Repository navigation
·
2 commits
to 1.x
since this release
Immutable
release. Only release title and notes can be modified.
What's Changed
The skills extension (SEP-2640) joins the official extensions on both sides, the HTTP endpoint can require scopes per tool, prompt, or resource, and a client credential can be bound to one authorization server. The fixes cover the OAuth resource parameter, large Server-Sent Events, subscriptions/listen streams with nothing to deliver, .localhost loopback names, and the stdio client transport on Windows and at shutdown.
Added
- The skills extension (SEP-2640):
SkillsServerExtensionserves skill directories asskill://resources, andSkillClientlists skills and verifies each file it reads. OptionalClientDeclarationInterface, for a server extension whose methods a client may call without declaring it.ClientSecretCredentialandPrivateKeyJwtCredentialtake an optionalissuer.ClientCredentialsGrantrefuses a credential bound to an authorization server other than the one the protected resource names.OperationScopeMiddlewareandSecuredHttpEndpoint'soperationScopesargument: scopes a single tool, prompt, or resource needs, answered with the403insufficient_scopechallenge a client steps up on.
Fixed
- The client sends the
resourceparameter exactly as the protected resource metadata publishes it, so an authorization server that matches the identifier byte-for-byte accepts a pathless resource such ashttps://mcp.example.com. - The client parses a large Server-Sent Event in time proportional to its size, where one delivered in small chunks used to cost quadratic time and stall the event loop.
- The server answers a
subscriptions/listenthat honours no notification type right after its acknowledgement, where it used to hold the stream open with nothing to deliver. - A name under
.localhostcounts as loopback for the redirect URI and forallowInsecureLoopback, so a local setup that separates tenants by host works. StdioClientTransport's default environment also passesCOMSPEC,PATHEXT,PROGRAMDATA,PROGRAMFILES,PROGRAMFILES(X86),PROGRAMW6432andWINDIR, which programs a server launches on Windows depend on.- A script that ends without closing a started
StdioClientTransportexits cleanly, where it used to die at shutdown with a fatalFiberError.
Full Changelog: v1.0.0...v1.1.0