One placeholder-less resource template makes the whole server unserviceable
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 72/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- php
调研方向
从 Builder::addResourceTemplate() 开始,然后阅读 ResourceTemplate.php 和 ReflectedElementLoader.php,以了解当前在哪里拒绝无效 URI。跟踪 Registry::load() 和延迟加载路径,以确认失败发生的时机。完成标准是:不含占位符的模板在注册期间而不是首次请求时被拒绝,同时不会阻止有效元素被注册。
由索引模型根据 Issue 内容生成。
描述
Reported by Mariano Damian Ferro Villanueva via email, opening it here on their behalf.
Problem
A #[McpResourceTemplate] whose uriTemplate contains no placeholder takes the whole server down, not just that one template.
#[McpResourceTemplate(
uriTemplate: 'data://tags',
name: 'all_tags',
title: 'All Tags',
description: 'All Tags',
mimeType: 'application/json'
)]
public function tag_all(?int $paged = 1): array
{
// ...
}
The handshake still succeeds, and then every request fails, including ones that have nothing to do with resources:
tools/list -> {"jsonrpc":"2.0","id":2,"error":{"code":-32602,"message":"Error registering manual resource template 'data://tags': Invalid URI template : \"data://tags\" must be a valid URI template with at least one placeholder."}}
tools/call -> {"jsonrpc":"2.0","id":3,"error":{"code":-32602,"message":"Error registering manual resource template 'data://tags': Invalid URI template : \"data://tags\" must be a valid URI template with at least one placeholder."}}
Reproduced on main against Server::builder() with the Streamable HTTP transport, on both the handshake and the 2026-07-28 lifecycle.
Cause
ResourceTemplate::__construct()requires at least one placeholder and throws (src/Schema/ResourceTemplate.php#L59-L61).ReflectedElementLoaderwraps that into aConfigurationException(ReflectedElementLoader.php#L214-L219), which abortsRegistry::load()before any element is registered.Builder::$lazyLoadingdefaults totrue, so that load runs on the first read during request handling.Registry::load()setsloadedonly on success, so every subsequent request retries and fails the same way.
So one misconfigured element is enough to make a server serve nothing, and the client is told -32602 (Invalid params) for what is a server-side configuration error it cannot do anything about.
The original report saw it as a 500 with Cannot modify header information - headers already sent (output started at /vendor/symfony/http-foundation/Response.php:393), which is how it surfaces once the response is already being written. I could not reproduce that part on main, so treat it as a symptom of the surrounding stack rather than part of this issue.
Secondary issue: inconsistent handling
The same mistake behaves differently depending on the registration path:
ReflectedElementLoaderthrowsConfigurationException, a hard failure taking down the registry.Discoverer::processFile()catches\Throwable, logs it and continues, so an attribute-discovered template with the same mistake is silently dropped.
Suggested fix
Validate the URI template in Builder::addResourceTemplate(), where the developer wrote it, instead of at the first read of the registry. PR follows.
Worth considering separately: a ConfigurationException reaching a client as -32602 is misleading (it is caught by catch (\InvalidArgumentException) in Protocol), and a single failing element aborting the whole registry load is a large blast radius for any other configuration mistake.
Line references are against main.
- 主要语言
- PHP
- 星标
- 1.6k
- 派生
- 173
- 平均合并
- 19 小时 19 分钟
- 30 天内合并 PR
- 8
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
modelcontextprotocol/php-sdk 的其他 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 78/100
modelcontextprotocol/php-sdk#516 ·
维护者通常 1 天内回复
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStan未关闭Server
难度 1/5 1 小时以内 新手友好度 78/100
modelcontextprotocol/php-sdk#468 · 2 条评论 ·
维护者通常 1 天内回复
-
needs confirmation needs maintainer action Server
难度 2/5 1-3 小时 新手友好度 68/100
modelcontextprotocol/php-sdk#398 · 1 个 reaction ·
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 68/100
modelcontextprotocol/php-sdk#370 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 74/100
modelcontextprotocol/php-sdk#524 ·
维护者通常 1 天内回复
查看 modelcontextprotocol/php-sdk 的全部 Issue
相似的 Issue
-
type/bug
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
bug No Code Attached Yet
难度 2/5 1-3 小时 新手友好度 88/100
joomla/joomla-cms#48556 · 1 条评论 ·
维护者通常 1 天内回复
-
sync-en
难度 1/5 1 小时以内 新手友好度 92/100
维护者通常 1 天内回复
-
sync-en
难度 2/5 1-3 小时 新手友好度 74/100
维护者通常 3 天内回复
-
Перевод устарел
难度 1/5 1-3 小时 新手友好度 88/100