fastmcp/tests/server/transforms/test_catalog.py
Jeremiah Lowin 3a9717e6be
Publish docs for v3.2.0 (#3713)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Jeremiah Lowin <jlowin@users.noreply.github.com>
Co-authored-by: Marvin Context Protocol <41898282+Marvin Context Protocol@users.noreply.github.com>
Co-authored-by: voidborne-d <voidborne-d@users.noreply.github.com>
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: d 🔹 <258577966+voidborne-d@users.noreply.github.com>
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
Co-authored-by: nightcityblade <nightcityblade@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Bill Easton <strawgate@users.noreply.github.com>
Co-authored-by: Sumanshu Nankana <sumanshunankana@gmail.com>
Co-authored-by: Eric Robinson <ericrobinson@indeed.com>
Co-authored-by: Martim Santos <martimfasantos@gmail.com>
Co-authored-by: d 🔹 <liusway405@gmail.com>
Co-authored-by: Matthieu B <66959271+mtthidoteu@users.noreply.github.com>
Co-authored-by: Sascha Buehrle <47737812+saschabuehrle@users.noreply.github.com>
Co-authored-by: Hakancan <142545736+hkc5@users.noreply.github.com>
Co-authored-by: nightcityblade <jackchen@haloailabs.com>
Co-authored-by: Matt Hallowell <17804673+mhallo@users.noreply.github.com>
Co-authored-by: nate nowack <thrast36@gmail.com>
Co-authored-by: Bill Easton <williamseaston@gmail.com>
Co-authored-by: Marcus Shu <46469249+shulkx@users.noreply.github.com>
Co-authored-by: Rushabh Doshi <radoshi@gmail.com>
Co-authored-by: AIKAWA Shigechika <shige@aikawa.jp>
Co-authored-by: Jeremy Simon <simonjer805@gmail.com>
Co-authored-by: Miguel Miranda Dias <7780875+pandego@users.noreply.github.com>
Co-authored-by: Anthony James Padavano <padavano.anthony@gmail.com>
Co-authored-by: Mostafa Kamal <hiremostafa@gmail.com>
Fix auto-close MRE script posting comment without closing (#3386)
Fix WorkOS token scope verification bypass 🤖 Generated with Codex (#3407)
Fix initialize McpError fallthrough 🤖 Generated with Codex (#3413)
Fix transform arg collisions with passthrough params (#3431)
Fix get_* returning None when latest version is disabled (#3439)
Fix get_* returning None when latest version is disabled (#3421)
Fix server lifespan overlap teardown (#3415)
Fix $ref output schema object detection regression (#3420)
resolved annotations (#3429)
Fix async partial callables rejected by iscoroutinefunction (#3438)
Fix async partial callables rejected by iscoroutinefunction (#3423)
fix: add version to components (#3458)
fix: use intent-based flag for OIDC scope patch in load_access_token (#3465)
Fixes #3461
fix: normalize Google scope shorthands and surface valid_scopes (#3477)
fix: resolve ty 0.0.23 type-checking errors and bump pin (#3481)
fix: shield lifespan teardown from cancellation (#3480)
fix: forward custom_route endpoints from mounted servers (#3462)
fix updates _get_additional_http_routes() to traverse providers,
Fixes #3457
fix: remove hardcoded version from CLI help text (#3456)
fix: monty 0.0.8 compatibility, drop external_functions from constructor (#3468)
fix: task test teardown hanging 5s per test (#3499)
Closes #3498
fix: validate workspace path is a directory before cursor install (#3440)
Fixes #3426
fix: handle re.error from malformed URI templates in build_regex (#3501)
fix: reject empty/OIDC-only required_scopes in AzureProvider (#3503)
fix: restrict $ref resolution to local refs only (SSRF/LFI) (#3502)
fix warnings and timeouts (#3504)
close upgrade check issue when build passes (#3505)
Closes #3484
fix: URL-encode path params to prevent SSRF/path traversal (GHSA-vv7q-7jx5-f767) (#3507)
fix: prevent path traversal in skill download (#3493)
fix: prefer IdP-granted scopes over client-requested scopes in OAuthProxy (#3492)
fix: remove unrelated transform and http.py changes from PR scope
fix: remove forced follow_redirects from httpx_client_factory calls (#3496)
fix: stop passing follow_redirects to httpx_client_factory
fix: restore follow_redirects=True for custom httpx client factories
Closes #3509
fix: CSRF double-submit cookie check in consent flow (#3519)
fix: validate server names in install commands (#3522)
fix: use raw strings for regex in pytest.raises match (#3523)
fix: reject refresh tokens used as Bearer access tokens (#3524)
fix: route ResourcesAsTools/PromptsAsTools through server middleware (#3495)
fix: resolve Pyright "Module is not callable" on @tool, @resource, @prompt decorators (#3540)
fix: filter warnings by message in KEY_PREFIX test (#3549)
fix: suppress output schema for ToolResult subclass annotations (#3548)
