Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ All notable changes to `mcp/sdk` will be documented in this file.
* Fix `JwtTokenValidator` with several issuers always fetching the keys of the first one: keys now come from the issuer the token claims, which must be configured.
* Fix `RequestEvent`, `ResponseEvent` and `ErrorEvent` not being dispatched for `2026-07-28` requests.
* [BC Break] Validate a tool result's `structuredContent` against the tool's `outputSchema`, which the specification requires the server to honour. A mismatch is answered with a `CallToolResult` carrying `isError: true` instead of the non-conforming value, matching the TypeScript, Python and Java SDKs. Skipped when the tool declares no `outputSchema`, when the result carries no `structuredContent`, and when the result is already an error.
* Stop the server `Protocol` from logging full JSON-RPC payloads (tool arguments, client replies) at info level: info records now carry only the method and id, the raw message is logged at debug level.

0.8.0
-----
Expand Down
9 changes: 5 additions & 4 deletions src/Server/Protocol.php
Original file line number Diff line number Diff line change
Expand Up @@ -178,7 +178,8 @@ private static function findResponseId(string $input): string|int|null
*/
private function doProcessInput(TransportInterface $transport, string $input, ?Uuid $sessionId): void
{
$this->logger->info('Received message to process.', ['message' => $input]);
$this->logger->info('Received message to process.');
$this->logger->debug('Received message payload.', ['message' => $input]);

$this->sessionManager->gc();

Expand Down Expand Up @@ -257,7 +258,7 @@ private function dispatchEvent(object $event): object
*/
private function handleRequest(TransportInterface $transport, Request $request, SessionInterface $session): void
{
$this->logger->info('Handling request.', ['request' => $request]);
$this->logger->info('Handling request.', ['method' => $request::getMethod(), 'request_id' => $request->getId()]);

$session->set(self::SESSION_ACTIVE_REQUEST_META, $request->getMeta());

Expand Down Expand Up @@ -361,7 +362,7 @@ private function handleRequest(TransportInterface $transport, Request $request,
*/
private function handleResponse(Response|Error $response, SessionInterface $session): void
{
$this->logger->info('Handling response from client.', ['response' => $response]);
$this->logger->info('Handling response from client.', ['message_id' => $response->getId()]);

$messageId = $response->getId();

Expand All @@ -381,7 +382,7 @@ private function handleResponse(Response|Error $response, SessionInterface $sess

private function handleNotification(Notification $notification, SessionInterface $session): void
{
$this->logger->info('Handling notification.', ['notification' => $notification]);
$this->logger->info('Handling notification.', ['method' => $notification::getMethod()]);

$event = $this->dispatchEvent(new NotificationEvent($notification, $session));
$notification = $event->getNotification();
Expand Down
88 changes: 88 additions & 0 deletions tests/Unit/Server/ProtocolTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,8 @@
use PHPUnit\Framework\MockObject\MockObject;
use PHPUnit\Framework\TestCase;
use Psr\EventDispatcher\EventDispatcherInterface;
use Psr\Log\AbstractLogger;
use Psr\Log\LogLevel;
use Symfony\Component\Uid\Uuid;

final class ProtocolTest extends TestCase
Expand Down Expand Up @@ -1648,4 +1650,90 @@ public function testNotificationEventWithNullDispatcher(): void
$sessionId
);
}

/**
* @return iterable<string, array{string, string}>
*/
public static function provideMessagesCarryingPayloads(): iterable
{
yield 'tools/call request' => [
'{"jsonrpc": "2.0", "id": 1, "method": "tools/call", "params": {"name": "login", "arguments": {"password": "s3cr3t-payload"}}}',
'tools/call',
];
yield 'client response to an elicitation' => [
'{"jsonrpc": "2.0", "id": 1000, "result": {"action": "accept", "content": {"password": "s3cr3t-payload"}}}',
'1000',
];
yield 'notification' => [
'{"jsonrpc": "2.0", "method": "notifications/cancelled", "params": {"requestId": 1, "reason": "s3cr3t-payload"}}',
'notifications/cancelled',
];
}

#[TestDox('Message payloads are only logged at debug level, info and above carry the method and id')]
#[DataProvider('provideMessagesCarryingPayloads')]
public function testMessagePayloadsAreOnlyLoggedAtDebugLevel(string $input, string $identifier): void
{
$handler = $this->createMock(RequestHandlerInterface::class);
$handler->method('supports')->willReturn(true);
$handler->method('handle')->willReturn(new Response(1, ['content' => []]));

$session = $this->createMock(SessionInterface::class);
$this->sessionManager->method('createWithId')->willReturn($session);
$this->sessionManager->method('exists')->willReturn(true);

$logger = new LevelRecordingLogger();
$protocol = new Protocol(
requestHandlers: [$handler],
notificationHandlers: [],
messageFactory: MessageFactory::make(),
sessionManager: $this->sessionManager,
logger: $logger,
);

$protocol->processInput($this->transport, $input, Uuid::v4());

$debug = $logger->contextsAt([LogLevel::DEBUG]);
$infoAndAbove = $logger->contextsAt([LogLevel::INFO, LogLevel::NOTICE, LogLevel::WARNING, LogLevel::ERROR, LogLevel::CRITICAL, LogLevel::ALERT, LogLevel::EMERGENCY]);

$this->assertStringNotContainsString('s3cr3t-payload', $infoAndAbove);
$this->assertStringContainsString($identifier, $infoAndAbove);
$this->assertStringContainsString('s3cr3t-payload', $debug);
}
}

/**
* Records every log entry with its level, so a test can tell what a logger
* configured at a given minimum level would have written.
*/
final class LevelRecordingLogger extends AbstractLogger
{
/** @var list<array{level: mixed, context: array<string, mixed>}> */
private array $records = [];

/**
* @param string|\Stringable $message
* @param array<string, mixed> $context
*/
public function log($level, $message, array $context = []): void
{
$this->records[] = ['level' => $level, 'context' => $context];
}

/**
* The JSON-encoded contexts of every record logged at one of the given levels.
*
* @param list<string> $levels
*/
public function contextsAt(array $levels): string
{
$contexts = [];
foreach ($this->records as $record) {
if (\in_array($record['level'], $levels, true)) {
$contexts[] = $record['context'];
}
}

return json_encode($contexts, \JSON_THROW_ON_ERROR | \JSON_UNESCAPED_SLASHES);
}
}
Loading