Repository navigation
[Server] Add PassthroughMiddleware for the HTTP transport opt-out - #526
Merged
chr-hertel merged 2 commits intoOct 6, 2026
Merged
chr-hertel merged 2 commits into
chr-hertel merged 2 commits into
Conversation
mglaman
requested review from
CodeWithKyrian,
Nyholm,
chr-hertel and
soyuka
as code owners
October 5, 2026 15:18
chr-hertel
reviewed
Oct 5, 2026
Member
|
Two things we could still do to improve this:
|
Contributor
Author
|
Done in 279e78b: shipped |
mglaman
force-pushed
the
docs/middleware-pass-through-opt-out
branch
from
October 6, 2026 16:43
7bf7b15 to
279e78b
Compare
StreamableHttpTransport logs a warning on every request when it gets an empty middleware list, but the constructor docblock and the HTTP guide still describe `[]` as the way to drop the defaults. Point integrators that already handle CORS and host validation at a pass-through middleware instead. 🤖 Assisted with AI
The docs no longer ask every host to write the same three-line class. The empty-list warning now names it, and drops "protocol version validation", which the transport applies to handshake-era requests regardless of the custom list. 🤖 Assisted with AI
chr-hertel
force-pushed
the
docs/middleware-pass-through-opt-out
branch
from
October 6, 2026 22:42
279e78b to
9878930
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #523
StreamableHttpTransportlogs a warning on every request when it getsmiddleware: []. The constructor docblock anddocs/run/http.mdstill describe[]as the way to drop the defaults, and the guide recommends it when the host application already handles CORS and host validation.This PR ships the opt-out suggested in #523 as
PassthroughMiddleware, a middleware that only calls$handler->handle($request):PassthroughMiddlewareinMcp\Server\Transport\Http\Middleware.handshakeMiddleware()to handshake-era requests regardless of the custom list.StreamableHttpTransport::__construct(): the docblock says an empty list logs a warning and points toPassthroughMiddleware.docs/run/http.md: themiddlewareparameter links to a new "Opting Out of All Middleware" section. The "run only your own chain" example passed a non-empty list but told readers to pass[], so I reworded it.StatelessHttpTransportdoesn't warn on an empty list, so it's unchanged.Tests:
testPassthroughMiddlewareDisablesDefaultsWithoutWarningchecks that the pass-through logs no warning and that CORS and DNS rebinding are off. The existing empty-list test still matches the new warning text.Checked locally: transport unit tests pass,
php-cs-fixeris clean,phpstanreports only the two existingElicitationSchema.phperrors frommain, andzensical build --strictpassed on the first commit.🤖 Generated with Claude Code