fastmcp/tests/server/transforms/test_resources_as_tools.py
Jeremiah Lowin 3a9717e6be
Publish docs for v3.2.0 (#3713)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Jeremiah Lowin <jlowin@users.noreply.github.com>
Co-authored-by: Marvin Context Protocol <41898282+Marvin Context Protocol@users.noreply.github.com>
Co-authored-by: voidborne-d <voidborne-d@users.noreply.github.com>
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: d 🔹 <258577966+voidborne-d@users.noreply.github.com>
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
Co-authored-by: nightcityblade <nightcityblade@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Bill Easton <strawgate@users.noreply.github.com>
Co-authored-by: Sumanshu Nankana <sumanshunankana@gmail.com>
Co-authored-by: Eric Robinson <ericrobinson@indeed.com>
Co-authored-by: Martim Santos <martimfasantos@gmail.com>
Co-authored-by: d 🔹 <liusway405@gmail.com>
Co-authored-by: Matthieu B <66959271+mtthidoteu@users.noreply.github.com>
Co-authored-by: Sascha Buehrle <47737812+saschabuehrle@users.noreply.github.com>
Co-authored-by: Hakancan <142545736+hkc5@users.noreply.github.com>
Co-authored-by: nightcityblade <jackchen@haloailabs.com>
Co-authored-by: Matt Hallowell <17804673+mhallo@users.noreply.github.com>
Co-authored-by: nate nowack <thrast36@gmail.com>
Co-authored-by: Bill Easton <williamseaston@gmail.com>
Co-authored-by: Marcus Shu <46469249+shulkx@users.noreply.github.com>
Co-authored-by: Rushabh Doshi <radoshi@gmail.com>
Co-authored-by: AIKAWA Shigechika <shige@aikawa.jp>
Co-authored-by: Jeremy Simon <simonjer805@gmail.com>
Co-authored-by: Miguel Miranda Dias <7780875+pandego@users.noreply.github.com>
Co-authored-by: Anthony James Padavano <padavano.anthony@gmail.com>
Co-authored-by: Mostafa Kamal <hiremostafa@gmail.com>
Fix auto-close MRE script posting comment without closing (#3386)
Fix WorkOS token scope verification bypass 🤖 Generated with Codex (#3407)
Fix initialize McpError fallthrough 🤖 Generated with Codex (#3413)
Fix transform arg collisions with passthrough params (#3431)
Fix get_* returning None when latest version is disabled (#3439)
Fix get_* returning None when latest version is disabled (#3421)
Fix server lifespan overlap teardown (#3415)
Fix $ref output schema object detection regression (#3420)
resolved annotations (#3429)
Fix async partial callables rejected by iscoroutinefunction (#3438)
Fix async partial callables rejected by iscoroutinefunction (#3423)
fix: add version to components (#3458)
fix: use intent-based flag for OIDC scope patch in load_access_token (#3465)
Fixes #3461
fix: normalize Google scope shorthands and surface valid_scopes (#3477)
fix: resolve ty 0.0.23 type-checking errors and bump pin (#3481)
fix: shield lifespan teardown from cancellation (#3480)
fix: forward custom_route endpoints from mounted servers (#3462)
fix updates _get_additional_http_routes() to traverse providers,
Fixes #3457
fix: remove hardcoded version from CLI help text (#3456)
fix: monty 0.0.8 compatibility, drop external_functions from constructor (#3468)
fix: task test teardown hanging 5s per test (#3499)
Closes #3498
fix: validate workspace path is a directory before cursor install (#3440)
Fixes #3426
fix: handle re.error from malformed URI templates in build_regex (#3501)
fix: reject empty/OIDC-only required_scopes in AzureProvider (#3503)
fix: restrict $ref resolution to local refs only (SSRF/LFI) (#3502)
fix warnings and timeouts (#3504)
close upgrade check issue when build passes (#3505)
Closes #3484
fix: URL-encode path params to prevent SSRF/path traversal (GHSA-vv7q-7jx5-f767) (#3507)
fix: prevent path traversal in skill download (#3493)
fix: prefer IdP-granted scopes over client-requested scopes in OAuthProxy (#3492)
