[Client] Expired HTTP sessions remain marked connected, including during cancellation
Maintainer antworten meist innerhalb von 1 Tag
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 25/100
Rechercherichtung
Start with src/Client/Transport/HttpTransport.php at send() and trace how HTTP responses are handled, then read src/Client/Protocol.php at notifyCancellation() to understand why notification failures are caught. Done means a session-bound 404 invalidates the session even during cancellation, preserves the original cancellation or deadline exception, and allows a fresh connection without replaying the interrupted call.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Describe the bug
Stateful Streamable HTTP session expiry is not correctly reflected in the PHP SDK’s connection state.
In the affected HttpTransport::send() implementation, HTTP status codes are not checked before processing or discarding the response body.
Consequently:
- A session-bound HTTP 404 with an empty or plain-text body leaves the tool request waiting until timeout.
Client::isConnected()remainstrue, and subsequent requests continue using the expired session.- A 404 returned for
notifications/cancelledis also discarded without invalidating the connection.
This concerns protocol revisions using Mcp-Session-Id, such as 2025-11-25.
To Reproduce
Ordinary tool request
- Initialize a connection to a stateful HTTP server and receive session ID
S. - Invalidate
Son the server. - Call a tool. The server returns HTTP 404 with an empty or plain-text body.
- Observe that the request waits until timeout and the client still reports itself connected.
- Make another call: it sends the same expired session ID.
Cancellation or deadline expiry
- Start a tool call using session
Sand leave its response pending. - Invalidate the session, then cancel the call or let its deadline expire.
- The SDK sends
notifications/cancelledwithS; the server returns HTTP 404. - The original call is interrupted, but the client remains marked connected despite its expired session.
Simply adding a ConnectionException for HTTP 404 is insufficient for the second case: Protocol::notifyCancellation() catches notification failures. Connection invalidation must persist independently of whether that exception reaches the caller.
Expected behavior
- Recognize a 404 on a request carrying
Mcp-Session-Idas session expiry. - Close the response body, clear the session ID, and mark the client uninitialized so
isConnected()returnsfalse. - Surface an ordinary request’s session expiry promptly as a connection failure.
- Preserve the original cancellation/deadline exception when expiry is detected during the cancellation POST.
- Allow a subsequent reconnect to initialize without the expired session ID.
- Keep healthy connections reusable after cancellation or deadline expiry.
The 2025-11-25 specification, Session Management points 3–4, requires fresh initialization after a session-bound 404. It does not require automatically replaying the interrupted tool call.
Additional context
- Related HTTP status-handling PR: #425.
- Similar reports: TypeScript SDK #1708, Python SDK #1676.
- Vorherrschende Sprache
- PHP
- Sterne
- 1.6k
- Forks
- 177
- Ø Merge
- 3 T. 1 Std.
- Gemergte PRs (30 T.)
- 27
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus modelcontextprotocol/php-sdk
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStanOffenServer
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 78/100
modelcontextprotocol/php-sdk#468 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudlyEvtl. vergeben @ousamabenyounes hat das vor 53 Tagen übernommen. Offenneeds confirmation needs maintainer action Server
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
modelcontextprotocol/php-sdk#398 · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
modelcontextprotocol/php-sdk#370 ·
Maintainer antworten meist innerhalb von 1 Tag
-
[Server][Streamable HTTP] Concurrent SSE streams on one session can consume each other's client responsesEvtl. vergeben @mglaman hat das vor 2 Tagen übernommen. Offenbug P2 Server
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 25/100
modelcontextprotocol/php-sdk#544 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Server
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 32/100
modelcontextprotocol/php-sdk#529 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in modelcontextprotocol/php-sdk
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
codeigniter4/CodeIgniter4#10616 ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug code quality
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
SemanticMediaWiki/SemanticMediaWiki#7149 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
-
bug
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 82/100
FriendsOfFlarum/upload#527 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
google/site-kit-wp#13825 ·
Maintainer antworten meist innerhalb von 3 Tagen