fix: increase sleep duration in proxy cache tests (#3567)
fix: store absolute token expiry to prevent stale expires_in on reload (#3572)
fix: preserve tool properties named 'title' during schema compression (#3582)
Fix loopback redirect URI port matching per RFC 8252 §7.3 (#3589)
Fix app tool routing: visibility check and middleware propagation (#3591)
Fix query parameter serialization to respect OpenAPI explode/style settings (#3595)
Fix dev apps form: union types, textarea support, JSON parsing (#3597)
fix(google): replace deprecated /oauth2/v1/tokeninfo with /oauth2/v3/userinfo (#3603)
fix: resolve EntraOBOToken dependency injection through MultiAuth (#3609)
fix(docs): correct misleading stateless_http header (#3622)
fix: filesystem provider import machinery (#3626)
Closes #3625 (issues 2, 3, 6)
fix: recover StdioTransport after subprocess exits (#3630)
fix(server): preserve mounted tool task metadata (#3632)
fix: scope deprecation warning filter to FastMCPDeprecationWarning (#3649)
fix imports, add PrefabAppConfig (#3650)
fix: resolve CurrentFastMCP/ctx.fastmcp to child server in mounted background tasks (#3651)
Fix blocking docs issues: chart imports, Select API, Rx consistency (#3652)
closed by default (#3657)
Fix prompt caching middleware missing wrap/unwrap round-trip (#3666)
fix: serialize object query params per OpenAPI style/explode rules (#3662)
Fixes #2857
fix: HTTP request headers not accessible in background task workers (#3631)
fix: restore HTTP headers in worker execution path for background tasks (#3681)
fix: strip discriminator after dereferencing schemas (#3682)
fix: remove stale ty:ignore directives for ty 0.0.26 (#3684)
Fix docs gaps in app provider pages (#3690)
fix: dev apps log panel UX improvements (#3698)
fix dev server empty string args (#3700)
2026-03-30 16:48:30 -04:00

258 lines
8.5 KiB
Python

"""Tests for CatalogTransform base class."""
from __future__ import annotations
import ast
from collections.abc import Sequence
from mcp.types import TextContent
from fastmcp import FastMCP
from fastmcp.server.context import Context
from fastmcp.server.transforms import GetToolNext
from fastmcp.server.transforms.catalog import CatalogTransform
from fastmcp.server.transforms.version_filter import VersionFilter
from fastmcp.tools.base import Tool
from fastmcp.utilities.versions import VersionSpec
# ---------------------------------------------------------------------------
# Helpers
# ---------------------------------------------------------------------------
def _make_versioned_tool(name: str, version: str) -> Tool:
"""Create a tool with a specific version for testing."""
async def _fn() -> str:
return f"{name}@{version}"
return Tool.from_function(fn=_fn, name=name, version=version)
class CatalogReader(CatalogTransform):
"""Minimal CatalogTransform that exposes get_tool_catalog via a tool.
After calling the ``read_catalog`` tool, the full catalog is available
on ``self.last_catalog`` for assertions beyond tool names.
"""
def __init__(self) -> None:
super().__init__()
self.last_catalog: Sequence[Tool] = []
async def transform_tools(self, tools: Sequence[Tool]) -> Sequence[Tool]:
return [self._make_reader_tool()]
async def get_tool(
self, name: str, call_next: GetToolNext, *, version: VersionSpec | None = None
) -> Tool | None:
if name == "read_catalog":
return self._make_reader_tool()
return await call_next(name, version=version)
def _make_reader_tool(self) -> Tool:
transform = self
async def read_catalog(ctx: Context = None) -> list[str]: # type: ignore[assignment] # ty:ignore[invalid-parameter-default]
"""Return names of tools visible in the catalog."""
transform.last_catalog = await transform.get_tool_catalog(ctx)
return [t.name for t in transform.last_catalog]
return Tool.from_function(fn=read_catalog, name="read_catalog")
class ReplacingTransform(CatalogTransform):
"""Minimal subclass that replaces tools with a synthetic tool.
Uses ``get_tool_catalog()`` to read the real catalog inside the
synthetic tool's handler, verifying that the bypass mechanism works.
"""
async def transform_tools(self, tools: Sequence[Tool]) -> Sequence[Tool]:
return [self._make_synthetic_tool()]
async def get_tool(
self, name: str, call_next: GetToolNext, *, version: VersionSpec | None = None
) -> Tool | None:
if name == "count_tools":
return self._make_synthetic_tool()
return await call_next(name, version=version)
def _make_synthetic_tool(self) -> Tool:
transform = self
async def count_tools(ctx: Context = None) -> int: # type: ignore[assignment] # ty:ignore[invalid-parameter-default]
"""Return the number of real tools in the catalog."""
