Skip to content

v1.1.0

Latest

Choose a tag to compare

@paulbalandan paulbalandan released this 05 Oct 09:00
· 2 commits to 1.x since this release
Immutable release. Only release title and notes can be modified.
v1.1.0
ba7e910

What's Changed

The skills extension (SEP-2640) joins the official extensions on both sides, the HTTP endpoint can require scopes per tool, prompt, or resource, and a client credential can be bound to one authorization server. The fixes cover the OAuth resource parameter, large Server-Sent Events, subscriptions/listen streams with nothing to deliver, .localhost loopback names, and the stdio client transport on Windows and at shutdown.

Added

  • The skills extension (SEP-2640): SkillsServerExtension serves skill directories as skill:// resources, and SkillClient lists skills and verifies each file it reads.
  • OptionalClientDeclarationInterface, for a server extension whose methods a client may call without declaring it.
  • ClientSecretCredential and PrivateKeyJwtCredential take an optional issuer. ClientCredentialsGrant refuses a credential bound to an authorization server other than the one the protected resource names.
  • OperationScopeMiddleware and SecuredHttpEndpoint's operationScopes argument: scopes a single tool, prompt, or resource needs, answered with the 403 insufficient_scope challenge a client steps up on.

Fixed

  • The client sends the resource parameter exactly as the protected resource metadata publishes it, so an authorization server that matches the identifier byte-for-byte accepts a pathless resource such as https://mcp.example.com.
  • The client parses a large Server-Sent Event in time proportional to its size, where one delivered in small chunks used to cost quadratic time and stall the event loop.
  • The server answers a subscriptions/listen that honours no notification type right after its acknowledgement, where it used to hold the stream open with nothing to deliver.
  • A name under .localhost counts as loopback for the redirect URI and for allowInsecureLoopback, so a local setup that separates tenants by host works.
  • StdioClientTransport's default environment also passes COMSPEC, PATHEXT, PROGRAMDATA, PROGRAMFILES, PROGRAMFILES(X86), PROGRAMW6432 and WINDIR, which programs a server launches on Windows depend on.
  • A script that ends without closing a started StdioClientTransport exits cleanly, where it used to die at shutdown with a fatal FiberError.

Full Changelog: v1.0.0...v1.1.0