modelcontextprotocol / modelcontextprotocol/python-sdk

Expose session, auth, and transport information on handler Context

Đang mở
#2,098 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

enhancement P1 v2
Ngôn ngữ chính
Python
Star
24.3k
Fork
4k
Merge trung bình
1 ngày 1 giờ
Pull request đã merge (30 ngày)
31

Mô tả

Problem

Users consistently need access to transport-level information from inside tool, resource, and prompt handlers. Today, this data exists in the system but is not accessible through the Context object that handlers receive.

There are three categories of information users are asking for:

Session identity

Users need to identify which client session they are serving — for per-session state, logging, debugging, or multi-tenant scenarios. The session ID exists at the transport layer (e.g., Mcp-Session-Id header for streamable HTTP, UUID query param for SSE) but there is no way to read it from a handler.

  • #485 — "How to get session_id in tool"
  • #942 — "How to expose mcp_session_id to user?"
Auth credentials

Users completing an OAuth flow need to access the authenticated token or claims inside their handlers. The auth middleware already validates tokens and stores them in a ContextVar (auth_context_var), but Context does not expose this.

  • #638 — "FastMCP Auth Context in tools"
Transport metadata (HTTP headers, client info)

Users need access to HTTP request headers, client IP, or other request-level metadata. The Starlette Request object is passed through as ServerMessageMetadata.request_context and lands on ServerRequestContext.request, but it is typed as Any and not surfaced on Context.

  • #750 — "How to get HTTP request headers in tools"
  • #375 — "Passing client context to tools"

Current state

The underlying data is available in the system — it just is not reachable from Context:

  • Session ID: managed by StreamableHTTPSessionManager / SseServerTransport, not exposed to handlers
  • Auth info: stored in auth_context_var by AuthContextMiddleware, not exposed to handlers
  • HTTP request: passed through as request_context: Any on ServerMessageMetadata, available on ServerRequestContext.request but not on Context

Scope

This issue is about designing and implementing access to these three categories of information on the handler Context. Key design considerations:

  • Behavior varies by transport — stdio has no session ID, headers, or auth; stateless HTTP has no session ID; SSE has a different session ID mechanism than streamable HTTP
  • The solution should work for both MCPServer (high-level) and low-level server handlers
  • Should be consistent with the direction of #2021 (typed transport context) and #1684 (explicit context parameters)

Prior art

  • PR #1608 — adds ctx.session_id by threading through InitializationOptionsServerSessionRequestContextContext

Related issues

  • #2021 — Refactor handler context to be transport- and handler-type-aware (v2 architectural)
  • #1684 — Refactor global contextvars into explicit parameters (v2 architectural)
  • #2054 — Add dependency injection support to MCPServer (v2 architectural)

AI Disclaimer

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu bằng cách lần theo Context, ServerRequestContext và ServerMessageMetadata.request_context, sau đó kiểm tra StreamableHTTPSessionManager, SseServerTransport và AuthContextMiddleware. So sánh các cách tiếp cận trong #2021, #1684 và #1608. Công việc được xem là hoàn tất khi các handler có thể truy cập nhất quán thông tin session, xác thực và transport phù hợp trên tất cả các transport được hỗ trợ, bao gồm cả những trường hợp đã được ghi lại mà dữ liệu không khả dụng.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
api, authentication, backend
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.