fix(everything): answer 404 for an unknown streamable HTTP session - #4944
Open
jayhemnani9910 wants to merge 1 commit into
Open
jayhemnani9910 wants to merge 1 commit into
jayhemnani9910 wants to merge 1 commit into
Conversation
Requests carrying a session ID the server didn't know (never issued, or already terminated with DELETE) got 400 "No valid session ID provided". The transport spec requires 404 here so the client starts a new session; with 400 a client cannot recover, e.g. after a server restart. Return 404 "Session not found" (as the SDK transport does) for an unknown session ID, and keep 400 for a missing one.
|
5 tasks done
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The everything server's streamable HTTP endpoint answered
400 "Bad Request: No valid session ID provided"for a request carrying a session ID it didn't know, whether never issued or already ended withDELETE. The transport spec (Session Management) says the server MUST answer 404 in that case, and that the client MUST start a new session when it gets 404. With 400 a client can't tell that its session is gone, for example after the server restarts. Unknown session IDs now get404 {"code": -32001, "message": "Session not found"}, the same response the SDK transport uses. A request with no session ID still gets 400.Server Details
Motivation and Context
The everything server is what client authors test against, so it should show the session-expiry behaviour clients are expected to handle.
How Has This Been Tested?
DELETE, then POST/GET/DELETE with the old ID, plus the same with a never-issued ID. All six now return 404 (400 on main), and a live session still works.npm run buildandvitestpass. There are no transport-level tests in this package to extend.Breaking Changes
None for spec-compliant clients.
Types of changes
Checklist