Skip to content

fix(http): validate Origin literals and cache known schemas - #1319

Open
GraciousGazelles wants to merge 2 commits into
modelcontextprotocol:mainfrom
sednalabs:fix/http-origin-and-schema-cache
Open

GraciousGazelles wants to merge 2 commits into
modelcontextprotocol:mainfrom
sednalabs:fix/http-origin-and-schema-cache

Conversation

@GraciousGazelles

Copy link
Copy Markdown

Unknown tool names were retained as negative schema-cache entries before request rejection. The cache now retains only successful schema lookups, preserving shared positive results while allowing unknown names and failed service lookups to be retried without persistent entries.

The HTTP Origin validator now rejects duplicate fields and malformed serialized authorities before URI component extraction. Complete IP-literal and port checks preserve valid IPv6/IPvFuture, default-port, absent-Origin and configured allowlist behavior.

Regression coverage uses the existing cache and HTTP transport seams: repeated distinct misses and factory failures, shared positive lookups, matching-allowlist malformed Origin cases, duplicate fields, and valid literal/default-port controls. No dependency or public API changes.

Validation: formatting and diff checks passed. Native hosted CI is pending; the no-local-feature test lane is required to execute the HTTP implementation and its regressions.

@GraciousGazelles
GraciousGazelles requested a review from a team as a code owner October 4, 2026 08:17
@github-actions github-actions Bot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-core Core library changes T-test Testing related changes T-transport Transport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant