| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
There was a problem hiding this comment.
Hardens server-side JSON-RPC processing against malformed payloads and unexpected PHP throwables.
Changes:
Copilot reviewed 50 out of 50 changed files in this pull request and generated 5 comments.
Show a summary per file| File | Description |
|---|---|
| src/JsonRpc/MessageFactory.php | Validates JSON-RPC method types. |
| src/Server/Protocol.php | Contains unexpected processing failures. |
| src/Schema/Annotations.php | Validates annotation payloads. |
| src/Schema/Content/AudioContent.php | Validates audio fields and annotations. |
| src/Schema/Content/BlobResourceContents.php | Validates optional blob metadata. |
| src/Schema/Content/EmbeddedResource.php | Safely hydrates annotations. |
| src/Schema/Content/PromptMessage.php | Validates content types and roles. |
| src/Schema/Content/SamplingMessage.php | Validates content types and roles. |
| src/Schema/Content/TextContent.php | Safely hydrates annotations. |
| src/Schema/Content/TextResourceContents.php | Validates optional text metadata. |
| src/Schema/Elicitation/ElicitationSchema.php | Validates required-property lists. |
| src/Schema/Extension/Apps/UiResourceContentMeta.php | Validates UI resource metadata. |
| src/Schema/Extension/Apps/UiResourceCsp.php | Validates CSP containers. |
| src/Schema/Extension/Apps/UiToolMeta.php | Validates UI tool metadata. |
| src/Schema/Icon.php | Adds safe icon-list hydration. |
| src/Schema/Implementation.php | Validates implementation metadata. |
| src/Schema/ModelPreferences.php | Validates model preferences. |
| src/Schema/Notification/CancelledNotification.php | Validates cancellation reasons. |
| src/Schema/Notification/LoggingMessageNotification.php | Validates logging fields and levels. |
| src/Schema/Notification/ProgressNotification.php | Validates numeric progress fields. |
| src/Schema/Prompt.php | Safely hydrates arguments and icons. |
| src/Schema/PromptArgument.php | Validates optional argument fields. |
| src/Schema/Request/CompletionCompleteRequest.php | Validates completion references. |
| src/Schema/Request/CreateSamplingMessageRequest.php | Validates sampling parameters. |
| src/Schema/Request/InitializeRequest.php | Validates initialization parameters. |
| src/Schema/Request/ListPromptsRequest.php | Validates prompt cursor. |
| src/Schema/Request/ListResourcesRequest.php | Validates resource cursor. |
| src/Schema/Request/ListResourceTemplatesRequest.php | Validates template cursor. |
| src/Schema/Request/ListToolsRequest.php | Validates tool cursor. |
| src/Schema/Request/SetLogLevelRequest.php | Safely validates logging levels. |
| src/Schema/ResourceDefinition.php | Validates resource metadata and icons. |
| src/Schema/ResourceTemplate.php | Validates template metadata. |
| src/Schema/Result/CallToolResult.php | Validates tool result fields. |
| src/Schema/Result/CompletionCompleteResult.php | Validates completion result fields. |
| src/Schema/Result/CreateSamplingMessageResult.php | Safely validates result roles. |
| src/Schema/Result/ElicitResult.php | Safely validates elicitation actions. |
| src/Schema/Result/GetPromptResult.php | Validates prompt result messages. |
| src/Schema/Result/InitializeResult.php | Validates initialization result metadata. |
| src/Schema/Result/ListPromptsResult.php | Validates prompt lists and cursors. |
| src/Schema/Result/ListResourcesResult.php | Validates resource lists and cursors. |
| src/Schema/Result/ListResourceTemplatesResult.php | Validates template lists and cursors. |
| src/Schema/Result/ListToolsResult.php | Validates tool lists and cursors. |
| src/Schema/Root.php | Validates optional root names. |
| src/Schema/Tool.php | Uses safe icon-list hydration. |
| src/Schema/ToolAnnotations.php | Validates tool annotation fields. |
| tests/Unit/Fixtures/ThrowingRequest.php | Provides throwable-producing fixture. |
| tests/Unit/JsonRpc/MalformedInputTest.php | Covers malformed payload hydration. |
| tests/Unit/JsonRpc/MessageFactoryTest.php | Covers invalid method types and batches. |
| tests/Unit/Schema/Result/ElicitResultTest.php | Updates invalid-action expectations. |
| tests/Unit/Server/ProtocolTest.php | Covers containment and message redaction. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Sorry, something went wrong.
| // Last line of defense: a malformed message must never escape as a PHP error and take the | ||
| // server process down. | ||
| try { | ||
| $this->doProcessInput($transport, $input, $sessionId); |
There was a problem hiding this comment.
Taking this as known issue
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Malformed input could fail with a PHP TypeError/ValueError instead of an InvalidInputMessageException. Those escape every catch on the way out — MessageFactory, Protocol::processInput(), BaseTransport::handleMessage() and Server::run() — so the peer got a dead process instead of a JSON-RPC error.
Reported by @nickelsec.