| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Should this be "prior request call state"? I don't think we want other requests to effect the outcome as well right? |
Sorry, something went wrong.
|
|
||
| **Clients.** Clients become simpler: they no longer track or resend session identifiers, or need to determine whether a given server is stateful. List-endpoint caching becomes safe. | ||
|
|
||
| Rollout is a clean break: sessions are removed in the next spec version, with no deprecation window. Servers that currently rely on session-scoped state stay on the current protocol version until they have migrated to explicit handles. Protocol version negotiation already handles mixed-version deployments — a client that supports both versions speaks the old protocol to an unmigrated server and the new one to everyone else. This avoids shipping a version where clients support both modes simultaneously, which would prevent the caching benefit (a client cannot cache list endpoints if any connected server might be session-scoped). |
There was a problem hiding this comment.
Rollout is a clean break: sessions are removed in the next spec version, with no deprecation window. Servers that currently rely on session-scoped state stay on the current protocol version until they have migrated to explicit handles.
Somewhere in this SEP we should provide an example of how SDKs should handle this. I think we are essentially saying that the session functionality become a no-op.
Sorry, something went wrong.
|
This looks good to me. Supportive of this! |
Sorry, something went wrong.
|
This was reviewed by Core Maintainers: 6 Accepted, 2 Accept with Changes. |
Sorry, something went wrong.
|
New commits were pushed — removed the accepted label. Re-approve with /lgtm. |
Sorry, something went wrong.
This means that MCP Servers cannot filter tools, resources, or prompts based on authorization. Seems like a step backwards. Why list an entity the client / user can't use? Actually, I guess you could do an auth to entity permission look-up on every call. It just means greater burden on the server |
Sorry, something went wrong.
|
Continuing from #2575 (comment)
Even if all transport calls are authenticated/authorized, there is a danger that the user with lower permissions could potentially hijack the session of a super user by using their handle id. |
Sorry, something went wrong.
You can still filter based on auth. I should clarify that sentence as I can see why it looks like it implies the opposite. "Per-connection state" means relying on information sent in previous messages on the connection. The auth headers are on every request, so it is stateless. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Summary
Draft SEP proposing the removal of protocol-level sessions from MCP, replacing implicit session-scoped state with explicit, server-minted state handles. Builds on SEP-1442 (stateless-by-default) but argues the opt-in stateful path should not exist at all.
Core claims:
What changes:
Imported from modelcontextprotocol/transports-wg#25.