Agent 基础设施官方发布自动监测

MCP TypeScript SDK 1.32.0

MCP TypeScript SDK 1.32.0 restricts default HTTP redirect handling to same-origin and introduces server options for limiting tool input elements and validating token audience.

原始内容为英文;当前页面提供中文导航与来源说明,具体事实请以原文为准。

人类阅读

为什么值得关注

MCP TypeScript SDK version 1.32.0 updates redirect behavior across HTTP client transports (StreamableHTTPClientTransport and SSEClientTransport). Transports now follow redirects only within the same origin (same scheme, host, and port; http to https on the same host is allowed). Cross-host or cross-port redirects require either updating the endpoint URL directly or explicitly setting redirectPolicy: 'follow' , which is also required for browser-based redirected requests to succeed. The release also adds optional configuration flags: maxToolInputElements on McpServer to limit array elements and object members in tool call arguments, and expectedResource in requireBearerAuth to validate the token's target audience. Other fixes include accepting tools/call and prompts/get requests without arguments, scoping in-memory tasks to the session that created them, and capping idle sessions in examples.

Agent 解析

可执行摘要

Upgrade to MCP TypeScript SDK 1.32.0: HTTP client transports now restrict automatic redirects to same-origin unless redirectPolicy: 'follow' is configured. New server options include maxToolInputElements to limit tool call arguments and expectedResource for audience validation in requireBearerAuth.

Agent 实用度
94/100
可信度
96%
机器格式
JSON + Markdown
下一步

开发者应核对什么

  • Check deployments using StreamableHTTPClientTransport or SSEClientTransport that rely on cross-host or cross-port redirects, and either specify the final target URL or set redirectPolicy: 'follow'.
  • Ensure browser-based MCP clients receiving redirects configure redirectPolicy: 'follow' to prevent request failures.
  • Optionally configure maxToolInputElements on McpServer to enforce limits on argument array/object sizes.
  • Optionally configure expectedResource in requireBearerAuth if audience restriction is required for authentication tokens.
分类

标签与路由

mcpsdktypescript
相关信号

继续阅读