[Client] Expired HTTP sessions remain marked connected, including during cancellation
维护者通常 1 天内回复
评估
调研方向
Start with src/Client/Transport/HttpTransport.php at send() and trace how HTTP responses are handled, then read src/Client/Protocol.php at notifyCancellation() to understand why notification failures are caught. Done means a session-bound 404 invalidates the session even during cancellation, preserves the original cancellation or deadline exception, and allows a fresh connection without replaying the interrupted call.
由索引模型根据 Issue 内容生成。
描述
Describe the bug
Stateful Streamable HTTP session expiry is not correctly reflected in the PHP SDK’s connection state.
In the affected HttpTransport::send() implementation, HTTP status codes are not checked before processing or discarding the response body.
Consequently:
- A session-bound HTTP 404 with an empty or plain-text body leaves the tool request waiting until timeout.
Client::isConnected()remainstrue, and subsequent requests continue using the expired session.- A 404 returned for
notifications/cancelledis also discarded without invalidating the connection.
This concerns protocol revisions using Mcp-Session-Id, such as 2025-11-25.
To Reproduce
Ordinary tool request
- Initialize a connection to a stateful HTTP server and receive session ID
S. - Invalidate
Son the server. - Call a tool. The server returns HTTP 404 with an empty or plain-text body.
- Observe that the request waits until timeout and the client still reports itself connected.
- Make another call: it sends the same expired session ID.
Cancellation or deadline expiry
- Start a tool call using session
Sand leave its response pending. - Invalidate the session, then cancel the call or let its deadline expire.
- The SDK sends
notifications/cancelledwithS; the server returns HTTP 404. - The original call is interrupted, but the client remains marked connected despite its expired session.
Simply adding a ConnectionException for HTTP 404 is insufficient for the second case: Protocol::notifyCancellation() catches notification failures. Connection invalidation must persist independently of whether that exception reaches the caller.
Expected behavior
- Recognize a 404 on a request carrying
Mcp-Session-Idas session expiry. - Close the response body, clear the session ID, and mark the client uninitialized so
isConnected()returnsfalse. - Surface an ordinary request’s session expiry promptly as a connection failure.
- Preserve the original cancellation/deadline exception when expiry is detected during the cancellation POST.
- Allow a subsequent reconnect to initialize without the expired session ID.
- Keep healthy connections reusable after cancellation or deadline expiry.
The 2025-11-25 specification, Session Management points 3–4, requires fresh initialization after a session-bound 404. It does not require automatically replaying the interrupted tool call.
Additional context
- Related HTTP status-handling PR: #425.
- Similar reports: TypeScript SDK #1708, Python SDK #1676.
- 主要语言
- PHP
- 星标
- 1.6k
- 派生
- 177
- 平均合并
- 3 天 1 小时
- 30 天内合并 PR
- 27
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
modelcontextprotocol/php-sdk 的其他 Issue
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStan未关闭Server
难度 1/5 1 小时以内 新手友好度 78/100
modelcontextprotocol/php-sdk#468 · 2 条评论 ·
维护者通常 1 天内回复
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudly可能已有人在做 @ousamabenyounes 于 52 天前认领。 未关闭needs confirmation needs maintainer action Server
难度 2/5 1-3 小时 新手友好度 68/100
modelcontextprotocol/php-sdk#398 · 1 个 reaction ·
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 68/100
modelcontextprotocol/php-sdk#370 ·
维护者通常 1 天内回复
-
[Server][Streamable HTTP] Concurrent SSE streams on one session can consume each other's client responses可能已有人在做 @mglaman 于 1 天前认领。 未关闭bug P2 Server
难度 4/5 3-5 天 新手友好度 25/100
modelcontextprotocol/php-sdk#544 · 1 条评论 ·
维护者通常 1 天内回复
-
Server
难度 4/5 3-5 天 新手友好度 32/100
modelcontextprotocol/php-sdk#529 · 1 条评论 ·
维护者通常 1 天内回复
查看 modelcontextprotocol/php-sdk 的全部 Issue
相似的 Issue
-
spec:debating
难度 2/5 1-3 小时 新手友好度 72/100
blackie0424/tao_among#93 ·
维护者通常 1 天内回复
-
📚 Documentation: Placeholder link `link-to-realtime-docs` in Flutter SDK changelog可能已有人在做 @ShyneChikwapulo 今天认领。 未关闭api / realtime product / auth product / messaging product / vcs
难度 1/5 1 小时以内 新手友好度 82/100
appwrite/appwrite#14272 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
-
难度 1/5 1 小时以内 新手友好度 75/100
Boavizta/boaviztapi#580 · 1 条评论 ·
-
Add Prestashop未关闭request
难度 2/5 1-3 小时 新手友好度 72/100
endoflife-date/endoflife.date#11303 ·
维护者通常 1 天内回复