This release contains important security and bug fixes. All users are encouraged to upgrade. Thanks to our 2 contributors.
What's Changed
Security 🔒
- [3.x] Apply Host/Origin protection settings to the SSE transport by @jlowin in #5428
- [3.x] Exclude Cookie from forwarded HTTP headers by @jlowin in #5429
- [3.x] Pass client CLI arguments literally to Windows .cmd wrappers by @jlowin and @strawgate in #5420
- [3.x] Use the server's auth provider for component manager routes by @jlowin and @strawgate in #5426
- [3.x] Bound CIMD cache growth by @jlowin in #5430
- [3.x] Include resource metadata in component manager auth challenges by @jlowin in #5435
- [3.x] Apply transforms, enabled state, and auth to hashed tool lookups by @jlowin and @strawgate in #5416
- [3.x] Build client schema types with create_model and bounded caches by @jlowin and @strawgate in #5414
- [3.x] Keep $ref pointers when inlining would produce an oversized schema by @jlowin and @strawgate in #5422
- [3.x] Resolve injected tools through the server's tool lookup by @jlowin in #5432
- [3.x] Require a startup-URL session for the fastmcp dev apps preview by @jlowin and @strawgate in #5418
- [3.x] Inline schemas whose pointers pass through alias definitions by @jlowin and @strawgate in #5439
- [3.x] OpenAPI components send only declared arguments and keep configured headers by @jlowin and @strawgate in #5424
Docs 📚
Full Changelog: v3.4.7...v3.4.8