FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[Server] Reject JSON-RPC batch requests by ez-lbz · Pull Request #424 · modelcontextprotocol/php-sdk · GitHub

Repository navigation

[Server] Reject JSON-RPC batch requests - #424

Open
ez-lbz wants to merge 3 commits into
modelcontextprotocol:mainfrom
ez-lbz:reject-jsonrpc-batches
Open

ez-lbz wants to merge 3 commits into
modelcontextprotocol:mainfrom
ez-lbz:reject-jsonrpc-batches

Conversation

ez-lbz commented Aug 16, 2026

Copy link
Copy Markdown

MCP no longer supports JSON-RPC batches: a POST body must be a single JSON-RPC message. MessageFactory currently accepts top-level arrays and hydrates each entry, so a batch is processed as a set of messages instead of being refused outright.

This change rejects any top-level array as invalid input before any entry is hydrated, returning a single InvalidInputMessageException (the existing per-message error contract) instead of processing the batch. The now-dead maxBatchSize cap, its constructor parameter, and DEFAULT_MAX_BATCH_SIZE are removed.

Tests:

  • MessageFactoryTest: batch payloads (valid, mixed, and error-containing) are asserted to be rejected wholesale; obsolete maxBatchSize tests removed.
  • MalformedInputTest: a batch payload is asserted to be rejected without hydrating any entry.
  • Server\ProtocolTest: batch input is asserted to produce a single Invalid Request error and to never hydrate batch entries.

MCP no longer supports JSON-RPC batches: a POST body must be a single
JSON-RPC message. MessageFactory currently accepts top-level arrays and
hydrates each entry, so a batch is handled as a set of messages instead
of being refused outright.

Reject any top-level array as invalid input before any entry is hydrated,
and drop the now-dead maxBatchSize cap and its constructor parameter.
Update the affected unit tests and the transports docs to match.
chr-hertel added the Server Issues & PRs related to the Server component label Aug 16, 2026
chr-hertel added this to the 0.9.0 milestone Aug 16, 2026

chr-hertel left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Hi @ez-lbz, thanks for bringing this up - this will simplify that part message handling quite a bit :)

Comment on lines 100 to 104
* @return array<MessageInterface|InvalidInputMessageException>
*
* @throws \JsonException When the input string is not valid JSON
*/
public function create(string $input): array

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

this can be simplified even further now:

Suggested change
* @throws InvalidInputMessageException When the input data is not a valid message
* @throws \JsonException When the input string is not valid JSON
*/
public function create(string $input): MessageInterface

Comment thread src/JsonRpc/MessageFactory.php Outdated
$batch = $data;
} else {
$batch = [$data];
return [new InvalidInputMessageException('JSON-RPC batch requests are not supported; send a single JSON-RPC message.')];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality
Suggested change
return [new InvalidInputMessageException('JSON-RPC batch requests are not supported; send a single JSON-RPC message.')];
return [new InvalidInputMessageException('JSON-RPC batch requests are not supported anymore since specification release 2025-06-18; send a single JSON-RPC message.')];

chr-hertel added the needs more work Not ready to be merged yet, needs additional follow-up from the author(s). label Aug 16, 2026

ez-lbz commented Aug 17, 2026

Copy link
Copy Markdown
Author

Thanks for the review! Applied the suggestion to reference the spec release that removed batches in the error message (commit 752c430). The maxBatchSize parameter and cap were already removed as dead code in the original change.

chr-hertel added breaking change Breaking the Backwards Compatibility Promise on hold Blocked on external dependency (SEP, other PR, decision) and removed needs more work Not ready to be merged yet, needs additional follow-up from the author(s). labels Sep 7, 2026
chr-hertel removed this from the 0.9.0 milestone Sep 7, 2026
chr-hertel added the needs confirmation Needs confirmation that the PR is actually required or needed. label Sep 7, 2026

Copy link
Copy Markdown
Member

Putting this on hold for now - the spec version 2025-06-18 removed batch support but we currently still support that version. Will check back, in my understanding we only need to support the current and two older versions, but need to check back.

Anyhow, when we tackle this, we should go even one step further and change the method profile to Mcp\JsonRpc\MessageFactory::create(string $input): MessageInterface

This branch has not been deployed

No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking change Breaking the Backwards Compatibility Promise needs confirmation Needs confirmation that the PR is actually required or needed. on hold Blocked on external dependency (SEP, other PR, decision) Server Issues & PRs related to the Server component

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL