Skip to content

test: pin authenticated GET/DELETE on /mcp returning 405 #991

Description

@moonming

Follow-up from the protocol-version docs audit: the sessionless /mcp serving posture means GET and DELETE return 405 after authentication (rmcp 3.1.2 tower.rs serves POST-only when legacy_session_mode = false with no event store), and the docs now state this — but no first-party test in this repo pins it. The guarantee currently rests on the vendored SDK's dispatch arm alone; an rmcp upgrade that starts serving GET (SSE streams) or DELETE (session teardown) by default would change the wire surface silently.

Add a small case to crates/aisix-mcp/tests/protocol_generations.rs (or the proxy suite for the authenticated path): authenticated GET /mcp and DELETE /mcp → 405, unauthenticated → 401 first.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions