fix(server): parse Accept media types exactly - #2481
Conversation
🦋 Changeset detectedLatest commit: e3715bc The changes in this PR will be included in the next version bump. This PR includes changesets to release 6 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
@modelcontextprotocol/client
@modelcontextprotocol/codemod
@modelcontextprotocol/core
@modelcontextprotocol/server
@modelcontextprotocol/server-legacy
@modelcontextprotocol/express
@modelcontextprotocol/fastify
@modelcontextprotocol/hono
@modelcontextprotocol/node
commit: |
Reject Streamable HTTP requests whose Accept values only contain the required media types as substrings, while preserving case-insensitive and parameterized values. Adds GET/POST regression coverage. Fixes modelcontextprotocol#2480. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
9f897d9 to
e3715bc
Compare
|
Rebased onto current |
|
@felixweinberger, when you have a chance, could you review this? It complements #2441 by applying exact media-type parsing to |
Fixes #2480.
Summary
Streamable HTTP server
Acceptvalidation used raw substring checks, so values such asapplication/jsonxandtext/event-stream-bogusincorrectly satisfied the required concrete media types. This affected both POST negotiation and GET SSE requests.This change:
listsMediaTypehelper that parses the comma-separatedAcceptlist and compares media-type essences case-insensitively;This follows the same parsed-media-type approach recently applied to
Content-Typein #2441 / #2444, while keepingAccept-specific list parsing internal.Testing
pnpm --filter @modelcontextprotocol/core-internal test -- test/shared/mediaType.test.ts— 11 passingpnpm --filter @modelcontextprotocol/server test -- test/server/streamableHttp.test.ts— 50 passingpnpm --filter @modelcontextprotocol/core-internal check— cleanpnpm --filter @modelcontextprotocol/server check— clean