fix(mcp): enforce no-transform on POST SSE responses - #8303
diegosouzapw merged 1 commit into
Conversation
1234d39 to
9b449f3
Compare
|
CI note: the failing fast-path shards include repository-wide baseline failures outside this PR’s changed files (for example DashScope video assertions appear on multiple unrelated PRs). The focused tests listed in this PR body pass locally. I am still checking for any failure attributable to this patch. |
9b449f3 to
853e461
Compare
Co-Authored-By: Claude <noreply@anthropic.com>
853e461 to
cd06722
Compare
|
Maintenance update: rebased the single focused POST SSE commit onto the current Fresh focused verification after rebase:
No owner review or inline comments are currently pending. Broad fast-path failures on the prior run are outside these two files and match the repository baseline already observed on merged #8292/#8296; I have not modified unrelated code. |
|
Concrete repository-baseline evidence for the broad gates, for reviewer reference:
PR #8303 changes only the MCP transport helper and its focused regression test. I will inspect the current rerun for any changed-file failure, but will not fold unrelated baseline repairs into this PR. |
|
Current rerun inspection is complete. No failure references either changed file ( PR-attributable checks are clean: DAST, change classification, merge integrity, both Semgrep checks, and no-new-ESLint-warnings all passed; focused MCP tests, lint, typecheck, and diff checks also passed after the latest-base rebase. The PR is currently |
|
Merged into |
Co-authored-by: Ravi Tharuma <RaviTharuma@users.noreply.github.com> Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ravi Tharuma <RaviTharuma@users.noreply.github.com> Co-authored-by: Claude <noreply@anthropic.com>
Summary
Cache-Control: no-cache, no-transformno-transformwhen a POST JSON-RPC message response istext/event-stream, closing the remaining compression/buffering gap independently of SDK version behaviorVaryheaders, untouchedThis is the clean release-based replacement for closed #8291 and implements the owner-approved defense-in-depth scope for #8277.
Tests
npm exec -- tsx --test tests/unit/mcp-sse-response-headers-8277.test.ts tests/unit/mcp-session-sweep.test.tsnpx eslint open-sse/mcp-server/httpTransport.ts tests/unit/mcp-sse-response-headers-8277.test.tsnpm run typecheck:coregit diff --checkCloses #8277
Supersedes #8291
🤖 Generated with Claude Code