Commit graph

2,460 commits

Author SHA1 Message Date
Jeremiah Lowin
b5f88bfe42
Merge pull request #2426 from jlowin/simplify-object-schema-check v2.13.1
Simplify _is_object_schema helper
2025-11-15 12:39:04 -05:00
Jeremiah Lowin
e9667b6624 Fix test regex pattern for updated error message 2025-11-15 12:32:37 -05:00
Jeremiah Lowin
0af1c78cc9 Simplify _is_object_schema helper function 2025-11-15 12:27:37 -05:00
Jeremiah Lowin
e6936d0bf1
Merge pull request #2422 from jlowin/exclude-mcp-1.21.1-add-scope-validation
Exclude MCP SDK 1.21.1 and add scope validation to InMemoryOAuthProvider
2025-11-15 12:22:44 -05:00
Jeremiah Lowin
533cfb66fa
Merge pull request #2424 from jlowin/fix-bug-report-dI2C9
Fix self-referencing types not being recognized as object schemas
2025-11-15 12:21:21 -05:00
Jeremiah Lowin
f6635aa15b Fix type errors in oauth_proxy and test_auth_integration
- Add null checks for client_id before using in OAuthTransaction, AuthorizationCode, AccessToken, RefreshToken
- Add null check for redirect_uris before len() call
- Import AuthorizeError from mcp.server.auth.provider
2025-11-15 12:21:15 -05:00
Jeremiah Lowin
3826f1a240 Fix typos and formatting 2025-11-15 12:21:15 -05:00
Jeremiah Lowin
c7f4ff2cbe Add scope validation to InMemoryOAuthProvider and remove debug breakpoint
- Add scope validation to InMemoryOAuthProvider.register_client() to match MCP SDK behavior
- Ensures unit tests catch scope-related bugs like the MCP SDK 1.21.1 issue
- Remove debug breakpoint from OAuth client redirect_handler
2025-11-15 12:21:15 -05:00
Jeremiah Lowin
ec38507f9b Exclude MCP SDK 1.21.1 and update OAuth client tests
- Exclude MCP SDK 1.21.1 due to bug adding metadata URL to scopes
- Update OAuth client tests to use valid scopes
2025-11-15 12:21:15 -05:00
Jeremiah Lowin
e3ed74b794
docs: fix run_server_async documentation (#2423)
Remove incorrect task_group parameter and AnyIO references. Update to show correct async context manager usage matching actual implementation.

Fixes #2395

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Jeremiah Lowin <jlowin@users.noreply.github.com>
2025-11-15 12:07:22 -05:00
Jeremiah Lowin
d40f22b3e6 Fix type errors in oauth_proxy and test_auth_integration
- Add null checks for client_id before using in OAuthTransaction, AuthorizationCode, AccessToken, RefreshToken
- Add null check for redirect_uris before len() call
- Import AuthorizeError from mcp.server.auth.provider
2025-11-15 12:06:33 -05:00
Jeremiah Lowin
6df54c0729 Fix typos and formatting 2025-11-15 12:04:51 -05:00
Jeremiah Lowin
1895f86323 Add scope validation to InMemoryOAuthProvider and remove debug breakpoint
- Add scope validation to InMemoryOAuthProvider.register_client() to match MCP SDK behavior
- Ensures unit tests catch scope-related bugs like the MCP SDK 1.21.1 issue
- Remove debug breakpoint from OAuth client redirect_handler
2025-11-15 12:02:28 -05:00
Jeremiah Lowin
a98838c158 Exclude MCP SDK 1.21.1 and update OAuth client tests
- Exclude MCP SDK 1.21.1 due to bug adding metadata URL to scopes
- Update OAuth client tests to use valid scopes
2025-11-15 11:58:14 -05:00
Kiran Thakkar
ab683f178b
OCI Provider with Docs (#2389)
* OCI Provider with Docs

* Addressing feedback and adding improvements

* Addressing feedback and adding improvements

* Fixed Step Typo and Images

* Fixed Language Identifier

* Fixed Code Check Issues

* Fixed Identity Propagation Trust Command

* Renamed ociprovider to oci and fixed documentation

* Renamed ociprovider to oci

* Fixed Config URL

* Fixed TokenExchange variable

* Fixed Environment Variables

* Fixed Environment Variables

* Fixed Ruff Check

* Fixed Code Rabbit Comments

* Fixed Code Rabbit Comments
2025-11-15 11:04:47 -05:00
Jeremiah Lowin
bc076cba12
Handle request_context availability during MCP initialization (#2400)
The on_initialize hook (2.13.0) runs before the MCP session is established, causing request_context
to be unavailable. Changed request_context to return None instead of raising, allowing middleware to
check availability and use HTTP helpers when needed. Updated docs to guide this pattern.

