Skip to content

[Client] Expired HTTP sessions remain marked connected, including during cancellation #559

Description

@ineersa

Describe the bug
Stateful Streamable HTTP session expiry is not correctly reflected in the PHP SDK’s connection state.

In the affected HttpTransport::send() implementation, HTTP status codes are not checked before processing or discarding the response body.

Consequently:

  • A session-bound HTTP 404 with an empty or plain-text body leaves the tool request waiting until timeout.
  • Client::isConnected() remains true, and subsequent requests continue using the expired session.
  • A 404 returned for notifications/cancelled is also discarded without invalidating the connection.

This concerns protocol revisions using Mcp-Session-Id, such as 2025-11-25.

To Reproduce

Ordinary tool request

  1. Initialize a connection to a stateful HTTP server and receive session ID S.
  2. Invalidate S on the server.
  3. Call a tool. The server returns HTTP 404 with an empty or plain-text body.
  4. Observe that the request waits until timeout and the client still reports itself connected.
  5. Make another call: it sends the same expired session ID.

Cancellation or deadline expiry

  1. Start a tool call using session S and leave its response pending.
  2. Invalidate the session, then cancel the call or let its deadline expire.
  3. The SDK sends notifications/cancelled with S; the server returns HTTP 404.
  4. The original call is interrupted, but the client remains marked connected despite its expired session.

Simply adding a ConnectionException for HTTP 404 is insufficient for the second case: Protocol::notifyCancellation() catches notification failures. Connection invalidation must persist independently of whether that exception reaches the caller.

Expected behavior

  • Recognize a 404 on a request carrying Mcp-Session-Id as session expiry.
  • Close the response body, clear the session ID, and mark the client uninitialized so isConnected() returns false.
  • Surface an ordinary request’s session expiry promptly as a connection failure.
  • Preserve the original cancellation/deadline exception when expiry is detected during the cancellation POST.
  • Allow a subsequent reconnect to initialize without the expired session ID.
  • Keep healthy connections reusable after cancellation or deadline expiry.

The 2025-11-25 specification, Session Management points 3–4, requires fresh initialization after a session-bound 404. It does not require automatically replaying the interrupted tool call.

Additional context

Activity

  1. added
    ClientIssues & PRs related to the Client component
    on Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ClientIssues & PRs related to the Client componentbugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions