJsonContentType(String contentType) {
assertThat(HttpServletRequestUtils.isJsonContentType(contentType)).isFalse();
}

private static HttpServletRequest requestWithBody(String body, String characterEncoding) throws IOException {
HttpServletRequest request = mock(HttpServletRequest.class);
when(request.getInputStream()).thenReturn(servletInputStream(body.getBytes(StandardCharsets.UTF_8)));
Expand Down
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@

package io.modelcontextprotocol.server;

import java.io.BufferedReader;
import java.io.InputStream;
import java.io.InputStreamReader;
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
Expand All @@ -12,6 +15,9 @@
import java.nio.charset.StandardCharsets;
import java.time.Duration;
import java.util.Map;
import java.util.concurrent.CompletableFuture;
import java.util.concurrent.TimeUnit;
import java.util.concurrent.atomic.AtomicBoolean;
import java.util.stream.Stream;

import io.modelcontextprotocol.AbstractMcpClientServerIntegrationTests;
Expand All @@ -22,6 +28,7 @@
import io.modelcontextprotocol.server.McpServer.SyncSpecification;
import io.modelcontextprotocol.server.transport.HttpServletSseServerTransportProvider;
import io.modelcontextprotocol.server.transport.TomcatTestUtil;
import io.modelcontextprotocol.spec.McpSchema;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import org.apache.catalina.LifecycleException;
Expand All @@ -33,8 +40,12 @@
import org.junit.jupiter.api.BeforeEach;
import org.junit.jupiter.api.Test;
import org.junit.jupiter.api.Timeout;
import org.junit.jupiter.params.ParameterizedTest;
import org.junit.jupiter.params.provider.Arguments;
import org.junit.jupiter.params.provider.ValueSource;
import reactor.core.publisher.Mono;

import static io.modelcontextprotocol.util.ToolsUtils.EMPTY_JSON_SCHEMA;
import static org.assertj.core.api.Assertions.assertThat;

@Timeout(15)
Expand Down Expand Up @@ -194,6 +205,55 @@ public void cancel() {
assertThat(response.statusCode()).isEqualTo(HttpServletResponse.SC_REQUEST_ENTITY_TOO_LARGE);
}

@ParameterizedTest
@ValueSource(strings = { "text/plain;charset=UTF-8", "application/x-www-form-urlencoded", "multipart/form-data" })
void rejectsNonJsonContentType(String contentType) throws Exception {
var httpClient = HttpClient.newHttpClient();
var toolCalled = new AtomicBoolean();
prepareAsyncServerBuilder().capabilities(McpSchema.ServerCapabilities.builder().tools(true).build())
.tools(McpServerFeatures.AsyncToolSpecification.builder()
.tool(McpSchema.Tool.builder("tool1", EMPTY_JSON_SCHEMA).build())
.callHandler((exchange, request) -> {
toolCalled.set(true);
return Mono.just(McpSchema.CallToolResult.builder().build());
})
.build())
.build();

// Establish an SSE session to obtain a valid session ID
var sseRequest = HttpRequest.newBuilder()
.uri(URI.create("http://localhost:" + PORT + CUSTOM_SSE_ENDPOINT))
.header("Accept", "text/event-stream")
.GET()
.build();
HttpResponse<InputStream> sseResponse = httpClient.send(sseRequest, HttpResponse.BodyHandlers.ofInputStream());
try (var reader = new BufferedReader(new InputStreamReader(sseResponse.body(), StandardCharsets.UTF_8))) {
var sessionIdFuture = CompletableFuture.supplyAsync(() -> reader.lines()
.filter(line -> line.startsWith("data:") && line.contains("sessionId="))
.map(line -> line.substring(line.indexOf("sessionId=") + "sessionId=".length()).strip())
.findFirst()
.orElseThrow(() -> new IllegalStateException("sessionId not found in SSE stream")));
String sessionId = sessionIdFuture.get(5, TimeUnit.SECONDS);

// CORS-safelisted content types can be sent cross-origin by a browser without
// a
// preflight, so they must be rejected before the message is handled
var request = HttpRequest.newBuilder()
.uri(URI.create("http://localhost:" + PORT + CUSTOM_MESSAGE_ENDPOINT + "?sessionId=" + sessionId))
.header("Content-Type", contentType)
.POST(HttpRequest.BodyPublishers.ofString(
"""
{"jsonrpc":"2.0","id":"call-1","method":"tools/call","params":{"name":"tool1","arguments":{}}}"""))
.build();

var response = httpClient.send(request, HttpResponse.BodyHandlers.ofString());

assertThat(response.statusCode()).isEqualTo(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE);
assertThat(response.body()).contains("Unsupported Media Type: Content-Type must be application/json");
assertThat(toolCalled).isFalse();
}
}

static McpTransportContextExtractor<HttpServletRequest> TEST_CONTEXT_EXTRACTOR = (r) -> McpTransportContext
.create(Map.of("important", "value"));

Expand Down
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@
import java.time.Duration;
import java.util.List;
import java.util.Map;
import java.util.concurrent.atomic.AtomicBoolean;
import java.util.concurrent.atomic.AtomicReference;
import java.util.function.BiFunction;
import java.util.function.Function;
Expand Down Expand Up @@ -53,6 +54,8 @@
import org.junit.jupiter.api.BeforeAll;
import org.junit.jupiter.api.Test;
import org.junit.jupiter.api.Timeout;
import org.junit.jupiter.params.ParameterizedTest;
import org.junit.jupiter.params.provider.ValueSource;
import org.slf4j.LoggerFactory;
import reactor.core.publisher.Mono;
import reactor.test.StepVerifier;
Expand Down Expand Up @@ -915,6 +918,39 @@ public void cancel() {
assertThat(response.statusCode()).isEqualTo(HttpServletResponse.SC_REQUEST_ENTITY_TOO_LARGE);
}