Closes #2393
2025-11-15 10:50:24 -05:00
ChristophNetsch
67f9329b83
fix(OpenAPIParser): Fix missing $defs for response schemas in experimental OpenAPI parser (#2398)
* fix(OpenAPIParser): Fix missing  for response schemas in experimental OpenAPI parser

* chore: run linting

---------

Co-authored-by: Christoph Netsch <netsch@alpamayo.ch>
2025-11-15 10:50:00 -05:00
William Easton
be9c27fec4
Claude triage for test failures (#2407) 2025-11-15 10:35:27 -05:00
William Easton
8e0c6c8685
docs: clarify pytest-asyncio dependency and asyncio mode configuration (#2399)
* docs: clarify pytest-asyncio dependency and asyncio mode configuration

Added a Prerequisites section to the testing documentation explaining:
- pytest-asyncio is required for async test functions and fixtures
- Recommended configuration: asyncio_mode = 'auto' in pyproject.toml
- This eliminates need for @pytest.mark.asyncio decorators

Resolves #2372

Co-authored-by: William Easton <strawgate@users.noreply.github.com>

* feat: add testing_demo example with comprehensive test suite

Add a standalone example project demonstrating FastMCP testing patterns:
- Tools, resources, and prompts with full test coverage
- pytest-asyncio configuration in pyproject.toml
- 18 passing tests showing async fixtures, parametrized tests, and more
- Documentation explaining testing best practices

Co-authored-by: William Easton <strawgate@users.noreply.github.com>

---------

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: William Easton <strawgate@users.noreply.github.com>
2025-11-15 10:34:29 -05:00
EdenTrainorCDL
dffaa0bfce
fix(oauth_proxy): 🐛 add _extra_token_params as kwargs in refresh_token call (#2387)
custom oauth providers sometimes require extra parameters in their token calls, hence the need for the _extra_token_params in the inital token request. This PR includes those extra token params in the token refresh request too.
2025-11-15 10:33:51 -05:00
Sean McGrath
f7c89e2630
fix: upstream token cache expires when refresh expires (#2410)
* fix: upstream token cache expires when refresh expires

* fix: handle case where no refresh token provided
2025-11-15 10:32:34 -05:00
Lawrence
d191995840
Update CSP to allow data URI images on OAuth screens (#2405)
* Update CSP to allow data URI images

* Fix formatting issue
2025-11-15 10:30:31 -05:00
Patrick Stöckle
18d4a6ab63
chore(typos): fix additional typos (#2396) 2025-11-08 10:47:56 -05:00
Jeremiah Lowin
0fa3097153
Add version badge for DebugTokenVerifier in documentation (#2390)
Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Jeremiah Lowin <jlowin@users.noreply.github.com>
2025-11-06 18:25:26 -05:00
William Easton
05ac9457b8
Fix duplicate keyword argument error in configure_logging (#2381)
Allow traceback-related kwargs to override defaults by building a dict
with defaults first, then updating with user-provided values.

Fixes #2356

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: William Easton <strawgate@users.noreply.github.com>
2025-11-06 10:11:16 -05:00
Jeremiah Lowin
f8b896490e
Fix Windows test timeout and restore parallel testing (#2383)
OAuth consent tests were timing out on Windows due to SQLite database
locking when OAuthProxy instances used the default DiskStore without
explicit MemoryStore configuration. Added explicit client_storage=MemoryStore()
to three tests in TestConsentPageServerIcon.

Also restored parallel testing on Windows (--numprocesses auto) which
was previously disabled but is now safe with proper test isolation.
2025-11-05 20:25:10 -05:00
Cemal Kılıç
f540385b58
feat: add algorithm configuration to Supabase auth provider (#2376) 2025-11-05 20:21:10 -05:00
Jeremiah Lowin
48fc8cbc9a
Fix consent form action for subpath mounting (#2382)
* Fix consent form action for subpath mounting

When a FastMCP server is mounted at a subpath (e.g., /api/v1), the consent
form used a hardcoded absolute path (/consent/submit) that didn't include
the mount prefix, causing 404 errors on submission.