fix: remove unrelated transform and http.py changes from PR scope
fix: remove forced follow_redirects from httpx_client_factory calls (#3496)
fix: stop passing follow_redirects to httpx_client_factory
fix: restore follow_redirects=True for custom httpx client factories
Closes #3509
fix: CSRF double-submit cookie check in consent flow (#3519)
fix: validate server names in install commands (#3522)
fix: use raw strings for regex in pytest.raises match (#3523)
fix: reject refresh tokens used as Bearer access tokens (#3524)
fix: route ResourcesAsTools/PromptsAsTools through server middleware (#3495)
fix: resolve Pyright "Module is not callable" on @tool, @resource, @prompt decorators (#3540)
fix: filter warnings by message in KEY_PREFIX test (#3549)
fix: suppress output schema for ToolResult subclass annotations (#3548)
fix: increase sleep duration in proxy cache tests (#3567)
fix: store absolute token expiry to prevent stale expires_in on reload (#3572)
fix: preserve tool properties named 'title' during schema compression (#3582)
Fix loopback redirect URI port matching per RFC 8252 §7.3 (#3589)
Fix app tool routing: visibility check and middleware propagation (#3591)
Fix query parameter serialization to respect OpenAPI explode/style settings (#3595)
Fix dev apps form: union types, textarea support, JSON parsing (#3597)
fix(google): replace deprecated /oauth2/v1/tokeninfo with /oauth2/v3/userinfo (#3603)
fix: resolve EntraOBOToken dependency injection through MultiAuth (#3609)
fix(docs): correct misleading stateless_http header (#3622)
fix: filesystem provider import machinery (#3626)
Closes #3625 (issues 2, 3, 6)
fix: recover StdioTransport after subprocess exits (#3630)
fix(server): preserve mounted tool task metadata (#3632)
fix: scope deprecation warning filter to FastMCPDeprecationWarning (#3649)
fix imports, add PrefabAppConfig (#3650)
fix: resolve CurrentFastMCP/ctx.fastmcp to child server in mounted background tasks (#3651)
Fix blocking docs issues: chart imports, Select API, Rx consistency (#3652)
closed by default (#3657)
Fix prompt caching middleware missing wrap/unwrap round-trip (#3666)
fix: serialize object query params per OpenAPI style/explode rules (#3662)
Fixes #2857
fix: HTTP request headers not accessible in background task workers (#3631)
fix: restore HTTP headers in worker execution path for background tasks (#3681)
fix: strip discriminator after dereferencing schemas (#3682)
fix: remove stale ty:ignore directives for ty 0.0.26 (#3684)
Fix docs gaps in app provider pages (#3690)
fix: dev apps log panel UX improvements (#3698)
fix dev server empty string args (#3700)
2026-03-30 16:48:30 -04:00

358 lines
12 KiB
Python

"""Tests for ResourcesAsTools transform."""
import base64
import json
import pytest
from fastmcp import FastMCP
from fastmcp.client import Client
from fastmcp.exceptions import ToolError
from fastmcp.server.auth import AuthContext
from fastmcp.server.transforms import ResourcesAsTools
class TestResourcesAsToolsBasic:
"""Test basic ResourcesAsTools functionality."""
async def test_adds_list_resources_tool(self):
"""Transform adds list_resources tool."""
mcp = FastMCP("Test")
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
tools = await client.list_tools()
tool_names = {t.name for t in tools}
assert "list_resources" in tool_names
async def test_adds_read_resource_tool(self):
"""Transform adds read_resource tool."""
mcp = FastMCP("Test")
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
tools = await client.list_tools()
tool_names = {t.name for t in tools}
assert "read_resource" in tool_names
async def test_preserves_existing_tools(self):
"""Transform preserves existing tools."""