@ParameterizedTest
@ValueSource(strings = { "text/plain;charset=UTF-8", "application/x-www-form-urlencoded", "multipart/form-data" })
void rejectsNonJsonContentType(String contentType) throws Exception {
AtomicBoolean toolCalled = new AtomicBoolean();
McpServer.sync(mcpStatelessServerTransport)
.capabilities(ServerCapabilities.builder().tools(false).build())
.tools(McpStatelessServerFeatures.SyncToolSpecification.builder()
.tool(Tool.builder("tool1", EMPTY_JSON_SCHEMA).build())
.callHandler((transportContext, request) -> {
toolCalled.set(true);
return CallToolResult.builder().build();
})
.build())
.build();

// CORS-safelisted content types can be sent cross-origin by a browser without a
// preflight, so they must be rejected before the message is handled
var request = HttpRequest.newBuilder()
.uri(URI.create("http://localhost:" + PORT + CUSTOM_MESSAGE_ENDPOINT))
.header("Content-Type", contentType)
.header("Accept", APPLICATION_JSON + ", " + TEXT_EVENT_STREAM)
.POST(HttpRequest.BodyPublishers.ofString("""
{"jsonrpc":"2.0","id":"call-1","method":"tools/call","params":{"name":"tool1","arguments":{}}}"""))
.build();

var response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString());

assertThat(response.statusCode()).isEqualTo(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE);
assertThatJson(response.body()).inPath("message")
.isEqualTo("Unsupported Media Type: Content-Type must be application/json");
assertThat(toolCalled).isFalse();
}

private double evaluateExpression(String expression) {
// Simple expression evaluator for testing
return switch (expression) {
Expand Down
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
import java.util.Queue;
import java.util.concurrent.CompletableFuture;
import java.util.concurrent.ConcurrentLinkedQueue;
import java.util.concurrent.atomic.AtomicBoolean;
import java.util.concurrent.atomic.AtomicReference;
import java.util.function.Function;
import java.util.stream.Stream;
Expand Down Expand Up @@ -47,7 +48,9 @@
import org.junit.jupiter.api.BeforeEach;
import org.junit.jupiter.api.Test;
import org.junit.jupiter.api.Timeout;
import org.junit.jupiter.params.ParameterizedTest;
import org.junit.jupiter.params.provider.Arguments;
import org.junit.jupiter.params.provider.ValueSource;
import org.slf4j.LoggerFactory;
import reactor.core.publisher.Flux;
import reactor.core.publisher.Mono;
Expand Down Expand Up @@ -250,6 +253,61 @@ public void cancel() {
assertThat(response.statusCode()).isEqualTo(HttpServletResponse.SC_REQUEST_ENTITY_TOO_LARGE);
}

@ParameterizedTest
@ValueSource(strings = { "text/plain;charset=UTF-8", "application/x-www-form-urlencoded", "multipart/form-data" })
void rejectsInitializeWithNonJsonContentType(String contentType) throws Exception {
prepareAsyncServerBuilder().serverInfo("test-server", "1.0.0").build();

// CORS-safelisted content types can be sent cross-origin by a browser without a
// preflight, so they must be rejected before a session is created
var initialize = HttpRequest.newBuilder()
.uri(URI.create("http://localhost:" + PORT + MESSAGE_ENDPOINT))
.header("Content-Type", contentType)
.header("Accept", "text/event-stream, application/json")
.POST(HttpRequest.BodyPublishers.ofString("""
{"jsonrpc":"2.0","id":"init","method":"initialize","params":{
"protocolVersion":"2025-06-18","capabilities":{},
"clientInfo":{"name":"test-client","version":"1.0.0"}}}"""))
.build();

var response = httpClient.send(initialize, HttpResponse.BodyHandlers.ofString());

assertThat(response.statusCode()).isEqualTo(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE);
assertThat(response.body()).contains("Unsupported Media Type: Content-Type must be application/json");
assertThat(response.headers().firstValue(HttpHeaders.MCP_SESSION_ID)).isEmpty();
}

@Test
void rejectsToolCallWithNonJsonContentType() throws Exception {
var toolCalled = new AtomicBoolean();
prepareAsyncServerBuilder().serverInfo("test-server", "1.0.0")
.capabilities(McpSchema.ServerCapabilities.builder().tools(true).build())
.tools(McpServerFeatures.AsyncToolSpecification.builder()
.tool(McpSchema.Tool.builder("tool1", EMPTY_JSON_SCHEMA).build())
.callHandler((exchange, request) -> {
toolCalled.set(true);
return Mono.just(McpSchema.CallToolResult.builder().build());
})
.build())
.build();
var sessionId = initializeSession(httpClient);

var toolCall = HttpRequest.newBuilder()
.uri(URI.create("http://localhost:" + PORT + MESSAGE_ENDPOINT))
.header("Content-Type", "text/plain;charset=UTF-8")
.header("Accept", "text/event-stream, application/json")
.header(HttpHeaders.MCP_SESSION_ID, sessionId)
.POST(HttpRequest.BodyPublishers.ofString("""
{"jsonrpc":"2.0","id":"call-1","method":"tools/call","params":{"name":"tool1","arguments":{}}}"""))
.build();

var response = httpClient.send(toolCall, HttpResponse.BodyHandlers.ofString());

assertThat(response.statusCode()).isEqualTo(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE);
assertThat(response.body()).contains("Unsupported Media Type: Content-Type must be application/json");
assertThat(toolCalled).isFalse();
}

@Test
void resumedStreamReceivesServerNotifications() {
prepareAsyncServerBuilder().serverInfo("test-server", "1.0.0").build();
Expand Down
Loading

Back | FazBrowse Home | New Git URL