mirror of
https://gitea.com/gitea/gitea-mcp.git
synced 2026-08-03 15:49:23 +02:00
fix: accept null tool arguments and bound HTTP resource use
Review follow-ups on the SDK migration. An "arguments": null is what clients send for parameterless tools like get_me, and what mcp-go accepted by returning a nil map. The new adapter rejected it with InvalidParams, which broke those calls outright. The /mcp endpoint took unlimited request bodies and never expired idle sessions, so a peer that goes away without DELETE kept its session for the process lifetime. Both are reachable before any token check, so neither can stay unbounded; the body cap sits above the SDK default to leave room for the base64 content create_or_update_file accepts. Required() smuggled a bool through the property schema map and deleted it again, colliding with the JSON Schema keyword of the same name. It now sets a field on Property, so an object property can carry its own required list. The tool contract fixture cost a manual regeneration step and four hand-maintained counts on every tool change, and a snapshot freezes defects rather than reporting them. Property assertions cover the same surface and reject a duplicate tool name, a readOnlyHint that disagrees with the register call, and a default that contradicts its own type or enum. Co-Authored-By: Claude (Opus 5) <noreply@anthropic.com>
This commit is contained in:
+17
-14
@@ -32,6 +32,15 @@ import (
|
||||
"github.com/modelcontextprotocol/go-sdk/mcp"
|
||||
)
|
||||
|
||||
// maxRequestBodyBytes raises the SDK's 4 MiB default, which is too tight for the
|
||||
// base64 file content create_or_update_file accepts.
|
||||
const maxRequestBodyBytes = 32 << 20
|
||||
|
||||
// sessionTimeout expires idle sessions, which the SDK otherwise keeps for the
|
||||
// process lifetime: a client that goes away without DELETE /mcp leaks its
|
||||
// session, and initialize takes no token. Clients re-initialize on the 404.
|
||||
const sessionTimeout = 30 * time.Minute
|
||||
|
||||
var (
|
||||
mcpServer *mcp.Server
|
||||
|
||||
@@ -95,24 +104,18 @@ func authTokenMiddleware(next mcp.MethodHandler) mcp.MethodHandler {
|
||||
}
|
||||
}
|
||||
|
||||
func newStreamableHTTPHandler(s *mcp.Server) http.Handler {
|
||||
return mcp.NewStreamableHTTPHandler(
|
||||
func newHTTPServer(addr string, s *mcp.Server) *http.Server {
|
||||
mux := http.NewServeMux()
|
||||
mux.Handle("/mcp", mcp.NewStreamableHTTPHandler(
|
||||
func(*http.Request) *mcp.Server { return s },
|
||||
&mcp.StreamableHTTPOptions{
|
||||
Logger: log.Slog(),
|
||||
MaxRequestBodyBytes: -1,
|
||||
Stateless: false,
|
||||
MaxRequestBodyBytes: maxRequestBodyBytes,
|
||||
Stateless: false, // PR 2 switches this on
|
||||
SessionTimeout: sessionTimeout,
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
func newHTTPServer(addr string, s *mcp.Server) *http.Server {
|
||||
mux := http.NewServeMux()
|
||||
mux.Handle("/mcp", newStreamableHTTPHandler(s))
|
||||
return &http.Server{
|
||||
Addr: addr,
|
||||
Handler: mux,
|
||||
}
|
||||
))
|
||||
return &http.Server{Addr: addr, Handler: mux}
|
||||
}
|
||||
|
||||
func Run() error {
|
||||
|
||||
Reference in New Issue
Block a user