Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

[Client] Expired HTTP sessions remain marked connected, including during cancellation

Aberta
#559 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

@ineersa já está trabalhando nisso.

Desde 8/10/2026.

  • #560 de @ineersa — aberto

Avaliação

Dificuldade
4/5
Tempo estimado
3-5 dias
Facilidade para iniciantes
25/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Estagnada
Stack de tecnologia
php
Domínio
api

Direção de pesquisa

Start with src/Client/Transport/HttpTransport.php at send() and trace how HTTP responses are handled, then read src/Client/Protocol.php at notifyCancellation() to understand why notification failures are caught. Done means a session-bound 404 invalidates the session even during cancellation, preserves the original cancellation or deadline exception, and allows a fresh connection without replaying the interrupted call.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

bug

Describe the bug
Stateful Streamable HTTP session expiry is not correctly reflected in the PHP SDK’s connection state.

In the affected HttpTransport::send() implementation, HTTP status codes are not checked before processing or discarding the response body.

Consequently:

  • A session-bound HTTP 404 with an empty or plain-text body leaves the tool request waiting until timeout.
  • Client::isConnected() remains true, and subsequent requests continue using the expired session.
  • A 404 returned for notifications/cancelled is also discarded without invalidating the connection.

This concerns protocol revisions using Mcp-Session-Id, such as 2025-11-25.

To Reproduce

Ordinary tool request
  1. Initialize a connection to a stateful HTTP server and receive session ID S.
  2. Invalidate S on the server.
  3. Call a tool. The server returns HTTP 404 with an empty or plain-text body.
  4. Observe that the request waits until timeout and the client still reports itself connected.
  5. Make another call: it sends the same expired session ID.
Cancellation or deadline expiry
  1. Start a tool call using session S and leave its response pending.
  2. Invalidate the session, then cancel the call or let its deadline expire.
  3. The SDK sends notifications/cancelled with S; the server returns HTTP 404.
  4. The original call is interrupted, but the client remains marked connected despite its expired session.

Simply adding a ConnectionException for HTTP 404 is insufficient for the second case: Protocol::notifyCancellation() catches notification failures. Connection invalidation must persist independently of whether that exception reaches the caller.

Expected behavior

  • Recognize a 404 on a request carrying Mcp-Session-Id as session expiry.
  • Close the response body, clear the session ID, and mark the client uninitialized so isConnected() returns false.
  • Surface an ordinary request’s session expiry promptly as a connection failure.
  • Preserve the original cancellation/deadline exception when expiry is detected during the cancellation POST.
  • Allow a subsequent reconnect to initialize without the expired session ID.
  • Keep healthy connections reusable after cancellation or deadline expiry.

The 2025-11-25 specification, Session Management points 3–4, requires fresh initialization after a session-bound 404. It does not require automatically replaying the interrupted tool call.

Additional context

Linguagem predominante
PHP
Estrelas
1.6k
Forks
177
Merge médio
3d 1h
PRs com merge (30d)
27

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de modelcontextprotocol/php-sdk

Todas as issues de modelcontextprotocol/php-sdk

Issues semelhantes

Mais issues de PHP

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.