Follow-up from the protocol-version docs audit: the sessionless /mcp serving posture means GET and DELETE return 405 after authentication (rmcp 3.1.2 tower.rs serves POST-only when legacy_session_mode = false with no event store), and the docs now state this — but no first-party test in this repo pins it. The guarantee currently rests on the vendored SDK's dispatch arm alone; an rmcp upgrade that starts serving GET (SSE streams) or DELETE (session teardown) by default would change the wire surface silently.
Add a small case to crates/aisix-mcp/tests/protocol_generations.rs (or the proxy suite for the authenticated path): authenticated GET /mcp and DELETE /mcp → 405, unauthenticated → 401 first.
🤖 Generated with Claude Code
Follow-up from the protocol-version docs audit: the sessionless
/mcpserving posture meansGETandDELETEreturn405after authentication (rmcp 3.1.2tower.rsserves POST-only whenlegacy_session_mode = falsewith no event store), and the docs now state this — but no first-party test in this repo pins it. The guarantee currently rests on the vendored SDK's dispatch arm alone; an rmcp upgrade that starts servingGET(SSE streams) orDELETE(session teardown) by default would change the wire surface silently.Add a small case to
crates/aisix-mcp/tests/protocol_generations.rs(or the proxy suite for the authenticated path): authenticatedGET /mcpandDELETE /mcp→405, unauthenticated →401first.🤖 Generated with Claude Code