fix: mirror params.taskId into Mcp-Name for tasks requests (SEP-2663) - #2613
Code review found 1 important issue
Found 11 candidates, confirmed 3. See review comments for details.
Details
| Severity | Count |
|---|---|
| 🔴 Important | 1 |
| 🟡 Nit | 2 |
| 🟣 Pre-existing | 0 |
| Severity | File:Line | Issue |
|---|---|---|
| 🔴 Important | packages/core-internal/src/shared/inboundClassification.ts:472 |
Tasks methods exist only in the legacy 2025-11-25 wire era, but the Mcp-Name emission/validation machinery this PR exten |
| 🟡 Nit | packages/client/src/client/streamableHttp.ts:504 |
[quality] The Mcp-Name source-value extraction (Object.hasOwn-guarded table lookup + params?.[sourceField] + typeof-stri |
| 🟡 Nit | packages/core-internal/test/shared/standardHeaderValidation.test.ts:0 |
[quality] Stale Mcp-Name method-set doc comments left enumerating only tools/call/prompts/get/resources/read after the t |
Annotations
Check failure on line 472 in packages/core-internal/src/shared/inboundClassification.ts
claude / Claude Code Review
Tasks methods exist only in the legacy 2025-11-25 wire era, but the Mcp-Name emission/validation machinery this PR extends runs only on modern-enveloped (2026-07-28+) exchanges, so the new rows are unreachable via the SDK's own Client and only change whic
Tasks methods exist only in the legacy 2025-11-25 wire era, but the Mcp-Name emission/validation machinery this PR extends runs only on modern-enveloped (2026-07-28+) exchanges, so the new rows are unreachable via the SDK's own Client and only change which error a modern-era-nonexistent method gets. [also at: packages/core-internal/src/shared/inboundClassification.ts:474 - MCP_NAME_HEADER_SOURCE uses the wrong tasks method set: it adds a row for nonexistent 'tasks/update' and omits 'tasks/re]
Check warning on line 504 in packages/client/src/client/streamableHttp.ts
claude / Claude Code Review
[quality] The Mcp-Name source-value extraction (Object.hasOwn-guarded table lookup + params?.[sourceField] + typeof-string filter) is now duplicated verbatim between the client transport and the server validator instead of being a shared helper next to [a
[quality] The Mcp-Name source-value extraction (Object.hasOwn-guarded table lookup + params?.[sourceField] + typeof-string filter) is now duplicated verbatim between the client transport and the server validator instead of being a shared helper next to [additional confirmed claim at this location: Refactor silently drops Mcp-Name emission for off-table request methods that carry a string params.name: the removed ternary's else-branch mirrored params.name for EVERY method except resources/read, ]