Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[Client] Expired HTTP sessions remain marked connected, including during cancellation

未关闭
#559 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

@ineersa 已经在做这个了。

开始于 2026年10月8日。

  • #560 来自 @ineersa —— 未关闭

评估

难度
4/5
预计耗时
3-5 天
新手友好度
25/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
停滞
技术栈
php
领域
api

调研方向

Start with src/Client/Transport/HttpTransport.php at send() and trace how HTTP responses are handled, then read src/Client/Protocol.php at notifyCancellation() to understand why notification failures are caught. Done means a session-bound 404 invalidates the session even during cancellation, preserves the original cancellation or deadline exception, and allows a fresh connection without replaying the interrupted call.

由索引模型根据 Issue 内容生成。

描述

bug

Describe the bug
Stateful Streamable HTTP session expiry is not correctly reflected in the PHP SDK’s connection state.

In the affected HttpTransport::send() implementation, HTTP status codes are not checked before processing or discarding the response body.

Consequently:

  • A session-bound HTTP 404 with an empty or plain-text body leaves the tool request waiting until timeout.
  • Client::isConnected() remains true, and subsequent requests continue using the expired session.
  • A 404 returned for notifications/cancelled is also discarded without invalidating the connection.

This concerns protocol revisions using Mcp-Session-Id, such as 2025-11-25.

To Reproduce

Ordinary tool request
  1. Initialize a connection to a stateful HTTP server and receive session ID S.
  2. Invalidate S on the server.
  3. Call a tool. The server returns HTTP 404 with an empty or plain-text body.
  4. Observe that the request waits until timeout and the client still reports itself connected.
  5. Make another call: it sends the same expired session ID.
Cancellation or deadline expiry
  1. Start a tool call using session S and leave its response pending.
  2. Invalidate the session, then cancel the call or let its deadline expire.
  3. The SDK sends notifications/cancelled with S; the server returns HTTP 404.
  4. The original call is interrupted, but the client remains marked connected despite its expired session.

Simply adding a ConnectionException for HTTP 404 is insufficient for the second case: Protocol::notifyCancellation() catches notification failures. Connection invalidation must persist independently of whether that exception reaches the caller.

Expected behavior

  • Recognize a 404 on a request carrying Mcp-Session-Id as session expiry.
  • Close the response body, clear the session ID, and mark the client uninitialized so isConnected() returns false.
  • Surface an ordinary request’s session expiry promptly as a connection failure.
  • Preserve the original cancellation/deadline exception when expiry is detected during the cancellation POST.
  • Allow a subsequent reconnect to initialize without the expired session ID.
  • Keep healthy connections reusable after cancellation or deadline expiry.

The 2025-11-25 specification, Session Management points 3–4, requires fresh initialization after a session-bound 404. It does not require automatically replaying the interrupted tool call.

Additional context

主要语言
PHP
星标
1.6k
派生
177
平均合并
3 天 1 小时
30 天内合并 PR
27

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

modelcontextprotocol/php-sdk 的其他 Issue

查看 modelcontextprotocol/php-sdk 的全部 Issue

相似的 Issue

更多 PHP Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。