[Client] Expired HTTP sessions remain marked connected, including during cancellation
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 25/100
Direzione di ricerca
Start with src/Client/Transport/HttpTransport.php at send() and trace how HTTP responses are handled, then read src/Client/Protocol.php at notifyCancellation() to understand why notification failures are caught. Done means a session-bound 404 invalidates the session even during cancellation, preserves the original cancellation or deadline exception, and allows a fresh connection without replaying the interrupted call.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Describe the bug
Stateful Streamable HTTP session expiry is not correctly reflected in the PHP SDK’s connection state.
In the affected HttpTransport::send() implementation, HTTP status codes are not checked before processing or discarding the response body.
Consequently:
- A session-bound HTTP 404 with an empty or plain-text body leaves the tool request waiting until timeout.
Client::isConnected()remainstrue, and subsequent requests continue using the expired session.- A 404 returned for
notifications/cancelledis also discarded without invalidating the connection.
This concerns protocol revisions using Mcp-Session-Id, such as 2025-11-25.
To Reproduce
Ordinary tool request
- Initialize a connection to a stateful HTTP server and receive session ID
S. - Invalidate
Son the server. - Call a tool. The server returns HTTP 404 with an empty or plain-text body.
- Observe that the request waits until timeout and the client still reports itself connected.
- Make another call: it sends the same expired session ID.
Cancellation or deadline expiry
- Start a tool call using session
Sand leave its response pending. - Invalidate the session, then cancel the call or let its deadline expire.
- The SDK sends
notifications/cancelledwithS; the server returns HTTP 404. - The original call is interrupted, but the client remains marked connected despite its expired session.
Simply adding a ConnectionException for HTTP 404 is insufficient for the second case: Protocol::notifyCancellation() catches notification failures. Connection invalidation must persist independently of whether that exception reaches the caller.
Expected behavior
- Recognize a 404 on a request carrying
Mcp-Session-Idas session expiry. - Close the response body, clear the session ID, and mark the client uninitialized so
isConnected()returnsfalse. - Surface an ordinary request’s session expiry promptly as a connection failure.
- Preserve the original cancellation/deadline exception when expiry is detected during the cancellation POST.
- Allow a subsequent reconnect to initialize without the expired session ID.
- Keep healthy connections reusable after cancellation or deadline expiry.
The 2025-11-25 specification, Session Management points 3–4, requires fresh initialization after a session-bound 404. It does not require automatically replaying the interrupted tool call.
Additional context
- Related HTTP status-handling PR: #425.
- Similar reports: TypeScript SDK #1708, Python SDK #1676.
- Lingua principale
- PHP
- Stelle
- 1.6k
- Fork
- 177
- Merge medio
- 3g 1h
- PR unite (30g)
- 27
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di modelcontextprotocol/php-sdk
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStanApertaServer
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
modelcontextprotocol/php-sdk#468 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudlyForse già presa @ousamabenyounes l’ha presa 52 giorni fa. Apertaneeds confirmation needs maintainer action Server
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
modelcontextprotocol/php-sdk#398 · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
modelcontextprotocol/php-sdk#370 ·
I maintainer di solito rispondono entro 1 giorno
-
[Server][Streamable HTTP] Concurrent SSE streams on one session can consume each other's client responsesForse già presa @mglaman l’ha presa 1 giorno fa. Apertabug P2 Server
Difficoltà 4/5 3-5 giorni Idoneità per principianti 25/100
modelcontextprotocol/php-sdk#544 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Server
Difficoltà 4/5 3-5 giorni Idoneità per principianti 32/100
modelcontextprotocol/php-sdk#529 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di modelcontextprotocol/php-sdk
Issue simili
-
📚 Documentation: Placeholder link `link-to-realtime-docs` in Flutter SDK changelogForse già presa @ShyneChikwapulo l’ha presa oggi. Apertaapi / realtime product / auth product / messaging product / vcs
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 82/100
appwrite/appwrite#14272 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 75/100
Boavizta/boaviztapi#580 · 1 commento ·
-
Add PrestashopApertarequest
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
endoflife-date/endoflife.date#11303 ·
I maintainer di solito rispondono entro 1 giorno
-
0. to triage enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
I maintainer di solito rispondono entro 1 giorno