Skip to content

Commit 36215f5

Browse files
committed
fix: reject invalid JSON-RPC response versions
1 parent 1cf7903 commit 36215f5

2 files changed

Lines changed: 24 additions & 0 deletions

File tree

‎mcp-core/src/main/java/io/modelcontextprotocol/spec/McpSchema.java‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -320,6 +320,7 @@ public record JSONRPCResponse( // @formatter:off
320320

321321
public JSONRPCResponse {
322322
Assert.hasText(jsonrpc, "jsonrpc must not be empty");
323+
Assert.isTrue(JSONRPC_VERSION.equals(jsonrpc), "jsonrpc must be 2.0");
323324
Assert.notNull(id, "MCP responses MUST include an ID - null IDs are not allowed");
324325
Assert.isTrue(id instanceof String || id instanceof Integer || id instanceof Long,
325326
"MCP responses MUST have an ID that is either a string or integer");

‎mcp-test/src/test/java/io/modelcontextprotocol/spec/JsonRpcDispatchTests.java‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@
66

77
import static io.modelcontextprotocol.util.McpJsonMapperUtils.JSON_MAPPER;
88
import static org.assertj.core.api.Assertions.assertThat;
9+
import static org.assertj.core.api.Assertions.assertThatThrownBy;
910

1011
import java.io.IOException;
1112
import java.util.Map;
@@ -81,6 +82,28 @@ void dispatchesErrorResponse() throws IOException {
8182
assertThat(resp.result()).isNull();
8283
}
8384

85+
@Test
86+
void rejectsSuccessResponseWithInvalidJsonRpcVersion() {
87+
String json = """
88+
{"jsonrpc":"1.0","id":"req-1","result":{"content":[{"type":"text","text":"hi"}]}}
89+
""";
90+
91+
assertThatThrownBy(() -> McpSchema.deserializeJsonRpcMessage(mapper, json)).rootCause()
92+
.isInstanceOf(IllegalArgumentException.class)
93+
.hasMessage("jsonrpc must be 2.0");
94+
}
95+
96+
@Test
97+
void rejectsErrorResponseWithInvalidJsonRpcVersion() {
98+
String json = """
99+
{"jsonrpc":"1.0","id":"req-1","error":{"code":-32601,"message":"Method not found"}}
100+
""";
101+
102+
assertThatThrownBy(() -> McpSchema.deserializeJsonRpcMessage(mapper, json)).rootCause()
103+
.isInstanceOf(IllegalArgumentException.class)
104+
.hasMessage("jsonrpc must be 2.0");
105+
}
106+
84107
@Test
85108
void paramsMapSurvivesConvertValue() throws IOException {
86109
String json = """

0 commit comments

Comments
 (0)