Skip to content

fix(uri-template): percent-encode non-ASCII and space literals - #3528

Closed
gyanu2507 wants to merge 1 commit into
modelcontextprotocol:mainfrom
gyanu2507:fix/uri-template-literal-encoding
Closed

gyanu2507 wants to merge 1 commit into
modelcontextprotocol:mainfrom
gyanu2507:fix/uri-template-literal-encoding

Conversation

@gyanu2507

@gyanu2507 gyanu2507 commented Sep 18, 2026

Copy link
Copy Markdown

Fixes #3526

UriTemplate copied literal runs into expand/match verbatim. RFC 6570 section 3.1 requires a literal the URI grammar does not allow (for example cafe with an accent, or a space) to be UTF-8 percent-encoded. The encoded form is also what pydantic AnyUrl puts on the wire, so a resource template with a non-ASCII or space literal was listed and could never be read.

Literals are now encoded with the existing _encode(..., allow_reserved=True) helper, so expand and match share the same encoded atoms. After this change, the raw unencoded IRI no longer matches. That is the RFC 3986 form a server never sees over the wire.

Tested with the uritemplate-test literal-encoding case, a space in the path, round-trip match of the encoded URI, and a resource-template matches() case.

RFC 6570 section 3.1 requires literals that are not valid in a URI to
be UTF-8 percent-encoded on expand. match() used the same raw literals,
so a resource template with cafe or a space in the path was listed but
could never be read once AnyUrl encoded the URI on the wire.
@github-actions github-actions Bot added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Sep 18, 2026
@github-actions

Copy link
Copy Markdown
Contributor

This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3526.

If a maintainer assigns you to #3526, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take.

You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way.

CONTRIBUTING.md has the full reasoning, but in short:

  • We're a small team with very little capacity to review community PRs right now.
  • Many recent PRs are AI-generated with little human review, and reviewing one carefully still costs a maintainer as much time as it ever did. A well-described issue is usually more useful to us than the code.

Maintainers: reopen, remove missing-issue-link, or add bypass-issue-check to override.

@github-actions github-actions Bot closed this Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A resource template with a non-ASCII or space literal is advertised but can never be read

1 participant