Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ All notable changes to `mcp/sdk` will be documented in this file.
* Add `HttpTransport::getSessionId()` to read the server-minted `Mcp-Session-Id`: a request-scoped caller can persist it and pass it back through the constructor's `$headers` on a later transport. Always `null` on `2026-07-28`, which removed protocol-level sessions.
* Fix OIDC discovery rejecting issuers with a trailing slash (e.g. Authentik, Auth0).
* Fix stateless SSE streams holding back frames until close when PHP output buffering is enabled.
* Reject a recognized `Mcp-Param-*` header whose mirrored argument is absent from the body with `-32020`, instead of accepting the request (SEP-2243).

0.8.0
-----
Expand Down
6 changes: 4 additions & 2 deletions src/Server/Stateless/StandardHeaderValidator.php
Original file line number Diff line number Diff line change
Expand Up @@ -227,9 +227,11 @@ private function checkParam(string $headerName, array $headers, mixed $argument)
{
$declared = $this->header($headers, $headerName);

// An omitted argument means an omitted header.
// An omitted argument means an omitted header - and the other way around.
if (null === $argument) {
return null;
return null === $declared
? null
: \sprintf('%s header is present, but the body omits the mirrored argument.', $headerName);
}

if (null === $declared) {
Expand Down
30 changes: 30 additions & 0 deletions tests/Unit/Server/Stateless/StandardHeaderValidatorTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -291,6 +291,36 @@ public function testNestedMirroredArgumentIsChecked(): void
));
}

#[TestDox('a mirrored header without its argument in the body is rejected')]
public function testMirroredHeaderWithoutArgumentIsRejected(): void
{
$validator = new StandardHeaderValidator(self::registryWithMirroredTool());

$this->assertStringContainsString('Mcp-Param-Retries header is present', (string) $validator->validate(
'tools/call',
['name' => 'mirrored', 'arguments' => []],
['Mcp-Method' => 'tools/call', 'Mcp-Name' => 'mirrored', 'Mcp-Param-Retries' => '3'],
));

$this->assertStringContainsString('Mcp-Param-Region header is present', (string) $validator->validate(
'tools/call',
['name' => 'mirrored'],
['Mcp-Method' => 'tools/call', 'Mcp-Name' => 'mirrored', 'Mcp-Param-Region' => 'us-west1'],
));
}

#[TestDox('an unknown Mcp-Param header is ignored even without a matching argument')]
public function testUnknownParamHeaderIsIgnored(): void
{
$validator = new StandardHeaderValidator(self::registryWithMirroredTool());

$this->assertNull($validator->validate(
'tools/call',
['name' => 'mirrored', 'arguments' => []],
['Mcp-Method' => 'tools/call', 'Mcp-Name' => 'mirrored', 'Mcp-Param-Unknown' => 'x'],
));
}

private static function registryWithMirroredTool(): RegistryInterface
{
$registry = new Registry();
Expand Down
Loading