Skip to content

fix: require metadata for modern HTTP requests - #1089

Merged
DaleSeo merged 1 commit into
mainfrom
fix/1086-request-metadata
Jul 30, 2026
Merged

fix: require metadata for modern HTTP requests#1089
DaleSeo merged 1 commit into
mainfrom
fix/1086-request-metadata

Conversation

@DaleSeo

@DaleSeo DaleSeo commented Jul 29, 2026

Copy link
Copy Markdown
Member

Fixes #1086.

Motivation and Context

Modern requests are self-contained, so the HTTP protocol-version header cannot make a request valid when the corresponding body _meta is incomplete. Previously, these requests reached tool handlers and returned successful responses.

Reject direct Streamable HTTP requests that select the 2026-07-28 protocol through the MCP-Protocol-Version header but omit required request metadata. Validation now returns HTTP 400 with JSON-RPC -32602 before dispatch, and regression coverage exercises direct tools/list, direct tools/call, and individually missing metadata fields.

How Has This Been Tested?

Add tests

Both suites pass. Focused Clippy checks, including clippy::perf, also pass for the changed targets.

Breaking Changes

None.

Validation remains at the Streamable HTTP boundary so initialized legacy sessions retain their existing behavior. clientInfo remains optional for 2026-07-28, matching the final specification; the tests explicitly preserve that behavior.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actions github-actions Bot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Jul 29, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review July 29, 2026 23:58
@DaleSeo
DaleSeo requested a review from a team as a code owner July 29, 2026 23:58
@DaleSeo DaleSeo self-assigned this Jul 29, 2026
@DaleSeo
DaleSeo merged commit 58b136f into main Jul 30, 2026
22 checks passed
@DaleSeo
DaleSeo deleted the fix/1086-request-metadata branch July 30, 2026 19:45
@github-actions github-actions Bot mentioned this pull request Jul 30, 2026
howardjohn pushed a commit to agentgateway/agentgateway that referenced this pull request Jul 31, 2026
Bump to latest stable release
https://github.com/modelcontextprotocol/rust-sdk/releases/tag/rmcp-v3.1.0

```
Added
classify authorization-required errors (modelcontextprotocol/rust-sdk#1056)
add strict stateless protocol metadata validation (modelcontextprotocol/rust-sdk#1091)
SEP-2260 stream-based enforcement of client receive-side request association (modelcontextprotocol/rust-sdk#1055)
Fixed
(model) decode metadata-bearing input-required results affecting mrtr (modelcontextprotocol/rust-sdk#1097)
require metadata for modern HTTP requests (modelcontextprotocol/rust-sdk#1089)
honor supported_protocol_versions when negotiating initialize (modelcontextprotocol/rust-sdk#1093)
Other
document the ping utility with examples (modelcontextprotocol/rust-sdk#1106)
complete Tier 1 feature docs and finalize roadmap (modelcontextprotocol/rust-sdk#1101)
(conformance) meeting requirements for tier 1 (modelcontextprotocol/rust-sdk#1087)
```

Signed-off-by: Filinto Duran <1373693+filintod@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-core Core library changes T-test Testing related changes T-transport Transport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Streamable HTTP accepts direct 2026 requests without required request _meta

2 participants