[Server] Let a framework integration opt out of the HTTP edge middleware without a warning
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 62/100
Hướng nghiên cứu
Start with StreamableHttpTransport's empty-middleware warning and handshakeMiddleware(), then trace how Drupal's mcp_server integration supplies the empty list. Define an explicit opt-out that suppresses only the deliberate warning while preserving protocol validation, and keep accidental empty lists distinguishable.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
StreamableHttpTransport logs a warning whenever it gets an empty middleware list (added in #307):
Streamable HTTP transport started with an empty middleware list. Default security protections (CORS, DNS rebinding, protocol version validation) are disabled. …
In the Drupal integration (mcp_server), the empty list is deliberate. Drupal's HTTP layer already handles both edge checks:
- CORS comes from Drupal's
cors.config.CorsMiddlewarewould add a second set of CORS headers. - Host validation comes from Drupal's
trusted_host_patterns, which are regular expressions.DnsRebindingProtectionMiddlewaretakes an exact host list and answers 403 for any host not on it.
Since 0.8, the protocol version check runs through handshakeMiddleware() no matter what list is passed, so the "protocol version validation" part of the message no longer applies.
PHP builds a new transport for every request, so this warning becomes one log entry per MCP request on every Drupal site using the SDK.
Could the transport accept an explicit opt-out that doesn't warn? For example, a constructor flag, or a documented value that means "the host application handles CORS and Host validation". The warning still makes sense for an accidental [].
Downstream: https://git.drupalcode.org/project/mcp_server/-/work_items/3585939
- Ngôn ngữ chính
- PHP
- Star
- 1.6k
- Fork
- 177
- Merge trung bình
- 2 ngày 16 giờ
- Pull request đã merge (30 ngày)
- 36
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của modelcontextprotocol/php-sdk
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStanĐang mởServer
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 78/100
modelcontextprotocol/php-sdk#468 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudlyCó thể đã có người làm @ousamabenyounes đã nhận 54 ngày trước. Đang mởneeds confirmation needs maintainer action Server
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
modelcontextprotocol/php-sdk#398 · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
modelcontextprotocol/php-sdk#370 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
modelcontextprotocol/php-sdk#587 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 3/5 Nửa ngày Mức phù hợp với người mới 60/100
modelcontextprotocol/php-sdk#586 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của modelcontextprotocol/php-sdk
Issue tương tự
-
sync-en
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Maintainer thường phản hồi trong vòng 1 ngày
-
sync-en
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 4 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
ProfessionalWiki/NeoWiki#1637 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Перевод устарел
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
-
bug
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 76/100
m3ue/m3u-editor#1604 ·
Maintainer thường phản hồi trong vòng 1 ngày