github samanhappy/mcphub v1.0.44

3 hours ago

Summary

This release lets authenticated modern MCP clients reuse isolated state for session-dependent tools through X-MCPHub-State-Id, fixes upstream OAuth authorization callbacks after the SDK v2 migration, and improves routing compatibility coverage and contributor documentation. Modern application state is process-local and requires sticky routing across replicas.

Features

  • Enable isolated upstream connections and OpenAPI cookie state across modern MCP requests using a client-generated UUID v4 in X-MCPHub-State-Id. State is bound to the authenticated credential, user, and route, and expires after 30 minutes of inactivity. by @samanhappy in #1245

Fixes

  • Restore persisted OAuth discovery state and forward callback issuer information to fix authorization-code exchange failures after the SDK v2 migration. Pending flows created without discovery state must be restarted. by @samanhappy in #1249
  • Correct nonexistent commands and file paths in the contributor guide. by @Bdysj in #1247
  • Add real HTTP regression coverage and configuration documentation for modern MCP routing headers, including validation failures and legacy compatibility. by @samanhappy in #1246

摘要

本版本通过 X-MCPHub-State-Id,让已认证的现代 MCP 客户端能够为依赖会话状态的工具复用隔离状态,修复 SDK v2 迁移后的上游 OAuth 授权回调,并完善路由兼容性测试与贡献指南。现代应用状态保存在当前进程中,多副本部署需要使用粘性路由。

功能

  • 支持通过客户端生成的 UUID v4 X-MCPHub-State-Id,在现代 MCP 请求之间复用隔离的上游连接和 OpenAPI Cookie 状态。状态绑定到认证凭据、用户和路由,并在闲置 30 分钟后过期。 by @samanhappy in #1245

修复

  • 恢复持久化的 OAuth 发现状态并传递回调签发者信息,修复 SDK v2 迁移后的授权码交换失败。未保存发现状态的已有授权流程需要重新发起。 by @samanhappy in #1249
  • 修正贡献指南中不存在的命令和文件路径。 by @Bdysj in #1247
  • 为现代 MCP 路由请求头补充真实 HTTP 回归测试和配置文档,覆盖校验失败与旧版兼容性。 by @samanhappy in #1246

References

Don't miss a new mcphub release

NewReleases is sending notifications on new releases.