modelcontextprotocol / modelcontextprotocol/python-sdk

[Bug] check_capability does not validate elicitation sub-capabilities (form/url)

Offen Anfängerfreundlich
#2,965 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

bug needs confirmation P2 v2
Vorherrschende Sprache
Python
Sterne
24.3k
Forks
4k
Ø Merge
1 T. 1 Std.
Gemergte PRs (30 T.)
31

Beschreibung

Summary

Connection.check_capability() returns True when a client has URL-mode elicitation but the caller checks for form-mode elicitation — the sub-capability (ElicitationCapability.form / .url) is never inspected.

Root cause

In src/mcp/server/connection.py:340-341:

if capability.elicitation is not None and have.elicitation is None:
    return False

This only returns False when the client has no elicitation at all. It does not check individual sub-capabilities (form / url). Compare with sampling, which correctly checks sub-capabilities:

if capability.sampling is not None:
    if have.sampling is None:
        return False
    if capability.sampling.context is not None and have.sampling.context is None:
        return False
    if capability.sampling.tools is not None and have.sampling.tools is None:
        return False

Reproduction

# Client supports URL elicitation only
have = ClientCapabilities(elicitation=ElicitationCapability(url=UrlElicitationCapability()))

# Check for form elicitation — should be False (client does not have form)
want = ClientCapabilities(elicitation=ElicitationCapability(form=FormElicitationCapability()))

Connection.from_envelope("2025-11-25", client_info, have).check_capability(want)  # Returns True (BUG)

Impact

  • check_capability is public API (via ServerSession.check_client_capability)
  • Currently no production callers use elicitation sub-capability checks — low immediate impact
  • But once someone relies on it (e.g., checking if the client supports form elicitation before calling elicit_form), it will return wrong results

Additional gaps (lower priority)

  • extensionsClientCapabilities.extensions is not checked at all
  • tasksClientCapabilities.tasks and sub-capabilities entirely unhandled

Proposed fix

Add form / url sub-capability checks, matching the sampling pattern:

if capability.elicitation is not None:
    if have.elicitation is None:
        return False
    if capability.elicitation.form is not None and have.elicitation.form is None:
        return False
    if capability.elicitation.url is not None and have.elicitation.url is None:
        return False

AI assistance: Bug discovered and analyzed with AI assistance (opencode).

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne in src/mcp/server/connection.py bei den Zeilen 340–341 und vergleiche die Elicitation-Behandlung mit den bestehenden Sampling-Prüfungen. Reproduziere den im Issue beschriebenen Fall mit URL-only gegenüber form-only capabilities und überprüfe anschließend, dass übereinstimmende und nicht übereinstimmende form/url capabilities in der relevanten Testsuite die erwarteten Ergebnisse zurückgeben.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
api
Issue-Typ
Bug
Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Aktivitätsstatus
Ruhig
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
82/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.