mcp: expose streamable HTTP request summaries - #1101
Merged
guglielmo-san merged 9 commits intoSep 22, 2026
Merged
guglielmo-san merged 9 commits into
guglielmo-san merged 9 commits into
Conversation
…mmary # Conflicts: # mcp/streamable_test.go
…ssue-1076-request-summary
Contributor
Author
|
@guglielmo-san could you let the tests run on this PR? |
Contributor
Author
|
@guglielmo-san caught up, this is mergeable again |
guglielmo-san
approved these changes
Sep 22, 2026
This was referenced Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Streamable HTTP middleware can observe HTTP lifecycle information, but it cannot safely obtain JSON-RPC message metadata from the SDK-authoritative parse without reading and parsing the request body again. That duplicates buffering and risks retaining sensitive parameters.
This change adds a redacted
StreamableHTTPRequestSummaryand anOnRequestSummarycallback toStreamableHTTPOptions. The callback runs synchronously after the session transport decodes a POST body containing a single JSON-RPC message and before validation or dispatch. It is not invoked for deprecated JSON-RPC batches. The summary exposes only the method, a call request ID, and notification/response classification. It adds no request-body reads, replacements, or buffering.The callback receives the HTTP request context for middleware correlation. Its documentation describes concurrency, early HTTP/session/connection rejection gaps, attacker-controlled method strings, panic behavior, and its relationship to
Server.AddReceivingMiddleware.Verification:
gofmt -l .,go build ./...,go vet ./..., and staticcheck v0.8.0-rc.1 with Go 1.27.1go test ./...with Go 1.25.0 and Go 1.27.1go test -race ./...with Go 1.26.6go generate ./...leaves the worktree clean0.2.0-alpha.11: stateful server (2025-11-25), stateless server (2026-07-28), and the full client suite all pass the repository baseline checks. Results: 82 stateful assertions passed; 164 stateless assertions passed with 30 expected failures; 470 client assertions passed with 13 expected failures.Fixes #1076