Upgrade notes
- Redirects: the HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets
redirectPolicy: 'follow'onStreamableHTTPClientTransportorSSEClientTransport. In browsers, a redirected request fails unless that option is set. - New options, both off unless you set them:
maxToolInputElementsonMcpServerlimits the number of array elements and object members in a tool call's arguments.expectedResourceonrequireBearerAuthaccepts only tokens issued for this server (the token's audience).
What's Changed
- [v1.x] fix(client): follow redirects only within the endpoint's origin by @claude[bot] in #2902
- docs: point SECURITY.md at GitHub Security Advisories (v1.x) by @claude[bot] in #2910
- [v1.x] examples: close idle sessions and cap the session map by @maxisbey in #2914
- [v1.x] fix(tasks): keep tasks of the in-memory task store within the session that created them by @claude[bot] in #2925
- [v1.x] feat(server): add maxToolInputElements option to limit the number of elements in tool-call arguments by @claude[bot] in #2927
- [v1.x] fix(server): accept tools/call and prompts/get requests that omit arguments by @raashish1601 in #2045
- [v1.x] feat(auth): add expectedResource to requireBearerAuth by @claude[bot] in #2930
- [v1.x] test(e2e): cover tools/call and prompts/get without arguments by @claude[bot] in #2931
- chore: bump version to 1.32.0 by @claude[bot] in #2935
New Contributors
- @raashish1601 made their first contribution in #2045
Full Changelog: 1.31.0...1.32.0