Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[Server] Let a framework integration opt out of the HTTP edge middleware without a warning

Đã đóng
#523 4 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
62/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
php
Lĩnh vực
api, backend, security

Hướng nghiên cứu

Start with StreamableHttpTransport's empty-middleware warning and handshakeMiddleware(), then trace how Drupal's mcp_server integration supplies the empty list. Define an explicit opt-out that suppresses only the deliberate warning while preserving protocol validation, and keep accidental empty lists distinguishable.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

enhancement Server

StreamableHttpTransport logs a warning whenever it gets an empty middleware list (added in #307):

Streamable HTTP transport started with an empty middleware list. Default security protections (CORS, DNS rebinding, protocol version validation) are disabled. …

In the Drupal integration (mcp_server), the empty list is deliberate. Drupal's HTTP layer already handles both edge checks:

  • CORS comes from Drupal's cors.config. CorsMiddleware would add a second set of CORS headers.
  • Host validation comes from Drupal's trusted_host_patterns, which are regular expressions. DnsRebindingProtectionMiddleware takes an exact host list and answers 403 for any host not on it.

Since 0.8, the protocol version check runs through handshakeMiddleware() no matter what list is passed, so the "protocol version validation" part of the message no longer applies.

PHP builds a new transport for every request, so this warning becomes one log entry per MCP request on every Drupal site using the SDK.

Could the transport accept an explicit opt-out that doesn't warn? For example, a constructor flag, or a documented value that means "the host application handles CORS and Host validation". The warning still makes sense for an accidental [].

Downstream: https://git.drupalcode.org/project/mcp_server/-/work_items/3585939

Ngôn ngữ chính
PHP
Star
1.6k
Fork
177
Merge trung bình
2 ngày 16 giờ
Pull request đã merge (30 ngày)
36

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của modelcontextprotocol/php-sdk

Tất cả issue của modelcontextprotocol/php-sdk

Issue tương tự

Thêm issue về PHP

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.