Malformed requests get -32602 where JSON-RPC 2.0 requires -32600 (non-Request body) and -32601 (unknown method)
还没有人认领这个 Issue。
评估
调研方向
Start in mcp/server/streamable_http.py at the JSONRPCMessage validation handler, then trace mcp/shared/session.py::_receive_loop and server/lowlevel/server.py::_handle_request. Run the existing HTTP and session JSON-RPC tests, adding coverage for a non-Request JSON body and an unknown method. Done means each case returns its JSON-RPC-required error code while known methods with invalid params still return -32602.
由索引模型根据 Issue 内容生成。
描述
Two malformed-request shapes are answered with -32602 INVALID_PARAMS where JSON-RPC 2.0 requires a different code. Both are still present on main (checked against the 2.2.0 wheel).
1. A body that is valid JSON but not a JSON-RPC message → -32600, not -32602
mcp/server/streamable_http.py (1.28.1: lines 501-505; 2.2.0: 591-593) catches the JSONRPCMessage.model_validate ValidationError and passes INVALID_PARAMS to _create_error_response:
except ValidationError as e: # pragma: no cover
response = self._create_error_response(
f"Validation error: {str(e)}",
HTTPStatus.BAD_REQUEST,
INVALID_PARAMS, # <- a non-Request is INVALID_REQUEST, not invalid params
)
Request: POST /mcp with {"hello": "world"} → {"code": -32602, "message": "Validation error: 11 validation errors for JSONRPCMessage…"}. There are no params to be invalid, so -32600 INVALID_REQUEST is the correct code (-32700 would suit a body that does not parse as JSON at all, which this path already handles separately).
2. An unknown method → -32601, not -32602
mcp/shared/session.py (1.28.1: line 390) catches any exception from self._receive_request_type.model_validate(...) in _receive_loop and answers:
except Exception as e:
error_response = JSONRPCError(
jsonrpc="2.0",
id=message.message.root.id,
error=ErrorData(code=INVALID_PARAMS, message="Invalid request parameters", data=""),
)
An unknown method fails the ClientRequest union exactly like a bad-params request does, so it is reported as invalid params and never reaches Server._handle_request, where the else branch already returns METHOD_NOT_FOUND (server/lowlevel/server.py, ~line 801). Request: {"jsonrpc":"2.0","id":7,"method":"no/such/method","params":{}} → -32602; JSON-RPC 2.0 requires -32601 (and the existing -32602 for a known method with bad params must be preserved).
Why it matters
A client that mis-types a method is told its params are wrong, which is not the failure it has. Discovery makes it worse: /.well-known/oauth-authorization-server advertises authorization_endpoint, and spec-conformance suites that pin the JSON-RPC codes go red against a server that is otherwise healthy.
What we did locally
INVALID_REQUEST for case 1 (matching the SDK's own "Validation error:" prefix) and a read-stream filter for case 2 that answers -32601 for a method not in types.ClientRequestType, deriving the known set from the union. Both are monkeypatches because we did not want to fork; both would be unnecessary if the two call sites used the codes above. Server._handle_request's METHOD_NOT_FOUND branch suggests case 2 is unintentional.
- 主要语言
- Python
- 星标
- 24.3k
- 派生
- 4k
- 平均合并
- 1 天 19 分钟
- 30 天内合并 PR
- 29
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
modelcontextprotocol/python-sdk 的其他 Issue
-
v1 v2
难度 2/5 1-3 小时 新手友好度 85/100
modelcontextprotocol/python-sdk#3546 · 5 条评论 ·
-
v1 v2
难度 2/5 1-3 小时 新手友好度 76/100
modelcontextprotocol/python-sdk#3545 · 1 条评论 ·
-
v1 v2
难度 1/5 1 小时以内 新手友好度 91/100
modelcontextprotocol/python-sdk#3508 · 2 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 64/100
modelcontextprotocol/python-sdk#3504 ·
-
v1 v2
难度 2/5 1-3 小时 新手友好度 82/100
modelcontextprotocol/python-sdk#3492 · 1 条评论 ·
查看 modelcontextprotocol/python-sdk 的全部 Issue
相似的 Issue
-
Add: hunch 未关闭
难度 2/5 1-3 小时 新手友好度 74/100
AbdelStark/awesome-typesafe#104 ·
-
enhancement
难度 2/5 1-3 小时 新手友好度 72/100
-
难度 2/5 1-3 小时 新手友好度 68/100
DiamondLightSource/dodal#2211 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
openml/openml-python#1749 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
sipyourdrink-ltd/bernstein#6191 ·