mcp = FastMCP("Test")
@mcp.tool
def my_tool() -> str:
return "result"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
tools = await client.list_tools()
tool_names = {t.name for t in tools}
assert "my_tool" in tool_names
assert "list_resources" in tool_names
assert "read_resource" in tool_names
class TestListResourcesTool:
"""Test the list_resources tool."""
async def test_lists_static_resources(self):
"""list_resources returns static resources with uri."""
mcp = FastMCP("Test")
@mcp.resource("config://app")
def app_config() -> str:
return "config data"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("list_resources", {})
resources = json.loads(result.data)
assert len(resources) == 1
assert resources[0]["uri"] == "config://app"
assert resources[0]["name"] == "app_config"
async def test_lists_resource_templates(self):
"""list_resources returns templates with uri_template."""
mcp = FastMCP("Test")
@mcp.resource("file://{path}")
def read_file(path: str) -> str:
return f"content of {path}"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("list_resources", {})
resources = json.loads(result.data)
assert len(resources) == 1
assert resources[0]["uri_template"] == "file://{path}"
assert "uri" not in resources[0]
async def test_lists_both_resources_and_templates(self):
"""list_resources returns both static and templated resources."""
mcp = FastMCP("Test")
@mcp.resource("config://app")
def app_config() -> str:
return "config"
@mcp.resource("file://{path}")
def read_file(path: str) -> str:
return f"content of {path}"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("list_resources", {})
resources = json.loads(result.data)
assert len(resources) == 2
# One has uri, one has uri_template
uris = [r.get("uri") for r in resources if r.get("uri")]
templates = [
r.get("uri_template") for r in resources if r.get("uri_template")
]
assert uris == ["config://app"]
assert templates == ["file://{path}"]
async def test_empty_when_no_resources(self):
"""list_resources returns empty list when no resources exist."""
mcp = FastMCP("Test")
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("list_resources", {})
assert json.loads(result.data) == []
class TestReadResourceTool:
"""Test the read_resource tool."""
async def test_reads_static_resource(self):
"""read_resource reads a static resource by URI."""
mcp = FastMCP("Test")
@mcp.resource("config://app")
def app_config() -> str:
return "my config data"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("read_resource", {"uri": "config://app"})
assert result.data == "my config data"
async def test_reads_templated_resource(self):
"""read_resource reads a templated resource with parameters."""
mcp = FastMCP("Test")
@mcp.resource("user://{user_id}/profile")
def user_profile(user_id: str) -> str:
return f"Profile for user {user_id}"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool(
"read_resource", {"uri": "user://123/profile"}
)
assert result.data == "Profile for user 123"
async def test_error_on_unknown_resource(self):
"""read_resource raises error for unknown URI."""
from fastmcp.exceptions import ToolError
mcp = FastMCP("Test")
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
with pytest.raises(ToolError, match="Unknown resource"):
await client.call_tool("read_resource", {"uri": "unknown://resource"})
async def test_reads_binary_as_base64(self):
"""read_resource returns binary content as base64."""
mcp = FastMCP("Test")
@mcp.resource("data://binary", mime_type="application/octet-stream")
def binary_data() -> bytes:
return b"\x00\x01\x02\x03"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("read_resource", {"uri": "data://binary"})
# Should be base64 encoded
decoded = base64.b64decode(result.data)
assert decoded == b"\x00\x01\x02\x03"
class TestResourcesAsToolsWithNamespace:
"""Test ResourcesAsTools combined with other transforms."""
async def test_works_with_namespace_on_provider(self):
"""ResourcesAsTools works when provider has Namespace transform."""
