Skip to content

fix(uri-template): preserve percent-encoded triplets in reserved expansions - #2923

Draft
takagibit18 wants to merge 1 commit into
modelcontextprotocol:mainfrom
takagibit18:draft/uri-reserved-triplets
Draft

takagibit18 wants to merge 1 commit into
modelcontextprotocol:mainfrom
takagibit18:draft/uri-reserved-triplets

Conversation

@takagibit18

Copy link
Copy Markdown

Reserved and fragment expansions currently turn %20 into %2520, changing a value that already contains a URI escape. Preserve valid %HH sequences after encodeURI() for those two operators.

The behavior follows RFC 6570 section 3.2.1. Regression tests cover lowercase hex digits, encoded percent signs, list elements, fragment values and malformed escapes. A simple-expansion test checks that its percent sign is still encoded. The changeset covers the client and server packages, which publicly export UriTemplate.

Closes #2920.

Validation

  • Core-internal: 1528 tests passed with the repository's Vitest 4.1.2 configuration using --configLoader runner.
  • pnpm lint:all, pnpm typecheck:all, and pnpm build:all: passed.
  • The issue reproducer returns the expected output with this patch.
  • The Workers compatibility test passed when run outside the sandbox.

The full workspace test run on Windows has failures in the codemod symlink-cycle test and two stdio shutdown-escalation cases that wait for a SIGTERM marker.

@changeset-bot

changeset-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d7d4888

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
Name Type
@modelcontextprotocol/client Patch
@modelcontextprotocol/server Patch
@modelcontextprotocol/codemod Patch
@modelcontextprotocol/core Patch
@modelcontextprotocol/server-legacy Patch
@modelcontextprotocol/core-internal Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Oct 2, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/@modelcontextprotocol/client@2923

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/@modelcontextprotocol/codemod@2923

@modelcontextprotocol/core

npm i https://pkg.pr.new/@modelcontextprotocol/core@2923

@modelcontextprotocol/server

npm i https://pkg.pr.new/@modelcontextprotocol/server@2923

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/@modelcontextprotocol/server-legacy@2923

@modelcontextprotocol/express

npm i https://pkg.pr.new/@modelcontextprotocol/express@2923

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/@modelcontextprotocol/fastify@2923

@modelcontextprotocol/hono

npm i https://pkg.pr.new/@modelcontextprotocol/hono@2923

@modelcontextprotocol/node

npm i https://pkg.pr.new/@modelcontextprotocol/node@2923

commit: d7d4888

@claude claude Bot added the v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes label Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[v2] URI template reserved expansions encode existing %HH sequences again

1 participant