Skip to content

[Schema] Fix _meta guard key in Request::jsonSerialize() - #34

Closed
chr-hertel wants to merge 2 commits into
mainfrom
fix/issue-30-jsonserialize-guard
Closed

chr-hertel wants to merge 2 commits into
mainfrom
fix/issue-30-jsonserialize-guard

Conversation

@chr-hertel

@chr-hertel chr-hertel commented Aug 22, 2026

Copy link
Copy Markdown
Owner

The guard checked $params['meta'] while the write targets $params['_meta'], so params-provided _meta could be silently overwritten. Fix the key and add a regression test. Also fixes the identical guard in Notification::jsonSerialize() with a mirror test.

Closes #30

Confidence: 10/10 — one-character key fix matching the audit finding exactly; full unit suite, cs-fixer, and phpstan pass.

dependabot Bot and others added 2 commits August 26, 2026 07:45
…xtprotocol#483)

Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 9.0.0 to 10.0.1.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@v9.0.0...v10.0.1)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@chr-hertel
chr-hertel force-pushed the fix/issue-30-jsonserialize-guard branch from 2c1f67a to ca8517e Compare August 29, 2026 08:30
@chr-hertel

Copy link
Copy Markdown
Owner Author

Closed upstream by modelcontextprotocol#485

@chr-hertel chr-hertel closed this Sep 4, 2026
@chr-hertel
chr-hertel deleted the fix/issue-30-jsonserialize-guard branch September 4, 2026 23:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[C7] Request::jsonSerialize() guards the wrong key

1 participant