| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
…ion on initialize HttpServletStreamableServerTransportProvider and HttpServletStatelessServerTransport accepted POST requests regardless of Content-Type, processing text/plain and form-encoded bodies as if they were application/json. Add an early Content-Type guard in doPost() on both transports that returns HTTP 415 Unsupported Media Type when Content-Type is absent or does not start with application/json. Also validate on initialize requests that the MCP-Protocol-Version HTTP header, when present, is consistent with the protocolVersion field in the JSON-RPC body. A mismatch returns HTTP 400 with a JSON-RPC INVALID_REQUEST error. Fixes modelcontextprotocol#961 Fixes modelcontextprotocol#963 Signed-off-by: Gorre Surya <suryateja.g13@gmail.com>
…idation Covers the validation added in the previous commit: - HttpTransportValidationTests: verifies POST with non-JSON or missing Content-Type returns 415 for both streamable and stateless transports, and that application/json with charset parameter is accepted. - StreamableTransportProtocolVersionTests: verifies that a matching MCP-Protocol-Version header passes, an absent header passes, and a mismatched header returns 400. Signed-off-by: Gorre Surya <suryateja.g13@gmail.com>
|
Superseded by #1164 for the content-type |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Fixes #961 and #963.
Changes
#961 — Content-Type validation (HTTP 415)
HttpServletStreamableServerTransportProvider.doPost() accepted POST requests regardless of their Content-Type header, processing text/plain, application/x-www-form-urlencoded, and requests with no Content-Type identically to application/json requests.
Added an early guard in doPost() that returns HTTP 415 Unsupported Media Type when Content-Type is absent or does not start with application/json.
#963 — Protocol version header/body consistency on initialize
When the MCP-Protocol-Version request header on an initialize request disagrees with params.protocolVersion in the JSON-RPC body, the server now returns HTTP 400 with a JSON-RPC INVALID_PARAMS error rather than silently accepting the mismatched input.
Test plan