modelcontextprotocol / modelcontextprotocol/php-sdk
Streamable HTTP server does not validate body/header protocol-version consistency on initialize
Personne n'a encore pris cette issue.
- Langage dominant
- PHP
- Étoiles
- 1.6k
- Forks
- 173
- Merge moyen
- 2 j 49 min
- PR mergées (30 j)
- 23
Description
Describe the bug
When the initial initialize request carries an MCP-Protocol-Version HTTP header that disagrees with initialize.params.protocolVersion in the JSON-RPC body, the server accepts the request without error. In both mismatch directions, the server returned 2025-06-18 as the negotiated version rather than following either input value.
The current MCP 2025-11-25 specification does not explicitly require the server to check body/header consistency on initialize, so this is filed as an implementation observation rather than a strict spec-violation claim.
- Environment
- Reproduced with stable release
v0.5.0(fb2c8c2e) - Also reproduced with a
mainsnapshot from 2026-05-16 (5e0731f7) - Transport: Streamable HTTP server (stateful profile)
- Reproduced with stable release
To reproduce
- Start a PHP SDK Streamable HTTP server.
- Send an
initializerequest where the bodyprotocolVersionis2025-11-25but theMCP-Protocol-Versionheader is2025-03-26(or vice versa). - Observe that the server returns HTTP 200 with a normal
initializeresult. - Check the negotiated protocol version in the response.
Expected behavior
Option A: the server rejects the mismatch before negotiation, for example with HTTP 400 or a JSON-RPC Invalid Request error.
Option B: the spec clarifies which field is authoritative, and the SDK documents that behavior and covers it with a regression test.
Logs
Both mismatch directions were accepted:
body=2025-11-25 header=2025-03-26 -> HTTP 200, negotiated version = 2025-06-18 (server-determined)
body=2025-03-26 header=2025-11-25 -> HTTP 200, negotiated version = 2025-06-18 (server-determined)
The server returned its own preferred protocol version (2025-06-18) regardless of both the body and header values. In these tests, the negotiated version was server-determined rather than derived from either mismatched input.
With a Streamable HTTP server running, set ENDPOINT to the server endpoint and send an initial initialize request whose HTTP header and JSON-RPC body disagree:
ENDPOINT=http://127.0.0.1:8080/mcp
curl -i -sS --http1.1 -X POST "$ENDPOINT" \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-H 'MCP-Protocol-Version: 2025-03-26' \
--data '{"jsonrpc":"2.0","id":"init-conflict-1","method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"version-conflict-repro","version":"0.1.0"}}}'
Repeat with the values reversed: body 2025-03-26, header 2025-11-25.
Additional context
- Related: SEP-2575 introduces a related future-state requirement that, for HTTP requests, the
MCP-Protocol-Versionheader match_meta["io.modelcontextprotocol/protocolVersion"].
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez par localiser la gestion de la requête initialize du serveur Streamable HTTP du PHP SDK et reproduisez la divergence avec la commande curl fournie dans les deux sens. Décidez si les divergences doivent être rejetées ou documentées comme utilisant un champ faisant autorité, puis ajoutez une couverture pour le comportement choisi et vérifiez la réponse de version négociée.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- php
- Domaine
- api, backend
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- Calme
- Clarté
- Plutôt claire
- Accessibilité débutants
- 48/100