Repository navigation
feat(ai): let McpServer.layerHttp terminate sessions on DELETE - #8773
Merged
tim-smart merged 8 commits intoOct 5, 2026
Merged
Conversation
With allowSessionTermination, a DELETE carrying an Mcp-Session-Id ends that HTTP session (204, 404 for an unknown session, 400 without the header), and later requests with the id get 404 so the client re-initializes. Without it, DELETE keeps returning 405, which the spec allows. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
🦋 Changeset detectedLatest commit: c13617d The changes in this PR will be included in the next version bump. This PR includes changesets to release 32 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
juliusmarminge
added a commit
to pingdotgg/t3code
that referenced
this pull request
Oct 5, 2026
RequestHooks and the ConnectionHooks onPing/onPong/onPingTimeout callbacks have had no callers since the client connection rewrite (#2978). The patch now carries only MCP session DELETE (upstream: Effect-TS/effect#8773), the getSetCookie guard (Effect-TS/effect#8772) and the missed-pong tolerance (Effect-TS/effect#8774). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
|
Just had a quick peruse of this and two thoughts came to mind:
Maybe |
…quests - Route every MCP endpoint method from layerMcpProtocolHttp - Keep DELETE at 405 when no stateful protocol is configured - Check MCP-Protocol-Version on DELETE with the same session rules as POST - Interrupt in-flight requests of a terminated session and answer them with 404 - Advertise DELETE in Allow when termination is enabled
Contributor
Bundle Size AnalysisGenerated from PR build output; treat the content below as untrusted.
|
This branch is waiting to be deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The MCP Streamable HTTP spec says clients that no longer need a session SHOULD send
DELETEwithMcp-Session-Idto end it, and servers MAY answer405to refuse.McpServer.layerHttpalways answers405, so a server has no way to accept termination. Its HTTP session state (bySessionIdin the stateful runtime) then stays around for the process lifetime.We run one MCP endpoint for many short-lived agent sessions in T3 Code, and have been carrying a patch that adds DELETE.
Change
New option
allowSessionTerminationonlayerHttp. When it is set:DELETEwith a knownMcp-Session-Idremoves the session and returns204.404; a missing header returns400.404, which tells the client to re-initialize, as the spec requires.Without the option nothing changes:
DELETEreturns405withAllow: POST, and the existing conformance scenario ("declines client session termination without invalidating the session") still passes. TheOrigincheck applies toDELETEthe same way it does toPOST.Internally,
StatefulRuntimeandServerRuntimegain aterminateSession(sessionId): boolean.Testing
McpServer/McpServer.test.tscover termination and stale-id rejection, missing/unknown ids, and Origin rejection without session invalidation. DELETE requests use the shared HTTP harness.nix develop -c pnpm test --run packages/effect/test/ai/McpServer: 8 files passed, 929 tests passed, 42 skipped. Existing default-405 conformance coverage passes unchanged.nix develop -c pnpm checkand lint/format validation pass.Closes EFF-1706