Changed the form to use an empty action (action="") which submits to the
current URL, making it work correctly regardless of mount path. Also
consolidated the consent endpoints to handle both GET and POST at /consent.

Fixes #2380

* Update integration test to use /consent instead of /consent/submit
2025-11-05 20:20:38 -05:00
Giovanna Zanardini
a6ddde27df
Allow OAuth instance to use the same httpx factory as the Transport (#2324)
* Allow OAuth instance to use the same httpx factory as the Transport

* Fix test

* Update SSL verification mode assertion in tests

* This is actually not needed

* Creating a Client instance is not needed for this test

* Fix test

* Apply httpx_client_factory fix to SSETransport

Extends the OAuth httpx_client_factory changes to SSETransport.
SSETransport had the same issues as StreamableHttpTransport where it
wasn't passing the custom httpx client factory to OAuth, causing
certificate verification settings to be ignored during OAuth flows.

Changes:
- Set httpx_client_factory before calling _set_auth()
- Pass httpx_client_factory to OAuth constructor
- Add test for SSETransport OAuth client factory propagation

---------

Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
2025-11-04 12:14:28 -05:00
Jeremiah Lowin
a7563a39b0
Fix get_http_headers() returning empty dict in on_initialize middleware (#2370) 2025-11-04 11:56:43 -05:00
Jeremiah Lowin
a359b0b28d
Document client meta parameter for sending ancillary request data (#2367) 2025-11-04 11:32:31 -05:00
Jeremiah Lowin
80d10d23f4
Fix: URL-encode server name in Cursor deeplinks (#2369)
Server names with special characters (&, ?, #, etc.) were creating
malformed deeplink URLs. Now properly percent-encoded.
2025-11-04 11:26:57 -05:00
Jeremiah Lowin
c6a9b3df22
Fix Windows test timeouts from SQLite locking (#2368) 2025-11-04 10:58:49 -05:00
Jeremiah Lowin
5747cb6237
Fix OAuth metadata endpoint URLs when base_url differs from issuer_url (#2353)
* Fix OAuth metadata endpoint URLs when base_url differs from issuer_url

OAuth operational endpoints (/authorize, /token) are mounted at base_url,
but metadata was incorrectly declaring them at issuer_url. This caused
clients following the documented mounting pattern to receive incorrect
endpoint URLs in /.well-known/oauth-authorization-server.

Fixes #2287

* Update auth.py

* Remove unnecessary assertion from OAuthProvider init

* Add info log when issuer_url differs from base_url
2025-11-04 10:38:41 -05:00
Antonio Iorga
7e6610b7b6
Add meta to call tool (#2206)
* feat: Add optional meta parameter to Client tool call methods

* fix: Add support for mcp<1.19

* chore: cleaner solution

* Refactor call_tool to directly accept meta parameter and add tests for meta functionality

---------

Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
2025-11-04 10:25:52 -05:00
William Easton
7d0c3700ed
Merge pull request #2361 from jlowin/fix-marvin
Switch marvin to prek from pre-commit
2025-11-03 21:29:55 -06:00
strawgate
49259ae938 switch marvin to prek from pre-commit 2025-11-03 21:22:22 -06:00
marvin-context-protocol[bot]
7ccaa8ac6d
chore: Update SDK documentation (#2265)
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
2025-11-03 18:49:06 -05:00
Jeremiah Lowin
dcfd9ee387
Pin Cyclopts to v4.0.0 + compliance note (#2354)
* Pin cyclopts to v5.0.0a1+

* Document cyclopts/docutils licensing

* Update docs
2025-11-03 18:37:12 -05:00
Maxi Fernandez
8ad2dfc00c
fix: on_initialize is not using request params but the whole request (#2357)
* fix initialize type

* undo for clarity

* fix type hint
2025-11-03 16:04:02 -05:00
Jeremiah Lowin
9c861b232b
Add manual initialization control to Client (#2355)
* Add manual initialization control to Client

- Add auto_initialize parameter (default True) to control automatic initialization
- Make initialize() method public with idempotent caching
- Add comprehensive test suite for initialization behavior

* Document client initialization control and server instructions

- Expand documentation to cover auto_initialize parameter
- Show manual initialization for advanced use cases
- Document accessing server instructions via initialize_result

* Update client.mdx
2025-11-03 16:01:30 -05:00
Jeremiah Lowin
6cc9559f84
Bump ty to ==0.0.1a25 (#2350)
* Bump ty to >=0.0.1a25 with type fixes

Follow-up to #2295. Updates ty and fixes compatibility issues with alpha 25, including:

- Updated ignore comment syntax (possibly-unbound-attribute → possibly-missing-attribute)
- Fixed async generator type handling with anext()
- Fixed type narrowing for timeout parameters
- Converted base_url assignments to AnyHttpUrl after string manipulation
- Added CallToolResult to return type annotations
- Removed redundant type casts
- Fixed test form data to use strings instead of bytes

ty alpha 25 has limitations with isinstance() narrowing on unions (see pyproject.toml for details), requiring some targeted type ignores.

* Pin ty to ==0.0.1a25

Alpha releases can have breaking changes, so pin to the tested version.
2025-11-02 20:02:45 -05:00
Cole Murray
0e97a261cf
Security: Validate Cursor deeplink URLs and use safer Windows API (#2348)
* 🤖 Security: Validate Cursor deeplink URLs and replace cmd.exe on Windows

- Add URL scheme validation to reject non-cursor:// URLs
- Replace subprocess cmd.exe call with os.startfile() on Windows
- Add tests for scheme validation and error handling

* 🤖 Fix tests for cross-platform deeplink validation
2025-11-02 19:49:07 -05:00
Copilot
5499cda9d0
Fix lowest-direct dependency tests to actually test minimum versions (#2295)
* Initial plan

* Pin dev dependencies and use --resolution lowest-direct in pytest commands

Co-authored-by: strawgate <6384545+strawgate@users.noreply.github.com>

* Update uv.lock

* bump ty version

* ty upper bound

* Update uv.lock

* Update ty lock

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: strawgate <6384545+strawgate@users.noreply.github.com>
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
2025-11-02 17:30:31 -05:00
nate nowack
aba7d762de
switch from pre-commit to prek (#2309)
* switch from pre-commit to prek

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* fix prek tools list in contributing.mdx - include prettier, not pytest

* Use prek-action for caching

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
2025-11-02 17:08:36 -05:00
Jeremiah Lowin
bbf3050ba7
Improve ToolResult and structured output documentation (#2349)
- Restructured confusing sections: 'Object-like Results' → 'Dictionaries and Objects', 'Non-object Results' → 'Primitives and Collections', 'Complex Type Example' → 'Typed Models'
- Simplified CodeGroup examples to show Tool Definition + MCP Result instead of 3-4 confusing tabs
- Split Primitives/Collections into separate CodeGroups for clarity
- Renamed 'Full Control with ToolResult' → 'ToolResult and Metadata' for better TOC visibility
- Flattened ToolResult documentation with inline field descriptions instead of nested headings
- Added version badge for ToolResult meta field (2.13.1)
- Added clarification that ToolResult meta is separate from @mcp.tool meta
- Improved example server with realistic metadata (execution time, character/word counts)
- Fixed code formatting (multi-line objects, trailing commas)
2025-11-02 17:07:48 -05:00
Brandon Shar
c18782f02b
Add meta support to ToolResult (#2283)
* Add meta to ToolResult

* add this at the client level and test the full integration

* add example

* slipped through linting somehow

---------

Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
2025-11-02 16:46:52 -05:00
Cole Murray
c8ddbff488
Security: Update authlib to 1.6.5 (CVE-2025-61920) (#2347)
Updates authlib from 1.6.1 to 1.6.5 to address CVE-2025-61920, which
fixes a denial of service vulnerability in JOSE implementation that
accepts unbounded JWS/JWT header and signature segments.
2025-11-02 11:46:55 -05:00
Jeremiah Lowin
c9ec1459e1
Mark flaky Windows test for retry (#2344)
* Mark flaky Windows test for retry

test_multi_client_transform_with_filtering occasionally times out on Windows CI during exception formatting in linecache.checkcache(). Add @pytest.mark.flaky with 3 retries.

* Remove unnecessary delay from flaky marker
2025-11-01 16:52:08 -04:00
Jeremiah Lowin
dab125e069
Remove test warnings (#2331) 2025-11-01 14:53:51 -04:00