Skip to content

[Server] Let a framework integration opt out of the HTTP edge middleware without a warning #523

Description

@mglaman

StreamableHttpTransport logs a warning whenever it gets an empty middleware list (added in #307):

Streamable HTTP transport started with an empty middleware list. Default security protections (CORS, DNS rebinding, protocol version validation) are disabled. …

In the Drupal integration (mcp_server), the empty list is deliberate. Drupal's HTTP layer already handles both edge checks:

  • CORS comes from Drupal's cors.config. CorsMiddleware would add a second set of CORS headers.
  • Host validation comes from Drupal's trusted_host_patterns, which are regular expressions. DnsRebindingProtectionMiddleware takes an exact host list and answers 403 for any host not on it.

Since 0.8, the protocol version check runs through handshakeMiddleware() no matter what list is passed, so the "protocol version validation" part of the message no longer applies.

PHP builds a new transport for every request, so this warning becomes one log entry per MCP request on every Drupal site using the SDK.

Could the transport accept an explicit opt-out that doesn't warn? For example, a constructor flag, or a documented value that means "the host application handles CORS and Host validation". The warning still makes sense for an accidental [].

Downstream: https://git.drupalcode.org/project/mcp_server/-/work_items/3585939

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ServerIssues & PRs related to the Server componentenhancementRequest for a new feature that's not currently supported

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions