StreamableHttpTransport logs a warning whenever it gets an empty middleware list (added in #307):
Streamable HTTP transport started with an empty middleware list. Default security protections (CORS, DNS rebinding, protocol version validation) are disabled. …
In the Drupal integration (mcp_server), the empty list is deliberate. Drupal's HTTP layer already handles both edge checks:
- CORS comes from Drupal's
cors.config. CorsMiddleware would add a second set of CORS headers.
- Host validation comes from Drupal's
trusted_host_patterns, which are regular expressions. DnsRebindingProtectionMiddleware takes an exact host list and answers 403 for any host not on it.
Since 0.8, the protocol version check runs through handshakeMiddleware() no matter what list is passed, so the "protocol version validation" part of the message no longer applies.
PHP builds a new transport for every request, so this warning becomes one log entry per MCP request on every Drupal site using the SDK.
Could the transport accept an explicit opt-out that doesn't warn? For example, a constructor flag, or a documented value that means "the host application handles CORS and Host validation". The warning still makes sense for an accidental [].
Downstream: https://git.drupalcode.org/project/mcp_server/-/work_items/3585939
StreamableHttpTransportlogs a warning whenever it gets an empty middleware list (added in #307):In the Drupal integration (mcp_server), the empty list is deliberate. Drupal's HTTP layer already handles both edge checks:
cors.config.CorsMiddlewarewould add a second set of CORS headers.trusted_host_patterns, which are regular expressions.DnsRebindingProtectionMiddlewaretakes an exact host list and answers 403 for any host not on it.Since 0.8, the protocol version check runs through
handshakeMiddleware()no matter what list is passed, so the "protocol version validation" part of the message no longer applies.PHP builds a new transport for every request, so this warning becomes one log entry per MCP request on every Drupal site using the SDK.
Could the transport accept an explicit opt-out that doesn't warn? For example, a constructor flag, or a documented value that means "the host application handles CORS and Host validation". The warning still makes sense for an accidental
[].Downstream: https://git.drupalcode.org/project/mcp_server/-/work_items/3585939