from fastmcp.server.providers import FastMCPProvider
from fastmcp.server.transforms import Namespace
sub = FastMCP("Sub")
@sub.resource("config://app")
def app_config() -> str:
return "sub config"
main = FastMCP("Main")
provider = FastMCPProvider(sub)
provider.add_transform(Namespace("sub"))
main.add_provider(provider)
main.add_transform(ResourcesAsTools(main))
async with Client(main) as client:
result = await client.call_tool("list_resources", {})
resources = json.loads(result.data)
# Resource should have namespaced URI
assert len(resources) == 1
assert resources[0]["uri"] == "config://sub/app"
class TestResourcesAsToolsRepr:
"""Test ResourcesAsTools repr."""
def test_repr(self):
"""Transform has useful repr."""
mcp = FastMCP("Test")
transform = ResourcesAsTools(mcp)
assert "ResourcesAsTools" in repr(transform)
class TestResourcesAsToolsAnnotations:
"""Test ToolAnnotations on generated resource tools."""
async def test_list_resources_is_read_only(self):
"""list_resources is annotated as read-only by default."""
mcp = FastMCP("Test")
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
tools = await client.list_tools()
tool = next(t for t in tools if t.name == "list_resources")
assert tool.annotations is not None
assert tool.annotations.readOnlyHint is True
async def test_read_resource_is_read_only(self):
"""read_resource is annotated as read-only by default."""
mcp = FastMCP("Test")
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
tools = await client.list_tools()
tool = next(t for t in tools if t.name == "read_resource")
assert tool.annotations is not None
assert tool.annotations.readOnlyHint is True
def _deny_all(ctx: AuthContext) -> bool:
"""Auth check that always denies access."""
return False
class TestResourcesAsToolsAuthOnServer:
"""Auth checks work when using ResourcesAsTools on a FastMCP server."""
async def test_auth_protected_resources_hidden_from_list(self):
"""Auth-protected resources are filtered from list_resources tool."""
mcp = FastMCP("Test")
@mcp.resource("test://open")
def open_resource() -> str:
return "open content"
@mcp.resource("test://protected", auth=_deny_all)
def protected_resource() -> str:
return "protected content"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("list_resources", {})
items = json.loads(result.data)
uris = [r.get("uri") for r in items if r.get("uri")]
assert "test://open" in uris
assert "test://protected" not in uris
async def test_auth_protected_resource_cannot_be_read(self):
"""Auth-protected resources cannot be read via read_resource tool."""
mcp = FastMCP("Test")
@mcp.resource("test://protected", auth=_deny_all)
def protected_resource() -> str:
return "protected content"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
with pytest.raises(ToolError):
await client.call_tool("read_resource", {"uri": "test://protected"})
async def test_open_resource_still_accessible(self):
"""Non-auth-protected resources can still be read."""
mcp = FastMCP("Test")
@mcp.resource("test://open")
def open_resource() -> str:
return "open content"
@mcp.resource("test://protected", auth=_deny_all)
def protected_resource() -> str:
return "protected content"
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("read_resource", {"uri": "test://open"})
assert result.data == "open content"
class TestResourcesAsToolsVisibilityOnServer:
"""Visibility filtering works when using ResourcesAsTools on a server."""
async def test_disabled_resources_hidden_from_list(self):
"""Disabled resources are not listed via list_resources tool."""
mcp = FastMCP("Test")
@mcp.resource("test://public")
def public_resource() -> str:
return "public content"
@mcp.resource("test://secret")
def secret_resource() -> str:
return "secret content"
mcp.disable(names={"test://secret"})
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
result = await client.call_tool("list_resources", {})
items = json.loads(result.data)
uris = [r.get("uri") for r in items if r.get("uri")]
assert "test://public" in uris
assert "test://secret" not in uris
async def test_disabled_resource_cannot_be_read(self):
"""Disabled resources cannot be read via read_resource tool."""
mcp = FastMCP("Test")
@mcp.resource("test://secret")
def secret_resource() -> str:
return "secret content"
mcp.disable(names={"test://secret"})
mcp.add_transform(ResourcesAsTools(mcp))
async with Client(mcp) as client:
with pytest.raises(ToolError):
await client.call_tool("read_resource", {"uri": "test://secret"})