everything: Streamable HTTP answers 400 instead of 404 for an unknown or terminated session #4982
Copy link
Copy link
Closed
Labels
bugSomething isn't workingSomething isn't workingserver-everythingReference implementation for the Everything MCP server - src/everythingReference implementation for the Everything MCP server - src/everythingv2
Milestone
Description
Activity
- addedbugSomething isn't workingSomething isn't workingserver-everythingReference implementation for the Everything MCP server - src/everythingReference implementation for the Everything MCP server - src/everything
on Oct 4, 2026 - linked a pull request that will close this issuefix(everything): Streamable HTTP 404 for unknown sessions, per-stream replay, shutdown closes sessions #5006
on Oct 4, 2026 - linked a pull request that will close this issuefix(everything): Wave 1 rollup of #5004 (10 known bugs) #5043
on Oct 5, 2026 - added a commit that references this issue
on Oct 11, 2026
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workingserver-everythingReference implementation for the Everything MCP server - src/everythingReference implementation for the Everything MCP server - src/everythingv2
Problem
For a request carrying an
Mcp-Session-Idthat the server does not know, or that was ended withDELETE,transports/streamableHttp.tsanswers400 Bad Request. The spec (2025-11-25, Streamable HTTP, Session Management) says the server MUST respond404 Not Found, which is the signal for a client to start a new session. The400body for aPOSTalso omits the JSON-RPC requestid.Where it is pinned
src/everything/__tests__/streamable-http.test.ts: "answers %s for an unknown session with a 400" (GET, DELETE), "answers a POST for an unknown session with a 400 that omits the request id", "ends a session on DELETE, cleaning it up and refusing it afterwards", added in #4978 (Wave 1 of #4857). Each of these tests carries aKNOWN BUGmarker: it asserts the current, wrong behavior, so the fix has to change it.Expected
404for an unknown or terminated session ID, and the error object carries the request'sidwhen the request had one.Done when
KNOWN BUGmarkers are gone.