Skip to content

v1.7.0

Latest

Choose a tag to compare

@koic koic released this 05 Oct 10:35
· 2 commits to main since this release
d4202c2

This release lets a web application finish the OAuth authorization in the request that receives the redirect, bounds the initialize request a session retains and the resource URIs a subscriptions/listen stream retains, validates icons given as Hashes through MCP::Icon, and repairs two subscriptions/listen cases: a request that cannot be encoded is refused, and a removed stream is marked closed.
The two bounds and the icon validation reject what earlier releases accepted and ship in a minor release under the exceptions described in VERSIONING.md; raise max_initialize_request_bytes: and max_resource_subscription_bytes: (or set them to nil) where the byte bounds are too tight, and give Hash icons only the MCP::Icon members with a valid src.

Added

  • Let a web application finish authorization in the request that receives the redirect (#573)
  • Bound the resource URIs a subscriptions/listen stream retains (#582)
  • Bound the initialize request a session retains (#583)

Changed

  • Validate icons given as Hashes through MCP::Icon (#586)

Fixed

  • Refuse subscriptions/listen requests that cannot be encoded (#585)
  • Mark a removed subscriptions/listen stream closed (#587)