catalog = await transform.get_tool_catalog(ctx)
return len(catalog)
return Tool.from_function(fn=count_tools, name="count_tools")
class TestCatalogTransformBypass:
async def test_list_tools_replaced_by_subclass(self):
mcp = FastMCP("test")
@mcp.tool
def add(a: int, b: int) -> int:
return a + b
@mcp.tool
def multiply(x: float, y: float) -> float:
return x * y
mcp.add_transform(ReplacingTransform())
tools = await mcp.list_tools()
names = {t.name for t in tools}
assert names == {"count_tools"}
async def test_get_tool_catalog_returns_real_tools(self):
mcp = FastMCP("test")
@mcp.tool
def add(a: int, b: int) -> int:
return a + b
@mcp.tool
def multiply(x: float, y: float) -> float:
return x * y
mcp.add_transform(ReplacingTransform())
result = await mcp.call_tool("count_tools", {})
assert any("2" in c.text for c in result.content if isinstance(c, TextContent))
async def test_multiple_instances_have_independent_bypass(self):
"""Each CatalogTransform instance has its own bypass ContextVar."""
t1 = ReplacingTransform()
t2 = ReplacingTransform()
assert t1._instance_id != t2._instance_id
assert t1._bypass is not t2._bypass
class TestCatalogDeduplication:
"""get_tool_catalog() deduplicates versioned tools, keeping only the highest."""
async def test_returns_highest_version_only(self):
mcp = FastMCP("test")
mcp.add_tool(_make_versioned_tool("greet", "1"))
mcp.add_tool(_make_versioned_tool("greet", "2"))
mcp.add_tool(_make_versioned_tool("greet", "3"))
reader = CatalogReader()
mcp.add_transform(reader)
result = await mcp.call_tool("read_catalog", {})
names = _extract_result(result)
assert names == ["greet"]
async def test_version_metadata_injected(self):
"""Highest-version tool has meta.fastmcp.versions listing all available."""
mcp = FastMCP("test")
mcp.add_tool(_make_versioned_tool("greet", "1"))
mcp.add_tool(_make_versioned_tool("greet", "3"))
reader = CatalogReader()
mcp.add_transform(reader)
await mcp.call_tool("read_catalog", {})
assert len(reader.last_catalog) == 1
tool = reader.last_catalog[0]
assert tool.name == "greet"
assert tool.version == "3"
assert tool.meta is not None
versions = tool.meta["fastmcp"]["versions"]
assert versions == ["3", "1"]
async def test_mixed_versioned_and_unversioned(self):
mcp = FastMCP("test")
@mcp.tool
def standalone() -> str:
return "hi"
mcp.add_tool(_make_versioned_tool("greet", "1"))
mcp.add_tool(_make_versioned_tool("greet", "2"))
reader = CatalogReader()
mcp.add_transform(reader)
result = await mcp.call_tool("read_catalog", {})
names = sorted(_extract_result(result))
assert names == ["greet", "standalone"]
async def test_version_filter_applied_before_catalog(self):
"""A VersionFilter added before the CatalogTransform restricts what the catalog sees."""
mcp = FastMCP("test")
mcp.add_tool(_make_versioned_tool("greet", "1"))
mcp.add_tool(_make_versioned_tool("greet", "2"))
mcp.add_tool(_make_versioned_tool("greet", "3"))
# Filter keeps only versions < 3 — so v1 and v2 survive, v3 is excluded.
mcp.add_transform(VersionFilter(version_lt="3"))
reader = CatalogReader()
mcp.add_transform(reader)
await mcp.call_tool("read_catalog", {})
assert len(reader.last_catalog) == 1
tool = reader.last_catalog[0]
assert tool.name == "greet"
assert tool.version == "2"
class TestCatalogVisibility:
"""get_tool_catalog() respects visibility (disabled tools are excluded)."""
async def test_disabled_tool_excluded(self):
mcp = FastMCP("test")
@mcp.tool
def public() -> str:
return "visible"
@mcp.tool
def secret() -> str:
return "hidden"
mcp.disable(names={"secret"}, components={"tool"})
reader = CatalogReader()
mcp.add_transform(reader)
result = await mcp.call_tool("read_catalog", {})
names = _extract_result(result)
assert names == ["public"]
class TestCatalogAuth:
"""get_tool_catalog() respects tool-level auth filtering."""
async def test_auth_rejected_tool_excluded(self):
mcp = FastMCP("test")
@mcp.tool
def public() -> str:
return "visible"
@mcp.tool(auth=lambda _ctx: False)
def protected() -> str:
return "hidden"
reader = CatalogReader()
mcp.add_transform(reader)
result = await mcp.call_tool("read_catalog", {})
names = _extract_result(result)
assert names == ["public"]
# ---------------------------------------------------------------------------
# Test helpers
# ---------------------------------------------------------------------------
def _extract_result(result: object) -> list[str]:
"""Extract the list of names from a call_tool ToolResult."""
for c in result.content: # type: ignore[union-attr] # ty:ignore[unresolved-attribute]
if isinstance(c, TextContent):
return ast.literal_eval(c.text)
raise AssertionError("No text content found")