fix: mirror params.taskId into Mcp-Name for tasks requests (SEP-2663) - #2613
fix: mirror params.taskId into Mcp-Name for tasks requests (SEP-2663)#2613jwcarman wants to merge 1 commit into
Conversation
🦋 Changeset detectedLatest commit: b81ab36 The changes in this PR will be included in the next version bump. This PR includes changesets to release 6 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
@modelcontextprotocol/client
@modelcontextprotocol/codemod
@modelcontextprotocol/core
@modelcontextprotocol/server
@modelcontextprotocol/server-legacy
@modelcontextprotocol/express
@modelcontextprotocol/fastify
@modelcontextprotocol/hono
@modelcontextprotocol/node
commit: |
|
@KKonstantinov Verified, Inspector not sending Mcp-Name header on
|
|
Verified end-to-end with this branch's With the fix in place, all three methods now carry
|






Summary
The Streamable HTTP client transport omits the
Mcp-Nameheader ontasks/get/tasks/update/tasks/cancel. SEP-2663's Streamable HTTP binding makes that header a client MUST for these methods:A conforming server therefore rejects every task poll from this SDK (and from Inspector, which surfaced it: modelcontextprotocol/inspector#1917) with
-32020 HeaderMismatch/ HTTP 400.Changes
@modelcontextprotocol/core-internal—MCP_NAME_HEADER_SOURCEgains the threetasks/*→taskIdrows (type widened to'name' | 'uri' | 'taskId').validateStandardRequestHeadersneeds no code change — it is already table-driven — so SDK servers now also require/cross-checkMcp-Nameon tasks requests, symmetric with the client.@modelcontextprotocol/client—_applyBodyDerivedHeadersnow derivesMcp-Namefrom the sharedMCP_NAME_HEADER_SOURCEtable instead of a hardcodedresources/read-vs-params.nameternary, so client emission and server validation cannot drift apart. The lookup isObject.hasOwn-guarded like the server side. Sentinel encoding is unchanged and applies to the taskId value as well.Behavior notes
tools/call/prompts/get→params.name,resources/read→params.uri, off-table methods → none — pinned by a newtasks/listnegative test).Tests
standardHeaderValidation.test.ts: tasks missing-header rejection (namesparams.taskId), matching-header pass for all three methods, mismatch rejection,tasks/listoff-table pass, and the exact-table test updated for the SEP-2663 rows.mcpParamMirroring.test.ts: client emitsMcp-Name: <taskId>for all three tasks methods and no header fortasks/list.typecheck:all+lint:allclean.Fixes modelcontextprotocol/inspector#1917 (the Inspector bug is this SDK behavior — Inspector needs only the dependency bump once released).
🤖 Generated with Claude Code